Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
buggregator Skill QA Testing AppQA expert that analyzes the entire application, generates structured test cases, and executes end-to-end testing. Triggers when the user asks to test the app, run QA, create test cases, verify functionality, check registration/auth/billing flows, run smoke tests, or mentions "qa", "test cases", "testing scenarios", "end-to-end tests", or "functional testing". Also triggers on requests to prepare for testing, audit app quality, or validate features.
-
burythehammer Bundle Claude Md SlimAudit and slim down bloated CLAUDE.md files — and other overlong project markdown like READMEs — by applying progressive disclosure. Use whenever the user asks to audit, trim, shrink, slim, refactor, declutter, restructure, or optimise a CLAUDE.md (or AGENTS.md / project memory) file, says their CLAUDE.md or README is too long or bloated, mentions context bloat or token waste from project instructions, wants rules moved into .claude/rules/ or subdirectory CLAUDE.md files, wants long docs split into linked pages, or asks about @imports or progressive disclosure — even if they don't name the file explicitly (e.g. "my project instructions are getting out of hand").
-
bygama Bundle Extracting Design MdReverse-engineers a DESIGN.md (Google Labs format) from an already-built project — electing tokens from the surfaces the owner designates as reference rather than from whichever value is most frequent, shipping everything unconfirmed as `[provisional]`, and writing decisions per module under a `### Global` tier. Use whenever an existing codebase should adopt DESIGN.md, when UI values have multiplied (several grays, mixed radii, inconsistent buttons), when the owner says the UI looks inconsistent or "quedó desprolijo", when an app has too many surfaces for one flat list of decisions, or to re-audit drift after a migration batch — even if nobody says the word DESIGN.md.
-
christophecapel Bundle CheckSession-close audit — session-scoped manifest, two-section open items, decisive close signal. Runs the `/check` audit defined in `check.md`. Use when the user says "check", "audit this session", "close the session", "definition of done", or wants a clean-vs-blocked verdict before ending a session.
-
christophecapel Bundle Error AuditAudit errors across Claude Code session transcripts. Scans ~/.claude/projects/*.jsonl for 7 error classes (tool_error, validation_error, permission_denial, hook_block, bash_fail, retry_storm, read_before_edit), clusters by root-cause signature, and surfaces top N with suggested remediation tiers. Use when the user says "error audit", "errors across sessions", "system health errors", or "/error-audit".
-
christophecapel Bundle Press1 CheckAudit which Bash commands required manual approval ("press 1") in Claude Code sessions. Use when the user says "press1-check", "press 1 check", "permission audit", or wants to review which commands need allow-listing.
-
circleci Skill Content ReviewReview CircleCI documentation pages for quality, clarity, and adherence to style guidelines. Use this skill whenever the user asks to review, audit, or assess documentation content, check for style compliance, evaluate page quality, or wants feedback on docs pages. Also trigger when the user mentions content quality, readability issues, or asks "how does this page look" or "is this page good." Even if they just reference a docs file path and ask for a review or feedback, use this skill.
Audited -
ckorhonen Skill Reflect FeedbackAudit whether past reflect improvements are actually working. Reads the .reflect/applied.md ledger and checks each applied rule, skill, command, or script for evidence it fired and helped; grades entries verified, unused, or regressed, and prunes dead weight. Use on a schedule (weekly or every ~10 sessions), when the user asks "are these improvements working?", or before a reflect-memory consolidation pass. Requires prior reflect runs — if no .reflect/ ledger exists, run reflect first.
Audited -
kaelys-js Bundle Sec Auditsec-audit
-
layr-labs Skill Audit ExtractorExtract findings from PDF audit reports and convert them to a markdown checklist. Use when the user asks to process an audit report, extract audit findings, or create an audit action items list. (project)
-
leonvanzyl Bundle Review An AppReview a web app that already exists and report what is actually wrong with it — security holes checked against the OWASP Top 10, search and AI discoverability that has drifted out of date, and anything the app claims that it no longer does. Use when the user asks to review, audit, or check over an app, wants a security review or vulnerability check of a whole codebase rather than a diff, asks whether their sitemap, robots.txt or llms.txt are still correct, or suspects their landing page, docs or privacy policy have fallen behind the product. Reviews the app as it stands today, not a pull request and not a build sheet, so it catches what was already wrong before the current branch. Read-only by default; gathers evidence once, runs independent lenses over it in parallel, re-checks anything uncertain with a command, and names every check it could not perform rather than implying it passed.
-
omarmfouad25 Skill Sl Geo AuditAudit and score a site for AI citation readiness across three dimensions: Foundations, Answer Engine and Generative Citation. Use when the user asks why AI assistants never mention their brand, wants an AI visibility audit, asks how to measure GEO, wants to know why competitors get cited instead, needs a share-of-citation baseline, or asks what to fix first to appear in AI Overviews, ChatGPT, Perplexity or Claude answers.
