Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
blueberrycongee Skill Security AuditSecurity audit skill. Use when asked to "audit security", "check for vulnerabilities", "security review", "pentest", or when evaluating code that handles auth, user input, secrets, or external data. Runs a phased scan covering OWASP Top 10 and STRIDE threat modeling.
-
brenbuilds1 Bundle Ste AuditCheck output against the machine-checkable ASD-STE100 rules: sentence length caps, noun cluster limits, allowed verb forms, -ing restrictions, passive voice, paragraph limits. Use after adding an STE memory line, CLAUDE.md rule, or writer skill, or when replies drift wordy again. Violations table with Issue 9 rule numbers and quoted receipts, plus a drift verdict (holding, drifting, gone). Reports only; never rewrites; no dictionary bundled.
-
brenbuilds1 Bundle Engineering ReviewCode review stance for serious engineering changes. Use when asked to review a diff, PR, commit, branch, patch, architecture change, migration, implementation, or test plan for bugs, regressions, missing tests, operational risk, security/privacy issues, and maintainability problems that could actually hurt users.
-
cameroncooke Skill Changelog UpdaterUpdate upcoming CHANGELOG release notes with user-facing outcomes. Use when asked to update changelog entries, prepare release notes, reconcile changelog content with git history, or audit release-note drafts.
-
cameroncooke Bundle Pr Comment ResolutionAudit and resolve GitHub pull request review comments with a concise, human-readable, evidence-based workflow. Use when asked to "address PR comments", "resolve review feedback", "handle inline comments", "reply to review threads", or "close out PR review notes".
Audited -
canonical Bundle Documentation ReviewPerforms comprehensive documentation review including build validation, Diataxis analysis, structure audit, accuracy verification, and style compliance. Use when reviewing documentation changes or auditing documentation quality.
-
cbdreamer11 Skill Loop CloseCloses a slice or a session - adversarial audit of the diff, ledger entry, selective commit, honest report, and the handoff for the next session. Use before considering anything finished.
Audited -
cbrunnkvist Bundle Katana Web CrawlAuthorized ProjectDiscovery Katana crawling for owned apps, approved pentest or bug-bounty targets, and CTF labs. Use to inventory URLs, endpoints, JavaScript routes, forms, XHR, or scoped headless routes; enforce scope, limits, secret-safe authentication, and hostile-content handling.
-
dangogit Skill Ncode Rls GuardEnforces Row Level Security on every Supabase table and Firebase Security Rules on every collection. Activates automatically when creating tables or collections.
-
datadog Skill Dd Sdk IOS Update Feature DocsUse when public API changes have been made to review and update all *_FEATURE.md documentation files, or to audit whether they are still accurate.
-
digital-go-jp Skill ReviewReview changed code in this repo against the project's review checklist (readability, maintainability, performance, security, consistency).
-
dillonschultz93 Skill Design Token AuditInspect and health-check an existing design token system. Runs orphan detection, broken reference checks, naming validation, and WCAG contrast analysis, then summarizes findings. Use when the user wants to audit, lint, or validate their token system quality.
-
donnfelker Skill Pr AutopilotAutonomously watch a single pull request and drive its review feedback, failing CI checks, AND merge conflicts to completion without supervision: each round fetch every unaddressed review and comment (Claude, CodeRabbit, Copilot, other bots, humans), the PR's check runs (tests, lint, type, build, security), and its mergeability; address the actionable ones (resolving conflicts by merging the base branch into the head), commit, push, reply/resolve threads, and re-request review from bots whose change requests were addressed, then loop until a quiet round or a safety cap. Use whenever the user wants to 'watch a PR', 'babysit a PR', 'keep addressing PR comments until done', 'fix the failing checks', 'get CI green', 'resolve the merge conflict on PR #N', 'auto-respond to reviews', or run a hands-off review-response loop on ONE PR, even if they don't name this skill. Pass --single-pass (or --max-rounds 1) for one autonomous round, no loop. For MANY stacked PRs from a parent ticket, see /implement-full-spec.
