Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
dojogenesis Skill Dependency AuditorScan project dependencies for outdated, vulnerable, or unused packages across multiple languages. Use when auditing supply chain risk or cleaning up lockfiles. Trigger phrases: "audit dependencies", "check vulnerabilities", "find unused packages".
-
dojogenesis Skill Env Secrets ManagerAudits .env files and secrets hygiene across local development and production, detecting drift, leaked secrets, and rotation gaps. Use when: 'manage environment variables', 'secrets audit', 'env hygiene', 'rotate secrets', '.env review', 'check for leaked keys', 'environment config'.
-
sairam0424 Skill Requesting Code Review 3Pre-commit review: security scan, quality gates, auto-fix.
-
odjaramillo Skill Code Review Checklist 2Comprehensive checklist for conducting thorough code reviews covering functionality, security, performance, and maintainability
-
odjaramillo Skill Nodejs Best Practices 2Node.js development principles and decision-making. Framework selection, async patterns, security, and architecture. Teaches thinking, not copying.
-
purpleailab Skill Osint 2Open-source intelligence gathering — email harvesting, social media profiling, breach data checking, employee enumeration, GitHub secret scanning, organizational mapping.
-
wufufu770 Skill Hunt Xss 2Hunting skill for xss vulnerabilities. Built from 174 public bug bounty reports. Use when hunting xss on any target. For markup injection that reflect
-
wufufu770 Skill Second Opinion 2Get a second independent perspective on a finding or attack approach before committing. Review the evidence chain (request/response, payload, success criteria), assess whether the conclusion holds under alternative interpretations, and suggest additional verification steps. Use when an unusual finding seems too good to be true, or when a complex attack chain needs sanity-checking before exploitation.
-
wufufu770 Skill Hunt Cache Poison 2Hunting skill for cache poison vulnerabilities. Built from 10 public bug bounty reports including X-Forwarded-Host poisoning, X-HTTP-Method-Override / GCS cache, reflected→stored XSS via cache, classic Omer-Gil Web Cache Deception, Cloudflare Cache Deception Armor bypass, session-token cache deception, Akamai hop-by-hop smuggling → server-side edge poisoning, and Kettle's 2024 path-normalization W
-
wufufu770 Skill Prototype Pollution 2JS 原型污染:客户端/服务端入口点识别、gadget 分析、向 XSS/RCE 的利用升华。触发词:原型污染、prototype pollution、__proto__。
-
aladicf Skill Security UX 2Design security-conscious interfaces that protect users without frustrating them. Use when the user asks about MFA, password UX, breach notifications, trust indicators, secure forms, account recovery, or making security feel safe rather than scary.
-
aladicf Skill Security UX 3Design security-conscious interfaces that protect users without frustrating them. Use when the user asks about MFA, password UX, breach notifications, trust indicators, secure forms, account recovery, or making security feel safe rather than scary.
-
aladicf Skill Security UX 4Design security-conscious interfaces that protect users without frustrating them. Use when the user asks about MFA, password UX, breach notifications, trust indicators, secure forms, account recovery, or making security feel safe rather than scary.
-
aladicf Skill Security UX 5Design security-conscious interfaces that protect users without frustrating them. Use when the user asks about MFA, password UX, breach notifications, trust indicators, secure forms, account recovery, or making security feel safe rather than scary.
-
aladicf Skill Security UX 6Design security-conscious interfaces that protect users without frustrating them. Use when the user asks about MFA, password UX, breach notifications, trust indicators, secure forms, account recovery, or making security feel safe rather than scary.
-
aladicf Skill Security UX 7Design security-conscious interfaces that protect users without frustrating them. Use when the user asks about MFA, password UX, breach notifications, trust indicators, secure forms, account recovery, or making security feel safe rather than scary.
-
aladicf Skill Security UX 8Design security-conscious interfaces that protect users without frustrating them. Use when the user asks about MFA, password UX, breach notifications, trust indicators, secure forms, account recovery, or making security feel safe rather than scary.
