Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
tomevault-io Bundle Django Perf Review 4Django performance code review. Use when asked to "review Django performance", "find N+1 queries", "optimize Django", "check queryset performance", "database performance", "Django ORM issues", or audit Django code for performance problems. Use when this capability is needed.
-
tomevault-io Bundle Code Review 263Use when code has been written and needs validation before committing, or when the user asks for a code review or security check.
-
tomevault-io Bundle Code Review 264Perform code reviews following Sentry engineering practices. Use when reviewing pull requests, examining code changes, or providing feedback on code quality. Covers security, performance, testing, and design review. Use when this capability is needed.
-
tomevault-io Bundle Performance 10Optimize web performance for faster loading and better user experience. Use when asked to "speed up my site", "optimize performance", "reduce load time", "fix slow loading", "improve page speed", or "performance audit". Use when this capability is needed.
-
tomevault-io Bundle Security Patterns 6Security vulnerability detection patterns including OWASP Top 10, language-specific vulnerabilities, and remediation guidance. Load when reviewing code for security issues, conducting audits, or implementing authentication/authorization. Use when this capability is needed.
-
tomevault-io Bundle Code Review 278Thorough code review practices and checklists. Covers security review, performance analysis, maintainability assessment, and constructive feedback. Use when reviewing PRs, auditing code quality, or establishing review standards. Use when this capability is needed.
-
tomevault-io Bundle Code Reviewer 52Reviews code for bugs, security vulnerabilities, and quality issues. MUST be invoked automatically after completing a coding task (feature, bug fix, or refactor) - do not wait for user to request it. Use when this capability is needed.
-
tomevault-io Bundle Audit 10Run security audit on code for OWASP Top 10, CWE vulnerabilities, and security anti-patterns Use when this capability is needed.
-
tomevault-io Bundle Senior Backend 6Designs and implements backend systems including REST APIs, microservices, database architectures, authentication flows, and security hardening. Use when the user asks to "design REST APIs", "optimize database queries", "implement authentication", "build microservices", "review backend code", "set up GraphQL", "handle database migrations", or "load test APIs". Covers Node.js/Express/Fastify development, PostgreSQL optimization, API security, and backend architecture patterns. Use when this capability is needed.
-
tomevault-io Bundle Code Review Expert 4Expert code review of current git changes. SOLID, security, performance, error handling, boundary conditions. Senior engineer lens. Use when this capability is needed.
-
tomevault-io Bundle Security Hardening 2Review code for application-level security hardening issues beyond framework checklists. Focuses on abuse prevention, API protection, business logic exploitation, rate limiting, input validation, and early request rejection. Use when auditing code for security, reviewing endpoints for abuse potential, or checking application resilience to real-world attacks. Use when this capability is needed.
-
tomevault-io Bundle Code Reviewer 54Comprehensive code review skill for TypeScript, JavaScript, Python, Swift, Kotlin, Go. Includes automated code analysis, best practice checking, security scanning, and review checklist generation. Use when reviewing pull requests, providing code feedback, identifying issues, or ensuring code quality standards. Use when this capability is needed.
-
tomevault-io Bundle Senior Secops 3Comprehensive SecOps skill for application security, vulnerability management, compliance, and secure development practices. Includes security scanning, vulnerability assessment, compliance checking, and security automation. Use when implementing security controls, conducting security audits, responding to vulnerabilities, or ensuring compliance requirements. Use when this capability is needed.
-
tomevault-io Bundle Platform Audit 2Platform guideline compliance audit across iOS, Android, and web Use when this capability is needed.
-
tomevault-io Bundle Update Packages 2Use this skill when the user asks to "update packages", "upgrade dependencies", "fix vulnerabilities", "run audit", "update deps", or mentions outdated packages in this Backstage plugin project. Handles security vulnerability fixes, Backstage-compatible package upgrades, and verification.
-
tomevault-io Bundle Documentation Standards 9Enforces consistent documentation standards for Black Trigram — JSDoc/TSDoc completeness, architecture currency, bilingual Korean-English content, and security documentation updates Use when this capability is needed.
