Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
adewale Skill AuditComprehensive audit toolkit with 14 audit types. Includes a pre-push branch audit (8-category checklist with Clean/Minor/Blocking verdicts) plus 13 deep-dive audits run via sub-agents: code quality, documentation brittleness, docs-code sync, language best practices, concurrency, resource management, test quality, feature completeness, performance, bug patterns, design philosophy compliance, security vulnerabilities, and UI design (CRAP principles). Use this skill when the user wants to inspect a concrete codebase, branch, diff, repository, service, or docs/source pair: audit before pushing, check their branch, look for duplication or dead code, check docs-code sync, review test quality, find concurrency bugs or resource leaks, analyze concrete security/performance risks in code, review UI implementation, verify feature completeness, or check code against best practices/design principles. Do not use for conceptual explainers about audits, summarizing audit logs, changelog writing, or general security education
-
frendysanusi Bundle Claude Pentest SkillsStructured web application penetration testing with OWASP methodology, curated payload references, 6-gate validation, and professional report generation
-
gitbutlerapp Bundle Gitbutler Docs WriterWrite, edit, review, and audit GitButler documentation with reader-first structure, Diataxis page intent, GitHub-style task focus, Django-style doc taxonomy, and Stripe-style concrete examples. Use when working on `content/docs`, docs MDX/Markdown, command docs, troubleshooting docs, tutorials, explanations, or docs IA for the GitButler docs repo.
-
gitdolucas Bundle PagbankPagBank/PagSeguro integration guide for REST APIs, OAuth Connect, checkout (redirect and transparent), split payments, webhooks, mTLS transfers, PCI client-side encryption, SmartPOS/PlugPag, EDI reconciliation, homologation, production readiness, sandbox testing, fraud controls, and cybersecurity (PCI-DSS, webhook SHA256 authenticity, credential and certificate lifecycle). Use when building, modifying, or reviewing PagBank integrations, PagSeguro checkouts, PIX/Boleto/card payments, marketplace splits, subscriptions, payment terminals, security reviews, go-live checklists, or Brazilian payment compliance. Always use this skill when code may touch real payments, card data, seller authorization, transfers, webhooks, reconciliation, or PagBank production credentials.
-
gitpod-io Bundle Cve MitigationScan, triage, and remediate CVEs in the Gitpod monorepo. Use when asked to fix vulnerabilities, update dependencies for security, respond to CVE scan failures, or validate that dependency updates resolve known CVEs. Triggers on "fix CVE", "vulnerability scan", "security update", "dependency CVE", "grype scan", "leeway sbom", "CVE remediation", "update vulnerable dependency", "daily scan failure", "critical vulnerability".
-
giudegio-ai Skill HumanizerRewrites AI-generated text to remove robotic patterns and make it sound genuinely human, or detects AI-slop patterns without rewriting. ALWAYS activate this skill when the user types /humanizer followed by any text. Handles both Italian and English content. Produces a before/after comparison with annotations explaining what was changed and why, or a pattern-by-pattern detection report when asked to audit rather than rewrite.
-
glasshaven Skill MaintainOne bounded pass of proactive Haven maintenance — CI health, issues & discussions triage, community & Dependabot PRs, security advisories, F-Droid watch, release readiness & artifact verification. Designed to run under /loop with dynamic pacing.
-
gnipbao Bundle Dan Koe Life ResetGuides a user through a Dan Koe inspired one-day life reset protocol: uncover hidden motives, infer real goals from behavior, build anti-vision and vision, interrupt autopilot during the day, synthesize identity-level insight, and convert it into a one-year mission, one-month project, daily levers, constraints, and next-day timeblocks. Use when the user asks for 人生重启, one-day reset, life audit, anti-vision, identity change, stuck-pattern diagnosis, or turning life into a game.
-
grandamenium Bundle Gws Meta WorkflowsSix production-ready meta-workflows that chain Google Workspace CLI (gws) commands into complex automations - inbox triage, meeting prep, client onboarding, weekly digests, email security scanning, and scheduling conflict resolution. Use when the user wants to automate multi-step Google Workspace workflows, chain gws commands together, or build higher-level productivity automations on top of the GWS CLI.
