Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
jiayaoqijia Skill Code ReviewReviews code changes for bugs, security issues, and quality problems
-
metarhia Skill NPM PublishPrepare an npm package for publishing. Handles version bump, CHANGELOG update, typings check, test run, README refresh, package.json audit, and npm pack verification. Use when the user asks to prepare a release, bump version, publish a package, or do release prep.
-
mhmzdev Skill Docs GardeningAudit and maintain The Holy Qur'an app's knowledge base (AGENTS.md, .agents/rules/, docs/ OKF bundle) for staleness, broken cross-links, drift from code, and OKF structural issues. Use when asked to review, garden, audit, update, or clean up the docs. Also use proactively after any architectural change, convention shift, dependency/SDK bump, or feature merge.
-
microsoft Skill Jinja2Best practices for template rendering with Jinja2 including environments, filters, autoescaping, and security.
2.7k -
modiqo Bundle Clarity TrustStage 4 of the stranger test — audit the trust layer. Proof proximity (evidence adjacent to the claim it supports), specificity over adjectives, credibility signals, and risk reversal at the moment of doubt. Scored 0-10.
-
modiqo Bundle Clarity PricingStage 5 of the stranger test — audit the pricing page against the behavioral-economics literature (anchoring, decoy/compromise effects, loss aversion, mental accounting, pain of paying) and the catalog of SaaS pricing failures. Distinguishes ethical architecture from dark-pattern manipulation. Scored 0-10.
-
modiqo Bundle Clarity PromiseStage 1 of the stranger test — audit message match and information scent. Does the page confirm, within one glance, the promise that brought the visitor here? Scored 0-10; a mismatch with the primary entry path is a journey gate.
-
modiqo Bundle Clarity NarrativeStage 3 of the stranger test — the heart of the audit. Walk the page section by section carrying the question the visitor is holding at that moment; any section that answers no pending question is an exit ramp. Sequential by nature — never run in parallel. Scored 0-10.
-
mpagot Bundle Test CatalogAdd or audit a Perldoc documentation header on an OSADO test module following the test catalog standard. Use when a user asks to "add header", "document", or "add catalog header" to a Perl test module.
-
mpuig Bundle Slides AuditRun technical quality checks on an existing deck. Finds and fixes font size violations, shape overlaps, contrast issues, missing sources, and layout compliance problems. Use when the user says "check the deck for issues", "run QA", "lint the slides", "are there any formatting problems", "audit the presentation", or wants to verify visual quality before sharing.
-
mskayyali Skill State TriageRecommend evidence-aware risk and scope decisions for a complete Stateful condition inventory, recording likelihood, impact, confidence, rationale, and one of in, out-with-implication, or out for human confirmation. Use after state-list or state-audit and before specification. Do not persist recommendations or continue to specification until a human confirms them.
-
msutara Skill Cm Docs SyncDocumentation and skill template consistency auditing across all CM repos. Scans configuration files for drift, validates copilot-instructions.md accuracy, cross-references specs with code, detects version drift in skill templates (action versions, tool versions), checks README freshness, and runs markdownlint. Generates a unified report and optionally auto-fixes mechanical divergences. USE FOR: sync docs, docs audit, check documentation, update docs, docs consistency, audit docs, documentation check, verify docs, docs parity, skill template drift, skill audit.
-
msutara Skill Cm Parity CheckVerify functional, security, test, and documentation parity between the UI repos in .cm/project.json (repos whose role is exactly "tui" or "web" — case-insensitive, anchored regex via jq ascii_downcase). Reports gaps without making changes. USE FOR: parity check, check parity, tui web sync, compare tui web, parity audit, ui parity, check ui parity, verify parity, parity report.
-
mtkhawaja Skill Java AuditUse when asked to audit, sweep, or review Java code in bulk against the house conventions — the whole repository, the current branch's diff, or named paths/classes. Also invoked directly as /java-skills:java-audit [paths | diff]. Read-only; reports findings without modifying files.
-
opascope Bundle OpascopeChoose a work-process skill when unsure how to start, clarify a task, define completion, plan work, audit for deletion, prepare unattended work, or resume a session. Also handles package update and local usage-ranking requests.
Audited -
opascope Bundle Opascope OptimizeAudit a process, codebase or workflow for deletion and compression. Use when asked what can be deleted, what is unnecessary, or to simplify a process. Produces recommendations only and never changes the audited target.
Audited -
openkursar Skill Comment ReviewMust be invoked when the user asks to review, audit, or improve code comments — e.g. "check the comment quality", "审一下注释", "注释评审", "optimize the comments". Reviews comments in the current changes against this project's comment policy and fixes the issues found.
