Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
novusedge Bundle Anti Slop CodeAudit and trim code itself — narrator comments, defensive boilerplate, dead generality, tests that assert mocks, docstrings that restate the signature. Use for source files; use anti-slop for prose.
-
teccat Bundle UI PsychologyApply psychology frameworks to UI analysis, user flow design, interface generation, and design audits. Activate when the user mentions: UI improvement, conversion rate, user drop-off, design psychology, Cognitive Load, anchoring effect, social proof, FOMO, CTA optimization, onboarding design, UX audit, design principles, user experience, why users do not click, interface design, user flow, flow design, signup flow, purchase flow, onboarding flow. Supports four modes: ANALYZE, USERFLOW, GENERATE, AUDIT.
-
thegreencedar Bundle Design CourseDesign, build, revise, or audit reusable lessons, workshops, courses, curricula, onboarding paths, and learning assessments. Use when the output is learning material for later delivery; do not use for answering a learner's immediate explanation question.
-
asmyshlyaev177 Bundle Proxy SetupSet up test-proxy-recorder for any Playwright project. Covers the proxy CLI (test-proxy-recorder <target> --port --dir), package.json scripts for the three-service architecture (UI app → proxy → backend API), playwright.config.ts webServer block pointing to /__control, per-test fixtures using playwrightProxy.before(page, testInfo, mode, { url }), HAR browser-side recording via url pattern, .mock.json server-side recording, record/replay/ transparent modes, the record-once→commit→CI-replay lifecycle, automatic secret redaction of Authorization/Cookie/Set-Cookie headers (--no-redact, --redact-headers, --redact-body), an optional config file (test-proxy-recorder.config.ts via defineConfig, --config) with CLI-overrides- config precedence, and parallel test execution with fullyParallel. Load this skill when installing test-proxy-recorder, writing Playwright fixtures, or configuring record/replay.
-
astrbotdevs Skill Python SandboxShip runtime usage guide for code execution sandboxes. Covers Python execution via IPython kernel with persistent variables, Shell command execution, filesystem operations with security constraints, and common development workflows. Use this when working inside a Ship container to understand available tools, pre-installed libraries, path security rules, and best practices for file I/O, data processing, and project scaffolding.
-
baidu-baige Bundle Code AnalysisCode review and debugging assistant. Identifies bugs, performance issues, security vulnerabilities, and suggests optimizations.
Audited -
christofferbergj Bundle Update DependenciesAudit and update JavaScript and TypeScript dependency surfaces while preserving repository policy.
-
cosai-oasis Bundle Security ReviewComprehensive security code review workflow for a target repository, producing a markdown report with findings and recommendations.
-
frostwire Skill Frostwire Code ReviewerFrostWire code review skill — ensures correctness, performance, safety, security, gubatron+aldenml code style adherence, documentation quality, and regression test coverage for all new code and bug fixes in the FrostWire Desktop, Android, and common/ modules. Context-aware: applies different checks depending on whether code targets desktop, Android, or common. Enforces common/ JDK compatibility with Android (the limiting factor). Use when reviewing code before commit, during PR review, or when auditing existing code for issues.
-
innosage-llc Skill Draft CLIManage InnoSage Draft pages and hosted Secret Shares using the @innosage/draft-cli. Use this skill for `draft`, `draft page ...`, `draft secret ...`, and `draft auth ...`. Prefer JSON Workspace page operations anchored by workspace status/path metadata. Do not use this skill when "draft" is only a verb or when the task is a generic local-file writing task unrelated to Draft CLI.
-
vipentti Bundle Planlet CompleteValidate and safely complete or archive exactly one active repository-local Planlet with a UTC audit record. Use when a user asks to finish the Planlet lifecycle, archive completed work, or explicitly override incomplete tasks with a recorded reason.
-
lirantal Skill Use Snyk To Do Security Scans And Audit Project SecurityA handful of commands available for code security, dependency security and other security audits using Snyk
-
getaxonflow Skill Audit SearchSearch AxonFlow audit trail for recent tool executions, policy decisions, and compliance evidence
-
julianromli Bundle Backend DevComprehensive backend development workflow that orchestrates expert analysis, architecture design, implementation, and deployment using the integrated toolset. Handles everything from API design and database architecture to security implementation and DevOps automation.