Audited -
onekeyhq Bundle Onekey SwapUse when the user asks to swap tokens, trade ETH for USDC, buy tokens, sell tokens, exchange crypto, get a swap quote, check swap status, perform a cross-chain swap or bridge, swap SOL/SPL, swap BTC/TBTC, sign a BTC PSBT, 换币, 买币, 卖币, 兑换, 交易, or 跨链. Do NOT use for token research or prices — use onekey-market. Do NOT use for security audits — use onekey-security. Do NOT use for wallet balances or transfers — use onekey-wallet.
-
onekeyhq Bundle Onekey MarketUse when the user asks about token price, BTC/SOL market questions, trending tokens, search token, kline chart, candlestick data, trading volume, top holders, liquidity, token info, 代币价格, 热门代币, K线, BTC 行情, SOL 行情, or 搜索代币. Do NOT use for swap execution — use onekey-swap. Do NOT use for security audits — use onekey-security. Do NOT use for wallet balances or transfers — use onekey-wallet.
-
onekeyhq Bundle Onekey WalletUse when the user asks to log in with OneKey App Transfer/App Transport Bot Wallet or hardware wallet, check balance/assets, receive or derive BTC/Solana addresses, send/transfer BTC/SOL/tokens, view history, check wallet status, 查余额, 登录钱包, 硬件钱包, 转账, 发送, 收款, 导入钱包, or 交易记录. Do NOT use for swap execution — use onekey-swap. Do NOT use for token prices or research — use onekey-market. Do NOT use for security audits — use onekey-security.
Audited -
onekeyhq Bundle Onekey SecurityUse when the user asks is this token safe, wants a honeypot check, security scan, simulate transaction, risk assessment, hardware wallet safety, App Transfer/App Transport Bot Wallet secret safety, seed/private-key exposure requests, 代币安全, 蜜罐检测, 安全审计, 硬件钱包安全, or 模拟交易. Do NOT use for token prices — use onekey-market. Do NOT use for swap execution — use onekey-swap. Do NOT use for wallet balances or transfers — use onekey-wallet.
Audited -
openfort-xyz Bundle Openfort Backend WalletsCreate and operate Openfort backend wallets (developer custody) for EVM and Solana from server-side code. Use this skill whenever: creating backend wallets, sending transactions from server, importing/exporting private keys with RSA encryption, signing data/messages/typed-data server-side, EIP-7702 delegation, Solana transfers (SOL/SPL/USDC), gasless transactions, fee sponsorship, policy engine rules, wallet secret auth, webhooks, or operating wallets programmatically without user interaction. Trigger on: "backend wallet", "developer custody", "server-side wallet", "walletSecret", "sendTransaction from backend", "import private key", "export private key", "EIP-7702", "Solana transfer server", "gasless", "fee sponsorship", "policy rules", "batch transactions", "sponsor gas", "webhook", or any server-side wallet operation with Openfort.
-
paladini Skill Publish Devto To MediumEnd-to-end DEV.to to Medium cross-post: verify session, import draft, review formatting against source markdown, apply fixes, security checks, confirm save, and publish only when the draft is fully corrected. Use when the user wants a complete corrected Medium post from an existing or new DEV.to article.
-
patriksimek Skill MaintainerThe vm2 security-advisory maintainer role. Defines authority, scope, the triage/dedup/credit process, and the reporter correspondence loop for GitHub Security Advisories on the repo. Use when asked to "triage advisories", "work the security queue", "check for duplicates", "take the next vulnerability", "who reported X", or at the start of any session that touches the advisory queue. Delegates the actual patching to /fix-vulnerability and the landing to /merge-fix — this skill governs everything around them.
-
patriksimek Skill Fix VulnerabilityFix a vm2 sandbox escape vulnerability given a Security Advisory ID (GHSA/CVE). Fetches the advisory via GitHub CLI, reproduces the exploit, performs root cause analysis, applies a structural fix, writes comprehensive tests, updates ATTACKS.md, and red-teams the result. Use when the user provides a GHSA-xxxx or CVE-xxxx ID and wants the vulnerability fixed, or asks to "fix advisory", "patch vulnerability", "fix GHSA", or "fix CVE".
-
peersyst Bundle XrplApply opinionated rules and security patterns to JavaScript and TypeScript code that uses the xrpl.js client library to interact with the XRP Ledger. Use when users want to write a new XRPL integration with xrpl.js, review or refactor existing xrpl.js code, sign or submit a transaction, construct or credit a payment, work with issued currencies, AMM, NFToken, escrow, or payment channels, query account or ledger state, or audit an XRPL integration for security issues like partial-payment inflation, missing LastLedgerSequence, missing DestinationTag, or unsafe key management.
