Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
mturac Skill Laravel Security 4Laravel 安全最佳实践,涵盖认证/授权、验证、CSRF、批量赋值、文件上传、密钥管理、速率限制和安全部署。
-
mturac Skill Defi Amm Security 2DeFi自動マーケットメーカー(AMM)スマートコントラクトセキュリティ監査パターン。フラッシュローン、スリッページ、サンドイッチング攻撃、価格操作、再入攻撃、不正確な整数演算をカバー。
-
mturac Skill Quarkus Verification 2Verification loop for Quarkus projects: build, static analysis, tests with coverage, security scans, native compilation, and diff review before release or PR.
-
mturac Skill Defi Amm Security 3Solidity AMM 合约、流动性池和交换流程的安全检查清单。涵盖重入、CEI 排序、捐赠或通胀攻击、预言机操纵、滑点、管理员控制和整数数学。
-
mturac Skill Springboot Security 3Java Spring Boot 服务中认证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全性的 Spring Security 最佳实践。
-
mturac Skill Springboot Verification 2Verification loop for Spring Boot projects: build, static analysis, tests with coverage, security scans, and diff review before release or PR.
-
mturac Skill Ecc Tools Cost Audit 2证据优先的ecc工具燃烧和计费审计工作流。用于调查ecc工具仓库中的失控PR创建、配额绕过、高级模型泄漏、重复作业或GitHub App成本激增。
-
mturac Skill Security Bounty Hunter 2リポジトリ内の悪用可能なバウンティ対象のセキュリティ問題を発見します。ノイズの多いローカルのみの発見ではなく、実際のレポートに適格なリモートから到達可能な脆弱性に焦点を当てます。
-
mturac Skill Security Bounty Hunter 3在仓库中寻找可利用、值得赏金的安全问题。专注于远程可访问的漏洞,这些漏洞符合实际报告的条件,而不是嘈杂的仅本地发现。
-
mturac Skill Design SystemUse this skill to generate or audit design systems, check visual consistency, and review PRs that touch styling.
-
mturac Skill Perl SecurityComprehensive Perl security covering taint mode, input validation, safe process execution, DBI parameterized queries, web security (XSS/SQLi/CSRF), and perlcritic security policies.
-
mturac Bundle Security ReviewUse this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
-
mturac Skill Hipaa ComplianceHIPAA-specific entrypoint for healthcare privacy and security work. Use when a task is explicitly framed around HIPAA, PHI handling, covered entities, BAAs, breach posture, or US healthcare compliance requirements.
-
mturac Skill Laravel SecurityLaravel security best practices for authn/authz, validation, CSRF, mass assignment, file uploads, secrets, rate limiting, and secure deployment.
-
mturac Skill Quarkus SecurityQuarkus Security best practices for authentication, authorization, JWT/OIDC, RBAC, input validation, CSRF, secrets management, and dependency security.
-
mturac Skill Defi Amm SecuritySecurity checklist for Solidity AMM contracts, liquidity pools, and swap flows. Covers reentrancy, CEI ordering, donation or inflation attacks, oracle manipulation, slippage, admin controls, and integer math.
-
mturac Skill Postgres PatternsPostgreSQL database patterns for query optimization, schema design, indexing, and security. Based on Supabase best practices.
-
mturac Skill Django VerificationVerification loop for Django projects: migrations, linting, tests with coverage, security scans, and deployment readiness checks before release or PR.
-
mturac Skill Springboot SecuritySpring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.
-
mturac Skill Laravel VerificationVerification loop for Laravel projects: env checks, linting, static analysis, tests with coverage, security scans, and deployment readiness.
-
revfactory Bundle Internal Control Framework 2내부통제 프레임워크 가이드. scope-designer와 checklist-builder 에이전트가 감사 범위와 통제 항목을 설계할 때 참조. 'COSO', '내부통제', '통제 테스트' 요청 시 사용. 단, 외부 감사 대행이나 법적 의견서 작성은 범위 밖.
-
revfactory Bundle Audit Checklist Engine 2컴플라이언스 감사를 위한 체계적 체크리스트 생성 엔진. 'status-auditor'와 'remediation-planner' 에이전트가 현황 진단과 개선 계획을 수립할 때 이 스킬의 감사 프레임워크와 체크리스트 템플릿을 반드시 활용해야 한다. '감사 체크리스트', '이행 점검표', '준수 현황 평가' 등에 사용한다. 단, 법령 매핑이나 전체 오케스트레이션은 이 스킬의 범위가 아니다.
-
revfactory Bundle Sustainability Audit 2ESG/지속가능성 감사의 환경, 사회, 거버넌스 평가와 통합 보고서, 개선 계획을 에이전트 팀이 협업하여 한 번에 생성하는 풀 감사 파이프라인. 'ESG 감사 해줘', '지속가능성 보고서 작성', 'ESG 평가', '탄소배출량 산정', 'ESG 등급 진단', '거버넌스 점검', '사회적 책임 평가', 'GRI 보고서', 'TCFD 공시', 'ESG 개선 계획' 등 ESG/지속가능성 관련 전반에 이 스킬을 사용한다. 특정 영역(E/S/G)만의 평가나 기존 보고서 개선도 지원한다. 단, 실제 현장 감사 수행, 제3자 검증 인증서 발급, ESG 평가기관 등급 변경, 탄소 크레딧 거래는 이 스킬의 범위가 아니다.
