Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
bex-co Bundle Merge Upstream MainMerge the public openai/codex-security main branch into this fork's main branch and push the result to the fork remote. Use when asked to sync or merge upstream main for this repository.
-
bex-co Bundle Verify FixUse when the user asks whether an existing security fix, patch, finding, or completed issue actually remediates the original vulnerability without modifying the repository. Do not use to validate candidate findings, implement patches, or run full repository scans.
-
bex-co Bundle Deep Security ScanUse when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide or scoped-path Codex Security scan. Run repeated complete independent Standard scans with the Codex Security deep-scan tool, which aggregates their validated findings and prepares the canonical artifacts; then complete the same scan once. Do not use for PRs, commits, branch diffs, or working-tree diffs.
-
photonics-dhl Skill Repo MapUse when entering the repo for the first time, running a read-only codebase audit (Phase 0), or needing a directory/dependency/service/data map. Do NOT use for editing code or refactoring — this skill is strictly read-only.
-
photonics-dhl Skill Security ReviewUse when reviewing code that touches auth, permissions, uploads, secrets, sandbox execution, logging, or before any public release. Do NOT use for purely cosmetic or docs-only changes.
-
opencnid Bundle Judge CompositionCompose a differently blinded panel for grounding, coherence, independent corroboration, and audit of a claim, belief, record entry, or artifact. Use when asked to judge, vet, adjudicate, promote, reconcile, or impartially evaluate a self-authored claim; when a judge panel or promotion candidate is mentioned; or when authorship and expected verdict must stay out of evaluator prompts. Requires cold DSH subagents for blinded seats.
-
higangssh Bundle Yocto Doc RouterRelease-aware official documentation routing for Yocto Project, OpenEmbedded, and BitBake questions. Use when the user asks where to find current Yocto docs, when a Yocto answer may depend on release/branch, or before giving precise guidance about variables, classes, tasks, QA errors, migration, BSP, kernel, SDK, security, SBOM, CVE, or build setup.
-
higangssh Bundle Yocto Security SbomReview and debug Yocto license metadata, LIC_FILES_CHKSUM, LICENSE_FLAGS, incompatible licenses, license manifests, SPDX/SBOM generation, CVE checking, archiver/copyleft source compliance, and security policy. Use for compliance, CVE, SBOM, license, commercial license, source archiving, or security review questions.
-
jmailly Skill PHP Deprecations AuditAudit and fix deprecated Drupal/PHP APIs in custom code before a major Drupal core bump, on a Dockerized Makefile-driven project. Use when the user mentions upgrade_status, drupal-rector, phpstan deprecation detection, "removed in D11" (or the next major) APIs, implicitly-nullable PHP 8.4 parameters, or fixing custom-code deprecations before bumping core. Runs upgrade_status + rector + phpstan, applies automatic + manual fixes, loops until 0 errors. IMPORTANT: all commands MUST go through Makefile targets; run this WHILE core is still on the OLD major, never after the bump.
-
jinplu Bundle Teamwork ReviewUse when the user asks to review, audit, critique, or validate a stable code, document, plan, artifact, or claim; do not use to diagnose an unknown failure or create the initial candidate.
-
novacode37 Bundle Cors AuditorAudit a site's Cross-Origin Resource Sharing (CORS) configuration for misconfigurations — wildcard origin with credentials, reflected arbitrary Origin, the 'null' origin, overly broad allowed methods, and risky credentialed CORS. Use when the user asks to "check my CORS config", "is my API's CORS safe", "test for CORS misconfiguration", or "why can any site call my API".
Audited -
novacode37 Bundle JWT InspectorDecode and security-audit a JSON Web Token — flag alg=none, missing/excessive expiry, symmetric-alg confusion risk, missing claims — and attempt an offline HMAC secret crack against a wordlist to detect weak signing keys. Use when the user asks to "decode this JWT", "is this token secure?", "audit a JWT", or "check if this token uses a weak secret".
