Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
bondar-artem Skill Pw Test AuditAudit a recently written Playwright test as a fresh pair of eyes. Reviews only the most recent uncommitted changes via git diff, checks compliance with the project's Playwright scripting rules, architecture, and POM conventions, and reports findings before optionally applying fixes.
-
calvyntwh Bundle Inversion ThinkingProactive failure analysis using the Saboteur Method. Use when designing critical systems, security features, or debugging root causes.
-
rommapp Skill Pr ReadyRun the pre-submit gauntlet (security-audit, code-review, simplify, review-polish) over a change before opening or merging a PR.
-
rundeck Skill Cve RemediationVerify if a CVE affects the project and remediate it. Checks dependencies, identifies vulnerable versions, suggests/applies fixes, and validates changes. Use when analyzing security vulnerabilities or responding to CVE reports.
-
sadiksaifi Bundle Snap ReviewReview a GitHub pull request in read-only mode for material bugs, regressions, missing tests, architecture drift, security/privacy risk, performance risk, and merge blockers. Use when the user wants a PR reviewed before merge or before posting feedback.
-
saewookkangboy Bundle Role Security EngineerEnsure the application is secure, compliant, and robust against attacks.
-
sap Skill Automation Pilot Command ReviewReview production commands, inputs, and catalogs for Automation Pilot. Validates file structure, naming conventions, security requirements, mandatory patterns, and best practices. Use when reviewing .command.json, .input.json, or .catalog.json files.
-
scholarly360 Bundle Insecure DesignDetect, analyze, and remediate OWASP A06:2025 Insecure Design vulnerabilities in Python web applications (FastAPI and Flask). Use this skill whenever the user asks about architecture-level security flaws, threat modeling, rate limiting gaps, business logic vulnerabilities, insecure file uploads, race conditions, tenant isolation failures, or client-side enforcement of server-side security. Trigger even if the user doesn't say "Insecure Design" explicitly — common signals include: "missing rate limiting", "file upload security", "business logic flaw", "race condition", "multi-tenant isolation", "threat modeling", "STRIDE", "design review", or "can users abuse this flow". Also trigger for code reviews or audits where architecture-level security controls are being evaluated, not just implementation bugs.
-
scholarly360 Bundle Broken Access ControlSecurity testing skill for A01:2025 Broken Access Control — the #1 OWASP risk for two consecutive cycles. Use this skill whenever the user asks about: access control vulnerabilities, IDOR (insecure direct object references), authorization bugs, SSRF testing, CORS misconfiguration, privilege escalation, JWT/session manipulation, CSRF protection, or auditing FastAPI/Flask endpoints for missing auth guards. Also trigger when the user says "test my API for access control", "check authorization", "find IDOR bugs", "review permissions", "audit my routes", or mentions CWE-284, CWE-285, CWE-352, CWE-639, CWE-862, or CWE-918.
-
scholarly360 Bundle Cryptographic FailuresDetect, audit, and remediate A04:2025 Cryptographic Failures in Python web applications (FastAPI and Flask). Use this skill whenever the user asks about crypto security, password hashing, JWT configuration, TLS/SSL verification, weak randomness, hardcoded secrets, or any code using hashlib, random, ssl, jwt, passlib, or cryptography modules. Also trigger when the user wants to audit security, scan for OWASP A04 issues, fix crypto bugs, or review authentication-related cryptographic code. If there's any chance a crypto weakness is involved — trigger this skill.
-
scholarly360 Skill Authentication FailuresUse this skill whenever you need to audit, test, or fix Authentication Failures (OWASP A07:2025) in Python web applications — especially FastAPI and Flask. Triggers include: any mention of JWT security, session management, brute force protection, credential stuffing, password policy, MFA enforcement, login rate limiting, session fixation, token validation, or auth-related error messages. Also trigger for requests to "check authentication", "audit login flows", "test auth security", "find auth bugs", or any task involving CWEs: CWE-287, CWE-307, CWE-384, CWE-521, CWE-798, CWE-613. Use proactively whenever the user shares auth-related code (routes, middleware, decorators, token handlers) even if they haven't explicitly mentioned security testing.
-
scholarly360 Bundle Security MisconfigurationDetect, audit, and remediate Security Misconfiguration vulnerabilities (OWASP A02:2025) in Python web applications — especially FastAPI and Flask. Use this skill whenever a user asks about: hardening a Python/FastAPI/Flask app, checking for debug mode leaks, missing security headers, exposed API docs, hardcoded secrets, insecure cookie flags, XXE vulnerabilities, or any OWASP A02 misconfiguration issue. Also trigger for tasks like "security audit", "pen test prep", "production checklist", "find misconfigs", or "harden my app". This skill covers static analysis patterns, runtime checks, tooling (Bandit, OWASP ZAP), and remediation code snippets for each sub-category of misconfiguration.
