Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
unkeyed Skill Refreshing Docs ScreenshotsChecks and refreshes product documentation screenshots from the real local dashboard using DashboardScreenshot declarations and data-docs-target markers. Use when asked to audit all docs screenshots, refresh a specific screenshot, or perform a monthly screenshot check.
-
unlayer Bundle Unlayer ConfigConfigures Unlayer's email, page, popup, and document builders — feature flags, appearance, theming, merge tags, design tags, display conditions, special links, HMAC security, file storage, image uploads, localization, custom fonts, and validation. For the standalone Image Editor, use unlayer-image-editor.
-
viacheslav-tronko Skill Task VerificationHypothesis-driven task-correctness verification for AI coding agents on legacy codebases. Use WHENEVER user asks to verify, audit, or pre-flight a task artifact (IMP, RCA, Plan, Implementation, Fix, Jira ticket) before submission — /verify, /verify-task, /gate2, "verify this", "verify the RCA", "verify the implementation", "is this fix correct", "double-check my plan", "audit before merge", "pre-flight before PR", "Gate 2 / Pre-Send check", "find what's wrong with my IMP", or pastes RCA-/IMP-/PLAN-/FIX-*.md asking "verify". Falsification-first, evidence-bound, anti-hallucination — Architecture Pre-Read MANDATORY for multi-layer artifacts; Initial Intuition + KNOWN/OBSERVED/UNKNOWN anti-anchoring table BEFORE reading artifact reasoning; Killer Hypothesis FAIL-FAST; CoVe factored independent re-read; Stale-vs-Hallucinated decision (file shifted vs never existed); Pre-Claim Symbol Existence Check (Grep/Bash/WebSearch every external method/class/flag/pattern/CVE the artifact claims); Tier-budgeted hypotheses (5–3
-
specialone0007 Bundle Test Gap AuditRun a read-only audit for missing, weak, stale, or mis-scoped test coverage. If the user does not name a scope, audit the full repository and identify important code paths, routes, features, services, workflows, and contracts that lack proper tests. If the user names a feature, PR, branch, route, workflow, service, bug fix, API, security-sensitive path, or risky code change, focus only on that specific scope. Use when the user asks what tests are missing, whether coverage is enough, what regression tests to add, or how to prove a change is safe. This is not a general bug audit; use feature-audit for product readiness defects and security-audit for security risks.
Audited -
specialone0007 Bundle Docs Sync AuditRun a read-only documentation drift audit for a feature, PR, branch, release, API, configuration change, workflow, CLI, package, or repository area. Use when the user asks whether docs are stale, missing, inconsistent with code, or need updates after code changes. Checks README files, setup guides, API docs, env docs, changelogs, examples, comments, generated docs, and user-facing instructions. This is not a general code review; use feature-audit for product bugs and readiness risks.
Audited -
specialone0007 Bundle Repo Health AuditRead-only repository health and organization audit for finding naming drift, unclear file or folder placement, weak module boundaries, dead code, duplicate code, repeated patterns that should become shared helpers, duplicate concepts, inconsistent conventions, oversized files, circular dependencies, and structural issues that make a codebase harder to navigate or more likely to become spaghetti over time. Use when the user asks to review repo organization, folder structure, naming, architecture hygiene, codebase structure, module layout, dead code, duplicate code, reuse opportunities, or whether a repository is getting messy.
Audited -
specialone0007 Bundle Feature BrainstormBrainstorm evidence-grounded product, UX, workflow, and technical improvement ideas for a clearly named feature, route, workflow, product surface, or PR. Use when the user asks what could be added, improved, simplified, expanded, polished, automated, differentiated, or made more valuable. This is not a bug audit; use feature-audit for defects, regressions, launch blockers, missing tests, or production-readiness risks.
-
ssheleg Bundle Google AuthUse when a server authenticates to Google in a Node.js or Python application — OAuth 2.0 flows, verifying Google ID tokens server-side, service account authentication and keys, Application Default Credentials, Workload Identity Federation, API keys, or working with google-auth-library (Node.js) or google-auth (Python). Covers server-side ID token verification and security best practices. Triggers - "google auth", "OAuth 2.0 Google", "google-auth-library", "ADC", "Application Default Credentials", "service account", "Workload Identity Federation", "Google ID token", "verifyIdToken", "GOOGLE_APPLICATION_CREDENTIALS", "Google SSO", "авторизация Google", "сервисный аккаунт", "ключи сервисного аккаунта", "проверить ID-токен". For end-user web sign-in only, use the google-signin skill instead.
