Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
9heaven Bundle Linkedin Profile AuditUse when auditing or rewriting a founder, creator, or influencer LinkedIn profile so visitors convert into followers, leads, and clients. Scores every section against a buyer-journey rubric and rewrites the weak ones.
-
9heaven Bundle Linkedin Company Page AuditUse when auditing or rebuilding a LinkedIn company page for a small business, agency, or startup so it earns followers, credibility, and inbound leads. Covers setup, copy, content engine, and the founder-to-page traffic loop.
-
dolibarr Skill Skill Doli Code ReviewReviews Dolibarr PHP code for compliance with coding standards and security best practices, and fixes identified issues. Use when the user asks to review, audit, fix, or update code for Dolibarr, or mentions code quality, security vulnerabilities, or PSR-12 compliance.
Audited -
doorkeeper-gem Skill Security ReviewVerify that code changes do not introduce OAuth security vulnerabilities. Use when modifying token handling, client authentication, scope validation, redirect URI checks, secret comparison, or grant flows in Doorkeeper.
-
dragoon0x Skill Spacing AuditSpacing consistency and grid adherence analysis
-
edenfunf Skill SecurityProject-wide security rules for handling untrusted input, secrets, and database access.
-
whatifwedigdeeper Skill Security AuditSecurity Audit: $ARGUMENTS
-
plipowczan Skill SecurityEnforces security best practices
-
galando Skill SecurityEnforces security best practices
-
edmonddantesj Bundle Aoi Openclaw Security Toolkit CoreAOI OpenClaw Security Toolkit (Core)
-
ellehelvig Skill Fairness Audit PrepSet up the disparate impact test plan, thresholds, and monitoring template for any HR AI use case that scores, ranks, filters, or recommends people. Use when someone asks "how do we test this for bias," "what's a four-fifths check," "set up fairness monitoring," or before go-live on any scoring or ranking tool.
-
kklimuk Skill Codebase ReviewFull codebase audit — architecture, structural health, technical debt. Use when the user asks for a 'codebase review', 'architecture review', 'codebase audit', 'full review', 'engineering critique', 'refactoring plan', or 'what would a senior engineer think of this codebase'. Do NOT use for reviewing a PR or branch diff — that's /code-review.
-
kklimuk Skill Security ReviewReview code for security vulnerabilities. Use when the user says 'security review', 'security audit', 'check for vulnerabilities', 'pentest the code', 'OWASP check', or any variation of wanting a security assessment.
-
kreuzberg-dev Skill Regen AuditTreat running `alef generate`/`alef all`/`alef verify` in a consumer repo as an audit, not a build step. Use this skill whenever you run a regen, read its log or diff, or investigate "the fix didn't work" after regenerating a consumer repo's bindings.
Audited -
kreuzberg-dev Skill Binding AuditAudit bindings for coverage gaps — verify every public Rust item is exposed across all generated language bindings. Use this skill any time you need to check that a function/type is present in every target language, audit intentional exclusions, or investigate missing bindings in one or more languages. Covers the full audit flow: config review, attribute scan, item enumeration, cross-binding diff, gap reporting, and triage (alef vs Alef-owned workflow/action vs consumer config).
Audited -
kyungseo Bundle Docs Claim CheckCheck whether the claims in public-facing documentation (README, release notes, install/usage docs) are supported by the evidence the user provides — files, manifests, logs, and command outputs supplied in the conversation. Produces per-claim findings with a confidence label (verified / unsupported / stale-suspected / needs-human) and an explicit "input scope reviewed" statement. Advisory only. Use when the user asks to fact-check docs, verify a README against a repo, audit release notes, or find stale or overstated documentation claims. Do NOT use for standalone code review or bug hunting, security audits, fix/patch generation, or pure command-execution tasks. When such requests are mixed with an eligible claim-check, still use this skill for the claim-check portion and decline only the out-of-scope part — by contract it does not execute commands or edit files.
-
laragentic Bundle Code ReviewComprehensive code review for security, performance, and best practices
Audited -
lfnovo Skill ReviewAnalyze a Harny 0.5 run from run.json v4, audit events, normalized attempt transcripts, ChangeSets, and provider usage. Use after failed, retried, slow, costly, paused, mixed-provider, or otherwise surprising runs.
-
michellepellon Skill Fresh Eyes ReviewUse when about to commit, create a PR, or declare work complete — after verification-before-completion confirms tests pass but before code ships. Catches security vulnerabilities, logic errors, and business rule bugs that slip through despite passing tests.
-
michellepellon Bundle Documentation AuditSystematically verify documentation claims against codebase reality. Use when auditing docs, before releases, after refactors, or when documentation drift is suspected. Two-pass approach with pattern expansion ensures comprehensive detection of false claims, dead references, and gaps.
-
myatminlu Bundle Codebase AuditForensic whole-codebase audit and staged refactor. Use this skill whenever the user wants a codebase reviewed, audited, cleaned up, refactored, or "made systematic" — and also whenever they mention duplicated code, duplicated features or services, copy-pasted modules, band-aid or quick-fix or hacky code, technical debt, legacy vs new implementations living side by side, dead code, code smells, or wants to verify that features, functions and services are actually wired together and working end to end. Trigger it for requests like "review my codebase", "find duplicate logic", "why is this code such a mess", "check if everything is connected properly", or "plan a refactor", even when the user does not say the word "audit". Do NOT use it for a single-file review, a single bug fix, or writing new features.
