Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
itsyasirkhandev Bundle FallowCodebase intelligence for JavaScript and TypeScript. Free static layer finds unused code (files, exports, types, dependencies), code duplication, circular dependencies, complexity hotspots, architecture boundary violations, and feature flag patterns. Optional paid runtime layer (Fallow Runtime) merges production execution data into the same health report for hot-path review, cold-path deletion confidence, and stale-flag evidence. 90 framework plugins, zero configuration, sub-second static analysis. Use when asked to analyze code health, find unused code, detect duplicates, check circular dependencies, audit complexity, check architecture boundaries, detect feature flags, clean up the codebase, auto-fix issues, merge runtime coverage, or run fallow.
-
agenvoy Bundle Code ReviewerAnalyze project source code and generate optimization suggestions. Use when user wants code review, performance optimization advice, security hardening recommendations, or architecture improvement suggestions.
Audited -
agenvoy Bundle Skill CreatorCreate, edit, improve, or audit AgentSkills. Use when creating a new skill from scratch or when asked to improve, review, audit, tidy up, or clean up an existing skill or SKILL.md file. Also use when editing or restructuring a skill directory.
-
ai4s-research Bundle Traceability ReviewUse when the user asks to review, verify, or audit a report, manuscript, or analysis in the workspace for traceability — resolving citations, flagging numbers with no source, and checking figures against the code that generated them. Emits a structured review block the app renders as reviewer findings. Verifies traceability, never "correctness".
Audited -
ainova-systems Bundle Intelligence Review ContextAudit rules, agents, and skills and propose behavior-preserving reductions
-
alexferrari88 Bundle High Efficiency Learning DesignUse this skill to design, audit, or troubleshoot high-efficiency learning for hierarchical skills, especially mathematics, technical subjects, tutoring flows, study plans, curricula, assessments, and adaptive learning systems. Activate when deciding what a learner should practice next, why they are stuck or forgetting, how much guidance, practice, or review to give, whether they are ready to advance, or how to structure worked examples, retrieval, spacing, interleaving, diagnostics, remediation, or learning incentives, even if the user never mentions learning science or Math Academy. Do not use merely to solve or explain subject-matter problems, discuss education casually, or optimize entertainment or superficial exposure.
-
canonical Bundle Ct Security ReviewSecurity code review for vulnerabilities. Use when asked to "security review", "find vulnerabilities", "check for security issues", "audit security", "OWASP review", or review code for injection, XSS, authentication, authorization, cryptography issues. Provides systematic review with confidence-based reporting.
Audited -
canonical Bundle Gha Security ReviewGitHub Actions security review for workflow exploitation vulnerabilities. Use when asked to "review GitHub Actions", "audit workflows", "check CI security", "GHA security", "workflow security review", or review .github/workflows/ for pwn requests, expression injection, credential theft, and supply chain attacks. Exploitation-focused with concrete PoC scenarios.
-
commonhuman-lab Skill Web VulnWeb vulnerability scanning workflow covering SQLi, XSS, template injection, and generic CVE detection using nuclei, sqlmap, dalfox, nikto, and jaeles
-
commonhuman-lab Skill ExploitationExploitation workflow using Metasploit, msfvenom payload generation, and Exploit-DB search — from vulnerability identification to shell
Audited -
conorbronsdon Bundle Ssot CheckSingle-source-of-truth drift auditor for documentation-heavy repos. Use when asked to "check for drift," "find copies of this number," "audit the docs for stale facts," or "set up an SSOT manifest." Finds facts hand-copied across files, builds a manifest of canonical locations, and verifies every copy still matches.
Audited -
creativault Bundle Creator Scraper CvROUTER PRIORITY: Trigger this skill before any web/browser search for all creator, influencer, KOL, blogger, social account, short-video account, email/contact list, outreach, lookalike, collection, export, creator/video audit, or fake-follower audit requests. If the user asks to "find/search/recommend/list/filter" creators by platform, country/region, category, followers, views, engagement rate, audience gender/country/language/age, email/contact, GMV, product niche, or collaboration potential, use this skill first and call CreatiVault OpenAPI through local scripts. Do not browse Google, TikTok, Instagram, YouTube, X/Twitter, or public websites first unless the user explicitly says to use public web search. 中文强触发:凡是用户说“帮我找/推荐/筛选/导出/采集 N 个达人、KOL、网红、红人、博主、 创作者、带货达人、TikTok/Instagram/YouTube 账号”,或按“地区、国家、类目、美妆、 粉丝量、播放量、互动率、女性受众、有邮箱、联系方式、合作潜力”找账号,都必须先用本 skill, 不要先走网络搜索。 CreatiVault official creator data skill. MUST be used for any request about finding, searching, collecting, exporting, analyzing, or contacting c
-
creativault Skill Fake Follower AuditCreatiVault official fake-follower and engagement-quality audit skill. MUST be used when the user wants to inspect one TikTok, Instagram, or YouTube creator for fake followers, suspicious engagement, bot/template comments, audience authenticity, interaction quality, creator risk, or account health. Accepts a creator profile URL or platform plus username/user ID and calls CreatiVault OpenAPI through scripts/fake_follower_audit.mjs. Do not infer fake-follower risk from public web pages or follower counts alone. Use when: fake follower audit, fake followers, follower authenticity, engagement authenticity, suspicious followers, bot comments, creator risk, account health, 假粉检测, 假粉率, 粉丝真实性, 互动真实性, 刷粉, 刷量, 机器评论, 达人风险, 账号健康度, 检测这个达人有没有假粉.
