Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
acaprino Bundle Marketplace Audit 3Validates the integrity of any Claude Code plugin marketplace. Use PROACTIVELY before any commit that modifies plugin files or marketplace.json. TRIGGER WHEN: verifying marketplace.json integrity, finding orphan plugins/skills/agents/commands, checking dependency resolution or cycles, confirming documented plugin counts still match README and docs tables, or checking naming conventions. DO NOT TRIGGER WHEN: content quality review (use marketplace-review) or scaffolding new plugins (use marketplace-scaffold-plugin / skills-creator).
-
acaprino Bundle Marketplace Audit 4Validates the integrity of any Claude Code plugin marketplace. Use PROACTIVELY before any commit that modifies plugin files or marketplace.json. TRIGGER WHEN: verifying marketplace.json integrity, finding orphan plugins/skills/agents/commands, checking dependency resolution or cycles, confirming documented plugin counts still match README and docs tables, or checking naming conventions. DO NOT TRIGGER WHEN: content quality review (use marketplace-review) or scaffolding new plugins (use marketplace-scaffold-plugin / skills-creator).
-
hybridlabor-api Bundle Wcag Audit PatternsComprehensive guide to auditing web content against WCAG 2.2 guidelines with actionable remediation strategies.
-
dnyoussef Bundle When Auditing Security Use Security Analyzer 2When Auditing Security Use Security Analyzer
-
dnyoussef Bundle When Reviewing Pull Request Orchestrate Comprehensive Code RUse when conducting comprehensive code review for pull requests across multiple quality dimensions. Orchestrates 12-15 specialized reviewer agents across 4 phases using star topology coordination. Covers automated checks, parallel specialized reviews (quality, security, performance, architecture, documentation), integration analysis, and final merge recommendation in a 4-hour workflow.
-
tcuzzo Skill Guided Steps 7当一次配置里有只有人能做的步骤时使用——第三方后台、凭证、CI secret、开通服务、一次性迁移、切换上线。生成一个分阶段的交互式脚本:打开每个 URL、说清点什么复制什么、接住值、写到它该在的地方。Trigger words: wizard, human-only steps, provision, credentials, dashboard setup, CI secrets, cutover. 中文触发词:向导、人工步骤、开通、凭证、后台配置、CI 密钥、切换上线。
-
tcuzzo Skill Seam Engineering 4À utiliser pour réparer un bug ou clôturer un audit ou une chasse aux bugs. Fixe la classe de défaut une fois à sa primitive partagée, balaie chaque occurrence sœur, pose un garde qui attrape la prochaine instance, et clôt chaque constat remonté — aucun report silencieux. Trigger words: seam, class fix, whole-seam closure, point patch, structural guard, do it right the first time, couture, fix de classe, clôture de couture entière, patch ponctuel, garde structurel, bien faire du premier coup.
-
tcuzzo Skill Seam Engineering 5तब लगाओ जब कोई bug ठीक करना हो या किसी audit या bug hunt को बंद करना हो। Flaw की class को एक बार, उसके shared primitive पर ठीक करता है, हर sibling को sweep करता है, अगली instance पकड़ने वाला guard लगाता है, और सामने आई हर finding बंद करता है — कोई चुपचाप टालना नहीं। Trigger words: seam, class fix, whole-seam closure, point patch, structural guard, do it right the first time, पूरी class ठीक करो, जड़ से बंद करो, पहली बार में सही, पूरा seam बंद करो.
-
garyld1962 Bundle Feature Sweep 4Audit installed skills against verified current platform releases and propose or apply targeted improvements. Use after a Codex or Copilot release, or to find useful new integrations; use a skill quality audit for ordinary wording and trigger problems.
-
garyld1962 Bundle Audit Existing 3Read-only audit of an existing implementation before planning or extending it. Produces implemented, missing, duplicated, broken, and risky findings without editing files.
-
delorenj Skill Gsd Progress 2Check project progress, show context, and route to next action (execute or plan). Use --forensic to append a 6-check integrity audit after the standard report.
1 -
delorenj Skill Gsd Audit Uat 2Cross-phase audit of all outstanding UAT and verification items
1 -
delorenj Skill Gsd Audit Uat 3Cross-phase audit of all outstanding UAT and verification items
1 -
delorenj Skill Gsd Code Review 2Review source files changed during a phase for bugs, security issues, and code quality problems
1 -
delorenj Skill Gsd Eval Review 2Retroactively audit an executed AI phase's evaluation coverage — scores each eval dimension as COVERED/PARTIAL/MISSING and produces an actionable EVAL-REVIEW.md with remediation plan
1 -
delorenj Skill Gsd Code Review 3Review source files changed during a phase for bugs, security issues, and code quality problems
1 -
delorenj Skill Gsd Eval Review 3Audit an executed AI phase's evaluation coverage and produce an EVAL-REVIEW.md remediation plan.
