Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
is-bo Skill Forge Reliability 2Audit timeouts, retries, overload, dependencies, degradation, consistency, and operational objectives.
-
is-bo Skill Forge Integrations 2Audit outbound and inbound integrations for authentication, validation, failure isolation, drift, and replay safety.
-
is-bo Skill Forge Supply Chain 2Inspect dependencies, build integrity, provenance, releases, licenses, actions, and secret exposure across the delivery chain.
-
is-bo Skill Forge API 3Audit API contracts, boundary validation, authorization, consistency, pagination, errors, and idempotency.
-
is-bo Skill Forge Docs 3Verify that user, contributor, architecture, operations, security, and release documentation is accurate and executable.
-
is-bo Skill Forge Infrastructure 2Audit infrastructure as code, network and identity boundaries, encryption, state, drift, and least privilege.
-
is-bo Skill Forge Cache 3First decide whether caching is justified, then audit keys, invalidation, consistency, privacy, and failure behavior.
-
is-bo Skill Forge Offline 3Audit local persistence, queued actions, synchronization, conflicts, revocation, privacy, and recovery under intermittent connectivity.
-
is-bo Skill Forge Discover 3Build an evidence-backed application profile and architecture map before any specialized audit begins.
-
is-bo Skill Forge Payments 3Audit money movement, pricing, entitlements, provider events, reconciliation, idempotency, and sensitive data boundaries.
-
is-bo Skill Forge Security 3Perform a threat-informed audit of trust boundaries, injection, secrets, browser controls, dependencies, and abuse cases.
-
is-bo Skill Forge Reliability 3Audit timeouts, retries, overload, dependencies, degradation, consistency, and operational objectives.
-
is-bo Skill Forge Integrations 3Audit outbound and inbound integrations for authentication, validation, failure isolation, drift, and replay safety.
-
is-bo Skill Forge Supply Chain 3Inspect dependencies, build integrity, provenance, releases, licenses, actions, and secret exposure across the delivery chain.
-
is-bo Skill Forge Infrastructure 3Audit infrastructure as code, network and identity boundaries, encryption, state, drift, and least privilege.
-
spike-faye-lei Skill Citation Audit 2Zero-context verification that every bibliographic entry in the paper is real, correctly attributed, and used in a context the cited paper actually supports — catching hallucinated authors, wrong years, fabricated venues, version mismatches, and wrong-context citations. Use when user says "审查引用", "check citations", "citation audit", "verify references", "引用核对", or before submission to ensure bibliography integrity.
-
braxtonrose4 Skill SherlockOSINT username search across 400+ social networks. Hunt down social media accounts by username.
Audited -
masih-0x3 Bundle AsoWhen the user wants to audit or optimize an App Store or Google Play listing. Also use when the user mentions 'ASO audit,' 'app store optimization,' 'optimize my app listing,' 'improve app visibility,' 'app store ranking,' 'audit my listing,' 'why aren't people downloading my app,' 'improve my app conversion,' 'keyword optimization for app,' or 'compare my app to competitors.' Use when the user shares an App Store or Google Play URL and wants to improve it.
-
masih-0x3 Bundle Competitor ProfilingWhen the user wants to research, profile, or analyze competitors from their URLs. Also use when the user mentions 'competitor profile,' 'competitor research,' 'competitor analysis,' 'profile this competitor,' 'analyze competitor,' 'competitive intelligence,' 'competitor deep dive,' 'who are my competitors,' 'competitor landscape,' 'competitor dossier,' 'competitive audit,' or 'research these competitors.' Input is a list of competitor URLs. Output is structured competitor profile markdown files. For creating comparison/alternative pages from profiles, see competitors. For sales-specific battle cards, see sales-enablement.
-
seikaikyo Skill Tgd Security And HardeningHardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services.
-
mr-q526 Bundle Security Best PracticesPerform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.
-
manusco Bundle Page Audit 2Page Audit
-
gongyijie85 Skill Perl SecurityComprehensive Perl security covering taint mode, input validation, safe process execution, DBI parameterized queries, web security (XSS/SQLi/CSRF), and perlcritic security policies. Use when reviewing Perl input handling, process execution, DBI queries, or web-facing code.
-
yknothing Bundle Pc Risk Assessment 2Use when planned work must be challenged for delivery, dependency, migration, security, or operational risk before the team commits to scope or sequence.
-
yknothing Bundle Pc Security Design 2Use when the architecture is defined and the team must turn trust boundaries, sensitive data paths, and attacker assumptions into concrete control design before implementation and audit.
-
viktorsbaikers Bundle Rite Review 2Review polished feature diff for correctness, readability, architecture, security, tests proving acceptance, Critical/Important findings, and quality dimensions before seal.
-
viktorsbaikers Bundle Rite Frame 2Frame an ad-hoc ask before coding, then audit the diff. Use for underspecified imperative asks, raw-diff self-audits, or `$rite-quick` setup. Not a lifecycle gate.
-
viktorsbaikers Bundle Rite Review 3Review polished feature diff for correctness, readability, architecture, security, tests proving acceptance, Critical/Important findings, and quality dimensions before seal.
-
viktorsbaikers Bundle Rite Clarify 2Audit a completed spec for missing decisions before strategy or architecture. Use after $rite-spec when coverage is incomplete or stale; not for spec writing.
-
viktorsbaikers Bundle Rite Upgrade 2Audit and reconcile an older released DevRites workspace. Proves a current-contract defect, then routes its phase owner while preserving completed work and history.
-
viktorsbaikers Skill Devrites Audit 2Audit one feature read-only for security, performance, or simplification risks. Use for one bounded audit axis; not for code changes.
-
viktorsbaikers Skill Devrites Audit 3Audit one feature read-only for security, performance, or simplification risks. Use for one bounded audit axis; not for code changes.
-
oleg-koval Skill Dependabot Triage 2Triage all open Dependabot and Renovate PRs in bulk: classify each by risk tier (patch / minor / major / security), auto-approve and merge safe patch-only bumps, flag breaking major upgrades with a summary of what changed, and post a digest of what was done. Use when dependency PRs are piling up, when the user says "deal with Dependabot", "triage dependency updates", or "merge the safe ones", or at the start of a maintenance window.
-
oleg-koval Skill Skill Budget Audit 2Diagnose and fix Claude Code's skill context budget overflow, identify heavy plugin bundles that exceed the 2% budget, remove domain-specific ones, deactivate rarely-used skill sets, and validate the warning clears. Use when Claude Code shows "Exceeded skills context budget" or skill descriptions are stripped.
-
muhammedadnank Bundle Audit IntegrityShared audit integrity framework for all AppSec agents — enforces output quality, intellectual honesty, and continuous improvement through anti-rationalization guards, self-critique loops, retry protocols, non-negotiable behaviors, self-reflection quality gates (1-10 scoring, ≥8 threshold), and a self-learning system with lesson/memory governance for security analysis agents.
-
farmage Bundle The FoolUse when challenging ideas, plans, decisions, or proposals using structured critical reasoning. Invoke to play devil's advocate, run a pre-mortem, red team, or audit evidence and assumptions.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include forge-offline, rite-upgrade, security-best-practices. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.