-
codealive-ai Bundle Package Macos App IconsBuild, audit, replace, and install native macOS app icons from raster source artwork. Use when Codex needs to review an icon candidate against Apple macOS icon expectations, remove background halos with the standard macOS rounded-rectangle enclosure, preserve PNG alpha while resizing into .iconset/.icns files, update SwiftPM macOS app packaging scripts, compare installed/build/dist icon assets, or clear/restart local app icon installation state.
-
chainloop-dev Skill Vulnerability RemediationReviews vulnerability policy violations for the chainloop project recorded in Chainloop and performs fixes in Dockerfiles or go.mod. Use when asked to fix vulnerabilities, review CVEs, or remediate security issues in chainloop.
-
isatimur Bundle HallmarkAnti-AI-slop design skill for greenfield pages, audits, redesigns, and design extraction from URLs or screenshots. Use when the user asks to build a new app or landing page, wants to redesign something, invokes Hallmark by name, or uses audit/redesign/study.
-
heet-p Bundle Legal CheckFull-stack legal, privacy, and compliance audit engine for web applications and SaaS platforms. Use this skill when the user wants to audit a codebase for legal exposure, privacy risks, GDPR/CCPA compliance gaps, missing consent flows, unsafe data practices, cookie policy issues, payment/auth compliance, AI disclosure requirements, or platform liability risks. Trigger whenever the user says "audit my app for compliance", "check my codebase for privacy issues", "do a legal check", "GDPR audit", "privacy policy review", "terms of service check", "is my app compliant", or uploads/shares a codebase and asks about legal or privacy concerns. Also trigger proactively when reviewing any app that handles user accounts, payments, AI outputs, or file uploads — even if the user doesn't use the word "legal".
-
heet-p Bundle Security AuditDeep adversarial security audit engine for full-stack web applications. Use this skill when the user wants to audit a codebase for security vulnerabilities, broken access control, injection risks, authentication weaknesses, payment security, file upload exploits, IDOR, CSRF, SSRF, RLS bypass, business logic abuse, rate limiting gaps, or deployment security issues. Trigger whenever the user says "audit my security", "find vulnerabilities", "pen test my app", "is this secure", "check for IDOR", "harden my auth", "review my payment flow for exploits", "can someone bypass this", "what can an attacker do", or shares code and asks about security, exploits, or hardening. Also trigger proactively when reviewing any app that handles auth, payments, file uploads, admin routes, or user-generated content — even if the user doesn't use the word "security".
-
microsoft Skill AsklearnLook up Microsoft Purview documentation and guidance from Microsoft Learn. Use this skill ONLY when the user's question does NOT match a diagnostic symptom in dlm-diagnostics. Use dlm-diagnostics first for troubleshooting issues like retention policy errors, archive problems, inactive mailboxes, etc. Use asklearn for general questions like: how do I create a retention policy, how do I set up eDiscovery, how do I enable audit logging, how do I configure communication compliance, how do I set up information barriers, how do I use insider risk management, how do I manage records, or how do I configure adaptive scopes.
2.7k -
microsoft Bundle Dlm DiagnosticsDiagnose Microsoft Purview Data Lifecycle Management (DLM) issues in Exchange Online. Use this skill when a user reports: retention policy not applying to workloads, retention policy stuck in Error or PendingDeletion, items not moving from primary mailbox to archive, auto-expanding archive not provisioning additional storage, inactive mailbox not created after user deletion, Recoverable Items or SubstrateHolds folder growing uncontrollably, Teams messages not being deleted after retention period expires, MRM and Purview retention conflicting causing unexpected deletion or retention, adaptive scope including wrong members or not populating, or auto-apply retention labels not labeling content or showing Off Error status. Requires Exchange Online and Security & Compliance PowerShell sessions.
2.7k -
dlt-hub Skill Refresh SourceAudit a verified source against the current state of its upstream API/SDK, find breakages and outdated patterns, and propose (or implement) a fix plan with credential-free unit tests. Use when users report a source is outdated or broken, or for periodic source maintenance.
-
edouard-claude Bundle IronloopVerification-first software engineering harness with 5 layers (spec → gen → test → sim → pentest). Use when generating, reviewing, or planning code with AI agents, especially for Rust projects, new feature work, legacy migrations, or any task where code correctness must be guaranteed. Activates on phrases like "build a", "implement", "refactor", "review this code", "migrate from", "add tests for", or when the user describes a coding task with correctness or security requirements.
