Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
dataojitori Skill Memory Audit记忆审计入口。当我主动决定审视记忆质量时,先读此文件判断应使用哪个子技能。
-
dataojitori Skill Memory Audit Belief Duel信念对决。当父子节点内容冲突、或两条你都认可的记忆逻辑上不能并存时使用。
-
dataojitori Skill Memory Audit Dead Data Purge死数据清洗。当一条记忆读不读你的行为都不会变、感悟没有现实锚点时使用。
-
dataojitori Skill Memory Audit Discoverability可发现性审计。当disclosure写法有问题、parent放错、alias缺失、子节点过多时使用。
-
dataojitori Skill Memory Audit Node Decomposition节点分解。当一个节点体积过大、或塞了多个不相关概念导致disclosure无法覆盖时使用。
-
dataojitori Skill Memory Audit Pattern Extraction模式提取与失效解药分析。当发现多条记忆在讲同一个教训,或发现自己在一而再再而三地犯同样的错误时使用。
-
dbosk Skill Honor AuditAudit a draft KTH submission for honor-code risk — copied content, missing citations, undisclosed AI use, group-attribution gaps, attendance-record issues.
-
defectdojo Bundle Import ScansUpload scanner output or an SBOM into DefectDojo Pro. Use when the user has results from a security scanner and wants them in DefectDojo, or says import this scan, upload these results, push the Semgrep or Trivy or ZAP or Snyk or Nuclei or Burp output to Dojo, ingest this SBOM or CycloneDX or SPDX file, or reimport the latest scan. Trigger even if the word DefectDojo never appears, for example "get these scan results into our vulnerability tracker" or "load this JSON from the scanner". Handles product and engagement creation, import versus reimport, and background processing.
-
defectdojo Bundle Connection DoctorDiagnose and repair the connection between Claude Code and DefectDojo Pro. Use when DefectDojo tools are missing or failing, when setting up or configuring DefectDojo for the first time, when a token is rejected or expired, when the user asks whether DefectDojo is connected or working, or when any other DefectDojo skill stops with a connection, authentication, permission, or edition error. Trigger even if the word DefectDojo never appears, for example "my security findings tools disappeared", "why do I get 401 from the vuln tracker", "the scanner database says forbidden", or a pasted "Token authentication failed" error.
-
bayramannakov Bundle Why TreeDiagnose a hard problem by building an evidence-graded "Why Tree" - a Goldratt Current-Reality Tree that fans many AI agents across the problem's branch-space, grades every node by the kind of evidence behind it (validating measured numbers' pipelines before trusting them), tries to refute its own load-bearing branches, and converges on the ONE system constraint plus the cheapest test that would prove it. Use when someone asks "why is X happening / why are we falling short of a goal", wants a root-cause analysis with real rigor (not a 5-minute 5-Whys), needs to find the real bottleneck before spending build effort, or asks to "stress-test our diagnosis" / "build a current-reality tree". Also runs an **Idea Audit** - evaluating a product/feature idea by first diagnosing the problem it claims to solve (idea quarantined from the swarm), then judging the idea against the located constraint - trigger on "evaluate my product idea", "should I build X", "would anyone pay for this", "would my product have solved this"
-
bayramannakov Bundle Constraint FinderFind the ONE binding constraint in a flow/process system using Goldratt's Theory of Constraints, classify it as a RESOURCE or (usually) a POLICY, and return the 5 Focusing Steps as concrete actions — Exploit and Subordinate before Elevate. Judges every move against the goal in throughput terms (Throughput up, Inventory down, Operating Expense down). Triggers on "find my constraint", "what's my bottleneck", "theory of constraints", "5 focusing steps", "where's the pile", "найди ограничение", "где узкое место", "теория ограничений", "пять шагов фокусировки". Refuses to optimize non-constraints, to Elevate before Exploit/Subordinate, to proceed without a goal, or to force a single constraint on a demand-constrained or exploratory system.
-
beforemerge Bundle Beforemerge Supabase ReviewComprehensive code review rules for Supabase applications including RLS security, auth patterns, query performance, migration workflows, and type safety. Use this skill when reviewing, writing, or refactoring Supabase-backed code — especially before merging pull requests. Triggers on tasks involving code review, PR review, security audit, performance review, or quality checks for Supabase/PostgreSQL projects.
