Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
jppuche Bundle Skill AuditorAudit and review Claude Code skills against best practices. Use when: the user says "audit skills", "review skills", "check my skills", "skill health check", "/skill-auditor", or when running scheduled skill maintenance. Evaluates structure, security, quality, description effectiveness, progressive disclosure, and context budget.
-
pax-k Bundle Build Right Engineering PrinciplesApply Build Right engineering principles as a planning, implementation, and review standard. Use when Codex is choosing technologies, service boundaries, storage models, architecture boundaries, splitting modules or features, creating public contracts, changing provider adapters, reviewing implementation quality or over-engineering risk, planning tests, handling side effects, errors, observability, security, or deciding whether markdown guidance needs enforceable checks.
-
jacopalas Skill Security ScanBasic security scanning for common vulnerabilities. Use when the user wants to check security, scan for vulnerabilities, find secrets, audit security, revisar seguridad, escanear vulnerabilidades, or check for exposed credentials.
-
lukeberrypi Skill Prune Dead CodeAudit a codebase for dead and otherwise safe-to-remove code, and report each finding for approval. Use when asked to find dead or unused code, deduplicate repeated constants, replace magic literals that duplicate a named constant, or remove arbitrary caps, thresholds, or timeouts.
-
pawlakcamille Bundle Cami DesignUI audit before ship. Spots what's off, routes to layout, interaction, copy, or engineer. Use when reviewing a screen, a flow, or polishing a near-done project.
-
poisoneddiety Bundle Academic Prose AuditAudit and revise drafted academic legal prose for propositional compression, mechanical sentence rhythm, and AI register, while preserving formal academic voice and OSCOLA conventions. Fixes the defect where too much meaning is left for the reader to reconstruct. Use this on any draft paper, response paper, seminar piece, or long note before submission, and whenever the user says a draft reads mechanically, sounds like AI, or needs humanising. Do NOT use for first drafts, exam answers, or casual chat.
-
qualimetry Bundle Analysis IssuesRetrieves and helps clear rules-based analysis issues (bugs, vulnerabilities, code smells) for a repository branch. Prioritises by severity and type, works file-by-file or in batch mode, and assesses the security hotspots that are waiting on a human review decision. Requires Qualimetry Enterprise.
-
saketmunda Skill Audit ModuleAudit Module
-
skillmedev Skill Skill Description WriterWrites the description field that makes a skill fire reliably - WHAT it does, WHEN to invoke it with quoted user phrasing, and what it is NOT for. Use when drafting or improving only the description or trigger of a SKILL.md or catalog entry - "this skill never fires", "fix this description", "write the frontmatter description". Do NOT use to author a whole skill (use skill-creator) or to grade/audit one (use skill-auditor).
-
srcodexstudio Skill Headroom CompressContext compression audit. Detects stale file reads, bloated Bash output, redundant content, and wasted tokens. Produces a compression report with estimated savings and actionable recommendations.
-
tomasb2bc Bundle RequestSkill lifecycle harness hub. Shows open requests, routes to sub-skills (request-capture, request-develop, request-audit, request-verify, request-close). Use as the entry point for all skill lifecycle work. Triggers on 'request', 'skill request', 'skill status', 'what needs work', '/request'.
-
vambrocop Bundle Environment Life Review ForgeAdapts evidence synthesis workflows for environmental, ecological, biomedical, and life-science questions. Use for PECO/PICO frameworks, exposure-outcome reviews, ecological heterogeneity, dose-response evidence, risk-of-bias planning, environmental indicators, NDVI or vegetation-index models, partial least squares regression, PLS VIP audits, ecosystem-service relationships, ESR synergy/trade-off mapping, interpretable machine learning, GWR/XGBoost spatial modeling, threshold-oriented ecological management, optimal interval identification, air pollution crop-yield models, ozone/aerosol food-security co-benefits, SIF-based crop productivity, soil biodiversity, aridity gradients, ecosystem stability, climate-stress moderation, soil fauna meta-analysis, ant-mediated carbon cycling, SOC and CO2 dual-outcome synthesis, organism/tissue/time-scale coding, wetland methane scaling, small-patch geospatial upscaling, cryosphere or permafrost evidence products, near-surface ground ice mapping, geospatial environmental ma
-
adampie Bundle Fact CheckFact-checks factual claims against live web sources and against the local codebase, reporting each one with a verdict, a correction and a citation. Use when the user asks to fact-check or verify a document, article, draft, README or design doc, to check whether a claim is true, to confirm that what the docs say about the code is still what the code does, to trace whether a stated behaviour holds by following the call paths, to source or back up statements, or to audit the accuracy of what Claude itself said earlier in the conversation. Not a code review: it checks claims made about the code, not the quality of the code.
