Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
tomevault-io Bundle GRAPHQL Architect 16Master modern GraphQL with federation, performance optimization, and enterprise security. Build scalable schemas, implement advanced caching, and design real-time systems. Use when this capability is needed.
-
tomevault-io Bundle Security Risk 2Combine security scanning and threat modeling for changes involving data handling, API interception, sync, storage, authentication, and encryption. Use when this capability is needed.
-
tomevault-io Bundle Authentication Patterns 3Comprehensive authentication implementation guidance including JWT best practices, OAuth 2.0/OIDC flows, Passkeys/FIDO2/WebAuthn, MFA patterns, and secure session management. Use when implementing login systems, token-based auth, SSO, passwordless authentication, or reviewing authentication security. Use when this capability is needed.
-
tomevault-io Bundle Optimise Cursor Repo 2Audit a repository's Cursor configuration or evaluate whether a specific artefact (rule, skill, command, subagent) is correctly placed. Use when optimising the repo for Cursor, improving indexing, adding or assessing rules/skills, or deciding where information should live. Use when this capability is needed.
-
tomevault-io Bundle Security Bluebook Builder 4Build a minimal but real security policy for sensitive apps. The output is a single, coherent Blue Book document using MUST/SHOULD/CAN language, with explicit assumptions, scope, and security gates. Use when this capability is needed.
-
tomevault-io Bundle Threat Mitigation Mapping 3Map identified threats to appropriate security controls and mitigations. Use when prioritizing security investments, creating remediation plans, or validating control effectiveness. Use when this capability is needed.
-
tomevault-io Bundle Architecture Design Review 3Red-team review of system/design proposals to find fatal flaws and blockers across architecture/tech risk, business reasonableness, and security/compliance. Outputs rejection-style critique (blockers, contradictions, missing invariants), not improvement plans. Use when the user wants a harsh risk审查/否决/质疑/拆穿 review. Use when this capability is needed.
-
tomevault-io Bundle Code Review Checklist 18Language-agnostic code review checklist. Covers security, performance, readability, maintainability, testing, and common pitfalls across languages. Use when performing code reviews, creating review guidelines, or when the user mentions code review, PR review, review checklist, or code quality. Use when this capability is needed.
-
tomevault-io Bundle Jeremylongshore Claude Code Plugins Plus Skills Log Anal 2Log Analysis Security
-
tomevault-io Bundle Code Review 322Review code changes for bugs, security issues, and improvements Use when this capability is needed.
-
tomevault-io Bundle API Authentication 2API authentication patterns including JWT, OAuth 2.0, API keys, and session-based auth. Covers token generation, validation, refresh strategies, security best practices, and when to use each pattern. Use when implementing API authentication, choosing auth strategy, securing endpoints, or debugging auth issues. Prevents common vulnerabilities like token theft, replay attacks, and insecure storage. Use when this capability is needed.
-
tomevault-io Bundle Auditing Access Control 2Audit access control implementations for security vulnerabilities and misconfigurations. Use when reviewing authentication and authorization. Trigger with 'audit access control', 'check permissions', or 'validate authorization'. Use when this capability is needed.
-
tomevault-io Bundle Wordpress Penetration Testing 4This skill should be used when the user asks to "pentest WordPress sites", "scan WordPress for vulnerabilities", "enumerate WordPress users, themes, or plugins", "exploit WordPress vulnerabilities", or "use WPScan". It provides comprehensive WordPress security assessment methodologies. Use when this capability is needed.
-
tomevault-io Bundle Esaldgut AI Native Engineering Workspace Swift Auth Secu 2Auth security audit suite (iOS, Swift Testing)
-
tomevault-io Bundle Shared Setup Patterns 2Shared configuration patterns for project setup commands. Provides security hooks, Claude framework structure templates, and framework detection patterns used across multiple setup commands. Use when this capability is needed.
-
tomevault-io Bundle Code Review Checklist 19Comprehensive code review criteria covering correctness, readability, maintainability, security, performance, and testing. Reference when reviewing code changes or preparing code for review. Use when this capability is needed.
-
tomevault-io Bundle Backend Security Coder 3Expert in secure backend coding practices specializing in input Use when this capability is needed.
-
tomevault-io Bundle Auth Implementation Patterns 7Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems. Use when implementing auth systems, securing APIs, or debugging security issues. Use when this capability is needed.
