Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
ipxe Skill Ipxe Security ReviewSystematic memory-safety review of iPXE's attacker-facing parsers. Use when asked to hunt for vulnerabilities, audit a network-input parser, or review a FILE_SECBOOT(PERMITTED) file that handles DHCP / DNS / TFTP / HTTP / TLS / EAP / PeerDist data or downloaded images, for length, overflow, or underflow defects.
-
isaaccorley Bundle Bib AuditFlag hallucinated references, authors and bib items, and correct badly formatted ones, in any paper — your own draft (run it before submitting) or one you are reviewing — from a .bib file, a PDF, or a pasted reference list. Checks every entry against Crossref (DOI), arXiv (eprint ID), and title search; detects fabricated DOIs/arXiv IDs, hallucinated titles and authors, truncated author lists, wrong years; recovers canonical publisher BibTeX. Also citation-style rules (et al., \cite spacing, shortcite, reference sorting, bib title capitalization). Use to validate/audit/check references, verify citations in a submission under review, fix bib entries, hunt hallucinated or invented citations, extract a bibliography from a PDF, look up a DOI/canonical BibTeX, or gate a pre-submission bibliography.
-
itsncki-design Bundle App Store Submission AuditorScans an iOS app project for App Store rejection risks. Reads source code directly — no back-and-forth. Auto-detects vibe coder vs developer and adapts language. Detects mid-build apps and asks before switching modes. Outputs a risk register, detailed findings with dynamic copy-paste fixes, reviewer experience checklist, draft App Store Connect reviewer notes, and a post-scan manual checklist. TRIGGER THIS SKILL for any of these — even if not explicitly asked: "audit my app" / "is my app ready" / "about to submit" / "submitting soon" / "about to launch" / "ready to ship" / "App Store review" / "keep getting rejected" / "got rejected" / "rejection" / "App Store Connect" / "TestFlight" / "submit for review" / "pre-submission" / "app review" / "first app" / "never submitted before" / "why did Apple reject" / "what do I need to fix" / "is this ready to launch". Also trigger proactively when working on an iOS app and the user seems close to shipping. Flutter/RN stack: load references/flutter-patterns.md. First-tim
-
itwin Bundle Fix Audit VulnerabilitiesIdentify and fix high-severity npm/pnpm security vulnerabilities in the saved-views monorepo. Use when asked to "fix audit vulnerabilities", "run pnpm audit", "update audit", "fix security issues", "address CVEs", or when security advisories need to be resolved. Runs pnpm audit --audit-level high, diagnoses affected packages, applies dependency overrides or upgrades, then verifies fixes with build and tests.
Audited -
iwritec0de Skill Dep GuardThis skill should be used when the user asks to "install a package", "add a dependency", "check for vulnerabilities", "audit dependencies", or mentions "npm install", "pip install", "composer require", "yarn add", "pnpm add", "check vulnerability", "audit dependencies". Provides dependency security and version management by intercepting package installs to enforce latest versions and block vulnerable packages.
Audited -
jackterror Bundle Persuasion Audit EngineReviews persuasive writing across emails, DMs, LinkedIn posts, articles, landing pages, website copy, and high-stakes personal or professional messages. Use when the goal is to improve trust, clarity, response rate, conversion, emotional accuracy, or persuasive strength before rewriting.
-
jaeseongs95 Bundle Independent Audit Gate보안·권한·결제·데이터 손실·스키마 마이그레이션·프로덕션 배포·전역 설정처럼 실패 영향이 큰 변경을 실행하거나 릴리스하기 전후에, 구현자와 분리된 감사자가 최종 변경과 검증 근거를 직접 확인하고 완료 가능 여부를 판정한다. 단순 조사, 저위험 수정, 일반 코드 리뷰, 구현 없는 설계 토론에는 사용하지 않는다.
-
mloki23 Bundle AI TranslatorUse when a small business owner wants to discover where AI can save them time and money, or when a consultant needs to run a structured AI opportunity audit for a client. Triggers on: "audit my business for AI", "what AI tools should I use", "where can AI save me time", "run the AI Translator". Covers businesses of 1–50 staff across any industry or country.
