Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
tomevault-io Bundle Health Check 2Periodic Codex repo health check orchestrator. Runs CI status, AGENTS.md staleness audit, documentation accuracy audit, and Obsidian Vault sync if present, pausing for approval between steps and producing one consolidated report. Global and project-agnostic. Trigger when the user says "health check", "health-check", "repo health", "check repo health", "repo maintenance", "run a health check", "audit the repo", "check everything", "periodic maintenance", or "check if everything is up to date". SKIP when the user only wants one specific audit. Use when this capability is needed.
-
tomevault-io Bundle Code Review 115Perform thorough code reviews with security, performance, and quality checks. Use when reviewing PRs, auditing code changes, or finding potential bugs. Use when this capability is needed.
-
tomevault-io Bundle Code Review 116Systematic code review process with focus on quality, security, and best practices Use when this capability is needed.
-
tomevault-io Bundle Fabric 4Intelligent pattern selection for Fabric CLI. Automatically selects the right pattern from 242+ specialized prompts based on your intent - threat modeling, analysis, summarization, content creation, extraction, and more. USE WHEN processing content, analyzing data, creating summaries, threat modeling, or transforming text. Use when this capability is needed.
-
tomevault-io Bundle Security Scan 3Deep security analysis of codebase. Scans for secrets, vulnerabilities, and insecure patterns. Use when this capability is needed.
-
tomevault-io Bundle Security Review 4Perform security-focused code review using OWASP guidelines and AI-specific security best practices. Use when this capability is needed.
-
tomevault-io Bundle Code Reviewer 19Performs comprehensive code reviews with security, quality, and best practice checks Use when this capability is needed.
-
tomevault-io Bundle Sonarqube 2Fetch and fix SonarQube code quality issues, coverage metrics, security hotspots, and quality gate status. Use when reviewing SonarQube findings for a project or pull request, checking code coverage, investigating security hotspots, verifying quality gate pass/fail, or searching for SonarQube projects. Use when this capability is needed.
-
tomevault-io Bundle Code Review 145Review Python code for bugs, security issues, and style problems Use when this capability is needed.
-
tomevault-io Bundle Security 14Run security audit with GitLeaks pre-commit hook setup and code analysis Use when this capability is needed.
-
tomevault-io Bundle Second Opinion 2Get multiple AI perspectives (Gemini + Codex) on a question. Use for architectural decisions, security reviews, or when you want validation from other AIs. Use when this capability is needed.
-
tomevault-io Bundle Solidity Auditor 2Professional-grade Solidity smart contract security auditor. Performs comprehensive audits or targeted reviews (security vulnerabilities, gas optimization, storage optimization, code architecture, DeFi protocol analysis). Use this skill when users request smart contract audits, security reviews, vulnerability assessments, gas/storage optimization analysis, code quality reviews, or when analyzing Solidity code for any security or quality concerns. Supports all Solidity versions with version-specific vulnerability detection. Based on OWASP Smart Contract Top 10 (2025) and real-world exploit patterns. Use when this capability is needed.
-
tomevault-io Bundle Code Review 147Use when reviewing code for quality, bugs, security, and maintainability
-
tomevault-io Bundle Code Review 148Review a code snippet for bugs, security issues, and style, with concrete fixes. Use when the user shares code and asks for feedback or a review. Use when this capability is needed.
-
tomevault-io Bundle Meeting Prep 2Prépare un briefing complet avant un rendez-vous prospect. Orchestre TOUS les skills d'intelligence (sirene, scorer, audit-flash, nis2-radar, aides, bodacc) pour produire une fiche synthétique d'une page. Utiliser quand l'utilisateur a un RDV à préparer. Use when this capability is needed.
-
tomevault-io Bundle Nestjs Expert 3Use when building NestJS applications requiring modular architecture, dependency injection, or TypeScript backend development. Invoke for modules, controllers, services, DTOs, guards, interceptors, TypeORM/Prisma, CQRS, advanced DI, security hardening, database patterns.
-
tomevault-io Bundle Template Skill 6Use when working with a template showing the canonical skill structure
-
tomevault-io Bundle Security 16OWASP security patterns, secrets management, security testing Use when this capability is needed.
