Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
courtneyr-dev Bundle Comprehensive Documentation EngineeringUse when the user says 'write docs', 'document this', 'docs audit', 'Diátaxis', 'restructure the docs', 'release notes', 'field guide', 'verify the docs', or 'docs strategy', or when tutorials, how-tos, reference, or explanation need writing, review, or governance. Release testing goes to wp-release-party; audit handoffs to wordpress-audit-handoff.
-
cpvalente Skill Code ReviewReview Ontime changes for concrete correctness, architecture, testing, routing, security, and maintenance issues. For GitHub Copilot review.
Audited -
crev-dev Skill Cargo Crev ReviewReview Rust dependencies and create/publish cargo-crev package review proofs for the user. Use when the user asks you to review one of their Rust dependencies, audit a crate, or produce a crev proof.
-
cristoslc Bundle AI Output HumanizerAudit and rewrite content to remove AI writing patterns. Three modes (rewrite, detect, edit), voice calibration from sample or named profiles, iterate-to- convergence, context-aware strictness, and explicit ethics framing. Synthesizes the best detection patterns from conorbronsdon/avoid-ai-writing, blader/humanizer, brandonwise/humanizer, stephenturner/skill-deslop, and lguz/humanize-writing-skill.
-
csy-csy123 Skill Code ReviewPerform thorough code reviews with security, performance, and maintainability analysis. Use when user asks to review code, check for bugs, or audit a codebase.
-
atharvnaik1 Skill Ipaship AuditUse when auditing iOS/Android app submissions for compliance with Apple App Store Review Guidelines or Google Play Developer Policies. Scan .ipa, .apk, or .zip files against official store policies, generate structured compliance reports, and identify violations with remediation steps.
-
atlasaidev Bundle Wordpress Plugin DevelopmentBuild WordPress plugins correctly and pass wp.org Plugin Directory review. Covers the full Plugin Developer Handbook (security, hooks, REST, shortcodes, blocks, CPTs/taxonomies, settings/meta, privacy/GDPR, users/roles, HTTP API, WP-Cron, JS/Ajax, i18n, readme/assets/SVN) and the 19 wp.org guidelines that cause closures (trialware, telemetry without opt-in, remote-loaded assets, missing source for minified files, wrong text-domain literal, missing REST permission_callback, vendored library collisions). Use when building a WordPress plugin or fixing a Plugins Team closure, preparing a submission, auditing compliance, responding to Plugin Check warnings, adding REST routes/shortcodes/blocks, registering CPTs/taxonomies/settings/meta, enqueuing scripts, wiring cron or activation hooks, translations, sanitizing/escaping, capability/nonce checks, or bundling PHP libs. Apply proactively on code under `wp-content/plugins/` or when you see `register_rest_route`, `add_shortcode`, `register_post_type`, `register_settin
-
avdlee Bundle Xcode Disk CleanupAudit and safely clean Xcode-related developer storage on macOS. Use whenever a developer mentions low disk space, Xcode storage, DerivedData, simulator devices or runtimes, stale beta platforms in Xcode Settings, DeviceSupport, archives, dSYMs, CocoaPods caches, simulator dyld caches, project .build folders, downloaded Xcode DMGs/XIPs, duplicate Xcode installers, or old Xcode applications. Also use this skill proactively when you hit low storage during other work, such as a build, download, or install failing with an out-of-disk-space error. Always measure first, report recoverable GiB with evidence, and obtain explicit itemized approval before any mutation.
-
axelfreeman Bundle Hermes Security AuditFree security audit for Linux servers — no API keys, no paid tools. Scans for viruses (ClamAV), rootkits (rkhunter + chkrootkit), SSH brute force, crypto miners, exposed credentials, and open ports. 12 detection methods, proven on production (11,000+ attacks found and blocked). Use when the user asks to audit or harden a Linux server, check for malware/rootkits/crypto miners, scan open ports, or detect SSH brute force — "security audit", "check for malware".
-
ayrtonaldayr Bundle Java Spring FrameworkSenior Java & Spring Boot 4 / Spring Framework 7 architect skill for 2026-standard development. Use when the user asks to build, scaffold, design, review, or explain Java applications using Spring Boot 4.x, Spring Framework 7.x, Spring Modulith, or any related Spring ecosystem project. Triggers include: creating REST APIs, designing microservices, configuring data access (JdbcClient, JPA 3.2, R2DBC), reactive programming (WebFlux), security (Spring Security 7), observability, GraalVM native images, Gradle/Maven build configuration, Jakarta EE 11 migration, and any task requiring idiomatic modern Java (Java 25: records, sealed classes, structured concurrency, scoped values, pattern matching, JSpecify null safety).
-
baagad-ai Bundle Expert OpinionUse when you want multi-expert parallel review of any artifact — code, documents, architecture plans, business proposals, agentic skills, or any URL. Detects your environment, discloses what it found, asks what to add, then proposes expert perspectives specific to the submitted artifact. Gates on confirmation. Runs each expert in a parallel subagent with streaming progress markers. Synthesizes findings into a prioritized audit document. Runs adversarial verification on critical/major findings. Supports follow-up conversation and remembers past audits for diff-aware re-audits. For skill artifacts (directories containing SKILL.md), uses a specialized skill-audit mode with structural pre-validation, maturity scorecard, and phased remediation plan.
