Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
taroify Bundle T Wiki为任意代码仓库或 Markdown 知识库初始化、编译、增量刷新和使用本地 docs/wiki 知识层。用于用户要求创建或维护 T Wiki、把仓库资料编译成可追溯的 Markdown/Obsidian Wiki、执行 query/search/lint/audit、检查 stale/coverage/source-map,或把单个源文件 ingest 到 Wiki;独立运行,不依赖阶段状态、共享 core、插件 hook 或其他 wiki skill。
-
tegnike Skill Optimize ImagesOptimize images in a web project by converting PNG/JPG to WebP format with resizing. Use this skill whenever the user mentions image optimization, page load speed, image compression, converting images to WebP, reducing image file sizes, or asks about large images slowing down their site. Also trigger when the user asks to audit or check image sizes in public/ or static asset directories.
-
tejasashinde Bundle Troubleshooting It IssuesTroubleshoots IT-related issues. Use when user mentions software crashes, error messages, issues related to operating systems, networks, software, hardware, error codes, system performance, installation and configuration errors, security, or other IT troubleshooting concerns.
-
tempoloss Bundle MentorUse when the user accepts, reviews, or asks about non-trivial code — their own or AI-generated — and should understand it rather than just ship it. Triggers on "mentor", "teach me", "explain this", "quiz me", or right after generating concurrency / security / DB-query / algorithm / auth code. Runs a comprehension loop instead of a lecture: show the failure, compare the options, price the choice, name the terms, then make the user restate it and grade them.
-
temporalio Bundle Temporal Workflow Design CriticCritique, audit, or score a Temporal workflow design for correctness, production readiness, and best-practice compliance. Use when asked to review a Temporal architecture, evaluate whether a design is production ready, identify anti-patterns or risks, assess Temporal fitness for a use case, or give a design a thumbs up/down. Not for writing or debugging Temporal code — use temporal-developer for that.
-
tencent Bundle Tencent Edgeone SkillA comprehensive skill for Tencent EdgeOne (Edge Security & Acceleration Platform), covering edge acceleration (DNS, certificates, caching, rule engine, L4 proxy, load balancing), edge security (DDoS protection, Web protection, Bot management), edge media (real-time video / image processing), edge development (Edge Functions, EdgeOne Pages), and more. Use this skill whenever a user mentions any EdgeOne / EO-related configuration, operations, querying, or troubleshooting needs.
-
vins13pattar Bundle Dpdpa ComplianceAudit, implement, and remediate Digital Personal Data Protection Act 2023 (DPDPA) compliance in any application codebase. Use this skill whenever the user mentions DPDPA, Indian data protection, personal data handling for Indian users, consent management, data breach notification, children's data protection in India, cross-border data transfer from India, privacy policy for Indian apps, Data Fiduciary obligations, Data Principal rights, or compliance auditing for Indian privacy law. Also trigger when the user asks to "audit my app for privacy", "check data protection compliance", "implement consent flows", "add breach notification", "handle children's data", "add data deletion/erasure", "implement right to access", "GDPR equivalent in India", or any task involving personal data processing for users in India. This skill covers code-level implementation, architecture review, compliance auditing with remediation, and organizational/process guidelines that fall outside application code.
-
viticci Bundle HandholderSet up, migrate, repair, or audit Android gaming handhelds over ADB, including Cocoon, emulators, RetroArch hotkeys and shaders, replacement textures, lawful ROM and save migration, artwork, controls, displays, and launch testing. Includes profiles for AYN Thor and Retroid Pocket Nova; use the generic workflow for other Android handhelds.
-
vitormiziara Bundle Saas SecurityComprehensive SaaS security skill covering code auditing, checklist generation, and vulnerability reporting. TRIGGER this skill whenever the user asks to: audit code for security issues, review a codebase for vulnerabilities, generate a security checklist, check for OWASP compliance, review authentication or authorization logic, check for injection risks, race conditions, or insecure configurations, or asks anything related to SaaS security hardening. Also trigger proactively when the user shares code and asks for a review — always include a security perspective using this skill.
-
vltansky Bundle Roast My Agents MdBrutally honest AGENTS.md/CLAUDE.md review backed by real A/B test evidence. Not just opinions — actual proof that your rules are dead weight. Roasts instruction files for bloat, slop, and redundancy, then proves it by running evals. Use when user says "roast my agents.md", "roast my CLAUDE.md", "prove my rules are useless", "eval roast", or wants entertaining evidence-based feedback on their AI config files. Also triggers on "audit my instructions" or "are my rules helping".
-
vmware-skills Bundle Vmware Nsx SecurityUse this skill whenever the user needs to manage VMware NSX security (rebranded VMware vDefend in VCF 9) — distributed firewall (DFW) policies, security groups, microsegmentation, and IDS/IPS. Directly handles: create/manage DFW policies and rules, security groups, VM tags, network traceflow diagnostics, IDPS profiles and status. Always use this skill for "create firewall rule", "set up microsegmentation", "add VM to security group", "run traceflow", "check IDS status", "vDefend firewall rule", or any NSX security / vDefend / DFW task. Do NOT use for NSX networking operations like segments, gateways, NAT, or routing (use vmware-nsx), or VM lifecycle (use vmware-aiops). For load balancing/AVI/AKO use vmware-avi.
