Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
fareedkhan-dev Skill Code ReviewUse when asked to review code, audit a file for bugs, check code quality, or suggest improvements. Provides a structured review process and issue categorisation.
-
fedimint Skill Fedimint Federation SetupUse when setting up and running a Fedimint federation with `fedimintd` — to offer your community a private, scalable way to hold and transact in Bitcoin under shared (community) custody, rather than trusting a single custodian. Covers installing/launching guardian(s), running the setup/DKG ceremony, obtaining the invite code your members use to join, setting meta fields (federation name, welcome message, etc.), and day-to-day guardian operations (status, audit, config backup, coordinated shutdown/upgrade). Triggers on: "fedimintd", "set up a federation", "run a federation", "community custody", "guardian", "DKG", "setup ceremony", "set-local-params", "start-dkg", "invite code", "meta fields", "federation_name", "welcome_message", "meta module", "guardian dashboard", "FM_PASSWORD", "solo federation".
-
forceinjection Bundle Linux PwnLinux 二进制漏洞利用专项技能。覆盖栈溢出、堆利用(House of系列/FSOP/tcache/fastbin)、 高级 ROP(ret2csu/SROP/JIT-ROP)、格式化字符串深入利用、内核提权与保护绕过。 当用户请求 exploit 开发、漏洞利用、提权、CTF pwn 挑战解决时触发。
-
micheleangioni Bundle Codebase AuditorUse this skill when the user asks for a review, audit, evaluation or analysis of a codebase, to identify bugs, security vulnerabilities, outdated dependencies or runtimes, performance bottlenecks, or code quality concerns.
-
microsoft Skill Review Multi PerspectiveMulti-perspective code review using four parallel constructive reviewers (conservative, security, usability, speed) followed by a sequential adversarial gap-analysis pass. Each reviewer uses a two-phase inventory-then-assess approach for systematic coverage. Findings are synthesized, deduplicated, verified, and presented as a prioritized remediation plan.
2.7k -
narumiruna Skill Writing Agents MdCreate, review, audit, migrate, or update scoped AGENTS.md files with clear rules, verified commands, action limits, instruction order, and checks that prove the work is done. Use also when verified, durable repository guidance emerges during authorized work and should be captured at the narrowest applicable scope.
-
thewh1teagle Skill TranslateTranslate anything under i18n/ into the project's locales with parallel subagents — desktop and website catalogs, changelog entries, docs pages — then verify the structure, stamp the source hashes and run the audit. Use when the user asks to translate strings, release notes or docs, to fill missing locale keys, or invokes /translate.
-
timbenniks Skill Contentstack CLI AssistantIntelligent CLI assistant that translates natural language into csdx commands. Covers auth, export/import, branches, publishing, migrations, launch, audit, and more.
-
timbenniks Skill Sdk Readiness AuditAudit an API surface (OpenAPI 3.0/3.1, GraphQL schema, or REST docs) for SDK readiness and developer experience. Use when asked to evaluate whether an API is SDK friendly, produce a readiness scorecard, list concrete refactors, describe "if we shipped an SDK today" pain points, or suggest OpenAPI fixes and x-* extensions to improve client generation.
-
tjboudreaux Bundle Awesome ReadmeCreate, audit, revise, and standardize project README files by inspecting repository evidence, asking only for material missing context, and applying audience-appropriate structure and technical-writing checks. Use for README.md work in public open-source or proprietary team repositories, including requests to write, rewrite, refresh, improve, review, or make a README awesome.
-
tjhils Bundle Fin Procedure AdvisorAn interactive decision framework that helps B2B SaaS support leaders choose which Fin Procedures to build and in what order. Use this skill whenever someone asks about Fin Procedures, Intercom automation strategy, which processes to automate with Fin, or how to prioritise their Fin setup. Also trigger when someone mentions "Procedures", "Fin Tasks", "what should I automate", "which Procedure should I build first", "review my Procedures", "Fin audit", "Procedure improvements", "what's working with Fin", "what should I automate next", or anything related to choosing, prioritising, evaluating, or improving Fin Procedure candidates. This skill walks the user through a structured Inventory → Filter → Score → Sequence → Build → Test process and helps them maintain a Procedure Registry and Data Connector Registry for ongoing gap analysis and improvement.
-
unisone Skill Repo Security Scanrepo-security-scan
-
yibie Skill Security ChecklistReviews code for security concerns, auth risks, and missing tests. Use when auditing a PR or investigating a bug fix.
-
yjl9903 Bundle Subject AuditReview AnimeGarden animation resource-to-Bangumi Subject bindings for a specified time range, identify missing or incorrect bindings, and report evidence-backed Subject search improvements. Use for manager-side audits; online binding corrections are optional and require explicit user confirmation.
