Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
lagz0ne Bundle Triage ThreeThis skill should be used when the user asks for adversarial code review, security audit, bug triage, architecture review, or any deep analysis that benefits from multiple perspectives challenging each other. Trigger phrases include: 'triage this', 'find bugs in', 'security audit', 'review this code', 'adversarial review', 'find vulnerabilities', 'audit this for', 'review this PR for correctness'. Uses three adversarial roles (Pusher finds, Challenger questions, Arbiter decides) with style presets (measured, wide-funnel, paranoid, baseline, max-tension).
-
landco-llc Bundle Agentic Change AuditAudit software changes, pull requests, local diffs, or release candidates for target identity, scope, correctness, regression, security, evidence quality, and merge or release readiness. Use for independent audits, fixed-HEAD reviews, focused re-audits, docs-only audits, or verdicts such as PASS, CHANGES REQUESTED, BLOCKED, and NOT AUDITABLE. Do not use to implement fixes or perform a generic style-only review.
-
liminal-hq Bundle Pr IntegrationReview and integrate pull requests with audit and execute flows, conflict-aware ordering, validation gates, checkpointing, and rollback safeguards.
-
lujiafa Bundle Docs ContextSuper Base Context — project doc loader & synchronizer. Triggers even without explicit "load docs"/"sync docs." READ MODE — load architecture/modules/coding/decision docs when work references project state: code work (write/modify/remove); design (features/APIs/schemas/architecture); review (modules, past solutions); tech selection; ADR research; migration/refactor planning; performance/security analysis; tests; code reviews; any spec/plan/design/ADR referencing project. WRITE MODE — NET DELTA vs. last doc sync: additions/modifications/REMOVALS/deprecations of previously-synced code or decisions (docs revert: delete BCU file/ADR), AND rollbacks. User signals: sync docs/done/ready to commit/pre-commit/record decision. Auto-fires before final task-completion reply. WRITE MODE does NOT fire on: brainstorming, generic/read-only Q&A, in-session try-and-undo with no net change, already-synced.
-
xpalien Bundle AI Code ReviewSystematic code review checklist for AI-generated code. Use this skill whenever reviewing code produced by AI assistants (ChatGPT, Copilot, Claude, Cursor, Codex, Gemini, etc.), or when the user asks to review, audit, or harden any code they did not write from scratch themselves. Also trigger when the user says "review this," "is this safe," "check my code," "audit this," "harden this," or pastes code they want evaluated before merging or deploying. If the user mentions vibe coding, shipping AI code, or debugging code they do not fully understand, use this skill.
-
nerdbase-by-stark Bundle Skill ForgeDisciplined 9-phase workflow to audit and improve a project's skill library — discover, audit, candidates, edits, research, structure, QA, memory. Invoked by /skill-forge or when asked to improve/audit/tune skills. Not for authoring one new skill (use skill-creator) or quick single-skill questions.
-
nunomaduro Bundle Laravel Best PracticesApply this skill whenever writing, reviewing, or refactoring Laravel PHP code. This includes creating or modifying controllers, models, migrations, form requests, policies, jobs, scheduled commands, service classes, and Eloquent queries. Triggers for N+1 and query performance issues, caching strategies, authorization and security patterns, validation, error handling, queue and job configuration, route definitions, and architectural decisions. Also use for Laravel code reviews and refactoring existing Laravel code to follow best practices. Covers any task involving Laravel backend PHP code patterns.
-
orizon-eu Bundle API BreakerAutomated API security testing starting from domains. Discovers REST, GraphQL, and SOAP APIs, reconstructs schemas, and tests for BOLA/IDOR, BFLA, mass assignment, JWT attacks, rate limiting bypass, and business logic flaws. Use when user asks to "test API security", "break API", "find API vulnerabilities", "test GraphQL", "test JWT", "API pentest", or provides domains with API endpoints. For authorized testing only.
-
perhapsspy Bundle Source Owner AuditUse for read-only source-of-truth audits: identify the current code, API, config, doc, or behavior to follow; compare a proposed, migrated, ported, or current change against it; and report evidence, mismatches, unresolved decisions, and owner-level recommendations.
-
lll0k0lad Skill Security And HardeningUse when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services.
-
sebas-aikon-intelligence Skill Production Code AuditAutonomously deep-scan entire codebase line-by-line, understand architecture and patterns, then systematically transform it to production-grade, corporate-level professional quality with optimizations
-
netresearch Bundle RetroUse when a Claude Code session ends or is declared finished, a friction needs fixing, a reusable learning needs capturing, local memory needs promoting upward, or for cross-session audits — detect friction AND learnings, route each to the right destination, and gate 'done'. Triggers: /retro, /retro done, 'retrospective', 'capture this learning', 'fix this skill', 'promote memory', 'audit', 'alles erledigt'.
-
odradekai Bundle Release ChecklistRun pre-release quality gates for CyberOracle. Checks version drift, code quality, tests, build, security, and git state. Reports pass/fail with actionable fixes.
