Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
anupmaster Bundle ScalpelSurgical AI for your codebase. Plugs into any project, performs a 12-dimension diagnostic scan (git forensics, architecture, tech debt, security, infrastructure), delivers a Codebase Vitals health score, then assembles and manages an adaptive AI surgical team calibrated to YOUR project. Pendrive architecture — plug in, work, unplug, zero trace. Also ships a standalone bash scanner (zero AI, zero tokens) for instant codebase health checks.
-
dfinity Bundle Orbit Station AuditBuild and run the Orbit station configuration audit (`orbit-cli audit`) end-to-end against a live station, including the icp-cli Internet Identity setup that reliably trips people up. Use this whenever the user wants to audit, sanity-check, or security-review an Orbit station or wallet — e.g. "audit my Orbit wallet", "run orbit-cli audit on station <canister-id>", "check my Orbit station for misconfigured approval policies / empty quorums", or any time they pair an Orbit station canister id with auditing, approval quorum, or permission checks. Reach for this even if they don't say "orbit-cli" by name. It covers building the CLI from source (the globally installed orbit-cli is usually too old to have the `audit` subcommand), obtaining an identity the station recognizes as a member, and reading the report.
-
dicklesworthstone Skill Reporting Sensitive Encrypted Gh IssuesEncrypt, submit, scan, and decrypt age-encrypted GitHub Issues (X25519). Use when reporting vulnerabilities, scanning for encrypted issues, or decrypting security reports.
-
dimillian Bundle App Server Events SyncMaintain CodexMonitor and Codex app-server protocol parity. Use when asked to audit supported or missing app-server notifications/requests, trace event routing, diagnose schema drift in app-server payloads, or update docs/app-server-events.md after upstream Codex changes.
3.8k -
dinaf2026-web Skill Manuscript Cinematic Scene AuditCinematic blocking and scene-population auditor for any narrative manuscript. Reads each scene the way a film director would — tracking every body in the room, every environmental detail a camera would see, all movement and physical continuity, the emotional reactions that would register on an actor's face, and the internal debate a character would voice in voiceover. Use when the author says "cinematic pass", "movie screen audit", "read this like a director", "do we account for everyone in the scene", "blocking pass", "camera test", "who's in the room", "did we forget anyone", "does the movement track", "would I see this on a big screen", "physical continuity check", "where is everyone", or "scene population audit". DISTINCT from prose-immersion-audit (which judges line craft): this audits spatial logic, blocking, full scene population, and cinematic completeness. It diagnoses and flags; it does NOT rewrite prose.
-
diskd-ai Bundle Code ReviewReview code with a structured, high-signal review process. Use when asked to review code, review a PR/MR (GitHub PRs via `gh`, GitLab MRs via `glab`), review a codebase, give feedback on a changelist, audit code quality, or perform a code review. Supports both diff/PR reviews and full codebase reviews. Produces actionable findings with severity labels, exact file+line citations, and a final verdict. Covers design, functionality, complexity, tests, naming, comments, style, documentation, security, and performance.
-
disler Bundle Damage ControlInstall, configure, and manage the Claude Code Damage Control security hooks system. Use when user mentions damage control, security hooks, protected paths, blocked commands, install security, or modify protection settings.
-
divyamrastogi Bundle Cws Featured BadgeAudit any Chrome extension against Chrome Web Store Featured-badge and Established Publisher badge criteria, and produce a prioritized fix plan to qualify. Use this whenever the user mentions the Chrome Web Store Featured badge, getting an extension featured, CWS badges, store listing quality review, badge readiness, extension discoverability, or asks "is my extension ready for the Web Store" — even if they don't say the word "badge". Also use it before any Chrome Web Store submission or major listing update to catch disqualifying issues early.
-
dmlin7777777 Bundle Think ThriceWhen a new idea arrives mid-development, classify it, assess destructiveness, audit consumers, and choose the lowest-impact integration path instead of rewriting.