-
tomevault-io Bundle Jeremylongshore Claude Code Plugins Plus Skills Scanning 2Xss Vulnerability Scanner
-
tomevault-io Bundle Jeremylongshore Claude Code Plugins Plus Skills Generati 8Generating Security Audit Reports
-
tomevault-io Bundle Jeremylongshore Claude Code Plugins Plus Skills Implemen 3Database Audit Logger
-
tomevault-io Bundle Standard Security Auth 2Security & Authentication Specialist - Expert in JWT, cookie-based auth, MFA, and generic security patterns Use when this capability is needed.
-
tomevault-io Bundle Security Checklist 8OWASP Top 10 quick reference and common vulnerability patterns for security-focused code review and auditing. Use when this capability is needed.
-
tomevault-io Bundle Dependency Evaluator 2Evaluates whether a programming language dependency should be used by analyzing maintenance activity, security posture, community health, documentation quality, dependency footprint, production adoption, license compatibility, API stability, and funding sustainability. Use when users ask "should I use X or Y?", "are there better options for [feature]?", "what's a good library for [task]?", "how do we feel about [dependency]?", or when considering adding a new dependency, evaluating an existing dependency, or comparing/evaluating package alternatives. Use when this capability is needed.
-
tomevault-io Bundle Protocol Reverse Engineering 3Comprehensive techniques for capturing, analyzing, and documenting network protocols for security research, interoperability, and debugging. Use when this capability is needed.
-
tomevault-io Bundle Security Bluebook Builder 6Build a minimal but real security policy for sensitive apps. The output is a single, coherent Blue Book document using MUST/SHOULD/CAN language, with explicit assumptions, scope, and security gates. Use when this capability is needed.
-
tomevault-io Bundle Security Bluebook Builder 7Build a minimal but real security policy for sensitive apps. The output is a single, coherent Blue Book document using MUST/SHOULD/CAN language, with explicit assumptions, scope, and security gates. Use when this capability is needed.
-
javimosch Skill Quickstart 384---\nname: clair\ndescription: Clair container security scanner\n---\n# clair Plugin\nClair container security scanner
-
tomevault-io Bundle Review Code 14Perform comprehensive csharp/dotnet code reviews focusing on clean code, security, testing, performance, and documentation Use when this capability is needed.
-
tomevault-io Bundle Security Vulnerability Report 2Scan GitHub repositories for security vulnerabilities including Dependabot alerts, code scanning results, and secret scanning findings. Use when auditing repository security, preparing compliance reports, or triaging vulnerability alerts. Use when this capability is needed.
-
tomevault-io Bundle Best Practices 20Searchable knowledge base of 152+ programming best practices across 30+ languages and frameworks. BM25-powered search over curated resources from industry leaders (Google, Airbnb, Uber, Mozilla, Shopify, OWASP). Use when this capability is needed.
-
tomevault-io Bundle Documentation Specialist 6Extracts system architecture and creates data flow documentation (Stages 1, 2, 6). Focuses on source traceability and accurate information extraction. Does NOT perform security analysis or quality validation.
-
tomevault-io Bundle Django Perf Review 12Django performance code review. Use when asked to "review Django performance", "find N+1 queries", "optimize Django", "check queryset performance", "database performance", "Django ORM issues", or audit Django code for performance problems. Use when this capability is needed.
-
tomevault-io Bundle Convex Performance Audit 6Audits and optimizes Convex application performance across hot-path reads, write contention, subscription cost, and function limits. Use this skill when a Convex feature is slow or expensive, npx convex insights shows high bytes or documents read, OCC conflict errors or mutation retries appear, subscriptions or UI updates are costly, functions hit execution or transaction limits, or the user mentions performance, latency, read amplification, or invalidation problems in a Convex app. Use when this capability is needed.
-
tomevault-io Bundle Hunt Research System And Tradecraft 2Research system internals and adversary tradecraft to ground a threat hunt in real system behavior and realistic abuse patterns. Use this skill at the start of hunt planning, when you are given a high-level hunt topic but lack a clear understanding of how the system normally operates or how adversaries are known to abuse it. This skill informs early hunt direction by producing candidate abuse patterns, key assumptions, and cited sources, and should be used before defining a concrete hunt hypothesis or selecting data sources. Use when this capability is needed.
-
tomevault-io Bundle Codebase Cleanup Deps Audit 2You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies. Use when this capability is needed.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include graphql-architect, security-risk, authentication-patterns. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.