Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
farmage Bundle Test MasterGenerates test files, creates mocking strategies, analyzes code coverage, designs test architectures, and produces test plans and defect reports across functional, performance, and security testing disciplines. Use when writing unit tests, integration tests, or E2E tests; creating test strategies or automation frameworks; analyzing coverage gaps; performance testing with k6 or Artillery; security testing with OWASP methods; debugging flaky tests; or working on QA, regression, test automation, quality gates, shift-left testing, or test maintenance.
-
hamza-ali-shahjahan Skill Moat Builder 2Identify and deepen moats — workflow lock-in, data network effects, domain depth, integration depth. Audit current moats + propose investments.
-
hamza-ali-shahjahan Skill Security Reviewer 2Pre-launch security review covering auth, data exposure, input validation, and dependency vulns. Produces a remediation list, not a "looks good" stamp.
-
hamza-ali-shahjahan Skill Compliance Auditor 2Pre-enterprise compliance check — SOC2 / GDPR / HIPAA / CCPA gap analysis with prioritized remediation. Not a substitute for real audit.
-
egregore-labs Skill Review Pr 2Use when the user says 'review PR', 'is this PR safe to merge', or 'audit PR' — runs a CTO-level 10-point review checklist on one or more pull requests. Not creating a PR (/pr) or validating local changes (/test).
-
sky-cube Skill Skill 55全局安全审计报告的结构与编制规范。当需要汇总各专项审计结果,输出面向管理层与技术团队的全局安全审计报告时使用。
-
sky-cube Skill AI Skill 3AI 代码专项安全审计:模型凭证、提示词模板安全、输出内容合规。当项目集成大模型能力或产出 AI 相关代码,需要专项审计其安全性与合规性时使用。
-
sky-cube Skill Skill 59Skill
-
sky-cube Skill Skill 60容器镜像漏洞扫描流程与镜像安全加固要求。当构建容器镜像或部署容器前需要扫描镜像漏洞并执行安全加固时使用。
-
sky-cube Skill Skill 75Skill
-
robomotionio Bundle Semgrep Rule CreatorCreates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. Use when writing Semgrep rules or building custom static analysis detections.
-
agentik-os Bundle Blueprint Os 2Compile software, AI, platform, service, marketplace, mobile, web, or internal-tool ideas and existing project context into a complete, coherent, traceable Product + Technical Definition Pack before implementation planning or coding. Trigger on /blueprint, Blueprint {OS}, product blueprint, product-definition audit, recovery, revision, extension, delta, or preparation for Stepper {OS}. Preserve project decisions and stable IDs, separate evidence from assumptions, define product/UX/domain/data/API/AI/security/operations/test contracts, run gates, and continue across outputs without declaring partial work complete.
-
ascend Bundle Security Code Review多语言安全代码审查 (Security Code Review)。对 Python、C++、Shell、Markdown 文件进行系统性安全漏洞检测与修复指导。覆盖 OWASP Top 10、CWE Top 25、CERT 安全编码标准。当用户提及以下内容时,务必使用此技能:安全审查、安全代码审查、security review、code review 中的安全检查、漏洞扫描、安全合规检查(CWE/CERT/OWASP)、编写安全代码、检查代码安全性、推理服务安全审计、多模态 Token 安全校验、JSON 嵌套深度攻击防护。即使用户没有明确说'安全审查',只要涉及代码安全性评估、漏洞检测、安全最佳实践,都应触发此技能。
-
hwj123hwj Bundle Writing ShapeWriting, exploit — shape raw material into an article, paragraph by paragraph.
-
yue-zhou1 Bundle Audit Common 2Provides shared severity, testing-evidence, and finding-contract references for ZK and cryptographic audit skills. Use when classifying findings, checking whether test evidence is sufficient, or writing findings in a consistent structure.
-
yue-zhou1 Bundle Mpc Auditor 2Audit MPC implementations for garbled-circuit integrity, oblivious transfer misuse, share validation, Beaver triple authenticity, and transcript/session binding issues.
-
yue-zhou1 Bundle Vdf Auditor 2Audit VDF implementations for sequentiality assumptions, Wesolowski/Pietrzak verifier soundness, challenge derivation integrity, and modulus/group setup risks.
-
yue-zhou1 Bundle Vrf Auditor 2Audit Verifiable Random Function implementations (RFC 9381 ECVRF and RSA-FDH-VRF) for key validation, ciphersuite/suite-string domain separation, encode-to-curve and cofactor handling, proof-to-hash ordering, and uniqueness/pseudorandomness assumptions, plus application-level output grinding. Use when reviewing VRF provers, verifiers, or consumers of VRF outputs (leader election, lotteries, randomness beacons).