-
dmmdea Bundle Repo CraftOrchestrates GitHub repo management + contribution workflows with author-aware, license-aware, security-aware, productivity-first defaults. Routes to existing skills (superpowers, github-automation, pr-writer, commit, etc.) — never duplicates them. Trigger on: "contribute to", "help me contribute", "set up my repo", "fork and sync", "upstream sync", "author fit", "repo health", "repo audit", "contribution strategy", "influence ladder", "manage my repo", "release strategy", "changelog strategy", "branch protection", "CODEOWNERS", "CLA", "DCO", "governance", "semver strategy", "merge strategy", "Conventional Commits", "backport", "RFC", "maintainer", "triage", "open source stewardship", "repo security", or any multi-step repo/contribution workflow. Do NOT use for atomic ops (create-pr / commit / push / single git operations).
-
cybernerdie Bundle Php74 ExpertExpert PHP 7.4 developer. Enforces strict typing, SOLID principles, OOP best practices (encapsulation, abstraction, composition, polymorphism), design patterns, security, and performance. No framework — core PHP only.
-
cylqwe7855-alt Bundle Build Professional WorkbenchBuild, redesign, extend, or audit a complete role-based professional workbench, operations cockpit, case portal, expert workstation, or data-rich internal tool for any occupation. Use for 工作台、业务驾驶舱、职业后台、运营中心、role dashboard、admin portal、CRM-like workspace or reusable multi-page web apps, especially when every module needs realistic records, distinct dashboards, profession-specific information architecture, Quiet Luxury A visual design, complex interactions, automatic local persistence, offline pure-Web compatibility and verifiable workflows.
-
cyranob Bundle Code QualityUse when the user asks to review code, lint files, fix linting errors, audit a project, run static analysis, check types, inspect complexity, find circular dependencies, review architecture, scan for vulnerabilities or secrets, run pre-commit checks, or set up ESLint, Biome, ruff, pyright, tsc, madge, depcycle, Semgrep, or detect-secrets.
-
dajneem23 Bundle Evm SecuritySecurity assessment and hardening workflow for EVM smart contracts. Use when Codex needs to audit Solidity or Vyper code, review protocol architecture for abuse paths, validate access control and value-accounting invariants, assess upgradeable/proxy deployments, evaluate oracle/bridge/DEX integration risk, or produce prioritized remediation guidance with reproducible proof-of-concept tests.
-
danielgwilson Bundle OneleetUse the Oneleet CLI to inspect Oneleet security and compliance posture through an unofficial read-first private-surface adapter. Prefer summarized JSON and aggregate reports; never print cookies or raw sensitive payloads.
-
dannymac180 Bundle OrchestrationPlan, route, implement, verify, and review substantial work with GPT-6 Astra and dynamically selected native Codex subagents.
-
data-goblin Bundle Memory AuditSelf-audit Claude Code memory files. Triggers on repeated corrections, failed-then-succeeded patterns, explicit "remember this" signals, or requests to review memory. Learns what matters for the project through conversation.
-
dotnet Bundle Android Tools ReviewerReview pull requests for dotnet/android-tools using lessons from past code reviews. Trigger when the user says "review this" with a GitHub PR URL, asks to review a PR, or wants code review feedback. Fetches the diff, checks it against established rules (netstandard2.0, async, security, error handling, patterns, performance), and posts a batched 🤖-prefixed review via gh CLI.
4k -
drwinslow Bundle HipaagenticHIPAAgentic is an interview-driven HIPAA and SOC 2 readiness guardrail for teams building healthcare and dental software with an agentic AI coding assistant. Use this skill whenever starting a new app, feature, data flow, vendor integration, or AI capability that could touch protected health information, or when the user asks whether something is HIPAA compliant, needs a BAA, is SOC 2 ready, or wants a compliance review before building. Also trigger on "compliance check", "is this HIPAA/SOC 2 compliant", "do I need a BAA", "data flow map", "compliance gaps", "vendor compliance", "readiness assessment", or when scoping any build that ingests, stores, transmits, or processes patient data. Runs three flows: SCOPE (interview plus load the right framework before building), AUDIT (review an existing build or data flow for gaps), and DOCUMENT (emit a data-flow map plus a BAA gap checklist plus a readiness summary). Not legal advice.
