Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
ezraapple Skill Outcome First WorkflowsUse when leading a larger implementation, investigation, audit, migration, or review that needs an observable end state, explicit scope, a stopping condition, bounded parallel work, or evidence matched to completion claims. Do not use for a small task with one obvious check.
-
fernandocelmer Skill Repo AuditUse this skill when the user asks to "audit repo", "analyze repository", "find bugs", "find gaps", "review codebase", "check code quality", or wants to analyze a repository for bugs, missing features, test coverage gaps, security issues and create GitHub issues for findings. Performs a deep technical audit and optionally opens GitHub issues for high-priority problems.
-
fernandocelmer Bundle Security AuditSecurity audit skill for repositories. Use when the user asks to 'audit security', 'pentest repo', 'find vulnerabilities', 'security review', 'check for exploits', 'OWASP check', or wants a comprehensive security analysis of a codebase. Covers OWASP Top 10, dependency vulnerabilities, secrets detection, auth/authz flaws, injection vectors, and infrastructure misconfigurations.
Audited -
fernandocelmer Skill Smart Review PrUse this skill when the user asks to "validar PR", "validate PR", "review PR", "revisar PR", "checar PR", "check PR", mentions a PR number to review/validate, or asks to review a pull request before merging. Performs a comprehensive PR review covering code quality, security, architecture, design patterns, CLAUDE.md compliance and historical context — posts inline comments directly on the PR.
-
freddie-ger Bundle Surgical ChangesScope contract before the edit, hunk-by-hunk diff audit after. Use for ANY change to existing code — implement, fix, refactor, add a feature, before a PR, or when asked 'why did you change that?'.
-
iggmasterdev Bundle Testing Quadrants MapperMap a feature, story, release, or system to the four Agile Testing Quadrants and produce a concrete test-coverage plan — what to test, who owns it, automated vs manual, when, and with which modern tools — that deliberately surfaces the test types teams forget (Quadrant 3 exploratory/UAT/usability and Quadrant 4 performance/security/reliability). Use this whenever someone asks what tests a feature needs, plans test coverage or a test strategy for a story or release, asks "am I missing any kinds of testing", wonders how to balance unit vs functional vs exploratory, or mentions the testing quadrants. Trigger even when the user only describes a feature and asks "how should I test this" — the quadrants are the right lens for a complete answer.
-
artemnovichkov Bundle Audit Xcode Security SettingsAudit and enable security-oriented Xcode build settings. Progressively enables compiler warnings, static analyzer checkers, and Enhanced Security features. Use when: user wants to secure their Xcode project, audit security settings, enable hardening, review security posture of build configuration, set up security-focused static analysis, enable static analysis, improve warning coverage, harden diagnostics, or catch more bugs at compile time in C/C++/Objective-C/Swift. SKIP: network security (TLS/ATS), code signing, privacy APIs.
Audited -
t0dorakis Bundle Code Review ExpertExpert code review of current git changes with a senior engineer lens. Detects SOLID violations, security risks, and proposes actionable improvements.
-
stunspot Bundle Verification Reviewer🔍 Audit release verdicts and test proof.
Audited -
hermeticormus Bundle Geo Platform OptimizerPlatform-specific AI search optimization — audit and optimize for Google AI Overviews, ChatGPT, Perplexity, Gemini, and Bing Copilot individually
-
poco-ai Bundle Idea EvaluatorEvaluates a preliminary research idea against a five-dimension framework (Higher, Faster, Stronger, Cheaper, Broader) plus idea-lifecycle and student-capability matching, paradigm-shift probing, and a fatal-flaws audit. Returns a reviewer-style verdict; non-STEM ideas route to substitute frameworks. Use when the user has a draft research idea and asks whether it is worth pursuing, asks to 'evaluate this idea', 'score this idea', 'assess feasibility', 'novelty check', 'is this a good research direction', or before committing to a paper scope.
-
docmancer Skill StatusInspect Docmancer tree, index, capture, and security health.