-
ssheleg Bundle Crypto PaymentsUse when adding or auditing crypto checkout, crypto top-up, or payment webhooks — where a payer sends the wrong amount, a webhook arrives more than once, and the rate moves between quote and transfer. Covers invoice lifecycle and status mapping, webhook signature verification and the JSON-escaping trap, idempotent processing, IP allowlisting behind a proxy, CSRF exemption for callback routes, the conversion buffer, reconciliation fields, credit waterfalls, refund and AML-hold states, local development with a tunnel and signed mock callbacks, a test matrix and a security checklist. Triggers - "crypto payment", "crypto checkout", "pay with crypto", "USDT payment", "TRC20", "payment webhook", "IPN", "webhook signature", "underpayment", "Heleket", "NOWPayments", "приём криптоплатежей", "оплата криптой", "вебхук платежа", "недоплата". Not for card billing — use stripe-billing.
-
ssheleg Bundle UX AuditUse when verifying the codebase against the UX scenario base - runs a batched, evidence-backed scenario audit and writes a versioned report to docs/ux/audits/. Triggers - "ux audit" / "UX-аудит", "run the scenarios" / "прогони по сценариям", "check all buttons/states/errors", pre-release UX verification, scenario compliance check.
-
t4sh Bundle Eleventy NunjucksEleventy v3, Build Awesome v4 prerelease, and Nunjucks operating guide for static-site authoring, templates, build pipelines, migrations, and security review. Use when the user asks to "create an 11ty page", "add a Nunjucks filter", "fix my layout chain", "review my .njk template", "set up Eleventy", "migrate to Build Awesome", or "audit my static site"; when `package.json` includes `@11ty/eleventy` or `@awesome.me/buildawesome`; when paths include `.eleventy.js`, `eleventy.config.js`, `.njk`, `.11tydata.js`, `.data.js`, `.11ty.js`, or `.server.js`; or when debugging data cascades, filters, shortcodes, async Nunjucks, autoescape, or static-site security.
-
team-attention Skill Doc DriftUse this skill when the user wants to audit the memory and documents Claude Code loads into context — CLAUDE.md (user global + project + nested), MEMORY.md, @imports, .claude/skills, .claude/agents, .claude/commands, installed plugins — and detect three kinds of issues: outdated claims, mutually contradictory statements, and risky-or-ambiguous wording. Produces a prioritized improvement list at `.drift-reports/`. Zero config. Trigger phrases: "doc drift", "memory drift", "memory audit", "context drift", "docs audit", "문서 점검", "문서 감사", "메모리 감사", "메모리 점검", "outdated 문서", "문서 충돌".
-
team-attention Bundle Check HarnessAudit a Claude Code project's development readiness: runtime and LSP, context, permissions, hooks, tests/CI, skills and independent verification. Distinguish configured, observed working, missing and unverified capabilities. Use for /check-harness, 하네스 점검, LSP 설치 확인, or 개발 환경 종합 점검.
-
tenfoldmarc Skill Tenfoldmarc 6Tenfold AI Step 6: Your First Win. Recaps everything that's been set up, then gives the user 4 options for their first real task — website audit, landing page build, competitor analysis, or their own idea. Actually executes the task using installed tools.
-
yzhao062 Bundle News SearchSystematic web search for news, media, policy, and industry coverage of FORTIS Lab publications, tools, and research. Use when the user asks for a news audit, media coverage check, broader impact evidence, or visibility search for their work.
Audited -
yzhao062 Bundle Citation AuditCitation Affiliation Audit
-
z1nun Skill Buildcrew QAQA a project with buildcrew quality roles — browser QA via Playwright, 3-lens QA audit on git diffs, or a 0-10 code health score. Use when the user asks to test the site, audit code quality, run QA, or get a health check.
-
z1nun Skill Buildcrew SecurityRun a buildcrew security audit — OWASP Top 10 + STRIDE threat modeling with a fix loop for critical findings. Use when the user asks for a security audit, vulnerability scan, or security check.
-
zhiming33416 Bundle Top Cs ResponsePrepare, audit, or revise evidence-grounded author responses, rebuttals, discussion replies, decision-email triage, cover letters, revision packages, and LaTeX response templates for WWW, ICLR, ICML, NeurIPS, CVPR, ACL, or a generic computer-science venue. Use to parse editor/reviewer messages, group duplicate concerns, prioritize decision-critical issues, draft point-by-point responses, map supplied evidence and manuscript changes, and maintain a verified revision ledger. Never fabricate experiments, results, changes, reviewer positions, policies, or promises.
