Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
amazingchow Bundle Sync Self Explanatory DocsSynchronize Python architecture documentation with code using a three-level self-explanatory system: repository root docs, package-level `.package.md` files, and module header docstrings. Use when Codex changes Python project structure, adds or removes modules, refactors boundaries, updates entrypoints/domain/usecases/infrastructure responsibilities, or needs to audit and repair drift between the codebase and its architectural documentation.
-
opencoredev Bundle Convex Performance AuditAudits Convex performance for reads, subscriptions, write contention, and function limits. Use for slow features, insights findings, OCC conflicts, or read amplification.
-
youhai020616 Skill Security ChecklistUse when reviewing code for security issues, handling secrets, setting up authentication, auditing dependencies, or before deploying to production
-
enocgit Skill Definition Of Done ReviewReviews a change against this team's Definition of Done before merge. It goes beyond generic code review by checking acceptance criteria, contract fidelity, proportional verification and test coverage, docs/ADR updates, and security for sensitive areas, then gives a pass/fail verdict with evidence appropriate to each item. Use at Stage 6 after code-review and simplify, or when the user asks "is this ready to merge" or "run the DoD check".
-
ryanduguid Skill Github Repository AuditUse when assessing whether a GitHub repository is trustworthy, maintainable, presentable, or ready to feature.
-
srid Skill Nix Oss CacheUse this when setting up a GitHub repo to push its Nix builds to Juspay's shared OSS Attic cache (cache.nixos.asia/oss) — adds the substituter to flake.nix, a nix-cache.yml GitHub Actions workflow, and prompts for the ATTIC_TOKEN secret.
-
nucliweb Skill WebperfWeb performance measurement and debugging toolkit. Use when the user asks about web performance, wants to audit a page, or says "analyze performance", "debug lcp", "check ttfb", "measure core web vitals", "audit images", or similar.
Audited -
hostile-shorepatrol81 Bundle Map Personal KnowledgeMap personal knowledge by separating direct understanding from borrowed language, hidden assumptions, and untested beliefs. Use when the user wants to audit whether someone truly understands a concept or judgment.
-
iamaanahmad Skill Security ReviewUse this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
-
iammm0 Skill Nmap UsageProfessional nmap scanning techniques and optimization for penetration testing. Use this skill when you need to perform network reconnaissance, port scanning, or service enumeration during authorized security assessments.
-
iammm0 Skill System ControlComprehensive system control operations for security testing. Use this skill when you need unified access to file operations, process management, system information, and command execution through a single interface during authorized penetration testing.
-
iammm0 Skill System CommandsSystem-level commands for security assessment and system enumeration. Use this skill when performing local system reconnaissance, process analysis, or system information gathering during authorized security testing.
-
iammm0 Skill Terminal SessionPersistent terminal session management for security testing. Use this skill when you need an interactive shell session that maintains state between commands (working directory, environment variables, etc.) during authorized penetration testing.
-
iammm0 Skill Command ExecutionSecurity-focused command execution techniques for penetration testing. Use this skill when executing system commands during authorized security assessments. Covers Windows and Linux command execution, common security testing commands, and best practices for avoiding detection.
-
iceberggymnast Bundle Session Audit로컬 Claude Code 세션 로그(~/.claude/projects)를 전수 파싱해 사용자 프롬프트 원본을 복원하고, 틀을 가진 분석(A안)과 틀 없는 백지 분석(B안)을 독립 수행한 뒤, 검증을 거쳐 실행 계획(C안)으로 합쳐 노트로 남긴다. 사용자가 "세션 전수 분석", "내 프롬프트 로그 분석해줘", "백지 분석 돌려줘", "내 작업 방식 분석해줘", "지난 한 달 내가 뭘 했는지 분석", "세션 회고", "자동화 후보 뽑아줘"라고 하거나, 반복 작업을 스킬·에이전트로 만들 근거를 로그에서 찾으려 할 때 사용한다. 개별 세션 요약이 아니라 여러 달치 로그를 한꺼번에 보는 작업에만 해당한다. 출력은 두 모드다 — 노트 파일로 남기는 전수 분석(기본)과, 지적만 대화에 내는 쓴맛 보고("내 로그 좀 까줘", "냉정하게 봐줘", "쓴소리 좀 해줘"). 또한 "이 스킬 의도대로 작동해?", "이 스킬 잘 되고 있어?"처럼 스킬 자체의 효과를 점검해 달라는 요청에도 발동하며, 그때는 같은 폴더의 `RATIONALE.md`를 읽고 이번 세션·기존 기록과 대조한다.