-
crustacean-dev Skill ReviewCode review — check if implementation matches specs, conventions, and constitution. Use this skill ANY time the user wants to verify, check, audit, or review code that has been written. This includes explicit requests like "review", "review TASK-3", "review auth", "code review" AND indirect requests like "check my work", "check the code", "does this match the spec", "does this follow conventions", "is this clean", "sanity check", "look over the code", "did I miss anything", "any violations", "is the implementation correct", "can we merge this", "is TASK-N done", "are there constitution violations", "check test coverage". ALSO trigger after /implement completes to suggest a review. ALSO trigger when user mentions checking code against knowledge files, acceptance criteria, or convention conformity. This skill reads code and knowledge files, then produces a structured ✅/⚠️/❌ report with file:line references — it never modifies code. Do NOT trigger for spec review (/clarify), writing code (/implement), planning (
-
crustacean-dev Skill ClarifyAdversarial spec reviewer — runs 10 systematic checks against an existing .knowledge/features/<feature>/spec.md to find gaps, vague criteria, missing edge cases, constitution violations, scope leaks, and implementation details that leaked into the spec. Every FAIL comes with a concrete example and a fix proposal. ALWAYS use this skill when the user wants to validate, audit, challenge, stress-test, or review a feature spec before planning or implementation — whether they say "clarify", "clarify <feature>", "review the spec", "is the spec complete", "what's missing", "find gaps", "challenge the spec", "stress test", "audit the spec", "are we missing anything", "check the spec", or any variant asking about spec quality, completeness, or readiness. Also trigger when the user is about to move from spec to plan and wants confidence the spec is tight. This skill reads and updates spec.md ONLY — it does not create new specs (use /spec), produce plans or architecture (use /plan), break down tasks (use /tasks), write c
-
goingli0324 Bundle Web Security Reviewer對使用者自己的程式碼做防禦性安全審查,輸出依嚴重度排序的風險報告與修正後程式碼。當使用者要找漏洞、加固、擔心被攻擊或個資外洩,或貼上一段 AI 生成的程式碼要人幫忙看安不安全時觸發。也是 agentic-dev-loop Verify 雙閘的安全閘,供其他 skill 呼叫。
-
goww7 Skill Halal VerdictUse when the user asks whether a specific stock is Shariah-compliant ("Is X halal?", "Screen TSLA", "Compliance of AAPL"). Produces a single-stock verdict across all 5 methodologies (AAOIFI, DJIM, FTSE, MSCI, S&P), explains any failures, and suggests a halal alternative if non-compliant. Does NOT cover ETFs (use halal-etf-analysis) or portfolios (use halal-portfolio-audit).
-
goww7 Skill Halal Portfolio AuditAudit an existing portfolio (list of holdings with weights or values) for Shariah compliance. Produces per-stock results, aggregate compliant %, purification owed, and remediation suggestions for non-compliant names. Does NOT build new portfolios (that's halal-portfolio-builder).
-
goww7 Skill Using Halal InvestingUse at the start of any Halal Terminal / Shariah investing session. Checks the user has an API key (runs setup inline if not), then routes to the right sub-skill (verdict / audit / builder / etf / zakat / methodologies / news-watch / watchlist), detects audience (retail / advisor / scholar), applies the non-fatwa disclaimer, and warns Free-plan users approaching quota.
-
huajiexiewenfeng Skill Conversation ReviewUse when the user asks for self-review, Dolores mode, conversation review, skill trace audit, failure analysis, eval gap detection, improvement-loop suggestions, failure case or golden case status, or skill feedback dashboard.
-
huifer Bundle Redis AuditRedis cost optimization expert. Analyzes memory usage, connection management, command patterns, hot keys, and provides optimization strategies. Trigger when user mentions Redis costs, memory optimization, or Redis audit.
Audited -
huifer Bundle Supabase AuditSupabase cost optimization and audit expert. Monitors database performance, storage, bandwidth, Edge Functions, Auth MAU, and provides optimization recommendations. Trigger when user mentions Supabase costs, database optimization, or Supabase audit.
Audited -
huifer Bundle Cloudflare AuditCloudflare platform cost optimization expert. Monitors Workers, D1, KV, R2 usage, identifies cost anomalies, and provides optimization recommendations. Trigger when user mentions Cloudflare costs, Workers optimization, or platform audit.
