Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
lnrd390 Bundle Plan RefineAudit and refine an existing execution plan so downstream agents need less rediscovery and fewer architectural decisions.
-
luochang212 Bundle Code AuditSecurity audit and code scanning. Use when the user asks to scan code for bugs/vulnerabilities, audit security, run SAST, find code patterns, or review code for security issues. Supports two modes — fast pattern scanning (Semgrep) for quick results and CI gating, and deep AI-powered investigation (deepsec) for thorough reasoning-based analysis. Also use when the user mentions "semgrep", "deepsec", "static analysis", "security scan", "code scanning", "find vulnerabilities", "scan my code", or "security audit".
-
luochang212 Skill Code QualityUse when the user asks to review code quality, find redundant code, audit duplication, or "clean up" a codebase. Also use when the user says "find issues" or "anything worth fixing" after a feature is built. This skill provides a systematic framework for identifying code quality issues, evaluating whether each fix is worth making, and safely applying changes without over-engineering.
-
lwouis Skill Audit Specs TestsAudit the AltTab test suite for spec/test/code consistency. For every co-located triad in `src/` (`Foo.swift` + `FooSpecs.md` + `FooTests.swift`), it cross-checks that each XCTest method has a matching scenario line in the spec and vice-versa, flags drift between a scenario's description and the test's doc-comment, and reports orphan tests, orphan scenarios, and unpaired files. Use after adding or editing any `*Tests.swift` / `*Specs.md`, before committing a test change, or to get an overall health check of the suite.
-
primeline-ai Bundle Code ReviewUse when reviewing pull requests, reviewing your own code before committing, or when asked to review code changes. Provides structured analysis with severity categorization, security focus, and optional worktree isolation for safe PR review.
-
pzehrel Bundle Maintain Agents MdCreate and audit scoped, verifiable AGENTS.md hierarchies and route durable rules into repository policy documents. Use for repository guidance; not for temporary notes.
-
quarkusio Skill Quarkus Module BuildUse when asked to build, compile, or rebuild specific Quarkus modules. Accepts multiple module names and builds them in parallel via subagents. Examples - build graphql module, compile openapi and rest, rebuild security extensions.
-
recrsn Skill Electron To ElectrobunPort an Electron app to Electrobun. Runs a compatibility audit first, then migrates IPC, windows, preload, menus, dialogs, and build config to Electrobun equivalents.
-
joshphoenix1 Bundle Skill DoctorDiagnose hygiene problems across an installed skill set — routing token cost, vague or missing trigger descriptions, overlapping triggers between skills, and duplicates installed in multiple places. Use when the user asks to tidy, audit, trim, or debug their skills, when skills fire at the wrong time or not at all, or when too many skills are installed.
-
jovd83 Bundle Skill YAML CleanupAudit and reduce YAML frontmatter bloat in SKILL.md files. Trigger to: scan skill directories, identify oversized frontmatter, propose deduplication/flattening/migration optimizations, and apply approved changes. Requires user approval before writing.
-
kcsujeet Bundle AuditAudit a repository's Claude Code instruction setup and propose a restructure. Trigger on "audit my CLAUDE.md", "review my CLAUDE.md", "is my CLAUDE.md any good", "my CLAUDE.md is too long", "Claude keeps ignoring my instructions", "should this be a skill or a rule", "set up CLAUDE.md for this repo", or a request to reorganize claude rules, skills, and hooks. Inventories every instruction file, classifies each section by where it belongs (CLAUDE.md, path-scoped rule, skill, hook, or deletion), reports the always-loaded token cost before and after, and proposes a file plan. Never rewrites instruction files without explicit approval.
Audited -
kestra-io Bundle Kestra Flow HardeningAudit one or more existing Kestra flows and add production-hardening controls — retries, timeouts, concurrency limits, error/finally/afterExecution handlers, SLAs, checks, and idempotency guards. Produces a severity-ranked findings report, then applies confirmed edits. Use when users ask to harden, audit, review, or make a flow more production-ready, resilient, or idempotent — not for authoring new flows (use kestra-flow).
