Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
dominikwozniak Skill Dw GrainAudit code just written for excess the gate cannot see: a helper reinvented beside its canonical home, a wrapper with one caller, config for a case that never occurs, a shape the neighbouring files build differently, code this change stranded. One table, and every row is a deletion or a reuse. Explicit-invoke only.
-
drgarbage Bundle Live Dev InitEnvironment preflight checks and initialization. Probes and installs git, gh, node, vercel, firebase-tools, and gitleaks. Verifies .nvmrc, .gitignore, and Git Flow develop branch setup, and enforces the Secret Vault Policy.
-
eyesecurity Bundle Nis2 Gap AnalysisACTIVATE when the user asks about NIS2, Cyberbeveiligingswet (Cbw), NIS2 applicability, NIS2 gap analysis, or NIS2 compliance assessment. Interview-driven gap analysis with 5-level maturity scoring field-tested by security consultants.
Audited -
eyesecurity Bundle Incident ManagementACTIVATE when a security incident, data breach, outage, or suspicious event is reported, discussed, or detected. Guides structured incident documentation through the full lifecycle: detection → triage → response → notification → recovery → lessons learned. Ensures NIS2 24/72h/30d notification deadlines and GDPR 72h breach reporting are met. Also activate when the user asks about incident response procedures, or breach notification obligations.
-
eyesecurity Skill Risk Assessment WriterACTIVATE when the user asks to write, create, draft, or generate a risk assessment, risk entry, risk evaluation, or threat/vulnerability description — or when the user describes a threat, vulnerability, weakness, new business activity, or scenario they want risk-assessed. Covers information security, compliance, operational, vendor, HR, physical, and quality risks within the ISO 27001 framework. Produces a structured risk entry with Risk Evaluation + Risk Treatment tables, L/M/H scoring, and guided likelihood/impact questions.
-
eyesecurity Skill Security Compliance ToolsACTIVATE when the user asks about compliance tooling, risk assessment methods, critical assets (crown jewels), or how to assess their organisation's security posture for EU regulations (NIS2, GDPR, ISO 27001). Curated index of tools and methodologies that support EU compliance — not generic AppSec tooling.
-
knockoutez Skill Wigolo SearchLocal-first web search with ML reranking, multi-query arrays, domain scoping, phrase-exact match, time-range filters, country hints, depth tiers, and explainable evidence scoring. Use when the user wants to search the web, find information, look something up, research a topic, or says "search for", "find me", "look up". Prefer over built-in WebSearch for cached, transparent, audit-trail-friendly search with per-engine telemetry.
Audited -
schalkneethling Skill PerformanceOptimize web performance for faster loading and better user experience. Use when asked to "speed up my site", "optimize performance", "reduce load time", "fix slow loading", "improve page speed", or "performance audit".
Audited -
schalkneethling Skill Best PracticesApply modern web development best practices for security, compatibility, and code quality. Use when asked to "apply best practices", "security audit", "modernize code", "code quality review", or "check for vulnerabilities".
Audited -
aws-samples Bundle API Gateway Authorizer SecuritySecure Amazon API Gateway routes when a scanner reports missing authorization, choose Cognito/OIDC JWT or other business authorizers first, and use an always-allow Lambda authorizer only as an explicitly documented fallback for public routes.
-
lennney Skill Project Plan AuditUse when auditing TicketPilot project plans, modules, tests, OpenSpec changes, and phase status before continuing development.
-
lennney Skill Ticket Risk PolicyUse when implementing or reviewing risk assessment, human review routing, complaint handling, compensation handling, legal risk, privacy risk, or account security risk.
-
spencergoss Skill Code Review SessionUse after writing or modifying code, before committing or merging — to catch bugs, security issues, and quality problems. Trigger on: "review this code", "check my code", "look at what I wrote", "code review", finishing a feature or bug fix, after a tdd-workflow green phase, or before any git commit on non-trivial changes. NOT for design reviews, architecture discussions, or general issue checking — only for reviewing code changes (git diff).
Audited -
stevevitali Bundle Review PrReview someone else's GitHub PR as a Staff Engineer and post a high-precision review — mechanical grounding (CI, local verification), focused design + security passes, calibrated severity labels, inline comments with suggestion blocks. Use when asked to review a PR, give feedback on a PR, or act as a code reviewer.
Audited -
stevevitali Bundle Refresh Repo DocsAudit and sync a repo's human-facing documentation (README, docs/, CHANGELOG, CONTRIBUTING, examples) against the actual code — detect drift deterministically, fix stale claims, remove cruft, fill gaps, and verify every claim written. Use when docs are outdated, after major feature work, or on a periodic docs-hygiene pass.
Audited -
swih Skill Codestral ReviewReviews a code diff through Codestral with an auto-detected focus (correctness, performance, security, or api_design). Auto-fetches the diff via git diff if no argument is provided. Use when the user asks for code review, PR review, security audit of a diff, or critique of recent changes.
-
swih Skill Compliance Audit WorkflowRun a compliance audit Mistral Workflow, query mid-run findings via workflow_interact(action="query"), and signal approval or escalation decisions at checkpoints via workflow_interact(action="signal"). Use when the user wants to run a compliance audit (GDPR, SOC2, PCI-DSS, etc.) against a deployed Mistral Workflow.
