Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
viprasol-tech Bundle Wallet Security ReviewReview a crypto wallet signature request, token approval, or wallet's exposure for drainer & phishing risk — unlimited approvals, Permit/Permit2, setApprovalForAll, eth_sign blind signing, and EIP-7702 delegations. Outputs a sign/don't-sign verdict and remediation. Use before signing anything, or to audit a wallet's approvals.
-
yash-kavaiya Bundle Google Appsheet ProductionUse when designing, building, modifying, securing, automating, integrating, testing, deploying, reviewing, or troubleshooting a Google AppSheet application. Produces a source-grounded implementation pack or makes verified editor changes, with data modeling, expressions, security filters, automation, performance, release, rollback, and operations gates based on live official AppSheet Help.
-
yorketang1993 Skill Health CheckAudit Markdown project notes for staleness — find projects marked active that stopped moving weeks ago. Run it weekly, or whenever asked how the portfolio is doing.
-
databrickslabs Skill Ip Acl MigrationMigrate a Databricks workspace's existing IP access list (ACL) into a context-based ingress (CBI) account network policy, as-is, using the dbx-migrate-ip-acls CLI. Use when the user wants to convert / migrate an existing IP access list to a network policy, recreate their IP ACL as CBI, or stand up a network policy from the current ACL without audit-log analysis. Runs `dbx-migrate-ip-acls`, which reads this workspace's ACL (ALLOW->allow rules, BLOCK->deny rules) and recreates it verbatim — nothing added — then creates the account network policy (enforce or dry-run) and optionally auto-assigns it to the current workspace.
-
dave817 Bundle Case VerificationFail-closed verification of legal case citations against CourtListener. Detects fabricated cases, wrong pincites, and fabricated or misquoted language in briefs, motions, memos, and opinions. Use this skill whenever the user asks to verify citations, check quotes, catch AI hallucinations in legal writing, audit a brief or motion before filing, find errors in opposing counsel's filings, or review any legal document with case citations — even if they don't use the word "verify" (phrases like "check the cites in this motion", "find hallucinations", "is this quote real", "did they make this up", "review opposing counsel's brief", or "is this case real" all apply). US federal and state courts only.
-
dbhq-uk Bundle DovetailCheck whether a repository agrees with itself, then work through the findings one at a time. Finds broken links, dangling heading anchors, orphaned files, duplicate content, translations that have fallen behind, drift between docs and code, contradictions between documents, and conventions the repo states but does not follow. Trigger on phrases like "dovetail", "check this repo", "does this repo agree with itself", "find contradictions", "repo coherence", "docs drift", "audit this repository".
-
he8um Bundle Github Skillsprofessional github repository architecture, governance, automation, security, and troubleshooting for ai agents. use when a user asks to create, scaffold, audit, refactor, document, secure, automate, release, or maintain a github repository; design repository structure, community health files, issue forms, pull request workflows, labels, projects, rulesets, code owners, github actions, releases, dependency automation, security controls, github cli/api plans, migration steps, and machine-readable repository blueprints.
-
hedimanai-pro Bundle GuardsmanCalibrated, verified, convention-consistent engineering judgment for coding tasks. Reads the codebase's conventions and the change's real risk before writing code, verifies the check it leaves behind before letting anything pass, and tracks deliberate shortcuts in a logbook instead of a stray comment that rots. Five modes: build (default, persistent), review (diff), audit (repo-wide), logbook (harvest shortcuts), post-report (real per-repo status, no invented numbers). Use on ANY coding task: writing, adding, refactoring, fixing, reviewing, or auditing code, and choosing libraries or dependencies. Also use when the user says "guardsman", "stand the post", "challenge this diff", "right-size this", "logbook", "post report", "verify before you ship", "is this over-engineered", "what can we delete", or complains about bloat, boilerplate, unnecessary dependencies, or code that does not match the codebase. Do NOT use for non-coding requests (general knowledge, prose, translation, summaries, recipes).
