Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
gtrusler Bundle SecurityAdvanced security validation for Clawdbot - pattern detection, command sanitization, and threat monitoring
-
gtskevin Bundle Test AuditAutonomous test auditor. After code is written, analyzes changes, decides what tests are needed, writes and runs them, then reports a verdict with a coverage map and what remains untested. No user input required. Use when finishing a feature, after code generation, before committing, or when the user says "check tests", "add tests", "test audit", "test check".
-
guhou-hvi Bundle Elsevier Figure StyleGenerate, revise, and audit source-backed quantitative manuscript figures, and visually audit exported schematic/conceptual figures and graphical abstracts without redrawing them in v0.1. Use for Elsevier-style manuscript figure generation, matplotlib or ggplot2 result plots, line charts, heatmaps, bar charts, scatter or Pareto plots, artwork export checks, pre-submission figure QA, mechanism/workflow diagram audits, graphical-abstract audits, or equivalent Chinese-language requests for paper figures and submission checks.
-
gurpriya Skill Blog Validator Enhancer ExampleValidates and enhances blog posts about cybersecurity and AI. Use this skill whenever the user shares a draft blog post, article, or write-up and wants it reviewed, improved, or polished — even if they just say "check this", "review my post", "make this better", or "does this look good". Also trigger when the user pastes any long-form technical content about security topics (CVEs, exploits, threat modeling, AI/ML techniques, tools) and asks for feedback. Handles all input formats: markdown, plain text, or pasted content. Always use this skill before giving feedback on any technical blog content the user shares.
-
h5i-dev Bundle H5iBrowse or automate web pages, perform authorized web security testing on captured HTTP traffic, or run untrusted development work inside disposable confined boxes with auditable evidence and reviewed export.
-
haaaiawd Bundle Disk Space AuditScan and analyze disk space usage on Windows and macOS (with Linux references), then produce a categorized cleanup report — and, only when the user explicitly asks, execute cleanup with per-item confirmation. Use this skill whenever the user asks to "scan C drive", "analyze disk space", "find what's eating my storage", "clean up system drive", "磁盘空间分析", "清理 C 盘", "扫描磁盘占用", "找重复文件", "find duplicates", or wants a breakdown of where disk space went. Also trigger when user mentions disk full, low space warnings, or wants to know what can be safely deleted. The audit phase is always read-only. The cleanup phase requires explicit, per-item user confirmation and never proceeds on ambiguous intent.
-
hainrixz Bundle HumanizaloDetects and eliminates 40 AI writing tells across vocabulary, structure, formatting, content inflation, and communication artifacts. Includes personality injection, 6-dimension scoring, and a self-audit loop. Use when editing or reviewing any text to make it sound unmistakably human.
-
haiyichen001 Skill Reference WorkbenchAcademic citation toolkit — verify reference authenticity or write literature reviews with auto-generated bibliographies. Checks paper existence, metadata accuracy, and whether cited claims are actually supported. Supports PDF, DOCX, TXT, Markdown, LaTeX. Use when user asks to: "check citations", "verify references", "audit citations", "validate my references", "are these citations real", "write introduction", "write literature review", "review my lit review", "generate bibliography", "format references", "check my paper's citations", "citation audit", "fact-check references", "proofread citations", "verify my bibliography", "帮我查引用", "检查论文引用", "写文献综述", "验证参考文献", "引用查证". Merges former citation-check and introduction-review skills.
Audited -
hamedghaderi Bundle Pr NarrativeTwo-mode PR skill. **Author mode** writes pull-request descriptions that read like an explainer, not a code dump. Use it when the user asks to write, draft, generate, or improve a PR description / PR body / PR write-up, or says "write the PR", "make a PR description for this branch", "describe these changes for review". **Reviewer mode** renders any PR's diff as an annotatable page: click-to-comment on lines, optional AI-drafted risk callouts you triage, and posts accepted comments as a PENDING GitHub review the user finalizes. Use it when the user says "review this PR <url>", "review PR #N", "annotate this PR", or "review my branch/changes". Confirm the mode with one question first unless the user already named it. Also supports subcommands: "explain" (explains a diff in chat), "review-security" (reviewer mode, security-only AI findings), "summarize-changes" (quick chat summary); an explicit subcommand skips the mode question. Do NOT use for code review scoring, commit messages, or release notes.