-
tomevault-io Bundle Nodejs Best Practices 2Node.js 22+ production mastery. ES Modules, async patterns, Express/Fastify/Hono, middleware architecture, error handling, streaming, worker threads, environment config, security hardening, process management, and deployment patterns. Use when building Node.js servers, APIs, CLI tools, or any server-side JavaScript. Use when this capability is needed.
-
tomevault-io Bundle Security Engineer 2Activate when user needs security work - vulnerability assessment, security architecture, compliance audits, penetration testing. Activate when the security-engineer skill is requested or work requires security review. Use when this capability is needed.
-
tomevault-io Bundle Generate Sandbox Policy 2Generate sandbox security policies from plain-language requirements and optional REST API documentation. At minimum, takes API host:port endpoints and intent to produce preset-based or L4 policies. With full API docs (OpenAPI, Swagger, markdown), generates fine-grained per-endpoint L7 rules. Trigger keywords - generate policy, create policy, update policy, change policy, sandbox policy, network policy, API policy, security policy, allow API, restrict API. Use when this capability is needed.
-
tomevault-io Bundle Code Review Checklist 2Code review guidelines covering code quality, security, and best practices. Use when this capability is needed.
-
tomevault-io Bundle Code Review 288Perform thorough code reviews with security, performance, and maintainability analysis. Use when user asks to review code, check for bugs, or audit a codebase. Use when this capability is needed.
-
tomevault-io Bundle Analyze 12Analyze entire codebases using Gemini CLI's 1M token context. Generates architecture reports covering structure, security, performance, and improvement roadmaps. Use when auditing code quality or running /analyze. Use when this capability is needed.
-
tomevault-io Bundle Container Security 2Container security hardening for RabbitMQ deployment with Podman Use when this capability is needed.
-
tomevault-io Bundle Security Engineer 3Implement security best practices across the application stack. Use when securing APIs, implementing authentication, preventing vulnerabilities, or conducting security reviews. Covers OWASP Top 10, auth patterns, input validation, encryption, and security monitoring. Use when this capability is needed.
-
tomevault-io Bundle Code Reviewer 50Review code for correctness, maintainability, performance, and security. Produce actionable, prioritized feedback and concrete fixes aligned with repo standards. Use when this capability is needed.
-
tomevault-io Bundle Audit 8Comma-separated list of audit types (e.g., 'dead-code,pii,soc2') or 'all'. If omitted, you will be asked. Use when this capability is needed.
-
tomevault-io Bundle Security 22API security expertise including authentication, authorization, OWASP compliance, and vulnerability detection. Use when this capability is needed.
-
tomevault-io Bundle Prepare Pr 4Prepares code for a pull request by running linting (ruff), tests, security scans (bandit), and dependency checks (pip-audit). Use when ready to create a PR or before committing changes. Use when this capability is needed.
-
tomevault-io Bundle Code Review 272Perform thorough code reviews with security, performance, and maintainability analysis. Use when user asks to review code, check for bugs, or audit a codebase. Use when this capability is needed.
-
tomevault-io Bundle Code Review 274Review code changes for security, architecture, and quality issues. Use for deep PR-level review — checks OWASP vulnerabilities, hexagonal architecture violations, code smells, and test gaps. For a quick architecture-only check, use /check-architecture instead. Use when this capability is needed.
-
tomevault-io Bundle Security Check 5Assess token and address security via the GoPlus Security API. Use when this capability is needed.
-
tomevault-io Bundle GRAPHQL Security 2Detects GraphQL schemas without depth limits, cost analysis, or introspection Use when this capability is needed.
-
tomevault-io Bundle Code Review 275Review Python code for quality, security, and best practices Use when this capability is needed.
-
tomevault-io Bundle Code Review 276Perform thorough code reviews checking for security vulnerabilities, error handling, test coverage, performance issues, and proper logging. Use when this capability is needed.
-
tomevault-io Bundle Performance Audit 5Audit application code for performance issues including N+1 queries, bundle size, caching, lazy loading, and connection pooling. Use when this capability is needed.
-
tomevault-io Bundle Security Reviewer 3Audit memory safety and security in unsafe code blocks, buffer handling, and security-sensitive operations Use when this capability is needed.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include django-perf-review, code-review, code-review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.