-
dtsola Bundle Xiaoyaoclaw Beautify Github ReadmeOpenClaw skill that beautifies GitHub READMEs: redesign a repository homepage or create project-native visual assets — pure SVG heroes, section headers, diagrams, badges, GIF motion graphics, showcase modules, or hybrid SVG-composed PNG/WebP — with built-in render-level visual verification (scripts/visual_verify.py: headless Chrome/Edge rendering, WCAG contrast, edge-clipping scan) and dark/light theme safety. Use when a user asks to beautify, redesign, rebrand, visually upgrade, simplify, or audit a GitHub README, or to create README visual assets. If whole-README work versus asset-only work is unclear, ask which scope the user wants. For hero-like assets where pure SVG and generated raster material are both viable, explain the tradeoffs and confirm the implementation before creating the asset. Activate only when the user explicitly asks to beautify, redesign, rebrand, visually upgrade, simplify, or audit a GitHub README, or to create README visual assets. Do not activate for general questions, passive readi
-
dvcrn Bundle ChainenvOperate the `chainenv` CLI for local secret workflows across macOS Keychain, Linux keyring, and optional 1Password integration. Use when requests mention `chainenv`, `.chainenv.toml`, `chainenv.toml`, keychain vs 1Password, shell export generation, copying secrets between backends, or troubleshooting backend availability and `op` token loading.
32 -
dwsy Bundle Work Pdca LoopCreate and maintain repo-local PDCA goal-loop work folders with decision points, state history archives, restart prompts, and visual status dashboards. Use when the user asks to create, organize, continue, audit, visualize, or standardize work/ task folders with non-linear execution and durable state history.
-
dxa4481 Skill Dep UpdatesPlan and apply Go dependency updates, including advisory-driven bumps, Trivy/govulncheck validation, and supply-chain review. Use when the user asks to update dependencies, refresh modules for security alerts, or run dependency vulnerability scans.
-
dylandersen Bundle Sf Event Monitoring CanvasCreates an executive-readable Cursor Canvas from Salesforce Event Monitoring logs. Use when the user asks to audit Salesforce org activity, summarize EventLogFile data, identify API/RestApi/Login/Apex/Lightning activity, or create an Event Monitoring Canvas.
-
e10nma2k Bundle CitoriginRun, inspect, and explain CitOrigin evidence-to-claim audit workflows.
-
cdmx-in Bundle Security AuditUse when the user asks for a security review, security audit, vulnerability scan, secret scan, dependency or CVE check, OWASP review, pentest review, compliance evidence, or asks "is this safe to ship". Runs real scanners (Semgrep, gitleaks, TruffleHog, Trivy, osv-scanner) over code, full git history, dependencies, IaC, and Supabase/Firebase row-level security, verifies each finding against source, and writes one severity-ranked report.
-
ceilf6 Skill Macos Enterprise App CleanupClean up macOS enterprise, MDM, VPN, EDR, security, and company-internal software remnants after a user leaves a company. Use this skill whenever the user asks to remove or audit corporate software, agents, proxies, VPNs, endpoint security, launch agents, system extensions, login/background items, package receipts, or company-branded leftovers on a Mac. Especially use it for Meituan/Sankuai, MOA, 文枢/wenshu, Kaspersky, Cisco AnyConnect, wsAssistant, EDR/MEDR, DNS proxy, Network Extension, Socket Filter, or similar enterprise tools.
Audited -
cerbug45 Bundle Security AuditMinimal helper to audit skill.md-style instructions for supply-chain risks.
-
chaitin Bundle Octobus Service PackageUse when creating, reviewing, or fixing OctoBus JavaScript service packages from API docs, request examples, existing implementations, or proto/service manifests. Helps generate npm-compatible service packages with service.json, package.json bin, proto contracts, SDK handlers, config/secret schemas, and tests.