-
vmware-skills Bundle Vmware NsxUse this skill whenever the user needs to manage VMware NSX networking — segments, gateways, NAT, routing, and IP pools. Directly handles: create/manage network segments, configure Tier-0/Tier-1 gateways, set up NAT rules, manage static routes, configure IP pools, check transport node and edge cluster health. Always use this skill for "create segment", "set up gateway", "create NAT rule", "check network health", "troubleshoot connectivity", or any NSX/networking/segment task. Do NOT use for DFW firewall rules or security groups (use vmware-nsx-security), VM lifecycle (use vmware-aiops), or AVI/ALB load balancing (use vmware-avi). For multi-step workflows use vmware-pilot.
-
vmware-skills Bundle Vmware VdiUse this skill whenever the user needs to operate a VMware/Omnissa Horizon VDI environment via its Connection Server: list and manage desktop pools, RDS farms and published apps, inspect and act on user sessions (log off, disconnect, send message), manage desktop machines (reset, maintenance, remove), view and change entitlements, read Horizon events/health/statistics, and push instant-clone golden images. Always use this skill for "log off VDI user", "reset this desktop", "why is the desktop pool not provisioning", "push the new image to the pool", "list Horizon sessions", "who is entitled to the pool", "VDI health" — when the context is explicitly Horizon / Omnissa / VDI / desktop-pool / RDS-farm. Do NOT use for the underlying vCenter VM lifecycle/power/snapshot/migrate (use vmware-aiops), read-only vSphere monitoring (use vmware-monitor), or NSX microsegmentation (use vmware-nsx-security). This skill manages the Horizon broker layer; vmware-aiops manages the vCenter VMs backing the desktops.
-
vmware-skills Bundle Vmware PilotUse this skill whenever the user wants to design, execute, or manage complex multi-step VMware workflows with human approval and automatic rollback. Pilot is the orchestration brain — it breaks a goal into steps across companion VMware skills (aiops, monitor, nsx, nsx-security, aria, vks, storage, avi), adds approval gates before destructive operations, and rolls back automatically if anything fails. Always use vmware-pilot for: "clone and test before applying to production", "VMware incident response with checkpoints", "investigate alert root cause", "VMware rolling restart with health checks", "baseline capture and drift detection", "rolling maintenance with AVI drain", or any VMware workflow needing approval gates or rollback. 15 built-in templates + custom YAML + AI-designed workflows. Do NOT use for single-step work — use vmware-aiops for one VM action, vmware-monitor for read-only queries, vmware-avi for load balancer queries.
-
voidful Bundle MichelinAudit, rewrite, redesign, and validate Traditional Chinese for Taiwan and English copy or visual design so the result feels specific, intentional, and authored rather than templated. Use for 去 AI 味, 說人話, 台灣用語, anti-slop, natural copy, design critique, redesign, voice calibration, or blind human-versus-AI validation. Diagnose the AI-flavor cues first, preserve facts and constraints, revise only the failed families, then run an independent validation loop.
-
voidxai Bundle TasteUse this skill when the user wants a qualitative judgment on whether code, architecture, APIs, or design are *good* — not just working. MUST USE for: the word "taste" or "品味"; phrases like "well-designed", "feels off", "feels mediocre", "amateur hour", "something is off", "design quality"; asking which approach shows better craftsmanship; requesting someone to evaluate overall quality of code or a system. Also use when the user's core question is "is this good?" rather than "make this work." Do NOT use for: specific bug fixes, performance debugging, security audits, writing tests, refactoring with clear instructions, or UI changes with concrete goals like "fix spacing on mobile."
-
voronindenis5 Bundle Group Expense SettlerSplit group expenses fairly (equal or weighted shares) and compute the minimum number of money transfers to settle up. Reads a simple ledger of who paid for what, handles non-even splits, weights, and shared vs personal items, then produces an optimal settlement plan (who pays whom, how much) plus a fairness audit. Use when settling trip costs with friends, splitting rent and utilities among roommates, or running any shared-expense pool without a dedicated app.
-
vstrofago Bundle Zettelkasten OrganizerAudit and maintain Zettelkasten slip-boxes in Obsidian.
-
vxcozy Bundle SanitizeRun a 12-point security audit on a git repo — checks for private keys, API tokens, .env files, config files with secrets, plaintext passwords, RPC URLs with embedded keys, wallet addresses, console.log leaks, .gitignore gaps, and test files with real credentials.
-
w33ts Bundle Virustotal APIComprehensive reference for the VirusTotal API v3, covering authentication, rate limits, endpoint usage, and the critical differences between Free (Public) and Premium (Enterprise) tiers. Use this skill whenever a user asks about VirusTotal, VT API, scanning files or URLs with VirusTotal, threat intelligence lookups, IoC enrichment, YARA hunting, Retrohunt, Livehunt, VT Intelligence search, VT Graph, VT Monitor, VT Feeds, private scanning, malware analysis via VirusTotal, or building integrations with the VirusTotal API. Also trigger when the user mentions "VT", "virustotal", hash lookups, file reputation checks, URL scanning services, sandbox detonation reports, or any workflow involving programmatic interaction with VirusTotal's threat intelligence platform — even if they don't say "API" explicitly.
