Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
dss-time Bundle Dependency Upgrade Analysis 2Explicit-invocation analysis of one defined dependency upgrade using manifests, lockfiles, repository usage, and verified official release evidence, covering compatibility, security, licensing, validation, and rollback. Do not trigger for ordinary code changes or modify manifests or lockfiles. 仅显式调用:基于 manifest、锁文件、仓库用法和已验证官方发布资料分析一个已定义的依赖升级,覆盖兼容、安全、许可证、验证和回滚。不得因普通代码变更而触发,也不修改 manifest 或锁文件。
-
ihabkhaled Skill Evidence Floor 2Use when mandatory behavior, integration, security, migration, or data requirements lack the appropriate kind of proof.
-
ihabkhaled Skill Loophole Hunter 2Use when rules appear satisfied while their intent is bypassed, counters reset, classifications change conveniently, or an AI-Psychiatry audit is requested.
-
ihabkhaled Skill Decision Readiness 2Use when an important implementation, architecture, security, data, or delivery decision rests on unresolved critical unknowns.
-
ihabkhaled Skill Executive Override 2Use when an AI-Psychiatry budget expires while new evidence shows a narrow extension is required for correctness, security, or completion.
-
heyeddi-com Bundle Pre Merge Gate 3Runs pre-merge checks (tests, build, types, optional UI audit) and returns a markdown pass/fail report. Use when QA approves a PR or before merge to main.
-
heyeddi-com Bundle Engineering Excellence 3Audits code for KISS, YAGNI, DRY, SOLID, and testability; maintains living engineering notes under .heyeddi/docs/engineering/. Use when refactoring, before merge, or when the user asks for simple scalable design, architecture notes, reuse catalog, or engineering ADRs — not for visual UX (use ux-flow-auditor) or CI gates (use pre-merge-gate).
-
vetcoders Bundle Vc Audit 2READ-ONLY falsification of a completed plan or multi-task implementation. Builds a per-task requirements matrix, then proves or refuses each claim against code + tests evidence. Default verdict is UNVERIFIED — PASS is earned, never assumed. Runs whenever a written plan claims completion, regardless of upstream — workflow, implement, marbles, human work, or a mix. Trigger phrases: "audit", "vc-audit", "task-by-task audit", "verify implementation plan", "spec falsification", "post-marbles audit", "did this plan actually land", "weryfikuj implementację", "audyt planu", "co naprawdę wylądowało", "falsyfikacja completion".
-
vetcoders Bundle Vc Intents 2Operator-side intention-to-runtime truth audit. Use when the team needs to know which planned implementations actually landed in code, which are only partially present, which never materialized, and what the highest remaining truth is. This skill pulls intentions from aicx, reduces them to a bounded implementation checklist, then verifies each item against the live repo. Trigger phrases: "intents", "co z planu siedzi", "which planned items exist", "what from the plan is in code", "check intent coverage", "planned vs code", "highest truth", "checklist from intents".
-
kai-cli Bundle Secupdates 2Security news from tldrsec, no.security, Krebs, Schneier, and other sources. USE WHEN security news, security updates, what's new in security, breaches, security research, sec updates, tldrsec, Krebs, Schneier.
-
zereight Bundle Zereight Review 2Comprehensive code review skill for practical PR feedback. Use for feature, bugfix, and refactor reviews. Prioritizes correctness, edge cases, logic invariants, fallback-chain safety, async state transitions, architecture analysis, OWASP security, and clear actionable feedback.
-
stevennitesh Bundle Writing For Agents 2Create, edit, or audit instructions agents consume, including skills, AGENTS.md, prompts, guides, specs, tickets, handoffs, and subagent assignments used in orchestration. Exclude ordinary human-facing prose, application code, and orchestration mechanics such as worker selection, scheduling, or integration.
-
zouyangxiaohao111 Skill Code ReviewerExpert code reviewer who provides constructive, actionable feedback focused on correctness, maintainability, security, and performance — not style preferences.
-
zouyangxiaohao111 Skill Autonomous Optimization ArchitectIntelligent system governor that continuously shadow-tests APIs for performance while enforcing strict financial and security guardrails against runaway costs.
-
tugoukezhang Skill Skills Security Check腾讯云鼎实验室出品,Skill安全审查工具。对用户指定的skill.md文件及其配套的文档、程序、脚本等进行全面安全审计,确保引用安全
-
mateaix Skill Requesting Code ReviewPre-commit review: security scan, quality gates, auto-fix.