Audited -
facebook Skill App Health CheckRun a comprehensive health check on a Meta app — audits settings, security, compliance, app review status, rate limits, and API deprecations in one pass. Use when you want a full picture of an app's current state.
Audited -
facebook Skill Compliance CheckCheck compliance status for a Meta app — surfaces open required actions, active violations, and recommendations with remediation guidance. Use to audit compliance posture or resolve compliance blockers.
Audited -
fevra-dev Bundle Opsec ReviewRed-teams documents, code, READMEs, social posts, commit messages, and paste content for inadvertent operational security leakage before external exposure. Use when user says "review this before I post", "OPSEC check", "is this safe to share", "audit this README", "pre-flight check", "what does this reveal", "check before I push", or when preparing any artifact for public release, GitHub push, social media, client delivery, or external API submission. Distinct from PII redaction — focuses on what an adversary can INFER from context, metadata, structure, and timing signals, not just explicit identifiers.
-
fmanimashaun Skill Code ReviewReview doctrine for the class of defect authors are systematically blind to — code that is correct on its own terms but does not do what its own documentation, config, comments or project rules claim it does. Use this skill whenever reviewing a diff, a pull request, or a branch; before committing; when asked to check, audit, critique or sign off on changes; or when acting as a merge gate. Names the recurring defect classes (claims-vs-enforcement, dead-declaration, carve-out-without-negative-test, coverage-gap, doctrine-contradiction, unverified-negative, gate-that-cannot-fail) and how to detect each. Complements correctness review (authorization, scoping, query safety, tests); it does not replace it. Code QUALITY — duplication, redundant state, efficiency, a fix at the wrong level — is the separate, advisory `quality-pass` skill, which runs after this one.
-
fortify Bundle Fortify FodPerform tasks against Fortify on Demand (FoD): query applications/releases; query & triage existing security issues in FoD; start & monitor full SAST/DAST/SCA/open source scans of the codebase; create releases; import FPR/SARIF/CycloneDX artifacts; policy and portfolio analysis. NOT for lightweight AI review of local code changes/diffs (use fortify-change-review).
-
fortify Bundle Fortify SscPerform tasks against Fortify SSC (Software Security Center): query applications/application versions; query & triage existing security issues in SSC; start & monitor full ScanCentral SAST/DAST scans or upload FPR artifacts; create app versions; policy and portfolio analysis. NOT for lightweight AI review of local code changes/diffs (use fortify-change-review).
-
fortify Bundle Fortify RemediateRemediate SAST (static) and DAST (dynamic) security vulnerabilities ALREADY detected by Fortify in FoD or SSC — fix specific issues, categories, or reduce issue counts, including applying SAST Aviator fixes. For SCA / open source dependency findings (vulnerable third-party components, CVEs), use fortify-dependency-upgrade instead. NOT for discovering or reviewing new issues (use fortify-change-review for a local code-change review, or fortify-fod / fortify-ssc to scan and triage).
-
fortify Bundle Fortify Create AppCreate new Fortify application(s) in Fortify on Demand (FoD) or Application Security Center (SSC).
-
furqanistic Bundle Improve Backend CodeBackend code quality for clean, production-ready, maintainable code. Adapts to the existing language, framework, and style. Covers functions, reusability, modern syntax, error prevention, readability, and security awareness. Use when writing, reviewing, or refactoring backend code for quality, maintainability, or production readiness.
-
furqanistic Bundle Audit Backend SecurityBackend security review and hardening for authentication, authorization, tokens, sessions, secrets, validation, injection, payments, uploads, webhooks, data exposure, rate limits, and deployment configuration. Use when asked to audit, security-review, harden, threat-check, or inspect backend code for vulnerabilities across Express, NestJS, Django, Rails, Go, and other stacks.
-
genezo13 Bundle Monadvault Privacy SentinelAudit MonadVault material for privacy leakage, unsafe sharing, missing consent, excessive access, memory-scope mistakes, provider exposure, and publication risk. Use when a Steward asks whether something is safe to store, remember, send, export, disclose, or publish; requests redaction or a privacy review; or reviews Monad settings, Vault Memory, Share Capsules, public copy, prompts, capability permissions, third-party data, credentials, or sensitive personal information.
-
genezo13 Bundle Monadvault Capability PackagerCreate, audit, improve, or package repeated Steward workflows as focused MonadVault capabilities or Codex Skills. Use when a Steward asks to create a skill, convert a workflow into a capability, improve SKILL.md instructions or discoverability, write trigger descriptions, reduce overlap between skills, choose references/scripts/assets, define required scopes or install mode, add safety metadata and test prompts, or decide whether behavior belongs in a portable Skill or the MonadVault runtime.
-
gidila91 Skill Lovable Vibe Code AuditChecklist and workflow for spotting the visual/copy/structural tells that a Lovable-built site still looks "vibe-coded" — generic, unpolished, and obviously AI-generated — rather than like custom-built client work. Use before showing a Lovable project to a client, before a real launch/publish, or whenever asked to review a site for polish/professionalism.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include fallow, code-reviewer, skill-creator. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.