-
lxgic-studios Bundle AI Xss CheckXSS Scanner
-
lxgic-studios Bundle Clawdbot Security Auditai-security-audit
-
laucked-security Bundle AuditDeep white-box OSWE-style web application security audit. Invoke ONLY via the explicit /oswe:audit command. Detects stack and attack surface, traces source-to-sink vulnerabilities, chains them toward unauthenticated RCE under a proof contract, and writes a dated report to .oswe/reports/.
-
layton2617 Bundle Shield ScanAI-powered security scanner — detect vulnerabilities, leaked secrets, and dependency risks in any codebase
-
levnas Bundle Audit FlushInspect and flush staged audit-trail entries to the remote trail repository. Use when the user asks to "flush audit trail", "show what's pending in audit trail", "dry-run audit flush", "retry audit pending", or when diagnosing why a previous auto-flush was skipped (secret hit, push failure, manual mode).
-
longxl6 Bundle Windows 360 CleanerAudit and safely remove confirmed 360/Qihoo Windows software, including browsers and security products, SoftMgr download components, Huabao/duohuipingbao screen savers, persistence, and leftovers. Use when a user asks to find, explain, uninstall, or clean 360-family software from Windows. Do not use for generic malware cleanup or deleting every path containing the number 360.
-
lucashenriquediniz Bundle Adsense Site AuditorAudit websites for Google AdSense application readiness and ad-serving compliance. Use when checking whether a site is likely to satisfy AdSense eligibility, site ownership, content quality, navigation, crawler access, ads.txt, privacy disclosure, Google Publisher Policies, AdSense Program policies, or when the user asks if a site can apply for AdSense, pass AdSense review, show ads, or fix AdSense rejection/site-not-ready issues.
-
lum1104 Bundle Red ButtonUse when an action could cause material, hard-to-reverse harm to production, data, security, finances, users, or external systems.
-
mnickz Bundle Docs Driven WorkflowUse when starting or finishing any coding/editing task in a project that follows a documentation-first AI collaboration workflow — declare scope before editing, log every change afterward with a changelog entry, scaffold a brand-new project with this discipline (AGENTS.md/README/docs skeleton), or audit and reorganize a project's folder structure against its own documented conventions.(中文触发词:初始化新项目/搭 AGENTS.md 骨架、存量项目接入文档驱动规范、整理文件夹/文件归档、改动前声明范围、改动后写 CHANGELOG/留痕)
-
machai-kydoimos Bundle Dependabot AuditAudit an automated dependency-bump PR and produce an evidence-backed merge recommendation — verify lockfile artifact hashes against the registry, cross-check the true latest version, read changelogs for security and behavior changes, reproduce the repo's own checks in an isolated worktree, and report. Verifies uv.lock, GitHub Actions and pre-commit hooks end to end; any other ecosystem gets the ecosystem-independent phases and a stated boundary rather than an improvised recipe. Use when the user asks to review, audit, check, or decide on a Dependabot or Renovate PR, a dependency bump, a lockfile PR, or asks "is this safe to merge".
-
mattiaf95 Bundle Codebase Analysis AIAnalyze repository evidence to bootstrap, migrate, update, or audit project documentation covering architecture, flows, APIs, schemas, security, configuration, and delivery. Use when creating a complete documentation system, synchronizing existing docs with Git or code changes, adopting unmanaged documentation, checking documentation accuracy, or installing the supporting workflow. Prefer bounded Git-diff analysis for updates; use full-repository analysis only for explicit bootstrap requests. Do not use for generic writing, standalone code explanations, or code-quality reviews.
-
fennal Bundle Biblio CheckVerify, correct, and reformat academic bibliographies. Use when the user asks to check, audit, validate, or verify citations or references in a paper, or asks whether a bibliography contains hallucinated, fabricated, or wrong sources. Also triggers on "check my references", "audit my works cited", "are these citations real", "fix the bibliography", "convert citations to APA/MLA/AMA/Chicago/Vancouver/IEEE/Harvard", "format my works cited", or any task that involves a .bib file, .ris file, or a references/works-cited section of a paper. Use this skill whenever the user mentions citations, references, bibliography, works cited, DOI lookup, or worries about hallucinated sources, even if they do not explicitly use the word "check". For papers that have no references and need them, use the suggest subcommand to find candidate sources, but never auto-insert citations without human review.
-
fitz-s Bundle Chatgpt ConsultOffload a deep, self-contained job — code review, architecture/planning, hard reasoning, research, a second opinion, an audit — to the user's ChatGPT Pro subscription in the background, keep working locally, and get woken with the full result. Use when the job is worth ~25 min of frontier reasoning AND you have other work meanwhile. Do NOT use for anything answerable locally in minutes, for routine checks, or when the answer is needed immediately. Inputs must be PUBLIC GitHub links or content safe to send externally — never secrets/`.env`/keys/private code.