-
mohi-devhub Bundle AntivibeCode learning and audit framework. Analyze any codebase — new, legacy, or AI-generated — and produce educational explanations or architectural audits. Use when the user wants to understand WHAT and WHY behind any code, not just accept it.
-
moonweave-research Bundle Ref VerifyPrevents citation hallucination in academic writing. Invoke when: finding papers to support a specific claim; verifying/checking/auditing existing citations or DOIs; confirming whether a paper actually says what the user claims it says ('is that what the paper says?', 'did they actually show X?'); adding a citation by describing a paper ('add a citation for the paper where X'); running a pre-submission reference sweep. Do NOT invoke for: formatting references in APA/IEEE style, general topic explanations, citation style questions, or prose editing. Selects Quick Screen (seconds per paper) or Full Audit (source-depth claim check) automatically.
-
motiful Bundle Self ReviewRun a 4-pillar, 6-dimension alignment audit on the current project. Checks design currency, executes artifact verification, detects skill deposits. Use when the user says "self-review", "审视一下", or "audit". Report-only — never auto-fix.
-
mpklu Bundle Living DocsAdopt, audit, or operate the living-documentation methodology in any project or workspace. Use when the user says "set up living docs", "adopt the methodology", "/living-docs adopt", "/living-docs audit", "/living-docs sweep", or asks to apply the living-documentation pattern.
-
mplind Bundle Second ReaderBuild and run a source-verified Markdown knowledge vault (opens as an Obsidian vault). Ingests books, PDFs, transcripts, and articles into atomic, cross-linked, cited notes, then gates every note and every answer behind an independent verification pass that re-reads the source cold and loops until a round finds nothing. Includes a closed learning loop, the vault designs a curriculum from its own gap analysis, runs vault-blind tutoring sessions (spoken or text), grades them, and feeds results back into the vault. Use when the user wants to build a knowledge base from sources, ingest material into a vault, query accumulated knowledge with cited answers, audit vault quality, find knowledge gaps, or study and learn a subject from their vault (the category some call a second brain). Not for one-off summarization, ordinary Markdown editing, generic note formatting, or casual capture. This skill is expensive by design and gates everything it writes.
-
mrsoundmind Bundle Product AuditComprehensive UX, product strategy, and experience audit skill. Use this whenever the user invokes /audit, /product-audit, /ux-audit, /site-audit, or asks for a design audit, UX audit, product audit, experience audit, or conversion audit for any app or website. Triggers on: 'audit this product', 'audit this app', 'audit this site', 'run a full audit', 'do a UX audit', 'review the experience of', 'audit for a client'. Produces a comprehensive .docx report authored by Shashank Rai, with depth scaled to product type. Always use this skill. Never attempt an audit without reading it first.
-
xrpl-commons Bundle Xrpl DevEnd-to-end XRPL development playbook. Covers XRP Ledger dApp development including project scaffolding (create-xrp), wallet integration (xrpl-connect), client SDKs, transactions, tokens, NFTs, DEX/AMM, cross-chain interoperability (Axelar), and security best practices.
-
xshuiai Bundle Media Publish CheckAll-platform pre-publish audit and adaptation for creators publishing to 抖音/Douyin、小红书/Xiaohongshu、微信视频号/Weixin Video Accounts、快手/Kuaishou. Review videos, images, graphic posts, audio, articles, transcripts, subtitles, covers, livestream scripts, product claims, reposted material, and overseas content. Use when users need one Skill to check visible content, spoken claims, AI disclosure, sources, rights, commercial context, platform mentions, livestream commerce, or platform-specific release versions. Trigger on requests such as “能不能发”“发布前审核”“查违禁词/敏感词”“会不会限流”“检查口播/字幕/封面/导流/带货”“标注 AI/转载/演绎/广告/个人观点”, “按我的经验库审核”“保存这次审核”“复盘这条内容”.
-
xsourabhsharma Skill Security AuditDefensive web and web-application security auditing for local projects, localhost, staging, and authorized public/private websites. Use when the user asks to audit, scan, review, find vulnerabilities, check OWASP issues, inspect security headers, assess APIs, or produce a security report for a website or web app.
