Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
madappgang Bundle 1password SdkHow to load secrets and environment variables from 1Password programmatically using the official @1password/sdk (JavaScript/TypeScript). Use this skill whenever code needs to read a 1Password secret, resolve an op:// reference, fetch many secrets at once, discover the fields/sections of a 1Password item (e.g. to import API keys), or read a 1Password Environment — even if the user doesn't name the SDK explicitly. Triggers on: "@1password/sdk", "op://", "OP_SERVICE_ACCOUNT_TOKEN", "DesktopAuth", "resolve a secret from 1Password", "1Password service account", "1Password Environments", "fetch API keys from 1Password", or wiring 1Password into a Node/Bun/TypeScript app. Prefer this in-process SDK over shelling out to the `op` CLI unless the task specifically needs the user's interactive `op signin` session.
-
perryts Skill Port NPM To PerryPort an npm package to run under Perry — audit it for TypeScript-subset gaps, add it to perry.compilePackages, and patch whatever breaks so the package compiles natively. EXPERIMENTAL — feedback welcome at github.com/PerryTS/perry/issues/115.
-
phelps-sg Skill Vault InsightsAudit the Obsidian vault for inconsistencies and latent insights
-
phucbm Skill Audit BlocksFast structural audit of all blocks — checks required files, wrapper attributes, fields.json timestamp, preview.png. No AI, runs instantly via script.
-
phucbm Skill Audit Blocks DeepDeep AI audit of all blocks — runs structural checks first, then uses AI to review content quality, descriptions, grammar, admin render justification, wrapper usage, and empty-state messages.
-
pingidentity Skill TestingRequired conventions for writing and modifying tests — framework, file template, section ordering, and security test requirements. TRIGGER when: creating or modifying any file under test/; adding, changing, or removing tool parameters or response behavior that requires test updates; user asks about testing patterns or test structure.
-
pingidentity Skill Review ConventionsCode review checklists and common pitfalls for this codebase — security, correctness, conventions, and verification commands. TRIGGER when: reviewing a PR or diff; user asks to review, check, or validate changes; running /review or /security-review; verifying tool implementation correctness before committing.
-
pravidhi-net Skill Pravidhi Commit ProtocolA complete, opinionated development workflow skill for agents. Triggers when the user asks to implement a feature, fix a bug, or refactor code in a Git repo. Enforces hygiene, security, quality, and atomic commits.
Audited -
quanhua92 Bundle First PrinciplesApply first-principles thinking with the D.A.R.E. sequence: decompose the problem, audit inherited assumptions, recombine surviving building blocks, and test them against reality. Use when the problem framing, requirements, constraints, or conventional solution may rest on assumptions that should be reconstructed from fundamentals, or when the user explicitly requests first-principles reasoning.
-
rackulalives Skill Vibe Security SkillThis skill helps Claude write secure web applications. Use when working on any web application to ensure security best practices are followed.
Audited -
meleantonio Skill Formalize ProofFormalize a natural-language mathematical proof in Lean 4 (or another kernel) incrementally: small goals first, expand, audit mismatches, refactor. Use after an informal proof of an open problem is drafted and audited, or when the user asks for Lean formalization of a proof artifact.
-
meleantonio Skill Adversarial Proof AuditIndependently attack a candidate mathematical proof: find gaps, circular lemmas, silent hypothesis changes, insufficient uniformity, and false completions. Use after any draft proof of an open problem, before claiming success, or when the user asks to audit, stress-test, or red-team a proof.
-
shev-pro Bundle Code ReviewPerform structured code reviews on MR/PR diffs, individual files, or code snippets. Use this skill whenever the user asks to review code, check a pull request, audit an implementation, validate a merge request, spot bugs, assess code quality, or evaluate any piece of code before merging or shipping. Trigger even on soft phrases like "can you check this?", "does this look right?", "any issues here?", or when the user pastes a diff or links a GitLab/GitHub MR. Covers Python/FastAPI, Java/Spring, TypeScript/Node.js, Go, and Kotlin, but applies to any language.