-
peersyst Bundle Xrpl GoApply opinionated rules and security patterns to Go code that uses the Peersyst/xrpl-go client library to interact with the XRP Ledger. Use when users want to write a new XRPL integration in Go, review or refactor existing xrpl-go code, sign or submit a transaction, construct or credit a payment, subscribe to ledger or transaction streams, work with issued currencies, AMM, NFToken, escrow, or payment channels, query account or ledger state, or audit an xrpl-go integration for security issues like partial-payment inflation, missing LastLedgerSequence, missing DestinationTag, or unsafe key management.
-
robertderose Skill Dstack Audit FeatureAudit approved intent, implementation, and current documentation for drift using deterministic evidence.
-
roshaw Skill Translate Audittranslate-audit
-
rusq Skill Pre ReleasePrepare this repository for a release. Use when asked to do pre-release checks, summarize changes since a previous tag, update WHATSNEW.md or changelog entries, update CONTRIBUTORS.md, audit command long help or docs for release-visible features, or verify release documentation consistency.
-
sap-samples Skill Doc SyncAudit AI guidance files (CLAUDE.md, copilot-instructions.md, .github/agents/, .github/prompts/) for consistency. Use after updating any AI-facing documentation.
-
sciphys-ai Bundle Audit Scientific ClaimsAudit scientific claims for traceability, evidential support, uncertainty, provenance, and reproducibility. Use to review a manuscript, report, AI-generated analysis, Evidence Bundle, benchmark submission, or publication package before expert review or release.
-
ta-lib Skill Sec CheckOn-demand semantic security review of one PR before merge — reads the diff and judges intent, rather than just pattern-matching. Blocks and asks for human review on any suspicion instead of trying to resolve it. Use when asked to security-check, vet, or judge whether a PR is safe to merge. Triggers on "sec-check", "security check this PR", "vet this PR", "is this PR safe to merge".
-
theagenticguy Bundle Audit SkillScore a single skill against the gardener rubric. Reads the skill's SKILL.md, references/, and templates/, then writes a 7-dimension scorecard with per-criterion rationales and a recommended-actions list. Isolated counterpart to /gardener: same rubric, one item at a time. Use when the user asks to audit a skill, score a skill, check if a skill is healthy, or wants to re-score after making changes.
-
theagenticguy Bundle Rewrite DescriptionsPropose description rewrites to resolve skill collisions. Given a collision pair from a gardener audit, reads both skills' descriptions, generates before/after rewrites with negative discriminators, and writes a proposal Markdown the user applies manually. Uses current Claude prompting discipline: positive imperatives, motivation clauses, scope explicit. Use when the user asks to fix a collision, rewrite a description, disambiguate two skills, or mentions resolving a gardener-flagged pair.
-
tmchow Bundle Vhs Terminal RecorderThis skill should be used when the user names Charmbracelet VHS, asks to use the `vhs` CLI, wants a terminal recording, terminal GIF, terminal MP4/WebM, `.tape` file, scripted terminal demo, or a reproducible command-line screencast. Do NOT use for generic browser recording, full desktop screen capture, or unscripted secret-bearing interactive sessions.
-
tuist Skill Takt ActionDesign or review Takt actions. Use when working on project-local configured uses of capabilities, including defaults, secret bindings, labels, and ownership metadata.
-
librocat Skill Knowledge ReviewReview and improve a librocat library: raise link health, add missing architecture/decision concepts, and prepare knowledge changes as a Git PR. Use when the user asks to audit, clean up, or level-up an OKF bundle, when ingesting a code repo and wanting durable higher-level concepts on top of the mechanical Code File concepts, or when reviewing a knowledge PR.
-
linear Skill Stale LabelsAudit a Linear team's labels and report stale ones. Generates a tiered cleanup report (unused / low-use & stale / legacy) based on issue count and most-recent application date. Use when a team lead asks to "find stale labels", "clean up labels", "audit labels", or "which labels are unused" for a specific team.
-
liuyueyi Skill Code ReviewerReviews Java code for best practices, security issues, and Spring Framework conventions. Use when user asks to review, analyze, or audit code.
-
lm203688 Bundle Cn AI VisibilityAnalyze brand/keyword visibility across 5 Chinese AI search engines (DeepSeek/Kimi/豆包/通义千问/文心一言). Get per-engine citation logic analysis, visibility scoring, and optimization strategies. Use when: checking if your brand appears in AI search results, optimizing content for AI citation, monitoring brand visibility in Chinese AI engines, planning GEO (Generative Engine Optimization) strategy for China market. RUN: ./check-visibility.sh 'brand' --api for instant 0-100 audit score.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include qa-testing-app, claude-md-slim, extracting-design-md. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.