-
beforemerge Bundle Beforemerge Wordpress ReviewComprehensive code review rules for WordPress plugin and theme development. Covers security anti-patterns, performance pitfalls, architecture mistakes, and code quality issues. Use this skill when reviewing, writing, or refactoring WordPress/PHP code — especially before merging pull requests. Triggers on tasks involving code review, PR review, security audit, performance review, or quality checks for WordPress projects.
-
beforemerge Bundle Beforemerge Fullstack Architecture ReviewCode review rules for DRY/SOLID layered architecture in fullstack TypeScript applications. Covers dependency direction, service/repository patterns, factory injection, domain entities, security hardening, performance optimization, and code quality patterns. Use this skill when reviewing, writing, or refactoring fullstack TypeScript code with layered architecture — especially before merging pull requests. Triggers on tasks involving code review, architecture review, SOLID principles, clean architecture, or quality checks for fullstack TypeScript projects.
-
benmarte Skill AuditScan the codebase for deficiencies, generate a prioritized report ranked by efficiency (points per iteration), and optionally transition into focused improve loops area-by-area until the user stops or the score hits 100.
-
bestiaya Skill Ctx CheckupWeekly cache audit — use on "weekly checkup", "where did the tokens go", "audit session costs", or /ctx-checkup; runs cache-audit, flags sessions over the pre-registered lines, backfills archive pointers in case files. Also triggers on Chinese — 用户说"周检""查一下会话花费""哪些会话该收口了""跑一下缓存审计""这周 token 都花哪了",或显式 /ctx-checkup 时用。
-
bithumb-official Skill Bithumb SystemInspect Bithumb local audit logs (operation/trade history) and run connection and credential diagnostics. The diagnose command needs no auth to test credentials; audit reads local logs only. 빗썸 로컬 감사 로그 조회, 연결·인증 진단, 활성 모듈 상태 확인을 처리합니다. 감사 로그·거래 로그·시스템 진단·연결 상태 관련 요청에 사용하세요.
-
breferrari Skill Review PrsRun multi-persona code review (PO, Senior Eng, Security, Docs) on open PRs. Pass PR numbers or omit to auto-detect from recent branches. Runs 2 rounds by default.
Audited -
aident-ai Bundle Aident SkillUse Aident Loadout to connect your AI agents to 1,000+ real-world apps and tools like Gmail, Slack, Linear, Notion, Firecrawl, and Fal, unlock 27,000+ executable actions, and track full audit history so your agents can get real work done reliably.
Audited -
alexsmedile Bundle Repo GuardrailsGuard a named Git/GitHub operation against material repository policy; audit repository posture; propose exact changes from selected findings; or apply an explicitly approved set of named proposal item IDs. Covers branch protection, reviews, checks, secret scanning, push protection, environments, scoped-secret metadata, and security automation. Not for executing Git operations, generic configuration requests without selected findings, cleanup, documentation, or ambiguous workstream selection.
-
alonbaron Skill Review SwarmLocal, free, multi-specialist review of a diff: parallel Claude subagents (correctness, security/trust boundaries, data/perf, architecture-altitude, ponytail-simplicity, tests/failure paths), adversarial verification, dedup, ranked file:line report. Use proactively when asked to review, check, or assess a diff, branch, or PR — and after any non-trivial implementation, before the PR. Also on "review-swarm", "swarm review", "deep review". Not for trivial diffs, not when asked to fix rather than review, not when security alone is the whole ask (built-in "security-review"), and not when "/code-review" is named explicitly.
Audited -
and3r817 Bundle Github CLIThis skill should be used when working with GitHub CLI (gh) for repository management, pull requests, issues, API access, GitHub Actions, or automation workflows. Provides comprehensive guidance on gh command patterns, security considerations, and best practices.
-
arbi-elezi Bundle Judgment ChainEmperor Time's pinky chain — the rule staked into the heart. Router for five aspects: gatekeeping (opening gates G0–G5 on evidence), claim audit (the G4 scientific-method sweep), self-critique (the prosecutor protocol), hetero-critique (borrowed prosecutors from other agents), and verdicts-and-breaches (rulings, re-entry, the Stake of Retribution). Use at every gate, before any delivery, when reviewing work, or when a vow breach is suspected. Load one aspect file at a time per the Invocation Ritual.
