Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
webmaxru Skill Pr ReviewThe Atlas pull-request review checklist for AI coding agents. Use when opening a pull request or reviewing one in an Atlas service — to self-review a diff, write the PR description, or leave review comments. Covers correctness, tests, security, API compatibility, and rollout/observability. Don't use for non-Atlas repositories or for unrelated code-explanation tasks.
Audited -
webmaxru Skill Secure CodingAtlas secure-coding standards for AI coding agents. Use when writing, reviewing, or refactoring code that handles user input, secrets, authentication, database access, or third-party dependencies in an Atlas service. Enforces input validation, no hardcoded secrets, parameterized queries, least-privilege, and pinned dependencies. Don't use for non-Atlas projects or for general security research unrelated to a code change.
Audited -
xnfinite Bundle Icm LedgerKeep score on an AI's advice inside an ICM workspace. Every consequential recommendation is logged with a confidence word, a falsifier, a cost class, and a review date BEFORE it is given; outcomes attach in the same file; readouts turn the record into a self-briefing the next session reads on arrival. Use when (1) you are about to give a recommendation that changes what the owner does next, costs money, or ships — log it first; (2) reality delivers an outcome for an open entry — attach it; (3) the owner asks "what's our track record", "where are you overconfident", or "should I trust this call"; (4) a supervised audit pass runs — compute a readout and regenerate BRIEFING.md; an unattended maintenance pass only regenerates a stale briefing from an existing readout; (5) you are about to make a call of a class the ledger scores — read your record first; (6) the owner overrides an adviser, or two advisers oppose each other — log the disagreement as a D-entry. The record is honest only if outcomes get attached.
-
xwcai999 Bundle Wawa SubmissionPrepare Wawa Writer (蛙蛙写作) novel projects, emit execution-ready submission packages, and connect them to the local page-prefill engine without duplicating the novel creation workflow. Use when Codex needs to start a “蛙蛙” novel, prepare or audit completed submission materials, map a novel-studio project to the Wawa form, read active campaigns, log in, or prefill the official page for human review and final submission.
-
near Skill Pr ReviewReview a Rust pull request against the nearcore engineering rubric — correctness, production safety, performance, Rust-specific concerns, security, and comment quality. Use when asked to review a PR, do a code review of a branch's changes, or check a diff before merge. This is the same rubric CI runs on @claude review.
-
neogenz Bundle Angular ArchitectureThis skill should be used when the user asks "where should I put this", "can X import from Y", "Angular folder structure", mentions feature isolation, lazy loading placement, dependency violations, architecture audit, circular dependency, import cycle, barrel file, bundle size, initial load performance, signal store placement, state management, or when creating/moving Angular components, services, or modules between folders. Also use when reviewing PRs for architectural compliance, scaffolding new features, or setting up eslint-boundaries. Angular enterprise architecture advisor for placement decisions, dependency rules, isolation patterns, and architectural verification.
-
neondatabase Bundle Blume Update DocsKeep a Blume docs site in sync with the product it documents. Audit recently merged pull requests, changelogs, config schemas, CLI help, and public APIs against the docs content, update only pages that are factually stale, verify the docs build, and open (or update) a maintenance pull request — or report a clean no-op. Use when asked to check docs for drift, refresh stale documentation, run a scheduled docs audit, or keep docs current after a release.
-
neptunehub Skill Sec ReviewSecurity review of this codebase - reasons about the code like a security researcher, tracing untrusted input from entry point to sink rather than pattern-matching. Scans the whole tree at HEAD for hardcoded secrets (anything beyond the empty defaults config.py declares), then checks what the current change introduces against the head of remote main. Uses the OWASP Top Ten as the primary risk source, reports severity plus confidence in a markdown table, and proposes fixes without ever applying them. Use when asked whether the code is secure, to audit for vulnerabilities, to check for injection, auth, secrets, or dependency risk, or to review a change for security regressions.
-
newmanxbt Bundle X Content OptimizerAudit and optimize tweets, X articles, and threads for X's recommendation algorithm. Use when user wants to review content before posting, improve engagement potential, or get algorithm-friendly suggestions. Triggers on /x-content-optimizer or requests to "review tweet", "optimize for X algorithm", "audit my post", or "improve engagement".
-
newmanxbt Bundle Audit Report GeneratorGenerate professional PDF audit reports from markdown findings. Use when converting security audit findings to formal PDF reports, creating audit deliverables, or formatting vulnerability assessments. Triggers on requests to "generate audit report", "create PDF report", "format findings as PDF", or any audit report generation task.