-
codyswanngt Skill Lisa Setup Openclaw 2Set up OpenClaw as the chat-surface runtime for this project's staff. Verifies the openclaw CLI, ~/.openclaw/openclaw.json, a secret provider, and required gateway capabilities, then writes a lean `openclaw` section to .lisa.config.json. Run before connect-staff / connect-repo-topic.
-
asgard-ai-platform Bundle UX HeuristicConduct heuristic evaluation of user interfaces using Nielsen's 10 usability principles. Use this skill when the user needs to audit a website, app, or interface for usability issues, prioritize UX improvements, or conduct a quick expert review without user testing — even if they say 'review this UI', 'find usability problems', or 'why do users struggle with our app'.
-
asgard-ai-platform Bundle Med PoliticalUse when the user wants to write a political news piece — election coverage, legislative reporting, policy analysis, official-statement coverage, poll interpretation, or political profile — from supplied material (transcripts, press releases, poll data, vote records, leaked documents, interviews). Activates political-beat-specific workflow on top of the general news-reporter workflow: stance tagging, poll-reading discipline, defamation/election-law red lines, and frame-neutrality audit. Also triggers on phrases like 'write up this 質詢', 'turn into an election report', 'analyze this poll', '幫我寫成政策追蹤報導', '寫一篇選戰分析', '把這份立委發言整理成新聞', 'cover this candidate's policy platform'. Defers general news craft to med-news-reporter; do NOT use for press releases (use pr-press-release) or government PR (use pr-*).
-
asgard-ai-platform Bundle Grad Strat RbvApply the Resource-Based View (Barney, 1991) and VRIO framework to evaluate whether a firm's resources and capabilities confer sustained competitive advantage. Use this skill when the user needs to assess internal resources for strategic value, determine if a competitive edge is sustainable, audit resource portfolios for VRIO criteria, or when they ask 'what makes our advantage sustainable', 'which resources matter most', or 'can competitors replicate this'.
-
asgard-ai-platform Bundle Algo Risk BenfordApply Benford's Law to detect anomalies in numerical datasets by analyzing first-digit frequency distributions. Use this skill when the user needs to audit financial data for fraud indicators, validate data integrity, or detect fabricated numbers — even if they say 'data manipulation detection', 'first digit test', or 'accounting fraud screening'.
-
asgard-ai-platform Bundle Grad Brand EquityApply brand equity frameworks (Aaker, 1991; Keller, 1993) to assess and build customer-based brand value. Use this skill when the user needs to audit brand strength, diagnose brand equity components, design brand-building strategies, or when they ask 'how strong is our brand', 'what drives brand value', or 'how do we build brand equity'.
-
asgard-ai-platform Bundle Grad Dual ProcessApply dual-process theory to diagnose whether judgments arise from fast intuitive (System 1) or slow analytical (System 2) processing and identify resulting cognitive biases. Use this skill when the user needs to explain why quick decisions go wrong, design choice architectures that account for cognitive defaults, audit decision processes for heuristic errors, or when they ask 'why do people misjudge probability', 'how to reduce snap-judgment errors', or 'when does intuition fail'.
-
ngocsangyem Bundle Mk Pack 2Pack an EXTERNAL repository into one AI-friendly file (markdown/xml/json) for third-party analysis, security audits, or handoff. Do NOT use for the current project — it's already read lazily.
-
ngocsangyem Bundle Mk Pack 3Pack an EXTERNAL repository into one AI-friendly file (markdown/xml/json) for third-party analysis, security audits, or handoff. Do NOT use for the current project — it's already read lazily.
-
ngocsangyem Skill Mk Review Pr 2Reviews a GitHub PR with a shallow correctness/security/breaking/AI-slop checklist and emits a verdict; optionally posts via gh. NOT for own-diff audit (mk:review); NOT for replying (mk:respond-pr).