-
dtsong Bundle Pbc PackageMaps audit PBC request lists to support files, identifies gaps, drafts auditor responses, and assembles audit-ready evidence packages. Use when the user provides a PBC request list and a folder of support files and asks to match support to requests, identify missing items, flag duplicates or orphaned files, or draft responses to the auditor.
Audited -
dtsong Bundle Workpaper StandardsUse whenever producing an accounting workpaper, schedule, reconciliation, journal entry, or audit deliverable. Defines firm formatting conventions, the evidence-table requirement, journal entry templates, and the standard for source tie-outs. Required dependency for bank-rec, flux-analysis, prepaid-schedule, pbc-package, and je-review skills.
-
freepeak Skill Code ReviewComprehensive code review framework for evaluating code quality, security, performance, and maintainability
-
full-stack-skills Bundle Kotlin Code ReviewReview Kotlin changes for correctness, compatibility, concurrency, nullability, API, security, performance, test quality, and Gradle integration. Use when asked to review, audit, assess risk, or explain defects in Kotlin code; produce evidence-backed findings without modifying code unless a fix is explicitly requested.
-
full-stack-skills Skill Spring BootProvides comprehensive guidance for Spring Boot development including project creation, auto-configuration, dependency injection, web development, data access, security, testing, and deployment. Use when the user asks about Spring Boot, needs to create Spring Boot applications, configure Spring Boot, or implement Spring Boot features.
-
full-stack-skills Bundle Spring SecurityProvides comprehensive guidance for Spring Security including authentication, authorization, OAuth2, JWT, and security best practices. Use when the user asks about Spring Security, needs to implement security in Spring applications, configure authentication, or work with security features.
-
full-stack-skills Bundle Swift Code ReviewReview Swift changes for correctness, API compatibility, ownership, concurrency, memory safety, Codable and Objective-C bridges, security, performance, test quality, and SwiftPM integration. Use when asked to review, audit, assess risk, or explain defects; report evidence-backed findings without changing code unless a fix is explicitly requested.
-
getkyo Bundle ReadmeWrite or review a high-quality README that serves engaged readers, not audit checklists. Cuts bloat by default; only adds when the addition closes a question the reader is actually asking.
Audited -
getlark Skill ManageThis skill should be used when the user asks to "list workflows", "show getlark workflows", "get workflow details", "archive a workflow", "update a workflow", "list workflow groups", "manage secret contexts", "show executions", "show repairs", "show generations", "show events", or runs `/getlark:manage`. Covers read/update/archive operations across all getlark resources and formats CLI JSON as human-friendly tables. Use `create-workflow` to create new workflows and `invoke-workflow` (or `validate-branch`) to run them — this skill never triggers executions, it only inspects and mutates metadata.
Audited -
getlark Bundle Getlark OverviewThis skill should be used when the user mentions "getlark", "getlark.ai", "larkci", "larkci CLI", "end-to-end test workflow", or asks about authoring, running, or debugging automated tests on the getlark platform. getlark tests any software surface — browser UIs, HTTP APIs, CLIs, shell scripts, data pipelines, or mixed flows. Provides background on getlark concepts (workflows, workflow groups, executions, repairs, generations, secret contexts, events) and points to the other plugin skills for actions. Use as reference context — defer to `create-workflow`, `invoke-workflow`, `manage`, `validate-branch`, or `setup` whenever the user wants to take an action rather than learn.