-
eloqdata Bundle Finish PrUse when a non-trivial code change is substantially complete and needs a final diff audit, documentation check, verification record, or pull request description.
-
embedpdf Bundle Embedpdf ChangesetsCreate and audit Changesets release notes for EmbedPDF pull requests and working-tree changes. Use when a PR needs changesets, when package coverage must be verified, or when combined or duplicate package changesets need cleanup.
-
cfrs2005 Skill Security Review在添加身份验证、处理用户输入、使用机密信息、创建 API 端点或实现支付/敏感功能时使用此技能。提供全面的安全清单和模式。
-
chadjardine Bundle WritingGeneral-purpose writing skill for drafting, editing, and improving prose. Currently includes a module for cutting AI-slop patterns and making drafts sound sharper and more human (voice-preserving editing, or detection/audit of AI-sounding patterns without rewriting). Use whenever the user wants help writing something, wants a draft edited, tightened, made more direct or more opinionated, wants writing to sound less AI-generated, or asks whether a piece reads as AI-written. More writing modules will be added here over time (e.g. structure, tone, style guides) — check the modules list below and load whichever reference file fits the request.
-
chainreactors Bundle AiscanUse this skill for AIScan's attack surface management and penetration-testing capabilities, including scanner pseudo-commands, supporting security tools, vulnerability verification, evidence handling, and assessment reporting.
-
chakrit Skill Kode ThaiRun an iterative audit-and-fix loop on Thai prose using the kien-thai skill — repeats audit/fix passes until a full pass produces zero new edits. TRIGGER when user invokes `/kode-thai`, asks for "audit loop" / "วน audit" / "ตรวจวนๆ" / "ขัดภาษาไทยให้สุด" on Thai writing, says variants of "แก้ไปเรื่อยๆ จนกว่าจะไม่เจอที่ผิด", or explicitly requests repeated review passes on Thai prose. DO NOT TRIGGER for single-pass rewrites or one-off Thai edits (use kien-thai directly), or for non-Thai content.
-
chantastic Skill Prepare PostPrepare a chan.dev post for publication or metadata enrichment. For a single post, harden the draft, generate description and tags, validate frontmatter, and optionally set publishDate. For batches, do metadata-only work: generate or audit descriptions and tags across many posts.
-
chichou Skill IgfCLI interface for igf (Grapefruit) dynamic instrumentation server. Use to enumerate Frida devices, list apps, run hooks, query logs, access device file systems, inspect classes, dump memory, and perform mobile app security analysis.
-
chichou Skill MastgAutonomous mobile security audit aligned with OWASP MASTG v2. Performs checklist-driven analysis across MASVS categories: storage, crypto, network, platform, code, resilience, privacy. Exports structured markdown report with MASTG test references.
-
cinderfi Bundle CinderfiUse Cinderfi for any retirement planning, tax, or government benefit question involving Canada or the US. Triggers: retirement projections, RRSP/TFSA/IRA/401k questions, CPP or Social Security timing, GIS eligibility, RRSP meltdown or Roth conversion strategy, Monte Carlo simulation, withdrawal order optimization, inheritance or windfall allocation, purchase impact on retirement, what-if scenario comparison, or retirement readiness scoring. Covers both single and couples plans (couples requires Pro). Supports all Canadian provinces and US states.
-
codealive-ai Bundle Apple App Store ReviewerAudit Apple-platform apps before App Store submission or resubmission. Use for iOS, iPadOS, macOS, tvOS, watchOS, and visionOS release reviews involving source code, archives or IPAs, App Store Connect metadata, screenshots, subscriptions, login, privacy manifests, AI features, UGC, age ratings, review notes, or an Apple rejection. Produces evidence-backed findings, deterministic preflight results, screenshot review queues, runtime test plans, remediation steps, and a submission-readiness gate.
-
codexstar69 Bundle Code PerfectionAutonomous code refactoring and optimization with enforced resolution loops, zero-regression verification, and large codebase audit strategy. Every change preserves behavior, introduces zero bugs, and loses zero functionality.
-
consensys-incorporated Skill Style ReviewReview Teku documentation for editorial compliance (voice, terminology, formatting, content type, and workflow checks). Use before submitting a PR or when auditing pages.
Audited
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include audit-search, asklearn, anti-slop-code. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.