-
yantoumu Bundle Adsense Site AuditorAudit websites for Google AdSense application readiness and ad-serving compliance. Use when checking whether a site is likely to satisfy AdSense eligibility, site ownership, content quality, navigation, crawler access, ads.txt, privacy disclosure, Google Publisher Policies, AdSense Program policies, or when the user asks if a site can apply for AdSense, pass AdSense review, show ads, or fix AdSense rejection/site-not-ready issues.
-
yasserstudio Bundle CodeigniterUse when working with CodeIgniter 3 or CodeIgniter 4 applications — controllers, models, views, routing, database queries, migrations, libraries, helpers, security, file uploads, email, caching, testing, services, events, CLI commands, and deployment. Trigger on: CI3 projects with system/core/CodeIgniter.php or index.php bootstrapping CI, CI4 projects with app/Config/App.php or spark CLI, any mention of CodeIgniter, HMVC in CI3, Shield auth in CI4, CI query builder usage, or 'php spark' commands.
-
yegor256 Bundle Submit An IssueFiles one already-identified bug as a GitHub issue against one named repository. Use when the user, a code review, or an audit hands over a single finding to file and says "file this bug", "open an issue", "report this defect", "log this on GitHub", or "raise a ticket for this". Confirms the finding is fresh against the codebase, writes a concise report that names the symptom and points at the code, suggests a fix, and pings the repository owner in one comment.
-
yegor256 Bundle Audit Quality GatesUse this skill when the user wants to audit how a project configures its style checkers and static analyzers.
-
swei99386-alt Bundle Windows C Disk CleanerWindows C/E disk cleanup and disk-space governance for requests such as C盘满了, C盘清理, Windows disk cleanup, C/E drive cleanup, large files, duplicate files, Downloads, installers, repair backups, or a deletion manifest. Audit, explain, and clean using a recovery-cost-first rule: recommend delete, keep, or move, then execute only after confirmation of exact paths.
-
maxbogo Bundle Yc Web Design StrategyStrategic web design consultant for building, reviewing, or auditing websites and landing pages. Trigger when the user asks to build a landing page, review a site's messaging, write hero copy or CTAs, audit for "AI slop," or plan page information architecture. Also trigger on keywords: "landing page," "above the fold," "hero section," "conversion funnel," "social proof," "product page design."
-
maxgfr Bundle UltrasecAudit a codebase for exploitable security issues with cross-file tracing, scanner adjudication, and grounded findings.
-
maxim-saplin Bundle Goal SlocPlaybook for using lines-of-code (SLOC) as a north-star metric to genuinely simplify and improve an engineering solution — without gaming the number. Use when asked to "cut SLOC", "reduce/simplify the codebase", remove bloat/complexity/tech-debt, delete dead code or duplication, or hit a line-count target. Covers preflight (baseline + feedback loops + tooling), an honest reduction order, a self-audit against gaming, stop conditions, and a Flutter reference.
-
mazze93 Bundle Conservative File ReorgConservative, transparent, context-aware file reorganization for local folders with deterministic taxonomy, duplicate staging, report generation, profile modulation, and rollback safety. Use when a user asks to clean up or systematize a directory tree, reclassify inbox folders, create repeatable file-overhaul workflows, generate audit/plan/apply reports, generate custom reorg profiles, or undo a prior reorganization run.
-
mcmespinaa Bundle Eval TheoriesEvaluate a thesis Theoretical Framework chapter against the OL646E (SALSU Master Thesis) course rubric — the four canonical Theory-Chapter rules (problem-derived selection, selectivity, distinct-from-introduction, closing analytical framework), plus a 12-point pre-submission audit covering critical stance, concept-to-analysis traceability, and chapter-to-chapter coherence. TRIGGER when the user pastes a Chapter 3 / Theory / Theoretical Framework draft, links a markdown or PDF theory chapter, or asks to score, audit, evaluate, critique, or check a theoretical framework. Also trigger on /eval-theories. SKIP when the request is for an introduction (use anchoring-map-evaluator instead), a methodology chapter, a literature review chapter, a findings chapter, or non-thesis writing. Synthesised from the OL646E_2026 course guidelines (Malmö University SALSU programme), Chouliaraki and Fairclough (1999) on theoretical-method integration, and the Nass and Purwin (2024) examination exemplar.
