Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
kwoekel Bundle Repo Structure AuditUse for full-repo or scoped structure reviews covering navigation, ownership, duplication, archives, generated files, config, or Git hygiene.
-
laramint Bundle Laravel BrainAnalyze a Laravel application for complexity hotspots, security surface, and database access patterns using laravel-brain. Activate when: the user asks what needs work, what should be improved, what to work on next, where to focus, what is the most complex code, what are the security issues, audit the codebase, analyze code quality, find technical debt, find refactoring targets, what are the worst parts of the codebase, or when user mentions: brain, hotspots, cyclomatic, complexity audit, security audit, codebase health, codebase review.
-
laskar-ksatria Skill Nodejs Express Mongodb Backend PatternScaffolds or references a production-ready Node.js REST API with Express 5, TypeScript, Mongoose (MongoDB), Redis, Sentry, JWT auth, bcrypt, rate limiting, and centralized error handling. Use when the user wants to start a new observable and resilient backend, needs a Node.js API boilerplate with security and monitoring, or asks to clone or adapt this template repository.
-
latias94 Bundle Upgrade Dear Imgui StackUse when a user asks to upgrade Dear ImGui, cimgui, ImPlot, ImPlot3D, ImNodes, ImGuizmo, Dear ImGui Test Engine, or related bindings in this repository. Refresh submodules, regenerate pregenerated native/WASM bindings, audit safe Rust API and backend shim changes, update examples/docs/changelog/versioning, and validate release readiness.
-
lb623 Bundle No Negative EchoPrevent 此地无银三百两式 residue: finalize artifacts without echoing rejected session-only alternatives into labels, metadata, commits, PRs, or handoffs. Use after corrections or discarded proposals. Not for ordinary deletion, deprecation, migration, or exclusions materially required for safety, accuracy, compatibility, audit, quotation, or requested comparison.
-
lee-fuhr Bundle UX Framework AuditRun 17 UX frameworks serially against any web app. Each framework audits, fixes critical issues, verifies build, then the next framework runs against the improved version. Proven to raise SUS scores from 57.5 to 92.5.
-
legioncodeinc Bundle Lovable Audit StingerAudit Lovable-built Supabase apps: RLS denials, role-differential reads, function gating, auth posture, bundle-forensics key/endpoint extraction, findings triage, reporting.
-
leifermendez Skill Skill Security LayerAudits security and configuration of fullstack web applications from code the user pastes in chat. Generates a technical checklist with status ✅/❌/⚠️ evaluating essential security controls. Activate when the user requests to review, audit, or verify their project, or when they paste code asking if it's properly configured or secure.
-
lemur47 Skill Si Quick CheckDetect manipulation and disinformation patterns in spiritual, metaphysical, New Age, guru, channelled, prosperity-gospel, conspirituality, or self-help text, scoring seven dimensions plus a CVP consciousness-topology layer. Use whenever the user asks to quick-check, screen, vet, or analyse a passage for manipulation markers, coercion, red flags, or undue influence — e.g. "quick-check this", "analyse this text for manipulation", "is this spiritual content manipulative?", "run a threat check on this channelled message", "スピリチュアルのテキストを分析して", "この文章を診断", "操作のパターンをチェック". Auto-detects English or Japanese (日本語) input. Produces an approximate 0–100 threat score, a per-dimension table, quoted signals, matched tradition categories, and a CVP structural assessment. Heuristic pattern analysis for human judgement, not a verdict on truth or harm.
-
zaoqu-liu Bundle Renwei ZhAudit and revise Chinese text to reduce formulaic AI-style writing while preserving facts and author voice. Use for 中文润色, 去机器味, 去 AI 味, 公众号/知乎/小红书/商业/学术稿改写, 模型化表达审计, 声线保留, fact-safe Chinese editing.
-
zavelinski Skill Secret ScanBefore a commit, push, paste, or share, scan the diff/text for leaked secrets (API keys, tokens, private keys, passwords, connection strings) and block them, instead of leaking and rotating later. Use before any git push, before sharing logs/config, before pasting output. Trigger with /secret-scan or "check for secrets", "is there a key in this", "scan before push".
-
zavora-ai Bundle Credentials ManagementSecurely manage credentials — list available secrets, request runtime tokens, rotate keys, revoke access, and audit usage. Use when retrieving API keys, rotating secrets, checking credential metadata, auditing access, or validating secret scopes.