Audited -
n1arko Bundle PromoПродающие страницы и представительские тексты на русском языке: лендинги, промостраницы, страницы продукта, услуги, тексты о себе, профили, отклики, страницы компании, миссии и пресс-релизы. Use this skill whenever the user asks to write, audit, structure, or improve a Russian landing page, promo page, sales page, product page, service page, about-me text, job application, company page, mission, press release, homepage copy, or text describing services. Триггеры: «лендинг», «промостраница», «продающий текст», «страница продукта», «текст о себе», «отклик на вакансию», «о компании», «миссия», «пресс-релиз», «опиши мои услуги», «текст для главной». Для коротких постов см. skill post; для статей и лонгридов — statya; для текстов интерфейса — ux-copy.
-
louisbrulenaudet Skill Review ChecklistEnumerated review checklist for this api-template - the diff-level checks that map to .claude/rules/. Use when reviewing a diff or auditing files for rule conformance; preloaded by the code-reviewer and security-reviewer subagents.
-
luabagg Skill Memory PalaceUse when the user asks to search, ingest, or audit their Obsidian knowledge vault.
-
luabagg Bundle Thorough Pr ReviewUse when the user asks to review a pull request, evaluate diff-level merge-readiness, or audit the current branch before opening a PR. Triggers include "review this PR", "review my branch", "code review", or a GitHub PR URL paired with review intent. For pure security reviews, prefer `security-review` instead.
-
ludo-technologies Skill Polyscan Fp AuditRun polyscan against one JavaScript/TypeScript, Go, Rust or C++ repository and triage findings for false positives using sub-agents. Auto-files clear polyscan bugs as GitHub issues (with `auto-filed` label, dedup, rate limit) and accumulates cross-repo tuning patterns into draft files. Outputs a markdown report under `.polyscan/audit/results/`. Accepts a repo URL/path as argument, or auto-picks the next pending entry from `.polyscan/audit/queue.md`.
-
lxyang20131208-star Skill X AuditAudit a draft X (Twitter) post or thread against the open-source X algorithm BEFORE publishing. Use when the user shares a tweet draft and wants feedback, asks "will this do well on X / Twitter", "review my post", "is this good to post", or wants to improve reach before posting. Returns a PASS / FLAG / BLOCK verdict per dimension plus a concrete rewrite.
-
lxyang20131208-star Skill X ProfileAudit an X (Twitter) profile — handle, display name, bio, header, pinned post — for follow conversion. Use when the user asks "review my X profile", "improve my bio", "why don't visitors follow me", "audit my Twitter profile", or shares their profile details. Returns a per-element audit and rewritten copy.
-
markmdev Bundle Error AuditAudit code for silent error swallowing, fallbacks to degraded alternatives, backwards compatibility shims, and UI that fails to show errors to the user. Finds and fixes all occurrences in the specified scope.
-
markmdev Bundle UX States AuditAudit UI code for missing loading states, empty states, and error states. Every async operation and data-driven UI must handle all three. Finds gaps and implements the missing states using the app's existing patterns.
-
markmdev Bundle Observability AuditAudit code for observability gaps — debug logs left in, errors caught without being logged, missing context on log entries, untracked slow operations. Uses the app's existing observability tooling exclusively.
-
mdfranz Bundle Osqueryd AnalystAnalyzes osqueryd differential result logs to investigate endpoint state changes, hunt for persistence, and correlate process and network activity. Use when a user provides osqueryd.results.log files, asks for host-based threat hunting, or needs to reconstruct current system state from scheduled query output.
-
mdorf Bundle BrevityUse before replying with the results of an investigation, review, or audit; before reporting completed work; before walking through code changes or explaining a technical mechanism; before answering a yes/no or single-decision question; when the reply must carry a decision or approval the user has to act on; and when the user complains about verbosity, walls of text, buried questions, or answers they stopped reading.
-
melvinmt Bundle Python Security HardeningHarden Python projects with security-first development practices. Enforces 100% test coverage, static analysis, secret scanning, mutation testing, pre-commit hooks, and SOC 2 compliance. Use when setting up security tooling, writing security tests, or hardening a Python codebase.
-
roebi Skill Code Review EnPerforms a structured code review against requirements and architecture docs. Checks correctness, test coverage, security, KISS/SOLID principles, and code style. Produces a review-checklist.md with pass/fail per criterion and a list of required fixes. Use after the implement phase and before release. Activate for trigger phrases like: "code review", "review this code", "review phase", "check the implementation", "audit the code", "does the code meet requirements", or "pre-release review".
Audited -
rudironsoni Bundle Brain LintHealth-check ontology-brain. Use before shipping any brain change, when asked to lint or audit the brain, or when pages may have broken links, stale index entries, duplicated facts, relationship drift, or ontology anti-patterns.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include linkedin-profile-audit, x-profile, linkedin-company-page-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.