Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
tomevault-io Bundle Exploit Development 2PoC development, payload crafting, shellcode generation, ROP chains, heap exploitation, bypass techniques for modern mitigations (ASLR, DEP, CFI, stack canaries) Use when this capability is needed.
-
tomevault-io Bundle Fastapi Patterns 11FastAPI patterns for async APIs, dependency injection, Pydantic request and response models, OpenAPI docs, tests, security, and production readiness. Use when this capability is needed.
-
tomevault-io Bundle Audit Code 2Run a single-session code review audit on the codebase Use when this capability is needed.
-
tomevault-io Bundle Fastapi Patterns 13FastAPI patterns for async APIs, dependency injection, Pydantic request and response models, OpenAPI docs, tests, security, and production readiness. Use when this capability is needed.
-
tomevault-io Bundle Creating Claude Hooks 2Use when creating or publishing Claude Code hooks - covers executable format, event types, JSON I/O, exit codes, security requirements, and PRPM package structure
-
tomevault-io Bundle Test Specialist 2This skill should be used when writing test cases, fixing bugs, analyzing code for potential issues, or improving test coverage for JavaScript/TypeScript applications. Use this for unit tests, integration tests, end-to-end tests, debugging runtime errors, logic bugs, performance issues, security vulnerabilities, and systematic code analysis. Use when this capability is needed.
-
tomevault-io Bundle Reviewing Pull Requests 2Use when user mentions reviewing PRs, provides GitHub PR URLs/numbers, or discusses code review. Provides structured analysis of code quality, backward compatibility, security issues, test coverage, and unaddressed comments with categorized findings (Critical/High/Medium/Low). Creates isolated git worktree for safe review, ensures comprehensive security analysis, and generates actionable recommendations. Invoke before analyzing any pull request changes.
-
tomevault-io Bundle Supabase Patterns 2Generic Supabase best practices for Row Level Security, realtime subscriptions, storage, and edge functions. Framework-agnostic. Use when this capability is needed.
-
tomevault-io Bundle Senior Backend 8This skill should be used when the user asks to "design REST APIs", "optimize database queries", "implement authentication", "build microservices", "review backend code", "set up GraphQL", "handle database migrations", or "load test APIs". Use for Node.js/Express/Fastify development, PostgreSQL optimization, API security, and backend architecture patterns. Use when this capability is needed.
-
tomevault-io Bundle Generate Sandbox Policy 5Generate sandbox security policies from plain-language requirements and optional REST API documentation. At minimum, takes API host:port endpoints and intent to produce preset-based or L4 policies. With full API docs (OpenAPI, Swagger, markdown), generates fine-grained per-endpoint L7 rules. Trigger keywords - generate policy, create policy, update policy, change policy, sandbox policy, network policy, API policy, security policy, allow API, restrict API. Use when this capability is needed.
-
tomevault-io Bundle Code Reviewer 62Research-backed code review skill with OWASP Top 10 security checks, SAST tool integration (SonarQube, CodeQL, Snyk), performance pattern detection, and automated quality standards enforcement. Auto-invoked for code review, security audit, PR analysis, and bug checking. Implements 2025 best practices with 92% faster vulnerability remediation. Use when this capability is needed.
-
tomevault-io Bundle Security Auditor 6Activates when user needs security review, vulnerability scanning, or secure coding guidance. Triggers on "security review", "find vulnerabilities", "is this secure", "check for injection", "security audit", "OWASP", "secure this code", or security-related questions. Use when this capability is needed.
-
tomevault-io Bundle Binary Analysis 2Analyze binary files (exe, dll, sys, bin, ocx, scr, cpl, drv) to assess if they are malicious, perform decompilation, extract strings/imports/exports, detect malware, and provide threat assessment. Use this skill when user asks to analyze, examine, check, or assess any binary file, asks if a file is malicious/suspicious/safe, or provides a file path to a binary. Trigger for phrases like "Is [file] malicious?", "Analyze [file]", "What does [binary] do?", or any request involving binary file analysis. Use when this capability is needed.
-
tomevault-io Bundle Code Review Excellence 5This skill should be used when the user asks to review a diff or pull request, write review comments, audit code quality, establish review standards, or improve how a team performs code review. Use when this capability is needed.
-
tomevault-io Bundle Django Security 23Security audit for Django applications including settings.py (SECRET_KEY, DEBUG, ALLOWED_HOSTS), middleware order, ORM raw queries, template autoescape bypass, CSRF protection, Django Admin exposure, authentication backends, file upload handling, and Django-specific patterns. Use this skill whenever the user mentions Django, settings.py, manage.py, Django ORM, Django REST Framework, DRF, makemigrations, urls.py, views.py, or asks "audit my Django app", "Django security review", "Django settings safe". Trigger when the codebase contains `django` in `requirements.txt` / `pyproject.toml`, or `manage.py`, `settings.py`, `urls.py` files. Use when this capability is needed.
-
tomevault-io Bundle Code Review 308Review code for correctness, security, maintainability, and style. Use when reviewing pull requests, examining code changes, or performing code review. Use when this capability is needed.
-
tomevault-io Bundle Code Reviewer 63Comprehensive code review skill for TypeScript, JavaScript, Python, Swift, Kotlin, Go. Includes automated code analysis, best practice checking, security scanning, and review checklist generation. Use when reviewing pull requests, providing code feedback, identifying issues, or ensuring code quality standards. Use when this capability is needed.
