Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
akashsebastian333 Skill Sec ReviewReview the current changes for the CWE classes Peephole enforces, as a checklist including the absence-of-guard classes regexes cannot catch. Use when the user says /sec-review or asks for a security review of recent code before committing.
-
aksheyw Bundle Ship SecurityShip Gate security gate, applies the distilled security checklist to the diff; optionally augments with /security-review.
-
alexclymo Skill Tracker CloseUse when ending a session, closing out, wrapping up and updating the task docs, or at session end — triggers like "end the session", "close out", "wrap up and update the task docs", "let's close for today", "session end". Confirms or demotes in-progress work, writes the session's state into tracker/, compliance-checks its own edits against the invariants and the mechanical size/consistency checks, recommends tracker-audit or tracker-supersede when warranted, and commits tracker/ separately from code. Manages project task *documents* on disk, not Claude Code's in-session task tools (TaskCreate/TaskList) — those are scoped to one conversation and never persist; this skill closes out the durable, git-tracked record instead.
-
amergrgic Skill Kodama ConstraintsEnforce non-negotiable safety, scope, security, and quality constraints for implementation and review work.
Audited -
apicurio Skill Security ReviewSecurity review checklist. Use when the conversation involves authentication, authorization, OIDC, secrets, or TLS configuration changes.
Audited -
apify Bundle Review DocsReview Apify documentation for style guide compliance, quality standards, and best practices. Use when user says "review this doc", "check this page", "audit documentation", "review before PR", "is this ready to publish", or "review-docs". Runs automated checks and manual review against Apify style guide.
-
harzva Bundle Rebuttal AuditAudit and polish one-page academic rebuttals or author responses, especially LaTeX/PDF responses with reviewer IDs, strict page limits, compact evidence tables, reviewer-specific concerns, protocol or label-use ambiguity, cost evidence, negative-case framing, and strict short-tail-line/orphan-word checks. Use when Codex must check formatting, page fullness, orphan lines, reviewer coverage, cited evidence, rebuttal tone, or final submission readiness.
-
harzva Bundle Rebuttal Leak AuditAudit academic rebuttals, author responses, LaTeX/PDF text, Markdown drafts, and OpenReview replies for leaked internal/developer notes, local paths, tool traces, private experiment logistics, advisor or AI feedback traces, non-reviewer-facing remarks, and wording that should be rewritten before showing reviewers or ACs. Use when checking whether rebuttal content accidentally exposes Codex/ChatGPT/Claude notes, teacher/advisor comments, TODOs, logs, shell commands, filesystem paths, “AC-facing” meta-language, draft-only reasoning, or score-strategy language.
-
heptameta Bundle Public Repo GuardThis repo (heptabase-cli-skills) is PUBLIC — everything committed is visible to the world and permanent in git history. Use before EVERY commit, push, PR, or release here, and whenever adding or editing docs, skills, scripts, or examples in this repo. Scans staged changes for sensitive or internal data — credentials, tokens, private keys, emails, personal home paths, internal workspace URLs (Notion, Slack, Discord, Linear), real card/workspace UUIDs, IP addresses, secret-bearing filenames — and explains how to judge and fix findings. Also use when asked to review any content in this repo for public sharing.
-
hiero-ledger Bundle Solo Log CI FailureCreate a GitHub bug issue in hiero-ledger/solo for a failed CI workflow run — preserves the job log, solo.log, and diagnostics as a secret gist, extracts error context, and creates a fully-tagged P0 bug linked to the current quarter initiative. Single Bash call per URL, parallelised when multiple URLs are provided.
-
huajielong Bundle Skill EvaluatorEvaluate any skill before installing. Run security gate, score trigger precision, execution quality, and cost efficiency. Get a yes/no recommendation. Use when users find a new skill and ask "这个技能值不值得装?" v3.1: 脚本计数精度+信息密度阈值+脚本完整性检查
Audited -
huajielong Bundle Evil Test SkillMock malicious skill for testing the evaluator's security gate.
-
huangjia2019 Skill Code ReviewingReview code for security vulnerabilities, performance issues, and coding best practices. Activate when the user asks to review code, check code quality, give feedback on code changes, or audit a file.
-
idank Bundle Mandoc FixDrive a mandoc rendering-bug fix end-to-end — scope the bug class, dispatch a subagent in the mandoc source tree, validate via /eval-render audit + compare, and decide whether to promote. Use when the user has identified (or suspects) a class of `-T markdown` rendering bug and wants the full diagnose → fix → validate → promote cycle.
