Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
tomevault-io Bundle Code Reviewer 29Reviews code for quality, security, and best practices Use when this capability is needed.
-
tomevault-io Bundle Code Analysis 2Code review and debugging assistant. Identifies bugs, performance issues, security vulnerabilities, and suggests optimizations. Use when this capability is needed.
-
tomevault-io Bundle Security Audit 8Réalise un audit de sécurité complet d'un projet en orchestrant secret_scan, dependency_guard et iac_guardrails_scan. Utilise cette skill quand l'utilisateur demande un audit sécurité, une revue de sécurité, ou veut vérifier la posture de sécurité d'un codebase. Use when this capability is needed.
-
tomevault-io Bundle Code Review 174Systematic code review patterns covering security, performance, maintainability, correctness, and testing — with severity levels, structured feedback guidance, review process, and anti-patterns to avoid. Use when reviewing PRs, establishing review standards, or improving review quality. Use when this capability is needed.
-
tomevault-io Bundle Review Code 7Comprehensive code review with language-specific expertise. Use PROACTIVELY after writing code, when reviewing PRs, or for security audits. Analyzes for correctness, security, maintainability, and test coverage. Use when this capability is needed.
-
tomevault-io Bundle Convex Performance Audit 2Audits and optimizes Convex application performance across hot-path reads, write contention, subscription cost, and function limits. Use this skill when a Convex feature is slow or expensive, npx convex insights shows high bytes or documents read, OCC conflict errors or mutation retries appear, subscriptions or UI updates are costly, functions hit execution or transaction limits, or the user mentions performance, latency, read amplification, or invalidation problems in a Convex app. Use when this capability is needed.
-
tomevault-io Bundle Commit Push Pr 2Commit changes, push to GitHub, and open a PR. Includes quality checks (security, patterns, simplification). Use --quick to skip checks. Use when this capability is needed.
-
tomevault-io Bundle Review Security 2Perform comprehensive security review targeting OWASP Top 10 2025 vulnerabilities Use when this capability is needed.
-
tomevault-io Bundle Security Review 11Review code changes for security vulnerabilities against Meridian's security architecture Use when this capability is needed.
-
tomevault-io Bundle Code Review 203Code review standards and checklist. Use when reviewing code, PRs, or implementations for correctness, security, and quality. Use when this capability is needed.
-
tomevault-io Bundle Code Review Expert 2Expert code review of current git changes with a senior engineer lens. Detects SOLID violations, security risks, and proposes actionable improvements. Use when this capability is needed.
-
tomevault-io Bundle Rust Review 3Post-implementation quality review for Rust port slices. Runs the audit-data extractor, then appends one structured row to reviews.jsonl + new rows to findings.jsonl + (if applicable) edits flowcharts.md. Output is data, not prose — every behavioral trace, simplification delta, and finding lands in the audit dashboard. Use after /porting-to-rs completes a slice, or standalone when you want to verify a Rust module's correctness without reading Rust. Use when this capability is needed.
-
tomevault-io Bundle Security Review 13Evaluate code for security vulnerabilities and privacy compliance. Use when reviewing code that handles file input, storage, external APIs, or sensitive data. Use when this capability is needed.
-
tomevault-io Bundle Django Expert 5Expert level Django development focused on production architecture, security hardening, testing excellence, and deployment readiness. Use when this capability is needed.
-
tomevault-io Bundle Code Review 213Review code changes for correctness, maintainability, integration risk, tests, dependencies, and security-relevant regressions. Use this skill whenever the user asks for a code review, PR review, diff review, commit review, staged/working-tree review, or asks "review this", "check my changes", "look over this branch", or "before I merge". Produces evidence-cited findings with verification and concrete fixes. Use when this capability is needed.
-
tomevault-io Bundle Security Scanner 2Scan codebase for security vulnerabilities including secrets, insecure Use when this capability is needed.
-
tomevault-io Bundle Code Reviewer 25Review code for quality, security, and performance with comprehensive Use when this capability is needed.
-
tomevault-io Bundle Code Review 161Code review skill for finding bugs, regressions, risky behavior, missing tests, and maintainability problems in diffs, pull requests, or local changes. Use when the user asks for review, scrutinize, audit, inspect, or feedback on code. Use when this capability is needed.
