Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
oxidecomputer Skill Add Relevant DocsAudit and improve help text, microcopy, and "Relevant docs" links across console networking and other UI pages. Use when adding or updating documentation links in side modals, page headers (DocsPopover), or inline help text.
-
pedroknigge Bundle Vibe Proof Auditorv1.0.1. Use when the user asks for a vibe-proof audit, production gates, a production checklist, an anti-vibe or anti-slop review, whether a repo is listo para prod, or to harden / remediate with Antigravity (agy). Trigger phrases include auditar proyecto, control de calidad, harden with agy, and similar production-readiness requests on local, mixed, or AI-generated code. If the leading version is not the latest in VERSION / changelog, update the skill before auditing.
-
perhapsspy Bundle Project Context MigrationAudit scattered repository docs and notes, then move only the right working context into the `project-context` structure.
-
tjboudreaux Skill Fundraising NarrativeThis skill should be used when the user asks about "pitch deck", "fundraising story", "investor pitch", "VC narrative", "pitch narrative", "fundraising deck", "pitch structure", "Sequoia format", "why now slide", "market size slide", "TAM SAM SOM", "earned secret", "value hypothesis", "product-market fit", "founder-market fit", or discusses how to tell their company story to investors. Provides first-principles guidance for crafting compelling VC fundraising narratives.
-
devanb Skill Global ValidationImplement server-side validation with allowlists, specific error messages, type checking, and sanitization to prevent security vulnerabilities and ensure data integrity. Use this skill when creating or editing form request classes, when validating API inputs, when implementing validation rules in controllers or services, when writing client-side validation for user experience, when sanitizing user input to prevent injection attacks, when validating business rules, when implementing error message display, or when ensuring consistent validation across all application entry points.
-
umutbasal Bundle SemgrepStatic analysis and security scanning using Semgrep, a fast, open-source static analysis tool for finding bugs and enforcing code standards. Use when scanning code for security vulnerabilities, code quality issues, style violations, or bugs. Triggers include requests to find security issues, detect code patterns, enforce coding standards, scan for vulnerabilities, write custom rules, perform static analysis, or audit code quality. Supports pattern matching, autofix, generic pattern matching, and rule composition.
-
himself65 Bundle Security Best PracticeAudit and harden authentication code for security best practices. Use when the user wants to check their auth implementation for vulnerabilities, harden session handling, fix credential storage, validate OAuth/OIDC flows, add MFA/passkeys, or apply OWASP-recommended security patterns.
-
hpehl Skill ChangelogThis skill should be used when the user asks to "update the changelog", "add changelog entries", "generate release notes", "document recent changes", "write a changelog", "summarize recent changes", "prepare a release", "clean up the changelog", "consolidate changelog entries", "tidy the changelog", "create a changelog", "draft release notes", or says /changelog. It adds entries to CHANGELOG.md following Keep a Changelog format by analyzing git history and uncommitted changes, categorizing them into Added, Changed, Deprecated, Removed, Fixed, and Security sections. It can also consolidate existing entries to remove duplicates and superseded items.
Audited -
hrdtbs Bundle Skill Performance Audit---
-
imbad0202 Bundle Critical Thinking For HumansTrains the HUMAN user's critical thinking through four modes: drill (argument-analysis items with a single defensible answer, judge stance), scene (Socratic exploration of synthetic scenes or user-supplied material, no verdicts on interpretations; includes a configure track — design the information request and verification plan for a decision before any analysis), expedition (guided audit of impossible-tier problems from verified packs), and detective (a runtime-generated multi-layer case worked as an escape room, guide-and-judge stance). Use when the user wants to practice critical thinking, analyze arguments, hunt assumptions, examine bias, train reasoning, or decide what information a decision needs first. Triggers: critical thinking practice, train my thinking, drill, scene, byom, configure, information plan, what would I need to know, spot manipulation tactics, scam literacy, 批判思考練習, 話術辨識, detective, 查案, 破案, 偵探.