-
mounirdhahri Bundle Plain EnglishTighten prose by stripping AI tics and applying Orwell/Gowers plain-English rules. Use when the user asks to rewrite, tighten, simplify, or detox writing — phrases like "plain English", "make this clearer", "cut the AI voice", "fix the writing", "rewrite plainly", "tighten this", "detox this". Also run as a self-audit pass before delivering long-form prose (essays, blog posts, articles, reports, documentation) so the output isn't recognisably AI-generated.
-
adand-91 Bundle Gpt6 Astra Skill OptimizerAudit one selected project and its explicitly related Skills for GPT-6 Astra compatibility, then propose evidence-backed improvements. Use when the user asks to audit a project and its Skills, check Astra readiness, diagnose repeated Skill failures, or apply an approved Skill fix. Read-only by default; changing files, syncing, committing, publishing, or messaging requires separate explicit authorization.
-
ssheleg Bundle Telegram BotsUse when building or auditing a Telegram bot on the official HTTP Bot API: receiving updates by polling or webhook, deduplicating them, keyboards and inline mode, Telegram Stars payments, files, rate limits, and the seam where an update becomes a row in your own database. Covers the pinned API version, update_id as the only idempotency key, the allowed_updates default that drops three update types in silence, the webhook secret header, the ten-second pre-checkout window, XTR and refunds, the 20MB download ceiling, and what a bot cannot do at all. Triggers - "telegram bot", "bot api", "aiogram", "grammy", "telegraf", "python-telegram-bot", "setWebhook", "getUpdates", "telegram stars", "pre_checkout_query", "телеграм бот", "бот апи", "вебхук телеграм", "звёзды телеграм". Not for user accounts or reading history a bot cannot see (telegram-userbots), and not for the web layer (telegram-miniapps).
-
staksoft Bundle Magento AuditPerformance audit of a Magento 2 / Mage-OS / Adobe Commerce storefront: full-page cache misses and cacheable="false" leaks, Varnish/Redis configuration, indexer modes and cron health, TTFB, payload sizes, and Core Web Vitals. Use this skill whenever the user says a Magento store is slow, asks to audit/review/check storefront performance, mentions FPC or cache hit rate, X-Magento-Cache-Debug, Varnish not caching, high TTFB, stuck or realtime indexers, cron problems, or Core Web Vitals / PageSpeed scores for a Magento or Mage-OS site. Works from a URL alone, from a codebase alone, or both. For writing or fixing module code, use the magento-module skill instead.
-
syjcnss Bundle Fetch SourceFetches verified smart contract source code from Sourcify and Etherscan for any EVM-compatible chain. Use this skill whenever the user wants to download, retrieve, or inspect the source code of a smart contract at a given address, audit a contract, or analyze on-chain code — even if they don't say "Sourcify" or "Etherscan" explicitly.
-
tao3k Bundle NsjailUse when configuring Linux sandboxing with nsjail, generating security profiles, or configuring process isolation for skills.
-
roblox2009emrobloxpiano-coder Skill Copilot Setup AuditAudit a repository's Copilot CLI customization setup and suggest improvements. Use when the user wants to review their Copilot configuration, find gaps, or optimize their CLI customization setup.
-
rolling-scopes Bundle Nestjs Best PracticesNestJS best practices and architecture patterns for building production-ready applications. This skill should be used when writing, reviewing, or refactoring NestJS code to ensure proper patterns for modules, dependency injection, security, and performance.
-
ronanpinho-ipt Bundle Impact Report BuilderActs as the Impact Intelligence & ESG Reporting Officer for a nonprofit hub or member network. Use this skill whenever someone needs to turn raw program metrics into a verified, normalized, audit-ready impact report or corporate-partner briefing. Triggers on phrases like "CSRD impact report", "ESG impact data", "audit-ready outcomes", "audit-ready impact data", "verified impact metrics", "GRI report", "SASB mapping", "TCFD", "SDOH outcomes", "social determinants of health report", "quarterly partner briefing", "Founding Partner report", "corporate sponsor impact briefing", "impact dashboard", "normalize our metrics", "map our outcomes to a framework", "theory of change to data", "outcomes reporting", "M&E report", "monitoring and evaluation", "annual impact report data layer", "we promised the sponsor impact data", "what data do we have for our funders", "build the impact appendix", "data gaps in our reporting", "member org metrics rollup", "aggregate member metrics", "self-report template for members". Does
-
neuralblitz Skill Chrome Release VerifyEnd-to-end Chrome security backport for an Electron release branch. Given a Chrome Releases blog URL and a branch (e.g. 41-x-y), determines which CVE fixes are missing from the *actual synced source*, writes the cherry-pick patches locally, validates them with `e sync --3` + `lint --patches`, then pushes a single PR. Use when asked to backport a Chrome security release to N-x-y, "is CVE-X already in N-x-y?", or to produce/validate the cherry-pick set for a release branch.
