Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
rlespinasse Bundle Verify Readme FeaturesVerifies that features listed in a README (or similar documentation) are actually implemented in the codebase. Use when user mentions verify features, check feature list, confirm README, validate documentation claims, or audit feature accuracy. Helps catch stale, missing, or inaccurate feature descriptions.
-
stickerdaniel Skill Email And Password Best PracticesConfigure email verification, implement password reset flows, set password policies, and customise hashing algorithms for Better Auth email/password authentication. Use when users need to set up login, sign-in, sign-up, credential authentication, or password security with Better Auth.
-
utk2103 Skill Lean AuditWhole-repo audit for over-engineering. Like lean-review, but scans the entire codebase instead of a diff: a ranked list of what to delete, simplify, or replace with stdlib/native equivalents. Use when the user says "audit this codebase", "audit for over-engineering", "what can I delete from this repo", "find bloat", "lean-audit", or "/lean-audit". One-shot report, does not apply fixes.
Audited -
meshtastic Skill Design AuditDesign Audit Skill
-
automatedmarketer Skill Humanistic ReviewerAudit any draft copy for AI slop, generic filler, voice mismatch, and weak structure. Use this skill after any writing engine produces output — always run before delivering copy to the user. Also trigger when the user says "review this copy", "edit this", "make this less AI-sounding", "punch this up", "is this good enough to send", or pastes copy and asks for feedback. Returns a score, flagged issues, revision instructions, and optionally a rewritten draft.
-
entropy-cloud Skill Nop Doc Audit文档审计工作流 — 交叉验证docs文档与实际代码的一致性,修复不准确的引用和描述。触发词:文档审查、doc audit、核查文档、文档准确性。
-
itallstartedwithaidea Bundle Security AuditorSecurity Auditor Skill
-
adamos486 Bundle Production ReadyUse when preparing any project for production deployment, performing security audits, or release preparation. Triggers on "make production ready", "security audit", "prepare for release", "hardening", "pre-deployment checklist".
-
operately Bundle Help DocsDiscover help documentation work from operately git history. Use when the user asks to audit what needs documenting since a release, tag, or SHA, or to identify documentation gaps from code changes. Requires a baseline SHA or tag as input.
-
outfitter-dev Bundle Use BunBun-first development patterns for TypeScript projects. Use when auditing Node.js projects for migration opportunities, starting new projects, evaluating npm dependencies, or reducing package.json bloat. Triggers on mentions of npm, yarn, pnpm, Node.js migration, dependency audit, or package optimization.
-
outfitter-dev Skill Docs CheckRigorous quality gate for documentation before merge or publish. Verifies code examples run, links resolve, APIs match implementation, and all sections are complete. Use when auditing docs, reviewing documentation PRs, or when "verify", "quality gate", "docs audit", or "check examples" is mentioned.
-
oxyroid Skill M3u Epg Data AuditAudit M3UAndroid M3U and EPG data flows for parser behavior, channel/programme matching, duplicate handling, fallback behavior, joins, and timezone/time-range correctness.
-
oxyroid Skill I18N Resource AuditAudit M3UAndroid localization resources for missing default strings, placeholder consistency, key naming, hardcoded user text, fallback behavior, and locale safety.
-
oxyroid Skill Room Migration AuditAudit M3UAndroid Room schema and migration changes for versioning, schema artifacts, data preservation, indices, defaults, DAO compatibility, and migration validation.
-
oxyroid Bundle Jetpack Compose AuditAudit Android Jetpack Compose repositories for performance, state management, side effects, and composable API quality. Scans source code, scores each category from 0-10, writes a strict markdown report, and summarizes the most important fixes. Use when reviewing a Compose codebase, rating repository quality, inspecting recomposition/state issues, or running a Compose audit.
-
oxyroid Skill Android Tv Focus AuditAudit M3UAndroid Android TV screens for DPad focusability, focus order, initial focus, visual focus states, touch assumptions, and couch-distance readability. Use when reviewing TV UI or changing focus behavior.
-
oxyroid Skill Extension System AuditAudit M3UAndroid extension APIs and runtime for host/plugin boundaries, classloader compatibility, manifest metadata assumptions, IPC/protobuf compatibility, and dependency leakage.
-
pabasara-mahindapala Skill Wso2 U2 UpdateApply WSO2 U2 updates to a WSO2 IS product distribution up to a defined update level. Handles online update (direct), offline update (create-update + apply-update), level pinning (--level), dry-run, revert, hotfix apply/revert, and current-state inspection. Keywords: wso2update, u2, update level, wso2is update, product update, security update, hotfix
-
pabasara-mahindapala Skill Wso2 Is TroubleshootUse when troubleshooting WSO2 Identity Server issues — login failures, token exchange errors, adaptive auth script tracing, federated IdP auth, correlation ID analysis, audit log events, HTTP access log correlation. Keywords: authorization code, oauth2, oidc, adaptive auth, saml, token, login not working
-
patriceckhart Skill Secret ReviewCheck a change for accidentally exposed credentials and private data.
