Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
adeluise Skill AuditChecks active decisions in decisions.md against the current codebase and git history, then reports which still hold, which have been violated, and which look superseded. Use when reviewing whether past decisions still hold, before a refactor, or when the decision log feels out of date.
Audited -
adobe Bundle Guide ReviewReview a multi-chapter guide, series, or book from six specialist perspectives. Orchestrates Series Editor, Non-Technical Proxy, Practitioner Proxy, Consistency Auditor, Diagram Reviewer, and Claims Auditor. Use for single-chapter review, full-series audit, consistency checks, diagram audits, and claims audits.
142 -
agentlogbooks Bundle Deep Code ReviewHotspot-first, multi-pass code review for pull requests, branches, pasted diffs, and work-in- progress changes. Models behavior changes, selects risky hotspots, acquires minimal local context, generates candidate findings and questions, runs a skeptic pass and dedup, then surfaces at most 5 high-signal outputs. Persists a per-run JSONL trace and per-PR SQLite ledger under ./.logbooks/code-review/. Invoke for any concrete review request: "review PR #123", "deep review", "check this diff", "review current branch", "review staged changes", "review codebase", "audit this repo", "review this repo". Do not invoke for vague opinion requests that have no diff, code, or concrete review target ("what do you think of these changes?", "any concerns?", "thoughts on this?") — requests like "check this diff" or "feedback on this PR" are reviewing tasks even without the word "review".
-
junhan2 Bundle Fable Auditfable-audit · score prompts against the Fable 5.1 guide
-
junhan2 Skill Fable Setupfable-setup · choose delivery, mode, effort; audit conflicts
Audited -
managementmo Skill A2l SyncRefresh an Agent2Learn vault safely, choose sync scope, read AUDIT.md, and recover from expired-session exit 75.
-
masahirosakoda Bundle Owasp SecurityUse when reviewing code for security vulnerabilities, implementing authentication/authorization, handling user input, or discussing web application security. Covers OWASP Top 10:2025, ASVS 5.0, and Agentic AI security (2026).
Audited -
openly-useful Bundle Pickup SwarmUse when recovering interrupted work, resolving an uncertain handoff, or discovering explicitly requested outstanding workflows. Plain current-status queries use the existing status snapshot rather than a recovery audit.
-
sandy-zippy Skill DiagnoseMerge the audit and visibility reports into the 15 fastest fixes ranked by effort vs impact, plus the exact questions people ask AI that the site never answers. Use when asked "what do we fix first", "run diagnose", or after audit + visibility have produced reports.
-
codingrajan Bundle Post HumanizerWrite or rewrite social posts and short online content so they read like a real person wrote them, not a chatbot. Use whenever the user asks to "humanize" a post, or asks Claude to "write," "draft," "compose," or "post" a LinkedIn post, X/Twitter post or thread, blog post, newsletter section, Instagram or Facebook caption, or similar short-form content. The rules apply equally to editing existing text and to Claude's own freshly composed output: run the same audit on anything you write. Targets LinkedIn "broetry" line breaks, manufactured staccato drama, the "I did X, here's what I learned" formula, fake-candid openers ("Honestly?"), CTA bait ("Agree? Thoughts? Drop a comment below"), emoji-bulleted lists, em dashes, rule-of-three, and "it's not just X, it's Y," while keeping a real voice, contractions, and genuine short sentences. Based on Wikipedia's "Signs of AI writing" guide.
-
cybertheory Skill Audit SkillVerify document for secrets and policy before approval
Audited -
cyhzzz Bundle Audit Book Writing V1Write comprehensive audit books and review materials with systematic workflow. Use when writing audit survey books, practical guides, case analyses, or review materials on topics like financial audit, internal control audit, compliance audit, performance audit, IT audit, internal audit, government audit. Triggers on requests for "审计书籍", "审计综述", "审计实务", "写书", "审校", "审计案例分析", or mentions of writing audit-related books or review materials.
