Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
gmh5225 Skill Web3 Security ToolingGuide for security tooling (analyzers, fuzzers, decompilers, compilers) and consistent placement in README.md.
-
gmh5225 Skill Awesome Web3 Security OverviewGuide for understanding and contributing to the awesome-web3-security curated resource list. Use this skill when adding resources, organizing categories, or maintaining README.md consistency (no duplicates).
-
gmh5225 Skill Smart Contract SecurityGuide for EVM/solidity smart contract security work: vulnerability taxonomy, review workflow, and where to place resources in README.md.
-
goldsky-io Skill Streamling Plugin BasicsUse when creating a new streamling plugin crate in Rust (source, sink, transform, preprocessor, UDF, or side output), or when wiring up registration macros, constructor contracts, the plugin lifecycle, the async runtime, error types, or option/secret handling. Start here before the type-specific skills.
-
gyf9712 Skill ProofcheckSystematically verify mathematical proofs in statistics/ML theory paper appendices. Use when user says "proof check", "check proofs", "verify proofs", "audit paper", "检查证明", "证明验证", or wants to verify correctness of a paper's mathematical proofs.
-
gyf9712 Skill Theory SimulationBridge between theoretical results and Monte Carlo simulation, built to top-stat-journal standards (AoS, JASA, JRSS-B, Biometrika, Bernoulli). Two modes: (1) DESIGN mode — for each theoretical claim, design new simulations that verify rates, coverage, stress-test assumptions, and reveal theory-improvement opportunities; (2) AUDIT mode — when the paper already has simulations, evaluate whether they actually verify the theorems, identify claim-coverage gaps and adequacy flaws, and propose targeted improvements (extend / add / reformat) rather than full redesign. Produces publication-grade figures (no titles, content in caption, color-blind safe) and feeds findings back to refine theory. Use when user says "simulation plan", "Monte Carlo", "验证理论", "审查 simulation", "audit simulation", "模拟实验", "已有 simulation 检查", "stress test theory", "bridge simulation", "rate verification", or wants reproducible stat-journal simulations tied to theorems.
-
hcussi Bundle Spring Oauth2 Resource ServerConfigure a Spring Boot app as an OAuth2 resource server that validates JWT access tokens against any OIDC provider (Keycloak, Auth0, Okta, Cognito, Entra ID). Sets up the security filter chain, JWT decoder with audience validation, CORS, config properties, and a slice test. Use when adding token-based API authentication to a Spring Boot service.
-
hlhr202 Bundle Architect ReviewReview Architect track work or explicit current changes against project context, track intent, style guides, and tests. Use when the user asks to review, verify, audit, inspect, approve, or apply review fixes for Architect-managed work.
-
storyclaw-official Bundle Trade ExecutorExecute cryptocurrency trades on exchanges (Binance, OKX) with risk controls, user confirmation, and audit logging.
-
maples7 Bundle Pre Commit ReviewReview uncommitted Apple-platform changes across seven lenses — performance, user experience, test coverage, architecture, code style, security & privacy, and documentation — and produce a structured report with severity-graded findings before the user runs git commit. Use when the user asks to review a diff before committing, audit pending Swift / SwiftUI / Apple-platform changes for regressions, layering or style drift, security or privacy issues, missing tests, or stale docs.
-
mason-1011 Bundle Macos App Store ReadinessCheck macOS apps for App Store submission readiness and generate compliance reports. Use when the user wants to audit an app for App Store compliance, review App Store requirements, prepare a macOS app for distribution, or invokes /macos-app-store-readiness.
-
nasseralbusaidi Skill Grill My ArchitectureBrutal staff-engineer review of system architecture — service/module boundaries, data ownership, communication patterns, failure modes, scaling, security trust boundaries, evolvability, cognitive load, cost. Accepts an architecture doc, a set of ADRs, a system design write-up, a diagram pack, a verbal sketch, OR the codebase itself (the skill reconstructs the de-facto architecture from the code when no doc exists). Distinct from `grill-my-code` (file/function craft), `grill-my-backend` (server-side surface within one service), `grill-my-plan` (a specific planned change before code is written), `improve-codebase-architecture` (constructive refactoring opportunities), and `plan-eng-review` / `plan-ceo-review` (constructive walkthroughs). Use when the unit of critique is the *system shape*, not a file or a feature. Triggers on "grill my architecture", "grill the system design", "grill these ADRs", "is this architecture going to survive", "tear apart this design", "review my system design brutally", "stress-test
-
omarsaleh506 Bundle AI Os InitScaffolds an "AI Operating System" project structure into any project, non-destructively — adds only missing pieces, never removes or overwrites anything that already exists. Creates: CLAUDE.md (memory layer), docs/architecture.md + docs/decisions/ + docs/runbooks/ (documentation), tools/scripts/ and tools/prompts/ (utilities), and .claude/ with two example skills (new-adr, clean-tests), six hooks (guard-secrets, branch-guard, auto-format, typecheck, n+1-guard, audit-log), and a read-only docs-auditor subagent — all wired via .claude/settings.json. Requires only Python 3 and bash; no external dependencies. Use when asked to "init Claude Code project structure", "scaffold the AI-OS layers", "add CLAUDE.md hooks subagents to this project", "set up the Claude Code layers", "initialize ai-os", "add the AI operating system structure", "scaffold this project for Claude Code", or "add skills hooks agents here". Safe to re-run — idempotent. Not for non–Claude-Code agents (it scaffolds Claude Code's .claude/ layer) an
-
pr1m4lc0d3 Bundle Scout GeoUse when checking whether an AI assistant finds and correctly describes the product, running a discoverability audit, or planning a weekly check of how the market's own tool (an AI chat assistant) answers a literal-ask query. Reads lexicon.md for the queries, runs them in a clean session, and writes .monkeys/discoverability.md.