-
revfactory Bundle Materiality Assessment 2ESG 중대성 평가 매트릭스. esg-reporter와 improvement-planner 에이전트가 ESG 이슈의 중대성을 평가하고 우선순위를 설정할 때 참조. '중대성 평가', '중요성 분석', 'Materiality Matrix' 요청 시 사용. 단, 이해관계자 설문 시행이나 외부 인증은 범위 밖.
-
yigityildiz0 Bundle Click Path AuditTrace every user-facing button/touchpoint through its full state change sequence to find bugs where functions individually work but cancel each other out.
-
yigityildiz0 Skill Security And HardeningHardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature.
-
yigityildiz0 Bundle Security Best PracticesPerform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security.
-
wenjunduan Skill Code Quality 4Linus-style six-dimension code review with manual security checks for Codex
-
wenjunduan Skill Code Quality 5Linus-style six-dimension code review with official plugins and security scanning
-
revfactory Bundle Audit Report 2내부감사 보고서 생성 파이프라인. 감사 범위 설정부터 체크리스트, 발견사항, 개선 권고, 추적 대장까지 에이전트 팀이 협업 생성한다. '감사 보고서 작성해줘', '내부감사 준비', '감사 체크리스트 만들어줘', '감사 발견사항 정리', '시정조치 계획', '감사 추적 대장', '컴플라이언스 감사', '운영 감사 보고서' 등 내부감사 전반에 이 스킬을 사용한다. 외부 회계감사, 세무조사, 법적 소송 관련 감사는 이 스킬의 범위가 아니다.
-
revfactory Bundle Cve Analysis 2CVE(Common Vulnerabilities and Exposures) 분석 방법론, 의존성 취약점 스캔 도구 활용, CVSS 점수 해석, 취약점 우선순위 결정 가이드. 'CVE', '취약점 분석', '의존성 취약점', 'CVSS', 'npm audit', 'Snyk', 'Trivy', 'CVE 데이터베이스', '취약점 우선순위' 등 CVE 기반 취약점 분석 시 이 스킬을 사용한다. vulnerability-scanner의 스캐닝 역량을 강화한다. 단, 실제 침투 테스트 실행이나 코드 수정은 이 스킬의 범위가 아니다.
-
revfactory Bundle Security Audit 2보안 감사의 취약점 스캔, 코드 보안 분석, 침투 테스트 시나리오 작성, 개선 권고를 에이전트 팀이 협업하여 수행하는 풀 보안 감사 파이프라인. '보안 감사해줘', '취약점 점검', '보안 진단', '코드 보안 분석', '침투 테스트 보고서', '보안 취약점 스캔', 'OWASP 점검', '시큐어 코딩 검토', '보안 개선 방안', '인프라 보안 점검' 등 보안 감사 전반에 이 스킬을 사용한다. 코드 분석만 필요하거나 개선 권고만 필요한 경우에도 지원한다. 단, 실제 네트워크 침투 실행, 악성코드 분석, SOC 운영, 실시간 보안 모니터링은 이 스킬의 범위가 아니다.
-
revfactory Bundle Threat Modeling 2STRIDE, DREAD, Attack Tree 등 위협 모델링 방법론과 위협 식별·평가·대응 전략 수립 가이드. 'STRIDE', 'DREAD', '위협 모델링', 'threat modeling', '공격 트리', 'attack surface', '위협 식별', '보안 설계' 등 시스템 위협 분석 시 이 스킬을 사용한다. security-consultant와 pentest-reporter의 위협 분석 역량을 강화한다. 단, 실제 침투 테스트 실행이나 CVE 스캐닝은 이 스킬의 범위가 아니다.
-
revfactory Bundle Ghg Protocol 2GHG Protocol 상세 가이드. environmental-analyst 에이전트가 온실가스 배출량을 산출하고 보고할 때 참조. 'GHG Protocol', '탄소 배출', 'Scope 1/2/3', '탄소 발자국' 요청 시 사용. 단, 탄소 배출권 거래나 CDM 사업 수행은 범위 밖.
-
revfactory Bundle Finding Classification 2감사 발견사항 분류 및 보고 프레임워크. findings-analyst와 recommendation-writer 에이전트가 발견사항을 체계적으로 분류하고 개선 권고를 작성할 때 참조. '발견사항 분류', '감사 보고', '개선 권고' 요청 시 사용. 단, 법적 제재 결정이나 징계 절차는 범위 밖.
-
jiayaoqijia Bundle Okx Agentic Wallet 2Operate OKX Onchain OS wallets and execute or inspect on-chain transactions. Use for wallet login/status/accounts/addresses/balances/holdings; receive/send/transfer; swaps, bridges, limit orders, contract calls, gas estimation, simulation, broadcast, and tracking; Bitcoin UTXO/BRC-20/inscriptions; signing, approvals, wallet policy/export, public-address portfolios, security checks, and audit logs.
Audited
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include laravel-security, defi-amm-security, quarkus-verification. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.