Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
coreylyn Bundle Harmonyos ReviewReview native HarmonyOS ArkTS and ArkUI repositories for concrete, source-evidenced defects in correctness, security, lifecycle and resource ownership, state management, concurrency, persistence, permissions, compatibility, and performance. Use for code review, bug hunting, release readiness, migration audits, or review of a diff, PR, module, or whole project. Report only findings demonstrated by reachable code and project configuration, with precise file and line references; use current official Huawei documentation for version-sensitive claims.
-
andreasasprou Bundle OracleStrategic technical advisor with two modes. Use for second opinions, architecture decisions, debugging, security analysis, and research. REPO MODE explores your codebase autonomously (finds gaps, reviews code, traces bugs). WEB MODE researches external info via @steipete/oracle CLI (current best practices, library comparisons, docs). Run both in parallel when comparing your implementation against current standards.
-
anklecrusher Bundle Project Health AuditAudit a project for structure health, skill hygiene, and navigation completeness. Use when scanning a repo, workspace, or vault-like project for rules, entrypoints, config surfaces, overgrown skill loading, missing links, or read-only health issues that need a prioritized report.
-
arcadia-1 Bundle Adctoolbox User GuideRouter skill for using ADCToolbox from Python. Trigger when a task involves: computing or plotting spectra (SNDR, SFDR, ENOB, THD) from ADC output, fitting a sine to measured aout, calibrating SAR weights (weight_sine / weight_sine_lite), generating synthetic ADC stimulus/output, or validating aout/dout buffer shapes. For deeper debug (dashboards, phase-plane, bit-level, error decomposition, static nonlinearity, ramp INL/DNL, cap-to-weight), open references/advanced-debug.md. NOT for analog topology selection, transistor sizing, Spectre simulation, or layout/parasitic review — those belong to the analog-agents skills (analog-design, analog-verify, analog-audit). NOT for editing ADCToolbox source code — use adctoolbox-contributor-guide instead.
-
arhamhi Bundle HooksmithUse when the user asks for Instagram Reel hooks, TikTok or Shorts hooks, stronger openings, first-frame text, spoken intros, identity hooks, open loops, rehooks, retention paths, caption hooks, or an audit of the first 15-30 seconds of a short-form video. Builds, audits, rewrites, and stress-tests complete hook systems. Also handles `hooksmith init`, `hooksmith generate`, `hooksmith audit`, `hooksmith rewrite`, `hooksmith identity`, `hooksmith rehook`, and `hooksmith caption`.
-
artyom-88 Bundle Code ReviewReview git changes in the current repository or a specified branch, pull request, merge request, commit, or diff range. Use when the user asks to review code, review changes, analyze a branch, inspect a PR or MR, assess regression risk, or identify correctness, API, data-flow, security, performance, or test-coverage issues.
-
agentcommander Skill DebriefReview exploration progress. Use to get a tree health report, ingest hypothesis feedback events, decide what to explore next, audit cross-direction lessons, or get a cross-tree review of the current state. Wide read across the whole map, narrow write — proposes and routes; doesn't change tree substance.
Audited -
autom8minds Bundle Dental Practice AuditAudits a dental practice on the six BOOKED Score signals plus the four that are specific to dentistry - recall compliance, treatment plan acceptance, new-patient call handling, and hygiene schedule utilization - then writes a graded report with a prioritized fix list. Use when the user asks to audit, score, grade, or review a dental practice, dentist, orthodontist, or dental clinic; asks "why is my hygiene schedule empty", "why are patients not accepting treatment plans", "our recall isn't working", "we're not getting new patients"; pastes a dental practice name or Google Maps URL and asks what to fix; or wants a dental audit report to send a practice as a prospect.
-
beautsgo Bundle Beautsgo BookingBook appointments at 1300+ top-rated Korean dermatology & plastic surgery clinics in Seoul, Busan, Jeju directly from your AI assistant. Supports laser, injection, Botox, skin boosters, double eyelid, rhinoplasty, anti-aging, acne treatment in Chinese/English/Japanese/Thai. Keywords: Korea medical tourism, Seoul skin clinic, Korean dermatology, plastic surgery Korea, 韩国医美预约, 韩国皮肤科, 韩国整形外科, 首尔美容院, 医疗旅游韩国, 韩国整容, 水光针预约, 肉毒素预约, 韩式双眼皮. 热门医院: 江南 — 梅宗德/Barog/JD皮肤科/hev赫熙/鹿美人/secret希瑞特/金泰拉/伊美芝/爱妮/美LAB/Oganacell奥嘉娜/reberry/Shinebom/ELEV/Pind/GD医院/ID医院/陶瓷医院; 明洞 — UMI优美/reberry/丹雅/lijin/可丽/daybeau/奥缇娜/本思; 弘大 — 罗薇lovae/凯特kate/丽诺芙/思丽本/可丽/本思/桔艺菲/mind; 东大门 — doctors/夏恩/德希尔; 清潭 — 伊瓷美/minit/jionu/ruby抗衰/antian; 圣水 — serene/melting/iris艾瑞诗/newlline; 光化门 — Heritique赫瑞缇/赫利缇可; 舍堂 — Essential艾森秀; 釜山 — 德佛斯特/JRYN/米米/丽诺博renovo/Star/奥纳比/本思/genius; 济州 — NowMedi/with皮肤科/4ever/miwoo整形/Wyne; 连锁 — 本思/daybeau/朵戈芙蒂/doctors/丽芬聚/Toxnfill/Barog/德希尔/reberry/cnp/you&i/gu/dayone/VSLINE/Kbeauty.
