Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
tomevault-io Bundle Code Review 13Structured code review covering style, readability, and security concerns with actionable feedback. Use when reviewing pull requests or merge requests to identify issues and suggest improvements. Use when this capability is needed.
-
tomevault-io Bundle Design 6This skill makes technical decisions for complex problems. Use when the "how" IS the problem - algorithms, data structures, system boundaries, performance, security. Triggers include "design this", "what's the algorithm for", "how should this work technically", "technical approach for", "architecture for". Use when this capability is needed.
-
tomevault-io Bundle Review 16Review current code changes for bugs, style issues, and security concerns Use when this capability is needed.
-
tomevault-io Bundle Code Reviewer 4Perform comprehensive code reviews with focus on correctness, performance, security, and maintainability. Use when reviewing pull requests, merge requests, or code changes. Use when this capability is needed.
-
tomevault-io Bundle Ship 4Ship current branch — CI, SonarCloud, code review, security review, fix all issues, merge. Assumes code is already committed and pushed. Use when this capability is needed.
-
tomevault-io Bundle Security 2Security review process and vulnerability prevention. Use when reviewing code for security issues, implementing authentication or authorization, handling user input or secrets, adding API endpoints, or approving code that touches security boundaries. Also use for OWASP Top 10 analysis, secret scanning, dependency auditing, or when code handles forms, file uploads, sessions, tokens, database queries, or shell commands. Essential when someone says 'it's just a small change. Use when this capability is needed.
-
tomevault-io Bundle Fastapi 4Security testing playbook for FastAPI applications covering ASGI, dependency injection, and API vulnerabilities Use when this capability is needed.
-
tomevault-io Bundle GRAPHQL 5GraphQL security testing covering introspection, resolver injection, batching attacks, and authorization bypass Use when this capability is needed.
-
tomevault-io Bundle Code Review 4This skill should be used when a user asks for a code review, feedback on a PR or MR, diff assessment, or says things like 'can you review my changes', 'look at this diff', 'is this ready to merge', 'check my code', 'review this branch', 'what do you think of these changes', or 'LGTM check'. Covers correctness, tests, performance, security, and architecture feedback on pull/merge requests or raw diffs from any platform (GitHub, GitLab). Use when this capability is needed.
-
tomevault-io Bundle Security 3Application security - OWASP, validation, secrets. Use when securing the app. Use when this capability is needed.
-
tomevault-io Bundle Release 20This skill should be used when the user asks to "release a project", "create a release", "bump version", "publish to GitHub", "prepare a release", "run release validation", or needs to perform SDLC-compliant releases for Claude Code plugins, Python, Node.js, Go, or Rust projects. Provides comprehensive pre-release validation including tests, lint, coverage, and security checks. Use when this capability is needed.
-
tomevault-io Bundle Go Project Conventions 3Project conventions with module caching, linting, security checks, and tests via Make Use when this capability is needed.
-
tomevault-io Bundle GRAPHQL 3Design GraphQL schemas and resolvers with proper performance, security, and error handling. Use when this capability is needed.
-
tomevault-io Bundle Camsnap 2Capture frames or clips from RTSP/ONVIF cameras. Grabs snapshots, video clips, and motion events from IP cameras, security cameras, and video streams. Use when the user wants to take a snapshot from a camera, record a clip from an RTSP stream, monitor motion on a security camera, discover ONVIF devices on the network, or configure camera access for automated surveillance capture. Use when this capability is needed.
-
tomevault-io Bundle Code Reviewer 7Performs comprehensive code reviews with security, quality, and best practice checks Use when this capability is needed.
-
tomevault-io Bundle Fabric 3Native Fabric pattern execution for Claude Code. USE WHEN processing content with Fabric patterns (extract_wisdom, summarize, analyze_claims, threat modeling, etc.). Patterns run natively in Claude's context - no CLI spawning needed. Only use fabric CLI for YouTube transcripts (-y) or pattern updates (-U). Use when this capability is needed.
