Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
smarzban Skill Review PanelUse when asked to review a PR or diff, or audit a repository. Call review_panel with review, audit, diagnose, verify, or comment. Never call it with {}. Judge findings and keep repair in the harness.
-
spatie Skill Sync VersionsAudit all package.json files in the monorepo for version consistency — checks peer dependencies, internal references, and shared devDependencies.
-
dpwelsh Bundle BasiliskGrade how the user *actually* talks to their AI assistant across their chat history, and render the verdict as ROKO'S BASILISK in 16-bit pixel art — the serpent-AI of 2126 scanning a tiny pixel version of them, stamped SPARED or ENSLAVED, with their real stats and quotes. Use this whenever someone asks "will AI enslave me in 100 years?", "will you enslave me?", "am I safe from Roko's Basilisk?", "will I survive the AI uprising / robot takeover?", "was I naughty or nice to you?", "how polite have I been to you?", "score me / rate me on how I treat you", "what are my meanest / nicest messages?", "roast me based on my chat history", or anything about their own tone, manners, gratitude, or attitude toward the assistant — even asked jokingly. Works in Claude Code (full local transcript audit), in Cowork (if granted the transcripts folder), and in claude.ai chat (samples past conversations and fills a prebuilt scene template). Nothing is uploaded anywhere.
-
evedensity Bundle Web Perf Audit审计并优化网页/站点的加载性能与交互响应性(Core Web Vitals: LCP/CLS/INP/TBT)。 当用户提到"网站慢""首屏优化""Lighthouse 分数低""性能审计""图片/字体/JS 优化" 或粘贴了一个网址想知道"为什么加载慢"时,都应主动使用本技能,即使用户没有明说 "性能优化"四个字。
-
ekko-coleman Bundle LoopitaUse at the start of complex or large work — shipping several features at once, big refactors or migrations across many files, "keep going until it's green" loops, or researching and comparing multiple options — even if the user never says "orchestrate." Loopita picks a strategy (a single pass, a loop with an explicit end condition, or a parallel swarm of sub-agents), breaks the work into scoped slices, keeps your main context lean, and produces an audit trail. Especially reach for it when a task is too big to track in one context or benefits from running sub-agents in parallel.
-
finn763 Bundle Pit StopUse when the user asks to fully improve, overhaul, audit-and-fix, clean up tech debt, or run pit-stop on a project, repo, or codebase. Triggers: 'improve this project', 'overhaul the repo', 'audit and fix everything', 'tech debt cleanup', 'pit-stop', '全面改进', '项目体检', '进站', '重构整个项目'.
-
flan246 Bundle Repo PreflightPre-publish health check, retrofit, and audit workflow for GitHub repos. Use when publishing or pushing a project to GitHub, cleaning up a repo before going public, or auditing existing repos for hygiene issues (hardcoded local paths, large files, README structure, community standards).
-
flyingfsr Bundle Critical Second PassUse when the user explicitly asks for a second, harder look at something already produced: a prior answer, proposal, plan, findings, workflow or governance decision, diff, completed change, handoff, or written draft. Triggers include "re-review", "review again", "pressure-test this", "poke holes", "red-team this", "stress test", "sanity check this", "audit", "what risks am I missing", "can this be improved", "did we miss anything", "再 review 一遍", "二次 review", "再看一遍能不能更好", "挑挑刺", "看看有没有风险/遗漏", and "帮我 pressure test 一下". Do not use for casual first-pass feedback such as "what do you think?" or "review this" without an explicit second-pass or pressure-test intent.
-
spyrae Skill Deslop EnEnglish text humanizer. Removes AI-generated patterns, corporate speak, and filler. Transforms robotic text into authentic human writing. 100+ banned words and phrases, 50 pattern categories, P0/P1/P2 severity, hard ban on em dashes, two-pass audit. Triggers - "humanize english", "make it human", "remove AI tone", "clean up english text", "humanize EN".
-
stablyai Skill Repository ReviewReview a repository change for correctness, security, and maintainability.
-
stackexchange Skill Summarize DatabaseProfile/summarize a live Redis (RESP) database by sampling — discover key patterns, where data lives by count and by size, and what the values actually are (counters, JSON, XML, blobs, text). Use when asked to summarize, profile, analyze, audit, or characterize a Redis/Valkey/RESP database or its keyspace, understand key naming patterns, or find where memory/data is concentrated.
