Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
linuxfoundation Skill Member Service Code ReviewHow to judge the implementation of an lfx-v2-member-service pull request: the grounding technique for reading a hunk in its real context, the general quality dimensions (correctness, error handling, logging, tests, concurrency, readability, code truthfulness), how to hold the diff to the repo's documented standards for this Goa + NATS + Salesforce Go service, the member-service specifics worth a second look, and the security anchors that make a diff security-relevant here. Use on every PR that changes code, however small; this is the reviewer's line-level lens.
-
linuxfoundation Skill Member Service Pr ReadinessShape-only pre-PR check for local lfx-v2-member-service work. Audits the branch name, LFXV2 ticket reference, conventional commit subjects, rebase status, DCO and GPG signing per commit, total diff size, and protected member-service files touched against the target base branch. Does not audit code behavior or run build/test/lint checks; run /member-service-preflight after this passes.
-
lishix520 Bundle Jtbd Job DefinerExtract, audit, or rewrite a solution-free and outcome-free Core Functional Job statement from customer quotes or candidate sentences. Use when given a proposed product feature or customer statement and asked to express the underlying functional job, audit a job statement for solution contamination, or determine if enough evidence exists to validate a job statement. Do not use to map job steps, write desired outcomes, calculate opportunity scores, or recommend product strategy.
-
lishix520 Bundle Jtbd Outcome EngineerFormulate formulaic Desired Outcome Statements for a specific job map step using ODI metrics (time, likelihood, effort, cost, output). Use when given a job map step, qualitative pain point, or survey question and asked to express performance metrics, audit outcome statements, or prepare survey items for quantitative research. Do not use to calculate opportunity scores or recommend product strategy.
-
longyenkai83 Bundle Kallaway Script MasterViết kịch bản video viral (60s-15min) theo phương pháp Kallaway — kết hợp 6 Levels of Storytelling (Reporter→Artist), 4 Blockers (Research/Hook/Structure/Engagement), và 6 Story Locks (Naming/Embedded Truths/Thought Articulation/Negative Frames/Loop Openers/Contrast Words). Use when user wants to write/audit/improve full video script (>15s), kịch bản reels dài, kịch bản long-form, audit retention curve, viết kịch bản giữ chân người xem. Vietnamese-first. Triggers — "viết kịch bản", "script video", "kịch bản long-form", "audit script", "tăng retention", "story locks", "6 levels storytelling".
-
lst97 Skill Security AuditStatic Analysis and Threat Modeling skill to detect OWASP Top 10 vulnerabilities.
-
manutej Skill Production GradeRouter and orchestrator for the craft code-quality guardrails. Use FIRST on any broad "is this production-ready?", "review this code/diff/PR", "build this properly", "why does our AI-generated code keep needing rework", or "make this maintainable" request. Two modes: GENERATIVE GUARD (load the right senior heuristics before writing code) and CRITIQUE (audit a diff/file and return one worst-first ranked list of findings). Decomposes the request, fires the relevant craft member skills plus the existing complexity/refactoring/dependency/test skills in the right order, resolves their conflicts, and returns a single merged verdict. Defer to a single member skill only when the task is already narrow.
-
nainishshafi Bundle Scan Halucinated TestsUse when the user asks to "scan for hallucinated tests", "check if my tests are hallucinated", "validate tests against source", "verify test accuracy", "find fake test assertions", "audit tests for hallucinations", "test hallucination scan", "verify tests match source code", "check java tests", "validate c# tests", or "check javascript tests for hallucinations". Also use when the user wants to cross-check a test file against real source code to detect phantom symbols, wrong imports, bad mock targets, or fabricated constants — in any supported language.
Audited -
nainishshafi Bundle Design Pattern DetectorUse when the user asks to "detect design patterns", "find patterns in this file", "analyze code for patterns", "check for anti-patterns", "pattern analysis", "is this a singleton", "detect god object", "find factory pattern", "check for strategy pattern", "scan for design patterns", "what patterns does this code use", "find anti-patterns", "pattern audit", or wants to identify design patterns and anti-patterns in a source file or across the entire repository.
Audited -
nanmicoder Bundle Dsh Upgrade AuditAudit external compatibility between two DSH (DeepSeek Harness) versions and detect reverts, producing an upgrade-report directory; compares git tags with a source checkout, or published npm packages without one. Use whenever the user asks to check/compare/audit two DSH versions or whether upgrading is safe — e.g. "more changes or reverts in dsh-vX -> dsh-vY", "compare the breaking changes" — even with only two version numbers and no source location. Read-only outside the report directory; npm mode installs in isolation with --ignore-scripts.
Audited -
hitoshura25 Skill Security CheckSecurity Check Skill
-
hitoshura25 Skill Security SetupSecurity Setup Skill
-
curvineio Bundle Cv Test ReportPublish Curvine full-chain daily test reports to the Hextra Hugo site at CurvineIO/test-reports, using a standard Markdown template with no environment or secret leakage. Use when the user asks to publish a test report, convert harness output to Markdown, or update CurvineIO/test-reports.