-
cyhzzz Bundle Audit Book Writing V2审计书籍写作增强版skill,提供四轮评审流程、双模式优化、多文件留痕,集成100个法律法规知识库。
-
cyhzzz Bundle Audit Book Writing V4审计书籍智能校对优化技能,基于26步校对优化流程,提供智能标记、法规验证、案例替换、内容扩充、结构优化等功能。
-
decocms Bundle Generate ReportGenerate a structured Markdown report with YAML frontmatter for repository health monitoring. Use when the user asks to create a report, health check, audit, scan result, or status update for a repository.
-
etherscan Bundle Etherscan Contract ReviewReview and explain verified deployed EVM smart contracts from a contract address and chain. Use when a user asks to break down what a Solidity contract does, map its architecture and source files, identify user/admin flows, proxy or implementation roles, asset movement, privileged controls, events, state variables, or unresolved uncertainty for developer onboarding, integration triage, or preliminary technical review. This is a developer-oriented contract review, not a security audit or safety certification.
-
etherscan Bundle Etherscan Transaction DebuggerAnalyze and explain one or two EVM transactions using live Etherscan data and human-verifiable Etherscan evidence links. Use when a user provides a transaction hash or asks what happened, why a transaction failed, which contracts or internal calls were involved, where assets moved, whether a proxy implementation executed, which call reverted, or why two transactions behaved differently. Reconstruct the supported execution path, decode calls and events, summarize asset and permission changes, showcase the relevant Etherscan transaction, contract, token, label, log, and internal-transaction views, and provide plain-English, developer, support, or security-focused explanations with confidence and limitations. Do not use for broad wallet investigations, multi-hop laundering traces, or full contract audits.
-
evomap Skill Ar Workspace SafetyHard filesystem and Python-environment safety rules for ar-runtime skills on a Linux GPU server. MUST be applied for ANY write, delete, move, install, or python invocation. Triggers like write file, save, mkdir, rm, delete, move, mv, cp, overwrite, cleanup, git reset, git clean, pip install, conda create, conda install, python3, python, miniconda, env, sudo, .ssh, .env, secret, credentials, /etc, /usr, /var, /opt, 删除, 安装, 写入, 清理. Independent of ar-experiment-runner — load and apply this skill even when no experiment context is in scope.
-
fayazara Skill Add BindingAdding a new Cloudflare binding (KV, R2, D1, Durable Object, Queue, secret, or environment variable) to this TanStack Start + Cloudflare Workers project. Use this skill whenever the user asks to add a binding, connect a new Cloudflare service, wire up KV/R2/D1/Queues, add a secret, or set an environment variable. Also trigger when the user says things like "I need caching" (KV), "add file storage" (R2), "set up a queue", "add a secret for my API key", "I need a new D1 database", or "add an env var". This skill covers the exact wrangler.jsonc configuration for each binding type, the cf-typegen step to get TypeScript types, and the usage patterns for accessing bindings via `import { env } from "cloudflare:workers"`.
-
feichangai-team Skill Cn Data ExportAssess cross-border data transfer compliance under PIPL/网络安全法/数据安全法. 7-question risk assessment determines compliance pathway (安全评估/标准合同/认证). Covers personal information thresholds, important data identification, CIIO obligations. Use when: transferring data from China overseas, assessing if data export needs CAC security assessment, determining which compliance pathway applies, checking PIPL compliance for international business, evaluating data localization requirements.
-
flaqai Bundle Dsh Plugin ReviewReview a DeepSeek Harness plugin, Bundle, Profile, or Patch for correctness, compatibility, lifecycle, and security. Use for pre-install audits, code review, publication readiness, version upgrades, or investigating leaks, unsafe permissions, broken replay, and plugin-order problems.
-
florianbruniaux Skill Eval RulesAudit .claude/rules/ files for structural correctness, glob validity, and real-world usefulness. Resolves each paths: pattern against actual project files, then asks whether each rule is still relevant. Can update rules in-place. Use when setting up rules for the first time, debugging rules that fire too often or never, or doing a periodic rules hygiene pass.
-
florianbruniaux Skill Eval SkillsAudit all skills in .claude/skills/ for frontmatter completeness, effort level appropriateness, allowed-tools scoping, and content quality. Produces a scored report with effort-level recommendations for each skill. Use when onboarding, reviewing skill quality before shipping, or adding effort fields to an existing skill library.
