Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
theomonfort Skill Github SupportAnswer GitHub product, platform, security, billing, and Copilot questions using only public sources with exact URLs and quoted evidence. Use when a user needs a concise, customer-ready GitHub support answer that must be double-checked before stating any fact.
Audited -
tikhomirovv Bundle Website AI Discoverability AuditAudits a public website for search crawlability, structured data, sitemaps, robots.txt, optional llms.txt, and major AI crawler policies; produces an evidence-backed report and only applies vendor-confirmed remediation guidance. Use when the user wants an AI/search discoverability audit, llms.txt review, robots.txt for GPTBot/OAI-SearchBot/Claude/Perplexity, sitemap quality, or “make my site work well with AI search + Google/Bing”.
-
tokugero Skill Sdlc ReviewRead-only codebase review using parallel audit agents. Produces consolidated findings and exceptions in docs/.tmp/ without making any code changes.
-
twingate-solutions Bundle Twingate IdentityUse when the user asks about IdP integration, SCIM provisioning, security policies, device trust, groups, users, or access control in Twingate. Activate for: SAML, SCIM, Okta, Entra ID, Google Workspace, JumpCloud, OneLogin, Keycloak, device trust, device posture, MFA enforcement, groups, JIT access, ephemeral access, auto-lock, offboarding, deprovisioning, multi-IdP deployments, or security policy configuration. Also activate for identity automation tooling: automating device trust from an MDM or EDR inventory (Jamf, Kandji, Intune, CrowdStrike, SentinelOne, FleetDM, Automox, JumpCloud, Mosyle, Datto RMM), migrating group access between IdPs, self-service or Slack-based group access requests, and location-based group switching.
-
twingate-solutions Bundle Twingate TroubleshootUse when the user reports connectivity issues, access failures, DNS resolution problems, or any error with Twingate. Activate for: "can't connect", "not working", "resource not found", "access denied", DEAD connector, DNS not resolving, device-trust blocks, security policy issues, P2P failure, or any Twingate diagnostics. Also activate for symptom-shaped queries: exact client error text ("unknown network name", "too many open files", "setup wizard ended prematurely", "unable to join network"), OS-specific client bugs on Windows, macOS, Linux (Fedora, Ubuntu, NixOS), ChromeOS, or Android Auto; client crashes, freezes, or unresponsiveness; version-specific regressions (a specific build misbehaving); TAP/virtual network adapter issues; device posture, screen-lock, or disk-encryption failures; third-party AV/EDR/VPN/DNS-filtering conflicts (CrowdStrike, Zscaler, Elastic AV, Avast, consumer VPNs); packet capture, system reports, client/connector logs; and engaging or escalating to Twingate technical support.
-
varunk130 Skill Dependency AssessmentEvaluate whether to add, update, or remove a dependency based on maintenance, security, size, and licensing criteria.
-
waldronlab Skill Security Audit R PackagePerform comprehensive security audit of R/Bioconductor packages
-
onekeyhq Bundle Hardware Security ReviewPerform an explicit security review of hardware-wallet signing, derivation, wallet sessions, PIN/passphrase, unlock, secure channels, firmware updates, logging, dependencies, or sensitive-data boundaries.
-
open-edge-platform Skill SecurityOn-demand security review skill for Scenescape — code and configuration security guidance.
-
openshift Skill Review SkillsReview project AI skills for duplication, stale references, mistakes, and structural issues. Use when the user asks to review skills, audit skills, check for duplicate skills, or verify skill quality.
-
openshift Skill Review ReadmesReview all README.md files in the repo for typos, errors, and outdated information. Use when the user asks to review READMEs, check documentation accuracy, or audit docs.
-
pmndrs Bundle Diataxis DocsDesign, classify, write, audit, or restructure technical documentation with the Diátaxis framework. Use for tutorials, how-to guides, reference material, explanations, documentation maps, README routing, documentation audits, or requests to separate mixed-purpose docs. Do not apply it automatically to internal plans, ADRs, research logs, or specifications unless the user wants those artifacts organized as product documentation.
-
pnp Skill Permissions AuditorAudit PnP PowerShell permission attributes against the APIs a cmdlet actually calls and against its documentation. Use when a change adds or alters an API call or a RequiredApi* attribute, when a user reports a 401/403 or a consent problem, or to sweep a folder under src/Commands/ for wrong or over-declared permissions.
-
hereshecodes Skill Security ContextUse ALWAYS when writing any code. Sets the secure-by-default mindset for all development tasks.
-
hereshecodes Skill Security HeadersUse when configuring HTTP responses, middleware, or server settings
-
hereshecodes Skill Dependency SecurityUse when adding packages, updating dependencies, or reviewing lock files
-
hoangvantuan Skill Pk LintKiểm tra sức khoẻ hệ thống .cockpit/: link hỏng, registry lệch, file mồ côi, schema cũ. 3 mode: check (rà soát read-only), fix (sửa + rebuild index), evolve (nâng cấp schema). Dùng khi user nói 'lint', 'kiểm tra hệ thống', 'dọn dẹp cockpit', 'audit', 'rebuild index', hoặc nghi ngờ dữ liệu cockpit bị lệch.