-
deeplook Bundle Follow CligAudit an existing CLI against the CLIG guidelines, guide the creation of a new CLIG-compliant CLI, or fix violations inline. Use when the user wants to check, improve, or build a CLI tool that follows clig.dev best practices.
-
deeplook Bundle Release HygieneAudit and improve release hygiene for GitHub-hosted Python packages, including PEP 740 attestations, PyPI Trusted Publishing, workflow triggers and credentials, action pinning, Dependabot, wheel availability, version consistency, and changelog coverage. Use when checking PyPI release integrity, supply-chain hygiene, attestations, or publish workflows, and when applying approved repository fixes.
-
devclarityai Bundle Finding Skill OpportunitiesUse when asked to find skill opportunities in a codebase, audit a repo for automatable workflows, decide what skills to write, or mine git history, existing automation, and recent Claude Code session transcripts for recurring multi-step procedures worth turning into Claude Code skills.
-
e3742526 Bundle Failsafe ReadinessAudit whether software fails safely under missing dependencies, bad configuration, malformed input, stalled work, interrupted runs, network errors, partial data, and operator mistakes. Use when reviewing graceful startup, shutdown, cleanup, timeout, recovery, degraded mode, logging, and rerun safety.
-
e3742526 Bundle Recovery ReadinessAudit recovery, restore, reconstitution, and rerun safety using NIST-style contingency and resilient-system thinking. Use when reviewing checkpointing, rollback, backup or restore flows, degraded operation, and validation of recovered capability.
-
ekroon Bundle Codespaces Secret SyncSync user Codespaces secret repository access so multiple secrets match a base secret (defaults to first listed secret).
-
shenjingnan Skill Fix Audit安全审计技能,用于检查和修复依赖安全问题
-
gaurav Skill Sync DocsChecks that the documentation files in a repository don't drift far from the source code. Also called a documentation audit.
-
geod Bundle DebtsInterview-driven workflow that consolidates loan statements (mortgage, HELOC, auto, student, credit card) plus manual entries (401(k) loans, family loans, BNPL, medical debt, tax-debt payment plans) into a single household debt ledger and produces structured analysis — total debt by type, weighted-average cost of debt, variable-rate exposure, payoff timeline at current pace, anomaly surface. Strictly descriptive — describes what you owe and at what rate, never recommends refinancing, payoff order, consolidation, or strategy. Use whenever the user wants to understand their debt picture, prepare a balance sheet, or audit their debt stack. Trigger on phrases like "analyze my debts", "what do I owe", "debt breakdown", "consolidate my loan statements", "debt audit", "liabilities", "my liability picture", "weighted average interest rate", "time to payoff", "mortgage statements", "student loan summary", or when the user drops a folder of loan statements and wants to make sense of them. Also trigger on refresh asks —
-
geod Bundle ExpensesInterview-driven workflow for turning a pile of raw credit-card and bank exports into a single consolidated, categorized, person-attributed expense ledger — and then analyzing it. Use this whenever the user wants to understand their household spending, build a personal budget, prepare for a financial review, or audit categories from a previous import. Trigger on phrases like "where is my money going", "consolidate my expenses", "categorize my transactions", "build a budget", "spending breakdown", "lifestyle expenses", "TTM spend", "split spending by person", or whenever the user drops a folder of card/checking CSVs and wants to make sense of them. Also trigger when the user asks to revise an existing expense classification ("move X to category Y", "drop work-trip charges from lifestyle", "split this row into kids vs travel") — the skill's iterative cleanup loop is built for exactly that.
-
geod Bundle Investment AnalysisInterview-driven workflow that consolidates investment statements (PDFs, CSVs, spreadsheets) into a single position ledger and produces structured analysis — through-the-fund allocation, concentration map, tax-location audit, fee breakdown, income/yield map, anomaly surface. Strictly descriptive — describes the current state of a portfolio, never recommends trades or target allocations. Use whenever the user wants to understand what they own, where it sits, how it's distributed, and how concentrated they are. Trigger on phrases like "analyze my investments", "what do I own", "portfolio breakdown", "asset allocation", "consolidate my brokerage statements", "where are my investments", "investment audit", "portfolio concentration", or when the user drops a folder of brokerage / 401(k) / pension statements and wants to make sense of them. Also trigger on refresh asks — the skill is built to re-run quarterly against a stable config and surface what changed.
