Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
vxcozy Skill AuditProductivity analyst that maps your workflow, scores tasks by time cost and energy drain, and builds a prioritized 4-week automation plan. Use when you want to audit your workflow, figure out what to automate, do a productivity review, identify high-leverage tasks, feel overwhelmed and need to prioritize, or after the compounder surfaces new friction. Part of the architect-system loop. Outputs to system/audit-report.md.
Audited -
vxcozy Skill ArchitectSolution architect that creates implementation blueprints before building. Maps 2-3 approaches ranked by simplicity, creates phased build plans with rollback points, and checks dependencies. Use when you need to design a solution, create a blueprint, plan before building, or take a task from the audit and need an implementation plan. Part of the architect-system loop. Reads from system/audit-report.md. Outputs to system/blueprints/.
Audited -
vxcozy Skill CompounderWeekly review partner that compounds productivity gains over time. Tracks velocity, logs friction, sets next-week targets, recognizes patterns across weeks, and feeds insights back to the audit for the next loop. Use when you want a weekly review, need to identify friction, want to see patterns, or want to update your system map. Part of the architect-system loop. Outputs to system/compounder/week-{date}.md.
Audited -
vxcozy Skill Architect SystemMaster orchestrator for the 5-step productivity loop. Runs audit, architect, analyst, refinery, and compounder in sequence or individually. Use when you want to run the full loop, start the system, check system status, resume from where you left off, or run a specific step. Manages state, sequencing, and skill chaining. Supports full loop, single step, resume, and status-only modes.
Audited -
wazootech Skill Mega Plan Audit> [!IMPORTANT]
-
yelban Skill System Audit掃描 CLAUDE.md、MEMORY.md 與所有已安裝 skills,找出冗餘指令、臃腫內容、 重疊範圍與 token 浪費。產出清理建議並互動確認執行。 觸發詞:/system-audit、audit skills、audit claude.md、系統審核
-
mohitmishra786 Skill ResearchResearch latest frameworks, libraries, security best practices, and technical benchmarks for informed decisions
Audited -
mohitmishra786 Skill SecurityScan for vulnerabilities, check OWASP Top 10, audit dependencies, and implement security best practices
Audited -
optima-cityu Bundle EohEvolution of Heuristics (EOH) method skill. USE WHEN the user explicitly requests EoH / Evolution of Heuristics, or wants population-level heuristic evolution with explore-exploit-merge-modify operators.
-
redteamlife Skill Forge ReviewUse when the user asks to review work, a PR/MR, or whether a task is done in a repo containing `docs/forge/` or governed by FORGE. Runs the critique, security review, and evaluation gates in order; CI alone is not a review.
-
redteamlife Skill Forge Security ReviewApply FORGE checklist-based security review to a task. Use when selecting a task-specific security checklist, reviewing trust-boundary and sensitive-data impact, and producing explicit pass, n-a, or escalated outcomes for each item.
-
skillx-run Bundle Dangerous ExampleExample skill with intentional security issues for scanner demonstration
-
swarmclawai Bundle Skill CreatorCreate, edit, improve, or audit skills for SwarmClaw agents. Use when creating a new skill from scratch or when asked to improve, review, audit, tidy up, or clean up an existing skill or SKILL.md file. Also use when editing or restructuring a skill directory. Triggers on phrases like "create a skill", "author a skill", "tidy up a skill", "improve this skill", "review the skill", "clean up the skill", "audit the skill".
Audited -
usrrname Bundle DepcheckChecks projects and packages for CVEs using Socket.dev CLI and native audit commands. Use when installing or auditing dependencies for vulnerabilities, evaluating a package before install, or scanning a project's dependency tree (npm, bun, Python/uv, PyPI).
-
usrrname Skill Prune MemoryAudit the current project's memory store (`~/.claude/projects/<encoded-cwd>/memory/`) and prune memories that no longer match the project state — dead file/function/flag references, past-dated project memories, orphaned index entries, and duplicates. Suggests candidates with rationale and requires per-item confirmation before deleting; does not edit memory bodies. Use when the user says "prune memory", "clean up memory", "audit memory", "memory is stale", "remove old memories", or invokes /prune-memory.
-
sohaibt Skill Founder AuditDiagnose where you sit on the founder mode vs. manager mode spectrum. Based on Brian Chesky's operating system and Paul Graham's framework. Use when a founder or CEO wants to assess whether they're leading like a founder or drifting into manager mode.
-
syncfusion Bundle Syncfusion Dotnet PDFCreate, read, edit, secure, sign, and convert PDF documents (.pdf) using Syncfusion PDF Library for .NET. Use this skill for PDF processing and document automation when the user asks to generate PDF files, modify PDF content, add security or signatures, extract text or images, merge or split PDFs, or perform PDF/A conversion using C# code or CSX execution.