-
newmanxbt Skill Contract Maturity Issue WriterUse when assessing a smart contract repository with code maturity criteria and converting concrete gaps into structured GitHub issues.
-
next-friday Bundle RebutUse on an open pull request that carries AI code-review comments from CodeRabbit, Gemini Code Assist, or a similar bot reviewer that need handling, and right after pushing to a PR where such a reviewer is expected to weigh in. Triggers on requests like 'audit the bot comments', 'respond to coderabbit', 'rebut the reviewer', 'go through the AI review', or whenever an open PR shows unresolved bot review threads to triage.
-
nowork-studio Bundle Ads AuditGoogle Ads account audit and business context setup. Run this first — it gathers business information, analyzes account health, and saves context that all other ads skills reuse. Trigger on "audit my ads", "ads audit", "set up my ads", "onboard", "account overview", "how's my account", "ads health check", "what should I fix in my ads", or when the user is new to AdsAgent and hasn't run an audit before. Also trigger proactively when other ads skills detect that business-context.json is missing.
-
o0000-code Skill Ensemble PatrolRun a comprehensive QA patrol on the CC Workshop Tauri desktop app. Use when asked to check Tauri project health, run tests, lint code, or audit for issues. Do not use for iOS projects.
-
obot-platform Skill Rewrite Security AdvisoryRewrite an obot GitHub security advisory into Obot's short, user-facing format (Summary / Am I affected? / Details / Impact / Mitigation / Severity / Credits). Use when the user gives a GHSA id or advisory URL and asks to rewrite, simplify, or reformat it. Writes the result to a markdown file in the repo root for the user to paste into the advisory editor.
-
octolaba Bundle Para OrganizerImplement the PARA Method (Projects, Areas, Resources, Archives) on a user's local file system. Use this skill whenever the user wants to: organize their files or folders using PARA, set up a PARA system from scratch, classify existing files/folders into Projects/Areas/Resources/Archives, do a PARA audit or cleanup of their digital environment, identify their current projects and areas of responsibility, or reorganize a messy Documents folder. Also trigger when the user mentions 'PARA', 'Second Brain file organization', 'organize my files by actionability', or asks which folders should be projects vs areas vs resources. This skill scans real files, presents a complete reorganization plan for the user to approve, then executes it.
-
olshansk Skill Cmd Rss Feed ReviewReview RSS feed generators and their XML output for broken selectors, missing error handling, stale cache logic, feed link conventions, empty/malformed feeds, and duplicate entries. Use when asked to "review feed", "check feed quality", "audit feeds", or after creating/modifying a feed generator.
-
appneta Bundle Security Advisory TriageMove a GitHub Security Advisory through accept, fix, and publish for this repo. Use when the user shares a GHSA URL, asks to triage/accept/publish an advisory, or asks whether new advisories apply to the current code.
-
asteroid-belt Bundle Skulto Release CertCertify a skulto build for Homebrew prod release. Runs three passes — unit/lint/cross-compile, clean-slate CLI walkthrough, and security audit — then produces a certification summary.
-
gygantskiymatilyock Skill IOS Security AuditoriOS Security Auditor
-
hardness1020 Bundle Security AuditSecurity vulnerability audit — check for OWASP top risks, hardcoded secrets, injection points, and dependency CVEs. Use when auditing code for security vulnerabilities, reviewing authentication/authorization logic, or checking for secrets leakage before merge.
-
haroontrailblazer Bundle Ghost DecodeDecode videos that hide text in moving dots or noise using dense optical flow and optional OCR. Use for ghost-font clips, motion-defined text, random-dot kinematograms, TV-static videos with secret messages, text visible only during playback, or requests asking what a ghost-font video says.
-
hatemecha Bundle Open Source ProjectCreate, convert, audit, and prepare software projects for genuine open-source publication. Use when starting a public repository; choosing licenses; improving README, contribution, governance, security, privacy, or release practices; identifying open-washing; or assessing project health.
-
hiero-ledger Bundle Kb FreshnessCheck the consensus-layer knowledge base (platform-sdk/docs/consensus-layer) for drift against the code. Runs the deterministic engine, then performs the semantic (prose-vs-code) reading and presents a combined report. Use when asked to check, refresh, or audit the consensus-layer KB.
-
hiromaily Skill AI Friendly AuditLightweight AI Friendliness check for a repository (no subagents, within 5 minutes). Quickly prioritizes basic improvements.
