Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
mike007jd Bundle Gsp Hud Readability Audit 2Use when auditing HUD hierarchy, readability, controls discoverability, or mobile thumb-zone pressure.
-
mike007jd Bundle Gsp Mechanics Systems Audit 2Use when auditing core verbs, loop integrity, progression, or whether implemented systems form a playable game.
-
mike007jd Bundle Gsp Scope Completeness Audit 2Use when auditing whether delivered features actually match the promised scope and quality target.
-
mike007jd Bundle Gsp Production Readiness Audit 2Use when auditing whether a game project meets production-grade standards for release or continued iteration.
-
mike007jd Bundle Gsp Architecture Maintainability Audit 2Use when auditing structure, boundaries, coupling, or state-management risks in an existing game project.
-
drmoisan Skill Evidence And Timestamp Conventions 2Evidence storage and timestamp naming conventions for audits and remediation. Use when storing baseline/regression/QA evidence or naming audit artifacts with ISO-8601 timestamps.
-
keyvaluesoftwaresystems Skill Postgres PatternsPostgreSQL database patterns for query optimization, schema design, indexing, and security. Based on Supabase best practices.
-
keyvaluesoftwaresystems Skill Quarkus SecurityQuarkus Security best practices for authentication, authorization, JWT/OIDC, RBAC, input validation, CSRF, secrets management, and dependency security.
-
keyvaluesoftwaresystems Skill Springboot SecuritySpring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.
-
yue-zhou1 Bundle Signature Scheme Auditor 2Audit classical signature schemes — generic ECDSA across curves, Schnorr/ BIP-340, EdDSA/Ed25519, RSA-PSS and PKCS#1 v1.5 — for verification-equation correctness, malleability, canonical encoding, public-key validation, and hash/prehash semantics. Use for standalone signature library review outside Ethereum application encoding, BLS, or threshold protocols.
-
yue-zhou1 Bundle Differential Test Harness Gen 2Generate cross-implementation differential test harnesses for cryptographic code: official test-vector and Wycheproof replay, normalization of error/result semantics, deterministic corpus capture, and evidence handoff to crypto-fp-check. User-triggered only — never auto-invoked by the audit flow.
-
yue-zhou1 Bundle Commitment Scheme Auditor 2Audit polynomial commitment schemes (KZG, FRI, IPA, Pedersen) for degree bound enforcement, evaluation proof verification, trusted setup provenance, and batch opening soundness.
-
yue-zhou1 Bundle Encryption Scheme Auditor 2Audit encryption implementations for AEAD nonce handling, decrypt oracle behavior, associated-data binding, key-derivation misuse, and decrypt-error side effects.
-
asymmetric-al Skill Repo Entry 2Audit or update Core's repository instruction system and skill mirrors. Use for AGENTS.md architecture, canonical skill ownership, skills:sync, or skills:verify; do not invoke for ordinary application work.
-
kora-projects Bundle Kora Soap Client 2SOAP/WSDL clients in Kora 2.x — wsdl2java (Apache CXF, jakarta) generates jakarta.jws @WebService interfaces, then the Kora processor generates $Service_SoapClientImpl and a @Module $Service_SoapClientModule from artifact io.koraframework:soap-client. Covers SoapClientModule, SoapServiceConfig under soapClient.<PortType> (url, timeout, telemetry), synchronous generated methods, SoapFaultException / SoapInvalidHttpResponseException / SoapRequestMarshallingException, typed @WebFault exceptions, WS-Security via SoapEnvelopeProcessorsUtils.wssAuth and the tagged Function<SoapEnvelope, SoapEnvelope> envelope processor, MTOM/XOP multipart responses, RPC Holder out-params, and the Gradle wsdl2java wiring for Java (annotation-processors) and Kotlin (KSP symbol-processors). Use when consuming an external SOAP service from a Kora service, or when a generated SOAP client is missing from the graph.
-
mike007jd Bundle Gsp Feel Audit 2Use when auditing control feel, responsiveness, timing, camera reaction, or animation feedback in a game.
