Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
eddieran Bundle Dependency AuditorAudit npm, pip, cargo, and go dependencies for vulnerabilities, license risk, and stale versions.
-
erenisci Skill Auditacta:audit
-
home-assistant Skill Ha Android ReviewHome Assistant Android code review guidance. Use when reviewing changes or a diff for correctness, style, and convention adherence, or checking security requirements.
-
oriolrius Bundle Openapi FastifyComprehensive guide for OpenAPI documentation with Fastify using @fastify/swagger. This skill should be used when creating self-documenting REST APIs, generating OpenAPI 3.x specs from route schemas, integrating Swagger UI or Scalar API reference, implementing security definitions, or building Node-RED nodes that expose documented API endpoints. Covers code-first and design-first workflows.
-
oriolrius Bundle Security PracticesComprehensive security practices for Node.js and Node-RED applications. This skill should be used when implementing credential storage, certificate handling, TLS/SSL configuration, authentication mechanisms (SASL, OAuth, API keys), password field masking in UI, or file path validation.
-
knvpk Skill Pre Commit PythonThe standard .pre-commit-config.yaml used across this user's Python projects — ruff (lint + format), pre-commit-hooks sanity checks, bandit security scanning, and pyupgrade for py312. Use when creating or editing .pre-commit-config.yaml in a Python project, or reviewing one for consistency with this user's other projects.
-
pachca Skill Pachca SecurityPachca — журнал безопасности: отслеживание входов, действий пользователей, изменений сообщений и нарушений DLP. Требуется тариф «Корпорация». Используй этот скилл, когда пользователь хочет посмотреть события безопасности, журнал аудита, историю входов, подозрительную активность, узнать кто что делал, экспортировать логи безопасности или отслеживать нарушения DLP. НЕ для отправки сообщений или управления сотрудниками. Use when: журнал безопасности, аудит, события безопасности, кто заходил, история входов, подозрительная активность, DLP, экспорт логов, токены API. NOT for: отправить сообщение, управление сотрудниками.
-
jerrywu001 Skill Design ReviewDesigner's eye QA: finds visual inconsistency, spacing issues, hierarchy problems, AI slop patterns, and slow interactions — then fixes them. Iteratively fixes issues in source code, committing each fix atomically and re-verifying with before/after screenshots. For plan-mode design review (before implementation), use /plan-design-review. Use when asked to "audit the design", "visual QA", "check if it looks good", or "design polish". Proactively suggest when the user mentions visual inconsistencies or wants to polish the look of a live site.
-
sylla-bv Bundle Code UpkeepThis skill should be used when the user asks to "update docstrings", "audit docstrings", "fix docstrings", "add docstrings", "check docstrings", "Google-style docstrings", "add field descriptions", "update tests", "audit test coverage", "generate tests", "add tests", "fix tests", "write pytest tests", "check test coverage", "missing tests", "stale tests", "test this module", "add test cases", "bring code up to date", "code upkeep", "maintain code", or wants to audit and update Python docstrings or tests.
-
xrplf Bundle Code ReviewReview the current branch's diff against go-* anti-pattern rules and xrpl-standards specs. Spawns focused subagents per changed package, plus a single XRPL-domain reviewer when protocol files are touched, and synthesizes findings cross-cutting. Use when the user types /code-review, finishes a task and wants a self-review, or fetches a teammate's branch and wants to audit it before merging.
-
ceratops-code Bundle Ceratops Misunderstanding AuditFind and analyze user misunderstandings in N days of task history or one supplied exchange, preserve exact evidence and repeated clarification chains, and propose targeted communication or workflow changes. Use when the user requests a misunderstanding audit or diagnosis of why an answer was confusing; do not activate merely because the user asks What or requests an ordinary clarification.
Audited -
hermeticormus Bundle Geo ReportGenerate a professional, client-facing GEO report combining all audit results into a single deliverable with scores, findings, and prioritized actions
-
hermeticormus Skill Geo SchemaSchema.org structured data audit and generation optimized for AI discoverability — detect, validate, and generate JSON-LD markup
-
withqwerty Skill Nutmeg ComputeCalculate derived football metrics and models. Use when the user wants to compute xG, xGOT, PPDA, passing networks, expected threat, possession value, pressing intensity, or any derived football statistic from raw data.