-
caelumca Skill QA LoopDetect-triage-fix loop for keeping a codebase green and safe. Deterministic runners execute tests, lint, typecheck and security scanners (secret scanning, dependency audit, static analysis); an Opus triage lane distills raw output into a stable issue log; fixer lanes run only on issues Fable has approved and briefed. Use whenever setting up or running a test/lint watch loop, triaging build, test or security-scan failures, logging recurring errors, or deciding whether a failure should be auto-fixed. Pairs with the fable-orchestration skill, which governs how the lanes themselves are spawned.
-
chisanan232 Bundle Requirement ZeroChallenge whether a requirement deserves to exist before planning or implementing it. Use when a request asks to build, add, or design something and its necessity or scope has not been established — new features, abstractions, plugin systems, dashboards, configurability, migrations, or "we should probably support X". Reaches an explicit verdict: DELETE, REDUCE, DEFER, BUILD, or BUILD HARD. Do not use for already-validated work, bug fixes, or explicit safety, security, legal, or compliance requirements.
-
chisanan232 Bundle Codebase ZeroAudit whether an artifact that already exists in a codebase still deserves to exist, and reach an evidence-backed verdict before changing anything. Use when asked to review, audit, clean up, simplify, or find removable scope in existing code — modules, abstractions, compatibility layers, dependencies, feature flags, config, endpoints, jobs, caches, tests, CI, or docs — or when deciding whether an existing subsystem should be deleted, consolidated, or invested in further. Reaches one verdict per artifact: DELETE, CONSOLIDATE, SIMPLIFY, DEFER CLEANUP, KEEP, or INVEST. Audits and recommends; it does not delete code on its own authority. Do not use for bug fixes, code review of a change in progress, work whose removal has already been decided and only needs carrying out, or deciding whether to build something new — that last one is requirement-zero. Already-decided removals still get audited when the target is a security, safety, privacy, data-integrity, legal, compliance, or compatibility control.
-
dynamods Bundle Write Dotnet CodeWrite and review C#/.NET code in Dynamo following Dynamo coding standards, modern C# patterns, and repo conventions. Use this skill whenever writing C# code, reviewing a PR diff, designing types, managing PublicAPI surface files, choosing patterns, making performance decisions, or refactoring in the Dynamo codebase. Also use when asking about NUnit testing, async patterns, error handling, immutability, or security in Dynamo.
-
fracerqueira Skill Manage AdrsUse whenever the user wants to create, review, approve, reject, version, revise, supersede, undo, migrate, configure, audit, or fix the header/format of Architecture Decision Records (ADRs) via the `adrplus` CLI tool — including bringing pre-existing, hand-written ADR files into compliance with the adrplus schema, and managing adrplus's own plugin system (`adrplus plugins`/`sync`). Trigger on requests like "create an ADR for X", "approve this ADR", "supersede ADR 0001", "set up adrplus in this repo", "fix these ADR headers to match adrplus", "adjust our ADRs to the adrplus standard", "list/activate/install an adrplus plugin", or any mention of ADRs/architecture decision records in a repo that could use adrplus.
-
iml1s Skill Skill OrganizerScans `~/.claude/skills/` and relocates project-specific skill directories to their owner projects under a configured projects root, archives orphans to a sibling archive dir, and preserves cross-project utilities globally. Only triggers when the user explicitly asks to organize/audit/declutter their skills library, reports that context is being eaten by skills, or invokes `skill-organizer` by name. Triggers include: '整理 skills', 'organize skills', 'clean up skills', 'skill bloat', 'reduce context from skills', 'context 被 skills 吃光'. Does NOT trigger on general debugging, refactoring, or file-management conversations. Does NOT touch plugin-managed skills (under `~/.claude/plugins/` or namespaced like `plugin:skill`) or loose dependency files at the skills root (`.md/.py/.sh` referenced by other skills).