-
ngocsangyem Bundle Mk Context Audit 2Read-only audit of .codex/ structural overhead: 'remove X save Y tokens' vs the context window. NOT for cost tracking (budget skill); NOT for runtime read/compact decisions (mk:context-engineering).
-
bromso Skill Audit 2Perform a deep-dive review of specific accounts or transactions
-
bromso Skill Review 2Review code pre-merge for bugs, security, quality, and test coverage
-
bromso Skill Risk Assessment 2Score and prioritize security risks by likelihood and impact
-
melodic-software Bundle Audit 3Audit the test suite for tests that cannot fail, a deterministic script detects assertion-free test bodies, self-identical (recomputed-expectation) assertions, and mock-only oracles across JS/TS, Python, and C#, reports with a coverage denominator, gates fail-closed via --check, and opt-in persists a findings file the review fix pass consumes. Use when: the user wants tests that cannot fail found (tautological, vacuous, or assertion-free tests, or tests that pass but prove nothing), a CI gate on can't-fail tests, or the audit's findings persisted for the fix pass. Flags: `--check` (exit-code gate), `--strict` (gate mock-only-oracle findings too), `--persist-findings` (write the findings file the review fix pass consumes). Read-only on the suite: findings propose repairs; nothing edits or deletes a test.
-
melodic-software Bundle Setup 19Verify the guardrails hooks' runtime prerequisites and per-guard toggle state for this machine. Use when: 'set up guardrails', 'configure guardrails', 'is guardrails working', 'which guards are on', a guard failed open with a jq notice, after tuning guard toggles, or 'install the commit-msg hook' / 'enforce the commit convention for every committer', or 'install the pre-commit content hook' / 'enforce secrets and hardcoded-path checks on every commit'. Actions: check (read-only verification, default) | apply (resolve what check found) | apply install-commit-msg (opt-in: install the tool-agnostic commit-msg convention hook into this repo's personal .git/hooks) | apply install-pre-commit-content (opt-in: install the write-path-independent secret/hardcoded-path pre-commit hook into this repo's personal .git/hooks). Re-runnable and safe.
-
melodic-software Bundle Setup 21Set up and maintain this repository's provenance configuration: `.claude/provenance.json` across the config cascade's three layers. Manages the categorical exclusions (including the eval-fixture tree, which is a config entry by design and never a rule in a script), the per-candidate and corpus fetch budgets, the separation-rule constants, the stamp expiry window, the accuracy dials for nomination passes and judge sampling, and the fix-eligibility gates. Enables the off-by-default trigger-less-stamp check for a repository whose stamp forms are uniform enough to greppably support it. Use when: 'set up provenance', 'configure provenance', 'exclude a path from the provenance audit', 'change the stamp expiry window', 'the provenance audit flags too much', 'turn on the trigger-less stamp check', or after installing the plugin. Writes only the consuming repository's own config file, never source.
-
melodic-software Bundle Setup 30Verify or configure the code-metrics plugin for this repository: `check` probes the interpreter, every configuration layer (user-global, team, local overlay, and the consumer's ecosystem files) for the YAML subset and the tracked-file guard, prints every reference with the layer that supplied it, and probes each collector adapter (a version, or missing with its install hint); `apply` writes the tracked `.claude/code-metrics.yaml` team layer per key, idempotently, never installing a tool and never editing `.gitignore`. Use when: 'set up code-metrics', 'configure code metrics', 'is code-metrics configured', 'which collectors are installed', 'set the cyclomatic reference', 'change the file length reference', 'code-metrics setup', or an audit skill reports a configuration layer it could not read.
-
melodic-software Bundle Setup 33Verify the disk-hygiene plugin's runtime prerequisites and platform posture for this machine. Use when: 'set up disk-hygiene', 'configure disk-hygiene', 'is disk-hygiene working', a clean run reported a missing prerequisite, or before a first audit on a new machine. Actions: check (read-only verification, default) | apply (resolve what check found). Re-runnable and safe.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include security-ux, audit, risk-assessment. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.