-
writer Skill Cerebro Regression TestsAdd focused regression coverage for Cerebro review findings, bugs, and security edge cases.
-
wukongnotnull Skill Quality ReviewReview code for bugs, security, and performance
-
xjsongphy Bundle WriterRoute the creation, revision, audit, or explanation of academic and technical documents. Use for reports, experiment reports, paper or repository explanations, textbook material, and their Markdown, LaTeX, or Typst source; compose one primary type with optional lenses, source objects, domains, format, and format integrations.
-
ymd38 Skill Yds Report To IssuesParses reports generated by the yds-software-evaluation or yds-vulnerability-scan skills and interactively registers selected tasks as GitHub Issues using the `gh` CLI. Use when the user wants to convert an evaluation report (docs/evaluation/*.md) or security audit report (docs/security-audit/*.md) into GitHub Issues. Triggers on requests like "create issues from report", "register tasks to GitHub", "convert report to issues", or when pointing at a specific report file.
-
ysskrishna Skill Creative ThinkingUse this skill when the user asks for creative thinking (including naming it or directing use/apply/run with obvious misspellings; decisive) or wants divergent ideation—fluency, flexible perspectives, novel combinations, and elaboration, with optional light convergence. Use when they want fresh ideas, blue-sky options, reframes, or more variety before committing, including casual or messy prompts. Skip when they want a single delivered answer with no exploration, audit-only teardown with no generation asked for, or purely mechanical execution.
Audited -
ysskrishna Skill Critical ThinkingUse this skill when the user asks for critical thinking (including naming it or directing use/apply/run with obvious misspellings; decisive) or wants to evaluate a claim, argument, plan, or belief: clarify assertions, weigh evidence, surface assumptions, test reasoning for gaps or fallacies, scan biases, consider alternatives, and stress-test conclusions—whether they phrase it plainly ("red team", "devil's advocate", "what am I missing", steel/straw man, bias scan) or indirectly (decision-quality review, epistemic calibration). Skip for execution-only tasks with no evaluative angle, or when they only want wording, tone, layout, or open-ended brainstorming with no request to audit reasons, assumptions, or evidence.
Audited -
qingye-lab Bundle Mobile Architecture AuditSpecialized architecture audit for mobile applications, especially iOS and SwiftUI. Use when assessing local persistence, offline behavior, synchronization and conflicts, migrations, background execution, notifications, networking and caches, state ownership, privacy permissions, battery efficiency, or excessive client-side business logic. Extends rather than replaces the general project architecture audit.
-
qingye-lab Bundle Project Architecture AuditEvidence-backed, persistent architecture audit and profile setup for one repository. Use when initializing `.architecture`, onboarding to a codebase, reviewing architecture health, preparing a refactor, investigating structural debt, or assessing module boundaries, ownership, contracts, resilience, security, observability, tests, deployment, and over-design. Automatically initializes missing project governance unless the user explicitly requests read-only work. Produces candidate findings for independent verification, not confirmed conclusions, fixes, or remediation plans.
-
qingye-lab Bundle Architecture Knowledge CuratorMaintains the plugin's architecture quality models, styles, patterns, technology profiles, reference architectures, migration guides, domain guidance, decision rules, machine rule packs, and evidence-provider registry. Use when adding or refreshing architecture knowledge, checking official-source freshness, reviewing framework capability claims, resolving duplicate or contradictory entries, or preparing a release whose decision knowledge may be stale. Does not audit a product or choose a product architecture.
-
quick-brown-foxxx Skill Writing Python CodeALWAYS LOAD THIS SKILL WHEN WRITING OR EDITING PYTHON CODE. Do not write or modify Python files directly — use this skill first. Core Python standards: basedpyright strict typing, Result-based error handling, async patterns, security, code style.