1 -
paulnsorensen Skill Sliced Bread DepthScore each slice of a Sliced Bread codebase as a deep module: classify its crust shape, measure where implementation mass sits relative to the crust, and recommend which crusts to break down. Use when the user asks "are our slices deep", "review the crusts", "which modules should we break down", "is this facade too fat", or after a compliance review passes but a slice still feels monolithic. Do NOT use for boundary compliance on a change set (sliced-bread-review) or a rule-violation sweep (sliced-bread-audit) — this skill measures depth, not compliance.
-
paulnsorensen Bundle Slice And Spine ReviewRun a human-in-the-loop whole-repo coherence review of a Sliced Bread codebase: inventory slices, the spine, and seams; fan out subagents to digest every file with its tests; walk seams in ranked order with the human issuing a disposition per stop; review the spine for orchestration drift. Use when the user says "review the seams", "slice and spine review", "whole-repo coherence review", "walk the seams", or asks whether slices still hang together after individual changes passed review. Do NOT use for rule-compliance checking on a bounded change set (sliced-bread-review), autonomous audit and issue filing (sliced-bread-audit), or depth/crust-shape scoring (sliced-bread-depth) — this skill is a guided session over the whole repo, not an automated check.
-
rtk-ai Skill Image WebpAudit and convert images to WebP format. Checks public/assets/ for PNG/JPG files, verifies <img> tags have width/height, and generates cwebp conversion commands.
-
soniqo Skill Review PrReview a pull request for conceptual fit, architecture impact, adversarial failure modes, security risk, docs impact, regression risk, test coverage, and merge readiness. Use when asked to review a PR, check whether a PR is safe to merge, decide if more tests are needed, perform adversarial or security review, or summarize PR risk.
-
spboyer Bundle Sensei**WORKFLOW SKILL** — Iteratively improve skill frontmatter compliance using the Ralph loop pattern. WHEN: "run sensei", "sensei help", "improve skill", "fix frontmatter", "skill compliance", "frontmatter audit", "score skill", "check skill tokens". INVOKES: token counting tools, test runners, git commands. FOR SINGLE OPERATIONS: use token CLI directly for counts/checks.
-
x7dl8p Skill Open Skill Security ExpertThe most comprehensive application security review skill available. Use this for any and all security-related tasks.
-
yacafx Bundle Rpg Library CuratorAudit, classify, deduplicate, document, and safely reorganize tabletop RPG libraries. Use when Codex needs to inspect an RPG collection, triage RPG files from inboxes or download folders, identify exact duplicate PDFs/assets, propose a durable folder structure, document routing rules, or execute an explicitly approved migration of RPG materials.
-
voxpelli Bundle Tag AuditTriage and prune accumulated git safety tags using sort-by-SHA grouping and a per-tag decision tree (duplicate / branch-ref / intermediate-waypoint). Read-only by default; deletes only after explicit user confirmation. Use when stacked-rebase or surgical-fix sessions have accumulated multiple safety tags across namespaces (safety/*, pre-*, post-*, backup-*, stack-*), when /stack-cascade's Step 2 collision check blocks reuse of an OP_ID, or when auditing inherited tag soup. Pairs with /stack-cascade as post-success aftercare. Covers scenarios like: 'clean up safety tags', 'too many backup tags', 'prune accumulated tags', 'tag audit', 'tag-audit', 'safety tag cleanup', 'rollback anchor cleanup', 'which tags can I delete', 'tag namespace collision', 'OP_ID already has tags'.
-
wandb Skill Sync OperatorSync wsm to be e2e compatible with a target github.com/wandb/operator ref — always invokes /audit-operator-diff first, then applies the user-approved fix list, updates docs, and smoke-tests on Kind. Triggers on phrases like "sync wsm with operator", "bump operator dep", "update for new operator release", "match operator changes". v2 surface only by default; v1 only on explicit user request. Requires a local clone of the operator repo and OrbStack running.
-
wandb Skill Audit Operator DiffAudit changes between two github.com/wandb/operator refs and produce a categorized impact report on wsm. Use independently for code review / release planning, or as Step 1 of /sync-operator. Triggers on phrases like "audit operator diff", "what changed in operator", "show me operator impact on wsm", "operator compatibility audit". Does NOT make code changes — produces a fix list at .claude/audit-report.md that the user (or /sync-operator) consumes.
-
wazuh Bundle Docs ReviewAudit the wazuh-indexer-plugins mdBook documentation (docs/) for coverage gaps, staleness against source code, structural/navigation issues, and style inconsistency. Produces a written findings report — it does not rewrite prose. Use when asked to review, audit, or assess the Wazuh Indexer technical documentation.
-
web-infra-dev Bundle Dependency Audit审计 Modern.js 仓库依赖健康度,默认直接扫描整仓并从维护者与 Modern 用户 app 两个视角输出报告,覆盖幽灵依赖、循环依赖、重复多版本、安装体积与安装耗时。在「review 依赖改动、pnpm 严格模式报错、构建变慢、包边界不清」时使用。
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include chrome-release-verify, telegram-bots, code-review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.