-
adamradek-ux Skill Memory AuditCompares two memory layers — git-backed context notes in your vault vs the non-git Claude Code auto-memory store — finds overlap/drift and convention drift, and PROPOSES a source of truth plus what to merge or delete. Read-only analysis; propose → OK → write. Triggers: "memory audit", "what's duplicated in memory", "sync my memory", "what's stale in my context notes", and Czech aliases "audit paměti", "co je zastaralé v paměti".
-
aurite-ai Skill Verify SecurityVerify code for security issues including hardcoded secrets, input validation, error exposure, and dependency vulnerabilities. Use when asked to "verify security", "check for secrets", or "scan for vulnerabilities".
-
automattic Bundle Wordpress Workspace Release RunbookGuide WordPress Workspace build, packaging, signing, notarization, OAuth secret injection, release checks, and release documentation for this repo. Use when the user asks to build, package, sign, notarize, publish, smoke test, or explain release operations.
-
bartwaardenburg Bundle Security TrustFixes security and trust issues — configures HTTPS, HSTS, Content-Security-Policy, X-Content-Type-Options, frame protection, CORS, and Referrer-Policy headers so AI agents and platforms trust the website for interaction. Use when asked to "fix security headers", "add HSTS", "configure CSP", "fix HTTPS", "improve security score", "add security headers", "fix CORS", "add Referrer-Policy", or any security header configuration task.
-
lendtrain Skill Security GuardrailsSecurity Guardrails
Audited -
bhouvana Skill Instinct AuditUse when the user asks for a whole-repo or whole-history audit of engineering judgment — "audit this repo", "did we leave reasoning behind", "find undocumented breaking changes", "provenance audit". Broader than instinct-review, which checks one diff; this looks across history. Explicit invocation only; one-shot report, changes nothing.
Audited -
bitrix-tools Bundle ScanТщательно сканирует один Bitrix-модуль (PHP) на security-уязвимости и возвращает JSON-отчёт. Вызывай с одним аргументом — путём к папке модуля (например, `modules/ipol.dpd`). Подходит для использования как сабагент в оркестраторной архитектуре.
-
bitrix-tools Skill Scan ComposerMarketplace pre-submission security-flow для ОДНОГО Bitrix-модуля — сырой аудит и BUS-aware пересмотр severity. Headless точка входа автоматического сканера (без UI). Вызывается с одним аргументом — путём к распакованному модулю.
Audited -
bitrix-tools Bundle Journal ReviewUse when reviewing JSON vulnerability journals for 1C-Bitrix Site Manager or boxed Marketplace modules, especially when scanner severity may ignore Bitrix admin/content-editor trust boundaries.
-
bitrix-tools Bundle Journal UpdateUse when updating and validating cumulative security-journal.json files for Bitrix module security runs from reviewed scan JSON outputs.
-
bitrix-tools Skill Using Marketplace SecUsing Marketplace Security
-
blair2004 Bundle Laravel Best PracticesApply this skill whenever writing, reviewing, or refactoring Laravel PHP code. This includes creating or modifying controllers, models, migrations, form requests, policies, jobs, scheduled commands, service classes, and Eloquent queries. Triggers for N+1 and query performance issues, caching strategies, authorization and security patterns, validation, error handling, queue and job configuration, route definitions, and architectural decisions. Also use for Laravel code reviews and refactoring existing Laravel code to follow best practices. Covers any task involving Laravel backend PHP code patterns.
