Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
shipiit Skill Code ReviewReview a diff or pull request for correctness, security and maintainability. Use when asked to review, critique, or approve code changes.
-
shipiit Skill Incident ReportWrite a blameless incident report from logs, a timeline, or notes. Use after an outage, security event, or production failure.
-
soupandpsy Bundle Psy Ana DesignerDesign a behavioral-psychology data analysis plan and produce a confirmed analysis config YAML. Use for scientific-question formulation, data-structure intake, statistical-method selection, analysis plans, cleaning/exclusion rules, effect sizes, assumption checks, sensitivity analyses, and figure choices, including “数据该怎么分析/用什么统计方法”. Compare viable methods before the user chooses. Do not generate or audit R/Python code; use psy-ana-coder or psy-ana-reviewer for those stages.
-
soupandpsy Bundle Psy Ana ReviewerAudit a behavioral-data analysis plan or R/Python script without modifying it. Use for statistical-method review, reproducibility review, publication readiness, seeds, exclusion logging, effect sizes, multiple-comparison correction, assumptions, sensitivity analyses, figures, session information, and “检查分析代码/统计方法审查/分析脚本有没有问题”. Select the review mode from the available input and report graded findings plus a readiness label. Do not generate or fix analysis code.
-
soupandpsy Bundle Psy Exp DesignerDesign or revise a psychological experiment before implementation. Use when the user has an idea, partial protocol, trial/block structure, timing, randomization, response mapping, condition table, PsychoPy/jsPsych/ Psychtoolbox target, or a paradigm such as Stroop, IAT, N-back, priming, dot-probe, visual search, task switching, Go/No-go, or stop-signal, and needs a confirmed experiment config YAML. Do not use to implement/debug existing code or to audit readiness; use psy-exp-coder or psy-exp-reviewer instead.
-
soupandpsy Bundle Psy Exp ReviewerAudit psychological experiment ideas, configs, implementation plans, or code without modifying them. Use for code review, design review, readiness for data collection, timing/RT correctness, condition balance, data integrity, PsychoPy/jsPsych/Psychtoolbox anti-patterns, smoke-test guidance, or “实验代码 有没有问题/能不能正式采集”. Select code-audit, config-audit, implementation-plan-review, triage-only, or blocked mode from the available input. Report graded findings and a readiness label; do not generate fixes.
-
specialone0007 Bundle Security AuditRun a read-only, evidence-grounded security audit of a named feature, route, workflow, PR, branch, service, API, or code path, or of the whole repository when no scope is named. Use when the user asks for security risks, AppSec review, auth/authorization review, secrets exposure, injection risks, data leakage, abuse paths, unsafe dependencies, secure-by-default gaps, or security launch readiness. This is not a general bug audit; use feature-audit for broad product readiness and defects.
Audited -
wrathza Skill Skill Forge AuditBatch-evaluate all skills in the repo with skill-forge-judge and render a single consolidated grade report sorted by grade (worst first) so effort is directed correctly. Use when reviewing overall skill quality, finding where to invest improvement effort, or after bulk skill changes. Triggers: audit all skills, grade report, skill health check, where should I focus.
-
wrathza Skill Skill Forge RecapRead a skill's body and report what it actually does vs. what the description claims: drift, undeclared behaviors, verdict. After the recap, offers context-sensitive actions: fix frontmatter via HITL, hand off to skill-forge-update, or run skill-forge-judge. Use before updating a skill. Triggers: recap [skill], what does [skill] do, audit [skill] description, summarize [skill].
-
abedegno Bundle Android Mitm SetupIntercept a mobile Android app's HTTPS traffic on Android 7+ where TLS pinning is in force. Walks through rootable emulator selection, mitmproxy CA installation into the system trust store, proxy routing, and Frida-based pinning bypass. Use when you need to see what an Android app is sending over the wire — for security research, API documentation, or interoperability work.
-
adaptyteam Bundle Flow Auditflow-audit
-
aditya-ariosity Bundle UX UI AuditAudit or critique an existing digital product artifact or flow and return evidence-backed, severity-calibrated findings. Trigger on "audit this", "critique this screen", "review this flow", "usability review", "heuristic evaluation", or "find UX issues" when inspectable evidence is available. Use dashboard-redesign for dashboard redesigns and design-system-review for system-wide library reviews. Do not use for greenfield design.