-
tomevault-io Bundle Android 2Skills for Android application security testing including APK analysis, static/dynamic analysis, and exploitation. Use when this capability is needed.
-
tomevault-io Bundle Docs Sync 4Analyze main branch implementation and configuration to find missing, incorrect, or outdated documentation in docs/. Use when asked to audit doc coverage, sync docs with code, or propose doc updates/structure changes. Only update English docs (docs/src/content/docs/**) and never touch translated docs under docs/src/content/docs/ja, ko, or zh. Provide a report and ask for approval before editing docs. Use when this capability is needed.
-
tomevault-io Bundle Pr Review 16This skill should be used when the user asks to "review a PR", "review pull request", "check this PR", "look at this PR", "is this PR ready to merge", "PRレビューして", "PRをレビュー", "PR見て", "コードレビュー", or when performing automated or manual code reviews on GitHub pull requests. Provides a structured, incremental review workflow with security checks, file prioritization, and merge readiness assessment. Use when this capability is needed.
-
tomevault-io Bundle Security Scan 5Scan code content for CWE-22 (path traversal) and CWE-78 (command injection) vulnerabilities before PR submission. Lightweight pattern-based detection for Python, PowerShell, Bash, and C# files. Use when preparing code for review or as a pre-commit gate. Use when this capability is needed.
-
tomevault-io Bundle Code Review 166Review code changes for correctness, test coverage, security, performance, and maintainability Use when this capability is needed.
-
tomevault-io Bundle Code Review 169Comprehensive code review assistant that analyzes code quality, security, and best practices Use when this capability is needed.
-
tomevault-io Bundle Code Review 170Comprehensive code review for pull requests and commits. Reviews code against associated stories/tasks, checks naming conventions, linting, clean code practices, readability, maintainability, and security vulnerabilities (OWASP). Provides constructive feedback with explanations. Use when reviewing code, analyzing PRs, checking commits, or validating implementations against requirements. Use when this capability is needed.
-
tomevault-io Bundle Security Review 12Perform enterprise security review of the codebase Use when this capability is needed.
-
tomevault-io Bundle Pump Testing 2Multi-language test infrastructure for the Pump SDK — Rust unit/integration/security/performance tests, TypeScript Jest tests, Python fuzz tests, shell test orchestration, Criterion benchmarks, and CI quality gates. Use when this capability is needed.
-
tomevault-io Bundle Code Review 206AI-powered code review focusing on bugs, security, and performance Use when this capability is needed.
-
tomevault-io Bundle Code Review 207Review code for bugs, security issues, performance problems, and best practices. Provide actionable feedback. Use when this capability is needed.
-
tomevault-io Bundle Security Audit 10Comprehensive security audit checklist covering OWASP Mobile Top 10, PII protection, GDPR compliance, and Firestore security rules for the One By Two app. Use when this capability is needed.
-
tomevault-io Bundle Run Tests 13Run the full test suite with linting, type checking, and code quality audit Use when this capability is needed.
-
tomevault-io Bundle QA Expert 2This skill should be used when establishing comprehensive QA testing processes for any software project. Use when creating test strategies, writing test cases following Google Testing Standards, executing test plans, tracking bugs with P0-P4 classification, calculating quality metrics, or generating progress reports. Includes autonomous execution capability via master prompts and complete documentation templates for third-party QA team handoffs. Implements OWASP security testing and achieves 90% coverage targets. Use when this capability is needed.
-
tomevault-io Bundle Reviewer 4Reviewer Role - Responsible for code audit, architecture compliance checking, and feedback Use when this capability is needed.
-
tomevault-io Bundle Reviewer 5Activate when reviewing code, before committing, after committing, or before merging a PR. Activate when user asks to review, audit, check for security issues, or find regressions. Analyzes code for logic errors, regressions, edge cases, security issues, and test gaps. Fixes findings AUTOMATICALLY. Required at process skill quality gates. Use when this capability is needed.
-
tomevault-io Bundle Code Review 180Review code changes between commits for security, logic, performance, and style issues Use when this capability is needed.
-
tomevault-io Bundle Code Reviewer 26Code review workflow for local changes and remote PRs. Reviews focus on correctness, maintainability, security, and test coverage with concrete examples and inline comments. Use when this capability is needed.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include code-reviewer, code-analysis, security-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.