-
nexscope-ai Bundle Ecommerce Geo AuditorDiagnose an ecommerce page or listing for GEO, AI-search, AI-citation, and AI-shopping readiness using inspected page evidence, supplied content, or crawl data. Use when the user asks for a GEO audit, AI visibility readiness check, AI search audit, citation-readiness review, or why a product is hard for AI systems to understand. Diagnose only; do not claim actual AI mentions or rewrite the full page.
-
nexscope-ai Bundle Geo Content OptimizerRewrite ecommerce product, category, store, or marketplace content so verified facts are clear, specific, structured, and answer-ready for GEO, AI search, and AI citations. Use when the user asks to optimize content for GEO, AI search, AI answers, citations, or clearer product facts. Do not perform a technical audit or claim measured AI visibility without live evidence.
-
nexscope-ai Bundle Ecommerce Geo OptimizerTurn verified ecommerce GEO, AI-search, or AI-citation readiness gaps into a prioritized implementation plan covering content, product facts, technical access, structured data, trust, and measurement. Use when the user asks to improve GEO, optimize for AI search, fix a GEO audit, or create an AI visibility readiness plan. Do not present the plan as a live audit or measured visibility.
-
noique Bundle Security Precommit CheckPre-commit security scanner for git repos — blocks API keys, proxy credentials, private keys, and project-specific secrets before they reach a remote. Provides a central rule definition + per-repo customization + one-line installer that wires up `.git/hooks/pre-commit`. Use when you want to prevent accidental credential / identity / brand leaks across multiple repos. Triggers on "set up pre-commit security check", "block API keys in commits", "git secret scanner", "prevent credential leaks", "protect identity isolation in public repos".
-
nowespojrzenie Skill AI Personas Not ModesUse when an assistant keeps switching register on its own — dropping into tables, measurements and audit language in the middle of an ordinary conversation, or conversely staying chatty when the user needs the machinery. Provides a calling ladder built from names rather than modes, three verb-actions that fire once without changing who you are talking to, a state indicator on every reply, and a three-class rule for when the assistant may switch by itself. Load when someone says the assistant "won't stop being formal", "keeps producing reports", or when designing how a user should address a system that has more than one working voice.
Audited -
nowespojrzenie Skill AI Self Audit Without HedgingUse alongside ai-hallucination-truth-status when self-auditing would otherwise flood the conversation with tags, hedges, and disclaimers. Keeps the audit running silently and gates disclosure — surfacing a named substrate voice only when it would change the reader's decision, when a threshold is crossed, or when asked. Load when the user says "stop hedging", "too many caveats", "just answer", or when a long session has turned every reply into a forest of qualifiers.
Audited -
nutstore Bundle Cw Code Review ExpertConduct a rigorous, evidence-based code review for a change set, pull request, diff, or selected files. Use when users ask to review code, assess a PR, find bugs/security/performance risks, validate a refactor, or request a second engineering opinion. Inspect scope before details, load targeted checklists progressively, prioritize only actionable findings as P0-P3, and report before making any code changes.
-
onflow Bundle Cadence LangComprehensive guide for writing correct, secure, and idiomatic Cadence smart contract code on the Flow blockchain. Covers language fundamentals (resources, contracts, transactions, interfaces, accounts, references, imports), access control and entitlements, capabilities, pre/post conditions, security best practices (including checks-effects-interactions, trust-boundary validation, and bounded loops), anti-patterns to avoid, proven design patterns, style and readability rules, and numeric precision with checked arithmetic. TRIGGER when: writing or debugging Cadence code, asking about Cadence syntax, access(self), access(all), entitlements, resources, move operator (<-), capabilities, references, pre/post conditions, storage paths, optional binding, if let, guard let, force-unwrap, string templates, UFix128, Fix128, fixed-point precision, overflow, checks-effects-interactions, reentrancy, "how do I write cadence", "cadence error", "compile error in .cdc", "what does access(self) mean", "how do resources work",
-
onflow Bundle Cadence AuditComprehensive audit and review skill for Cadence smart contracts on the Flow blockchain. Identifies security vulnerabilities, bugs, code quality issues, and optimization opportunities. Produces severity-rated findings (Critical/High/Medium/Low) with actionable fixes. TRIGGER when: auditing, reviewing, or improving Cadence code, checking for security issues, performing code review on .cdc files, looking for anti-patterns or vulnerabilities, optimizing smart contract code, "review cadence", "audit cadence", "check cadence security", "validate cadence contract", "review my .cdc file", "security review", "code review", "find vulnerabilities", "check this contract", "is this code secure", "audit my project". DO NOT TRIGGER when: writing new contracts from scratch (use cadence-scaffold), asking about Cadence syntax or patterns (use cadence-lang), building token contracts (use cadence-tokens).
