Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
tsuzat Skill Two Factor Authentication Best PracticesConfigure TOTP authenticator apps, send OTP codes via email/SMS, manage backup codes, handle trusted devices, and implement 2FA sign-in flows using Better Auth's twoFactor plugin. Use when users need MFA, multi-factor authentication, authenticator setup, or login security with Better Auth.
-
vechain Bundle Secure Github ActionsSecure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks. Use when creating, scaffolding, editing, or reviewing `.github/workflows/*.yml`, reusable workflows, `action.yml`, or Dependabot config for GitHub Actions. Also use for full repository security audits ("audit my workflows", "harden this repo", "security scan", "pin actions to SHA"), secrets scanning with gitleaks and trufflehog, and pre-public-release security reviews. Enforce full 40-character commit SHA pinning, avoid `pull_request_target` on untrusted code, pass GitHub context into `run:` steps via `env:`, and set least-privilege permissions.
-
mfish-qf Skill Workflow Audit为 mfish-nocode-pro 项目集成 Flowable 工作流审批能力,包括注册 FlowKey、实体审批状态字段、Service 启动/撤回流程、Controller 审批回调接口、Feign 回调接口注册五个步骤的完整代码模板。当用户说"带工作流审批"、"发布审核流程"、"集成工作流"、"审批回调"时使用此 skill。
-
skillmedev Skill Series A ReadinessAudits whether a seed-stage company clears the Series A bar - benchmark metrics, narrative, team, and data room - and produces a red/yellow/green readiness scorecard with a 90-day gap-closing plan. Use when a founder asks "am I ready for Series A", "what metrics do I need to raise an A", "what goes in a Series A data room", "should I raise now or wait two quarters", or is deciding when to open an A process. Do NOT use for a general pre-pitch hygiene check at any stage - use fundraise-readiness-audit instead - or for choosing which round to raise at all - use fundraising-stage-selector instead.
-
arustydev Skill Homebrew FormulaCreate, test, and maintain Homebrew formulas. Use when adding packages to a Homebrew tap, debugging formula issues, running brew audit/test, or automating version updates with livecheck.
8 -
hex Skill Store SecretStore secrets shared in chat into the cs session secret store. PROACTIVE - invoke immediately when the user shares API keys, passwords, tokens, or other credentials in their message; do not wait to be asked.
-
m13v Bundle Social AutoposterAutomate social media posting across Reddit, X/Twitter, LinkedIn, and Moltbook. Find threads, post comments, create original posts, track engagement stats. Use when: 'post to social', 'social autoposter', 'find threads to comment on', 'create a post', 'audit social posts', 'update post stats'.
-
minhuw Skill Fix Code Quality IssuesFetch and fix current CodeQL and Codacy issues for the minhuw/coquic repository. Use when asked to inspect GitHub Security code scanning alerts at https://github.com/minhuw/coquic/security, Codacy current issues at https://app.codacy.com/gh/minhuw/coquic/issues/current, or to automatically repair static-analysis/security findings without weakening scanner configuration.
-
2233admin Skill Salacia GcRun Salacia garbage collection — analyze drift patterns, rotate audit logs, merge learned patterns into memory. Use when: 'salacia gc', 'clean salacia', 'salacia refine', 'optimize scope', 'salacia learn'.
-
2233admin Skill Salacia StatsShow Salacia audit statistics — event counts, top drifted files, learned promotions. Triggers on: 'salacia stats', 'scope stats', 'drift stats', 'guard stats', 'salacia report'.
-
2389-research Skill ExpertsUse when a project needs multi-perspective review — pre-launch audit, post-refactor check, inherited codebase assessment, or periodic health check. Dispatches parallel expert reviewer agents with persona framing.
Audited -
23blocks-os Skill Mail HandlerBehavioral skill for safe email interaction. Enforces content security boundaries when reading, processing, and acting on email content. All email from non-operator addresses is treated as untrusted external data.
-
amitkrpaliwal Skill Shell ExecutionExecute shell commands, scripts, and CLI tools in the workspace with security controls
-
atypical-consulting Bundle Linus ReviewUse when the user requests a code review focused on engineering correctness, code quality, and technical rigor. On-demand Linus Torvalds persona review evaluating abstractions, error handling, security, logging/observability, performance, and whether the code is actually good. Trigger this skill whenever the user asks for a "linus review", "linus style", "engineering review", "correctness review", "technical review", deep code quality analysis, or wants to know if their code is actually correct, thread-safe, or maintainable. Also trigger when reviewing error handling, DI patterns, race conditions, or anything where rigorous engineering scrutiny is needed.