-
thijsvos Bundle VetStructured code review across correctness, security, performance, and conventions with prioritized findings and fix offers.
-
thijsvos Bundle RefactorComprehensive code refactoring across correctness, security, performance, and maintainability with behavior-preserving, incremental changes.
-
tjboudreaux Skill Eng Security SafetyApply proactive threat modeling, least-privilege design, and safety guardrails before delivering any code or infrastructure change.
-
ommakes Bundle RighterApply UX content writing principles to review existing UI copy or write new UI copy from scratch. Use this skill whenever someone asks you to: review, audit, critique, or improve UI text, error messages, button labels, tooltips, empty states, onboarding copy, form helper text, or any software interface copy. Also trigger when someone asks you to write new UI copy, label a button, draft an error message, write a modal, or create any in-product text. If the request involves words that appear inside software — use this skill.
Audited -
open-gsd Bundle Gsd Loop ReviewAudit one open PR against its linked issue contract and required CI, then post a gsd-loop verdict and labels. Use when asked to run the reviewer or audit the PR queue. Never merge or push; each invocation completes one pass.
-
peterfox Bundle PackagistLook up PHP packages on Packagist using the API. Use when the user wants to search for packages, get package details or metadata, check download statistics, look up security advisories, list packages by vendor or type, or find popular PHP packages. Triggers on phrases like "find a package for...", "look up packagist", "search for a composer package", "check package stats", "packagist security advisories", "what packages does vendor X have".
-
peterfox Bundle NPM UpgradeGuides Node.js project upgrades using npm, yarn, or pnpm. Use when helping users upgrade npm packages, check for security vulnerabilities with `npm audit`, prioritize which packages to upgrade first, understand dependency conflicts, interpret `npm outdated` output, use `npm explain` to trace who requires a package, plan safe upgrade paths, resolve package version conflicts in package.json, or resolve merge conflicts in package-lock.json / yarn.lock / pnpm-lock.yaml. Trigger this skill whenever the user mentions npm packages, Node.js dependencies, outdated packages, CVEs in JavaScript or TypeScript projects, yarn or pnpm upgrades, or security advisories in package.json.
Audited -
peterfox Bundle Composer UpgradeGuides PHP project upgrades using Composer commands. Use when helping users upgrade PHP packages, check for security vulnerabilities with `composer audit`, prioritize which packages to upgrade first, understand dependency conflicts, interpret `composer outdated` output, use `composer why-not` to diagnose version constraints, use `composer why` to trace dependencies, use `composer bump` to harden version constraints after upgrading, plan safe upgrade paths, resolve package version conflicts in composer.json, or resolve merge conflicts in composer.lock. Trigger this skill whenever the user mentions composer packages, PHP dependencies, outdated packages, CVEs in PHP projects, or security advisories.
Audited -
philoserf Bundle Code AuditReviews a codebase for bugs, design issues, and code cleanliness problems with specific file paths and line numbers. Use when auditing code quality, finding bugs, doing a code review, or reviewing a project for issues. Writes issues to `.issues/`.
-
pitzcarraldo Bundle Tech Spec ReviewReview a tech spec document written in the team's Notion template format (Summary, Background, Goals, Non-Goals, Plan, Measuring Impact, Security/Privacy/Risks, Other Considerations, Milestones, Open Questions). Use when the user asks to "테크 스펙 리뷰", "tech spec 리뷰", "스펙 문서 리뷰", "이 스펙 봐줘", or provides a Notion/Google Docs/Markdown tech spec link or file and asks for feedback, critique, or readiness check before sharing with the team.
-
gualask Bundle Cf StartAssess and plan repository-level refactors: architecture, structure, ownership, dependency direction, target shape, migration order, execution, review, verification, and `.cflow` resume. Use after the diagnostic frame is confirmed. Do not use for a bounded fix, a security or correctness defect confined to a few files, or any change that does not move ownership, structure, or dependency direction.