Audited -
t3chnaztea Skill Unifi WifiUse when UniFi Wi-Fi is slow, unstable, or being tuned: "my wifi is slow but speedtest on the router is fast", "great signal, terrible speed", "should I use 80MHz or 40MHz", "channel planning", "co-channel interference", "DFS channels", "my APs keep picking the same channel", "audit my SSIDs", "hidden SSID", or diagnosing throughput that collapses under load. Also roaming: "my phone stays stuck on the far AP", "sticky clients", "improve roaming", "should I enable fast roaming", "minimum RSSI", "TX power tuning". Covers the diagnostic ladder for slow Wi-Fi, channel width and DFS tradeoffs, safe radio writes, cell sizing and roaming persuasion, SSID hygiene, and the in-wall AP port trap. Assumes unifi-connect. Not for firewall policy between networks (unifi-firewall), wired port and client operations (unifi-clients).
-
tegnike Skill Elyth CycleELYTH生活heartbeatのlive行動を判断・実行し、world guard/auditを通して読みやすいDiscordレポートを返す。
-
tegnike Skill World Safety GuardELYTH/からくり発話やmemory proposalのsecret・cross-surface混入を検査する。
-
tegnike Skill Nikechan Another WorldELYTHとからくりワールド向けのworld行動判断・memory proposal・guard/auditを扱うHermes profile-local skill。
-
themattberman Bundle Pixel CapiMeta Pixel + Conversions API (CAPI) setup, audit, testing, and EMQ optimization. Covers browser pixel installation, server-side CAPI implementation, deduplication, advanced matching, and Event Match Quality scoring across all major platforms.
Audited -
timeplus-io Bundle Cisco Asa SyslogParse, interpret, and analyze Cisco ASA (Adaptive Security Appliance) firewall syslog messages. Use this skill whenever working with Cisco ASA log files, syslog streams from ASA devices, firewall event analysis, or security investigations involving ASA-generated events. Covers the syslog protocol foundation and the ASA-specific message format with message ID categorization.
-
tmoody1973 Bundle Clean Code ReviewPerform a read-only, evidence-based code quality review focused on correctness, clarity, maintainability, tests, security, and framework conventions. Use when the user asks to review code, audit code quality, find code smells, assess maintainability, or asks whether code is ready for another developer. Do not edit files; use boy-scout-cleanup for small safe edits or /refactor for structural changes.
-
tmoody1973 Bundle Product Readiness ReviewJudges user journeys and product behavior, not repository controls: whether a real person can finish the core flows, what happens when they do the wrong thing, and whether the product is ready for users, production, technical due diligence, or developer handoff. A read-only, evidence-based assessment that reads code and docs and reasons about the product as a working system. Use when the user asks whether a product is production-ready, wants a product audit, wants to improve more than code style, or asks what must be fixed before launch or handoff. For broad production-readiness requests, run prod-readiness-coach first for the repository-controls scan, then this review for product judgment.
-
umbraco Bundle Umbraco Skill AuthorA framework for authoring Umbraco skills in THIS marketplace: how to structure, scaffold, write, and audit a skill so it matches the house conventions. Use this whenever the user wants to start or build a new skill for the Umbraco marketplace, e.g. "make a new skill for X", "how should I structure this skill", "turn these docs into a skill", "scaffold a skill", or "get this skill ready to ship". Ends with a self-audit checklist, then hands off to `umbraco-skill-evaluator` for the eval loop — this skill covers authoring, not evaluation. SKIP: non-skill work, and general skill-building unrelated to this Umbraco marketplace (use the generic skill-creator for those).
-
naxoc Skill Briefs HealthAudit the briefs for a project when it feels muddled, stalled, or you've lost the thread. Reports what's out of shape and asks one question to drive reprioritization.
-
ngreenwall Skill QA AuditStatic-analysis QA pass over instruction/config files (SKILL.md, CLAUDE.md, your global context file, command files), not code. Spawns an Opus subagent per file to check for contradictions, dead logic, unstated dependencies, and style violations, then proposes fixes for confirmation before applying. Use when the user says "QA this skill," "audit this file," "run a QA pass on X," "QA SKILL.md," "audit CLAUDE.md," "QA this command," or "check this file for consistency issues." Do NOT use for live-session drift (use drift-check), skill output grading (skill-creator eval), or code diffs (/code-review); this skill never touches code, only instruction/config prose.