-
kimon1230 Skill Security AuditUse when you want a thorough security review of the codebase, a specific file/directory, or a set of changes before shipping.
-
kylecorry31 Bundle Android Check Pr TranslationsAudit changed Android translations in a GitHub PR.
-
ladyiceberg Skill Memory CleanupGuided two-step cleanup for OpenClaw long-term memory (MEMORY.md) — audit first, confirm with user, then clean. Handles report_id automatically so the user never sees it. Use this skill whenever the user wants to clean, purge, or tidy their OpenClaw memories, mentions stale or old memories, or uses phrases like "clean memory", "cleanup memory", "delete old memories", "remove stale memories", "清理记忆", "删除旧记忆", "记忆清理". Always use this skill for memory cleanup requests — don't attempt cleanup without it.
-
larlarua Bundle Code Audit FindingDeepAudit Finding overlay for source-code auditing with code-audit-main references, mandatory reading routes, and progressive WooYun disclosure.
-
shenjingnan Skill Security Audit安全审计技能,用于检查和修复依赖安全问题
-
slayerman420 Bundle Mimiq MemoryPersistent memory and feedback system for Mimiq. Stores all scrapes, style fingerprints, audits, ghostwritten posts, and user feedback in a local database at ~/.claude/mimiq-memory/. Links multiple social media profiles to a single user identity. ALWAYS trigger this skill at the START of every Mimiq session to load existing memory, and at the END of every session to save new data. Trigger on: "remember this", "save my fingerprint", "log this post", "show my history", "what did you find last time", "rate this post", "give feedback", "what posts have I written", "show my past audits", "update my profile", "which profiles are mine", "link my accounts", "show community insights", "opt into sharing", or any reference to past Mimiq sessions. Also trigger automatically after voice-capture, content-audit, or post-strategist completes — always save results without being asked.
-
slayerman420 Skill Social SuiteMaster orchestrator for Mimiq — a complete personal social media system. Coordinates voice-capture, content-audit, and post-strategist in the right sequence. THIS IS THE ENTRY POINT for any broad social media request. ALWAYS trigger on: "help me with my social media", "set up Mimiq", "I want to grow my LinkedIn / Twitter / Instagram", "build my personal brand", "help me post consistently", "I want a content system", "I want to start posting regularly", "help me get more engagement", "I want to create content at scale", "I'm trying to grow an audience", "I don't know what to post", "help me show up online", or any request combining writing + strategy + personal voice. Also trigger when the user seems overwhelmed and doesn't know where to start. Do NOT trigger for a one-off post request when a fingerprint already exists (use post-strategist) or a standalone engagement question (use content-audit).
-
slayerman420 Skill Content AuditAnalyzes a user's social media posts to surface top-performing content, winning topics, best formats, and optimal posting times — using Apify actors for scraping public engagement data, falling back to manual input when actors are unavailable. ALWAYS trigger on: "what's been working for me", "what should I post about", "what are my best posts", "what topics get engagement", "when should I post", "analyze my content", "audit my social media", "what kind of posts do well for me", "I want to double down on what works", "show me my top performing content", "what do my followers respond to", sharing a social profile URL and asking what's working, or any question about past post performance or building a data-driven content calendar. Do NOT trigger for generic social media best practices with no reference to the user's own content — that's web search, not an audit.
-
slayerman420 Skill Post StrategistGhostwrites complete, ready-to-publish social media posts in the user's exact voice with optimal timing recommendations. ALWAYS trigger for any request to write or draft a social post on any platform. Trigger on: "write me a post", "draft a LinkedIn post", "write a tweet", "write my Instagram caption", "I need to post about X", "help me write content", "create a post about my launch / job / article", "write a week of posts", "I have an idea — write it up", "when should I post this", "what's the best time to post today", "write this in my voice", "turn this into a post", or any request ending in publishable social content. Check for a Style Fingerprint first — if none exists, run voice-capture before writing. Always offer both personal timing data and platform-research timing. Do NOT trigger for content performance analysis (content-audit) or style-capture with no writing request (voice-capture).
