Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
bigdra50 Skill Unity Sharedunity-cli 共通ルール。全 unity-* スキルが自動ロードする前提条件。Use as prerequisite for any unity-* skill (verification sequence, fallback order, security policy).
Audited -
bradmccloskey Skill Cisco Security AuditGenerate Python scripts that audit Cisco device security posture. Use when the user wants to check security hardening, compliance, ACL review, or vulnerability assessment of Cisco devices.
-
trollnhard Skill TruthfinderAlways-active web search safety skill. Classifies every website into SAFE, CAUTION, RISKY, or BLOCKED before reading or citing it. Reads and evaluates real user reviews and feedback to surface genuine sentiment. Detects fake, paid, or astroturfed reviews. Filters misinformation, malware, phishing, and data-harvesting sites. Never visits or relays content from dangerous sources. Protects the user's personal data and software from any site that could steal or exploit it.
Audited -
trollnhard Bundle Sentinel ArchitectDirectory-aware meta-skill. Maintains the integrity and efficiency of the entire skill society. On activation, runs scripts/crawler.py to map every SKILL.md under the project (loose files + .skill/.zip archives), then audits each skill against the 2026 efficiency standard in standards.md. Refactors skills whose projected efficiency gain is greater than 15 percent, merges duplicate/overlapping skills, and flags stale or malformed frontmatter. Trigger on: skill development, file uploads into skills directory, directory changes, or explicit "audit skills / refactor skills / merge skills" requests.
Audited -
takuan-osho Skill ReportCreate Investigation/Analysis Report. This skill should be used when summarizing investigation or analysis work into a structured GitHub Flavored Markdown report. Use it after completing research, debugging, security audits, or other analytical tasks.
-
takuan-osho Skill InterviewConduct iterative interviews to clarify scope, surface constraints, and reach a "do / don't do / done" agreement before starting non-trivial work. Use when receiving an ambiguous request, a vague task description, or before entering plan mode for any non-trivial implementation. Skip for one-line concrete fixes ("rename foo to bar"), single-fact questions, or when scope, constraints, and acceptance criteria are already specified. Supports requirements definition, debugging investigation, architecture review, security review, documentation creation, and general exploration.
-
thaildhe172591 Skill Pythia SpecUse when the developer asks to build or change something and the request leaves real decisions open - a new feature or flow ("build X", "lam luong Y", "them chuc nang Z"), a behaviour with more than one reasonable shape, a security or audit trade-off, or scope that could be read two ways. The request arrives as plain words, not a command - this skill fires on the words. Surface those decisions as questions with options and trade-offs, get them settled, and only then move to impact and write. Also use the moment you catch yourself choosing a business behaviour mid-implementation that the developer never stated.
-
lion-1209 Skill Wiki LintHealth check the Obsidian wiki vault. Finds orphan pages, dead wikilinks, stale claims, missing cross-references, frontmatter gaps, and empty sections. Creates or updates Dataview dashboards. Generates canvas maps. Triggers on: "lint", "health check", "clean up wiki", "check the wiki", "wiki maintenance", "find orphans", "wiki audit".
-
macareuxdigital Skill Concrete Cms SecurityApply this skill whenever you are writing, reviewing, or modifying PHP code for Concrete CMS (concrete5) — custom blocks, packages, single pages, dashboard or dialog or backend controllers, REST endpoints, Express entities, themes, attribute types, jobs, or anything in concrete/controllers, concrete/blocks, controllers/, blocks/, packages/, src/. Use it even when the user does not say "security" — for example, adding a new endpoint, accepting a POST parameter, rendering a user-supplied string, unserializing block config, fetching a URL server-side, or handling a file upload. Concrete CMS shipped 90+ CVEs over the past four years and the failure modes repeat — admin strings rendered raw, missing CSRF tokens on state-changing GETs, unserialize() on stored data, file uploads validated after writing, sequential IDs without per-object authz, type-juggling guard bypasses, OAuth handlers that skip account-state checks. This skill encodes the patterns behind those CVEs so you do not reproduce them.
-
proportione Skill Check SecuritySkill: Check Security
-
stallin-sanamandra Skill Bdr Enablement GeneratorGenerates account research briefs, personalized outreach sequences, persona-specific talk tracks, and objection handling frameworks for B2B SaaS BDR teams. Use when preparing BDR outreach for target accounts, building prospecting sequences, creating call scripts, developing objection responses, onboarding new BDRs, or reviewing outreach performance. Also use when asked to "write outreach emails," "build a prospecting sequence," "create a call script," "handle objections," or "research an account for outreach." Designed for BDR teams selling compliance, security, and GRC platforms to mid-market and enterprise buyers with multi-persona buying committees.