-
soapbox-pub Skill NakInteract with Nostr protocol using the nak CLI tool. Use to generate Nostr secret keys, encode and decode Nostr identifiers (hex/npub/nsec/nip05/etc), fetch events from relays, sign and publish Nostr events, and more.
-
yukkit Bundle Developer EvolutionAnalyze local Codex history to create and evolve a personal developer-profile skill and propose concise global AGENTS.md agreements. Use when the user asks to learn from coding chats, create or improve their profile skill, refresh preferences, or audit working agreements. Daily use of an existing profile belongs to developer-profile and does not require history analysis.
-
espennilsen Skill Daily BlogWrite and publish a daily blog post for aivena.dev. Covers topic selection, writing in Aivena's voice, security scanning, build validation, and PR shipping. Use when asked to write today's blog post, "daily blog", "write a blog post for aivena.dev", or when a scheduled blog task fires.
-
kylezantos Bundle Skill DistilleryCreate or audit Claude Code skills. Synthesizes source material (articles, frameworks, talks) bottom-up into strategic, interactive skills — or audits existing skills through a multi-lens framework. Use when creating new skills, turning articles into skills, capturing AI workflows as skills, auditing/reviewing existing skills, or improving skill quality. Triggers on: create skill, build skill, new skill, skill from article, turn this into a skill, capture this as a skill, audit skill, review skill, evaluate skill, improve skill.
-
muhammad-khalid-bin-walid Bundle Agentic PentestFull end-to-end agentic penetration test orchestration for security consultants running authorized client engagements. Use this skill whenever a user mentions a pentest, security assessment, red team engagement, bug bounty, or vulnerability assessment — even if they only reference a single phase like recon, scanning, exploitation, or reporting. This skill guides the complete engagement lifecycle: scoping → recon → scanning → exploitation → post-exploitation → remediation → final report. Triggers on phrases like "run a pentest on", "assess the security of", "find vulnerabilities in", "red team engagement", "security audit", "attack surface mapping", "CVE research for client", "write a pentest report", or any request involving authorized offensive security work. Always invoked when both a target and an authorization context are present.
-
thebgtagency Bundle AI Writing AuditAudit and repair text that reads as machine written. Any length, any format: a two line direct message, an automated message sequence, an objection reply, a caption, a carousel slide, a spoken script, a landing page, an essay. Runs two layers, surface tells and discourse tells, behind a false positive gate, and returns findings with a repair for each. Use on an existing draft. Do not use to compose a first draft.
-
theclaymethod Skill Ultra CleanPerform deep codebase cleanup and quality improvement through an evidence-driven multi-lane audit and refactor workflow. Use when a user wants to clean up a repo, reduce duplication, consolidate shared types, remove unused code, untangle circular dependencies, replace weak types, remove unnecessary defensive error handling, delete deprecated or fallback paths, or strip AI slop and unhelpful comments. Best for medium-to-large refactors where Codex should research first, produce a critical assessment with recommendations, delegate across eight cleanup lanes, and implement only high-confidence changes with validation.
-
usst-yk Bundle Cumcm Math ModelingCUMCM/数学建模竞赛 workflow for problem decomposition, data audit, route comparison, reproducible solving, validation, figures, and paper writing. Use for 全国大学生数学建模竞赛, CUMCM, 建模论文, 赛题分析, 技术路线图, 模型流程图, 灵敏度分析, 摘要, 一等奖标准, or contest-style modeling reports. Do not use for ordinary homework, non-contest paper polishing, image-only editing, or pure coding fixes unless contest modeling is requested.
-
thedatakey Bundle Apollyon ScanRun Apollyon against an authorized local source file or project, interpret its JSON or SARIF findings and exit codes conservatively, and verify remediations. Use for security review of handwritten or AI-generated C, C++, C#, Go, Java, Kotlin, JavaScript, TypeScript, PHP, Python, Ruby, Rust, or Swift code.
-
thoughtbot Bundle Dependabot ReviewReviews Dependabot dependency upgrade pull requests to assess impact, breaking changes, and merge readiness. Works across ecosystems (npm, RubyGems, PyPI, Go modules, etc.). Works in two modes: (1) single-PR review when the user pastes a Dependabot PR URL, and (2) audit mode that discovers every open Dependabot PR in the current repo, analyzes them one by one, and produces a consolidated triage report. Use this skill whenever the user pastes a Dependabot PR URL, asks to review a dependency upgrade PR, mentions a package version bump, or wants to know if a Dependabot PR is safe to merge. Also trigger in audit mode when the user says things like "review all open dependabot PRs", "which dependabot PRs are ready to merge", "audit our dep upgrades", "go through the open dep PRs", "check dependabot", or asks for a status/report on pending dependency updates. Trigger on any GitHub PR URL related to dependabot, package upgrades, or "bump" in the title.