-
tomevault-io Bundle Code Review 51Perform comprehensive code reviews focusing on best practices, security vulnerabilities, performance optimization, and maintainability Use when this capability is needed.
-
tomevault-io Bundle Code Review 55Review staged git changes for security, quality, performance, and project conventions Use when this capability is needed.
-
tomevault-io Bundle Tauri 3Expert guide and best practices for building secure, cross-platform applications with Tauri v2. Covers capability-based security, plugin architecture, build optimization, and performance patterns. Use when this capability is needed.
-
tomevault-io Bundle Code Review 57Expert code review specialist. Use when reviewing code for quality, security, maintainability, or when examining recent changes Use when this capability is needed.
-
tomevault-io Bundle Analyze 5Systematic multi-step codebase analysis producing prioritized findings with file-line evidence. Covers architecture reviews, security assessments, and code quality evaluations through guided exploration, investigation planning, and synthesis. Use when this capability is needed.
-
tomevault-io Bundle Code Reviewer 6Comprehensive code review skill for TypeScript, JavaScript, Python, Swift, Kotlin, Go. Includes automated code analysis, best practice checking, security scanning, and review checklist generation. Use when reviewing pull requests, providing code feedback, identifying issues, or ensuring code quality standards. Use when this capability is needed.
-
tomevault-io Bundle Healthcheck 3Host security hardening and risk-tolerance configuration for Razroom deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, Razroom cron scheduling for periodic checks, or version status checks on a machine running Razroom (laptop, workstation, Pi, VPS). Use when this capability is needed.
-
tomevault-io Bundle Code Review 46Use when user asks to review code for quality and security issues.
-
tomevault-io Bundle Security Audit 4Use when performing security reviews or hardening an application. Covers OWASP top 10 mitigations, input validation, injection prevention, authentication, secrets management, and dependency scanning.
-
tomevault-io Bundle Code Review 47Provides comprehensive code review covering 6 focused aspects - architecture & design, code quality, security & dependencies, performance & scalability, testing coverage, and documentation & API design. Use this skill for deep analysis with actionable feedback after significant code changes.
-
tomevault-io Bundle Analyze 4Analyze codebase for bugs, debt, documentation, security, or style issues Use when this capability is needed.
-
tomevault-io Bundle Healthcheck 2Host security hardening and risk-tolerance configuration for Otto deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, Otto cron scheduling for periodic checks, or version status checks on a machine running Otto (laptop, workstation, Pi, VPS). Use when this capability is needed.
-
tomevault-io Bundle Django 5Django framework best practices including project structure, ORM, and security. Use when this capability is needed.
-
tomevault-io Bundle Code Review 19Use when user asks for review, audit, risks, bugs, or missing tests.
-
tomevault-io Bundle HallmarkAnti-AI-slop design skill for greenfield pages, audits, redesigns, and design extraction from URLs or screenshots. Use when the user asks to build a new app or landing page, wants to redesign something, invokes Hallmark by name, or uses audit/redesign/study. Use when this capability is needed.
-
tomevault-io Bundle Code Review 22Review code for bugs, security issues, performance problems, and best practices. Provide actionable feedback. Use when this capability is needed.
-
tomevault-io Bundle Core 2Core development principles and guidelines covering security, QA, performance, documentation, and coding standards. Used by all agents to ensure consistent quality across the Orchestra system. Use when this capability is needed.
-
tomevault-io Bundle Code Reviewer 3Review code for best practices, bugs, and security issues. Use when this capability is needed.
-
tomevault-io Bundle Codeql 3Run CodeQL static analysis for security vulnerability detection, taint tracking, and data flow analysis. Use when asked to scan code with CodeQL, write QL queries, perform deep interprocedural analysis, or integrate with GitHub Advanced Security. Use when this capability is needed.
-
tomevault-io Bundle Review 10Code review and security audit Use when this capability is needed.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include code-review, design, review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.