-
zavora-ai Bundle Device Fleet ManagementManage device fleets — get device info, check security posture, list applications, collect diagnostics, run health checks, and create remediation tasks. Use when checking device health, auditing security posture, listing installed apps, collecting diagnostics, or remediating compliance issues.
-
zavora-ai Bundle Governance Policy EnforcementEvaluate governance policies, manage approvals, simulate policy changes, and export audit evidence. Use when checking if an action is allowed, requesting approvals, simulating policy impact, requesting exceptions, or generating compliance reports.
-
zavora-ai Bundle Security Vulnerability ManagementManage security vulnerabilities — search advisories (CVE/GHSA/OSV/RustSec), audit dependencies, score risk, generate remediation plans, and export findings. Use when checking for vulnerabilities, auditing dependencies, assessing security risk, planning patches, or generating security reports.
-
zawatton Bundle Memory PrunerAudit, deduplicate, and prune Claude Code auto-memory files. Detects orphans, broken links, duplicates, staleness, and bloat across MEMORY.md and individual memory files. Triggers: memory audit, memory prune, clean memory, メモリ整理, メモリ監査, プルーニング, 記憶整理
-
mariano-aguero Bundle Solidity Security AuditComprehensive Solidity smart contract security auditing and vulnerability analysis skill. Based on methodologies from Trail of Bits, OpenZeppelin, Consensys Diligence, Sherlock, CertiK, Cyfrin, Spearbit, Halborn, and other leading Web3 security firms. This skill should be used whenever the user asks to "audit a smart contract", "review Solidity code for security", "find vulnerabilities", "check for reentrancy", "analyze gas optimization", "review access control", "check proxy patterns", "analyze DeFi protocol security", "review ERC20/ERC721 implementation", "check oracle manipulation risks", "review upgrade patterns", or mentions any security review of EVM-compatible smart contracts. Also triggers for keywords like "slither", "echidna", "foundry fuzz", "formal verification", "invariant testing", "flash loan attack", "MEV", "sandwich attack", "front-running", "delegatecall", "selfdestruct", "reentrancy guard", "access control vulnerability", "storage collision", "proxy upgrade security", "smart contract exploi
-
master-cai Bundle Arxiv2beamerConvert research papers (local LaTeX source or Arxiv link) into doctoral group meeting style LaTeX Beamer slides. Use when you need to auto-detect the Beamer entry file, rewrite content after `\section{Introduction}`, reuse paper equations/figures/tables, and enforce quality via a `xelatex` + `pdf-vision` visual audit loop. Trigger keywords: beamer, slides, group meeting, arxiv, paper presentation.
-
mateoandries27-lang Bundle Move AuditorSecurity audit of Sui Move contracts while you develop. Trigger on "audit", "check this contract", "review for security". Modes - default (full repo), DEEP (+ adversarial reasoning + protocol analysis), or a specific filename.
-
avdlee Skill Code ReviewerReview code for correctness, maintainability, and security risks. Use when preparing a PR or auditing a change set.
Audited -
chaitin Bundle Chaitin CLIUse when running chaitin-cli commands to manage Chaitin security products: SafeLine WAF (site management, IP blocking, ACL, policy rules, attack logs), X-Ray vulnerability scanner (scan tasks, results, assets), CodeInsight (projects, repository configs, scan tasks, reports), CodeForce (projects, AI tasks, denoise, repositories), CloudWalker CWPP (events, vulnerabilities, assets), and T-Answer (semantic security operations for alarms, assets, policies, response actions, and Open API fallback).
-
1mangesh1 Bundle Hipaa GuardianThis skill should be used when the user asks to "scan for PHI", "detect PII", "HIPAA compliance check", "audit for protected health information", "find sensitive healthcare data", "generate HIPAA audit report", "check code for PHI leakage", "scan logs for PHI", "check authentication on PHI endpoints", "scan FHIR resources", "check HL7 messages", or mentions PHI detection, HIPAA compliance, healthcare data privacy, medical record security, logging PHI violations, authentication checks for health data, or healthcare data formats (FHIR, HL7, CDA).