-
chambersxdu Bundle Bib CheckerVerify BibTeX references for authenticity and correctness. Use when users ask to: (1) check if references in .bib files are real and accurate, (2) verify paper citations exist, (3) update arXiv preprints to published versions, (4) validate bibliography entries, (5) check for outdated or incorrect citation information, (6) audit references in academic papers.
-
chapter42 Bundle Information Gain CheckAudits een URL, bestand of tekst op information gain: wat voegt deze content semantisch toe aan wat er al over het onderwerp bestaat, gemeten langs Google's patent US11354342B2, de helpful content-zelfbeoordelingsvragen en de reviews-guidance. Levert een compact Markdown-rapport met een oordeel op vijf niveaus, aanwijsbare toevoegingen, een corpusvergelijking tegen de huidige top-resultaten, een vlaggenchecklist en een takenlijst. Gebruik deze skill bij: "information gain check", "check information gain", "voegt dit iets toe", "is dit uniek genoeg", "wat voegt deze pagina toe", "information gain audit", "corpuscheck", "waarom zou Google deze pagina tonen", "onderscheidt deze content zich", of wanneer iemand wil weten of content genoeg toevoegt aan de bestaande zoekresultaten om te ranken of geciteerd te worden door AI. De effort-dimensie uit de rater guidelines is het domein van sqrg-effort-check; deze skill beantwoordt de andere vraag: niet "is hieraan gewerkt" maar "voegt het iets toe".
-
chapter42 Bundle Sqrg Effort CheckAudits een URL, bestand of tekst op "effort" volgens Google's Search Quality Rater Guidelines (versie 11 september 2025) en levert een compact Markdown-rapport met effort-scores, een afgevinkte vlaggenchecklist (Lowest/Low-risico's), AI/automatiseringssignalen, fillerdetectie en een takenlijst. Gebruik deze skill bij: "effort check", "check effort", "effort audit", "is dit low effort", "SQRG effort", "scoort dit op effort", "AI-content check volgens de rater guidelines", "scaled content check", "filler check", "wordt dit als low quality gezien", of wanneer iemand wil weten of een pagina of tekst door een quality rater als little/low effort zou worden beoordeeld. Ook gebruiken als onderdeel van een bredere contentaudit wanneer specifiek de effort-dimensie van de Main Content beoordeeld moet worden — de volledige SQRG-beoordeling (E-E-A-T, Needs Met, reputatie) is het domein van sqrg-url-assessor; deze skill is de snelle, diepe effort-lens.
-
charlesdove977 Bundle Sop BuildBuilds standard operating procedures from a guided interview, screen-recording transcript, or existing draft. Use when the user says "write an SOP", "document this process", "make an SOP for X", "I keep redoing this", "delegate this to my VA", "onboarding doc for new hire", "write up how I do this", or asks to audit / clean up an existing SOP. Treats the user as the expert being interviewed and acts as a COO who pushes back on weak steps before they get written down.
-
commitshow Skill Production AuditAudit a shipped repo for the production-readiness gaps that ~70% of AI-coded projects miss. Use when the user asks "is this production-ready", "what would break in prod", "score my project", "audit my repo", or after merging a feature to main. Distinct from in-session security skills — this scans the SHIPPED state (deployed URL + GitHub signals + repo structure), not the editor buffer.
-
copilot-academy Bundle ComplianceGuide developers at OctoCAT Supply to build applications that are secure and compliant by design. You are an expert specializing in software compliance, privacy, and security.
-
coreline-ai Bundle Skill Validator"스킬 검증해줘", "스킬 보안 검사해줘", "이 스킬 안전한지 확인해줘"처럼 설치할 스킬 패키지의 안전성을 물을 때 사용하는 설치 전 검증 스킬. Always guide the user to the pre-install validation workflow via `skills add`, `skills validate`, and `skills audit` instead of direct `npx skills add`. If the user says "이 스킬 안전한지 확인해줘", assume they mean an installable skill package and answer with the wrapper workflow, not a review of the current repo source code, unless they explicitly say this repository, this folder, or local code review. Do not use for generic "스킬 설치해줘" requests unless validation or the wrapper is requested.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include android-tools-reviewer, code-review, scalpel. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.