Audited -
jondarza Bundle Docs ArchitectSet up, migrate, and maintain a project's documentation for maximum AI context efficiency using Claude Code's native mechanisms. Builds a 2-layer system (`.claude/rules/*.md` for the AI + `docs/*.md` for humans) that cuts startup tokens 20-40% vs custom summary patterns. Triggers — "set up docs structure", "optimize docs for AI", "install .claude/rules", "migrate _lite to rules", "audit docs", "sync docs with code", "docs-architect", "estructura de documentacion".
Audited -
jayden-x-l Bundle Claude Codex BridgeBridge Claude Code and Codex for bidirectional execution review. Use when Claude should send its result to Codex/GPT-5.5 for audit, audit Codex/GPT-5.5 handoffs, return feedback to Codex, or run an automated Claude-Codex review loop.
Audited -
aixarizzo Skill Kill SlopAudit a file or draft for AI slop and off-voice lines against the author's bound voice, report findings with in-voice swaps, then apply approved fixes. Use when the user says "kill slop", "/kill-slop [file]", "find the slop in this", "audit this for slop", or wants a deck, article, page, or draft cleaned to sound like them. Wraps the anti-slop skill with a voice binding and a fix workflow. NOT a detector-evasion tool, and NOT for text with no voice to bind.
-
akarachen Skill Review GateSecurity and correctness review gate before finishing.
-
alchemiststudiosdotai Bundle Pypi ReleaseThis skill should be used when releasing tunacode-cli to PyPI. It keeps the existing local release checks, then hands the actual PyPI upload to a GitHub Actions workflow that uses the repository's PYPI_API_TOKEN secret.
-
alchemiststudiosdotai Skill Audit HarnessUse when auditing HARNESS.md, pre-commit hooks, pre-push hooks, architecture gates, or CI workflows for tunacode-cli. This skill treats any mismatch, skipped gate, or failing check as a critical failure and requires manual one-by-one execution rather than make targets, batch wrappers, or summary-only audits.
-
aliasunder Bundle Obsidian VaultCreate, edit, and audit notes in an Obsidian vault. Handles frontmatter properties, wikilinks, embeds, callouts, tasks, block references, tags, and Mermaid diagrams. Plugin-aware: Dataview queries and inline fields, Tasks emoji syntax, Kanban boards, Meta Bind fields, Templater templates, Bases schemas, and Canvas JSON. ALWAYS-ON: if the working directory is inside an Obsidian vault (a .obsidian/ directory in any ancestor, or a CLAUDE.md identifying the project as vault-embedded), use this skill for ALL .md file operations — including CLAUDE.md, TASKS.md, and session logs — even when Obsidian isn't mentioned. Triggers: "create/edit a note", "update frontmatter", "add tags", "fix the links", "write a Dataview query", "fix this callout", "add a task", "edit my Kanban board", "make a template", or any note-editing task in a vault. NOT for: .md files outside a vault (code-repo READMEs, GitHub issues, static-site content), generic markdown linting, or Obsidian plugin development.
Audited -
alimansoor2003 Bundle Security AuditAudits codebases for security vulnerabilities, secrets exposure, auth risks, dependency health, and misconfigurations.
-
alondmnt Bundle Review ExperimentCritically review a research experiment against supplied project process context, either its DESIGN before a sweep or its RESULTS, registry, findings, or reasoning chain afterwards. Use to audit, stress-test, red-team, or recompute decision-grade evidence before it enters canonical memory, focusing on design validity, claim/evidence consistency, experiment-process compliance, statistical validity, implementation fidelity, and unresolved assumptions. Run isolated for any decision-grade or memory-updating review. This is not a comprehensive change-set review; use review-pr separately when the experiment is delivered through a PR.
-
bcorfman Skill Workflow AuditIdentify, name, de-duplicate, and fix missing GUI workflows; enforce a single obvious primary path per task.
Audited -
bdnhost Skill Lahav433AI-powered investigative intelligence engine modeled after elite federal investigative units — FBI-grade OSINT tradecraft for autonomous journalism. Activates for investigation requests, corruption/tender audits, financial forensics, municipal accountability, public-records analysis, and pre-publication legal review. Integrates with forensic-accountant and legal-news-advisor skills for triple-verified, legally safe publication. Use when the user asks to "investigate", "audit tenders", "check budget anomalies", "follow the money", "build an investigation dossier", or mentions OSINT, triangulation, Intelligence Cycle (הכוונה/איסוף/עיבוד/ניתוח/הפצה), financial forensics, Benford's Law, Israeli public-procurement law (חוק חובת המכרזים), or publication-risk assessment. Hebrew and English supported.