-
afterlaunch Bundle TellsAudit finished work, prose or a built interface, for the patterns that give machine-made output away. Reads one shared register, quotes the offending line or file:line for each check, then fixes what fails.
Audited -
aiopshwang Bundle Running Decision Grade Data ScienceOrchestrate an end-to-end data analysis or machine learning project from decision framing through reproducible handoff. Use when a request spans multiple lifecycle stages or an ambiguous modeling request must become a decision-ready result; use narrower audit or experiment-design skills for isolated reviews.
-
aj604 Skill Fixing DocsUse when landing fixes from a doc-lifecycle audit report — applying approved drift records (STALE, UNVERIFIABLE) or bloat records (CUT, CONDENSE, EXTRACT-AND-MOVE, MERGE-DOC, RETIRE-DOC, DISTILL) to the documentation, and whenever tempted to hand-edit a document because a record, a record-ID list, an issue comment, or a reviewer's say-so looks like authority enough.
-
aj604 Bundle Scheduling Doc SyncUse when wiring a repo for automated/unattended documentation audit — "set up doc sync", "automate drift detection", "schedule nightly doc checks", "keep docs in sync automatically" — installs the doc-lifecycle GitHub Actions (scheduled read-only drift and bloat audits, an optional policy apply lane, a manual apply dispatch, and a weekly upgrade check) instead of hand-rolling workflow YAML. Also the door for upgrading an existing install.
Audited -
nagisanzenin Skill AuditTwo-layer AI-tell audit of any text — deterministic scanner (lexicon, constructions, stylometry with line numbers) plus a blind semantic judge. Use when the user wants to know whether text reads AI-generated, what specifically gives it away, and how to fix it.
-
neeeophytee Bundle Audit ProvenanceAnswer the five provenance questions for a single asset in one pass - was provenance located, verified, and trusted, was the scan complete, and what remains unknown. Use when a user asks for an overall provenance verdict on a file and does not want to orchestrate the individual analyzers themselves.
Audited -
neeeophytee Bundle Audit Metadata PrivacyAudit supported metadata surfaces in images, SVG, PDF, and OOXML assets for privacy signals such as GPS, author, device, software, comments, and timestamps. Use when preparing a public release and metadata exposure must be assessed without altering or invalidating provenance.
Audited -
newmanxbt Bundle Sealevel Guard ReviewOrchestrates parallelized Solana trust-gate review to determine whether a codebase or program is safe enough to ship, integrate, or allocate capital through. Use when asked to review, audit, or assess risk of a Solana program.
-
nibzard Skill Book LedgerNatural-language access to book.db — project status, search, memory and context packs, canon, approvals, threads, continuity, tasks, retcons, and database health. Use to answer “where are we”, find what a character knows, locate open promises, approve a version, retcon a fact, or audit continuity. Translates requests into safe parameterized transactions.
-
rabbyhub Bundle Rabby Code ReviewReview Rabby browser-extension pull requests for actionable correctness, wallet-safety, security, privacy, build, and supply-chain issues, and publish validated inline GitHub findings. Use when Codex is asked to review a Rabby PR or its changed code; do not use it to implement fixes unless separately requested.
-
rabbyhub Skill Rabby Security ReviewHunt architectural, lifecycle, and state-confusion security bugs in Rabby that diff-scoped review misses — consent surviving session boundaries, cross-context message confusion, fail-open guards, and unsafe state across restarts. Use for any security audit of the Rabby codebase, especially non-PR-scoped or release-time audits.
-
rdlugs Skill Local Code ReviewReview uncommitted local code changes (working directory + staged) in a git repo, hunting for bugs, security issues, missing test coverage, and blast radius — everything downstream the change could break — then report findings grouped by severity and lay out an ordered plan to fix them. Use this skill whenever the user asks to review their changes, check their diff, look over what they wrote before committing, sanity-check a patch, trace what a change might affect, or says anything like "review my code", "can you look at this before I push", "did I break anything", "what does this touch", or "check my changes" — even if they don't say the words "code review". Also use it when the user is about to commit, open a PR, or asks whether their work-in-progress looks correct.
-
romainbellande Bundle LefthookSet up lefthook git hooks in a project — commitlint on commit messages, gitleaks secret scanning, and lint/format hooks matched to the project's stack. Use when the user wants to add git hooks, install or configure lefthook, enforce commit message conventions, or wire up commitlint, gitleaks, or pre-commit linting and formatting.
