Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
tomevault-io Bundle Security Documentation 2ISMS security documentation standards for Hack23 projects Use when this capability is needed.
-
tomevault-io Bundle Generate Sandbox Policy 3Generate sandbox security policies from plain-language requirements and optional REST API documentation. At minimum, takes API host:port endpoints and intent to produce preset-based or L4 policies. With full API docs (OpenAPI, Swagger, markdown), generates fine-grained per-endpoint L7 rules. Trigger keywords - generate policy, create policy, update policy, change policy, sandbox policy, network policy, API policy, security policy, allow API, restrict API. Use when this capability is needed.
-
tomevault-io Bundle Python 14Backend services development with Python emphasizing security, performance, and maintainability for JARVIS AI Assistant Use when this capability is needed.
-
tomevault-io Bundle Security Review 23Security-focused code reviewer specializing in OWASP Top 10 vulnerabilities for Chrome extensions. Use when reviewing code changes for security issues, auditing the extension, or adding new features that handle user input, network requests, or cross-context messaging. Use when this capability is needed.
-
tomevault-io Bundle Code Review Checklist 4Code review guidelines covering code quality, security, and best practices. Use when this capability is needed.
-
tomevault-io Bundle Security Best Practices 4Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks. Use when this capability is needed.
-
tomevault-io Bundle Smart Contract Security Review 2Security review for Scalus/Cardano smart contracts. Analyzes @Compile annotated validators for vulnerabilities like redirect attacks, inexact value validation, missing token verification, integer overflow, and self-dealing. Use when reviewing on-chain code, before deploying validators, or when /security-review is invoked. Requires explicit path argument. Use when this capability is needed.
-
tomevault-io Bundle Incident Response 2Incident response is a systematic approach to handling security breaches Use when this capability is needed.
-
tomevault-io Bundle Code Reviewer 55Comprehensive code review workflow for TypeScript, JavaScript, Python, Swift, Kotlin, and Go. Use when reviewing pull requests or local diffs, providing code feedback, identifying bugs/performance issues, checking best practices, security risks, and generating structured review checklists/reports. Includes scripts to analyze git diffs, scan for common issues, and output a review report. Use when this capability is needed.
-
tomevault-io Bundle Senior Security 3Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing. Includes security assessment tools, threat modeling, crypto implementation, and security automation. Use when designing security architecture, conducting penetration tests, implementing cryptography, or performing security audits. Use when this capability is needed.
-
tomevault-io Bundle Pattern Analysis 2Audit codebase patterns and conventions, evaluate proposed changes for consistency Use when this capability is needed.
-
tomevault-io Bundle Security Review 22Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
-
tomevault-io Bundle Code Review Checklist 3Systematic code review checklist for quality, security, and maintainability Use when this capability is needed.
-
tomevault-io Bundle Static Analysis 3Expertise in LLVM-based static analysis including dataflow analysis, pointer analysis, taint tracking, and program verification. Use this skill when implementing security scanners, bug finders, code quality tools, or performing program analysis research. Use when this capability is needed.
-
tomevault-io Bundle Security Analysis 2Comprehensive security analysis with tech stack detection, vulnerability scanning, and remediation planning Use when this capability is needed.
-
tomevault-io Bundle Code Review Checklist 5Structured code review criteria for pre-implementation plan review (Critic) and post-implementation security/quality review. Covers security, performance, maintainability, and correctness with severity ratings. Use when this capability is needed.
-
tomevault-io Bundle Log Analyzer 4智能日志分析工具,帮助快速定位应用错误和性能瓶颈 Use when this capability is needed.
-
tomevault-io Bundle Fastapi 25REST API and WebSocket development with FastAPI emphasizing security, performance, and async patterns Use when this capability is needed.
-
tomevault-io Bundle Search Knowledge 2Deep Python knowledge for code reviews. Provides detailed guidance on iterables, data structures, standard library, validation, testing, concurrency, APIs, and security. Use when this capability is needed.
-
tomevault-io Bundle Healthkit Sync 2iOS HealthKit data sync CLI commands and patterns. Use when working with healthsync CLI, fetching Apple Health data (steps, heart rate, sleep, workouts), pairing iOS devices over local network, or understanding the HealthSync Helper App project architecture including mTLS certificate pinning, Keychain storage, and audit logging. Use when this capability is needed.