-
getsentry Bundle Wrdn Gha WorkflowsDetects exploitable GitHub Actions workflow vulnerabilities, including pull_request_target pwn requests, unsafe PR checkout, expression injection in run steps and actions/github-script blocks, workflow_dispatch and workflow_call input command injection, comment- and discussion-triggered commands, TOCTOU between approval and checkout, secret exposure, broad permissions, reusable workflows that consume undeclared secrets, ArtiPACKED-style token leaks through uploaded artifacts, cache poisoning and eviction-stuffing, supply-chain risk from unpinned third-party actions (tj-actions/changed-files class), and self-hosted runner abuse. Run on diffs touching .github/workflows, action.yml, action.yaml, repo-local actions, or CI-loaded scripts and config.
Audited 845 -
ghostwright Skill MirrorWeekly self-audit playback. Surface patterns from the user's past week that they probably cannot see themselves.
-
ghostwright Skill OverheardFind commitments the user made in the last two weeks and did not follow through on. A promises audit.
-
grafana Bundle Audit GuideComprehensive read-only audit of an existing Pathfinder guide. Combines structural (lint), semantic (check + best-practices decision trees + the 21 critical rules), and adversarial (attack) analysis into one phased workflow that produces a single prioritised report. Use when the user asks to audit, review, lint+check, or check the quality of an existing guide directory.
-
gravitational Bundle Teleport Acl ReviewReview Teleport access lists that are due for audit. Use when the user asks to review access lists, audit Teleport ACLs, check which access lists need attention, perform periodic access list reviews, recertify access, or manage Teleport access list compliance. Trigger on phrases like "review access lists", "which access lists need review", "audit my ACLs", "recertify access lists", or any mention of Teleport access list reviews. Also trigger when the user follows up on access list findings from a previous command.
-
gregherbe76 Bundle Commissaire Aux ComptesRéviseur d'entreprises agréé luxembourgeois (RE/REA) — audit légal selon ISA-LUX en 7 phases, validation croisée bilan/CR/eCDF, opinion motivée.
-
waynesutton Skill Convex Auth ExpertExpert Convex Auth setup, production, OAuth, security, and debugging guidance. Use when adding or auditing Convex Auth, configuring GitHub/Google/Apple OAuth, setting auth env vars, protecting Convex functions with getAuthUserId, debugging callback URLs, preparing production auth, rotating keys, or reviewing auth security.
-
zerone-agent Bundle Openclaw Config GuardAudit and safely repair OpenClaw configuration with deterministic validation, backups, rollback, and change reporting. Use when asked to review or modify `openclaw.json`, check whether OpenClaw can still start, safely fix startup-blocking config errors, or audit OpenClaw config before deciding on changes.
Audited -
leonvanzyl Bundle Security ScannerPerforms comprehensive OWASP Top 10:2025 security vulnerability analysis on any codebase. Use this skill whenever the user asks to: review code for security, perform a security audit, scan for vulnerabilities, find security issues, improve application security, check for OWASP compliance, do a penetration test review, assess security posture, look for security flaws, scan for security risks, harden an application, or check code for exploits. Also trigger when the user mentions OWASP, CVEs, CWEs, security hardening, vulnerability assessment, or asks for a security report — even if they don't explicitly say "security scan." This skill works on any codebase in any language (JavaScript, TypeScript, Python, Java, Go, Ruby, C#, PHP, etc.).
-
auldsyababua Skill Security ValidationPre-merge security validation detecting secrets, user-specific paths, insecure SSH configurations, and security-weakening flags
Audited -
aeonfun Skill ShiplogRecap of everything shipped since the last run - cross-repo PRs, security fixes, star deltas, and X traction, synthesized into a digest article and a ready-to-post shiplog in your voice.
-
aeonfun Skill Vuln ScannerAudit trending repos for real security vulnerabilities and disclose responsibly - scan and route findings (PVR / dependency PR), re-submit queued advisories, and send armed email disclosures
-
aaronjmars Skill Secured WatchWatch the public "Secured by Aeon" leaderboard (aeon.fun/security) and report only newly secured repos and changed entries since the last run — repo, severity, stars, and the fix PR/advisory link.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include wrdn-gha-workflows, security-audit, ste-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.