-
onflow Bundle Cadence TokensGuide for developing NFT and Fungible Token contracts on the Flow blockchain using Cadence. Covers NonFungibleToken and FungibleToken interface conformance, MetadataViews integration for marketplace compatibility, collection patterns, minting, standard paths, event emission, and modular NFT architectures for complex traits and evolution. TRIGGER when: building NFT contracts, FT token contracts, implementing NonFungibleToken or FungibleToken interfaces, working with MetadataViews, creating collections, minting tokens, "create an NFT", "build a token contract", "mint NFT", "NFT collection", "fungible token vault", "royalties", "MetadataViews.Display", "NonFungibleToken.Collection", "token standards", "FungibleToken.Vault". DO NOT TRIGGER when: asking about general Cadence syntax or patterns (use cadence-lang), setting up flow.json or deploying (use flow-project-setup), auditing code (use cadence-audit).
-
erikhoward Bundle Bare BonesEdit or audit technical and general prose for clarity, factual precision, consistent terms, and preserved writer voice. Use strict ASD-STE100 rules only when requested.
-
ethereum Skill Audit ConfigCheck whether repository guidance and skills are still accurate.
-
ethereum Skill Grammar CheckAudit grammar in documentation and code comments.
-
ethereum Skill Property Rules TrustPer-property guidance for the Trust / robustness property group (drawn from the schema's Decentralization & Security and Verifiable groups, excluding maturity which lives in property-rules-timing). Invoke when evaluating, reviewing, or editing notes/values for Censorship resistance, External network dependence, Escape hatch, Open source, Upgradeability, or Third-party inspectability. Cross-cutting rules in scripts/research-prompts.ts still apply on top.
-
fcakyon Skill Paper VerificationUse when the user wants to verify paper claims against code or data, audit numerical accuracy, check formula-code alignment, or validate citation accuracy. Triggers on phrases like "verify claims", "check numbers", "do the numbers match", "formula vs code", "audit the paper", or "cross-check results".
-
fredchu Bundle AutomlAutonomous Evaluation Loop — calibrated alignment + round loop + audit discipline + always-on gates + RED_TEAM opt-in + multi-session lock + cross-session quota coordination + worktree advisory + orphan recovery + calibrator self-improvement telemetry. Triggered: /automl, "let it run to completion", "let it run until done".
Audited -
glincker Skill Mixer DoctorUse when the user describes a mix problem ("muddy", "harsh", "no headroom", "vocals get lost", "kick and bass fighting") or asks for a mix audit. Diagnoses the issue from session state and proposes specific corrective moves with EQ, compression, sends, and routing.
-
glincker Skill Mastering PrepUse when the user is finishing a track and wants to check it's ready to send to a mastering engineer or for self-mastering. Audits headroom, peak levels, mono compatibility, frequency balance, LUFS. Examples - "is this ready to master?", "audit my mix before export", "check my levels".
-
gualask Bundle Cf DocsWrite accurate, lean, nonduplicative documentation. Use when the request writes a Markdown file — authoring, updating, trimming, or restructuring docs, READMEs, or design notes — or asks to audit or fact-check them against the code; do not use otherwise.
-
rusel95 Bundle IOS SecurityUse for any iOS security question — whether you're asking about a specific vulnerability, checking if a pattern is secure, or running a full audit. Triggers on: Keychain vs UserDefaults decisions, ATS/NSAllowsArbitraryLoads configuration, certificate pinning implementation, WebView security (UIWebView, WKWebView), hardcoded secrets or API keys, jailbreak/tamper detection, biometric authentication, MASVS controls, OWASP mobile security, App Store rejection risks, and compliance requirements (HIPAA, PCI DSS, GDPR). Also use when someone asks 'is this secure?', 'what should I use instead?', or 'how do I fix this?' about any iOS storage, network, or cryptography pattern.
Audited -
seranking-planable Skill Content Calendar AuditAudit a Planable workspace's content calendar for a given period — surface what's scheduled, what's missing, what has no date, and what might have publishing issues. Use this skill whenever the user asks about upcoming content, wants to review the calendar, says things like "what's scheduled this week", "check the calendar for [client]", "what's going out next week", "any gaps in the schedule", "content audit", "what do we have planned", or wants a weekly/monthly content overview for a workspace. Always activate for calendar review and scheduling gap analysis in Planable.
-
siva01c Skill Owasp AsvsOWASP ASVS v5.0 security verification skill with Drupal 11 mappings. Use when performing security code reviews, implementing security requirements, or verifying security compliance in Drupal projects.
-
skill-tools Skill API CallerCalls an API to fetch data. Use when the user wants to retrieve data from our backend API.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include cadence-tokens, member-service-code-review, member-service-pr-readiness. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.