-
rorkai Bundle Audit Asc PrAudit App-Store-Connect-CLI pull requests end to end and fix concrete defects when authorized. Use for PR review, value and blast-radius assessment, issue verification, or requested fixes before merge.
-
rorkai Bundle Triage Asc IssueTriage App-Store-Connect-CLI GitHub issues against current code, CLI behavior, and App Store Connect API support. Use when the user asks to audit, reproduce, classify, label, scope, prioritize, or decide whether an ASC CLI issue should be fixed or implemented.
-
rorkai Bundle Review Wall Of Apps PrsAudit maintainer-side Wall of Apps pull requests in App-Store-Connect-CLI. Use when the user asks to review new app submissions, check Wall PRs for injected or unrelated changes, validate app metadata, approve with a personalized welcome, or merge legitimate Wall entries.
-
rsclarke Skill Hardening Github ActionsAudits and hardens GitHub Actions workflows, composite actions, and Dependabot configuration with zizmor, then adds an ongoing zizmor-action workflow. Use when asked to secure, audit, or remediate GitHub Actions using zizmor.
Audited -
thejdubb02 Skill Owasp AuditAudit application source code against the OWASP Top 10 vulnerability categories. Use when the user mentions 'OWASP,' 'security audit,' 'code security review,' 'vulnerability audit,' 'find vulnerabilities,' 'secure code review,' 'security review,' or wants to check their codebase for common security weaknesses.
-
thejdubb02 Skill Incident TriageGuide rapid triage and initial response to security incidents following NIST SP 800-61 methodology. Use when the user mentions 'incident response,' 'security incident,' 'triage,' 'we've been hacked,' 'breach,' 'compromised,' 'malware detected,' 'suspicious activity,' 'IOC,' 'indicators of compromise,' or needs help handling a security event.
Audited -
thejdubb02 Skill Dependency AuditAudit project dependencies, frameworks, languages, and dev tools for known vulnerabilities, CVEs, and security anti-patterns. Use when the user mentions 'dependency audit,' 'npm audit,' 'CVE,' 'vulnerable packages,' 'supply chain security,' 'outdated dependencies,' 'known vulnerabilities,' 'security advisory,' 'package security,' 'framework vulnerability,' 'is this package safe,' or needs to check whether their stack has known security issues.
-
thericardoli Bundle Zama Protocol DevSkill routing entry point for Zama Protocol development. Use it to decide which Zama skills to load for a concrete task: use zama-fhevm-solidity-core for contract APIs and Solidity patterns; use zama-hardhat-contract-dev for Hardhat-based contract development, testing, and deployment, usually with core; use zama-foundry-forge-fhevm similarly for Foundry/forge-fhevm; use zama-sdk for TypeScript application code that interacts with Zama contracts; combine SDK with core and either Hardhat or Foundry for a complete dApp; use zama-fhevm-security-review for security review.
-
thinkyou0714 Bundle Gh Pr Perm AuditSecurity-first audit of the per-repo GitHub setting "Allow GitHub Actions to create and approve pull requests" (can_approve_pull_request_reviews) across an account. Flags repos where Actions CAN approve PRs — a required-review bypass risk (OpenSSF) — unless you intentionally allow them. Read-only: it never changes settings; it prints the exact gh command for you to run. Use when you ask: "audit Actions PR permissions", "can GitHub Actions approve PRs?", "PR approval setting check", "Actions PR 権限監査", "review-bypass チェック". DO NOT USE FOR: creating PRs, changing branch protection, or writing code.
Audited -
thinkyou0714 Bundle Gh Repo Security AuditOpenSSF-aligned security posture audit across all repos in a GitHub account: default workflow token permissions, allowed-actions policy, branch protection, secret scanning + push protection, and Dependabot alerts. Reports WARN (fixable gaps) vs INFO (opinionated hardening). Read-only by default; the only optional mutation is enabling Dependabot alerts. Use when you ask: "repo security audit", "OpenSSF audit", "are Dependabot alerts on?", "GitHub hardening check", "repo セキュリティ監査", "Actions セキュリティ横断". DO NOT USE FOR: writing code, changing branch protection automatically, or the PR-approval toggle (use gh-pr-perm-audit for that).
Audited -
trugurpala Skill Repo AuditInspect an unfamiliar repository or code area before implementation. Use when stack, conventions, quality tooling, baseline state, ownership boundaries, or risks are not yet established.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include lefthook, owasp-audit, Code Review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.