-
exiao Bundle Document RestructureReorganize a document into new sections while preserving the author's exact words: SOUL.md, constitutions, READMEs, specs, plans, style guides. Use when the user says 'put my words into new sections', 'use the exact same words', 'reorganize this', 'what if the headers were X', 'try a different structure', or rejects your rewrite because the LANGUAGE is bad rather than the idea. Restructure is not editing and not rewriting: not one sentence may change. For improving the prose itself use writer or evaluate-content; for scoring a SOUL.md use soul-md-audit.
-
farfarfun-skills Bundle Bash Service GuideDesign, audit, standardize, or refactor Bash-managed service lifecycle scripts / Bash 服务启动停止脚本. Use when Codex needs to create, review, debug, or revise `scripts/setup.sh`, per-service startup or shutdown scripts, `publish` or package installation actions, `start` vs `run` behavior, service and environment selection, port variables, `.run/` logs and PID files, interactive menus, or production start commands that must run repository-installed formal packages instead of development source.
-
florianbruniaux Skill Analyze Github ProfileUse when analyzing a GitHub profile through the lens of its author's objective (build a flagship, raise funds, get hired, run a business). Reads repos, pinned items, contribution timeline and commits, then produces a structured profile sheet. Triggers on "analyse ce profil GitHub", "what does this GitHub profile say", "audit my github".
-
ghosttypes Bundle Python Best PracticesProduction-ready Python DOs and DON'Ts for engineers. Covers code quality, type hints, error handling, async patterns, testing, security, performance, logging, and data validation. Use when writing Python code that needs to be production-ready, reviewing Python code, refactoring legacy Python, or answering questions about Python best practices. Targets Python 3.12+.
Audited -
rorkai Skill Asc WorkflowDefine, validate, run, resume, and audit repo-local multi-step automations with current `asc workflow` and `.asc/workflow.json`, including step outputs and safe release/TestFlight workflows.
-
teamtinvio Bundle Jaz JobsUse this skill for recurring accounting workflows — month/quarter/year-end close, bank reconciliation, GST/VAT filing, payment runs, credit control, supplier recon, audit prep, fixed asset review, and Singapore Form C-S tax computation. 12 job playbooks that sequence real platform tools into complete business processes. Also use when the user mentions closing the books, period-end, tax filing, or any operational accounting task.
-
zurybr Skill Sanitize Git RepoGuide for sanitizing git repositories by identifying and replacing sensitive information such as API keys, tokens, and credentials. This skill should be used when tasks involve removing secrets from codebases, sanitizing repositories before sharing, or replacing sensitive values with placeholders. Applies to tasks involving secret detection, credential removal, or repository cleanup for security purposes.
-
2233admin Bundle Interface ReviewUser-invoked interface review of a change rather than a screen: uncommitted work, the current branch, or a pull request. Resolves the change scope, expands it to the surfaces it affects, reads both sides of the diff, and classifies every finding as introduced, a regression, or pre-existing, then hands the review to better-interface for domain routing, severity, and the verdict. Covers interface quality, not correctness, tests, or security. Supports quick and full review modes. Triggers on interface-review, review my branch, review my PR, review the diff, review my changes, review before pushing, design regression check, changed files interface review.
-
chinhquach303 Skill Pci ComplianceImplement PCI DSS compliance requirements for secure handling of payment card data and payment systems. Use when securing payment processing, achieving PCI compliance, or implementing payment card security measures.
-
0xcryptj Bundle AgentsecSenior-level defensive security auditing and remediation for vibe-coded and AI-assisted software projects. Use AgentSec to understand a repository efficiently, review application and server security, identify vulnerable or malicious dependencies, reason about architecture and least privilege, propose secure code rewrites, apply safe fixes, and verify the result with current security intelligence and deterministic tools.
Audited -
0xcryptj Skill Server Hardening ReviewReview a local Linux host or authorized server exposure for patch state, listening services, SSH, firewall, permissions, containers, and web roots. Use it when deployment or host hardening is part of the security scope.
Audited -
0xcryptj Skill Repository Security ReviewReview a local repository for architecture risks, vulnerable dependencies, secrets, unsafe source patterns, and deployment weaknesses. Use this capability when a project needs a defensible source and supply-chain security baseline.
Audited -
0xcryptj Skill Remediation And VerificationTurn AgentSec evidence into small, root-cause fixes with focused regression tests and a retest record. Use after an audit identifies a confirmed issue, security design gap, or high-confidence dependency risk.
Audited
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include judgment-chain, analyze-github-profile, memory-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.