-
aaronvanston Skill Convex ReviewComprehensive Convex code review checklist for production readiness. Use when auditing a Convex codebase before deployment, reviewing pull requests, or checking for security and performance issues in Convex functions.
Audited -
aaronvanston Skill Convex SecuritySecurity best practices for Convex functions including ConvexError handling, argument/return validation, authentication helpers, access control, rate limiting, and internal functions. Use when writing public queries/mutations/actions, implementing authentication, adding authorization checks, handling errors, or reviewing Convex functions for security.
-
adrigm06 Bundle Android Engineering SkillUse when working on Android/Kotlin projects — architecture decisions, Compose UI, build/Gradle, testing strategy, performance, security, code review, debugging, or release engineering. Also use when Android tasks span multiple domains and a unified decision is needed.
-
adrigm06 Bundle Android SecurityAndroid security engineering skill for threat-aware recommendations on secrets handling, secure storage, network hardening, Play Integrity, and release safeguards. Use this whenever security posture or sensitive data handling is in scope.
-
adrigm06 Bundle Android Code ReviewStructured Android code review skill with severity-based findings across architecture, correctness, maintainability, performance, and security. Use this for PR reviews and technical debt assessments.
-
agenkin Skill DoctorRun the TelemetryDeck CLI end-to-end health check (platform, config, secret store, auth, query round-trip).
-
ali-demirbas Skill Source VerifyUse when evidence records exist with verification_status pending and need to be checked before synthesis — either because the user asks to "verify these sources", "check if this quote actually supports the claim", "audit this evidence", or because the orchestrator has just finished a collection pass and is handing off to verification before synthesis. This is the mandatory station between any source skill and the synthesizer — no source skill's evidence reaches findings.jsonl without passing through here first. Do NOT use this to collect new evidence (that's the individual source skills) or to compute finding status (that's the deterministic validator, scripts/validate_run.py — this skill only resolves evidence-level verification_status).
-
anthropics Bundle Eval Audit And Sweep<!-- Copyright 2026 Anthropic PBC -->
-
assoumaaa Bundle Odoo PythonUse when writing or reviewing any Python in an Odoo module — models, computes, overrides, controllers, wizards. Carries PSAE review-derived principles for ORM correctness, performance, style, and security, plus references for exact patterns. Invoke before writing logic in models/, controllers/, or wizard/.
-
assoumaaa Bundle Odoo XML ConventionsUse when writing, reviewing, or migrating any .xml file in an Odoo module — views, actions, menus, security records, data files, QWeb templates. Holds Odoo's naming, formatting, inheritance, and cross-version syntax conventions. Invoke before adding records to views/, security/, data/, or report/ directories.
-
assoumaaa Bundle Odoo Module DevelopmentUse when designing or writing any Odoo module — new models, inherited models, views, security records, migrations, or demo data. Invoke before creating __manifest__.py or any file under a module directory.
-
asterinas Bundle Kverus Semantic AuditCompare original Rust source folders against migrated Verus code folders, identify executable-code differences that may change runtime semantics, and write per-file audit reports to an output folder. Use when checking whether Rust-to-Verus rewriting preserved executable behavior rather than merely verifying successfully.
Audited -
afaraha8403 Bundle Deep DeliberationRuns a checkpoint-gated decision process for consequential, forward-looking design choices. Use only when the user explicitly invokes deep-deliberation to compare approaches, challenge assumptions, and reach an evidence-grounded recommendation before implementation. Use dissect instead to audit an existing system or written plan.
-
26zl Bundle Secret HygieneNever write, echo, or commit secret values such as API keys, tokens, passwords, or private keys; reference them through environment variables or a secret manager, and report discovered secrets without reproducing the value. Use when writing code, tests, configuration, documentation, logs, or shell commands that touch credentials; do not use to weaken cryptographic material handling that the product itself must perform.
-
354685856-sn Skill Security Check安全与合规检查 - 检查代码是否符合安全规范
-
alexhagemeister Skill Audit GnaddRead-only GNADD alignment audit: load workflow principles, scrutinize context files for describe-vs-track violations, perform a shallow git/workflow check, and return a severity-grouped report with minimal proposed fixes. Nudges /new-issue-gnadd for remediation slices; never edits files or creates issues. Use when the user asks to audit GNADD alignment, review workflow hygiene, check project context files, or find describe-vs-track violations.
-
ap6pack Skill Web SurfaceProbe paths, endpoint scoring, email security analysis, vendor fingerprints, documentation leak hunting, and API endpoint references for authorized web-surface enumeration.
-
arielsmoliar Skill Pre Exec CheckSafety check before executing destructive or irreversible commands. Catches dangerous shell commands, risky git operations, secret exposure, and high-blast-radius actions before they run. Activates automatically when Claude is about to execute shell commands that match known risk patterns. Trigger phrases: "check before running", "is this command safe", "safety check", "pre-execution review".
-
clinical-quality-artifical-intelligence Skill Review FhirFHIR Implementation Guide and resource review — terminology, profiling, and compliance audit for UK NHS FHIR projects. Covers FHIR R4 conformance, UK SNOMED/dm+d/LOINC terminology binding, UKCore/CareConnect compatibility, nursing-specific profiling (NEWS2, Waterlow, ADPIE), and IG structure. Produces a scored compliance report.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include odoo-xml-conventions, dw-grain, live-dev-init. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.