Audited -
iceberggymnast Bundle Skill Checkup설치한 스킬이 실제로 돌고 있는지 재고, 안 돌면 트리거를 고친다. 사용자가 "스킬 점검", "스킬들 잘 돌고 있어?", "스킬 발동률 좀 봐줘", "설치한 스킬 상태 점검", "원장 정리 필요한지 봐줘", "프로필 업데이트 필요해?"라고 하거나, 스킬을 새로 만들거나 고친 뒤 한 달쯤 지나 효과를 확인하려 할 때 발동한다. 세션 로그에서 스킬별 발동 횟수를 세고, 기회 대비 발동률과 원장 기록률을 대조해 트리거 문제인지 절차 이탈인지 가른다. 원장·프로필의 상태도 함께 보고, 프로필 기재가 지금도 맞는지 새 문제를 내서 확인한다. 개별 스킬 하나가 자기 성공 기준을 충족했는지 보는 것("이 스킬 의도대로 작동해?")은 그 스킬 자신이 하고, 이 스킬은 함대 전체가 애초에 돌기는 했는지를 본다. 로그에서 새 자동화 후보를 발굴하는 것은 session-audit이다. 또한 "이 스킬 의도대로 작동해?"처럼 이 스킬 자체의 효과를 점검해 달라는 요청에도 발동하며, 그때는 같은 폴더의 `RATIONALE.md`를 읽고 지난 회차 관측과 대조한다.
Audited -
initlabsai Bundle Audit AlgorandPerform structured security audits and adversarial reviews of TypeScript Algorand applications and LogicSigs compiled with PuyaTs. Use for vulnerability assessments, threat models, exploit analysis, mainnet-readiness reviews, security findings, and remediation guidance involving AVM contracts, generated TEAL or ARC-56 artifacts, transaction groups, assets, state, upgrades, or external dependencies. Excludes Python, deployment execution, generic implementation work, and non-security code review.
-
ismail9k Bundle Anti KosharyTwo-pass audit and cleanup for a codebase that has started to congeal — spaghetti code, or "koshary code," where the layers have collapsed: business logic lives in the controller, the same validation sits in five files, and nobody wants to open the 800-line one. Pass 1 reports layer collapse, duplication that will drift, functions nobody reads, and dead code as a prioritized list and changes nothing; Pass 2 fixes in a safe order once the user approves. Security holes and vulnerable dependencies are covered too, as a later section rather than the headline. Use this whenever the user asks to audit, review, or clean up a codebase — and also when they say "this codebase is a mess," "spaghetti code," "technical debt," "this is unmaintainable," "duplicated logic," "dead code," "what's wrong with my code," or ask for a security review. Trigger it even when they never use the word "audit."
-
ivan-sincek Bundle Dread Threat Modeling FrameworkSystematically score and prioritize threats using the risk-centric DREAD threat modeling framework. Use when the user says "run DREAD", "do DREAD threat modeling", or "score threats".
-
ivan-sincek Skill Pasta Threat Modeling FrameworkSystematically identify and classify technical and business risks using the risk-centric PASTA threat modeling framework. Use when the user says "run PASTA", "do PASTA threat modeling", or "identify risks".
Audited -
ivan-sincek Bundle Stride Threat Modeling FrameworkSystematically identify and classify threats using the software-centric STRIDE threat modeling framework. Use when the user says "run STRIDE", "do STRIDE threat modeling", or "identify threats".
-
ivy-interactive Bundle Tendril Debug PlanDebug a Tendril plan by analyzing its execution logs, session JSONL, verification results, and checking infrastructure. Produces actionable bugfix and improvement recommendations. Use when the user wants to investigate why a plan failed, behaved unexpectedly, or to audit plan execution quality.
-
yaniv-golan Bundle Eml LabCompile ordinary formulas (exp(x+y), x**y, ln(x*y), sin(x)+cos(x), sqrt(x*y), x/y, asin(x), atan(x), log10(x)) into EML trees, look up calculator-primitive witnesses (exp, ln, add, mult, sub, pow, neg, inv, div, pi, i, sin, cos, tan, sqrt, asin, acos, atan, log10), inspect arbitrary EML trees, or run one-shot compile-render to emit tree + diagram + audit + summary from a sympy expression. Use when a user wants to lower a sympy-parseable expression into the EML IR, ask "how many tokens does the mult witness take?", visualize a tree as Graphviz/Mermaid, convert between nested / RPN / JSON forms, read shape stats (K, depth, leaf histogram), or produce a shareable artifact bundle in one command. Every named elementary primitive has a stored tree; the only `needs_tree` entry is `apex` (the closure proof itself, not a callable primitive).