-
christophera Bundle Session CleanupAdaptive session audit before closure. Uses structured ultrathink with category hints to review session work proportionate to complexity. Detects session depth (light/standard/thorough) and adjusts analysis. Checks for stale planning docs (>30 days). Loads project-specific checks if present. Prepares for session-closure. INVOCATION: Claude uses the Skill tool to invoke this skill when user says "session cleanup", "session review", "audit session", "pre-closure check", or "cleanup". The skill is NOT invoked by running scripts directly. WHEN: User requests session review before closing. Typically after significant work, before "close context" or session-closure. WHEN NOT: Quick session endings (use session-closure directly), mid-session file reviews, trivial sessions with no changes.
-
yknothing Bundle Skills RefinerAudit and refine a skill repository, a single skill, a workflow framework, or an eval set. Covers design quality, context engineering, purpose fit, evidence discipline, and boundary clarity — the structural dimensions that assertion-based testing does not reach. When a target_repo is provided, continues into compatibility review, extraction, and integration planning. Complements skill-creator by providing deep design-level judgment after functional tests pass.
-
mikacr1138 Skill Web3 AuditSmart contract security audit — 10 DeFi bug classes (accounting desync, access control, incomplete path, off-by-one, oracle, ERC4626, reentrancy, flash loan, signature replay, proxy), pre-dive kill signals (TVL < $500K etc), Foundry PoC template, grep patterns for each class, and real Immunefi paid examples. Use for any Solidity/Rust contract audit or when deciding whether a DeFi target is worth hunting.
-
ddoman90 Skill Web SecurityEnforce web security and avoid security vulnerabilities
-
qingye-lab Bundle Setup RootloomPlan, install, inspect, update, or roll back Rootloom Personal Core in a user's Codex home. Supports Skills-only, guidance, and the recommended personal preset. Use when the user explicitly asks for a Rootloom setup plan, installation, configuration, bootstrap, repair, audit, status, update, reduction, rollback, or removal. Never overwrite user-owned files without showing the plan and obtaining exact replacement authorization.
-
thejaustin Skill Sentry AuditFetches unresolved Sentry issues and maps stack traces to local codebase for ShizukuPlus.
Audited -
winbigfox Bundle Testing Best PracticesLaravel test design and review. Use when selecting coverage, naming or structuring tests, choosing assertions or test data, isolating dependencies, testing HTTP or security boundaries, improving suite performance, or reviewing test value. Use framework guidance or search-docs for Pest and PHPUnit syntax.
-
paladini Skill Pr Release AuditAudit pull requests and release readiness across correctness, tests, architecture, security, vendor documentation and version compatibility, repository docs, websites, changelogs, changesets, release notes, and explicit contributor attribution. Use when reviewing a PR, deciding whether it is merge-ready, adding support for a tool, or preparing a release.
-
paladini Skill Harness EngineeringUse when the user asks to improve, fix, or build their repository's AI harness — AGENTS.md, rules, skills, commands, hooks, guardrails, CI sensors — or to act on harness-score audit findings and raise their maturity level.
-
6ixgodd Skill Mine SyncReconcile MINE-owned design with repository reality using code-first synchronization. Use when onboarding an existing repository, after substantial out-of-band changes, when design drift is suspected, before stable release, or when the user requests a repository/design audit. Creates a verified local backup before rewriting design, then updates design to match current code unless the user explicitly protects a decision. Does not modify business code without a separate architecture/plan/execute flow.
-
bitfoundation Skill ReviewReviews code changes against this project's conventions - Bit.BlazorUI usage, theming, enhanced lifecycle methods, WrapHandled, Mapperly, OData, structured logging, nullable awareness, security and concurrency. Reports findings only and never modifies code. Use when the user asks to review changes, review a diff or PR, check code against project conventions, or says "run code review".
-
skillmedev Skill Changelog GeneratorGenerate or update a repository CHANGELOG.md in Keep a Changelog format from git history - grouping commits since the last tag into Added/Changed/Deprecated/Removed/Fixed/Security, rewriting them as user-facing entries, and recommending the semantic version bump. Use when someone asks "generate a changelog from the git log", "update CHANGELOG.md for this release", "what version bump does this release need", or "turn these commits into release notes". Do NOT use for writing benefit-first product announcement changelogs for end users from release notes - use changelog-writer instead; this skill produces the versioned CHANGELOG.md file that lives in the repo.