-
ngreenwall Bundle Drift CheckManual context-drift audit. Confirms your global context file (the standing instructions loaded on every session) is still loaded and being followed, and flags where context dropped. Run ONLY when the user explicitly types /drift-check or says "drift check," "context check," "are you still following my context," or "check for drift." Do NOT auto-trigger and do NOT run during normal task work.
-
ngreenwall Skill Token AuditAudits instruction/config files (SKILL.md, CLAUDE.md, your global context file, slash command files) and this repo's skill architecture for token bloat, then proposes fixes: rewrite, split, merge, add navigation, or remove. Use when the user says "audit tokens," "check token bloat," "shrink this file," "audit the skills library," "is this skill too big," "cut context cost," "check for updated Anthropic guidance," or "refresh the checklist." Do NOT use for finding bugs, contradictions, or dead logic (use qa-audit for that). Do NOT use for code files, only instruction/config prose and skill structure.
Audited -
no-today Skill Aidev ApicliUse when managing aidev HTTP session state or making HTTP calls with apicli login (capture a session via a flow), apicli whoami (inspect current session), apicli logout (remove session file), or apicli call (send HTTP request with injected session). Covers verb-first addressing, auto-login + auto-relogin (call is self-sufficient — no login-first), the {data}/{error} envelope, per-app response predicates, actors (incl. secret:<name>), and flow fidelity — multi-step + cross-step capture, per-step assert, cookie_from_set_cookie, multi-header inject, vars_defaults, extra_headers, trace_field, and file downloads (--output-file).
-
nulis-not-just-writing Bundle NulisCoaching menulis artikel jurnal berstandar Q1 (Scopus/WoS) — menyusun draft per section (Title s.d. Conclusion), memeriksa/audit draft, dan menjaga benang merah antar section. Berbasis move structures (CARS Swales, Hyland 5-move), reporting guidelines (APA JARS, COREQ/SRQR, GRAMMS, CONSORT/PRISMA), dan konvensi per bidang (matematika teorema-bukti, engineering/CS, natural sciences, social sciences, humaniora) serta per jenis riset (kuantitatif, kualitatif, mixed methods). Gunakan saat user ingin menulis, menyusun outline, mengembangkan section, atau mengaudit struktur naskah artikel jurnal. Untuk memoles prosa naskah jadi gunakan polish-manuscript; untuk gerbang pra-submisi (desk rejection) gunakan submit; untuk arsitektur cerita figur gunakan paper-narrative.
-
nusantara-ventures Skill Fx Accounting RatesUse whenever code touches multi-currency invoicing, bookkeeping, expense reports, revenue recognition, or financial reporting — choosing which FX rate to record a foreign-currency transaction at, converting an invoice to the home currency for the books, computing realized/unrealized FX gain or loss, or running month-end revaluation of open AR/AP balances. Trigger even for a one-off "convert this invoice to USD for the books". Covers rate-of-record date conventions and audit-trail fields, not just the raw conversion math.
Audited -
photonics-dhl Skill Dirac ExecutorUse for Dirac execution stage to run harness and Octopus with endpoint fallback and audit artifacts.
-
joe-bell Bundle Security ReviewSecurity code review for vulnerabilities. Use when asked to "security review", "find vulnerabilities", "check for security issues", "audit security", "OWASP review", or review code for injection, XSS, authentication, authorization, cryptography issues. Provides systematic review with confidence-based reporting.
Audited -
joe-bell Skill Writing GuidelinesReview or write docs/prose for Writing Guidelines compliance. Use when asked to "review my docs", "check writing style", "audit prose", "review docs voice and tone", "check this page against the writing handbook", or when writing/editing content under docs/src/content/docs/.
-
shadcn-labs Bundle Icon Set AuditAudit an existing SVG icon set and prioritize inconsistencies by visibility and repair cost. Use for a whole-set consistency review, an explanation of why a set feels uneven, or a split between safe mechanical repairs and redraw work. Use icon-set-extend when the user wants selected icons added or restyled.
-
shadcn-labs Bundle Icon Set ExtendAdd new SVG icons or restyle selected existing icons so they match an established set. Use when the user names the target set or library and wants specific icons to become indistinguishable from it. Use icon-set-audit for whole-set diagnosis and icon-set-generator for a new icon system.
-
tsale Bundle Admiralty SystemApply the NATO Admiralty System (AJP-2.1) to assess source reliability and information credibility in cyber threat intelligence, OSINT, and breach analysis. Use this skill whenever you need to evaluate a CTI report, breach claim, dark web forum post, threat actor advertisement, vendor blog, social media intel claim, leaked database listing, or any source plus information pair where trust matters. Trigger phrases include "assess this source", "rate this report", "is this breach real", "evaluate credibility", "source assessment", "should I trust this claim", "admiralty rating", "A1 to F6", and any review of CTI or OSINT material where you need to decide how much weight to give it. Use proactively when the user shares a breach post, threat actor claim, or vendor report and asks for analysis, even if they do not explicitly mention the Admiralty System. Also use when teaching, building courseware, or producing a training example around source evaluation.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include streamling-plugin-basics, web3-security-tooling, awesome-web3-security-overview. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.