-
f-tiger Bundle AI Efficiency AuditAudit a person's or team's weekly workflow, identify which tasks AI can realistically take over, and produce an evidence-based, manager-ready efficiency proposal with hours-saved ranges and a two-week pilot plan. Use this skill whenever the user mentions AI efficiency pressure from leadership, or says any of these — "提效", "降本增效", "老板让用AI", "老板天天提AI", "领导要我们用AI", "怎么向领导/老板证明AI有用", "我的工作哪些能让AI做", "AI能帮我自动化什么", "哪些活能交给AI", "向上汇报AI成果", "做个AI提效方案", workflow automation audit, "which parts of my job can AI do", building a business case for AI adoption, estimating hours saved or ROI from AI tools, or needing a pilot plan / proposal to introduce AI into a team. Also trigger when the user pastes their weekly tasks and asks what to automate.
-
facebookexperimental Skill FablerApply a disciplined read, plan, execute, and adversarially verify workflow. Use for complex research, architecture, implementation, or audit tasks.
-
fedimint Skill Github Cargo Dependabot ReviewReview Dependabot PRs updating Rust/Cargo crates with a security-focused crates.io tarball diff before commenting.
-
fedimint Skill Github Actions Dependabot ReviewReview Dependabot PRs updating GitHub Actions workflows/actions, with a security-focused upstream diff check before commenting.
-
frontic Bundle Commercetools Headless CommerceBuild headless storefronts against the Commercetools API using the official TypeScript SDK (@commercetools/platform-sdk + @commercetools/ts-client). Use when working with Commercetools cart operations (create/update carts, line items, discount codes, shipping/billing addresses), checkout flow (order creation from cart, payment handling, shipping method selection), and customer account features (signup, login, profile management, addresses, password reset, email verification). Covers the stateful/write side of the API with full type safety, optimistic concurrency (versioned updates), SDK client builder patterns, and BFF security hardening (session signing, query injection prevention, input validation, rate limiting) — not product data fetching (use Frontic for that). Also use to audit existing Commercetools implementations for security pitfalls.
-
full-stack-skills Bundle RedisProvides comprehensive guidance for Redis including data structures (string/hash/list/set/zset/geo/hyperloglog/bitmap/stream), common commands with examples, caching patterns, persistence (RDB/AOF), replication & sentinel, cluster, Lua scripting, transactions, pub/sub, pipelining, security hardening, and production best practices. Use when the user asks about Redis, needs to implement caching, choose Redis data structures, configure persistence or cluster, or troubleshoot Redis performance.
-
convergeai-labs Skill Anycap Architecture DiagramsProduce architecture and system diagrams with AnyCap — fact-graph-first prompting, label fidelity audit via image-read, hybrid plates with deterministic labels, and a public-safety pass that strips internal system details before generation. Use when turning a system design into a shareable architecture figure with AnyCap image models.
Audited -
cyl19970726 Bundle Design Notion Information ArchitectureAudit, design, review, or migrate governed Notion workspaces and page systems. Use when Codex must decide how pages, databases, wikis, hubs, views, links, and relations should work together; repair navigation or generic "Related pages" patterns; redesign development or canonical-document systems; create an isolated staging copy; plan a reversible migration; or validate a Notion information architecture before cutover.
-
danielarosenn Bundle Uipath Code ReviewerReview UiPath automation code (XAML and C#) for quality issues, best practices violations, and potential bugs. Generates actionable fix suggestions that can be implemented by AI. Use when asked to review UiPath code, check workflow quality, audit automation, or find issues in XAML/C# workflows. Triggers on requests like "review my UiPath code", "check this workflow", "audit automation quality", "find issues in XAML", or "code review".
-
vibeforge1111 Bundle Maintainable EngineeringKeep Spark Intelligence code, architecture, security, and documentation highly maintainable, scalable enough, and clean without adding unnecessary complexity. Use when reviewing code, planning architecture, writing docs, simplifying modules, improving quality, or enforcing long-term engineering standards.
-
vinilana Bundle Adr Architecture WriterWrite, review, or update Bench My Harness architecture decision records for hexagonal architecture, event schemas, benchmark protocol, adapter strategy, storage, security, comparability, metrics, or execution isolation.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include Skill Description Writer, skill-auditor, build-right-engineering-principles. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.