-
tomevault-io Bundle Review 35Comprehensive code review of recent changes in the iam-policy-validator project. Use when the user wants a code review, quality check, or audit of recent changes. Triggers on "/review", "review my changes", "code review", or "check code quality". Use when this capability is needed.
-
tomevault-io Bundle Security Review 5Comprehensive security audit of SaThuCoin contract, dependencies, deployment scripts, and scraper code. Only invoke manually — never auto-trigger. Use when this capability is needed.
-
tomevault-io Bundle Pr Review 15Use when reviewing a pull request with multi-persona feedback. Spawns sequential sub-agents (Architect, 10x Engineer, Security Expert, Engineering Manager) who post comments to the PR, then interactively lets you choose which fixes to implement.
-
tomevault-io Bundle Code Review 152Review code for quality and security Use when this capability is needed.
-
tomevault-io Bundle Ghost Repo Context 2Scans directory structure, detects projects, maps dependencies, and documents code organization into a repo.md file. Use when the user needs a codebase overview, project structure map, or repository context before security analysis. Use when this capability is needed.
-
tomevault-io Bundle Solidity 2Solidity language and compiler — source layout, types, contracts, control flow, security, compiler, ABI, internals. Use when this capability is needed.
-
tomevault-io Bundle Loop 3Optional review-specific instructions (e.g., 'focus on security', 'this repo uses X pattern') Use when this capability is needed.
-
tomevault-io Bundle Ship 12Ship current branch — CI, code review, security review, fix all issues. Assumes code is already committed and pushed. Use when this capability is needed.
-
tomevault-io Bundle Code Review 159Systematic code review guidance covering best practices, security, performance, and maintainability. Use when reviewing code, checking PRs, or analyzing code quality. Use when this capability is needed.
-
tomevault-io Bundle Performance Audit 3Analyze application performance including bundle sizes, API latency, and database query efficiency. Use when this capability is needed.
-
tomevault-io Bundle Microsoft Docs 3Use official Microsoft documentation to answer questions for TroubleScout (.NET SDK/C#/.NET 10, PowerShell 7.x, Windows Server, WinRM, publishing and security guidance). Use when this capability is needed.
-
tomevault-io Bundle Gemini CLI 6Google Gemini CLI for second opinions, architectural advice, code reviews, security audits. Leverage 1M+ context for comprehensive codebase analysis via command-line tool. Use when this capability is needed.
-
tomevault-io Bundle Best Practices 4Apply modern web development best practices for security, compatibility, and code quality. Use when asked to "apply best practices", "security audit", "modernize code", "code quality review", or "check for vulnerabilities". Use when this capability is needed.
-
tomevault-io Bundle Sandbox 2Execute commands in isolated sandboxes for security. Use when running untrusted code, system commands, or operations that could affect the host system. Automatically detects the right runtime (Python, Node, Rust, Go, Ruby, etc.) from the command. Use when this capability is needed.
-
tomevault-io Bundle Postgres Expert 2Use when optimizing PostgreSQL queries, configuring replication, designing partitioning strategies, hardening security, or implementing advanced database features. Invoke for EXPLAIN analysis, JSONB operations, extension usage, VACUUM tuning, transaction isolation, performance monitoring.
-
tomevault-io Bundle Auditor 2Unified financial expertise covering double-entry bookkeeping, bank reconciliation, financial reporting, and audit verification. Use when designing accounting systems, implementing matching algorithms, generating financial statements (Income Statement, Balance Sheet, Cash Flow), or performing financial audits and equation validation. Use when this capability is needed.
-
tomevault-io Bundle Review Code 8Review code changes for quality, security, and adherence to project conventions. Use after making code changes or when reviewing a pull request. Use when this capability is needed.
-
tomevault-io Bundle Coding Standards 7Go coding standards for the AutoCache project (github.com/10yihang/autocache). Use when writing or modifying Go code to stay consistent on project structure, formatting (gofmt/goimports), naming, error handling, concurrency lifecycle, API design, testing, logging, configuration validation, linting, performance, and security. Use when this capability is needed.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include health-check, code-review, code-review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.