-
mike007jd Bundle Gsp Orchestrator 2Use when a request needs routing across this Game Superpowers collection for build, audit, repair, or polish work.
-
mike007jd Bundle Gsp Project Audit 2Use when running a top-level audit of an existing game project before repair or major changes.
-
mike007jd Bundle Gsp UX Flow Audit 2Use when auditing first-minute onboarding, menus, fail/retry flow, or player comprehension in a game.
-
ldilov Skill Security Scan 2Auto-discoverable wrapper for `.hforge/library/skills/security-scan/SKILL.md`.
-
grcengclub Skill Glba ExpertGLBA expert for financial institutions. Deep knowledge of Gramm-Leach-Bliley Act including Safeguards Rule (16 CFR Part 314), Privacy Rule (16 CFR Part 313), FTC enforcement, information security program requirements, vendor management, and consumer privacy notices.
-
grcengclub Skill Au Apra Cps 234 ExpertAPRA CPS 234 expert for Australian prudential information security. Reference-depth framework plugin with scope determination, evidence checklist, and SCF-backed assessment guidance.
-
me2resh Skill Docs Audit 2Diataxis docs audit — tutorials, how-to, reference, explanation; checks README, API docs, deployment guides, changelog, staleness.
-
me2resh Skill Compliance Check 2GDPR + ePrivacy audit — consent, privacy policy, data handling, right-to-deletion, DPAs. Deep-dive for /launch-check compliance.
-
me2resh Skill Monitoring Audit 2Observability audit — logging, error tracking, health endpoints, alerting, runbooks. Deep-dive for /launch-check monitoring.
-
me2resh Skill Performance Audit 2Performance audit — bundle size, image opt, lazy load, code split, caching, CWV. Deep-dive for /launch-check performance.
-
caixinyu2017-star Skill Reference VerifyVerify references in an academic paper: check whether each BibTeX entry is real, whether in-text citations match the cited paper's actual content, and produce a structured verification report. Use when user says "验证参考文献", "ref verify", "check references", "核实引用", "引用是否正确", or wants to audit citations in a LaTeX manuscript.
-
kwakseongjae Bundle Omd Feel 2디자인·프론트 업계가 '감'으로 쓰던 인터페이스 디테일을 수치화한 규칙으로 적용(APPLY)하거나 감사(AUDIT)한다. Jakub Krehel의 make-interfaces-feel-better 철학을 계승 + HIG/Material/WCAG/DS 토큰/실무자 리서치로 확장한 17축·113규칙(provenance 등급별). 모션 타이밍·이징·동심원 radius·tabular-nums·44px 타깃·focus ring·prefers-reduced-motion 등. 'feel 좋게 다듬어줘', '인터페이스 디테일 적용', 'feel 점검', '마이크로 인터랙션 손봐줘', 'make this feel better', 'polish the interactions', 「インターフェースの細部を詰めて」, 「介面細節打磨」 류에 트리거. 브랜드 토큰은 DESIGN.md(omd:apply)가 우선.
-
promovaweb Bundle Specsfy Specialist Application Security 2Modelar ameaças e revisar segurança de aplicações, APIs, autenticação, autorização, dados, dependências, secrets e infraestrutura. Use para mudanças com trust boundaries, identidade, entrada externa, dados sensíveis ou revisão de segurança; não declare segurança sem evidência.