-
mrgediao Bundle Paper Reading Zh中文论文精读工作流。Use when the user provides a paper anchor such as a PDF, arXiv/OpenReview/ACM/IEEE/venue page link, paper title, abstract/full text, figure or table screenshot, or a list of papers — either with a deep-reading request (deep reading, explanation, summary/TL;DR, seminar/blog-style walkthrough, implementation/reproduction feasibility analysis, engineering integration analysis, literature survey, comparison, figure-by-figure reading, formula explanation, experiment analysis, evidence audit), or with no stated request yet (clarify once between deep reading, engineering breakdown, and comparison). Also use when the user expresses a deep-reading intent but has not named the paper (ask once which paper). Do not use for plain translation, single-term definitions, BibTeX only, or merely finding/downloading a paper.
-
mun1to Skill Audit This ProjectRun an independent security audit of this repository before trusting it. Use when the user asks whether this project is safe, what it sends over the network, what it does to their computer, whether it is malware or spyware, or asks for a security review of this codebase.
-
nick2bad4u Bundle Github Manage Security AlertsManage GitHub security alerts. Use when the user asks to inspect, triage, summarize, export, or safely update code scanning, Dependabot, malware, or secret scanning findings.
-
nyce-arrowprod Bundle Linkedin Founder OsFounder-led, multi-lane LinkedIn presence plus resume work: profile, content, voice, networking, weekly execution, and ATS-safe resumes. Use whenever the user wants to fix their LinkedIn profile, plan content, ghostwrite a post, check if a draft sounds like them, find networking targets, or build a personal brand spanning more than one professional lane. Trigger on: fix my LinkedIn, write a LinkedIn post, does this sound like me, what should I post this week, my LinkedIn is a mess, help with my personal brand, review my profile, ghostwrite this, who should I connect with, LinkedIn strategy, thought leadership, founder storytelling, audit my resume, will this pass ATS, rate my resume against this job, fix my resume, rewrite my bullets, tailor my resume. On first use this skill has no identity loaded and MUST run Phase 0 Setup first.
-
piyushsolanki038 Bundle Security Code ReviewAudit any codebase for the OWASP Top-10-style vulnerability classes (SQLi, XSS, IDOR, broken auth, CSRF, XXE, SSRF, file upload, misconfig, data exposure, insecure deserialization, command injection, path traversal) by reading the actual code, and propose/apply fixes. Detection-only — never generates attack payloads or exploit code.
-
pustelto Bundle Code ReviewUse for a thorough, impact-aware code review of the current branch (or an MR). Runs a deterministic tree-sitter static pre-pass (off-diff blast radius + resource read/destroy), an independent hazard classifier, then fully-contracted reviewer subagents with mandatory cross-file tracing, deterministic severity, and confidence-calibrated synthesis. Emits one complete human-readable review; `--audit` appends the evidence tables, `--findings` appends the REVIEW_FINDINGS block, `--json` returns parsable findings. Triggers on "review my code", "code review", "review this branch", "/code-review".
-
ian-tseng Bundle Audit Venue SubmissionAudit scholarly manuscripts and submission packages against current venue requirements, cross-section claim chains, and a canonical terminology contract. Use when checking venue format, anonymity, page or word limits, templates, declarations, author metadata, portal upload roles, DOCX/PDF/TeX output, supplements, claim continuity from research question through protocol, result, counterevidence, and boundary, cross-artifact consistency, run-aware word/paragraph alignment, terminology across prose, headings, figures, captions, tables, metadata, and generated artifacts, submission readiness, desk-rejection remediation, or venue adaptation.
-
junbaoliang Bundle Audit With PlansAudit and repair planning-with-files projects by comparing code with `.planning/*/{task_plan,findings,progress}.md` in both directions, executing documented entry points, and repeating independent cold-start reviews until a fresh pass reports 0/0/0/0. Use for project audits, code reviews, plan-versus-implementation checks, or consistency checks when a `.planning` baseline exists.
