Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
getnao Bundle Write Context RulesCreate or extend a nao project's RULES.md. Owns the RULES.md template. Use when the user wants to generate the initial RULES.md from synced metadata (called by setup-context), or improve their existing RULES.md. Do not use for first-time scope setup (use setup-context) or for diagnosing existing problems (use audit-context).
-
gocronx-team Bundle Security CheckAudit or harden gocron security across Go, pnpm workspaces, containers, authentication, authorization, secrets, command execution, SSRF, and dependency vulnerabilities. Use for security reviews, vulnerability remediation, Dependabot security alerts, release hardening, or suspected exposure.
-
hainrixz Bundle DoctorAudits an existing PagoKit integration in the current project against the generated per-provider checklist, so it covers every provider in the catalog rather than a hardcoded few. Checks .gitignore covers .env, that env vars are present and use test-key prefixes, that the webhook secret looks valid, that the webhook handler verifies signatures, that the minimum events for the integrated provider are routed, and that PAGOKIT_INTEGRATION.md exists. Used by /pagokit:doctor. Read-only — never writes files.
-
haru3613 Bundle AdviseDiagnose a project's test gaps and name the cheapest next tests. Use after hs-setup, after plugin install, or when someone asks what to test, which framework to add, whether coverage is enough, or to audit the test suite. Triggers: "/advise", "what should we test", "which test framework", "is coverage enough", "audit this project's tests", "quality report".
-
hendriknielaender Bundle Go Turbo Auditgo-turbo-audit
-
hereinthehive Skill UpdateAudit the project's Claude Code setup. Runs the curator (external best practices) and caretaker (internal integrity) subagents in parallel and presents merged findings in plain language.
-
homeassistant-ai Skill Contrib Pr ReviewReview a contribution PR for safety, quality, and readiness. Checks for security concerns, test coverage, size appropriateness, and intent alignment. Use when reviewing external contributions.
-
open-horizon-labs Skill SgMetacognitive oversight. "$sg review" for on-demand evaluation, "$sg init" to set up, "$sg audit" to review decisions.
-
zhanlincui Skill Review LoopOrchestrate a multi-round implementation + review cycle. Use when coordinating a feature that requires implementation (FE/BE), design review (UIUX), security review, and QA verification. Ensures QA findings get routed back for fixes until clean.
-
luckycat133 Bundle UX AuditRun UX walkthroughs and QA sweeps on live web apps using browser automation. Walks through apps as a real user, flags friction points and usability issues, tests CRUD operations, and produces ranked audit reports. Trigger with 'ux audit', 'ux walkthrough', 'qa test', 'test the app', or 'check all pages'.
-
ntholm86 Skill TrailAutomatic egress service for substantive work. Append a structured entry to .acm/audit-trail.md IN THE TARGET REPO ROOT — recording the interpretation, examination, decisions, actions, and reflection. Destination, Improve, Orient, and Probe apply Trail automatically; the operator should never need to invoke it separately. Direct use remains available for consequential work outside those workflows and independent-writer mode.
-
ntholm86 Skill ImproveThe improvement skill. Understand the ask, examine the target, challenge the first read, decide on one change (or argue for redesign, or declare silence), honor the operator's supervision or delegation boundary, act, reflect, record, and report the result clearly. USE WHEN: improve, audit, review, fix, refactor, redesign, evaluate, what would make this better, am I missing something.
-
ipea Skill HumanizeRead-only audit of `.tex`, `.qmd`, or `.md` text for AI-voice tells — boilerplate transitions ("Moreover", "Furthermore", "It is important to note that"), AI-cliché lexicon ("delve", "navigate the complexities", "tapestry", "robust framework"), em-dash overuse, symmetric paragraph shapes, tricolon abuse, hedging stacking, "not only X but also Y" frames, and formulaic openers. Produces a report; does NOT rewrite. Use when user says "humanize", "does this sound like AI?", "check for AI tells", "de-AI this draft", "remove AI voice", "audit my prose for sycophancy", or before journal submission / posting a working paper.
-
skillmedev Skill Curriculum MapperMaps a course's scope and sequence across a term or year - units, weeks, standards coverage with introduced/developed/mastered notation, and Bloom's-level progression - and flags gaps and redundancy. Use when someone asks "map my curriculum for the year", "build a scope and sequence for this course", "audit my course for standards gaps", or is deciding unit order for a semester. Do NOT use for planning a single lesson - use lesson-plan-builder instead; for adapting one lesson to mixed readiness levels in one classroom, use differentiated-instruction.
-
skillmedev Skill Expense And Approval PolicyDrafts a clear, enforceable expense and approval policy - per-category spend limits, a dollar-tiered approval matrix, receipt and documentation rules, 30/90-day submission deadlines, and audit sampling. Use when someone says "write our expense policy", "who should approve what spend", "set reimbursement rules", or is onboarding a finance system or preparing for a compliance review. Do NOT use for building a departmental or personal budget - use budget-builder instead; do NOT use for the monthly close checklist - use month-end-close instead; do NOT use for general internal SOPs outside spend - use process-doc instead.