-
irelia0nerf Skill Audit Trail Bcb538Use SEMPRE que o usuário mencionar SealedRecibo, DecisionID, Merkle chain, audit trail, evidência criptográfica, BCB 538/2025, retention paradox, LGPD vs retenção bancária, RFC 3161 timestamping, TSA, Zero-Persistence, shred_key, crypto-shredding, ou WORM tier no BigQuery. Triggers literais: "audit trail", "Merkle", "SealedRecibo", "DecisionID", "BCB 538", "retention paradox", "Zero-Persistence", "shred_key", "RFC 3161". Esta skill NÃO é genérica — é específica do contrato de evidência do REX Guard. Se o pedido for sobre logging/observabilidade comum, use outra skill.
-
irelia0nerf Skill Cg Blocker ResolutionUse SEMPRE que o usuário mencionar critical gap, CG-001, CG-002, CG-003, fechamento de bloqueador, pentest blocker, Bradesco blocker, hardcoded policy hash, audit gate ausente, shred_key simulado, localStorage JWT, AES-128 → AES-256-GCM, ou qualquer hygiene item que trava demo bancária. Triggers literais: "CG-001", "CG-002", "CG-003", "critical gap", "bloqueador Bradesco", "pentest", "policy_snapshot_hash", "shred_key fake", "JWT localStorage", "hygiene". NÃO use para bugs comuns ou refactors genéricos — esta skill é cirúrgica para os 4 críticos abertos do REX Guard.
-
tmonk Bundle Stata Referee ResponseOrganize and execute Stata workflows for referee responses, robustness requests, and coauthor follow-ups. Use when the user needs to answer a critique with targeted reruns, tables, figures, and a defensible audit trail.
-
asymmetric-al Bundle PayloadUse when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API). Use when debugging validation errors, security issues, relationship queries, transactions, or hook behavior.
-
harperaa Skill Security HeadersConfigure security headers to defend against clickjacking, XSS, MIME confusion, and SSL stripping attacks. Use this skill when you need to set up Content-Security-Policy, X-Frame-Options, HSTS, configure middleware headers, or understand browser security features. Triggers include "security headers", "CSP", "content security policy", "X-Frame-Options", "HSTS", "clickjacking", "MIME confusion", "middleware headers".
-
harperaa Skill Vibe Coding Security Awareness OverviewUnderstand the security risks inherent in AI-generated code and vibe coding. Use this skill when you need to understand why AI generates insecure code, statistics on vulnerabilities, real-world breach examples, or overall security awareness for AI-assisted development. Triggers include "vibe coding security", "AI code security", "AI vulnerabilities", "security risks AI code", "why AI insecure", "AI security awareness", "AI generated code risks".
-
harperaa Skill Supply Chain Dependency Risks AI CodeUnderstand supply chain vulnerabilities and dependency risks in AI-generated code including outdated packages, malicious packages, and dependency confusion attacks. Use this skill when you need to learn about vulnerable dependencies in AI code, understand supply chain attacks, recognize typosquatting, or identify outdated package suggestions. Triggers include "supply chain attacks", "dependency vulnerabilities", "outdated packages", "malicious npm packages", "typosquatting", "dependency confusion", "vulnerable dependencies AI", "npm security".
-
chase-key Bundle Rell DomainThe RELL compliance audit engine — architecture, philosophy, active modules, and development status.
-
barlevalon Bundle Documentation SystemApply the Diátaxis framework to write, audit, organize, and improve technical documentation. Use when creating or revising tutorials, how-to guides, reference, explanation, docs IA, README sections, or documentation that feels mixed, incomplete, or hard to use.
-
shrek-abaper Bundle Abap Code ReviewPerforms structured pre-release security and quality review of SAP ABAP programs across 9 dimensions (SEC, AUTH, DATA, PERF, STD, INTERFACE, CHANGE, COMP, FUNC), producing a formal sign-off-ready Markdown assessment report. Trigger when the user asks to review, audit, assess, or check ABAP code before release — phrases include: 'security review', 'risk check', 'release audit', 'code review', 'check before transport', 'safe to release', or 'can this go to production'; also when a program name (e.g. ZMMR0002) appears alongside 'review', 'check', or 'ready for transport'. Do not use for general ABAP syntax questions, runtime debugging, or performance tuning unrelated to a transport release gate.