-
waittim Bundle Memory CustodianUse when a project contains docs/memory/, or when the user asks to remember, retrieve, update, compact, forget, or audit project memory. MemoryCustodian manages local plain-text project memory with minimal context loading.
-
wallmage Bundle Repo ScoutAudit an open-source repository and return an INSTALL / SKIP verdict. Use only when the user explicitly invokes `$repo-scout` or explicitly names Repo Scout and asks to use it. Never auto-trigger for repository URLs, project websites, package pages, comparisons, installation requests, `/plugin install`, or shell commands.
-
incogbyte Bundle Android Reverse EngineeringDecompile Android APK, XAPK, AAB, DEX, JAR, and AAR files using jadx or Fernflower/Vineflower. Reverse engineer Android apps, extract HTTP API endpoints (Retrofit, OkHttp, Volley, GraphQL, WebSocket), trace call flows from UI to network layer, analyze security patterns (cert pinning, exposed secrets, Android Fragment Injection via exported PreferenceActivity), perform dynamic analysis with Frida (adaptive bypass generation, crash analysis, runtime hooking), and — only when the decompiled app contains Google API keys or Firebase configuration — run a conditional Firebase & Google API testing phase (Auth, Realtime DB, Firestore, Remote Config, Storage, Dynamic Links, FCM, Gemini, Maps). Use when the user wants to decompile, analyze, or reverse engineer Android packages, find API endpoints, follow call flows, audit app security, bypass runtime protections, test exposed Google/Firebase credentials, or check for Fragment Injection exposure.
-
tomevault-io Bundle Go Project Conventions 2Project conventions with module caching, linting, security checks, and tests via Make Use when this capability is needed.
-
tomevault-io Bundle QA 2Quality assurance verification. Checks test coverage against thresholds, validates test quality, identifies E2E/integration gaps, runs security dependency audit, performs static analysis, and generates QA report with quality score. Use when this capability is needed.
-
tomevault-io Bundle Golang 8Go code generation, project layout, naming, style, error handling, testing, concurrency, performance, and security following idiomatic Go conventions Use when this capability is needed.
-
tomevault-io Bundle Audit Docs 2Audit documentation coverage across CLI commands, web features, and configuration. Builds the CLI, discovers all commands/flags, checks web pages, and cross-references against docs/ and apps/docs/. Use when this capability is needed.
-
tomevault-io Bundle Code Review 31Review code for quality, security, performance, and maintainability. Use when reviewing PRs, auditing a codebase, or refactoring. Covers TypeScript, Node.js, infrastructure-as-code, and full-stack web apps. Use when this capability is needed.
-
tomevault-io Bundle Code Reviewer 5Review code for best practices, bugs, and security risks; use for PR reviews, code quality audits, or whenever the user wants feedback. Use when this capability is needed.
-
tomevault-io Bundle Find Bugs 2Find bugs, security vulnerabilities, and code quality issues in local branch changes. Use when asked to review changes, find bugs, security review, or audit code on the current branch. Use when this capability is needed.
-
tomevault-io Bundle Code Review 35Reviews code changes for correctness, security, test coverage, and design quality, producing severity-tagged findings. Supports local changes, specific commits, or GitLab merge requests. Use when user requests a code review, asks to review a diff, branch, commits, or MR — or asks to post, publish, or clean up review findings as inline MR comments. Never pushes to remote; never posts comments without user approval. Use when this capability is needed.
-
tomevault-io Bundle Security 4Security audits and secure coding. Use for vulnerability detection or auth implementation. Use when this capability is needed.
-
tomevault-io Bundle Code Review 37Brutally honest code review assessing security, reliability, performance, and taste Use when this capability is needed.
-
tomevault-io Bundle Docs Check 2Validate documentation freshness, completeness, and quality against the current codebase state. This skill should be used when users want to check documentation health, find stale docs, detect hallucinations in documentation, or audit documentation quality. Use when this capability is needed.
-
tomevault-io Bundle Oss Ready 2Transform projects into professional open-source repositories with standard components. Use when users ask to "make this open source", "add open source files", "setup OSS standards", "create contributing guide", "add license", "prepare for public release", "add CODE_OF_CONDUCT", "add SECURITY.md", "GitHub templates", or want to prepare a project for public release with README, CONTRIBUTING, LICENSE, and GitHub templates. Trigger this skill whenever the user mentions open-sourcing, public repos, community standards, or making a project contribution-ready — even if they just say "let's open source this". Use when this capability is needed.
-
tomevault-io Bundle Code Review 11Performs thorough code reviews with focus on best practices, security, performance, and maintainability. Use this skill when reviewing pull requests, auditing code quality, or getting feedback on implementations. Use when this capability is needed.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include t-wiki, optimize-images, troubleshooting-it-issues. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.