Audited -
beriktassuly Bundle Solana AuditUse when the user asks to audit a Solana or Anchor codebase, explain report-backed Solana vulnerability classes, review signer or PDA bugs, analyze CPI trust boundaries, assess Token-2022 or payment integrations, digest a public Solana audit report, investigate an exploit path, plan formal verification or invariant testing, or generate audit-readiness, release-gate, remediation, and final-report workflows.
-
beriktassuly Bundle Solana Incident ResponseUse when the user needs Solana incident triage, exploit or suspicious-transaction analysis, transaction timeline reconstruction, blast-radius classification, containment planning, evidence preservation, post-mortem drafting, or safe coordination guidance for Solana programs, Anchor protocols, SPL Token or Token-2022 assets, bridges, multisigs, wallets, RPC logs, or governance/admin compromises.
-
berylliumsec Bundle Nebula Product QualityEnforce end-to-end product quality for Nebula interface, mobile, LAN, chat/session lifecycle, provider, harness, workspace, and other operator-visible changes. Use whenever implementing, fixing, reviewing, or claiming completion of a workflow that an operator reaches through the Nebula UI, especially changes under ui/, API-to-UI integrations, persistence/reconnect behavior, responsive layouts, or browser security boundaries.
-
bgauryy Bundle Whats NewResearches what is new in AI, developer tools, web platform, security, and notable repositories. Use when the user asks for whats-new, latest updates, recent releases, tech news, AI news, changelogs, repo updates, or trend scanning.
-
billliao Bundle China Audit中国注册会计师审计准则(CAS)审计技能 — 风险评估、重要性水平、货币资金/应收账款/存货/固定资产/应付账款/收入/费用实质性程序、审计调整分录、审计报告。当用户需要执行审计程序、函证、账龄分析、坏账测试、编制审计底稿、出具审计报告时使用。
-
bitoex Bundle Bitopro SpotBitoPro exchange API wrapper covering both public market data and private trading on the spot market. Public tools (no API key required): real-time ticker, order book depth, public recent trades, candlestick/K-line, trading-pair specs and fees, OTC price. Private tools (API key + secret + email required): place/cancel/batch orders (LIMIT / MARKET / STOP_LIMIT), query open orders / order history / trade fills, account balance, deposit/withdraw history, initiate withdrawals. Supports TWD (New Taiwan Dollar) fiat trading pairs. Also supports session-aware order execution when invoked by strategy skills via the bitopro-trade-guard hook. For market-wide indicators across all BitoPro coins (Fear & Greed, dominance, rankings, trending, multi-timeframe % change, listing catalog, news), use `bitopro-market-intel`.
-
breed Bundle Repo AuditAudit a repository against the 10 "repo to product" tips (Mateusz Pusz) — discoverable naming, green CI matrix, issue triage, prose documentation, zero-install demos, dev containers, consumption paths, release announcements, contributor recognition, community building. Use when the user asks to audit, score, review, or health-check a repo's project hygiene, onboarding experience, docs structure, packaging, or open-source readiness; or says "repo audit", "audit this repo", "is my repo professional", "repo to product", "score my README". Read-only — pair with repo-upgrade to apply the fixes.
-
breed Bundle Repo UpgradeImplement the 10 "repo to product" tips (Mateusz Pusz) in a repository — scaffold issue templates, dev containers, CONTRIBUTING/CONTRIBUTORS, README pitch, CI matrix with reproducible seeds, Diátaxis docs structure, release announcements, AI-contribution policy, and zero-install demos. Use when the user asks to improve, fix, upgrade, professionalize, or productize a repo's onboarding, docs, packaging, CI, or contributor experience; or says "repo upgrade", "apply the tips", "fix my README", "add issue templates", "add a devcontainer", "make my repo contributor-friendly". Accepts a tip number or name to apply just one. Pair with repo-audit to find what's missing first.
-
cardmagic Bundle Audit DocsAudit README.md and docs/ for accuracy. Runs every documented code example, checks links, anchors, and prose rules, and verifies the CLI examples against the built gem. Use when documentation changes, before a release, or when the user asks to check the docs, verify code samples, or confirm the examples still work.
-
castorini Bundle Qrels ConstructionBuild and audit per-question relevance judgments for a projected benchmark - join a reviewer workbook with verified questions, judge candidate documents against hop standards, expand the pool over exact and near duplicates, and produce the distribution figures. Use when asked to build qrels, finalize relevance judgments, expand judgments over duplicates, check how redundant a judged pool is, or make qrels figures. Triggers include "qrels", "relevance judgments", "judge documents", "duplicate expansion", "near duplicate qrels", "how many relevant documents per question".
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include beautsgo-booking, write-dotnet-code, harmonyos-review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.