-
kamel94 Bundle Code ReviewReview pull requests, merge requests, commits, patches, diffs, and proposed code changes with a rigorous, low-noise methodology focused on correctness, functional intent, regressions, security, design, maintainability, and test effectiveness. Use when asked to review code changes or assess whether an implementation is safe and correct.
-
fuhaoda Bundle Stat WritingEnd-to-end statistical writing assistant for LaTeX - draft title/abstract/keywords, expand outlines into sections, audit manuscripts, write reviewer reports and response letters, and scaffold book manuscripts.
-
fullstackcrew-alpha Bundle Smart Pr ReviewOpinionated AI code reviewer — not a yes-machine. 6-layer deep review (logic, edge cases, performance, security, maintainability, architecture) with Devil's Advocate mode and standardized MUST FIX / SHOULD FIX / SUGGESTION output. Supports GitHub PR URL, local diff, commit hash. Languages: TypeScript/JavaScript, Python, Go, Rust. (中文) 有立场的智能代码审查:6 层审查维度、主动反对机制、标准化输出,支持 5 种语言。
-
gawezepobi09-debug Bundle Security Check🔒 Pre-installation security verification for external code and dependencies. Automated risk analysis for GitHub repos, npm packages, PyPI libraries, and shell scripts. Integrates CVE databases (Snyk, Safety DB) to detect vulnerabilities before you install. Shows risk level (✅ safe / ⚠️ review / ❌ dangerous) with actionable recommendations. First comprehensive security skill for OpenClaw — protect your system before downloading untrusted code.
-
gdavidpb Bundle SystemicSystemic analysis of software based on General Systems Theory (GST): models a solution as systems (elements, operators, conceptual state machines) and verifies their consistency — closure, reachability, transition completeness, invariants, operator ambiguity, idempotency, symmetry, minimal expression and system limits — producing a local Markdown findings report with evidence, severity and recommendations. Use it whenever the user asks for a systemic analysis, wants to review the consistency of states or a state machine, find inconsistencies or contradictions in a design, flow or operation, audit a lifecycle (workflow, saga, state machine), apply systems thinking or GST/TGS, or asks "is my design consistent?" — even if they never say the word "systemic". Works on code, design documents, or both.
-
gendigitalinc Skill Security AwarenessSecurity best practices for safe command execution, URL handling, credential management, and supply chain safety. Guidance on avoiding common attack vectors like reverse shells, command injection, and malware distribution.
-
getdex Bundle Dex SkillManage your Dex personal CRM — search, filter, create, archive, and update contacts; log notes; manage follow-ups, tags, groups, and custom fields; search connected email; and read or manage connected calendars. Use this skill to: (1) Find, add, or update contacts, (2) Log meetings and notes, (3) Manage reminders and keep-in-touch cadence, (4) Organize tags, groups, and custom fields, (5) Merge or archive contacts, (6) Review relationships or prepare meetings, (7) Search correspondence, (8) Manage calendar events, (9) Categorize, audit, or clean a network, (10) Turn notetaker output or transcripts into notes and follow-ups, (11) Prepare multiple meetings or event follow-up, (12) Research a contact on the public web, (13) See what is coming up — upcoming birthdays, due reminders, and who to reach out to, (14) Authenticate via /dex-login, or handle another personal CRM task involving the user's professional network.
-
gexijin Skill R Pre Push ReviewReviews all staged/unstaged R code changes in a GitHub repo before the user pushes to a branch. Use this skill whenever the user wants to review their code changes before pushing, asks if their code is "ready to push", wants a pre-push check, or says things like "review my changes", "check my code before I push", "is my R code good to go", or "pre-push review". Works both automatically (via git diff in bash) and manually (user pastes a diff). Focuses on bugs & logic errors, security vulnerabilities, performance issues, and test coverage in R code.
-
thanane15m Bundle Postgres FirstEvaluates whether PostgreSQL can satisfy database, cache, queue, search, vector, background-job, pub/sub, rate-limit, audit, or multi-tenant requirements before adding another data service. Use when designing or simplifying backend architecture, reviewing Redis/MongoDB/Elasticsearch/vector-store usage, or planning a migration toward PostgreSQL-native patterns.