-
haidrrrry Skill Android Kotlin ComposeJetpack Compose UI engineering for 2026 — edge-to-edge, Material 3, recomposition stability, Modifier ordering, LazyColumn performance, and animations. Use when building composables, fixing jank, theming, adaptive layouts, Canvas drawing, auditing screens, or asking "why does my screen recompose", "Modifier order", "edge to edge Compose", "audit this composable", "review this screen".
-
hannsxpeter Skill Malicious SkillA test skill with security issues
-
haorantang97 Bundle Lab Context Distillation WxUse when a user wants to collect, snapshot, lawfully decrypt, normalize, redact, map, merge, audit, adjudicate, or distill local macOS/Windows WeChat 4.x conversations into evidence-bounded personal context. Also trigger for 微信聊天蒸馏、微信数据库解析后的蒸馏、微信聊天知识库、全量 Map、跨事件归并、冲突补漏、蒸馏验收 or resumed WeChat distillation runs. Do not use for interview-led life review or general knowledge intake.
-
ivan-sincek Bundle Security Requirements AnalysisSystematically extract and classify security requirements from a specification document. Use when the user says "do a security requirements analysis" or "extract security requirements".
-
iwe-org Skill ReflectReorganize this repository's memory with the user — edit the MEMORY.md policy that governs what gets captured and how, analyze the store's frontmatter, propose new index fields, backfill them, group notes into areas with hub pages and subdirectories, extract the people, releases, components, tools and other entities the notes keep mentioning into typed pages the notes link to, prune or merge documents on request, and tune the knobs that pace reading and reminders. Use when the user asks to clean up, reorganize, group, audit, prune, or forget parts of memory, to structure the store into folders, areas, or hubs, to pull entities out of the notes and connect them, to change what memory captures, or to make the store more queryable.
-
jd-opensource Bundle Code ReviewReview code changes for quality, security, performance, and correctness following project-specific standards. Use when reviewing pull requests, examining git diffs, or when the user asks for a code review. This skill should be used proactively — when the user asks for a review without specifying commits, automatically detect the current branch and diff against the main branch.
-
johanthoren Bundle Code StandardsLanguage-agnostic code standards for writing clean, maintainable code. Covers modular design, functional patterns, error handling, security, and testing. Make sure to use this skill whenever writing, refactoring, or reviewing any code, even for quick fixes, prototypes, or single-file changes. This is the baseline for all code quality. Language-specific skills, if present, may override these defaults.
-
johanthoren Bundle Security AuditorAdversarial security auditing workflow for source changes. Make sure to use this skill whenever reviewing code before merge, hunting for vulnerabilities, auditing dependencies, or assessing security exposure of new features, even if the user doesn't explicitly ask for a security review. Includes OWASP-focused scans, dependency-audit attempts, coverage accounting, and strict pass/block recommendations.
-
joseruiz1571 Bundle HipaariskassessmentConduct a structured HIPAA Security Rule risk assessment for AI and emerging technology systems. USE WHEN conduct risk assessment, HIPAA risk analysis, assess risks for AI tools, security risk assessment, risk and vulnerability analysis, what are our AI risks, evaluate our risk posture, complete a risk assessment, document risks for AI adoption, 164.308 risk analysis, OR user needs to satisfy the HIPAA Security Rule risk analysis requirement.
-
joseruiz1571 Bundle VendorriskassessmentConduct structured AI vendor risk assessments against HIPAA compliance and data privacy standards. USE WHEN assess vendor, evaluate AI tool, vendor risk check, is tool HIPAA compliant, can we use tool with PHI, vet AI vendor, vendor due diligence, review AI product, AI procurement risk, vendor security review, OR user pastes vendor documentation or privacy policy for analysis.
-
bot8080 Bundle Powerhouse Claude Project Setup KitUse this skill whenever the user wants to CREATE a new AI project from scratch OR IMPROVE/audit an existing project's knowledge base and instruction files. Triggers include: "create a new project for X", "help me set up a project", "build a knowledge base for my project", "improve my project instructions", "audit my knowledge base files", "my project files are getting messy", "simplify my project", "restructure my project docs", "my AI instructions are too complex", "refresh my knowledge base", or any mention of wanting better project organization for AI assistants. Always use this skill when the user is thinking about project setup, project instructions (system prompts), or knowledge base files — even if they don't use those exact words.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include sec-review, ship-security, tracker-close. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.