-
wbso-ai Bundle Omarchy Plugin SecuritySecurity review for Omarchy Quattro plugins (Quickshell/QML bar widgets with bash, python or node helpers) before submitting to the plugin marketplace. Use when writing, auditing or hardening an Omarchy plugin, when a marketplace issue gets needs-fixes or security-needs-fixes, when preparing a [Plugin] or [Verify] submission, or when the user asks whether a plugin is safe to publish. Based on every maintainer review comment in the marketplace repository.
-
wenyuchiou Bundle Codex DelegateDelegates implementation-heavy or repetitive coding work (batch edits, boilerplate, multi-file refactors with clear patterns, test scaffolding) from Claude to OpenAI Codex CLI. Use when token cost outweighs judgment cost. Trigger phrases include "delegate to codex", "let codex do this", "batch refactor across files", "scaffold tests for". Avoid for architecture, security review, or root-cause debugging.
-
wenyuchiou Bundle Gemini DelegateDelegates large-context reading, bilingual or Chinese (CJK / zh-TW) drafting, cross-file synthesis, and second-opinion review to Google Antigravity CLI (`agy`) or legacy Gemini CLI. Use when input exceeds Claude's working budget, when the user writes in Chinese, when terminology must align across long documents, or when a reviewer pass is needed. Trigger phrases include "summarize this in Chinese", "second-opinion review", "long-context synthesis", "draft this in zh-TW". Avoid for bulk code generation or security-sensitive coding.
-
wesammustafa Skill Claude Md ReviewAudit a CLAUDE.md file for the patterns that actually degrade Claude Code's output — vagueness, unnamed files, stale facts, and bloat. Use when asked to review, audit, improve, shrink, or fix a CLAUDE.md, and when a project's results feel inconsistent or Claude keeps rediscovering the same context.
-
william-yeh Bundle Common Code ReviewerUse when the user asks to review code, audit changes, or review a PR.
-
windscribe Bundle Windscribe VpnControls Windscribe VPN via the windscribe-cli command-line tool. Use when installing Windscribe, connecting or disconnecting VPN, switching server locations or protocols, checking VPN status, managing the firewall, listing available locations, troubleshooting VPN issues, automating privacy and security workflows, or testing geo-dependent features across regions. All operations use shell commands via windscribe-cli. Not for Windscribe account management, billing, or browser extension control.
-
adversa-ai Bundle SecureclawSecurity hardening toolkit for OpenClaw. Run audits, apply fixes, scan skills, monitor costs and memory integrity.
-
zkblk Bundle Case Study ForgeBuild, restructure or audit portfolio case studies that survive interrogation — UI/UX, product, branding, design systems, fashion and motion. Runs the Defensible Case Study method — answer-first structure, forks documented as decision records, a declared evidence tier instead of invented metrics, an internal FAQ, and a weighted 100-point scorecard tied to real design-hiring rubrics. Use when the user asks to write a case study, review or fix a portfolio piece, structure a project story, strengthen or sanity-check impact numbers, prepare for a portfolio review or design interview, adapt a case study to a seniority level, or says "skriv ett case study", "granska min portfolio", "portfolio review", "case study feedback", "мой кейс слабый", "как описать проект". Also use before any project write-up meant for a hiring manager, jury, client or promo packet.
-
zw008 Bundle Vmware Nsx SecurityUse this skill whenever the user needs to manage VMware NSX security (rebranded VMware vDefend in VCF 9) — distributed firewall (DFW) policies, security groups, microsegmentation, and IDS/IPS. Directly handles: create/manage DFW policies and rules, security groups, VM tags, network traceflow diagnostics, IDPS profiles and status. Always use this skill for "create firewall rule", "set up microsegmentation", "add VM to security group", "run traceflow", "check IDS status", "vDefend firewall rule", or any NSX security / vDefend / DFW task. Do NOT use for NSX networking operations like segments, gateways, NAT, or routing (use vmware-nsx), or VM lifecycle (use vmware-aiops). For load balancing/AVI/AKO use vmware-avi.
