Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
fearofsnakes Skill Message Market FitUse when a PMM wants to audit, test, or improve their product messaging. Trigger on: 'test our messaging', 'audit our copy', 'is our messaging working', 'message-market fit', 'messaging too generic', 'stakeholders keep changing the messaging', 'message testing sprint', 'does our messaging resonate', 'check our website copy', 'score our messaging', 'messaging by committee', 'which message angle should we use', or 'are we talking to the right persona'.
-
flexprice Skill PrFlexPrice PR self-review checklist — security, layering, migrations, tests. Trigger: pr check, ship review, pre-PR.
-
forsonny Skill Continuity PassAudit a chapter range or current manuscript for contradictions, timeline errors, knowledge leaks, rule violations, and unresolved continuity risks.
-
bx33661 Bundle Omv FindFinds and ranks open-source packages worth auditing for passive CVE/VulDB research. Use when the user asks for vulnerability research targets, CVE hunting candidates, packages to audit, projects to fuzz, or `/omv-find`. Supports npm, Python, Go, Rust, Java, Ruby, PHP, C#, Swift, Dart, Elixir, Perl, R, and Lua, with strongest guidance for npm/Python/Go/Rust/Java/Ruby. Produces evidence-backed source -> sink -> guard notes, metadata, scoring, and local audit next steps without live exploitation.
Audited -
bx33661 Bundle Omv AuditDeep-audits a candidate finding from an Evidence.v1 file. Use when the user has an omv-find result they want to investigate further, wants to prove or disprove a vulnerability, needs to fill Evidence.v1 fields for omv-report, or invokes `/omv-audit`. Reads .omv/findings/<id>.yaml and produces a confirmed or blocked finding with all required evidence fields populated.
Audited -
bx33661 Bundle Omv ReproGuides a researcher through local reproduction of a vulnerability finding. Use when the user has an omv-audit result with evidence.reproducer filled but evidence.observed_result still unknown, wants to confirm a finding by running it locally, or invokes `/omv-repro`. Reads .omv/findings/<id>.yaml and guides step-by-step execution, then writes the observed result, records repro artifacts, and validates submission readiness.
Audited -
bx33661 Bundle Using OmvBootstrap discipline for oh-my-vul research. Use at the start of any vulnerability research conversation, when the user asks to audit/find/report a package, dig for CVEs, or run omv skills — and before claiming a finding is confirmed, ready to submit, or “done”. Establishes mandatory process, hard gates, and evidence-before-claims rules. Prefer this over improvising a research workflow.
Audited -
bx33661 Bundle Omv ReportGenerate a complete, ready-to-submit VulDB vulnerability report and CVE request. Covers all major package ecosystems: npm, pip, Go, Cargo (Rust), RubyGems, Maven, Gradle, NuGet, Composer (PHP), CocoaPods, Swift Package Manager, pub (Dart/Flutter), Hex (Elixir), CPAN (Perl), CRAN (R), LuaRocks. Use this skill whenever the user wants to submit a vulnerability to VulDB, request a CVE, write a security advisory, or document a security bug for disclosure. Trigger on phrases like submit to VulDB, request a CVE, write a CVE report, help me report this vuln, 提交 VulDB, 申请 CVE, 帮我报这个漏洞. Also trigger proactively when the user has just finished analysing a vulnerability in any package ecosystem and asks what to do next.
Audited -
campfirein Bundle Byterover AuditAudit knowledge freshness and coverage. Checks what's documented against the current codebase, identifies stale or outdated knowledge, finds gaps, and provides targeted brv curate commands to fix them.
-
campfirein Bundle Byterover ReviewReview code changes against stored conventions, patterns, and architecture decisions. Checks staged changes or specific files for convention violations, pattern mismatches, missing tests, and security concerns. Curates newly discovered patterns.
-
caoyuan-fire Skill Engifoundry AuditClassify new EngiFoundry work for inline action, a minimal direct PAK, a fully planned Package PAK, or a factual block. Use when deciding whether durable task identity and heavyweight orchestration add material value.
Audited -
cdeistopened Skill Fallacy DetectorAnalyze text for logical fallacies using Zakery Kline's framework from Chapter 3 of How to Think. Use when someone says 'check this argument', 'find the fallacies', 'is this reasoning valid', 'analyze this debate', 'what's wrong with this argument', 'logical fallacies', 'is this logically sound', 'audit this essay', 'check my reasoning', or 'fallacy check.' Scans for all 10 named fallacies, quotes the specific passages, and shows how to fix each one.