-
sidkh Bundle Dark Pattern AuditAudit codebases and product copy for deceptive dark patterns that are inferable from local source code and text. Produce a structured narrative report with confidence, source locations, concise reasoning, and the official pattern link for each detected pattern.
-
smartcontractkit Skill Subagent OrchestrationOrchestration guide for invoking specialized sub-agents during coding workflows. Defines when and how to invoke testing-engineer, security-auditor, quality-assurance-reviewer, context-keeper, and project-tracker agents. Use proactively after implementing features, modifying security-sensitive code, completing milestones, or when the user asks for reviews, tests, or status updates.
-
sscarduzio Skill Ror InternalsReadonlyREST internal architecture knowledge — kibana rule semantics and decision tree (BaseKibanaRule.shouldMatch, shared by the kibana and legacy kibana_access rules), FLS engine strategies, correlation-ID header contract, ROR admin API endpoints and their ES action names. Use when coding or reviewing changes to the kibana rules, FLS/fields rule, audit logging, or the _readonlyrest admin/metadata APIs.
-
stackrox Skill Go Dependency AnalyzerAnalyzes Go dependencies to determine usage in production code, what functionality is used, and where it's located. Use when user asks "verify where we use [dependency]", "is [dependency] used in production", "analyze dependency [name]", "what uses [package]", "dependency analysis", mentions CVE numbers, security vulnerabilities, or needs to understand dependency impact for triage, upgrades, or removal decisions.
-
synapsync Bundle QA ReviewSenior QA auditor — code review, architecture validation, security audit, and sprint-forge planning synchronization verification
-
win-hao Skill Stop Me CheckRetroactively scan an existing repository for decisions stop-me would have blocked. Use for "/stop-me-check", "check this repo for irreversible decisions", "audit this repo", or a first look at a codebase you did not write.
-
xpera-ch Bundle Security ImpactUse this skill when a diff touches a security-sensitive file and a PR or commit needs a security-impact callout — trigger phrases like "write the security-impact section", "draft the security callout", "does this need a security note", or "check if this touches sensitive files". Runs the bundled scripts/check-sensitive-files.mjs detection script against a dedicated structured config (security-sensitive.json at the project root) — never against CONTRIBUTING.md or any other prose file — and drafts the callout plus an invariants-unchanged checklist from its output. Small, mechanical, and deliberately decoupled from any CI enforcement gate.
-
xyd-gis Bundle Academic Response学术论文审稿意见回复信。输入是审稿人意见全文、reviewer comments、major/minor revision letter、或既有的 rebuttal 草稿时使用。功能包括:意见拆解 + ID 分配 + 行动映射(classify)、起草 point-by-point 回复(draft)、润色既有草稿(polish)、防御性与真实性审查(audit)、起草给编辑的 cover letter(cover)。覆盖期刊与会议 rebuttal、4 种困难场景(矛盾意见、不可能实验、缺关键证据、minor revision)。不适用于:正文段落写作(用 academic-writing)、图表生成(用 academic-figure)、参考文献格式(用 academic-citation)。
-
yang985-cmd Bundle Deliver Cumcm PaperAssemble and preflight evidence-backed mathematical-modeling competition papers in official Word, LaTeX, or PDF formats. Use when the primary request is template-compliant manuscript delivery, native equation handling, frozen-result insertion, format audit, or final page-by-page visual inspection.
-
yang985-cmd Bundle Build Modeling FiguresBuild and audit traceable quantitative plots and code-native modeling diagrams from existing modeling results. Use when the primary deliverable is a figure, diagram, figure bundle, or final-size visual QA rather than a complete modeling solution.
-
yang985-cmd Bundle Audit Modeling EvidenceAudit existing mathematical-modeling data, backend ownership, experiments, innovation claims, results, constraints, reproducibility, and claim-to-evidence links. Use when the primary request is to check or validate an existing modeling project rather than solve a complete new problem.
-
yibie Bundle Code ReviewReview code quality, check for issues, and provide improvement suggestions. Trigger when user asks to review code or check code quality.
-
zaxbyhub Skill Reviewing SecurityInspect trust boundaries, validation, authn/authz, deserialization, command execution, path handling, secrets, and failure handling with an evidence-first security review.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include audit-modeling-evidence, 1password-sdk, port-npm-to-perry. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.