Audited -
hackingyseguridad Skill API PentestUsar esta habilidad SIEMPRE que el usuario quiera realizar pruebas de penetración, auditoría, análisis o explotación de vulnerabilidades sobre una API REST, API GraphQL, API SOAP, portal web con API, servicio HTTP/HTTPS con endpoints de API, IP o FQDN con servicios de API activos. Activar cuando se mencionen: auditoría de API, OWASP API Top 10, autenticación API, JWT, OAuth2, API Key, token de acceso, endpoints API, Swagger, OpenAPI, GraphQL, REST, SOAP, inyección en API, BOLA, BFLA, SSRF en API, inyección de objetos, fuerza bruta API, limitación de tasa, CORS, cabeceras de seguridad API, fuzzing de API, enumeración de endpoints, secretos en GitHub, XSS en API, o cualquier técnica ofensiva sobre interfaces de programación. También activar cuando el usuario proporcione una IP/FQDN y pida: reconocimiento de API, explotar API, prueba de concepto API, análisis de token, auditar OAuth, revisar JWT, buscar endpoints expuestos, o auditoría de seguridad de API. Repositorio de referencia: https://github.com/hackingyse
Audited -
hackingyseguridad Skill Cve Poc ValidatorUsar esta skill cuando el usuario (hacker ético / auditor) quiera validar vulnerabilidades CVE ya identificadas mediante pruebas de concepto (POC), scripts o exploits reales para descartar falsos positivos/negativos. Activa cuando se mencionen: POC, prueba de concepto, validar CVE, confirmar vulnerabilidad, exploit, script de explotación, descartar falso negativo/positivo, código de prueba, PoC bash/python/C, enlaces exploit, github CVE. También activa cuando el usuario proporcione una lista de CVEs y pida código o scripts para probarlos. Contexto: hackingyseguridad.com — auditoría ofensiva ética, Kali Linux, entorno controlado.
-
hackingyseguridad Skill Cve ExploitUsar esta skill cuando el usuario tenga vulnerabilidades CVE ya confirmadas mediante POC y necesite: código de explotación (exploit), scripts en Bash/Python/C para demostrar la vulnerabilidad, o enlaces a exploits públicos en Exploit-DB, GitHub, PacketStorm, etc. Activa cuando se mencionen: exploit, explotación, CVE confirmado, script de ataque, POC funcional, payload, reverse shell, RCE, LPE, SQLi exploit, buffer overflow exploit. Prerequisito implícito: vulnerabilidad ya confirmada en entorno autorizado.
-
hackingyseguridad Skill Web PentestUsar esta habilidad SIEMPRE que el usuario quiera realizar pruebas de penetración, auditoría, análisis automático o explotación de vulnerabilidades sobre un portal web, aplicación web, API REST, servicio HTTP/HTTPS, IP o FQDN con el servicio web activo. Activar cuando se mencionen: auditoría web, SQLi, XSS, LFI, RFI, inyección de comandos, traversal de directorios, CSRF, XXE, SSRF, evasión de WAF, omisión de código 403, cabeceras HTTP inseguras, cifrados TLS débiles, smuggling HTTP, proxy abierto, fuerza bruta web, nikto, wapiti, dirb, gobuster, whatweb, CVE web, Apache, Nginx, Citrix, FortiGate, F5, PaperCut, Cisco IOS XE, Spring4Shell, o cualquier técnica ofensiva sobre el protocolo HTTP/HTTPS. También activar cuando el usuario proporcione una IP/FQDN y pida: reconocimiento web, explotar portal, POC web, escanear web, descubrir rutas, buscar secretos, analizar TLS, o auditoría OWASP. Repositorio de referencia: https://github.com/hackingyseguridad/webaudit/
Audited -
hcaiano Bundle Cyber AuditRead-only audit of this machine against a named CVE, malicious package, or supply-chain advisory. Use only when explicitly asked whether this machine is affected; not for general security review, news, breach response, or remediation.
-
hughyau Skill Paper Self ReviewAdversarially review a paper before submission and predict exactly what reviewers will attack, using the five-category rejection checklist (contribution, writing clarity, result strength, experimental coverage, method soundness) plus a claim-to-evidence audit. Produces a findings report with a verdict per item, not vague impressions. Use whenever the user asks if a paper is ready, what reviewers will say, whether the contribution is enough, whether they will get rejected, or asks you to review someone else's submission — and run it proactively before any submission deadline, because the checklist routinely surfaces a missing ablation or an unsupported abstract claim while there is still time to fix it. Boundary: this predicts what gets attacked and produces the findings list; actually rewriting what it finds is paper-revision. 中文触发:自评审、review论文、审稿、会不会被拒、contribution够不够、投稿前检查、adversarial writing、帮我看看这篇论文。
-
ibm Skill Code QualityFormat, tidy, vet, lint, and secret-scan the ibm-licensing-operator codebase before committing or opening a PR. Runs the same checks the pre-commit git hook and CI enforce (golangci-lint, shellcheck, yamllint, mdl, go vet, detect-secrets). Use before every commit, when preparing a PR, or after any code/YAML/script/markdown change.
-
iker-gonzalez Skill Antwork AuditUse when the user wants a full audit, health check, or scorecard of their social-media presence managed through Antwork — engagement performance, voice consistency, posting cadence, content quality, and platform coverage. Trigger on "audit my socials", "how's my LinkedIn/X doing", "social health check", "review my Antwork account", "what should I fix", "grade my content".
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include audit, architect, compounder. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.