Audited -
cerebrocybersolutions Bundle Cerebro DoctorMeta-audit of the skill system. Walks `{brain_root}/skills/` + `{brain_root}/AGENTS.md` and reports three classes of drift: (a) skills with no resolver row (unreachable), (b) AGENTS.md rows pointing at missing skills (orphan phrases), (c) DRY overlap — two skills claiming the same trigger substring. Exit code 0 = clean; non-zero = drift. Trigger on: "cerebro doctor", "check resolvable", "skill health check", "resolver audit", "DRY audit", "are my skills reachable".
Audited -
membrane Skill Release NotesGenerate GitHub release notes for the Membrane api-gateway repo by collecting the commits between the last release and master, grouping them into Features / Improvements / Fixes / Security / Dependencies, and linking each to its PR. Use whenever the user wants to draft, extract, or write release notes / a changelog / "what changed since the last release", prepare notes for the next GitHub release, or asks "what's unreleased on master". The user may name a base release (e.g. "since 7.2.3") or let the skill detect the latest one.
-
mflux-community Skill Remediating DependabotRemediates GitHub Dependabot alerts for mflux in one dependency-security change. Use when auditing, clamping, or upgrading Python dependencies in pyproject.toml and uv.lock, or when validating whether a branch will close Dependabot findings before opening a PR.
-
microsoft Bundle Daily Docs AuditAudit recently merged microsoft/vscode pull requests for documentation impact, stage deduplicated issue proposals, and create confirmed issues in microsoft/vscode-docs. ALWAYS use this skill when asked to run or configure a daily docs audit, identify documentation work from merged VS Code PRs, review pending docs issue proposals, or create docs issues for product updates.
Audited 2.7k -
microsoft Skill Docs Product AlignmentAudit and update docs/copilot/ documentation to accurately reflect current VS Code AI capabilities. Use when: competitive analysis reveals gaps, product launches new features, docs use outdated framing, or keyword coverage needs strengthening for discoverability by users and AI agents. Produces a gap analysis plus targeted edits across affected files.
2.7k -
minghinmatthewlam Bundle Maintain Verification SkillPeriodic pass that keeps a project's verification skill and feature map honest: parallel source readers per feature, one live session driving every feature, at most one PR of proven corrections. Use for $maintain-verification-skill or "audit the verify skill".
-
miroapp Bundle Miro Visualize PrUse when the user wants a polished, presentation-quality visualization of a PR/MR on a Miro board — a fresh board named *exactly* after the PR title, with a header banner, titled section bands, BEFORE/AFTER pill-labeled architecture diagrams, a color legend, and titled OWASP + Files-changed + Summary artifacts. Optimized for visual clarity and reviewer scan-ability, not raw diff coverage.
Audited -
miroapp Skill Miro Code To Board ArchitectureUse when the user wants a comprehensive architectural overview of an entire codebase rendered on a Miro board — system inventory, module dependencies, user flows, security analysis (OWASP), and per-module code-quality findings, organized as frames.
-
mshadmanrahman Skill Heuristic EvaluationAudit a design against Nielsen's ten usability heuristics, tying every finding to a specific element with a specific fix. Use on a built screen or a detailed mockup.
-
danilods Skill Matilha ReviewUse when user wants a quality review of a completed wave — will dispatch 6 parallel review agents (code-quality, UX, security, architecture, performance, docs) once Wave 3c ships.
-
datashaman Bundle HarnessControl surface for a harness-engineering Claude Code setup at user or project scope. Handles install, uninstall, update, doctor, adopt, snapshot, status, audit, and memoize. Installs CLAUDE.md, guardrail hooks, /verify, /plan, /critique, memory seeds, and settings patches; can also retrofit an existing project with scripts/harness-check.sh, report install state, snapshot ~/.claude/, and run deterministic memory hygiene. All sub-actions are idempotent. Use when asked to "set up my Claude Code", "install harness", "uninstall harness", "update harness", "diagnose my setup", "adopt harness", "retrofit", "snapshot my setup", "audit my setup", "harden my Claude", "memoize", "consolidate memory", or "prune memory".
Audited -
datashaman Bundle Audit CodebaseGit-based codebase health audit. Identifies churn hotspots, bus factor risks, bug clusters, and firefighting patterns from git history. Use when asked to "audit the codebase", "codebase health", or "who owns this code".
-
datashaman Bundle Audit AI StrategyAudit a codebase's AI strategy through John Cutler's four-bucket lens: bad ideas amplified, good ideas supercharged, genuinely new possibilities, and the meta-skill of reading context. Identifies where AI is bolted onto broken patterns, where it amplifies what already works, and where the codebase could embrace workflows that only exist because AI is in the loop. Use when asked to "audit AI strategy", "evaluate our AI playbook", "find AI opportunities", or "where can we think outside the box with AI".
