Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
tomevault-io Bundle Django Expert 4Robust Python web development with Django. ORM mastery, DRF patterns, security, and project structure. Use when this capability is needed.
-
tomevault-io Bundle The Fool 2Use when challenging ideas, plans, decisions, or proposals using structured critical reasoning. Invoke to play devil's advocate, run a pre-mortem, red team, or audit evidence and assumptions.
-
tomevault-io Bundle Verification Loop 26フェーズ検証ループ(Build→Type→Lint→Test→Security→Diff)でPRレディネスを判定。 Use when this capability is needed.
-
tomevault-io Bundle Test Review 2Review test quality and audit test coverage for any module. This skill should be used when reviewing existing tests, auditing test gaps, writing new tests, or when asked to assess test health. It pipelines testing standards into the audit workflow to produce a prioritized gap report. The output is a report, not code — do not write test implementations until the report is reviewed. Use when this capability is needed.
-
tomevault-io Bundle Django Security 5Applies Django security patterns for auth, CSRF, XSS, and deployment. Use when this capability is needed.
-
tomevault-io Bundle Code Review 192Review code changes for correctness, security, test coverage, and style. Use when this capability is needed.
-
tomevault-io Bundle Iotnet 2IoT network traffic analyzer for detecting IoT protocols and identifying security vulnerabilities in network communications. Use when you need to analyze network traffic, identify IoT protocols, or assess network security of IoT devices. Use when this capability is needed.
-
tomevault-io Bundle Review Code 9Reviews current git changes with a senior engineer lens. Detects SOLID violations, YAGNI/DRY/KISS breaches, security risks, performance issues, and proposes actionable improvements. Use when reviewing pull requests, checking code quality before merging, or auditing changes for security vulnerabilities. Use when this capability is needed.
-
tomevault-io Bundle Code Reviewer 30Automated code review with best practices, security checks, and quality standards. Use when this capability is needed.
-
tomevault-io Bundle Code Review 193Review completed changes for blockers, regressions, security, and scope drift. Use with /code-review before merge or final handoff. Use when this capability is needed.
-
tomevault-io Bundle Security Review 8Review Dart FFI code for security issues in cryptographic contexts. Use when reviewing code changes, checking for memory leaks, verifying secure memory handling, or auditing cryptographic code. Use when this capability is needed.
-
tomevault-io Bundle Security Review 9Thorough, adversarial security review of API endpoints, UI flows that call those endpoints, and any database-interacting code. Use when the user asks for a security review, permission/authorization audit, red-team style assessment, or vulnerability analysis. Assume access to source code and a running system; perform threat modeling and check current vulnerabilities relevant to the stack. Use when this capability is needed.
-
tomevault-io Bundle Code Reviewer 32Reviews code changes in pull requests for the Morphir Moonbit monorepo. Checks for code quality, best practices, security issues, and adherence to project conventions. Use when reviewing PRs or code changes before merging. Use when this capability is needed.
-
tomevault-io Bundle Django Perf Review 2Django performance code review. Use when asked to "review Django performance", "find N+1 queries", "optimize Django", "check queryset performance", "database performance", "Django ORM issues", or audit Django code for performance problems. Use when this capability is needed.
-
tomevault-io Bundle Security Audit 9Comprehensive security audit covering OWASP Top 10, input validation, authentication, authorization, secret management, dependency vulnerabilities, and injection attack prevention. Use when reviewing security posture, implementing auth flows, handling user input, auditing dependencies, conducting penetration test prep, or before production deployment. Use when this capability is needed.
-
tomevault-io Bundle Code Review 215Automated code review for pull requests using specialized review patterns. Analyzes code for quality, security, performance, and best practices. Use when reviewing code changes, PRs, or doing code audits. Use when this capability is needed.
-
tomevault-io Bundle Healthcheck 10Host security hardening and risk-tolerance configuration for text2llm deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, text2llm cron scheduling for periodic checks, or version status checks on a machine running text2llm (laptop, workstation, Pi, VPS). Use when this capability is needed.
-
tomevault-io Bundle Verification Gates 2Creates explicit validation checkpoints (verification gates) between project phases to catch errors early and ensure quality before proceeding. Use when the user asks about quality gates, milestone checks, phase transitions, approval steps, go/no-go decision points, or preventing cascading errors across a multi-step workflow. Produces acceptance criteria checklists, automated CI gate configurations, manual sign-off requirements, and conditional review rules for scenarios such as security changes, API changes, or database migrations.
-
tomevault-io Bundle Plugin Dev 4Validate plugin SKILL.md frontmatter and audit hook scripts for silent failures. Run validation to check all plugins pass schema, source path, and frontmatter checks. Run hook audit to detect unhandled errors in shell and Python scripts. Use when this capability is needed.