-
handsomezr-netizen Bundle Social Science PaperworkEnd-to-end social science and humanities manuscript workflow for research design, literature reviews, questionnaires, interviews, qualitative coding, survey analysis, APA/GB/T citation checks, ethics statements, journal/user-style adaptation, submission audits, and premium classroom/demo draft manuscripts with LaTeX/PDF output. Use when Codex helps plan, draft, audit, or analyze social science, humanities, education, communication, management, design research, cultural studies, or mixed-methods papers, especially involving surveys, interviews, focus groups, case studies, thematic analysis, grounded theory, scales, reliability, validity, human-subject data, target-journal style, advisor/lab writing preferences, non-submission demo papers, classroom presentations, advisor reports, senior-student or research-group presentations, simulated findings, draft-demo manuscripts, one-click complete papers, polished LaTeX, or "perfect paper" demo drafts.
-
hasinhayder Bundle Tyro LoginLaravel authentication infrastructure package providing guards, providers, sessions, tokens, verification, and security for the Tyro ecosystem.
-
ehmo Bundle Golang Binary Size ReductionReduce Go binary size safely across CLIs, daemons, libraries, plugins, Wasm targets, and packaged apps. Use when asked to shrink, strip, slim, optimize, or audit Go build artifacts, linker flags, build tags, CGO usage, embedded assets, or post-build packing.
-
ehmo Bundle Rust Binary Size ReductionReduce Rust binary size safely across CLIs, servers, libraries, WASM targets, and embedded systems. Use when asked to shrink, strip, slim, optimize, or audit Rust build artifacts, Cargo profiles, dependency trees, monomorphization, or post-build packing.
-
enderphan94 Bundle Web ScannerClient-side web security scanner — runs automatically with no setup required
-
enigmatry Skill Baseline Security AuditEnsures baseline security practices are followed in the project. Use this when asked to perform a security audit on the codebase. Can create Jira stories for selected security findings.
-
enilmalus Bundle Enil Ling Pesing渗透测试 / 安全研究 / 漏洞发现全流程 skill。覆盖 授权确认 → 被动侦察 → 主动枚举 → 漏洞探测 → 受限利用 → 报告 六阶段方法论;内置按漏洞类(SQLi/XSS/SSRF/IDOR/RCE 等)与资产类型的路由表、WAF/EDR 绕过决策、证据纪律与合规红线。当用户提到渗透测试、红队、SRC 挖洞、众测 / bug bounty、安全研究、漏洞复现 / 披露,或直接给出目标域名 / IP / API / APP 要求测试时使用。
-
enmr10 Bundle Token DoctorAudits and reduces token usage in context files (CLAUDE.md, AGENTS.md, memory files, docs). Measures token cost per file, finds waste (filler words, verbose phrases, blank bloat, oversized blocks), and safely compresses prose while preserving all code, inline code, URLs, file paths and tables. Use when your context files feel bloated, prompts are expensive, or you want to trim CLAUDE.md without losing meaning. Trigger: "reduce tokens", "token usage", "trim my CLAUDE.md", "compress context", "shrink memory file", "context too big", "save tokens", "audit token cost", /token-doctor. For skill description collisions, see skill-doctor.
-
erdalacundakonuk Bundle Repo GlowupAudits a GitHub (or GitLab) repository's first impression — README structure, badges, demo screenshot/GIF, one-liner install, description, topics, LICENSE, CONTRIBUTING — scores it against the factors that actually drive stars and adoption, then rewrites the README and drafts launch copy for Show HN, Reddit, and X/Twitter. Use this skill whenever the user wants to publish or open-source a project, get more GitHub stars, prepare a repo for launch, improve or rewrite a README, get feedback on a repo link they share, write a "Show HN" / Product Hunt / launch post, or asks something like "why isn't anyone starring my repo" or "how do I make my project look more professional" — even if they never say the words "audit" or "optimize."