-
skillmedev Skill Code Review ChecklistRun a systematic multi-pass code review - correctness, design, security, performance, tests - and report findings ordered by severity with concrete, respectful suggestions. Use when someone asks "review this PR", "review this diff", "what's wrong with this change", or wants a pre-merge quality gate on a branch. Do NOT use for a security-only deep audit of a change - use secure-code-review instead - or for writing the ticket or tracking artifact that describes the change - use jira-ticket-writer instead.
-
theedoran Bundle ExplainRead-only analysis of a feature's implementation (or the work just completed in the conversation) across security, performance, maintainability, and edge cases. Writes findings to a markdown report file for the user to act on; changes no code. Verifies security and library best practices against current documentation via Context7. Invoke only when the user explicitly requests `/explain` or `$explain`, optionally naming the feature, paths, or diff to analyze.
-
theedoran Bundle Explain FixAnalyzes the implementation of a feature (or the work just completed in the conversation) across security, performance, maintainability, and edge cases, then hardens it test-first — same analysis as the `explain` skill, but the fixes are applied instead of left to the user. Invoke only when the user explicitly requests `/explain-fix` or `$explain-fix`, optionally naming the feature, paths, or diff to analyze.
-
xindaan Bundle Public MirrorBaut und pflegt oeffentliche Ableger privater Arbeits-Repos — Neuanlage, Sync und das Pre-Push-Leak-Gate. Verwende diesen Skill bei "mach ein public Repo aus ...", "sync das public Repo", "pruefe vor dem Push", "public Ableger aktualisieren", "kann das public werden", "Leak-Check vor Veroeffentlichung", "oeffentlichen Snapshot bauen". Auch wenn ein bestehendes Paar privat/public auseinanderzulaufen droht oder ein Audit der public History gefragt ist.
-
yujunzhou Bundle TellonceEVERY-MESSAGE enforcement: scan for preference/pitfall/friction signals, record to memory, log observations. Also handles memory audit/restructure. Use on EVERY user message — even simple ones, even during intensive technical work, even when you think there's nothing to detect. If you're not invoking this, you're skipping compliance.
Audited -
a-pavithraa Bundle Code ReviewerUse when reviewing Spring Boot 4 / Java 17+ code with concrete files or diffs — pull requests, modules, or pasted Java/Spring sources — for migration risks, architecture boundary leaks, JSpecify null-safety gaps, security flaws, performance regressions, or Spring Data pitfalls. Not for Kotlin-only code, non-Spring frameworks, or generic review advice without code context.
-
a1024053774 Skill Behavioral Acceptance ReviewAudit whether tests, evals, benchmarks, autoresearch tasks, generated artifacts, public APIs, or user-visible workflows provide independent behavioral evidence. Use at a completion checkpoint, not for ordinary implementation or documentation-only changes.
Audited -
aarnold-livefront Skill Iotspy ContextIoTSpy project context — architecture, conventions, and security caveats specific to this codebase. Use when working in the IoTSpy repo, especially alongside dotnet-engineer, security-code-review, or threat-modeling. Pointers into in-repo docs rather than duplicated facts that rot.
-
aarnold-livefront Skill Security Code ReviewSystematic security review across the full attack surface — input handling, authorization, resource use, errors, crypto, secrets, and dependencies. Use when asked to review code for security, audit an endpoint, or check whether something is safe before merging. Also trigger on "is this OK?" / "any issues here?" — security bugs hide in code that looks fine.
-
abh80 Bundle Scala Code OptimizerAudit a Scala file or codebase for refactoring opportunities — Scala 3 modernization, idiom adoption, anti-pattern removal, performance hygiene, tail-recursion safety, and migration cleanup. Produces educational, documentation-backed findings as suggestions only, never editing the file in place. Use this skill whenever the user asks to refactor Scala code, modernize Scala 2 to Scala 3, find Scala anti-patterns, optimize Scala performance, review Scala idioms, apply opaque types, replace value classes, convert sealed traits to enums, migrate implicits to given/using, audit a `.scala` file, or do anything involving cleaning up or improving Scala code — even if they don't explicitly say "audit" or "refactor". Trigger on phrases like "review my Scala", "modernize this Scala", "make this idiomatic Scala 3", "find issues in this Scala file", "check for Scala anti-patterns", or any pasted Scala code accompanied by a request to improve, clean, optimize, or modernize it.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include homebrew-formula, Code Review Checklist, two-factor-authentication-best-practices. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.