-
dss-time Bundle Safe Code Review 2Review a concrete diff or PR through three independent axes: repository conformance, change-intent fidelity, and operational safety, then deduplicate evidence-backed findings. Use automatically for broad change review, not specialist-only security, performance, API, or migration assessment. Read-only: never implement fixes without a separate explicit request and write authorization. 通过仓库符合度、变更意图忠实度和运行安全三个独立轴审查具体 Diff 或 PR,再对有证据的问题去重。适合自动承接广泛变更审查,不吸收单一安全、性能、API 或迁移专项。本 Skill 只读;没有独立明确请求和写权限时绝不实施修复。
-
dss-time Bundle Repo Doctor Router 2Explicit routing entrypoint that recommends one verified Repo Doctor Skill and fast, standard, or audit mode from the current repository state, or returns a registered workflow when detailed routing is requested. Use only when the user explicitly invokes the Router or asks for Repo Doctor routing. Do not execute the recommendation, route ordinary factual questions, invent aliases, or bypass permission gates. 显式路由入口:根据当前仓库状态推荐一个已核验 Repo Doctor Skill 及 fast、standard 或 audit 模式;用户要求详细路由时再返回注册工作流。仅在用户显式调用 Router 或明确要求 Repo Doctor 路由时使用。不得执行推荐、路由普通知识问答、编造别名或绕过权限门禁。
-
dss-time Bundle Configuration Audit 2Explicit-invocation audit of configuration sources, precedence, overrides, defaults, validation, drift, dangerous settings, undocumented variables, and credential-commit risk using repository evidence. Do not trigger for one settled config edit, read sensitive values, connect to external environments, or modify configuration. 仅显式调用:基于仓库证据审计配置来源、优先级、覆盖、默认值、校验、漂移、危险设置、未文档化变量和凭据误提交风险。不得因一个已确定配置修改而触发,不读取敏感值、不连接外部环境,也不修改配置。
-
dss-time Bundle Project Health Check 2Explicit-invocation broad repository diagnosis across architecture, correctness, security, performance, dependencies, tests, and general release risk. Do not trigger for a bounded file, error, diff, or simple request. Use a specialized review for one dependency upgrade, API contract, migration, dead-code candidate, security surface, performance regression, configuration scope, or release candidate. 仅显式调用的全仓库诊断,覆盖架构、正确性、安全、性能、依赖、测试和一般发布风险。不得因单个文件、明确报错、Diff 或简单请求而触发。单一依赖升级、API 契约、迁移、死代码候选、安全边界、性能回归、配置范围或候选版本应使用对应专项 Skill。
-
dss-time Bundle Requirements To Spec 2Convert requirements whose material product, data, security, permission, compatibility, and acceptance decisions are already closed into a structured, implementable, testable specification. Use when a clarification summary or settled discussion is ready for specification and only non-blocking assumptions remain; stop and route material open decisions to requirements-clarification. Do not use for task decomposition, implementation planning, code explanation, bug fixing, or direct edits. 将产品、数据、安全、权限、兼容性和验收等重大决策已经闭合的需求整理为结构化、可实施、可验证的规格。用于已有澄清摘要或讨论已定稿、只剩非阻塞假设时;发现重大未决决策必须停止并转交 requirements-clarification。不用于拆工作项、制定实施计划、解释代码、修 Bug 或直接修改。
-
dss-time Bundle Security Focused Review 2Explicit-invocation scoped security review that establishes assets, trust boundaries, attacker prerequisites, and evidence-backed findings across the named security surface. Do not trigger for general code review, run attacks, access production, reveal credentials, or implement fixes. 仅显式调用:针对指定安全边界建立资产、信任边界和攻击前提,并输出有证据的专项发现。不得因普通代码审查而触发,不执行攻击、不访问生产、不显示凭据,也不实施修复。
-
dss-time Bundle Skill Quality Audit 2Perform a strictly read-only, pre-release quality audit of one AI Skill, a Pack, a plugin, or a Skills repository across structure, triggering, workflow, progressive resources, bilingual cross-platform output, safety, and publishing integration. Use when maintainers want findings, severity, evidence, and a release recommendation; do not audit ordinary application code or PRs, run a broad project health check, gate a product release candidate, or automatically fix files. 对一个 AI Skill、Pack、插件或 Skills 仓库执行严格只读的发布前质量审计,覆盖结构、触发、工作流、渐进资源、双语跨平台产物、安全和发布集成。维护者需要发现、严重度、证据和发布建议时使用;不用于普通应用代码或 PR 审查、广泛项目体检、产品候选版本门禁,也不自动修复文件。
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include gsp-hud-readability-audit, gsp-mechanics-systems-audit, gsp-scope-completeness-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.