-
hermeticormus Skill Code ReviewDomain-aware code review for an everyday diff or pull request. Classify the code's domain (algorithm, API, security, data, UI, infrastructure), then review for the failure modes that domain actually has. Use when reviewing a change. For production-readiness use mars-skills; for security hardening use vibe-proof-skills.
Audited -
hermeticormus Skill Dx AuditAudit and improve developer experience in a codebase by inspecting README, quickstart, scripts, contributing guide, env docs, error messages, and tooling, scoring onboarding friction, and reporting findings or implementing fixes. Use when a new contributor hits friction, when setup is undocumented, or when the README has not been run on a clean checkout since the stack changed.
Audited -
hexters Skill Security AuditComprehensive security audit for Laravel/PHP projects. Scans for malware, webshells, vulnerable packages, crypto miners, misconfigurations, and applies hardening. Built from real-world incident response experience.
-
hey-stefan Bundle Portfolio AuditAudit a design portfolio website against what top design leaders actually look for when hiring. Use with /portfolio-audit <url>.
-
hmans Skill Shader ReviewThis skill should be used when the user asks to "review shaders", "audit shaders", "check shader quality", "optimize shaders", "review GLSL", "shader best practices", or wants a thorough analysis of the engine's or game's shader code against state-of-the-art real-time rendering practices.
-
hook0 Bundle Security AdvisoryStandard process for turning a confirmed Hook0 vulnerability into a published security advisory and, where warranted, a CVE. Use whenever a security report is confirmed and a fix is being prepared or has shipped, or when the team asks to "publish an advisory", "request a CVE", "assign a CVE", "credit a researcher", or "handle a security disclosure". Covers the CVE decision, the GitHub Security Advisory draft, timing, doc updates, and crediting the reporter.
-
ifylab Bundle SkillmeldDiscovers existing community skills for a described use case and merges the best two or three into one coherent, deduplicated, security-scanned skill set tailored to the user's project. Use when someone wants to assemble or compose skills for a workflow, combine existing skills instead of writing one from scratch, or build a tailored skillset from community sources. Grounds in the user's repo, scans every candidate before use, and shows provenance plus a review before installing.
Audited -
igarbayo Bundle Open SourceGenerates the complete open-source governance of a repository: README, LICENSE, REUSE.toml and SPDX headers, CONTRIBUTING, SECURITY, CODE_OF_CONDUCT, GOVERNANCE, CHANGELOG, .github issue/PR templates, GitHub Actions, Dependabot, conventional commits, GPG/DCO signing, git flow and ADRs. Use whenever the user wants to open-source, publish, license or release a project, add community health files or governance docs to a repo (including hackathon projects), or mentions OSI licenses, REUSE/SPDX, FSF best practices or EU CRA.
-
igorvaryvoda Bundle Improve CodexAudit a codebase with improve, scrutinise plans with Sol, execute them through repo-local Symphony and Clanker Army when available or isolated Codex worktrees otherwise, then run final adversarial review. Use when the user wants audit-and-implement in one flow, asks to run improve then Codex, or asks to implement existing plans with Codex.
-
bassimeledath Bundle Beautiful SlidesProduce editable, visually disciplined PowerPoint decks (.pptx) from a brief. Use whenever a task mentions a deck, slides, a presentation, a .pptx file, or asks you to build/edit/inspect a slide deck. Uses python-pptx for fine control, LibreOffice for round-trip rendering, and enforces explicit mood→mode selection, a canvas-bounds check, and a must-include self-audit before declaring the deck done.
-
belschak Bundle Publish GateMandatory security, legal, and quality gate BEFORE anything goes public. Always run when a GitHub repository is about to be created, made public, or pushed; when something is submitted to a package registry or marketplace (npm, PyPI, a skills directory); when a blog post, gist, or artifact containing code or config is published; or when the user says "make it public", "publish", "push the repo", "launch", "release", "go live". Also trigger when publishing is only a sub-step of a larger task, when it seems urgent, or when someone claims "it was already checked". Nothing is published without a complete gate run and an explicit human go.