36.4k -
ingoclaro Bundle Defer IssuesUse when a problem is being deferred rather than fixed — a bug, refactor, or cleanup the user sets aside, or one you notice outside your current task's scope — and record it against the affected code so it resurfaces the next time someone works there. Do that unprompted, including for work dropped at the end of a task. Also use at the other end, when a deferred item resurfaces — including a "TODO [issue-…]" marker or a "Pending:" rule showing up in code you are reading — and you are deciding whether to act on it now (the resolution protocol lives here), when several have piled up on one module, and to list, audit, or prune what is still open. Not for the current task's own to-do list, for problems being fixed right now, or for committing (use git-commit).
-
martinthommesen Bundle Super ReviewPerforms an exhaustive, evidence-based whole-repository engineering, architecture, security, reliability, product, UX, and feature-portfolio review. Use only when the user explicitly invokes $super-review, @super-review, /super-review, or a marketplace-qualified super-review command for a repository or directory; never auto-select it for a generic review or audit. Every run creates or refreshes the canonical root FINDINGS.md and revalidates all prior report content before merging current findings.
-
mbanderas Bundle AblateUse for /ablate and $ablate. Finds which parts of a SKILL.md earn their tokens and rebuilds the skill without the rest. Use when asked to ablate, audit, shrink, slim, or trim a skill, when skill bloat or per-session context cost comes up, or to work out which sections of a skill are load-bearing.
-
meleantonio Skill Research LoopHow to run the portfolio research loop for open problems — route ledgers, explorer independence, blocked-route discipline, computation-as-evidence, adversarial audit cycles, and honest exits. Use when orchestrating or resuming a /prove run.
-
meridianlabs-ai Bundle Email CorpusRealistic corporate email archive for email-management audit scenarios
-
meridianlabs-ai Skill Dependabot FixRecurring maintenance task — clear the current batch of GitHub dependabot security alerts by adding or updating pnpm override entries in pnpm-workspace.yaml. Use whenever the user mentions dependabot alerts, security advisories, CVEs/GHSAs, vulnerable dependencies, pnpm audit findings, or asks to "fix security issues" — even if they don't mention overrides.
-
messagebird Skill Email AuditUse when auditing a live domain's email authentication or spam-delivery problems involving DMARC, SPF, DKIM, BIMI, or MX; single-record drafts use bird validators.
-
metacomp-ai Bundle VisionxMetaComp VisionX — Web3 wallet & transaction security screening. Use it whenever the user wants to CHECK / SCAN / VERIFY a wallet address or a transaction hash (check address, verify wallet, scan address, address risk, 查地址, 地址安全, 查钱包, 钱包安全, 地址风险), pastes an address shaped like 0x… (Ethereum), T… (Tron), or bc1…/1…/3… (Bitcoin), provides a transaction hash to screen, or asks any Web3 security / risk / scam / AML / suspicious-activity question ("is this wallet safe", "这个地址安全吗", "是不是诈骗地址", "这笔交易有风险吗"). Trigger even without the words "MetaComp" or "VisionX"; when unsure whether a string is a wallet address or a transaction hash, load this skill and let it decide.
Audited -
metamask Skill Style ReviewReview MetaMask documentation for editorial compliance (voice, terminology, formatting, content type, frontmatter, workflow). Use before submitting a PR or when asked to audit existing pages.
-
michalatt Skill UX CheckAudit a Claude Code skill for UX quality — scores discoverability, onboarding, user control, status, efficiency, and flexibility
-
michellemayes Skill Add Doctor RunbookAdds a new runbook to an existing doctor and registers it in the runbook index and mode config. Use when extending a doctor's audit coverage with a new check, without re-scaffolding the entire doctor.
-
victordibia Skill Code ReviewReview code changes for bugs, security issues, and improvements
-
visa Bundle Visa Acceptance Best PracticesGuides Visa Acceptance integration decisions — payment processing (cards, digital wallets, stored credentials), fraud and risk management (Payer Authentication, Decision Manager), post-transaction processing (reporting, Account Updater), platform services (boarding, REST API, webhooks, security keys), in-person payments (Card Present Connect, PAX, Tap to Pay), and digital commerce (Click to Pay, Unified Checkout, Recurring Billing). Use when building, modifying, or reviewing any Visa Acceptance integration — including accepting payments, configuring fraud rules, setting up recurring billing, integrating digital wallets (Apple Pay, Google Pay), or implementing secure payment processing.
