Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
rudironsoni Skill Brain RefreshReconcile ontology-brain with a source set or maintenance window. Use when asked to refresh, sync, audit freshness, or bring the brain up to date across multiple pages.
-
s1lver091 Skill Code ReviewReview code changes for bugs, security vulnerabilities, performance issues, and maintainability. Use when asked to review code, a PR, a diff, or recent changes.
-
canonical Bundle Cinder Spec GeneratorExtracts oslo.config options from OpenStack Cinder volume driver Python source code and generates driver-spec YAML files for sunbeam-cinder-factory. Use when adding new storage vendor support, updating existing driver specs from upstream Cinder, or batch-generating specs for all Cinder drivers. Handles AST parsing, type classification, secret detection, protocol detection, enum mapping, and type_override generation.
-
chinayin Bundle GoTeam Go microservice architecture and coding standards. Use this whenever designing or writing Go code in this repo — HTTP services and handlers (gin), CLI commands (cobra), configuration (gox/config), database migrations (goose), or project scaffolding (Makefile/CI). Consult it any time you touch Go code or plan a Go module — including small changes like reading a single environment variable, secret, or config value — even if the user never says "standards".
-
codacy Skill Codacy Code ReviewEnriches pull request code reviews with Codacy data — quality issues, security findings, coverage, and duplication. Use whenever the user asks to review a PR, check what a pull request introduced, verify PR coverage, look at PR quality, or find new issues in a PR. Also use when another code-review skill is active (e.g. CodeRabbit) to layer Codacy data on top. Trigger this skill for any pull request review workflow, even if the user just says "review PR 42" or "what's wrong with this PR".
Audited -
codacy Bundle Codacy Analysis CLIUses the Codacy Analysis CLI to run local static analysis on repositories or specific files. Handles installation, initialization, dependency management, dry-runs, and analysis with JSON output. Use whenever the user wants to analyze code locally, run static analysis, scan for bugs or security issues, lint files, check code quality without pushing to Codacy, or run tools like ESLint, Ruff, Semgrep, RuboCop, or any other supported analyzer on their machine. Also trigger when the user asks to analyze staged changes, scan a PR locally, or set up local Codacy analysis.
-
codewithcj Skill New MigrationUse whenever adding or changing a SparkyFitness database migration, creating a new table, or altering user-visible data access. Walks the mandatory cross-package checklist (RLS policies, schema backup sync, shared Zod schema, docs security tiers, downstream contracts). Triggers on "new table", "migration", "ALTER TABLE", "RLS", "schema change".
Audited -
cognitic-labs Bundle Geo AuditComprehensive GEO audit diagnosing why AI systems cannot discover, cite, or recommend a website — scores technical, content, schema, and brand dimensions with a prioritized fix plan. Use when the user mentions GEO audit, AI visibility, AI search optimization, AI citability, or provides a URL and asks why AI can't find/cite/recommend their site.
Audited -
cognitic-labs Bundle Geo MonitorRe-audit a website and compare scores against a previous GEO audit baseline to track improvement over time. Use when the user asks to re-audit, check progress, track GEO score changes, monitor improvements, or compare before and after optimization.
Audited -
conceptadev Skill Persistence Agnostic LinterAudit and fix persistence wiring so the repository adapter (TypeORM/Firestore/other) stays swappable. Use when adding or reviewing entity/repository code, when you see @InjectRepository or a module-local TypeOrmModule.forFeature, or when checking that core/feature packages don't hard-require an ORM. Triggers on "is this persistence swappable", "register this entity", "review repository usage".
Audited -
context-is-everything Bundle Markdown Fact CheckerDetect hallucinations and verify accuracy in markdown documents produced by Claude. Use when (1) Auditing completed research documents for factual accuracy, (2) Verifying citations and sources match claims, (3) Checking URLs exist and content matches, (4) Cross-referencing quotes against source files, (5) Quality assurance before document delivery, (6) Self-audit after completing research tasks.
-
corticalepilepsyladyofthehouse956 Skill Security ReviewReviews code for security issues and vulnerabilities.
Audited -
cosmtrek Skill Long Horizon AuditExercise context compression by requiring many large tool observations before a final report.
Audited -
alexshchuka Skill Paper To CodeImplement an academic paper (arXiv or any quantitative source) as verifiable code without inventing unstated details. Use when asked to implement, reproduce, or prototype a method from a paper. Produces an ambiguity audit before code, citation-anchored decisions, and machine-checkable sanity verification.
Audited -
alexshchuka Skill Harness ImproveTurn an observed harness deficiency or improvement idea into a landed, properly-gated change to the neuro-matrix protocol. Use when the user reports a harness gap or defect, proposes a protocol improvement, or asks to harvest improvements from a session or audit. Verifies the gap against current main first, then routes each change class to its correct gate.
-
alexshchuka Skill Robust By ConstructionThe engineering invariant bar — what "good" means for systems built by this harness. Use as a checklist during design, as the audit criterion for adversarial-review, and as the source of linter/CI rules to mechanize. Not a style guide; these are correctness and safety properties.
Audited -
checkpickerupper Bundle Antimatter Code Quality ReviewTotal annihilation: no finding survives unless it survives refutation. An unusually strict maintainability and structural-quality audit of a diff — review frame, intent/spec fit, repo standards, abstraction quality, cohesion, type/boundary cleanliness, duplication, control-flow tangles, missed extractions and invented variation, data structures whose cost grows faster than they need to, allocation on repeating paths, and correct-by-construction opportunities. Use for a deep code-quality audit, a harsh pre-merge review, or to determine what structural change makes a class of bug impossible rather than merely caught. Stricter than a conventional review because every finding must survive an adversarial refutation pass, ship with a concrete before→after, and prove it preserves behavior. Severity theater is prohibited: only provable findings are reported.