-
bethamil Bundle Drupal UpdateAutomate Drupal module updates in DDEV environments with safety snapshots, composer update, drush updb, config export, and changelog generation. Handles security updates, patch versions, minor versions, and major version upgrades with compatibility checking. Use when updating Drupal modules, checking for module updates, running composer update, upgrading dependencies, checking outdated packages, or when user mentions DDEV, drush, composer outdated, or module security updates.
-
blackboardsh Skill Review PrReview a GitHub pull request from its link, read the PR description, inspect the code locally only when useful, and judge whether the change is safe to run from a security and runtime-safety perspective. Use only after the user pastes a PR URL. Handle one PR at a time, make a clear merge/close/supersede recommendation, and keep all GitHub review and merge actions with the user.
-
jakozloski Bundle AutonomyFull autonomous issue or PR workflow: resolve repo conventions, plan with edge-case review, validate the plan with GPT-6 Astra, implement, self-review, pass the merge-readiness gate (migrations, cross-PR deps, AC conformance, claims audit), ship, and monitor CI/review feedback until clean or explicitly blocked. Use for 'solve this issue,' 'take over this PR,' 'implement autonomously,' or 'full autonomy.'
Audited -
jameswoolfenden Bundle Pike Safe Policypike++ — AI least-privilege layer on top of pike's deterministic permission scan. Adds Resource ARN scoping and Conditions to escalation-class actions, splits base/escalation into the two-role pattern, and validates the result against pike's own audit rules until clean.
-
jasonnamii Bundle Up DoctorUP(User Preferences) 전수 진단 엔진. 4축 합체 — 메타 진단(UP가 UP에 grep)·진화 압력(변천사 수정 빈도)·SPOF(단일 실패점)·적대적 검증(Red Team 우회 시나리오). v100~ 변천사 데이터 기반 불안정 룰 식별·자가위반 grep·우회 경로 카탈로그 산출. 트리거: UP진단, UP닥터, up doctor, UP감사, UP리뷰, UP점검, UP건강, UP검진, 메타진단, 진화압력, SPOF분석, 적대적검증, RedTeam, 룰위반, 자가위반, 우회시나리오, 불안정룰, 변천사분석, UP리스크, 진단해줘, 검진해줘, 점검해줘, 깨봐줘, audit. NOT: 스킬진단(→skill-doctor), UP편집(→up-manager), 스킬최적화(→autoloop), 스킬생성·수정(→skill-builder), 팩트체크(→fact-checker), 리스크 일반(→risk-radar).
-
jatinbansal1998 Bundle ReleaseCut a manual stable release for jenkins-cli-ts: bump package version (unless the user specifies one), tag vX.Y.Z, push to trigger .github/workflows/release.yml, then write GitHub release notes in the project's release-notes style. Also use to audit or correct existing release notes. Use when the user asks to release, ship, cut a version, publish, bump and tag, or runs /release.
-
jau123 Bundle Memory ManagementGuide Claude Code memory and CLAUDE.md management — what to record, how to write, when to update vs create new, and how to organize. Use when user asks to "记一下"、"新增记忆"、"更新记忆"、"沉淀本次经验"、"看看本次有什么值得记的"、"改 schema"、"加新 type"、"改记忆结构"、"review memory"、"audit memory"、"复盘"、"开发完了"、"总结一下" or discusses memory system design / CLAUDE.md 管理 / memory schema / memory hub / 防记忆系统漂移. Also use after feature work / debug / 对抗审查 when new insights worth recording.
-
jawadmjn Bundle Optimise Claude ContextAudit and optimise Claude Code context loading for any repository. Use when you want to reduce token usage, speed up Claude sessions, or check if a repo follows Claude context best practices.