-
meiiie Bundle Structured Root Cause ResearchEvidence-based root-cause research for complex debugging, architecture reviews, security reviews, incidents, and high-stakes technical decisions. Use when the user asks to think carefully, find root cause, avoid patch fixes, test competing explanations, run 5 Whys, compare against best practices, map data/control/error/trust flows, assess evidence, or produce a verifiable recommendation.
-
yevanchen Bundle Reclaim Code EntropyFind, rank, and safely remove accidental codebase complexity by proving real consumers, dynamic entrypoints, compatibility obligations, duplicate representations, speculative surfaces, and lifecycle ownership. Use when asked to simplify or clean up a repository, reclaim code entropy, reduce over-engineering or redundancy, find deletion candidates, collapse duplicate state/APIs, remove dead or added-then-abandoned code beyond static-tool output, or implement an evidence-backed simplification pass in any language or stack. Also trigger for 代码化简、熵回收、删代码、清理冗余、收敛抽象、去除过度设计. Do not use as a performance audit unless simplification is the stated goal.
-
youks7 Bundle Amazon KrCreate, reference-replicate, revise, resize, or audit Amazon main images, secondary listing images, and A+ modules for physical products. Use for product fidelity, listing graphics, lifestyle/use scenes, and image export QA. Excludes PPC, inventory, and account operations.
-
ysr666 Skill Code ReviewAdversarial pull-request review for dsh-vision-router. Use for code review, security review, regression review, and compatibility review.
-
ystemsrx Skill CfshareUse the cfshare CLI to expose local ports/files as temporary Cloudflare Quick Tunnel URLs. Trigger when a user needs a temporary public URL for a local service, needs to share files/directories from terminal, or needs to inspect/export cfshare audit and policy state.
-
ysyecust Bundle Write Reader First PapersRewrite, restructure, translate, or audit academic manuscripts so first-time readers can identify the problem, contribution, evidence, value, and limitations without decoding internal jargon or formulaic prose. Use for English or Chinese papers, abstracts, introductions, methods, results, conclusions, highlights, captions, tables, supplementary information, cover letters, rebuttals, and bilingual synchronization when the user asks for clearer language, natural authorial voice, direct wording, “说人话”, removal of unnecessary “not X but Y” or “不是……而是……” constructions, reader-first organization, a final prose review, or a contribution audit that separates research and engineering contributions from implementation mistakes, debugging effort, and corrective maintenance.
-
yuntaod Bundle AutoverifierRigorously verify the claims in a scientific or technical paper (or any research artifact) using the AutoVerifier six-layer protocol — corpus building, claim-triple extraction with provenance, intra-document consistency and overclaim detection, cross-source triangulation with contradiction root-cause analysis, external/commercial signal corroboration, and a final hypothesis matrix with a technology-maturity rating. Use this skill whenever the user wants to fact-check, audit, stress-test, peer-review, or assess the validity, reproducibility, novelty, or maturity of a paper, preprint, technical report, or "breakthrough" announcement, or asks whether a result is overclaimed, genuinely novel, independently corroborated, or commercially motivated — even if they never say the word "verify". Also trigger for literature triangulation, conflict-of-interest checks on authors, or technology-readiness / S&TI (scientific & technical intelligence) assessment.
-
yutkat Skill Suggest Neovim Plugin AlternativesAnalyze Neovim plugins and suggest modern alternatives. Activate when user asks about plugin alternatives, plugin migration, outdated plugins, unmaintained plugins, modernizing neovim config, plugin recommendations, checking plugins, updating plugin list, plugin audit, neovim plugin review, or better plugin suggestions.
-
yysun Bundle Audit UI OpsAudit how difficult it is to complete a plain-language business operation through a visible UI. Use for fresh-user operational UX audits and controlled UI comparisons that need verified outcomes, interaction traces, and complexity metrics; do not use for visual design critique, scripted E2E testing, or API automation.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include write-reader-first-papers, ipxe-security-review, bib-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.