-
davemaynard Bundle Gap ScanFind market gaps by chaining demand evidence with a supply audit — verify people want something, then grade how well existing tools serve it, and classify each pocket UNSERVED / UNDERSERVED / WELL-SERVED with cited evidence. Trigger with /gap-scan <seed space or demand pocket>, or when the user asks "is there a gap in X", "what's missing in the X market", "who already does this and are they good", or wants demand+supply evidence before committing to an idea.
Audited -
devkindhq Skill HarvesterOSINT domain intelligence skill — use when asked to research a company domain, find email addresses, subdomains, hosts, or employee names associated with a target domain for stack analysis or security reconnaissance.
-
devkindhq Skill Tech DetectorDetect the technology stack of any website. Use when someone shares a URL, asks "what are they running", "what's their stack", or wants to audit a site or research a competitor. Runs WhatWeb scan and returns stack insights and analysis angles.
-
dojocodinglabs Skill Audit EngineAudit a repo for structural anti-patterns and repo health: schema drift, duplicated logical columns, multiple writers with no owner, and the broader six-family sweep. Use when the user asks to "audit" a repo, hunt for "drift" or an "anti-pattern", check "repo health", or run a named detector profile (e.g. schema-drift / SCH). Owns the full flow: preflight, scope, detect, verify, cure-map, emit (findings doc + OpenSpec change + Bilingual Linear issues + 4-cure scaffold proposals). Do NOT trigger for premortems, code review of a single PR, or generic status reports.
-
dojocodinglabs Skill Domain Driven AdvisorGuided entry point for repo health when you don't know which audit you need. Use when the user asks "which audit", "where do I start", wants to check "repo health", or mentions "domain driven" design. Inspects the repo, asks a few plain-language questions, recommends which audit(s) to run (or the full ordered sweep), runs them via the audit-engine, and finishes with a premortem on the remediation plan. Best first command for a new repo.
-
edhahn Bundle Software ArchitectureSoftware architecture and engineering partner for design, code quality, and technical decision-making. Use this skill whenever the user is working on software projects and needs help with: system design or architecture decisions, evaluating technology choices or tradeoffs, code review or refactoring, writing technical specs/ADRs/RFCs, API design, database schema design, infrastructure planning, observability strategy, security architecture, or any discussion about how to structure, build, or evolve a software system. Also trigger when the user says things like "how should I architect this", "what's the right pattern for", "review this code", "I'm choosing between X and Y", "help me write a tech spec", "is this the right approach", or asks about scaling, performance, reliability, or maintainability of a system. Even general coding questions benefit from this skill when the problem involves meaningful design decisions.
-
elitongadotti Skill Acceptance AuditAudit a ticket's acceptance criteria against what the branch actually implements. Every item must be satisfied, and each must semantically match the implementation. Never edit or drop a criterion without the user's agreement.
-
leavesfly Skill Code ReviewReview code for bugs, security, and style issues
-
libpdf-js Skill Code ReviewBrutally honest code review assessing security, reliability, performance, and taste
-
lindoelio Bundle Meteor 3Use this skill whenever building, modifying, planning, scaffolding, testing, or debugging Meteor 3.x applications (Meteor 3.0 through 3.5+). Triggers on requests involving Meteor, Meteor.js, DDP, Minimongo, Atmosphere packages, `meteor create`, Blaze, Tracker, `Meteor.methods`, `Meteor.publish`, `Mongo.Collection`, `Meteor.callAsync`, `findOneAsync`, `insertAsync`, `updateAsync`, or any Meteor 3.x API. Also use when the user mentions Galaxy, MUP, Cordova with Meteor, or is migrating from Meteor 2.x (Fibers) to 3.x (async/await). Covers full-stack reactive architecture, collections/methods/publications, accounts, routing, security, testing, deployment, mobile, and package authoring. Provides scaffold scripts for fast, token-efficient agentic coding. Do NOT use for non-Meteor Node.js apps or Meteor 1.x/2.x projects that have not begun async migration.
Audited -
linuxfoundation Bundle Review PrReview a pull request against Insights architecture standards — fetches PR diff, verifies previous comments are addressed, validates PR metadata (title, branch, JIRA, size), runs a code-standards check against every file in `.claude/rules/` and `.claude/hooks/guard-protected-files.sh`, and drafts inline review comments with suggested fixes. NEVER auto-posts comments or submits reviews — always presents a draft in the terminal for user approval before any comment lands on the PR. Use when reviewing PRs, checking PR quality, validating code changes, or when the user says "review", "check this PR", or "audit code".
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include continuity-pass, miro-code-to-board-architecture, message-market-fit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.