-
pedromneto97 Bundle HTTP Actix AxumHTTP best practices for actix-web 4 and axum 0.7+ Rust backends. Use when: naming REST resources, choosing HTTP status codes, implementing RFC 9457 Problem Details error responses, configuring OWASP security headers, setting up CORS, enabling response compression, versioning APIs, implementing custom request extractors, wiring OpenAPI docs, or structuring the HTTP layer. Covers both actix-web and axum.
-
peterzat Skill SecuritySecurity-focused review from the perspective of a Principal Security Engineer. Use when the user asks for a security review, vulnerability check, or secret scan. Accepts optional scope argument: "changes-only" for proposed changes only, a file path to review specific files, or no argument for a full repository audit.
-
pluginagentmarketplace Bundle API ArchitectureProduction-grade API architecture skill for REST, gRPC, GraphQL design, versioning, and security patterns
-
pnp Skill Patch VulnerabilitiesThis skill should be used when the user asks to "patch vulnerabilities", "fix npm audit issues", "update vulnerable dependencies", "update outdated dependencies", "scan and fix vulnerabilities", "run npm audit and patch", "fix security vulnerabilities", "update npm packages", "check for outdated packages", or needs to comprehensively scan, patch, and re-verify npm dependencies with a cooldown safety check. Covers three blind spots: npm audit (security), npm outdated (staleness), and override checks.
-
primexiao Bundle TopicInitialize or tidy an ideas/topics directory, start or explore a topic in a flat topic archive, or safely audit/fix archive convention drift. Use for /topic init, /topic IDEA, /topic explore, /topic lint, topic archives, idea vaults, and organizing folders of independent exploratory ideas. An explicit /topic command always means a topic-archive workflow. Do not use to generate project task plans, manage issues, or refactor a generic source-code repository.
-
josemvcerqueira Bundle Sui Move ReviewAudit Sui Move pull requests, branches, packages, deployments, upgrades, or releases across architecture, source, security, and testing. Use for a comprehensive review; use a focused skill for a narrow domain review. Requires the complete suite installation.
-
josemvcerqueira Bundle Sui Move SecuritySecurity for privileged, stateful, economic, cryptographic, shared-object, and external-integration Sui Move code. Use when designing, changing, or reviewing transitions, authority, replay, bounded work, custody, DeFi, time, oracles, randomness, pauses, dependencies, or upgrades.
-
juice-shop Skill Create M3 ThemeInstructions for creating and integrating a new Angular Material M3 theme into OWASP Juice Shop.
-
julian-adv Bundle Prod Log AuditInvestigate OpenMMO production warnings, errors, suspicious behavior, and unresolved incidents within a deployment interval; correlate journald, nginx, and targeted evidence, then write a dated note to ~/work/notes. Use for "로그 조사", "로그 점검", "수상한 점 없는지", or "prod 점검". Routine statistics are covered by the dashboard.
Audited -
juncoding Bundle Nfs Review ProjectReview an existing project scaffolded with nextjs-fullstack-starter against the architectural invariants and patterns. Use this whenever the user wants to audit project conventions, asks 'does this follow our patterns', wants a pre-PR architecture check, suspects drift, is onboarding a new contributor, or invokes /nfs-review-project. Runs a mechanical check script for fast objective violations (missing server-only, DB queries in src/app/, missing requirePermission on mutations, missing audit, wrong cache primitives, tRPC imports from the wrong stack), then samples files for judgment calls, then produces a categorized report grouped by severity (must fix / should fix / notes / passing).
Audited -
juncoding Bundle Nts Review ProjectReview an existing project scaffolded with nextjs-trpc-prisma-starter against the architectural invariants and patterns. Use this whenever the user wants to audit project conventions, asks 'does this follow our patterns', wants a pre-PR architecture check, suspects drift, is onboarding a new contributor, or invokes /nts-review-project. Runs a mechanical check script for fast objective violations (missing server-only, DB queries in src/app/, Server Actions present, wrong cache primitives), then samples files for judgment calls, then produces a categorized report grouped by severity (must fix / should fix / notes / passing).
Audited -
karmada-io Bundle Karmada Audit PolicyUse this skill when the user provides or points to Karmada PropagationPolicy, ClusterPropagationPolicy, OverridePolicy, or ClusterOverridePolicy YAML and wants validation, review, risk analysis, or corrections. Audit schema and admission rules, selector scope, placement and replica semantics, priority and preemption, override patches, and runtime-dependent assumptions with source-backed findings. Do not use it primarily to generate a policy from new intent, explain one observed placement, debug live propagation, or update the skill knowledge base.
