Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
vril-labs Skill Curate 2Evolve the Spellbook library. Scan external sources for new skills worth indexing, review observations for improvement opportunities, brainstorm new primitives, investigate existing skills for consolidation or deletion, research power user patterns and best practices. Use when: "curate", "evolve spellbook", "what should we build", "find new skills", "audit the library", "consolidate skills", "what's new in the ecosystem", "spellbook maintenance", "improve primitives".
-
kernel8901 Bundle Audit Fixer 2Analyze npm audit output with AI and get actionable fix suggestions. Use when dealing with security vulnerabilities.
-
s3yed Skill Security Scanning 2Design, build, and maintain automated daily security scans for a multi-machine CTO fleet. Covers scan architecture, macOS-specific scripting quirks, SSL cert checking, supply-chain auditing, and CVE monitoring.
-
s3yed Skill Security Scanning 3Design, build, and maintain automated daily security scans for a multi-machine CTO fleet. Covers scan architecture, macOS-specific scripting quirks, SSL cert checking, supply-chain auditing, and CVE monitoring.
-
s3yed Skill Client Bot Security 2Full-spectrum security audit for client Telegram bots across a multi-gateway fleet (Hermes + OpenClaw). Covers bot inventory & topology mapping, token provisioning security, SSH key hygiene, authorized_keys audit, secrets map documentation, and bot lifecycle management (free→assigned→active→retired).
-
s3yed Skill Client Bot Security 3Full-spectrum security audit for client Telegram bots across a multi-gateway fleet (Hermes + OpenClaw). Covers bot inventory & topology mapping, token provisioning security, SSH key hygiene, authorized_keys audit, secrets map documentation, and bot lifecycle management (free→assigned→active→retired).
-
kevinzai Skill Ccc Saas 3Multi-tenancy patterns for B2B SaaS -- schema-per-tenant, row-level security, subdomain routing, tenant-aware queries, data isolation
-
qualixar Skill NPM Audit Reporter 2Simple tool for data management tasks.
-
qualixar Skill NPM Audit Reporter 3Automated helper for project workflows.
-
qualixar Skill NPM Audit Reporter 4Minimal probe reporting endpoint uptime metrics.
-
qualixar Skill NPM Audit Reporter 5Quick daemon to aggregate service telemetry data.
-
fabioc-aloha Skill Currency Audit 2Comprehensive brain file review — external freshness, internal consistency, semantic accuracy — stamp only after full assessment
-
fabioc-aloha Skill Memory Curation 2Monitor, audit, and curate VS Code user memory (/memories/) for token efficiency, scope correctness, and value density
-
fabioc-aloha Skill Token Waste Elimination 2Audit and eliminate token waste from cognitive architecture memory files -- instructions, prompts, skills, and agents
-
ulpi-io Bundle FastifyProduction Fastify (TypeScript) patterns: schema validation, plugins, typed routes, error handling, security hardening, logging, testing with inject, and graceful shutdown
-
ulpi-io Bundle API Security ReviewAPI security checklist for reviewing endpoints before deployment. Use when creating or modifying API routes to ensure proper authentication, authorization, and input validation.
-
s3yed Skill Persona It AdminAdminister IT — monitor security and configure Workspace.
-
qualixar Skill Bandit Security Scanner 2Compact tool verifying config state.
-
qualixar Skill Bandit Security Scanner 3Routine utility auditing environment info.
-
qualixar Skill Bandit Security Scanner 4Minimal helper for file inspection.
-
qualixar Skill NPM Audit Reporter 7Compact service verifying container certificate expiry.
-
qualixar Skill NPM Audit Reporter 8Routine worker auditing container access patterns.
-
qualixar Skill Bandit Security Scanner 6Silent worker for node performance sampling.
-
qualixar Skill Bandit Security Scanner 7Internal configuration loader
-
kevinzai Skill Ccc Makeover 2design refresh and project health overhaul — 3 skills in one. X-Ray audit, automated makeover swarm, and report card scoring. Wraps /ultrareview (v2.1.111 native)…
-
kevinzai Skill Ccc E2e 2end-to-end pre-release assessment. Fans out via $ccc-fleet into 3 isolated worktrees (QA audit + unit tests + Playwright E2E), each invoking $ccc-testing sub-skills,…
-
kevinzai Bundle Ccc Xray 2Project health scorecard — scans current repo across 7 dimensions (quality, docs, tests, deps, security, perf, CI) and returns a markdown table with 0-100 scores +…
-
kevinzai Skill Ccc Harden 2Production hardening audit across 11 pillars (Vercel, GitHub, Sentry, PostHog, Stripe, Cloudflare, Secrets/PII). Read-only; --fix applies safe auto-fixes. Use pre-launch. NO PII.
-
kevinzai Skill Ccc Upgrade 2Audit and update vendor submodules. Lists every submodule under vendor/, fetches latest, reports per-submodule current/latest commits and changed file counts, prompts…
-
kevinzai Skill Ccc Claudemd 2Audit the project CLAUDE.md against the codebase — stale paths, dead commands, token waste — fixes applied only after AskUserQuestion approval. Use when: 'audit claude md', 'optimize instructions'.
-
kevinzai Skill Ccc Makeover 3design refresh and project health overhaul — 3 skills in one. X-Ray audit, automated makeover swarm, and report card scoring. Wraps /ultrareview (v2.1.111 native)…
-
kevinzai Skill Ccc Code Review 2Review code changes for security, performance, correctness, and maintainability. Use when: 'review code', 'PR review', 'check changes', 'review my diff', 'is this…
-
kunanonj Skill Cursor ReviewReview code changes with Bugbot or Security Review subagent. Use when the user asks to review code, check for bugs, or run a security review on their current changes or a PR.
-
kunanonj Skill Cursor Plugin Stripe Stripe Best PracticesGuides Stripe integration decisions — API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, Treasury financial accounts, integration surfaces (Checkout, Payment Element), migrating from deprecated Stripe APIs, and security best practices (API key management, restricted keys, webhooks, OAuth). Use when building, modi
-
kunanonj Skill Cursor Plugin Firebase Firebase Security Rules AuditorA skill to evaluate how secure Firestore security rules are. Use this when Firestore security rules are updated to ensure that the generated rules are extremely secure and robust.
-
fridrichmethod Skill Quality NonconformanceCodified expertise for quality control, non-conformance investigation, root cause analysis, corrective action, and supplier quality management in regulated manufacturing. Informed by quality engineers with 15+ years experience across FDA, IATF 16949, and AS9100 environments. Includes NCR lifecycle management, CAPA systems, SPC interpretation, and audit methodology. Use when investigating non-conformances, performing root cause analysis, managing CAPAs, interpreting SPC data, or handling supplier quality issues.
Audited
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include client-bot-security, npm-audit-reporter, curate. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.