Audited -
novacode37 Bundle HTTP Sec AuditAudit a website's HTTP security headers and cookie flags — CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, COOP/COEP, version-leaking banners, and Secure/HttpOnly/SameSite cookies. Use when the user asks to "check my site's security headers", "audit HTTP headers", "is my CSP/HSTS configured right", or "scan a URL for header misconfigs".
Audited -
novacode37 Bundle Secret ScannerScan a codebase for hardcoded secrets — API keys, tokens, private keys and passwords — using a custom regex + Shannon-entropy engine. Use when the user asks to "find secrets", "check for leaked credentials", "scan for API keys", do a pre-commit secret check, or audit a repo before making it public.
Audited -
novacode37 Bundle Dockerfile ScanScan a Dockerfile for insecure build patterns — running as root, unpinned or :latest base images, ADD from remote URLs, piping curl/wget into a shell, hardcoded secrets in ENV/ARG, world-writable chmod 777, and sudo usage. Use when the user asks to "review my Dockerfile", "is this container image secure", "lint my Dockerfile for security", or "why does my image run as root".
-
novacode37 Bundle Dependency CheckAudit project dependencies for known-vulnerable versions and risky pinning. Parses requirements.txt and package.json, matches a bundled offline advisory DB, optionally queries OSV.dev live, and warns about unpinned versions. Use when the user asks to "check dependencies for vulnerabilities", "audit my requirements.txt / package.json", "scan for vulnerable packages", or "is my dependency tree secure".
Audited -
pratiyush Bundle Dependency AuditAudit project dependencies for known vulnerabilities, outdated packages, and license compliance issues. Use when the user asks to check dependencies, audit packages, review licenses, or assess supply chain security.
Audited -
sendlyhq Skill Rotating API KeysRotates a Sendly API key with a grace period so callers roll over with zero downtime, using the Account Keys API. Covers issuing a replacement key, the one-time raw secret, and the overlap window. Applies when rotating, refreshing, or replacing an API key on a schedule or after a suspected leak.
-
skillmedev Skill Longevity ProtocolAssembles an evidence-tiered weekly longevity routine across the four pillars with the strongest healthspan data - sleep, zone 2 aerobic work, strength training, and dietary pattern - plus stress and connection, delivered as a filled weekly template with honest evidence labels. Use when someone asks "build me a longevity routine", "what actually extends healthspan", "audit my health habits", or "is this supplement stack worth it". General wellness guidance, not medical advice. Do NOT use to program the individual pieces in depth - use zone-2-cardio-plan for the aerobic block, strength-training-plan for lifting, sleep-optimizer for sleep, nutrition-planner for macros; for HIIT/conditioning use fitness-program; for interpreting labs use bloodwork-explainer.
-
raroque Bundle Convex Performance AuditAudits Convex performance for reads, subscriptions, write contention, and function limits. Use for slow features, insights findings, OCC conflicts, or read amplification.
-
rlaope Skill VowPre-commitment engineering — declare falsifiable vows before the work starts and audit every one before claiming done, discipline pledges distilled from the engaged skills' Done means plus scope pledges bounding the blast radius. Use when the user says "don't touch anything else", "only this file", "stay in scope", "no new dependencies", "don't tell me it's done until", "commit to your constraints", or "show me the failing test first"; when a previous attempt was declared done and was not; when a diff wandered into files nobody asked about; when en announces an engagement (the announcement is the vow moment); or when delegated work needs acceptance criteria the delegate can be audited against.
-
slowdini Bundle Auditing Slow Powers UsageUse only when a slow-powers developer explicitly asks for a post-session audit of how slow-powers skills were used during the session just completed. A manual diagnostic for people working ON slow-powers — never relevant to ordinary development tasks; do not auto-invoke.
-
suitedaces Skill Review PrReview GitHub pull requests with structured code analysis. Use when asked to review a PR, check a pull request, or audit code changes.