-
eriemon Bundle Github ManagementUse when Codex needs to manage GitHub repositories with gh CLI or GitHub APIs, including issues, pull requests, review comments, GitHub Actions CI, releases, labels, milestones, branch protection, repository hygiene, security audit, dependency alerts, or repo governance tasks.
-
johnsmithca-sta Bundle Privacy Audit个人信息脱敏审查技能。当用户要求对技能、代码库、数据目录做发布前个人信息脱敏审查、隐私合规检查、敏感信息扫描、PII 检测、脱敏整改、发布前安全自查(脱敏审查 / 隐私审查 / 合规审查 / 敏感信息扫描 / 敏感字段检测 / 数据泄露排查 / PII scan / desensitization audit / privacy audit / 发布前审查 / 安全检查)时使用。仅做审查、分级与整改建议并产出报告,不做脱敏执行、不用于法律意见出具;高敏感场景建议人工复核。
-
josuecasanave Bundle Audit ProjectRead-only audit of an in-progress software project in any stack, reported in English or Spanish (asked up front, same analysis either way).
-
jovd83 Bundle Context Density OptimizerAudit the active working context and remove token noise before deeper implementation, review, or planning work. Use when Codex has accumulated too many files, notes, logs, prior summaries, or reference documents and needs to decide what to keep, drop, condense, or defer. Especially useful after broad codebase sweeps, large documentation reads, debug-log dumps, multi-skill handoffs, or whenever context relevance, signal density, or token efficiency has become uncertain.
-
jovd83 Bundle Principal Audit RefactorAudit a local software project, produce a severity-ranked engineering review, and execute an approval-gated refactor plan. Use when Codex needs to assess prototype-quality or inconsistent codebases, run stack-aware checks, write timestamped audit artifacts, and then implement production-grade improvements with explicit safety boundaries, report contracts, and refactoring discipline.
-
jovd83 Bundle Slide Deck PreparationConvert source material into grounded, presentation-ready slide deck outlines. Use when Codex needs to plan, audit, restructure, or enrich a presentation from URLs, articles, papers, transcripts, notes, documents, or an existing deck outline, with explicit audience framing, narrative arc, slide archetypes, speaker notes, visual guidance, and source citations.
-
jovd83 Bundle Tss Test Case ReviewerUse when the user wants to review, audit, critique, score, or mentor drafted software test cases, manual scenarios, UAT cases, or test suites for requirement traceability, coverage gaps, technical correctness, standards compliance, weak expected results, or TSS or TDD-style test design quality before execution, automation, or sign-off.
-
joylarkin Bundle Openclaw Security NewsSkill: openclaw_security_news
-
evomap Bundle Skill2gepGeneric skill distillation tool. Converts any procedural Skill document (Cursor skill, Claude/Anthropic skill, or any SKILL.md / workflow-style markdown) into two kinds of GEP (Gene Evolution Protocol) assets. Gene = compact strategy template (signals + strategy + AVOID + validation). Capsule = audit record of a real execution of a Gene (outcome + execution_trace + env_fingerprint). Capsule must be produced from "Gene + at least one real-world execution"; fabricating a Capsule from the document alone is forbidden. Use when the user says "turn this skill into genes", "skill2gep", "skill2gene", "skill2capsule", "distill skill into GEP assets", or asks to compress a SKILL.md / procedural document into GEP control signals.
-
explosivecoderflome Bundle Produce Long Form NovelProduce, maintain, analyze, and export long-form Chinese novels through staged, editable artifacts, with progressive confirmation of high-impact creative settings for novice authors. Use when Codex needs to turn an idea into a novel plan, guide choices such as audience channel or genre, analyze public ranking metadata for hot genres, deconstruct an authorized reference novel or diagnose a manuscript, design or revise volumes, generate chapter plans or prose, continue an existing novel, audit and repair chapters, export ready chapters as a TXT file, or decide the next production step from an existing Markdown/YAML workspace. Do not use for generic app development, database operations, unauthorized bulk copying, or unrelated short-form copywriting.
