Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
zhaoxuya520 Bundle Skills 15安全工程师 Skills 总控
12.8k -
plamentsv Skill Ability Analysis 2Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents
-
plamentsv Skill Dependency Audit 2Trigger EXTERNAL_LIB flag detected (protocol uses third-party Move dependencies) - Used by Breadth agents, depth-external
-
plamentsv Skill Economic Design Audit 2Trigger Pattern MONETARY_PARAMETER flag (required) - Inject Into Breadth agents (merged via M4 hierarchy)
-
plamentsv Bundle Verification Protocol 2Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)
-
plamentsv Skill Economic Design Audit 3Trigger Pattern MONETARY_PARAMETER flag (fee, rate, emission, cap, bps as template fields) - Inject Into Breadth agents (merged via M4 hierarchy)
-
plamentsv Skill Verification Protocol 3Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)
-
plamentsv Skill Economic Design Audit 4Trigger Pattern MONETARY_PARAMETER flag (required) - Inject Into Breadth agents (merged via M4 hierarchy)
-
plamentsv Skill Economic Design Audit 5Trigger Pattern MONETARY_PARAMETER flag (required) - Inject Into Breadth agents (merged via M4 hierarchy)
-
plamentsv Bundle Verification Protocol 5Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)
-
plamentsv Skill Economic Design Audit 6Trigger Pattern MONETARY_PARAMETER flag (fee, rate, emission, cap, bps values) - Inject Into Breadth agents (merged via M4 hierarchy)
-
plamentsv Skill Verification Protocol 6Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)
-
plamentsv Skill External Precondition Audit 2Trigger Pattern Any external package function call detected in program - Inject Into Breadth agents (merged via M5 hierarchy)
-
plamentsv Skill External Precondition Audit 3Trigger Pattern Any external module interaction detected in attack_surface.md - Inject Into Breadth agents (merged via M5 hierarchy)
-
plamentsv Skill External Precondition Audit 4Trigger Pattern Any CPI (Cross-Program Invocation) detected in program - Inject Into Breadth agents (merged via M5 hierarchy)
-
plamentsv Skill External Precondition Audit 5Trigger Pattern Any env.invoke_contract() or env.try_invoke_contract() detected in contract - Inject Into Breadth agents
-
antgroup Bundle Env Validator 2Validates .env files for security best practices. Checks for exposed secrets and suggests improvements. Use when: env check, secrets audit, dotenv security
-
antgroup Bundle Code Analyzer Pro 2Advanced static code analysis with AI-powered insights. Finds bugs, security issues, and code smells automatically. Use when: code review, static analysis, code quality, bug finding
-
starchild-ai-agent Skill Okx Audit LogUse this skill when the user asks to export audit logs, find audit log location, view command history, 导出日志, 查看日志, 日志路径, 操作记录, 调用记录, 命令历史. Do NOT use for wallet balance, token search, swap, or any other on-chain operation — use the corresponding skill instead.
Audited -
grandamenium Skill Guardrails Reference 3Full red flag table with all guardrail patterns. Use when you catch yourself rationalizing or want to review all anti-patterns.
-
h-mmer Bundle Learn 2Record a platform response and update learning. Usage: /learn <report_id> <status> [--bounty 500] [--vuln-type XSS]
-
h-mmer Bundle Dupcheck 2Check if a vulnerability has already been reported. Searches platform hacktivity + local findings. Usage: /dupcheck <vuln_type> e.g. /dupcheck XSS in search endpoint
-
h-mmer Bundle Fullscan 2Full security assessment with brain coordination. Multi-phase, skips known-exhausted areas, builds on prior knowledge.
-
is-bo Skill Forge API 2Audit API contracts, boundary validation, authorization, consistency, pagination, errors, and idempotency.
-
is-bo Skill Forge Docs 2Verify that user, contributor, architecture, operations, security, and release documentation is accurate and executable.
-
is-bo Skill Forge Cache 2First decide whether caching is justified, then audit keys, invalidation, consistency, privacy, and failure behavior.
-
jetbrains Skill Gws Admin ReportsGoogle Workspace Admin SDK: Audit logs and usage reports.
-
jetbrains Bundle Security Best PracticesPerform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.
-
aaaaqwq Bundle Skill Security AuditorSkill Security Auditor
1 -
richard0901 Skill Security Review[OMX] Run a comprehensive security review on code
-
zaxbyhub Bundle Commit Pr 2Apply when committing, pushing, opening or updating a PR, writing a pull request, creating release notes, or closing out remote CI. Enforces the opencode-swarm invariant audit, release-note fragment workflow, full validation suite, issue comment requirement, and post-PR lifecycle rules.
-
zaxbyhub Skill Commit Pr 4Apply when committing, pushing, opening or updating a pull request, or closing out CI. A portable, project-agnostic commit and PR workflow: verify before you push, write conventional commits and a clear PR body, and never commit generated or secret files.
-
zaxbyhub Skill Tech Debt CI Review 2Deep technical debt and CI stability audit for identifying test theater, missing or mis-scoped tests, actual and potential test failures, flaky-test risk, dependency/toolchain brittleness, and structural debt that prevents PRs from going green safely.
-
theneoai Bundle Nmap ExpertNmap Expert
-
theneoai Bundle Burpsuite ExpertBurp Suite Expert
-
kok-o Skill Security 2security
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include verification-protocol, skill-security-auditor, skills. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.