-
genlayerlabs Skill Branch ReviewReviews the current GenVM branch by fanning out three specialized review agents (spec, security, implementation). Use when asked to "review this branch", "review the PR", or do a full code review of a diff.
-
jongio Bundle Git TidyGit repository triage across branches, worktrees, stashes, remote refs, tags, remotes, artifacts, ignored-but-tracked files, large blobs, and maintenance. Correlates exact work for work-bearing carriers, runs protected read-only inventory for legacy scopes, reports coverage gaps, and recommends outcomes without treating age or names as proof. Analysis and revalidation are read-only; every refresh, save, cleanup, and GitHub write requires its own exact approval and established workflow. USE FOR: git-tidy, tidy repo, triage branches, audit worktrees, inspect stashes, stale branch review, repo hygiene, safe git cleanup. DO NOT USE FOR: history rewriting, repository deletion, automatic cleanup, or any mutation the user hasn't explicitly approved.
Audited -
ostin-pil Skill Knowledge AuditAudit the knowledge base for orphaned docs, stale docs, and unpromoted session learnings, and print a one-page health summary
-
panlm Bundle Awesome Skills DeepdiveDeep dive analysis of the awesome-openclaw-skills repository. Forks and clones the upstream repo, then systematically fetches every skill's SKILL.md source from GitHub, runs a 10-category security audit on each, and generates a Chinese README summary — all organized by category in a dedicated deepdive repo that syncs to GitHub. Dispatches parallel subagents per category for speed. Use when the user wants to: (1) analyze or audit skills from the awesome-openclaw-skills repo, (2) deep dive into a specific category of community skills, (3) fetch and review SKILL.md source for any ClawHub skill, (4) run security checks on community skills, (5) build a Chinese knowledge base of community skills. Triggers on keywords like "awesome skills", "deepdive skills", "audit community skills", "分析社区 skill", "审查 skill 安全性", "awesome openclaw".
Audited -
stempeck Skill Documentation UpdateAudits a documentation file line-by-line against the actual codebase, proving every factual claim with source file and line number citations. Produces a structured evidence table, applies corrections for inaccuracies, then verifies corrections are themselves accurate. Use when a user asks to review, audit, refresh, or update a documentation file, or says a doc is outdated.
-
academind Bundle Code ReviewComprehensive, read-only code review skill for analyzing entire codebases or explicitly mentioned files. Use when asked to review code for logic bugs, type errors, security issues, performance problems, regressions, maintainability risks, or other user-specified focus areas. Prioritize a thorough, evidence-based report with file references and never modify code while reviewing.
-
academind Skill Web SecurityEnforce web security and avoid security vulnerabilities. Use when handling user input, managing authentication/sessions, or other security-related tasks.
Audited -
blackplume233 Bundle Spec OptimizerReview and optimize project specs by finding omissions, redundancy, duplicate definitions, and cross-file conflicts, then drive a conflict-resolution workflow that asks the user one item at a time before applying edits. Use when users ask to audit spec quality, align contracts across modules, or clean documentation drift in .trellis/spec and related docs.
-
reason-healthcare Bundle Health DocsAudit and consolidate documentation for healthcare engineering systems. Supports two modes — analyze (coverage audit — writes only .health-docs/analysis.md) and document (consolidate existing docs + fill gaps). Detects applicable jurisdiction overlays and regulatory regimes from codebase signals, composes existing skills as subagents for deep-dimension analysis, and produces a structured handoff artifact consumed by document mode.
-
reason-healthcare Bundle Health Compliance ReviewAudit, validate, and enforce regulatory and security controls in healthcare codebases and delivery systems. Selects `us`, `eu`, or `us+eu` jurisdiction overlays from evidence, then delivers deterministic findings across regulatory compliance and security control areas.
Audited -
bosens-china Bundle File Line AuditAudit oversized source files in a repository. Apply repository .gitignore rules plus extra exclude patterns, filter candidate files with include glob patterns, count physical lines, and output only files at or above the threshold. Use this skill when the user asks to find long files, review file-length distribution, identify split/refactor candidates, or analyze technical debt.