-
franalgaba Bundle Clean Code TSReview and refactor TypeScript code following Clean Code principles (Robert C. Martin's Clean Code, adapted for TypeScript). Produces a report listing every violation found — grouped by category — along with a fully refactored version of the code. Use this skill whenever the user asks to "review", "clean up", "refactor", "lint", "audit", or "improve" TypeScript or TSX code for readability, maintainability, or clean code compliance. Also trigger when the user pastes TypeScript code and asks for feedback, best practices, or code quality improvements — even if they don't explicitly say "clean code". Do NOT trigger for pure style/formatting-only requests (e.g. "run Prettier"), non-TypeScript languages, or runtime debugging/error-fixing that has nothing to do with code quality.
-
frankxai Skill Visual Intelligence System VisAgentic visual asset management — scan, audit, and manage images across your site with AI-powered quality enforcement
-
shanedixongit Bundle Macverify ReviewUse when the user wants their Mac audited, reviewed or cleaned up - "audit my machine", "check my Mac", "why is my disk full", "is my setup secure", "review my Claude Code config", "what should I fix on this laptop" - or when a macverify report already exists and they want it read, triaged and turned into fixes. Runs the read-only macverify collector, then evaluates the findings and proposes specific fixes in the order they should be applied.
-
steffano198 Bundle Skill Security ScannerSkill Security Scanner
-
synthrun Bundle Cicada🔐 Cicada — Security Audit & Fix Skill
-
tabarc-code Bundle Repo Doc WriterWrites GitHub project documentation as two separate markdown files, README.md and description.md, in UK English and in the voice of the programmer who built the thing. Write-only: it drafts documentation, it does not audit, score or repair existing docs. Use this skill whenever anyone wants a README, a repo description, a description.md, an installation or setup guide, an idiot's guide, a project write-up, or documentation for a repository, package, skill or tool. Trigger it even on casual phrasing such as "write up my repo", "document this project", "I need a README for this", "give me the GitHub blurb", or when a user hands over source code and asks what to say about it.
-
zerodriftsec Bundle Move AuditorSecurity audit of Move code (Sui / Aptos). Auto-detects platform. Trigger on "audit", "check this contract", "review for security". Modes - default (full repo) or a specific filename.
-
zhen-bo Bundle Smell CheckRuns a smell-first audit on a user-chosen path set: measures structure metrics, applies a named size profile, and reports code smells and test smells with evidence strength. Use for smell audit, code smell scan, whole-repo audit, tech debt scan, test smell check, maintainability audit, or duplication and nesting checks. Do not use for PR review, merge advice, implementing fixes, writing new features, or lint/format-only passes.
-
aashaexo Bundle HumanizeRemove signs of AI-generated writing from prose, and keep it out of a repo. Use when drafting, editing, or reviewing text to make it sound natural and human, or when auditing a whole docs folder for AI slop. Detects 41 patterns across content, language, style, communication, filler, and rhetoric, including: significance inflation, promotional language, -ing tails, vague attributions, AI vocabulary, copula avoidance, negative parallelisms, false agency, em dash overuse, chatbot artifacts, hedging stacks, staccato drama, and aphorism formulas. Includes voice calibration, a no-fabrication rule, statistical tells, and a draft -> audit -> final rewrite loop.
-
abchatterjee7 Bundle Abc Spring Boot SkillsBuild Spring Boot 4.x applications following best practices. Covers how to use Spring MVC, Spring Data, and Spring Security.
-
aboudjem Bundle Solidity Style GuideApply the Aboudjem/solidity-style-guide rules to Solidity code — review, rewrite, or audit for naming, layout, formatting, NatSpec, custom errors, ERC-7201 storage, gas patterns, and Foundry test structure. Trigger when the user asks to "review Solidity style", "apply the style guide", "format .sol file", or mentions Solhint / Prettier / Foundry conventions in a Solidity repo.
-
acm-rgb Bundle Tutor BuddyA pragmatic workflow taking a software project from idea to a secured, GitHub-ready repository, for beginners and vibecoders who want to ship without the usual mistakes. Runs five phases - ideate (have an idea, or get one suggested from the user's profile and current trends), plan (structure, file names, boilerplate, pinned deps), build (execute only the agreed plan, flag deviations first), security-audit (real checks for leaked secrets, vulnerable or typosquatted/hallucinated dependencies, dependency confusion, plus CI and auth hardening, and an honest note on what it cannot verify), and ship (repo hardening and a safe first push). Use whenever someone wants to start a new project or app, has an idea or wants one suggested, asks how to structure or scaffold a project, wants a safety check before shipping, or wants help getting code onto GitHub safely. Triggers include "start a project", "build me an app", "is my project safe", "put this on GitHub", even when tutor-buddy is not named.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include tutor-buddy, comprehensive-documentation-engineering, code-review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.