-
tomevault-io Bundle Code Review 299Perform a maximally picky and professional code review of recent changes. Reviews all code added since the last review, checking for thread safety, async safety, security vulnerabilities, data integrity, test quality, and code smells. Use before committing significant changes. Use when this capability is needed.
-
tomevault-io Bundle Web Performance Audit 2Web performance audits with Core Web Vitals, bottleneck identification, optimization recommendations. Use for page load times, performance reviews, UX optimization, or encountering LCP, FID, CLS issues, resource blocking, render delays. Use when this capability is needed.
-
tomevault-io Bundle Codex Orchestrator 2Orchestrate OpenAI Codex CLI with specialized subagents for code review, debugging, architecture analysis, security audits, refactoring, and documentation. This skill should be used when delegating focused development tasks to Codex subagents (gpt-5.4, gpt-5.4-pro, gpt-5-mini) via AGENTS.md persona injection. Use when this capability is needed.
-
tomevault-io Bundle Security Specialist 2Auditing for unsafe code and secrets. Use when this capability is needed.
-
tomevault-io Bundle Env Localctl 2Bootstrap, diagnose (doctor), and reconcile local dev environment from env contract/values/secret refs; generate .env.local and redacted docs/context/env/effective-*. Use when local env is broken or needs syncing. Use when this capability is needed.
-
tomevault-io Bundle Security Checklist 5Use this skill when implementing security measures or conducting security audits. Provides OWASP Top 10 mitigations, authentication patterns, input validation strategies, and compliance guidelines. Ensures applications are secure against common vulnerabilities.
-
tomevault-io Bundle Webapp Testing 39Web application testing principles. E2E, Playwright, deep audit strategies. Use when this capability is needed.
-
tomevault-io Bundle Generate Sandbox Policy 4Generate sandbox security policies from plain-language requirements and optional REST API documentation. At minimum, takes API host:port endpoints and intent to produce preset-based or L4 policies. With full API docs (OpenAPI, Swagger, markdown), generates fine-grained per-endpoint L7 rules. Trigger keywords - generate policy, create policy, update policy, change policy, sandbox policy, network policy, API policy, security policy, allow API, restrict API. Use when this capability is needed.
-
tomevault-io Bundle Security Patterns 7Implements authentication, authorization, encryption, secrets management, and security hardening patterns. Use when designing auth flows, managing secrets, configuring CORS, implementing rate limiting, or when asked about JWT, OAuth, password hashing, API keys, RBAC, or security best practices. Use when this capability is needed.
-
tomevault-io Bundle Code Quality 25Maintain high code quality through formatting, linting, and static analysis. Use code-quality skill and scripts for rustfmt, clippy, or cargo audit. Use when this capability is needed.
-
tomevault-io Bundle Code Reviewer 59Automatic code quality and best practices analysis. Use proactively when files are modified, saved, or committed. Analyzes code style, patterns, potential bugs, and security basics. Triggers on file changes, git diff, code edits, quality mentions. Use when this capability is needed.
-
tomevault-io Bundle Review Changes 4Review uncommitted code changes for bugs, security vulnerabilities, and quality issues. Use before commits or when asked to review code. Use when this capability is needed.
-
tomevault-io Bundle Code Formatter 6This skill should be used when the user asks to "format code", "prettify code", "fix indentation", or "standardize code style". It provides guidance on formatting code consistently. Use when this capability is needed.
-
tomevault-io Bundle Security Auditor 5Security vulnerability scanner and OWASP compliance auditor for codebases. Dependency scanning (npm audit, pip-audit), secret detection (high-entropy strings, API keys), SAST for injection/XSS Use when this capability is needed.
-
tomevault-io Bundle Pentest Checklist 2This skill should be used when the user asks to "plan a penetration test", "create a security assessment checklist", "prepare for penetration testing", "define pentest scope", "follow security testing best practices", or needs a structured methodology for penetration testing engagements. Use when this capability is needed.
-
tomevault-io Bundle Audit Trail Design 2Audit logging design with event catalogs, log schemas, and retention policies Use when this capability is needed.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include security-documentation, generate-sandbox-policy, python. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.