-
stallin-sanamandra Skill Account Research Brief GeneratorGenerates sourced, BDR-ready account research briefs for named target accounts in B2B SaaS ABM and outbound motions. Use after a target account list is built and before outreach sequences are written. Best for Tier 1, Tier 2, and intent-qualified accounts where BDRs need a clear "why this account, why now, why this persona" hypothesis. Designed for B2B SaaS teams selling compliance, security, GRC, risk, or other technical platforms into mid-market and enterprise buyers. Not intended for broad list building or mass enrichment.
-
troyanovsky Skill Simple SimplifyAudit a recent implementation diff for unnecessary complexity and propose behavior-preserving simplifications without changing code. Use after simple-implement or simple-run when the user asks to simplify, reduce complexity, remove overengineering, or review generated code for a smaller and clearer solution.
-
danielkerridge Bundle Code ReviewDeep code audit that finds dead wiring, silent failures, unfinished features, placeholder stubs, bloated files, and unnecessary complexity. Produces an actionable report with file:line references grouped by severity. Think of it as a senior dev doing a thorough PR review of the entire codebase. Triggers on: "code review", "audit the code", "review the code", "find dead code", "find placeholders", "check for stubs", "prune the code", "code cleanup", "implementation review", "completeness check", "find unused code".
-
danielkerridge Bundle Dataverse Web APIUse when programmatically creating, modifying, or querying Dataverse schema and metadata via the Web API (OData v4.0). Covers table/column/relationship definitions, solution ALM, form and view XML construction, app module composition, global option sets, business rules, Custom API registration, and publishing. Triggers on: "dataverse api", "dataverse metadata", "entitydefinitions", "web api schema", "create dataverse table", "create dataverse column", "fetchxml", "formxml", "layoutxml", "dataverse solution", "dataverse relationship", "odata dataverse", "metadata api", "publish customizations", "dataverse alm", "grid control", "editable grid", "business rule", "rich text", "auto-number", "file column", "image column", "pcf control", "security role", "column security", "environment variable", "custom api", "data migration", "solution import".
-
dansnow Skill Spectra AuditAudit changed code for security sharp edges — dangerous defaults, type confusion, and silent failures
Audited -
datadog Skill Code ReviewComprehensive code review covering security, correctness, bash compatibility, test coverage, and code quality. Use for PRs, commits, or any code changes.
Audited -
dennisonbertram Skill Machine Security CheckThis skill should be used when the user asks to "check machine security", "run a security audit", "is my mac secure", "scan my machine", "audit my mac", or mentions SIP, Gatekeeper, FileVault, firewall, login items, launch agents, SSH keys, or authorized_keys. Performs a read-only macOS security posture audit and writes a structured JSON result to ~/.mac-guardian/data/.
-
desertcache Skill Audit InstructionsSelf-review: finds stale, missing, redundant, or conflicting rules across all config files. Use when the user says "audit instructions", "check rules", or "/audit-instructions". Reads CLAUDE.md, MEMORY.md, error-patterns.md, BRAIN.md, all skill files, and settings.json to produce a categorized report with suggested fixes.
-
dranshrad Bundle Paid CastGroundledger paid-media skill with SAFE defaults (Snapshot → Advise → Fence → Experiment). Observe-only unless MutationLatch opens. Modes: audit, plan, math, brand, budget, trial, attrib, landing, creative, pace, optimize-draft. Use for Google/Meta/LinkedIn/Microsoft-style account reviews, unit economics, brand safety lattices, experiment decks, and draft change packs — not live spend edits without explicit approval. Claude Code, Cursor, Cowork.
-
eclipse-che Skill Fix Cve DepUpgrade a vulnerable npm dependency end-to-end — version bump, resolutions pin, yarn install, license regeneration, and commit. Invoke for any CVE, security advisory, or dependency vulnerability ticket (Jira CRW-*, GHSA-*, or a user request to "fix the X vulnerability" or "upgrade Y for security"). Handles ClearlyDefined indexing checks, .deps/ file updates, and produces a properly formatted commit automatically.
-
eclipse-che Skill Manage ResolutionsAudit and clean up the resolutions field in package.json — find orphaned pins, verify which are still needed, and safely remove stale ones. Invoke when asked to "check resolutions", "remove stale pins", "clean up package.json resolutions", or after a CVE fix adds a new resolution override that needs validation.