Audited -
yaniv-golan Bundle Eml CheckVerify whether a claimed EML tree really computes a stated elementary function. Use when a user presents an EML expression (nested eml(...) form or RPN) and asks "does this really equal sin(x)?" / "is this a valid witness for log10?", when auditing proof-engine witness trees, when checking a compiler's output against a reference formula, or when someone needs a branch-cut / removable-singularity audit with an interior-domain sampler. Produces a structured audit report (audit.json, audit.md, audit.blog.md) covering leaf set, shape stats, numerical agreement, branch-cut flags, and removable-singularity caveats. The `--format blog` option emits a self-contained README/blog-friendly markdown artifact with embedded Mermaid, K-context table, witness provenance, and a probe table. Handles complex arithmetic via principal-branch cmath.
Audited -
yaniv-golan Bundle Eml OptimizeVerify numerical equivalence of two EML trees (interior samples + branch-cut probes), search for shorter trees via witness-swap peephole, or enumerate shortest trees bottom-up via beam search with function-hash deduplication, meet-in-the-middle complement lookup, backward goal-propagation priority population, and optional library-witness seeding. Use when a user wants to confirm two EML trees compute the same function, audit whether a subtree collapses to a known library entry (exp, ln, e, add, mult, sub, pow, neg, inv), or rediscover the shortest EML witness for a named claim (exp, ln, e, mult, sub, neg, inv, simple composites) within a K budget up to K=17. Produces delta-K, equivalence verdict with branch flags, or best-K tree with per-K candidate counts.
Audited -
t0ddharris Skill Skill AuditAudit all available Claude skills across user and project scopes — inventory them, map routing and overlap, score each on efficiency, reliability, clarity, maintainability, learning, currency, and safety, then produce a prioritized report and draft patches. Use when the user asks to audit, review, improve, optimize, modernize, clean up, consolidate, benchmark, or evaluate skills; to find outdated, duplicate, or inefficient skills; to identify missing skills; or to check whether skills follow current best practices. Diagnosis only — never edits a skill without explicit approval.
Audited -
2233admin Bundle Code ReviewComprehensive code review focusing on quality, security, and best practices
-
swellshinider Bundle Docs CleanerAudit and improve project documentation and open-source repository readiness: README files, guides, contribution policies, security and conduct files, support guidance, and GitHub issue or pull-request templates. Use when documentation is stale, redundant, incomplete, inconsistent, or needs a conservative open-source standards review. Documentation-only changes.
Audited -
astroicers Skill InstallerFixture for S-001. Use when testing security flags.
-
omas-odoo Bundle Odoo PythonUse when writing or reviewing any Python in an Odoo module — models, computes, overrides, controllers, wizards. Carries PSAE review-derived principles for ORM correctness, performance, style, and security, plus references for exact patterns. Invoke before writing logic in models/, controllers/, or wizard/.
-
omas-odoo Bundle Odoo Module DevelopmentUse when designing or writing any Odoo module — new models, inherited models, views, security records, migrations, or demo data. Invoke before creating __manifest__.py or any file under a module directory.
-
vechain Bundle Smart Contract DevelopmentSolidity smart contract development on VeChainThor — Hardhat setup, ERC-20/721 patterns, upgradeable contracts, gas optimization, testing with Thor Solo, security auditing, and ABI codegen.
-
minhuw Skill Herder ValidateValidate a Herder plan directory against the canonical mechanical and semantic contracts, report plan/index/dependency/drift issues without changing files, and conservatively repair safe issues with --fix. Use when the user invokes /herder-validate, asks whether herder-plans/ is Fire-ready or executable, wants a cold plan-quality audit, or asks to repair malformed, incomplete, or drifted plans. Do not use to execute plans, modify source code, or decide missing product intent.
-
xixiaofinland Bundle Clean ApexClean-code focused Apex guidance for readability, naming conventions, 3-tier architecture (entry-point, static service, OO), error handling, and unit vs integration testing. Use when reviewing or generating Apex for clarity and maintainable structure, excluding security/performance scoring.
-
xoshbin Skill Review IpcAudit IPC message contracts between extensions and the Asyar host. Use when adding a new SDK service, adding a new proxy method, changing a postMessage type string, or reviewing permission gate coverage.
-
zakirkun Skill PentestAuthorized penetration testing with Deep Eye (this repo). Use for pentest, penetration test, vulnerability assessment, web/API/mobile scan, OWASP testing, /pentest. Requires written authorization. Never scan unauthorized targets.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include eml-lab, eml-check, eml-optimize. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.