-
con-benksl Bundle Netops BuildAudit, plan, and execute authorized VPS networking or proxy-node changes, including 3x-ui, Xray, VLESS Reality, Hysteria2, TLS, DNS, address-family separation, firewall rules, and per-node upstream exits. Use for installing, adding, or changing services while preserving existing behavior. 典型中文请求:装一个节点、增加入站、换域名和证书、给某个节点单独配置出口、修改端口和防火墙。
-
con-benksl Bundle Netops ManageLong-term VPS and proxy operations: monitoring review, baselines, incident bundles, backups, upgrades, compatibility, security, capacity, fleet drift, user lifecycle, subscriptions, and read-only traffic portals. Use for ongoing reliability and multi-VPS management rather than a one-time repair. 典型中文请求:统一多台 VPS、定期备份和升级、管理用户和限流、订阅管理、长期监控方案。
-
cotal-ai Skill Cold ReviewWrite the brief for a single independent cold reviewer and grade what it returns, keeping it isolated from the panel that already graded the change. Read by whoever AUTHORS the brief; the graded seat never loads this file. Covers what the seat is given, what its verdict binds, who may override it, and how the rules degrade when the vendor set is short. Use when a panel has reached consensus and you want a second opinion consensus cannot anchor, when a change is security-sensitive or hard to reverse, or when you are the author and therefore the worst available reader of your own work.
-
darcos-loft Bundle RefineA shared vocabulary of named refine commands for existing UI (typeset, colorize, animate, settle, flow, bolder, quieter, distill, regroup, glass, iconify, deslop, brandward, productward, audit, critique, harden, polish). Use when the user asks to improve, fix, tighten, calm, strengthen, or polish a UI with a precise verb instead of a vague "make it better". Each command is one scoped move wired to the rest of the suite.
-
digitalpine Bundle GolangSetup, audit, and modernize Go projects with 2025 best practices. Startup-friendly with two tiers - quick start (5 minutes, minimal friction) or full setup (production-ready). Use when creating new Go projects or improving existing ones.
-
digitalpine Bundle VitestSetup, configure, audit, and modernize Vitest testing in projects. Use when creating new test configs, auditing existing Vitest implementations for v4.0+ best practices, fixing deprecated patterns, migrating from Jest, or configuring test environments (Node.js, browser, monorepo). Checks for breaking changes, outdated configs, missing coverage settings, and performance issues. Covers browser mode, visual regression testing, and CI integration.
-
eonraider Skill Third Party FixtureReviews dependency manifests for known-vulnerable version pins. Use when the user asks for a dependency security review or mentions vulnerable packages.
-
eonraider Skill Gha Fix Pr Smoke TestUse when manually smoke-testing the GitHub Action's fix-PR path end to end. This is a disposable test fixture for skill-artisan's own CI, not a real user-facing skill, and is deliberately missing evals/lifecycle classification so the audit always finds FAIL items to fix.
-
enoselinsa Bundle Latex Prose AuditUse when auditing or revising LaTeX manuscripts for sentence-level academic prose, subject–verb agency, terminology or symbol consistency, article and modifier usage, citation placement, result wording, or LaTeX-safe formatting—especially when a paper contains algorithms, equations, figures, tables, or quantitative claims that need line-specific findings.
-
ezee234 Skill Symbi PolicyCreate, edit, or validate Cedar authorization policies for Symbiont agents. Use when defining access control rules, setting up security policies, or debugging policy evaluation.
-
ezra144israel Skill Ship It Or Fix ItOracle-frozen Builder and independent-Judge convergence cycle. Load ONLY when the operator explicitly sets Governance Dial G2 for the task, or explicitly names this skill or an active work unit already running it. Never auto-activate on task class, such as security, auth, or payments. If a task seems to warrant G2 and the operator has not said so, ask first. Not for ordinary governed implementation, analysis, review-only, or documentation work.
-
ezra144israel Skill Write Maintainable CodeEvaluate minimum-sufficient implementation routes and enforce the selected route for a fixed, authorized outcome. Use after outcome, scope, authority, and acceptance evidence are fixed. Do not choose outcomes, set acceptance, adjudicate governance, grade finished work, design tests alone, conduct security audits, or perform unrelated cleanup.
-
gnsubrahmanyam Bundle Celery Development Best PracticesComprehensive Celery distributed task queue framework with 60+ prioritized rules across configuration, task execution, Canvas workflows, monitoring, security, performance, routing, periodic tasks, serialization, worker management, and advanced patterns. Use when implementing background tasks, periodic jobs, or distributed processing with Celery.
-
gnsubrahmanyam Bundle Django Development Best PracticesComprehensive Django development framework with prioritized rules across models, views, templates, security, and performance. Use when building Django applications, writing models, creating views, implementing authentication, or optimizing Django projects.
-
gnsubrahmanyam Bundle Fastapi Development Best PracticesComprehensive FastAPI development framework with prioritized rules across async patterns, validation, security, testing, and deployment. Use when building FastAPI applications, designing APIs, implementing authentication, or optimizing async services.
-
gnsubrahmanyam Bundle Structured JSON Logging Best PracticesComprehensive structured JSON logging framework with schema design, implementation patterns, security considerations, and enterprise best practices for observability and monitoring
-
gmh5225 Skill Mev SecurityGuide for MEV concepts, common attacks, mitigations, and how to organize MEV-related resources in README.md.
-
gmh5225 Skill Solana SecurityGuide for Solana/Sealevel security research and where to organize Solana-specific resources in README.md.
-
gmh5225 Skill Wallet SecurityGuide for wallet security topics: MPC/TSS, key management, wallet UX security, phishing, and how to categorize related resources in README.md.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include code-review, brain-refresh, cinder-spec-generator. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.