-
zhiming33416 Bundle Top Cs ReviewerPerform a confidential pre-submission audit of a computer-science manuscript against WWW, ICLR, ICML, NeurIPS, CVPR, ACL, or generic top-conference expectations. Use for reviewer-style assessment, rejection-risk analysis, claim verification, experimental and reproducibility audits, venue or track fit, anonymity checks, paper readiness, and actionable revision priorities. This is an author-side simulation, not an official review and not a substitute for domain experts.
-
hazat Skill Manifest Review RubricCode review guidelines and quality rubric for Manifest projects. Covers framework conventions, feature structure, schema quality, and security. Shared by the reviewer subagent and available for manual reviews. Use when reviewing code changes.
-
omacom Skill Better Auth Security Best PracticesConfigure rate limiting, manage auth secrets, set up CSRF protection, define trusted origins, secure sessions and cookies, encrypt OAuth tokens, track IP addresses, and implement audit logging for Better Auth. Use when users need to secure their auth setup, prevent brute force attacks, or harden a Better Auth deployment.
-
omacom Skill Two Factor Authentication Best PracticesConfigure TOTP authenticator apps, send OTP codes via email/SMS, manage backup codes, handle trusted devices, and implement 2FA sign-in flows using Better Auth's twoFactor plugin. Use when users need MFA, multi-factor authentication, authenticator setup, or login security with Better Auth.
-
ethereum Skill Infer Eip LayerClassify an EIP's client layer (EL or CL) and set the `layer` field on EIPs that are missing it. Use when active fork EIPs lack a layer (e.g. audit-eips reports "missing layer"). Combines a deterministic `requires`-dependency signal with a semantic read of the EIP's substance; auto-applies only when both agree, otherwise flags for human review.
-
ethereum Skill Draft Eip NarrativeDraft the laymanDescription, benefits, and tradeoffs fields for an EIP that already exists in src/data/eips/. Use when audit-eips reports missing narrative fields on EIPs that otherwise have complete metadata. For adding a brand-new EIP to the tracker, use convert-eip instead.
-
factorial-io Skill Security AuditUse when conducting security reviews, investigating vulnerabilities, or creating security documentation - provides systematic methodology for code audits with severity assessment, dual documentation patterns (client + internal), and acceptance-focused ticket creation
-
frankglendon Bundle Research Survey QcReview a three-column survey workbook and export an audit sheet while preserving input cells. Use for the portfolio survey QC workflow.
Audited -
ftshare-lab Skill Canvas**The primary skill for terminal TUI components.** Covers spawning, controlling, and interacting with terminal canvases. Use when displaying financial candlesticks, market tables, security snapshots, news lists, bar/line charts, or dependency DAGs.
-
ftshare-lab Skill Security SnapshotInteractive Ratatui overview of one FTShare A-share security with market, performance, valuation, and capitalization sections. Use when showing a mainland stock snapshot or asking the user to focus analysis on one metric group.
-
zebbern Skill Codex DelegationUse when a coding task would benefit from delegating work to Codex in the background — a deep independent second opinion, security or architecture analysis, or a parallel implementation running while the session continues. Lets Claude drive the codex companion itself (task, review, status --wait, result) without the user typing /codex:* commands.
-
youki0p0 Skill Jen ReviewJen review mode for acceptance review, UX/product/security/contrarian review, and PR readiness checks.
-
zaxbysauce Skill Tech Debt CI ReviewDeep technical debt and CI stability audit for identifying test theater, missing or mis-scoped tests, actual and potential test failures, flaky-test risk, dependency/toolchain brittleness, and structural debt that prevents PRs from going green safely.
-
arcjet Skill Protect RouteDeprecated: use the `arcjet` skill instead. Adds security protection to a server-side route or endpoint — rate limiting, bot detection, email validation, and abuse prevention.
Audited -
dajo-code Bundle SecuritySecurity auditing patterns for Midnight Network smart contracts and dApps. Use when reviewing code for vulnerabilities, privacy leaks, cryptographic weaknesses, or performing security audits.
-
dmnote-app Skill Codebase Memory QualityThis skill should be used when the user asks about "dead code", "find dead code", "detect dead code", "show dead code", "dead code analysis", "unused functions", "find unused functions", "unreachable code", "identify high fan-out functions", "find complex functions", "code quality audit", "find functions nobody calls", "reduce codebase size", "refactor candidates", "cleanup candidates", or needs code quality analysis.
-
vitoriarntrindade Bundle Spec Driven WorkflowRun a change through the full lifecycle in this repository — classify it, specify it, branch, implement, verify with the gate, review it with the right specialist, and stop at the human acceptance gate. Use whenever a feature, fix, refactor or security change is requested and it is not obviously trivial.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include better-auth-security-best-practices, google-auth, crypto-payments. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.