Audited -
elizaos Bundle Review Eliza ContributionsIndependently evaluate an elizaOS/eliza implementation, real-system verification, diagnosis, evidence artifact, or substantive review for quality, security, duplication, provenance, and contribution credit. Use in project CI or maintainer review before accepting work or changing a public reward allocation; reject unit-only or mock-only proof.
-
elizaos Bundle Review Delta Star ContributionsIndependently evaluate a SlopDotCash/proximityprize Delta Star implementation, Lean proof, test, refutation, diagnosis, or evidence artifact for correctness, security, duplication, provenance, and contribution credit. Use in project CI or maintainer review before publishing a Proximity Prize contribution share.
-
eroveda Skill Generate Testing StrategyGenerates TESTING_STRATEGY.md — a consolidated testing strategy document that aggregates the acceptance criteria from all executable specs into a global testing approach (unit, integration, E2E, load, security). Use this skill AFTER swebok-generate-spec has produced 03-SPECS.yaml (or the specs/ directory). ## When to invoke this skill - After all specs have been generated - When the user asks for a "testing strategy", "QA plan", "test plan", or "TESTING_STRATEGY.md" - When planning the testing phase of a project ## When NOT to invoke - Before specs exist - For projects without acceptance criteria defined
-
n24q02m Skill Impact AuditBlast radius of a change you have not made yet -- traces a symbol across federated repositories, splits impact per repo, and reports what must ship together.
-
n24q02m Skill Security SweepGraph-driven security sweep -- scan for dangerous sinks, then rank each finding by whether an entry point can actually reach it, and triage the rest into suppressions.
-
corvo007 Bundle Electron DevElectron main process and IPC development guidelines for Gemini-Subtitle-Pro. Use when working with IPC handlers, preload scripts, native integrations (ffmpeg, whisper, yt-dlp), file system operations, and desktop-specific features. Covers security requirements, IPC patterns, and cross-process communication.
-
45ck Skill Security Test Checklist Buildersecurity-test-checklist-builder
-
soham407 Bundle Shannon SecurityUse when running or evaluating white-box security testing for web applications and APIs with Shannon Lite or Shannon Pro.
-
noartem Skill Laravel Dependencies Trim PackagesRemove unneeded Composer packages and assets to improve boot time, memory, and security surface
-
vigolium Skill Audit AuthAudit authentication and session-management code for common issues — weak JWT config, session fixation, password-handling flaws, insecure cookies, broken OAuth flows, and missing auth checks on routes. Use when the user asks to review auth code or when source-aware scanning targets login/session/token handling.
Audited -
vigolium Skill Idor Blast RadiusWhen you find an Insecure Direct Object Reference (a URL/body/header parameter that lets you read or write another user's or another tenant's object), discover the ID space, prove the access is unauthorized, quantify the blast radius (how many records reachable, what data class, read vs write, same-tenant vs cross-tenant), and persist a finding sized by real impact rather than by the existence of the flaw. Use when an ID parameter (numeric, UUID, hash, slug, or an indirect ref in a header/cookie) changes the response across IDs, when CWE-639/CWE-284/BOLA was flagged, or when an audit finding hints at object-level access control gaps.
-
vigolium Skill Escalate Auth BypassTurn a suspected or confirmed authentication/authorization bypass into impact — admin access, session takeover, privilege escalation, or cross-tenant read. Use when you find a missing auth check on a route, a weak JWT verifier, a session cookie that's predictable or reusable across users, a privilege field client-controllable, or an audit finding tagged CWE-287/CWE-863/CWE-639. Walks from probe to admin-equivalent capability and persists a finding with the highest-impact action you reached.
-
vigolium Skill Command Injection RceTurn suspected OS command injection (a parameter that lands in a shell or a child process) into proof of remote code execution via an OAST callback, plus one safe demonstration of follow-on impact (read a file, list users, env dump). Use when a parameter feeds an exec/spawn/system call, when payloads with $(), `` ` ``, `;`, `|`, `&&` cause response differences, or when audit flags CWE-78 / CWE-77. Never sends destructive commands.
Audited -
dgalarza Bundle Aso AuditWhen the user wants to audit or optimize an App Store or Google Play listing. Also use when the user mentions 'ASO audit,' 'app store optimization,' 'optimize my app listing,' 'improve app visibility,' 'app store ranking,' 'audit my listing,' 'why aren't people downloading my app,' 'improve my app conversion,' 'keyword optimization for app,' or 'compare my app to competitors.' Use when the user shares an App Store or Google Play URL and wants to improve it.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include fix-cve-dep, sentinel-architect, unity-shared. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.