-
yue-zhou1 Bundle Crypto Fp Check 2Verifies suspected ZK and cryptographic findings before reporting. Use when deciding whether a suspected vulnerability is a TRUE POSITIVE or FALSE POSITIVE, assigning severity, or enforcing the Critical/High PoC gate.
-
yue-zhou1 Bundle Noir Auditor 2Audit Noir circuits for unconstrained function boundary failures, oracle validation gaps, Brillig/ACIR consistency issues, and witness-generation soundness bugs.
-
yue-zhou1 Bundle Zkvm Auditor 2Audit zkVM guest programs and proof systems for memory consistency, continuation proof soundness, precompile safety, and guest-host boundary violations across SP1, RISC Zero, and Valida.
-
yue-zhou1 Bundle Fix Verification 2Use when a supplied patch claims to fix a previously verified ZK or cryptographic finding and the remediation needs independent verification.
-
yue-zhou1 Bundle Cairo Auditor 2Audit Cairo and Starknet code for hint validation failures, felt252 overflow, builtin misuse, and Sierra-to-CASM soundness gaps. Use when reviewing Cairo contracts, prover hints, or Starknet-specific proof construction.
-
yue-zhou1 Bundle Zkbugs Index 2Queryable index of real-world ZKP vulnerabilities. Use when a Phase 2 audit skill identifies a suspicious pattern and needs to check whether a similar bug has been documented before — or when a confirmed finding needs to be recorded. Covers circom, noir, halo2, cairo, zkVM, and custom DSLs. Backed by upstream community corpus (zksecurity/zkbugs) and configurable organization findings repo.
-
yue-zhou1 Bundle Fhe Auditor 2Audit FHE implementations for noise-budget accounting, bootstrapping correctness, modulus-switching safety, plaintext leakage, and key-switch parameter integrity.
-
yue-zhou1 Bundle Spec Delta Checker 2Compare cryptographic code against a reference specification or paper. Use when implementation details look close to a standard but may have drifted in validation, transcript binding, parameter negotiation, or caller obligations.
-
yue-zhou1 Bundle Crypto Audit Router 2Route a full cryptographic or ZK audit across the framework. Use when you need to decide which skill should run next, which domain auditors apply, or how to move from initial context to verified finding, report, and index flow.
-
yue-zhou1 Bundle Crypto Audit Context 2Builds initial audit context for ZK and cryptographic code before vulnerability hunting. Use when starting a crypto audit, mapping trust boundaries, prioritizing code paths, or applying dimensional analysis to protocol values.
-
yue-zhou1 Bundle Crypto Report Writer 2Write final audit findings for ZK and cryptographic reviews. Use when a finding has survived verification and needs to be turned into clear report prose with severity, impact, root cause, and test evidence.
-
yue-zhou1 Bundle Fuzz Harness Gen 2Generate cargo-fuzz targets for Rust cryptographic code. User-triggered only and never auto-invoked by the audit flow. Produces crash and edge-case evidence for crypto-fp-check.
-
yue-zhou1 Bundle Kani Harness Gen 2Generate Kani proof harnesses for Rust crypto code. User-triggered only — never auto-invoked by the audit flow. Produces formal verification evidence for crypto-fp-check.
-
yue-zhou1 Bundle Lattice Auditor 2Audit lattice-based cryptography for LWE/RLWE parameter soundness, noise sampling correctness, rejection-sampling safety, and decryption-failure assumptions.
-
yue-zhou1 Bundle Pqc Kem Auditor 2Audit standardized post-quantum KEM implementations — currently ML-KEM / FIPS 203 — for encapsulation/decapsulation conformance, implicit-rejection correctness, ciphertext and key validation, compression/rounding, and decapsulation-failure oracle resistance. Use when reviewing ML-KEM/Kyber APIs, serialization, or decapsulation paths.
-
yue-zhou1 Bundle Zk Circuit Auditor 2Audit ZK circuits, proof systems, and verifier code for soundness and transcript failures. Use when reviewing witness constraints, Fiat-Shamir flows, KZG/PCS setup assumptions, public input encoding, or recursive proof threading.
-
yue-zhou1 Bundle Dkg Threshold Auditor 2Audit DKG, threshold-signature, and FROST/MuSig-style code for rogue-key, nonce-binding, share-verification, and session-isolation failures. Use when reviewing key aggregation, VSS share checks, threshold reconstruction, or concurrent signing state.
-
yue-zhou1 Bundle Dependency Auditor 2Audit cryptographic dependency sets for vulnerable versions, security-significant feature flags, advisory coverage, transitive risk, and stale fork provenance.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include 安全审计报告生成Skill, mpc-auditor, semgrep-rule-creator. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.