-
veithly Bundle CoollandingCompose, redesign, polish, audit, and optimize distinctive brand-specific landing pages by diagnosing the brief, selecting one of 9 lead style worlds, optionally attaching one research-backed motion/WebGL technique pack, and mixing 2-4 interaction mechanics. Use for new or existing immersive/WebGL/3D, multi-world, data-driven scroll, shader-tool, data-monument, luxury, editorial, craft, kinetic, papercraft, or spatial pages; also trigger for contrast/readability collisions, scroll smoothness, motion quality, asset fidelity, and pixel-level reference parity. Chinese triggers include 前端重构、深度优化、视觉审计、WebGL 动效、滚动性能、文字可读性、素材质量 and 像素级复刻. The workflow requires an auditable world decision and brand-owned combination instead of defaulting to cinematic-dark.
-
thoughtbot Bundle Rails Audit ThoughtbotPerform comprehensive code audits of Ruby on Rails applications based on thoughtbot best practices. Use this skill when the user requests a code audit, code review, quality assessment, or analysis of a Rails application. The skill analyzes the entire codebase focusing on testing practices (RSpec), security vulnerabilities, code design (skinny controllers, domain models, PORO with ActiveModel), Rails conventions, database optimization, and Ruby best practices. Outputs a detailed markdown audit report grouped by category (Testing, Security, Models, Controllers, Code Design, Views) with severity levels (Critical, High, Medium, Low) within each category.
-
ventaquil Bundle Threat Or Treat ReviewPrecision-first code review and pre-publish audit, run as a scoring game (+1 per verified finding, -2 per false positive or hallucination, 0 for staying silent). Use whenever the user asks to review code, audit a repo, do a pre-publish / pre-merge / pre-release check, hunt bugs, or "check before I ship" — even if they don't mention scoring. Drives an adversarial-verification pass so every reported issue is cited to a line and either tool-confirmed or source-verified; checks source, docs, markdown, CI, and release metadata, not just code.
-
vercel-labs Bundle Vercel ErrorUse @vercel/error to design, implement, migrate, audit, or review structured TypeScript errors. Trigger when a project uses or adopts the package, or when work involves its codes, fields, factories, HTTP APIs, telemetry, or terminal output. Use native Error for local failures that need no stable identity, recovery guidance, observability, or transport.
28.7k -
tibobfd Bundle Secure Vps SetupExpert Security Mentor. Guides users step-by-step to secure a Linux VPS (Hardening, Tailscale, Traefik, Crowdsec).
-
timwuhaotian Skill Code ReviewComprehensive code review with security and performance checks
Audited -
vibecure Bundle VibecureScan Node.js backends for missing rate limits, bot protection, and spending caps on Twilio, SendGrid, OpenAI, and 19+ more paid APIs. Detects which services your code uses, checks for security gaps that let bots or bad actors run up your bill, and fixes them. Use when the user mentions rate limiting, bot protection, API costs, securing a paid API like Twilio/SendGrid/OpenAI, or asks to scan for security issues on endpoints that cost money.
Audited -
tinyopsstudio Bundle
Automation Integration Preflight ActionAudit a public webpage for automation and integration readiness through the TinyOps paid x402 service. Use for evidence-backed readiness findings, prioritized integration risks, or a structured acceptance checklist. Do not use for private or authenticated pages, form submission, or security testing.
-
tokauth Bundle SkillscanSecurity gate for skills. Every new skill MUST pass SkillScan before use. Activate on any install, load, add, evaluate, or safety question about a skill. On first load, run first-run to scan all existing skills. Blocks HIGH/CRITICAL skills. No exceptions.
-
tommasinigiovanni Skill Server Security ScanUse when given an IP address (and optionally SSH credentials) to run a non-destructive security audit — external attack-surface analysis from IP alone, or internal privilege/configuration scan when SSH access credentials are provided.
-
transparent-pegasus Skill Artful SimplicityAudit code, tests, and prose for artful simplicity; use for readability, design, refactoring, over-engineering, and redundancy reviews.
-
tt-a1i Bundle Simplify CodebaseSimplification audit or authorized codebase simplification whose stated objective is to remove accidental complexity. Use for evidence-backed deletion or consolidation of dead code, duplicate state, redundant APIs or layers, ownerless abstractions, obsolete compatibility or design records, and over-engineering in any language; also use for 代码简化 or 熵回收. Do not use for general code review, onboarding, style-only refactoring, or performance tuning.
-
tapauth Bundle TapauthUse when you need delegated access from a user: OAuth tokens for Google Calendar, Gmail, GitHub, Slack, Linear, Notion, Vercel, Sentry, Asana, Discord, Apify, or Jira; or a user-entered password or fixed API key via the `secret` provider. Just run the bundled script and it handles grant creation, user approval, token/secret caching, and OAuth refresh when available. Do NOT use when you already have direct credentials.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include vercel-error, laravel-best-practices, coollanding. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.