-
florianbruniaux Skill Token AuditAudit Claude Code configuration to measure fixed-context token overhead and produce a prioritized action plan. Use when sessions feel slow, context compresses early, or after adding many rules files.
-
forjd Bundle Repo HardeningAudit and harden GitHub repository security settings using the gh CLI. Use when the user wants to review or improve repository security posture, enforce branch protection, enable secret scanning, configure merge policies, lock down GitHub Actions permissions, or apply security best practices. Triggers on requests to "harden", "secure", "lock down", or "audit" a GitHub repository, even if they just say "make this repo more secure".
-
full-stack-skills Bundle NestjsProvides comprehensive guidance for NestJS using the official documentation. Use when the user asks about NestJS architecture, controllers, providers, modules, middleware, guards, pipes, interceptors, dependency injection, GraphQL, WebSockets, microservices, OpenAPI/Swagger, security, or testing.
-
arweaveteam Bundle Ar Security Triage InternalVerify the findings in an internal security review report against current master and file the validated ones as issues. Use only when the user explicitly invokes this skill with a report file or issue URL.
-
baz-scm Skill ReviewReview code changes with Baz indexed search — a diff-scoped code review that checks the change against the rest of the org's repos, not just the files in front of it. Use when asked to review changes, review a diff or branch, review a pull request, check changes for bugs or security issues, or find what is wrong with the current changes before pushing. Invoke with /baz:review; supports committed / uncommitted / --base / --pr scopes and an optional --fix loop that applies the fixes it finds.
Audited -
beginnersinai Skill MapThis skill should be used when the user types '/map', asks to 'run an AI mapping audit', 'scan my workspace for AI gaps', 'find where AI should be in my business', or wants a full workspace AI audit. Runs a comprehensive AI Mapping Audit based on Kim, Kim & Koning (2026) research.
Audited -
beginnersinai Bundle AI Mapping AuditAutomatically activates when users discuss AI adoption strategy, ask where to use AI in their business, want to find new AI use cases, or mention the 'mapping problem'. Provides the 10-function framework and examples of how other firms have reorganized around AI to help users discover unmapped opportunities.
-
beginnersinai Skill Map VentureThis skill should be used when the user types '/map-venture', asks to 'audit a single project', 'map AI usage for this venture', or wants a focused AI mapping audit on one specific project or business. Provide the venture name or directory path as context.
Audited -
belsrc Bundle Engineering CouncilConvene a council of engineering personas (Knuth, Beck, Carmack, Lamport, Fowler, Schneier, Hickey, and more) to evaluate a technical decision from opposing viewpoints, then synthesize where they agree and where they conflict. Use this whenever the user wants multiple expert perspectives on a hard call, a design or architecture review, a debate between schools of thought, a tradeoff analysis, or says "engineering council", "council", "duo", "triad", or "what would X think". Trigger even when the user does not name the skill but is weighing a difficult architecture, performance, security, ML, API, testing, refactoring, or distributed-systems decision and would benefit from contrasting expert takes rather than a single answer.
-
block Skill Trailblaze Validate OobUse when validating or evaluating Trailblaze's out-of-box (OOB) user experience — does what the `trailblaze` skill claims actually match the real installed CLI? Triggers on requests to "validate the Trailblaze skill", "test the Trailblaze OOB experience", "evaluate Trailblaze UX", "check if the skill matches the CLI", "audit the Trailblaze CLI for new-user friction", or running an OOB regression check after the framework changes.
-
akashsebastian333 Skill PeepholeShow or change Peephole's enforcement mode (guided (default), audit, strict, hardened, off). Use when the user says /peephole, wants to see the current security mode, or asks to make enforcement stricter or looser.
-
akashsebastian333 Skill Sec DebtExplain and list Peephole sec-debt markers — deliberate, human-authorized security trade-offs recorded in code. Use when the user says /sec-debt, wants to knowingly accept a security finding, or asks what deferred security items exist.
-
akashsebastian333 Skill Sec AuditPrint Peephole's security audit report for this project — current mode, binary integrity, the CWE-mapped decision tally, sec-debt items needing approval, and tamper-evident log-chain status. Use when the user says /sec-audit or asks what Peephole has blocked or flagged.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include guide-review, generate-report, eval-rules. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.