-
tomevault-io Bundle Ml Vulnerabilities 2OWASP Machine Learning Top 10 (2023) vulnerability knowledge base for identifying, assessing, and remediating security risks in machine learning systems. Use when this capability is needed.
-
tomevault-io Bundle Github Actions 14Create, configure, and optimize GitHub Actions including action types, triggers, runners, security practices, and marketplace integration Use when this capability is needed.
-
tomevault-io Bundle Verification Loop 8Comprehensive quality verification system for code changes with build, type, lint, test, and security checks Use when this capability is needed.
-
tomevault-io Bundle Performance Audit 7Comprehensive performance audit workflow for web applications Use when this capability is needed.
-
tomevault-io Bundle Security Analysis 3Security vulnerability scanning and OWASP Top 10 compliance checking. Use when reviewing code for security issues, validating authentication/authorization, or ensuring security best practices. Use when this capability is needed.
-
tomevault-io Bundle UI UX Audit 3Mandatory audit workflow for UI/UX changes that reads current state FIRST, checks for redundancy, respects clean design philosophy, and identifies genuine gaps before implementation. Auto-invoked when user mentions UI, UX, design, layout, homepage, page improvements, visual changes, or interface modifications. Use when this capability is needed.
-
tomevault-io Bundle Code Review Checklist 6Use when performing cross-project code review, PR review, diff review, bug-risk assessment, regression review, C++ review, API review, test review, security-minded review, maintainability review, or checking correctness, resource ownership, exception safety, concurrency, validation, tests, and cross-platform risks.
-
tomevault-io Bundle Scan 3Run an on-demand security scan with one or more installed tools — ClamAV (clamscan / clamdscan against home or a chosen path), rkhunter, chkrootkit, Lynis (system audit), AIDE (integrity check). User picks scope (quick / deep / specific path) and which scanners to run. Reports go to the user-defined scan-results folder, organised per tool with timestamped filenames. Triggers on "scan my system", "run clamav", "rkhunter scan", "lynis audit". Use when this capability is needed.
-
tomevault-io Bundle Metasploit Framework 2This skill should be used when the user asks to "use Metasploit for penetration testing", "exploit vulnerabilities with msfconsole", "create payloads with msfvenom", "perform post-exploitation", "use auxiliary modules for scanning", or "develop custom exploits". It provides comprehensive guidance for leveraging the Metasploit Framework in security assessments. Use when this capability is needed.
-
tomevault-io Bundle Qms Audit Expert 2ISO 13485 internal audit expertise for medical device QMS. Covers audit planning, execution, nonconformity classification, and CAPA verification. Use for internal audit planning, audit execution, finding classification, external audit preparation, or audit program management. Use when this capability is needed.
-
tomevault-io Bundle Code Security Review 2Comprehensive code quality and security audit for financial systems. Use when asked to "review code", "code review", "security audit", "check for issues", "審核程式碼", "檢查安全性", or before merging changes. Focuses on DDD compliance, financial precision (no floats for money), security vulnerabilities, and test coverage. Use when this capability is needed.
-
tomevault-io Bundle GRAPHQL Security 3Security audit for GraphQL APIs covering query depth and complexity limits, introspection exposure, field-level authorization, mutation auth, persisted queries, batching abuse, error message leakage, subscription auth, and Apollo/urql/graphql-yoga/Mercurius/Hasura/PostGraphile-specific patterns. Use this skill whenever the user mentions GraphQL, Apollo Server, Apollo Client, urql, graphql-yoga, Mercurius, Hasura, PostGraphile, Strawberry (Python), gqlgen (Go), resolvers, schema.graphql, .gql files, query depth, query complexity, or asks "audit my GraphQL", "GraphQL security review", "depth limit", "persisted queries". Trigger when the codebase contains `.graphql`/`.gql` files, `apollo-server`, `@apollo/server`, `graphql-yoga`, `mercurius`, or `graphql` packages. Use when this capability is needed.
-
tomevault-io Bundle Code Review Checklist 8Comprehensive code review checklist covering quality, consistency, testing, documentation, and security. Use when reviewing pull requests or preparing code for merge. Use when this capability is needed.
-
tomevault-io Bundle Translation 4Guidelines for translating and localizing the Kilo Code extension, including language-specific rules for German, Simplified Chinese, and Traditional Chinese. Use when this capability is needed.
-
tomevault-io Bundle Secure Coding 3Provides guidance on secure coding practices including OWASP Top 10 2025, CWE Top 25, input validation, output encoding, and language-specific security patterns. Use when reviewing code for security vulnerabilities, implementing security controls, or learning secure development practices.
-
tomevault-io Bundle Docs Generator 4Improve NatSpec documentation and generate adapter AUDIT.md files based on existing Solidity implementations. Use after implementation to document behavior for audits and releases. Use when this capability is needed.
-
tomevault-io Bundle Code Review Checklist 7Structured code review approach covering security, quality, performance, and consistency. Use when this capability is needed.
-
tomevault-io Bundle Django Security 20Esta skill deve ser usada quando o usuário está trabalhando em código Django que envolve autenticação, autorização, formulários, queries, middleware ou configurações de segurança. Fornece checklist OWASP e diretrizes de segurança específicas do Django. Use when this capability is needed.
-
tomevault-io Bundle Security Review 25Use when working with a specialist skill for security reviews, threat modeling, and remediation guidance. Use for auth/permissions changes, secrets or PII handling, public endpoints, or dependency upgrades.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include exploit-development, fastapi-patterns, audit-code. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.