-
nishilbhave Bundle CodeprobeWhole-codebase code quality audit system with 9 specialized sub-skills covering security, SOLID principles, architecture, error handling, performance, test quality, code smells, design patterns, and framework best practices. Produces a scored health dashboard (0-100 per category), severity-rated findings (P0-P3) with severity rationales, and copy-pasteable fix prompts; also does PR-style diff review vs a base branch. Strictly read-only — never modifies user code. Use when the user says "codeprobe", "audit", "full code review", "code health", "check my code", "security scan", "code smells", "SOLID check", or asks how healthy, risky, or maintainable a codebase is. (For reviewing just the working diff, the built-in /code-review may be more appropriate unless the user asks for codeprobe.)
Audited -
nishilbhave Skill Codeprobe TestingAudits code for test quality and coverage issues — missing tests, test smells, poor test structure, mock abuse, coverage gaps, and fragile test data. Identifies weaknesses in the test suite and generates fix prompts. Trigger phrases: "test quality", "test audit", "test review", "coverage check", "missing tests", "test quality audit".
-
nishilbhave Skill Codeprobe SecurityScans code for security vulnerabilities — injection flaws, authentication gaps, XSS vectors, mass assignment, CSRF, insecure deserialization, sensitive data exposure, broken access control, and misconfigurations. Generates severity-scored findings with copy-pasteable fix prompts. Trigger phrases: "security scan", "security audit", "vulnerability check", "find security issues".
Audited -
nishilbhave Skill Codeprobe Error HandlingScans code for error handling and resilience issues — swallowed exceptions, missing try/catch on external calls, unhandled promise rejections, missing transactions, validation gaps, retry/timeout omissions, and logging blind spots. Generates severity-scored findings with copy-pasteable fix prompts. Trigger phrases: "error handling check", "exception audit", "resilience check", "try/catch review", "error handling audit".
-
nobodyonlyc Bundle Masoi Perf SecurityAudit Ma Sói server and client for performance bottlenecks, memory leaks, security vulnerabilities, rate limiting, input validation, CORS policy, timer cleanup, and room zombie detection. Use when changing socket handlers, setTimeout/setInterval patterns, Redis/PostgreSQL queries, authentication, or deploying to production.
-
nobodyonlyc Bundle Masoi Rules AuditorAudit and update Ma Sói game rules, role balance, win conditions, night/day/vote resolution, and special-role edge cases in this repository. Use when changing server/gameEngine.js, server/index.js phase logic, role assignment, Witch/Doctor/Wolf/Hunter/Wolf King/Idiot behavior, or when reviewing gameplay balance.
-
o3co Skill Dpd DumpDump the full DPD graph as JSON (a strict subset of YAML; json.loads round-trippable) via export_yaml. Use for snapshots, audit, diffing, or copy-paste into docs.
-
odradekai Bundle Opi AuditRun a fresh-context, read-only conformance audit of one registered Phase and install its validated report into the live indexed assurance set.
-
odradekai Bundle Opi RealignAudit opi inward against an exact earendil-works/pi revision, covering current implementation and authority-scoped target-design horizons while preserving pi design lineage through Rust-native implementation choices.
-
odradekai Bundle Opi DocumentIndependently audit every maintained current-product README against shipped implementation by default, repair documentation drift, and keep English and Chinese counterparts synchronized. Use for full README truth audits, targeted README/doc refreshes, localized mirrors, or the documentation phase before a release.
-
odradekai Bundle Opi RemediatePlan or apply closure for every finding in the current live indexed Opi audit set, bound to its exact active index digest.
-
zhijunio Bundle Topic LearnLearn one topic end to end (学): scoped mission, layered sources, mastery map, verified evidence, canonical article, interview layer, learning records. Modes new or refresh. Use for 主题学习, 技术深挖, 溯源验证; not single-link summaries, blank-page article writing, or codebase audit.
Audited -
zhijunio Bundle Article WriteArticle and document writing lifecycle (写) — ideate, gather, transcribe, compose, refine with author voice. Long-form, tutorials, scripts, talks, Xiaohongshu. Default voice in voice-default.md. Use for 写文档, 写文章, 选题, 审校定稿, publish-ready; not neutral-only de-AI on finished text, URL ingestion, topic learning, or codebase audit.
-
zkeviny Bundle Webhook Token Security Zero Exposure EditionSecure webhook token management using MGC Blackbox. Supports DingTalk, WeCom, Feishu, Telegram, Slack and more. Store webhook tokens locally in encrypted form, retrieve at runtime without exposing to AI models.
-
justinedevs Bundle VetUse when the user wants a security and trust-boundary review of the current design before implementation or release.
-
primefoldtools Bundle Factguard ProAdaptive verification intelligence system for detecting AI hallucinations, misinformation, and manipulation across multiple threat vectors. Use when users request verification of claims, ask to check facts, analyze suspicious content, detect AI-generated misinformation, evaluate source credibility, or investigate potentially manipulated information. Triggers include phrases like "verify this", "check if this is true", "is this accurate", "fact-check", "detect hallucinations", "analyze this claim", or when content appears suspicious.
-
xrequillart Bundle Magic Auditmagic-slash - /audit
-
arjitj2 Skill Squash Merge Dependabot FixesSquash-merge already-assessed Dependabot PRs one by one, handling merge conflicts carefully, waiting for fresh CI after Dependabot rebases, checking security alerts, and recording the outcome.
-
eddieran Bundle Code ReviewerProduction-grade structural code review for correctness, security, performance, and release risk.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include github-support, website-ai-discoverability-audit, sdlc-review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.