-
skillmedev Skill Month End CloseGuides finance teams through a controlled month-end close - sub-ledger cutoffs, journal entries in dependency order, full balance-sheet reconciliation, flux analysis, and sign-off - targeting a locked close by business day 5-10. Use when someone asks "help me close the books", "build a close checklist", "our close takes three weeks, how do we shorten it", "what order do the journal entries go in", or is preparing for an audit. Do NOT use for constructing or interpreting the financial statements themselves - use financial-statement-builder instead - or for writing the budget-variance narrative that follows the close - use budget-vs-actual instead.
-
travisboston16 Bundle Igem WikiPlan, write, implement, or audit an entire iGEM team wiki by coordinating project story, wet-lab evidence, modeling, Human Practices, implementation, and site-wide usability. Use for whole-wiki architecture, cross-page consistency, judging readiness, or work spanning multiple iGEM wiki sections; use a domain subskill for a single specialized section.
Audited -
travisboston16 Bundle Igem Wiki StoryPlan, write, implement, or audit the narrative and information architecture of an iGEM wiki, especially Home, Description, Awards, navigation, page introductions, and cross-page storytelling. Use for project framing and site-level comprehension; use a domain skill for technical evidence or Human Practices content.
-
vintlin Bundle Wiki LinksAudit and repair wiki link integrity, argument chain links, and link-layer structural rules across the repository.
Audited -
xileades Skill Pennylane Accounting ExportsProduce Pennylane accounting exports for an accountant or an audit: FEC (French fiscal export), general ledger, analytical general ledger, trial balance, and reading fiscal years. Use when the user asks for a FEC, a general ledger, a trial balance, an export for the accountant, closing a fiscal year, or "get me the accounts for that period". Load the pennylane-access skill first.
-
gabrielamz Bundle Webanatomy SetupThe foundation step for the whole Web Anatomy pack. Optional context setup. Use when the user says set up Web Anatomy, create context, start a landing page project, capture product context, benchmark my category, or prepare the benchmark skills. Also offer it as an optional preflight when another Web Anatomy workflow lacks product context and better recommendations would depend on ICP, industry, locale, competitors, conversion goal, proof assets, priority pages, or the voice and tone the rework copy should use. Do not require setup before find-examples, research-best-practices, write-page, or audit-page; those skills should continue with conservative assumptions if the user wants speed. Writes `.agents/webanatomy-context.md` as shared context.
-
hahaknight Skill Bug HunterMUST USE when debugging, fixing a bug, 排查/调试/修 bug/为什么报错/不工作, or when tests fail unexpectedly. Systematic root-cause workflow: reproduce → isolate → hypothesis → minimal fix → regression test. Forbids shotgun fixes and "fix around the symptom". Free sample of claude-skills-pro - 8 more Pro skills (security-audit, refactor-surgeon, perf-profiler, api-designer, db-migration-safe) + 11-chapter CN handbook. Buy / free review copy: github.com/Hahaknight/claude-skills-pro/issues/1
-
hahaknight Skill Test ForgeMUST USE when writing tests, 补测试/write tests/单元测试/test coverage, or when asked to verify a module with tests. Produces test suites that actually kill mutants: edge cases, boundaries, failure paths, property tests — not happy-path theater. Free sample of claude-skills-pro - 8 more Pro skills (security-audit, refactor-surgeon, perf-profiler, api-designer, db-migration-safe) + 11-chapter CN handbook. Buy / free review copy: github.com/Hahaknight/claude-skills-pro/issues/1
-
hahaknight Skill Pr ReviewerMUST USE when reviewing a pull request, reviewing changes, 审查代码/review/ 看看这个改动有没有问题, or before committing significant work. Performs a systematic 7-dimension review (correctness, security, performance, tests, API contract, error handling, maintainability) instead of a superficial read. Works on staged diffs, branch diffs vs main, or PR numbers via gh. Free sample of claude-skills-pro - 8 more Pro skills (security-audit, refactor-surgeon, perf-profiler, api-designer, db-migration-safe) + 11-chapter CN handbook. Buy / free review copy: github.com/Hahaknight/claude-skills-pro/issues/1
Audited -
hahaknight Skill Commit CraftMUST USE when writing git commit messages, 提交/commit/写提交信息, or when the user says commit this / 帮我提交. Groups changes into logical commits, writes conventional-commit messages that explain WHY, and never commits secrets or unrelated files. Free sample of claude-skills-pro - 8 more Pro skills (security-audit, refactor-surgeon, perf-profiler, api-designer, db-migration-safe) + 11-chapter CN handbook. Buy / free review copy: github.com/Hahaknight/claude-skills-pro/issues/1
-
hahaknight Skill Feature SpecMUST USE before implementing any non-trivial feature (new endpoint, new module, new user-facing behavior) or when the user describes a feature vaguely — 先出方案/需求不清/design first. Converts vague asks into a 1-page spec with scope, contracts, edge cases, and test scenarios — getting alignment BEFORE code is written. Free sample of claude-skills-pro - 8 more Pro skills (security-audit, refactor-surgeon, perf-profiler, api-designer, db-migration-safe) + 11-chapter CN handbook. Buy / free review copy: github.com/Hahaknight/claude-skills-pro/issues/1