-
jdpolasky Skill BloatbotAudits an AI workspace (instruction files, rules, skills, commands, memory, notes) for bloat, redundancy, dead structure, and token waste. Reports ranked findings and changes nothing without the user's explicit go. Use when the user types /bloatbot or asks for an audit of their setup.
-
jeeinn Bundle PHP Code ReviewComprehensive PHP code review with security analysis, performance optimization, and PSR-12 compliance checking for PHP7/PHP8 projects
-
howshannon Bundle Slop CopAudit, grade, rewrite, and issue funny evidence-backed tickets for generic AI-slop patterns in prose, social posts, UI/design, and code. Use when asked to de-slop writing, humanize AI copy, grade a draft, review a landing page or generated interface, remove vague claims and repetitive rhetoric, inspect AI-written code for generic abstractions and happy-path-only logic, or ticket someone for a specific quality offense. Do not use to determine whether AI authored something.
-
hpcc-systems Skill Code ReviewCode review checklist for the HPCC Platform. Use when reviewing C++ code changes, examining components for issues, or checking best practices. Covers memory management, thread safety, style compliance, security, API compatibility, and correctness.
-
hubeiqiao Bundle Gpt Pro AuditUse when the user asks to audit a plan, document, diff, website finding, or implementation proposal with ChatGPT using Pro reasoning effort through Chrome - starts automatically after invocation, packages codebase/project context ChatGPT cannot see, runs up to 5 review rounds until accepted, verifies Effort Pro and the response, and applies only accepted findings.
-
huntsyea Bundle Human WritingEdit, review, audit, or draft standalone prose while preserving the writer's meaning and voice. Use for documentation, markdown, emails, blog posts, PRDs, and other dedicated writing when the user wants clearer, more direct, more natural, or less AI-patterned language, or asks whether a draft contains AI-slop patterns. Do not use for routine conversational replies or code unless the user asks to edit its prose.
-
hyperb1iss Bundle UniflyThis skill should be used when the user asks to "manage UniFi devices", "configure UniFi networks", "create a VLAN", "provision an SSID", "create firewall rules", "reorder firewall policies", "create a NAT rule", "set up port forwarding", "configure masquerade NAT", "add DNS records", "manage traffic matching lists", "create DHCP reservations", "list DHCP reservations", "block a client", "kick a client", "find a client by IP or name", "adopt a device", "restart a UniFi device", "cycle a PoE port", "upgrade device firmware", "run a speed test", "stream UniFi events", "watch real-time events", "query UniFi stats", "analyze DPI traffic", "enable DPI", "generate hotspot vouchers", "show network topology", "audit firewall policies", "create a backup", "call the raw UniFi API", "check network health", or any task involving UniFi network infrastructure management via the unifly CLI. Also triggers on mentions of unifly, UniFi, Ubiquiti, UDM, UCG, USG, USW, UAP, UXG, UNVR, U6, U7, or UniFi controller operations.
-
hyt315 Bundle Github Oss OpsUse when maintaining an open-source GitHub repository after launch, including Issue triage, AI hallucination defense, reply drafting, PR review assistance, CI diagnosis, private security vulnerability handling (GHSA/PVR), release preparation, multi-channel release broadcasting, community moderation, contributor recognition (All Contributors), sponsorship ops, stale-item review, and approval-gated GitHub writes. Triggers include Issue 管理、分流、triage、PR 审查、回复 Issue、版本号、发版、Release、changelog、漏洞响应、社区治理、致谢贡献者、赞助运营、过期 Issue、stale、运营报告、开源项目运营、oss ops, and project operations.
-
iamravenous Bundle Dependabot Alert ReviewTriage a GitHub Dependabot security vulnerability alert (a .../security/dependabot/<N> URL, "alert
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include wallet-security-review, google-appsheet-production, health-check. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.