-
zw008 Bundle Vmware NsxUse this skill when the user needs to inspect or manage VMware NSX networking through NSX Manager — segments, Tier-0/Tier-1 gateways, NAT, static routes/BGP, and IP pools. Directly handles: list and inspect segments, gateways, NAT rules, routes and IP pools; check transport node, edge cluster and manager health; find a VM's segment. Changes (create/update/delete segments, Tier-1 gateways, NAT rules, static routes, IP pools, Tier-0 BGP) only when the user explicitly asks for that change. Use this skill for "create segment", "set up gateway", "create NAT rule", "check network health", "troubleshoot connectivity" when the context is explicitly NSX, NSX-T, or NSX Manager. Do NOT use for networking outside NSX, DFW firewall rules or security groups (use vmware-nsx-security), vSphere distributed port groups or host VMkernel adapters (use vmware-aiops), VM lifecycle (use vmware-aiops), or AVI/ALB load balancing (use vmware-avi). For multi-step workflows use vmware-pilot.
-
zw008 Bundle Vmware PilotUse this skill whenever the user wants to design, execute, or manage complex multi-step VMware workflows with human approval gates and explicit, best-effort rollback. Pilot is the orchestration brain — it breaks a goal into steps across companion VMware skills (aiops, monitor, nsx, nsx-security, aria, vks, storage, avi), adds approval gates before destructive operations, and records per-step undo actions that run only when rollback is explicitly called, never automatically. Always use vmware-pilot for: "clone and test before applying to production", "VMware incident response with checkpoints", "investigate alert root cause", "VMware rolling restart with health checks", "baseline capture and drift detection", "rolling maintenance with AVI drain", or any VMware workflow needing approval gates or rollback. 15 built-in templates + custom YAML + AI-designed workflows. Do NOT use for single-step work — use vmware-aiops for one VM action, vmware-monitor for read-only queries, vmware-avi for load balancer queries.
-
zw008 Bundle Vmware VdiUse this skill whenever the user needs to operate a VMware/Omnissa Horizon VDI environment via its Connection Server: list and manage desktop pools, RDS farms and published apps, inspect and act on user sessions (log off, disconnect, send message), manage desktop machines (reset, maintenance, remove), view and change entitlements, read Horizon events/health/statistics, and push instant-clone golden images. Always use this skill for "log off VDI user", "reset this desktop", "why is the desktop pool not provisioning", "push the new image to the pool", "list Horizon sessions", "who is entitled to the pool", "VDI health" — when the context is explicitly Horizon / Omnissa / VDI / desktop-pool / RDS-farm. Do NOT use for the underlying vCenter VM lifecycle/power/snapshot/migrate (use vmware-aiops), read-only vSphere monitoring (use vmware-monitor), or NSX microsegmentation (use vmware-nsx-security). This skill manages the Horizon broker layer; vmware-aiops manages the vCenter VMs backing the desktops.
-
zwbao Bundle AI Research ClinicianAI 时代研究型医生的 human-in-the-loop auto-research 引擎 — AI 驱动临床研究全流程(从临床现象提问、 检索证据、找工具/repo、跑最小复现、起草研究方案、审计偏倚与合规)并产出真实可用的成果,你在每个关口 (gate) 拍板、纠偏、授权、署名。它替你做执行,绝不替你做决定。Use when a clinician-researcher (medical student, resident, junior attending) wants to actually MOVE a clinical research project forward with AI doing the legwork and them steering — find a question from a case, appraise evidence, design a study, search/run tools, reproduce a minimal analysis, audit bias, draft a plan. Triggers on "帮我把这个临床现象做成研究", "带我跑完整研究流程", "我来把关你来跑", "auto research", "帮我检索/拆这篇论文", "我想做影像 AI 预测疗效", "想做生信/单细胞/Meta/真实世界研究", "帮我找/跑一个开源工具", "PICO", "选题", "研究设计", "审计我的方案/代码/结果", "research copilot", "run the research loop with me". Do NOT use for individual patient diagnosis/treatment decisions (那是主诊医生与 MDT 的职责), for producing a molecular tumor board report (用 cancerdao-vmtb), for rare-disease patient navigation (用 firefly), or for one-shot medical-record organization.
-
girofu Bundle Skill FetchThis skill should be used when the user asks to "fetch skill", "install skill", "search for a skill", or when a hook outputs "MISSING EXTERNAL SKILL". Searches 9 registries (SkillsMP, GitHub, Anthropic Skills, ClawSkillHub, skills.sh, PolySkill, SkillHub, Skills Directory) with multi-variant search, quality scoring, security labels, pagination, and local/global installation.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include case-study-forge, vmware-vdi, repo-structure-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.