Audited -
riggyz Bundle Brain ConsolidateAudit, lint, migrate, deduplicate, repair, archive, forget, or delete the configured brain. Use for explicit vault cleanup/doctor requests and clear structural debt. Audit is read-only by default; repairs are planned and destructive or semantic-loss actions require confirmation. Do not use for ordinary capture, targeted recall, generic code consolidation, semantic pattern promotion, or onboarding.
-
lyston11 Bundle Nature ResponseDraft, audit, or revise Nature-style revision correspondence packages: point-by-point reviewer response letters, rebuttal letters, revision cover letters, LaTeX cover/response templates, and red-marked revised-manuscript excerpts. Use for reviewer comments, editor decision letters, pasted editorial emails, response drafts, cover letters, response to reviewers, rebuttal, 修回信, 返修邮件, 编辑邮件, 返修 cover letter, 审稿意见回复, 逐点回复, 大修回复, 小修回复, 回复审稿人, 修改稿回复, 写rebuttal, 回应审稿意见, 标红修改, or LaTeX 模板.
-
deonmenezes Skill Canary Tripwire ResponseWhat to do if a mantis_canary decoy tool ever shows up as tempting or gets called -- treat it as a security incident, not a normal tool result
-
chrisgagne Skill Audit AttributionAudit attribution
-
khaoss85 Skill Debug Crm RunDiagnose a failed or unexpected Accordo workflow using run traces, audit events and module state. Use when a workflow, API operation, provider call or approval transition behaves incorrectly. Do not use for building something new — a stated objective is solve-business-goal, one lifecycle step is create-crm-workflow, a single custom object is create-crm-module — or for a pre-merge review (adversarial-review).
-
khaoss85 Skill Create Crm WorkflowImplement a deterministic cross-module CRM process with policy, trace, audit and optional human approval. Use for stage transitions, follow-ups, onboarding, renewals and approval rules. Do not use for a stated business objective ("we need to manage renewals") — that is solve-business-goal, which discovers what exists first and may call this skill itself; nor for a single custom object (create-crm-module), a named milestone (the build-* skills) or a failing run (debug-crm-run).
-
2233admin Bundle EvolutionGoal-contract, capability graph, TraceCard, and promotion-gate control plane for self-evolving reverse/security skill routing. Use before macro-routing when the task needs end-to-end completion, route repair, or reusable learning.
-
liauw-media Bundle Fix ReviewVerifies that git commits address security audit findings without introducing bugs. This skill should be used when the user asks to "verify these commits fix the audit findings", "check if TOB-XXX was addressed", "review the fix branch", "validate remediation commits", "did these changes address the security report", "post-audit remediation review", "compare fix commits to audit report", or when reviewing commits against security audit reports.
-
18816132863 Bundle Envguard Secret Credential ScannerScan repos and workspaces for leaked secrets. API keys in code, passwords in configs, tokens in logs. Catches them before they hit git.
-
nitrocloudofficial Skill Nitrostack Auth SecurityBest practices for implementing JWT, API Keys, OAuth 2.1, and RBAC in a NitroStack application.
-
6uclz1 Bundle Pro Reasoning Research OutputHigh precision workflow for complex analysis, current information, web research, citations, source verification, uncertainty handling, security analysis, implementation planning, comparative evaluation, decision support, and evidence-grounded output construction.
Audited -
antonioblago Skill Peec CheckupRead-only health check for an existing Peec AI project. In one pass produces (1) a setup-quality audit (red flags from the structural setup — wrong competitors, funnel gaps, taxonomy issues), (2) a brand-performance snapshot (visibility per stage / engine, hero prompts winning vs losing, source diversity, competitor delta), and (3) a priority-ranked list of 5–8 concrete improvements drawn from Peec's get_actions + URL gap data. Works from day 1 of Peec data — no 4-week history needed. Never writes to Peec or to setup_state.json. Use when the user asks "Wo stehe ich?", "Wie ist mein Status?", "Was sind die Verbesserungspotenziale?", "Mein Setup checken", or runs /peec-checkup.
Audited
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include cerebro-regression-tests, peec-checkup, dependency-auditor. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.