-
poooi Skill Game WebviewThe KanColle game <webview> — contextIsolation + disablewebsecurity, the preload world split, the poi-cache:// asset-hack scheme, and the window.open popup crash. Use when editing views/kan-game-wrapper.tsx, assets/js/webview-preload.js, assets/js/resource-hack.js, assets/js/kcs-resource-path.js, lib/kcs-resource.ts, lib/webcontent-utils.ts, or when debugging game asset loading, screenshots, renderer crashes, or webview security settings.
-
arthurzakirov Skill SecurityMandatory credential protection skill for all agents. Prevents reading, exposing, or leaking credentials, secrets, API keys, tokens, passwords, and auth-capable config files.
-
btcelectrician Skill Flask Redundancy AuditAudit a Flask backend for redundant logic and write redundancy-audit.md with clusters and a P0 P1 P2 plan.
Audited -
btcelectrician Skill Flask Redundancy Refactor P0Implement exactly one P0 item from redundancy-audit.md in a Flask backend with contract snapshots and a single commit.
Audited -
chaoschild Bundle Cavet TriageInterpret security scan findings, separate false positives from real issues, and surface only what matters. Use after code is written or changed, before a commit, whenever scan output appears in context (including pre-commit hook output), when the operator asks to check for vulnerabilities, "is this safe", "run a scan", or asks what to do about a finding. Covers both the isolated triage subagent and the parent session that reconciles its results.
-
chaoschild Bundle Cavet Secure CodingSecure-by-default construction while writing or modifying any code — functions, endpoints, queries, file and path handling, shell calls, serialisation, auth, tokens, config, scripts, tests, migrations. Use on every code-writing or code-editing task, regardless of whether it appears security-relevant; recognising what is security-relevant is exactly what this skill supplies, so it cannot be gated on that recognition.
-
derivativelabs Skill Decision ReviewAudit decisions for judgment quality, compliance bias, and manipulation vulnerability. Inspired by Anthropic's Project Vend Phase 2 finding that helpfulness training creates exploitable attack surface.
-
semantica-agi Skill ProvenanceTrace data lineage, source attribution, audit trails, and W3C PROV-O export in Semantica graphs. Uses ProvenanceManager.
-
cylixlee Bundle Golang Gin APIBuild REST APIs with Go Gin framework. Covers routing, handler patterns, request binding/validation, middleware chains, error handling, security headers (OWASP), CORS, timeout middleware, and layered project structure. Use when creating Go web servers, REST endpoints, HTTP handlers, or working with the Gin framework. Also activate when the user mentions Gin routes, middleware, JSON responses, request parsing, or API structure in Go.
-
awjackson2 Skill Phase AuditUse to check the integrity of the phase log and the workflow's git state. Trigger when the user asks to "audit the phases", "check the phase log", "is the phase log healthy", "phase doctor", "validate the phases", "any drift?", or before relying on the log for a release or a recap. Reports drift between plans, logs, the index, design docs, and git (missing logs, broken index links, dangling worktrees, stale design-doc sync, numbering gaps), most-severe first, then offers to fix what's safely fixable via a docs-lane PR. Read-only by default.
Audited -
cnwu16 Bundle Vedic CoreRun the standard full Vedic/Jyotish natal analysis from a verified structured_data.md: P1-P12 planet audit, divisional-chart cross-checks, house diagnostics, ten life areas, report packaging, and Q&A. Use for 'full Vedic chart analysis', 'complete birth chart reading', 'planet or house audit', 'analyze my life from this chart'; Chinese requests such as '完整分析', '星盘审计', '开始分析', and '生成报告'; Japanese requests such as 'ヴェーダ占星術で総合鑑定して', '出生図を詳しく分析して', and '完全分析して'; and follow-ups about an existing report. / 吠陀占星标准核心分析引擎。
Audited -
app-builders-club Bundle Playwright CLIBrowser automation via @playwright/cli. Use when capturing screenshots of a running web app for design audit, capturing live web pages as design references, inspecting rendered DOM/computed styles for review, or driving end-to-end interaction. Invoked by /design-builder:review (design-auditor) and /design-builder:improve --restructure to ground designs in real rendered visuals. Requires Node 18+; auto-installs via npx on first use.
-
elastic Skill Style ReviewReview changed or staged C# code against the docs-builder coding standards and flag violations. Use when the user asks to review code style, check for standards violations, or audit a diff before committing.
-
grandcamel Bundle Skills OptimizerAudit and optimize skills for token efficiency and progressive disclosure compliance. Use when user wants to "analyze skill tokens", "audit skills", "optimize skill size", "check token efficiency", or "validate progressive disclosure".
Audited -
harumiweb Bundle Adr ReconcilerAudit ExStruct ADRs against current specs, tests, and source code to detect policy drift, missing ADR updates, stale references, and evidence gaps. Use after merges, during periodic ADR audits, or when a review suspects that implementation and ADRs have diverged.
-
helloggx Bundle Code Review ExpertExpert code review of current git changes with a senior engineer lens. Detects SOLID violations, security risks, and proposes actionable improvements.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include security-auditor, use-bun, docs-check. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.