1 -
delorenj Skill Gsd Secure Phase 2Retroactively verify threat mitigations for a completed phase
1 -
delorenj Skill Gsd Secure Phase 3Retroactively verify threat mitigations for a completed phase
1 -
delorenj Skill Gsd Validate Phase 2Retroactively audit and fill Nyquist validation gaps for a completed phase
1 -
delorenj Skill Gsd Validate Phase 3Retroactively audit and fill Nyquist validation gaps for a completed phase
1 -
delorenj Skill Gsd Audit Milestone 2Audit milestone completion against original intent before archiving
1 -
delorenj Skill Gsd Audit Milestone 3Audit milestone completion against original intent before archiving
1 -
delorenj Skill Gsd Plan Milestone Gaps 2Create phases to close all gaps identified by milestone audit
1 -
777genius Skill Repo 50Skill
-
777genius Bundle Repo 54Skill
-
quantumquirkxyz Skill Quant Backtest 2Run a backtest with full audit hygiene — biases, costs, out-of-sample, regime splits — and produce a verdict on whether a strategy is robust.
-
evolution-foundation Skill Fin Audit SupportSupport SOX 404 compliance with control testing methodology, sample selection, and documentation standards. Use when generating testing workpapers, selecting audit samples, classifying control deficiencies, or preparing for internal or external audits.
-
ahtishamshahzad Skill Database Security 2Use to review database security from an audit/threat lens — least-privilege access, network exposure, injection surface, encryption of sensitive data, tenant isolation depth, and PII handling — verifying the data-layer hardening holds. The security-review lens; the database pack owns the build-side design.
-
gktuoktay Skill Testing JWT Token SecurityJSON Web Token (JWT) uygulamalarını kriptografik zayıflıklar, algoritma karmaşası ve yetkilendirme atlama zafiyetlerine karşı güvenlik testleri sırasında analiz eder.
Audited -
gktuoktay Skill Testing For Xss VulnerabilitiesWeb uygulamalarında Reflected, Stored ve DOM tabanlı XSS (Cross-Site Scripting) zafiyetlerini test eder. Burp Suite ve tarayıcı araçlarıyla JavaScript payload'ları enjekte ederek filtreleme (sanitization) ve CSP atlatma yöntemlerini uygular.
Audited -
gktuoktay Skill Testing For Broken Access ControlWeb uygulamaları ve API'leri Kırık Erişim Kontrolü (OWASP A01:2021) açısından test eder. Yetki yükseltme, eksik fonksiyon seviyesi kontrolleri, IDOR ve çoklu kiracı (multi-tenant) veri sızıntılarını tespit etmek için Burp Suite kullanır.
Audited -
gktuoktay Skill Software Composition And Dependency Auditing 2Proje bağımlılıklarındaki (npm, pip vb.) CVE zafiyetlerinin taranması, supply chain güvenliği ve versiyon güncellemeleri.
-
gktuoktay Skill Performing GRAPHQL Security AssessmentGraphQL API uç noktalarını introspection (içe bakış) sızıntıları, enjeksiyon saldırıları, yetkilendirme hataları ve servis dışı bırakma (DoS) zafiyetleri açısından değerlendirir.
Audited -
gktuoktay Skill Testing API Security With Owasp Top 10REST, GraphQL ve gRPC API uç noktalarını OWASP API Security Top 10 (2023) standartlarına göre sistemli olarak değerlendirir. Burp Suite ve Postman kullanarak otomatik ve manuel testler gerçekleştirir. Yetkili sızma testleri veya API gateway denetimleri öncesinde kullanılır.
Audited -
gktuoktay Skill Testing For JSON Web Token VulnerabilitiesJWT uygulamalarında algoritma karmaşası, 'none' algoritması atlatması, kid/jku parametre enjeksiyonu ve zayıf gizli anahtar (secret) zafiyetlerini test eder. jwt_tool ve Burp Suite kullanarak kimlik doğrulama atlatma ve yetki yükseltmeyi hedefler.
Audited
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include gsd-audit-uat, gsd-code-review, gsd-eval-review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.