-
karmada-io Bundle Karmada Explain PlacementUse this skill when a Karmada user, operator, or platform engineer asks why a concrete ResourceBinding or ClusterResourceBinding selected, rejected, ordered, or assigned replicas to specific member clusters. Use it for observed placement outcomes from full or partial evidence, including prose descriptions when binding YAML or runtime logs are unavailable; in partial cases bound conclusions and request the missing objects. Do not use it for policy creation, static YAML audit, general scheduling concepts, post-scheduling Work/member failures, live mutations, or knowledge maintenance.
-
keez97 Bundle Architecture WorkflowEnd-to-end codebase health workflow: discover architecture, review it, fix issues with TDD, and document the result. Chains describe-design, architecture review skills, and tdd-ai into a single phased workflow with checkpoint documents. Use this skill whenever the user says "audit my codebase", "do a full architecture review and fix things", "improve my codebase architecture", "health check this project", "review and refactor", "clean up this codebase", or any request that involves understanding an existing codebase, identifying architectural problems, fixing them, and documenting the result. Also trigger when the user wants a comprehensive codebase improvement that goes beyond a single review — they want the full loop of discover, diagnose, fix, and re-document. If the user seems to want both a review AND fixes applied, this is the right skill.
Audited -
keez97 Bundle Python Architecture ReviewExpert-level architecture review and design guidance for Python backends, with deep knowledge of FastAPI, PostgreSQL, async patterns, and modern Python project structure. Use this skill whenever the user asks you to review Python code architecture, design a new Python backend, evaluate project structure, assess API design, review database schemas, audit security posture, or discuss scalability of a Python service. Also trigger when the user shares Python backend code and asks "what do you think", "is this structured well", "how should I organize this", or describes a new feature/service they're planning to build in Python. Even if they don't say "architecture" explicitly — if they're asking about how to structure a FastAPI app, design their models, or whether their approach will scale, this skill applies.
-
kehwar Bundle Frappe Tweaks Open Observe API ExpertExpert guidance for OpenObserve API integration in Frappe Tweaks. Use when creating, configuring, or troubleshooting OpenObserve API DocType, implementing send_logs() or search_logs() functionality, integrating with Server Scripts/Business Logic/Client-side code, debugging connection issues, or implementing logging, monitoring, error tracking, performance metrics, or audit trail use cases.
-
kfchou Skill Wiki AuditUse when fact-checking a single wiki page against its cited sources — verifies that every footnote actually supports its claim and surfaces uncited factual claims. Run after ingesting a high-stakes page or any time you want confidence in one page's accuracy.
-
kimlawtech Skill Jangbu Connect홈택스·은행·카드사 데이터를 자동 수집하기 위한 CODEF API 자격증명 발급·설정 가이드 스킬. 사용자가 직접 CODEF(developer.codef.io)에 무료 가입해 받은 Client ID/Secret을 로컬(macOS Keychain 또는 ~/.jangbu/credentials.env)에 저장. BYOK(Bring Your Own Key) 방식, 외부 서버 전송 없음. 2026년 4월 기준.
Audited -
kiwissenorg-skills Bundle Skill CenterHaralds Kommandozentrale für Entwicklung, Auswertung, Versionierung, Testung, Dokumentation und Auslieferung von Skills für Kunden. IMMER nutzen, wenn Harald an seinen Skills arbeiten will — auswerten, verbessern, neu entwickeln, automatisch testen, dokumentieren, versionieren, ausliefern oder Feedback zu einem Skill erfassen. Trigger: "Skill-Center", "Skill auswerten", "Skills prüfen", "Skill-Audit", "Skill überarbeiten", "neuen Skill bauen", "Skill testen", "Testbericht", "Skill dokumentieren", "Skill ausliefern", "Skill verkaufen", "neue Version", "Skill freigeben", "welche Skills habe ich", "Skill-Register", "Skill hat falsch ausgelöst", "KI-Wissen-Standard", "Portabilität", "Video-Skript für den Skill", "Skill vorstellen". Auch triggern bei "mach meinen Skill fertig", "ist der Skill kundenreif", "optimiere Skill X", "lass uns gemeinsam einen Skill entwickeln", wenn Harald einen Fehlgriff eines Skills meldet oder einen Skill als Produkt professionalisieren will.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include clarity-promise, api-architecture, clarity-trust. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.