-
holden323 Bundle Ldm Memory System设计、审查和整理由 Memory、项目文档、Skill 与索引组成的长期认知资产系统。用户说“搭建记忆系统”“清理 memory”“memory 体检”“整理知识库”“检查真源或失效指针”“Skill 太多了”时使用;不处理普通文件归档、会话交接、代码部署或一般项目清理。 Design, audit, and maintain a long-term cognitive asset system composed of Memory, project docs, Skills, and pointers. Triggered when the user says "build memory system," "clean up memory," "memory health check," "organize knowledge base," "check source of truth or stale pointers," or "too many skills"; not used for ordinary file archiving, session handoff, code deployment, or general project cleanup.
-
hubeiqiao Bundle Tim Project GuideUse when structuring, formatting, evaluating, or reviewing a Technology Innovation Management (TIM) project report for Carleton University — provides report rules, chapter guidance, literature review expectations, research method templates, and a compliance-audit checklist.
-
desenvolvweb Skill Abby Covert HeuristicsRun a structured heuristic evaluation of any product, website, app, screen, or prototype using Abby Covert's 10 Information Architecture heuristics — in Portuguese: Encontrável (Findable), Acessível (Accessible), Claro (Clear), Comunicativo (Communicative), Útil (Useful), Credível (Credible), Controlável (Controllable), Valioso (Valuable), Fácil de aprender (Learnable), Encantador (Delightful). Produces a scored report (in pt-br) with per-principle findings and prioritized recommendations. Use this whenever the user wants to audit, evaluate, review, or critique the usability / UX / information architecture of something — e.g. "audit this page", "avaliar a usabilidade", "análise heurística", "revisar a UX", "esse produto é fácil de usar?", "heuristic evaluation", "o que está errado nessa interface", or asks how a page/app stacks up against IA or UX best practices. Trigger even when the user doesn't name the heuristics explicitly — any request to assess the quality of an experience holistically is a fit. This i
-
alinaqi Skill Cpg AnalysisDeep code property graph analysis with Joern CPG (AST+CFG+PDG) and CodeQL for control flow, data flow, taint analysis, and security auditing
-
openmoss Bundle API GatewayConnect to 100+ APIs (Google Workspace, Microsoft 365, GitHub, Notion, Slack, Airtable, HubSpot, etc.) with managed OAuth. Use this skill when users want to interact with external services. Security: The MATON_API_KEY authenticates with Maton.ai but grants NO access to third-party services by itself. Each service requires explicit OAuth authorization by the user through Maton's connect flow. Access is strictly scoped to connections the user has authorized. Provided by Maton (https://maton.ai).
-
delorenj Skill Toad Audit ProjectAudit an existing project against the pjangler parity rules and migrate the fixable ones. Use to check whether a project conforms to the latest pjangler/33GOD spec and to bring a legacy project up to standard.
1 -
shaivpidadi-agent-security-bonds-arc Bundle SkillUSDC Security Skill
-
100yenadmin Skill Boardstate DevThe Boardstate development loop — monorepo commands, scoped testing, changesets + release trains, the security-invariant verify discipline, and the house rules (wire-contract tests, inert rendering, reads≠actions). Use when implementing, reviewing, or releasing any change in this repo.
-
mrmarudi Bundle Academy ReviewUse when the user wants their way of working with Claude assessed — "review my session", "how am I using Claude Code", "audit my setup / workflow", "am I following best practices", "coach me", "what should I improve" — or pastes a Claude.ai/Cowork/Tag transcript and asks how they could have worked better. Do NOT use for reviewing code changes (that is code review) or for teaching a product from scratch (use academy-learn); this skill only reviews how the human works with Claude.
-
mrbaeksang Skill Project AuditService-profile-driven project audit. Auto-fires when the user requests audit, review, code review, pre-launch check, security audit, OWASP/SOLID/12-Factor compliance, project skeleton/bootstrap/setup, or any equivalent in any language (e.g., 점검, 감사, 리뷰, 출시 전 검토, 보안 점검, 골조, 셋업). Reads the full 0–10 section checklist from SPEC.md, filters items by grade (🔴🟠🟡🔵⚪) against the user's service profile, and outputs results as ✅❌⚠️⏭️ markers re-sorted by risk. Respond in the user's language.
-
novusedge Bundle Anti SlopAudit prose a human reads — comments, docstrings, commit messages, PR bodies, docs, chat replies. STE grammar, no AI buzzwords, no LinkedIn cadence, surgical brevity. Use anti-slop-code for source files.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include sec-review, toad-audit-project, security-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.