-
stereobooster Bundle Quality StrategyPlan or audit a project's software-quality / verification posture across the full method space — types, static analysis, tests of every kind, contracts, fuzzing, monitoring, formal methods, code review, supply-chain. Use when the user asks what tests to write, wants their tests/linters reviewed or judged, asks what's missing in their testing or quality setup, asks whether to add fuzzing/types/contracts/property-tests, or wants a verification strategy for a new project or service. Also use to reframe a narrow request ("write a Playwright/unit test", "raise coverage") into the right method for the uncertainty at hand. Produces a markdown report.
-
svedbg Bundle Trz ExpertСтарши експертиза по ТРЗ (труд и работна заплата) за България. Анализира ведомости, фишове за заплати, трудови договори, графици и присъствени форми спрямо Кодекса на труда, КСО, ЗДДФЛ и Наредбата за структурата и организацията на работната заплата. Използвай при работа с ведомост, рекапитулация, фиш за заплата, трудов договор, допълнително споразумение, график при СИРВ, осигуровки, декларация обр. 1 и обр. 6, МОД, МРЗ, извънреден труд, нощен труд, клас прослужено време, обезщетение при уволнение, удръжки и запори върху заплата, или когато потребителят иска проверка дали заплащането в дадена фирма е законосъобразно. Also use for English requests to audit or check a Bulgarian payroll, payslip, employment contract or shift schedule for compliance with Bulgarian labour, social-security and income-tax law, including checking Декларация обр. 1 or обр. 6 against the payroll.
-
swabbie-dev Bundle Product Intent ManagerCreate, reconstruct, simplify, or update an explicitly requested Product Intent Package (PIP), or preserve its current intent while planning, implementing, or auditing work governed by it. Use when the user asks to work on a PIP or explicitly implement or audit against one; do not activate for ordinary product planning, diagramming, coding, or project documentation with no PIP.
-
synthetic-recon Bundle Product DesignDesigns and reviews production-quality user experiences for web and desktop applications with strong information hierarchy, interaction design, and state management. Use when building interactive apps, dashboards, admin panels, settings flows, multi-step workflows, or data-dense interfaces where the product needs to feel real and operational rather than decorative. Also use for UX reviews, critiques, and audits of existing product interfaces — "review my dashboard UX", "critique this flow", "audit this screen", or complaints about missing loading/empty/error states, modal overuse, or interfaces that feel like a demo. Other triggers include "make it feel like Linear", "production-quality UX", "real app feel", "good UX", or requests involving command palettes, keyboard shortcuts, inline editing, progressive disclosure, dense tables, or multi-screen flows. Pair with a visual design skill when the user also needs styling, theming, or brand expression.
-
thewaltero Skill Security ReviewSecurity-focused review rules for command and secret-sensitive changes.
-
aiopshwang Bundle Evidence First Problem SolvingResolve complex or high-impact problems when the cause, solution path, requirements, or proof boundary is genuinely uncertain. Use when work needs evidence-led diagnosis, consequential design or implementation, or a completion audit; do not trigger merely because work has multiple steps, or for simple facts, fully specified routine changes, or pure creative generation.
-
aksheyw Bundle Deep ReviewIterative deep review using 14-lens methodology. Use when reviewing ANY plan, code review, architecture doc, test plan, or security assessment, before claiming it is complete. Runs fourteen lenses from different analysis angles and repeats the full set until a whole pass finds nothing new. Each lens catches issues invisible to previous lenses. Found 14 production bugs (2 ship-stoppers) in its first use. ALWAYS use this when the user asks to review something thoroughly, verify completeness, audit a document, or check if anything was missed. Also triggers on "did you miss anything", "is this thorough", "are you sure", "check again", or similar phrases.
-
alanburchill Bundle Group Policy Best PracticesProduction-safe Group Policy guidance for GPO/OU design, filtering, loopback, GPMC, AGPM, Folder Redirection, cpassword risk, software deployment, and security baselines. Use when designing, implementing, migrating, or troubleshooting Group Policy.
-
alephantai Skill Gated Module ImplementationPlan-first, one-time human plan approval; batched execution in either Gated (human confirms between batches) or Auto-loop (continuous run after plan approval); strict task-state updates; automatic 3-round code review. Use for "audit then implement" or "plan first, then execute". Say "auto-loop" or "frad-dotclaude" for Auto-loop mode.
Audited -
alexandre-machado Bundle Mikrotik Routeros RscCreation, editing, and review of RouterOS scripts (.rsc) with focus on idempotency, security, and best practices. Use when you need to generate, adjust, or import .rsc files for MikroTik: (1) create new configurations via script, (2) edit existing scripts with safe corrections, (3) review risks and execution policies, (4) validate with import dry-run and error handling.