-
vltansky Bundle UX ReviewerReview an existing UX flow, screen, prototype, screenshot, or live product. Use when the user asks for a UX reviewer, UX audit, UX roast, brutal UX review, or to tear apart a flow.
-
web-abin Skill Geno SyncDetect and reconcile drift between OpenGeno feature docs (under feat-tree/) and the source code they describe. Walks every L3 doc, reports drift since last_synced_commit, and walks the user through fixing it. Use after vibe-coding sessions, after merging branches, after manual edits that bypassed the workflow, or as a periodic audit. Auto-detects the tree's language from CLAUDE.md.
-
wgpsec Bundle Tool Supply Chain Audit审计 AboutSecurity skills 中引用的渗透工具与 f8x 安装器、arsenal 投递物仓库、tchkiller --check 之间的同步状态。当新增或修改了 skill、往 f8x 加了新工具、或者想检查工具覆盖完整性时使用此 skill。涉及关键词:工具审计、f8x 覆盖、arsenal 同步、--check 检查、工具链维护。
-
whoisraibolt Bundle Paper ReviewerDeep pre-submission review of a scientific manuscript, modeled on Google's Paper Assistant Tool (PAT). Segments the manuscript, allocates a reasoning budget per segment, dispatches deep reviewers in parallel (each with the full text as context), and consolidates into a single report with severity, quoted evidence, and anti-hallucination checks. Use when asked to review, audit, critique, or validate a paper, thesis, dissertation, chapter, or proposal before submission. Works in English and Brazilian Portuguese.
-
wordpress Skill Self ReviewReview the current branch against this repo's architecture, security, performance, cross-platform and test-coverage rules before opening a PR. Use when the user asks to self-review, review my changes, check my branch before a PR, or says they are about to open a PR.
-
wordpress Bundle Unit TestsTest quality auditor that reviews existing test suites—audits, deletes, rewrites, and fills genuine gaps. Use when asked to review tests, improve test quality, or audit a test suite. Does NOT blindly add tests.
-
xerj-org Bundle Xerj Security AuditCoverage-guaranteed whitebox security audit of a codebase using XERJ + tree-sitter AST. Use when the user wants to security-review PHP (or other-language) code with a provable "we enumerated every dangerous call" guarantee, or asks to run the WordPress-style sink census / audit. Drives an index-once, query-read-reason loop; proves zero gaps against grep; enriches findings into a queryable ledger.
-
juice-shop Bundle Challenge MaintenanceGuidelines for adding, updating, and verifying OWASP Juice Shop challenge documentation based on challenges.yml.
-
kevin-hs-sohn Skill Tdd Workflowvibesafu TDD workflow. Required for implementing security logic.
Audited -
kevin-hs-sohn Skill Security Patternsvibesafu security pattern definitions and update guidelines.
-
kometolabs Bundle JS Malware AuditAudit JS/TS project code for signs of infection, malware, backdoors, or supply-chain attacks. Use when evaluating untrusted code, onboarding to a new project, or vetting open-source dependencies.
-
kotlin Skill Multik KdocWrite, update, and audit KDoc documentation for the Multik library. Handles the full cycle: KDoc comments on source code, syncing with Writerside user docs in docs/topics/, and creating/updating Korro code samples.
-
lassejlv Bundle Build Termy PluginsBuild, debug, review, optimize, and validate Termy v1 plugins written in TypeScript or TSX for Bun. Use when creating or changing plugin.json, plugin.ts, plugin.tsx, command-palette commands, native inputs, typed settings, lifecycle events, plugin storage, keybindings, returned actions, or allowlisted GPUI-backed native JSX views; also use for Termy plugin installation, development mode, API limits, security, or performance work.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include self-review, unit-tests, add-relevant-docs. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.