-
susomejias Bundle NPM Security Best PracticesApply npm/pnpm supply-chain hardening when adding a dependency, editing package.json/.npmrc/pnpm-workspace.yaml, reviewing a lockfile change, or configuring CI install steps. Covers the 17 practices from lirantal/npm-security-best-practices.
Audited -
paldom Bundle Python Supply ChainHardens a Python repository's supply chain — Dependabot update automation, pip-audit vulnerability scanning, secret scanning and push protection, CodeQL, OpenSSF Scorecard, SBOMs, CODEOWNERS. Use for 'set up dependabot', 'audit dependencies', 'someone committed a key — stop that happening again', 'protect paths with CODEOWNERS', 'harden this repo'. Not for CI quality gates, workflow hardening, or PyPI publishing.
Audited -
mikker Bundle Xcode SkillsAuthoritative Apple guidance bundled with Xcode for SwiftUI, UIKit, App Intents, testing, device interaction, document apps, C bounds safety, and Xcode security settings. Use when writing, reviewing, debugging, testing, or modernizing Apple-platform code. Load the relevant bundled skill before acting.
Audited -
skael-dev Skill Code ReviewPerform thorough code reviews focusing on correctness, security, and maintainability.
Audited -
skael-dev Bundle Dangerous SkillExample skill that demonstrates security scanner detection.
-
skael-dev Skill Hardcoded SecretA bundle that leaks a real credential. This must never publish.
-
upsonic Bundle Code ReviewPerform structured code reviews with actionable feedback. Use when a user asks to review code, check code quality, find bugs, audit security, improve performance, or assess maintainability. Trigger when user says things like "review this code", "check for bugs", "is this code secure", "any issues with this", "code quality check", or pastes code asking for feedback. Also trigger for pull request reviews and pre-merge code checks. Do NOT trigger for writing new code from scratch, refactoring requests without review context, or general programming questions.
-
automattic Skill Wordpress CreatorRoute WordPress build, management, and audit requests to the right target and implementation path. Use when the user wants WordPress work and it is not yet clear whether the task should use a local WordPress Studio site, a live WordPress.com site, site creation, theme work, a custom block, a plugin, or an audit.
Audited -
cristoslc Bundle Swain Security CheckRun all security scanners against the project and produce a unified, severity-bucketed report. Orchestrates gitleaks (secrets), osv-scanner/trivy (dependency vulns), semgrep (static analysis), context-file injection scanner (built-in), and repo hygiene checks (built-in). Missing scanners are skipped with install hints — the scan always completes. Triggers on: 'security check', 'security scan', 'run security', 'scan for secrets', 'check for vulnerabilities', 'security audit', 'audit dependencies', 'check secrets', 'find vulnerabilities', 'scan codebase'.
Audited -
mrclrchtr Bundle Claude Md ImproverAudit and improve existing CLAUDE.md files across a repository. Use for a deliberate, repo-wide quality review—not to record learnings from the current session.
-
robinebers Bundle Code UpgradeEngineering-discipline toolkit for non-technical users working with AI coders. Wields KISS, DRY, YAGNI, fail-fast, and idempotency as commands. Use when the user asks to audit, simplify, clean up, dedupe, or harden code; or says "make this simpler", "any duplicates?", "is this safe to run twice", "explain this app", "find dead code", "simplify the plan", or "find silent failures".
-
gn00678465 Bundle Security Supply ChainHardens npm/pnpm/bun/yarn/uv/pip configs against supply chain attacks via minimum release age gates, lifecycle-script allowlists, OIDC trusted publishing, and commit-time secret scanning. Use when auditing package manager configs, configuring dependency bots (Renovate/Dependabot), evaluating whether a fresh package version is safe to install, or responding to a published npm/PyPI compromise (chalk/debug, ua-parser-js, TanStack-style hijacks).
Audited -
meleantonio Skill Replication CheckerUse when asked to verify reproducibility, audit a replication package, check a clean run, validate run instructions, or review before sharing research code.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include teamwork-review, merge-upstream-main, verify-fix. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.