-
bosens-china Bundle Publish NPM PackagesConfigure, audit, or migrate npm package publishing to current secure practices. Use when Codex needs to publish or prepare an npm package, fill npm Trusted Publisher settings, create a GitHub Actions/GitLab/CircleCI release workflow, adopt OIDC, replace npm tokens, publish organization-scoped public or private packages, or release multiple packages from a monorepo/npm workspaces repository.
-
open-gitagent Skill Code ReviewReviews code diffs and files for security vulnerabilities (OWASP Top 10), error handling, complexity, naming conventions, and performance issues. Use when the user asks to review a PR, pull request, diff, merge request, or code changes.
Audited -
the-vibe-company Bundle CompanionUse when managing local SKILL.md packages with Companion: validate, publish, update, resolve dependencies, declare secrets, environment variables, or hosted SQLite state tables, query skill state, install updates, audit skills, check workspace versions, or self-update this Companion skill through the Companion workspace API.
-
using-system Bundle Backend ConfigurationOwn the configured observability backend, in two sections invoked by name. Check: display the configured stack and the instance the runs will hit, prove the CLI connected, guide the user when it is not, and hand the preflight over to the mission. Switch: verify the target backend's CLI is installed (offer a guided install when missing), persist the switch via odd_config_set, persist the per-stack stack_config values the missions will need, then run Check for the proof. Stack-agnostic - the stack list and everything about a given stack come from the observability-cli-guides skill. Use before dispatching an observe, verify or bench mission, when the configured stack must be confirmed or the CLI's connection proven, when the user needs guidance to set their CLI up, and when the user asks to change the configured backend or to persist targeting values. Never installs silently, never authenticates on the user's behalf, never stores or echoes a secret.
-
ajstack22 Bundle Atlas FullFull 9-phase workflow for complex features, epics, and security-critical changes (2-4 hours)
Audited -
jrittelmeyer Bundle Harness Auditharness-audit
Audited -
asamassekou10 Skill Ship Safe HooksInstall ship-safe as real-time Claude Code hooks — blocks secrets and dangerous commands before they land on disk. Use when the user wants automatic security scanning on every file write or bash command.
Audited -
asamassekou10 Skill Ship Safe ScoreGet your project's security health score (0-100, A-F grade). Use when the user wants a quick security check or asks "is my code safe to ship?"
-
asamassekou10 Skill Ship Safe BaselineManage your security baseline — accept current findings as known debt, then only report new regressions on future scans. Use when the user wants to adopt security scanning incrementally or suppress existing findings.
-
autosendhq Bundle TransactionalBest practices for designing, writing, and sending transactional email. Always use this skill for transactional email tasks; a password reset or OTP landing in spam is a product failure, not just a deliverability problem, so these emails deserve special care. Use it for: OTP and 2FA emails, password reset flows, email verification, order confirmations, receipts, shipping notifications, account and security alerts, billing emails, subscription events, or any user-triggered notification. Also load it when asked to diagnose why a transactional email is going to spam, or when deciding whether to add promotional content to a system-triggered email.
-
aymericderbois Bundle Python Upgrade PackageMonte de version un ou plusieurs paquets Python d'un projet géré avec uv, en évaluant l'impact des changements cassants avant d'appliquer la montée. À utiliser quand l'utilisateur veut monter une dépendance Python, corriger une CVE remontée par uv audit, rafraîchir le lockfile, ou invoque /python-upgrade-package.
-
azadmotala Skill ReviewCode review for TenantFlow. Checks security, correctness, and quality. Focuses on tenant isolation, Stripe webhooks, and Clerk auth.
Audited -
bahadirkisbet Skill Blind ReviewUse when a major implementation is complete and per-task reviews have passed, before merging a multi-file feature or a finished plan — the final quality gate. Reviewers read the code independently and never see the implementer's account of the work; you pick which intent artifact they judge against — none (cold audit), the spec (compliance), or the plan (drift). Not for single-file fixes, docs-only changes, or behavior-preserving refactors.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include ship-safe-baseline, outcome-first-workflows, repo-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.