-
hahaknight Skill AI Code ReviewerMUST USE when reviewing AI-generated code (Claude/ChatGPT/Copilot output), AI 写的代码/生成的代码能上线吗, or when a change was produced fast and unverified. Targets the characteristic failure modes of AI-generated code: plausible-but-wrong, hallucinated APIs, silent behavior drift, security theater, and over-engineering. Free sample of claude-skills-pro - 8 more Pro skills (security-audit, refactor-surgeon, perf-profiler, api-designer, db-migration-safe) + 11-chapter CN handbook. Buy / free review copy: github.com/Hahaknight/claude-skills-pro/issues/1
-
hahaknight Bundle Changelog ReleaseMUST USE when cutting a release, writing CHANGELOG entries / release notes / 发版/版本号, or deciding the next semver. Produces user-facing notes grouped by impact and bumps versions by the actual contract delta. Free sample of claude-skills-pro - 8 more Pro skills (security-audit, refactor-surgeon, perf-profiler, api-designer, db-migration-safe) + 11-chapter CN handbook. Buy / free review copy: github.com/Hahaknight/claude-skills-pro/issues/1
Audited -
joaomonteiro100 Bundle Heuristic EvaluationRuns an expert usability inspection (heuristic evaluation) of a digital product — reviewing screens, flows, or a whole interface against established usability principles, logging issues with a consistent severity rating, and producing a prioritized findings report with recommendations. Use this whenever the user wants to audit, review, critique, or evaluate the usability of an interface without recruiting users; wants a "heuristic evaluation", "UX audit", "usability review", "expert review", or "cognitive walkthrough"; wants to find usability problems in a design, prototype, or live product themselves; or asks which usability principles a screen violates. This is expert-based inspection with NO participants — if the user instead wants to test with real users, that is moderated usability testing, a different method.
-
max-levitskiy Bundle Analyze DensityAnalyze text for information density, semantic repetition, and filler content. Two modes: "score" (read-only audit with per-method breakdown) and "fix" (rewrite to remove redundancy while preserving all unique information). Dispatches 7 core analysis methods (plus genre-targeted ones) as parallel subagents, then aggregates results into a composite score and actionable report. Use when asked to "check density", "find repetition", "remove AI slop", "deduplicate this text", "is this repetitive", "information density", "compress this writing", "tighten this doc", or whenever text feels bloated or AI-generated. Also use proactively when reviewing docs or PRs that contain suspiciously fluffy prose.
-
mrtoaster13 Bundle Pre PushPre-push orchestrator — detect Python/Node stack, then run simplify, review, security, test, commit as gated stages (retry flaky network, chmod +x scripts, stop on real failures). Use when ready to push to main, or on "pre-push", "clean up before pushing", "polish and commit", "finalize", "ship it".
-
postttt Skill Pre PushPre-flight safety gate that checks whether the project is actually safe to commit/push to GitHub (or any remote) RIGHT NOW. Use when the user asks "is this ready to push?", "can I commit this?", "check before I push", "did I leave any secrets in", "ready for GitHub?". Inspects the real git state — staged diff, tracked files, source, and history — for secrets/API keys, .env/.venv being tracked, PII, leftover debug/conflict markers, and .gitignore gaps. Read-only; reports a clear ready/blockers verdict and defers to the gitignore and security-audit skills for fixes.
-
crux-cli Skill Review PrReview open PRs: CI gate, code review, security review, docs review. Approve or request changes.
-
cyberuni Skill Validate SkillValidate a SKILL.md file for structure, quality, and security before committing or publishing. Use this skill when reviewing a new or modified skill — catches broken references, vague triggers, baked-in assumptions, scope creep, and security risks in one pass.
-
datadog Skill Test ModuleTest a pathrunner exploit module against a deployed pathfinding-labs scenario. Supports iterative fix-and-retry — the skill can loop up to N times, diagnosing pathrunner-side failures and applying fixes between runs.
-
datadog Skill External Pr CI TriggerTrigger CI for an external contributor's pull request by mirroring their fork branch onto DataDog/saluki under an `<owner>/<branch>` name. External forks don't run CI by default for security reasons; this skill lets an authorized maintainer push the fork's branch up to the main repo so the PR's CI checks attach to a trusted branch. TRIGGER when: user asks to run CI on an external/contributor PR, push an external branch for CI, mirror a fork branch, or invokes `/external-pr-ci-trigger`. DO NOT TRIGGER when: user wants to run CI on their own branch or on an internal PR — those run CI automatically.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include review-loop, write-context-rules, security-check. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.