-
tomevault-io Bundle Reviewing Code 8Performs systematic code review checking for correctness, maintainability, security, and best practices. Activates when user requests review, before creating PRs, or when significant code changes are ready. Ensures quality gates are met before code proceeds to production. Use when this capability is needed.
-
tomevault-io Bundle Pr Review 21Review code changes on the current branch for quality, bugs, performance, and security Use when this capability is needed.
-
tomevault-io Bundle Code Review 218Reviews code in this project following security, performance, readability, and testability guidelines. Use when user requests code review, PR review, or asks to check/review code changes. Responds in Japanese when prompted in Japanese, otherwise responds in English. Use when this capability is needed.
-
tomevault-io Bundle Code Reviewer 34Use when asked to review MERN stack code - comprehensive code reviewer that checks project health, security, maintainability, performance, testing, and architecture. Combines general code quality analysis with MERN-specific expertise.
-
tomevault-io Bundle Patch 3Propose a code patch for a finding. Produces a unified diff against the current HEAD plus a short rationale, written back as a finding note so the analyst can review, adjust, and open a PR themselves. The skill never pushes to the remote. Use when this capability is needed.
-
tomevault-io Bundle Review Changes 2Review code changes in a feature branch before merging. Use when asked to review a branch, review changes, check a PR, or audit code before merge. Compares the current branch against the default branch (main/master) and categorizes issues by severity (Critical, Major, Minor) with actionable solutions. Use when this capability is needed.
-
tomevault-io Bundle Chroma 2Comprehensive Chroma skill for designing, implementing, debugging, and operating Chroma-based retrieval systems. Covers collection design, embeddings, filters, ingestion/query workflows, performance, security, and repo-specific guidance for chroma-swift. Use when this capability is needed.
-
tomevault-io Bundle Senior Backend 3Designs and implements backend systems including REST APIs, microservices, database architectures, authentication flows, and security hardening. Use when the user asks to "design REST APIs", "optimize database queries", "implement authentication", "build microservices", "review backend code", "set up GraphQL", "handle database migrations", or "load test APIs". Covers Node.js/Express/Fastify development, PostgreSQL optimization, API security, and backend architecture patterns. Use when this capability is needed.
-
tomevault-io Bundle Code Reviewer 36Systematic code review for quality, correctness, and maintainability. Use when reviewing pull requests, code changes, diffs, or when asked to review/critique code. Also use when user says review this, check my code, any issues with this, PR review, code review, or provides code and asks for feedback. Covers functionality, architecture, performance, security, testing, and documentation with structured feedback using priority prefixes BLOCKING, SUGGESTION, QUESTION, NIT. Do NOT use when user wants to write new code from scratch or needs help debugging runtime errors. Use when this capability is needed.
-
tomevault-io Bundle Code Review 220Perform code reviews following Sentry engineering practices. Use when reviewing pull requests, examining code changes, or providing feedback on code quality. Covers security, performance, testing, and design review. Use when this capability is needed.
-
tomevault-io Bundle Code Reviewer 37Reviews code changes for bugs, security vulnerabilities, and performance issues. Use when this capability is needed.
-
tomevault-io Bundle Patch Diff Analyzer 2Specialized in reverse-engineering compiled binaries (JARs, DLLs). Use this when the user asks to compare versions, find security fixes, or analyze binary patches. Use when this capability is needed.
-
tomevault-io Bundle Security Audit 11Perform comprehensive security audits against OWASP standards. Use when auditing security, checking for vulnerabilities, or reviewing code for security issues. Use when this capability is needed.
-
tomevault-io Bundle Security Checklist 3Use this when performing security review of code, checking for OWASP vulnerabilities
-
tomevault-io Bundle Django Security 7Django security best practices, authentication, authorization, CSRF protection, Use when this capability is needed.
-
tomevault-io Bundle Code Reviewer 39Code review expert. Reviews code quality, security, performance, and conventions. Use for PR reviews, code audits, or quality checks. Responds to "review", "리뷰", "코드 리뷰", "봐줘", "검토", "이거 봐줘", "문제 없어", "코드 검토", "코드 확인", "체크해", "분석해", "code review", "PR review", "audit", "check code", "look at this", "inspect", "analyze" keywords. Use when this capability is needed.
-
tomevault-io Bundle Security Patterns 2brainbaseのセキュリティパターン(XSS Prevention、CSRF Protection、Input Validation)への準拠をチェックし、脆弱性を検出して修正提案する3 Phase Orchestrator Skill。 Use when this capability is needed.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include django-expert, the-fool, verification-loop. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.