-
slopstopper Skill Plumb Line AuditAudit against the plumb-line principles
-
slopstopper Skill Plumb Line RemediateUse when applying findings from a plumb-line audit report — the builder has a report (or pasted findings) and wants the fixes made. Opt-in and separate from the audit, which is read-only and never fixes.
-
starslingdev Bundle CI SpeedupAudits a repository's GitHub Actions workflows for CI optimization opportunities — missing caches, redundant setup, sleep-based readiness, long test jobs without sharding, full-history checkout, dead env vars, build-cache misconfig, and ~60 more patterns across caching, redundancy, parallelization, conditional execution, trigger scope, and hidden failures. Use when: (1) analyzing a repo's CI for optimization opportunities, (2) producing a prioritized report with measured wall-clock and runner-minute savings, (3) re-auditing after upstream CI changes. Do not trigger for: general CI setup help, writing new workflows from scratch, non-GitHub-Actions CI systems, or security/posture audits — use `ci-secure` for those.
Audited -
story-has-you Bundle Java DevComprehensive Java development skill based on Alibaba Java Coding Guidelines (Songshan Edition). Use when writing, reviewing, or refactoring Java code to ensure compliance with industry best practices. Triggers on: (1) Writing new Java code (.java files), (2) Reviewing existing Java code, (3) Refactoring Java projects, (4) Database design with MySQL, (5) API design and implementation, (6) Unit testing, (7) Concurrent programming, (8) Security implementation, or any Java development tasks requiring adherence to coding standards.
-
magnifito Skill Docs GateUse when docs-notary check fails — "check-docs FAILED", a GitHub annotation from check --format github, the plugin's edit hook reporting errors after a Write or Edit, or CI red on lint:docs. Not for a stray with no frontmatter (docs-sort), moving (docs-promote) or reviewing (docs-audit).
-
magnifito Skill Docs AuditUse when a repository with docs/index.json needs judgement about what its documents still claim — a periodic docs review, "are these docs stale", a plan that says it is done, an unverified state document, a review_by date that passed, a change that may have invalidated documents. Not for sorting (docs-sort), moving (docs-promote) or a red gate (docs-gate).
-
manu-brighter Bundle Full Project ReworkRuns a complete, autonomous, three-phase project overhaul — parallel analyzer subagents, then reviewer subagents that decide what ships, then implementer subagents that apply the changes (each on a dedicated branch, one commit per category). EXPLICIT-INVOCATION ONLY: use this skill solely when the user invokes it by name or runs it as a slash command. Do NOT auto-trigger or infer it from general requests like "improve the codebase", "clean this up", "modernize", "audit the project", or "fix the whole project" — for those, do the work directly or ask. This skill is strictly opt-in.
-
markcmarshall Skill Name The Unstated ControlsForce security controls that were never explicitly requested to get named and checked before an implementation is considered done. Use before marking any feature complete.
-
mcmespinaa Skill Folder AuditEvaluates any project's folder architecture against the ICM five-layer context hierarchy. Scores Layer 0 (Map/CLAUDE.md), Layer 1 (Rooms/CONTEXT.md), Layer 2 (Stage Contracts), Layer 3 (Reference Material), Layer 4 (Working Artifacts), plus Tools assessment. Checks 14 anti-patterns (8 base + 6 ICM), measures 5 structural metrics. Outputs a graded audit report with prioritized fixes. Use when: setting up Claude Code on a project, reviewing workspace quality, debugging degraded AI output, onboarding a new codebase, scoring folder structure, checking folder quality, evaluating project organization.
-
mduongvandinh Bundle Go Best PracticesGo Best Practices Audit
-
mduongvandinh Bundle PHP Best PracticesPHP Best Practices Audit
-
mduongvandinh Bundle Rust Best PracticesRust Best Practices Audit
-
mduongvandinh Bundle Dotnet Best Practices.NET Best Practices Audit
-
mduongvandinh Bundle Nodejs Best PracticesNode.js Best Practices Audit
-
mickzijdel Skill Airtable User ScrapingScrape user/collaborator access data from Airtable bases using the airtable-scrape-users utility. Use when the user wants to audit who has access to which Airtable bases and at what permission level.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include plan-refine, code-audit, code-quality. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.