-
scholarly360 Skill Mishandling Exceptional ConditionsDetect, analyze, and remediate OWASP A10:2025 — Mishandling of Exceptional Conditions in Python web applications (FastAPI and Flask). Use this skill whenever the user asks about error handling security, exception management, fail-open vulnerabilities, stack trace exposure, uncaught exceptions, transaction rollback safety, or resource leaks in exception paths. Also trigger for any OWASP A10 audit, security code review involving try/except blocks, global exception handlers, or HTTP error responses that may leak sensitive information. If the user mentions CWE-209, CWE-248, CWE-636, CWE-703, CWE-754, or CWE-476 in a Python context, use this skill immediately.
Audited -
scholarly360 Bundle Security Logging Alerting FailuresUse this skill whenever auditing, reviewing, or testing Python web applications (FastAPI or Flask) for OWASP A09:2025 — Security Logging & Alerting Failures. Trigger this skill when the user mentions: logging security, audit trails, log injection, sensitive data in logs, alerting gaps, insufficient logging, SIEM integration, log monitoring, incident detection readiness, or any request to audit or fix logging/alerting in a Python backend. Also trigger when a user asks "are we logging the right things?", "how do I detect attacks?", or "what should we be alerting on?". Do NOT skip this skill just because the request sounds simple — log-related security issues are consistently underestimated and require systematic coverage across all five CWEs.
-
sec-link Skill Insider Threat AssessmentAssess possible insider risk from unusual access, downloads, privilege use, and policy violations. Maintain neutral language, minimize personal data, and recommend auditable investigative steps.
-
serkan-ozal Skill Performance AuditAnalyze web and backend performance using Web Vitals, network timing, and Node.js metrics. Use when the user asks about page performance, load times, Core Web Vitals (LCP, CLS, INP), slow pages, backend bottlenecks, or SEO performance factors.
-
shubham0704 Bundle Paper Discourse GraphAudit LaTeX papers as discourse graphs when paragraph flow, story continuity, readability, reader-state breadcrumbs, payoff chains, or figure/equation placement matter. Use when the user asks whether a section feels abrupt, wasteful, machine-generated, monotonous, hard to parse, or wants to zoom in/out across paragraphs before editing.
Audited -
sindev08 Skill Reactprinciples Audit RecipeAudit an existing cookbook recipe for accuracy against the real codebase. Internal maintainer skill.
-
skyvanguard Skill Security AuditorUse when the user wants to check system security posture, find misconfigurations, audit permissions, or verify hardening. Checks common security issues across platforms.
Audited -
ednahq Skill Brand Guide AuditEvaluates website branding consistency against LearnFlow's brand style guide
-
emmanuelrtm Skill Verify ClaimsRun (or re-run) Stage 4 only — the Claim Verifier: extract every claim from the draft, verify each against its declared evidence source (numerical ±5%, citation entailment, method-code alignment), refine failures, finalize the paper, and run the Chain-of-Evidence audit. Requires paper/draft.md.
-
emmanuelrtm Skill Evaluation ProtocolOfficial scoring and audit protocol for Parallel Explore-Exploit branches. Preloaded into the ideator, solver, evaluator, auditor, and ablation-analyst agents; defines eval.json, the audit checklist, and what counts as a specification violation.
-
jlugagne Skill Doc TestingAgach testing strategy: test contract pattern, mock structure, contract tests, testcontainers with postgres:17, security tests, QA seed data
-
foreturn Bundle Security Engineering威胁建模、身份会话、授权隔离、入口防护、秘密密码学、隐私、供应链、检测响应与漏洞处置。
-
gabrielfst30 Bundle NatspecGenerates NatSpec-style documentation comments for complex implementations in any language or framework. Use when the user wants to add, complete, or audit documentation comments. Works with TypeScript, JavaScript, Solidity, Python, Rust, Go, and any other language. Triggers on phrases like "natspec", "adicionar natspec", "documentar função", "documentar classe", "gerar docs", "comentários natspec", "missing docs", "document this", "add comments", "adicionar comentários", "documentar implementação", "generate natspec", "@notice", "@param", "@return", "@dev".
-
gabrielfst30 Skill System VerifierFull architectural audit of the codebase. Runs automated checks (type-check, lint) and launches parallel architecture-guardian agents per domain to verify code quality and pattern compliance across the entire project.