-
expo Bundle Setup Code ReviewInstall and configure @expo/code-review-cli (ecr) in any repo — detect monorepo shape, mine GitHub history for review hotspots and past security issues, research best practices per technology, then generate the full .expo-code-review/ setup (config, agents, coordinator, shared, routing) via a large dynamic workflow. Use when the user wants to set up, install, or reconfigure AI code review in a repository.
2.2k -
ez-lbz Bundle Code Security ReviewScans source code for security vulnerabilities — injection flaws, authentication bypasses, hardcoded secrets, XSS, and more — then filters false positives and ranks findings by severity and confidence. Supports all programming languages. Uses a three-phase audit-filter-report workflow with customizable scan categories and filtering rules. Use when the user asks for a security review, vulnerability scan, security audit, code security check, or wants to find security bugs in their code.
-
ezefranca Bundle Sg Flw ClassifierClassify papers, PDFs, abstracts, datasets, intervention descriptions, or study protocols using the SG-FLW measurement framework for serious games and food waste, serious games for food waste reduction, games, gamification, and interactive interventions addressing food loss and waste. Use when Codex needs to assign B/K/D/E/L scores, explain evidence-chain certainty, review whether a sustainability game supports food-waste-reduction claims, audit AI over-crediting errors, or plan evaluation methods, telemetry, and evidence boundaries for a food-waste serious game.
-
f Bundle Create AuditCreate a new audit module for the check-ai scanner. Use this skill when the user wants to add a new audit section that checks for specific files, directories, or patterns in a repository. The skill generates a properly structured .mjs file in src/audits/ that is automatically loaded by the scanner.
-
fedius01 Bundle Cve TriageTriage a single vulnerability — CVE, GHSA, or OSV/PYSEC id — against the current Python repository (Poetry or uv) using Risk-Based Vulnerability Management. Use when a teammate asks to "triage CVE-YYYY-NNNN", "triage GHSA-xxxx-xxxx-xxxx", "is this CVE exploitable here", "should we fix it", "pip-audit flagged it", "SSVC this CVE", "write a VEX for PYSEC-YYYY-NN", or "give me a CycloneDX VEX for Dependency-Track". Reads whichever of poetry.lock or uv.lock the repo has. Takes the id first, an optional output format (cyclonedx | openvex | both) second. Gathers CVSS, EPSS, KEV, reachability and exposure evidence, produces an SSVC Deployer decision (Immediate / Out-of-cycle / Scheduled / Defer), and writes to security/triage/<vuln-id>/ a CycloneDX VEX naming every known CVE/GHSA/OSV id — so Dependency-Track matches whichever id the finding was filed under — plus a human-readable decision record. Not for explaining CVEs in the abstract, running scans, or triaging batches of CVEs.
-
bodadotsh Skill NPM SecurityPrevent JavaScript/TypeScript projects from supply-chain attacks across package managers like npm, pnpm, yarn, bun, and deno. Use whenever planning, installing, updating packages or configuring package managers
-
bomkino Bundle Pitchdog WritingWrite, rewrite, distil, voice-match, or audit writing when the user asks for pitch.dog or bomkino voice, says "write like us", "our voice", "written by us", or explicitly invokes this skill. Bring clarity, warmth, exactness, and earned wit to the requested medium while preserving the brief and a client or creator's own authorship. Do not apply studio voice to unrelated writing.
-
jiankang1991 Bundle Nsfc Benzi AuditUse when a user wants applicant-facing diagnosis and revision advice on a Chinese NSFC (国自然) application draft — asks for 本子把脉, 本子体检, 国自然申请书修改建议, NSFC benzi audit, 帮我看国自然本子, 标书逻辑诊断, 青年/面上/地区基金申请书修改, 对照已中本子, 从中标样本提炼写法规律, 选题撞题核查, or 申请代码选得对不对 — or wants critique of the title, abstract, key scientific questions, rationale, research contents, innovation, feasibility, research basis, 代表作/代表性论著 quality and support, or cross-section consistency. Accepts PDF/DOCX/Markdown/text or extracted draft text. This is applicant revision advice, not formal communication-review opinions; for expert review forms use nsfc-review.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include setup-code-review, security, test-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.