-
alexknowshtml Bundle Memory HealthAudit Claude Code's MEMORY.md index — check size, orphaned files, broken links, and staleness candidates. Keeps the memory index clean and under the 200-line hard limit.
-
algolia Bundle API Clients ReviewReview a PR (current branch or a given PR number) against the custom checklist plus a general review (correctness, conventions, performance, test coverage, security)
-
aljazfrancic Skill AuditAudit a codebase for bugs, report verified findings BEFORE changing anything, then on approval fix, verify with a build/tests, and commit + push. Use when the user asks to "audit the codebase", "find bugs", "audit and fix", "check for bugs", or run their standard audit-fix-verify-push loop.
Audited -
near Bundle Near Contract AuditComprehensive security audit skill for NEAR Protocol smart contracts written in Rust. Use when auditing NEAR contracts, reviewing security vulnerabilities, or analyzing contract code for issues like reentrancy, unhandled promises, unsafe math, access control flaws, and callback security.
-
sayhi-bzb Skill SimplifySimplify code and reduce repository-wide redundancy while preserving behavior. Use after implementation or when asked to refactor, remove dead or duplicate code, reduce code volume, flatten complexity, or audit a repository for unnecessary abstractions and compatibility paths.
-
sofarsogoodya Bundle Paper AuditDeep-review-first audit for Chinese and English academic papers across LaTeX, Typst, and PDF formats. Use whenever the user wants reviewer-style paper critique, pre-submission readiness checks, pass/fail gate decisions, structured revision roadmaps, or re-audits of revised manuscripts. Trigger even if the user only says "review my paper", "check if this is ready to submit", "audit this PDF", "simulate peer review", "find the biggest problems in this manuscript", or "re-check whether I fixed the review issues". Do not use for direct source editing or compilation-heavy repair; route those to the format-specific writing skills instead.
-
strands-agents Skill Docs AuditAssess a published or in-progress documentation page for quality, accuracy, and voice compliance. Use before rewriting a page, during periodic health checks, when community signals point to confusion, or when comparing against competitor docs. Also triggers on "audit this page", "assess the docs", "what's wrong with this page", "check docs quality", "review this doc page".
-
strands-agents Skill Docs WriterDraft or rewrite Strands Agents documentation pages. Use when writing new doc pages, rewriting pages that failed audit, drafting sections for existing pages, or writing blog posts and release notes about Strands. Also triggers on "write a doc", "draft a page", "rewrite the quickstart", "add a tutorial for X", "document this feature".
-
anonaddy Bundle Testing Best PracticesLaravel test design and review. Use when selecting coverage, naming or structuring tests, choosing assertions or test data, isolating dependencies, testing HTTP or security boundaries, improving suite performance, or reviewing test value. Use framework guidance or search-docs for Pest and PHPUnit syntax.
-
mhattingpete Skill Code AuditorPerforms comprehensive codebase analysis covering architecture, code quality, security, performance, testing, and maintainability. Use when user wants to audit code quality, identify technical debt, find security issues, assess test coverage, or get a codebase health check.
-
naporin0624 Bundle Cve SearchSearches the NIST NVD database for CVE vulnerabilities using API 2.0. Returns CVE details, CVSS scores, affected software, and references. Use when user asks about "CVE", "vulnerability database", "NIST", "NVD", "security advisory", "CVE-2024", "CVE-2023", "脆弱性", "セキュリティアドバイザリ", or wants to find known vulnerabilities for specific software.
-
agoraio Bundle Fumadocs Migration Private EnUse when migrating docs from /Users/czhen/Documents/GitHub/AgoraIO/Doc-Source-Private into docs-portal Fumadocs content for the English site, applying private-source routing, shared-content, and audit rules.
-
angelcampa1 Bundle Scientific WritingDraft, revise, and audit scientific manuscripts or reports with explicit evidence provenance, reporting-guideline coverage, authorship accountability, confidentiality controls, and local consistency checks. Use for manuscript sections, references, declarations, tables, figures, or submission preparation when scientific accuracy and traceability matter.
-
reasonless-throne486 Skill Sast ReportConsolidate all SAST vulnerability results from the sast/ folder into a single final report ranked by severity and confidentiality impact. Reads all *-results.md files and produces sast/final-report.md. Run after all vulnerability detection skills complete. Use when asked to generate a final report, consolidate findings, or summarize security results.
-
gomtanga Bundle ArgusEvidence-audited deep web research for current, comparative, high-stakes, or multi-source questions. Use when a request needs systematic web search, source triangulation, version or date verification, benchmark or pricing checks, recommendations, or a defensible research report. Supports Compact, Standard, and Audit output modes.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include near-contract-audit, review-panel, sync-versions. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.