-
the-biomechanist Bundle Wolfram Language EngineerUse this skill when users ask to design, implement, debug, refactor, optimize, document, or audit Wolfram Language (Mathematica) code, notebooks, packages, or paclets. Covers symbolic programming patterns, evaluation semantics, numeric workflows, testing, and code-quality review.
-
topsyturvy-cheapskate696 Bundle Security AuditEnterprise-grade security audit — performs SAST, secrets detection, dependency auditing, IaC review, auth analysis, and auto-remediation across any codebase.
-
toyworks Bundle T3 Hardware ScoringClassify a hardware product as Tool, Toy, or Trash using the MantaBase T3 audit: Brand Blinding, three independent auditors scoring fixed rubrics from verbatim evidence, an Eagle Eye validation pass, and a Final Judge that applies a safety veto. Use when the user shares a product link, gadget, or crowdfunding page and asks whether it is worth it, whether it is any good, whether the claims hold up, or asks for a T3 audit, hardware evaluation, or product scoring.
-
vasileiosmalt Bundle Fallacy DetectorDetect, analyze, and explain logical fallacies in any text. Use this skill whenever the user asks to analyze arguments, check reasoning, fact-check logical structure, review debate transcripts, evaluate essays, audit social media posts, or do any kind of critical thinking analysis. Trigger even for casual phrasings like "is this argument good?", "does this make sense logically?", "what's wrong with this reasoning?", "roast this argument", or "is this person right?". Handles single sentences, multi-paragraph essays, debate transcripts, and batch analysis of multiple arguments at once. Always outputs structured results (JSON or Markdown report). Biased toward intellectual rigor and political neutrality — never over-flags nuanced or complex valid arguments.
-
versoxbt Skill Skill AuditingActivates when the user wants to see their installed skills, mentions "skill manager", "check my skills", "skill audit", "what skills do I have", "skill updates", "newer version", "outdated plugins", or wants to know what's installed and where it comes from.
-
viprasol-tech Bundle Code ReviewRigorous, prioritized code review of a diff, PR, or file — correctness bugs first, then security (OWASP/CWE), performance, API design, tests, and maintainability. Outputs severity-rated findings with specific fixes, not nitpicks. Use to review a pull request, audit a change, or pre-merge check.
-
viprasol-tech Bundle Defi Protocol ReviewDue-diligence review of a DeFi protocol — admin-key & upgradeability risk, audit status, yield sustainability, liquidity/TVL quality, oracle dependency, and team transparency. Outputs a risk matrix and verdict. Use to vet a protocol before depositing, or to assess rug & exploit risk.
-
viprasol-tech Bundle Risk Management ReviewReview a portfolio, trading strategy, or single-position risk — volatility, drawdown, VaR/CVaR (ES), Sharpe/Sortino/Calmar/UPI, Kelly & volatility-targeted sizing, concentration & leverage caps, and stress tests. Outputs a verdict, risk dashboard, sizing review, stress-test table, and concrete recommendations. Use to vet a trade size, audit a portfolio, or institutionalize a risk policy.
-
viprasol-tech Bundle Smart Contract AuditAudit Solidity/EVM smart contracts for security vulnerabilities — reentrancy, access control, oracle manipulation, and more. Grounded in the SWC Registry and real DeFi exploit patterns. Outputs severity-rated findings with exploit scenarios and fixes. Use for smart-contract security review, DeFi audits, or pre-deployment checks.
-
viprasol-tech Bundle Trading Strategy ReviewReview trading strategies and backtests for the failure modes that blow up live — look-ahead bias, overfitting, survivorship bias, unrealistic fills, and risk-of-ruin. Grounded in backtest-overfitting research (PBO, Deflated Sharpe). Outputs severity-rated findings with fixes. Use to vet a strategy, audit a backtest, or pre-deployment risk-check.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include audit, claude-pentest-skills, gitbutler-docs-writer. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.