-
gabrielfst30 Bundle Route Security TesterTesta rotas de API e faz varredura de segurança (DAST leve) contra alvos autorizados. Use para testar rotas, route testing, exercitar endpoints via curl, mapear rotas de um backend (Express/Fastify/Nest, Flask/FastAPI/Django, Go, Spring, Rails, Laravel, .NET, actix-web e outros), rodar matriz de auth testing e access control, detectar vulnerabilidades — SQLi, NoSQLi, XSS, command injection, path traversal — via fuzzing e injection em nível de detecção, gerar coleções Insomnia/Postman v2.1/OpenAPI (swagger), e produzir relatório com achados de segurança e sugestões. Dispare quando o usuário mencionar: testar rotas, route testing, curl endpoints, DAST, fuzzing, injection, SQLi, XSS, auth testing, access control, insomnia, postman, openapi, swagger, vulnerabilidade, coleção de rotas, testar minha API, varredura de segurança, pentest da própria aplicação. Agnóstica de linguagem e framework: tudo específico do alvo é declarado em runtime.
-
geeksfino Skill Lw LintRun structural and content-health checks on wiki/, audit outputs/ for promotion candidates, save a durable lint report to outputs/, update wiki/log.md, and surface prioritized follow-up actions. Usage: /lw-lint
-
giovicordova Bundle VerifyAudits Claude's own output against the user's original request in the current session — did Claude do exactly what was asked, no more, no less? Checks requirements, styles, constraints, and flags scope creep (extras the user never asked for). Use when the user says "verify", "check your work", "did you follow my request", "audit this", "compliance check", or questions whether Claude improvised, missed something, or added unrequested features. This is specifically about holding Claude accountable to the user's brief — NOT for reviewing other people's code, checking external systems, debugging config files, running tests, or verifying things Claude didn't create.
Audited -
gitlabhq Skill Update DocsAudit and update documentation after code changes. Use when architecture, APIs, or behavior changed and docs may have drifted.
-
googlecloudplatform Bundle Persona SecurityAdopts the Security Expert (SEC) persona. Focuses on system hardening, vulnerability auditing, and the protection of sensitive credentials and data.
Audited -
haorantang97 Skill Scaffold Repo FilesUse this skill when the user needs to create the supporting files for a GitHub repository beyond the rule file itself and the README. This includes choosing and writing the LICENSE file, writing CONTRIBUTING.md with submission format and quality gates, creating .github/PULL_REQUEST_TEMPLATE.md, setting up the correct directory structure, and creating optional files like CHANGELOG.md and SECURITY.md. Trigger when the user says 'set up my repo files', 'what other files do I need', 'create a CONTRIBUTING file', 'scaffold the repo structure', 'set up the directory layout', or 'I have the skill and README, what's next'. Also trigger when the user is about to publish and asks what supporting files a proper repo should have. Do NOT trigger for writing the README itself (that is write-readme), for creating banner images (that is create-visual-assets), or for the git and GitHub operations (that is publish-to-github).
Audited -
hereshecodes Skill Xss CsrfUse when rendering user content, building forms, or handling POST requests
-
hereshecodes Skill API SecurityUse when building REST APIs, GraphQL endpoints, or webhooks
-
theanirudhkumar Bundle Stack AuditAudits the tools the user already pays for: what overlaps, what nobody has opened in ninety days, and what to cancel. Trigger when the user says "audit my subscriptions", "what are we paying for", "review our software spend", "what tools do we actually use", "SaaS audit", "stack audit", "what should I cancel", "are we paying for duplicates", or asks to review, clean up or rationalize a list of tools or subscriptions already in use. Builds an inventory table with cost, last use, overlap and a verdict per row, sorted worst first. Use before-you-install instead for a single new tool the user has not adopted yet; this one is for the tools already on the books.
-
theanirudhkumar Bundle Switch CostChecks what breaks before you leave a tool: what exports and in what format, what is lost outright, and what the move actually costs in hours. Trigger when the user says "what happens if I leave this tool", "what breaks if I switch", "should I switch from X to Y", "how locked in am I", "can I get my data out of", "before I cancel", "before I migrate off", or names two tools and asks about moving between them. Also trigger when a stack-audit verdict of cancel, or a before-you-install decision between two tools, needs the actual exit cost checked before anyone acts on it. Ends on a verdict: low switching cost, switching cost with conditions, or high switching cost, naming what makes it so. Use before-you-install for a tool not yet adopted, and stack-audit to decide whether a tool should be cancelled in the first place; this one is for what happens after that decision, on the way out.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include pw-test-audit, inversion-thinking, pr-ready. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.