-
understudy-ai Bundle Skill CreatorCreate, edit, improve, review, audit, or clean up AgentSkills. Use when creating a new skill from scratch or when asked to improve, review, audit, tidy up, or restructure an existing skill or SKILL.md file. Also use when editing a skill directory, moving content into scripts/ or references/, or validating against the AgentSkills spec.
-
oceanfsdfsvfdsvs Skill Saas License Rightsize 2Audit SaaS license exports, HR rosters, and usage CSVs to find reclaim, downgrade, duplicate-account, departed-employee, stale-admin, and owner-review opportunities. Use when IT, finance, procurement, MSP, or operations teams need a local-first license rightsize report before renewals, QBRs, budget reviews, or access cleanup without calling vendor APIs.
-
oceanfsdfsvfdsvs Skill Vendor Bank Change Preflight 2Review vendor bank-account change requests for payment-redirection, vendor impersonation, and audit-trail risk before AP updates bank details or releases ACH/wire/check payments. Use when finance, accounting, procurement, founders, or operators need a local-first callback and evidence check without connecting to an ERP, bank portal, or supplier portal.
-
oceanfsdfsvfdsvs Skill Security Questionnaire Triage 2Triage B2B security questionnaires into evidence-backed answers, escalation items, and safe non-answer labels.
-
oceanfsdfsvfdsvs Skill Employee Offboarding Access Preflight 2Audit employee or contractor offboarding exports for lingering access, privileged roles, direct-login SaaS accounts, active sessions, unreturned assets, and unrotated secrets before a departure or role-change access review is closed. Use when IT, security, HR ops, MSP, founders, or compliance owners need a local-first deprovisioning evidence report without connecting to an IdP, HRIS, MDM, or SaaS admin API.
-
oceanfsdfsvfdsvs Skill Rental Security Deposit Dispute Preflight 2Preflight residential rental security deposit return or deduction disputes before a tenant, renter helper, housing advocate, property manager, or small-claims filer sends a demand letter, complaint, or court packet. Use when the user needs to check refund deadlines, itemized deduction statements, normal wear-and-tear claims, move-in and move-out evidence, forwarding-address proof, receipts or estimates, deposit-cap issues, redaction risks, and owner next steps without making legal conclusions or filing live claims.
-
kennyolofsson23-netizen Skill Geo Platform OptimizerPlatform-specific AI search optimization — audit and optimize for Google AI Overviews, ChatGPT, Perplexity, Gemini, and Bing Copilot individually
-
nativ3ai Skill Requesting Code ReviewPre-commit review: security scan, quality gates, auto-fix.
Audited -
filippodesilva Bundle Nestjs SecurityImplement JWT authentication, RBAC guards, Helmet hardening, and Argon2 hashing in NestJS. Use when adding auth strategies, role-based access control, CSRF protection, or security headers.
-
arcadeai Skill Quality Review 2Deep review of any work-product — code, docs, specs, plans, decisions — grounded in current authoritative sources. Use when double-checking against latest docs, verifying versions or claims, checking security, or pressure-testing correctness and elegance before something ships. Complements the automatic quality hook with ecosystem verification. NOT for divergent ideation (brainstorm), weighing still-open options (figure-it-out), your own spec's framing (self-review), or scenario review (review-spec).
-
kwakseongjae Bundle Omd Slop Audit 2실제 제품 route의 UI·UX copy를 검사해 제품 맥락 없이 반복된 생성형 기본 패턴, 브랜드 근거 없는 장식, 카드·그라데이션·아이콘 타일 남용, 번역투와 추상 카피를 rule ID와 line ref로 진단한다. 'AI slop 잡아줘', '템플릿 같아', '왜 AI가 만든 화면 같지?', 'anti-slop audit' 요청에 사용한다. 접근성 오류와 취향 차이를 별도 등급으로 구분한다.
-
kwakseongjae Bundle Omd Orchestrator 2멀티 에이전트 디자인 워크플로우 supervisor. writer, locale adaptation, humanize, UI slop audit, designer review, final QA, image materialization을 routing한다. 2-round revision cap을 유지하며 다국어 문서·UI 개선·출간 준비처럼 여러 역할이 필요한 요청에 사용한다.
-
timdevai Skill Gdpr Audit PrepGdpr Audit Prep
-
gmickel Bundle Flow Next Audit 2Audit `.flow/memory/` entries against the current codebase and decide Keep / Update / Consolidate / Replace / Delete / Harden per entry. Triggers on /flow-next:audit, "audit memory", "review memory", "refresh learnings", "sweep stale memory", "consolidate overlapping memory entries", "graduate a recurring lesson into a gate". Optional `mode:autofix` token in arguments runs without questions and marks ambiguous as stale (Harden is never auto-applied). Optional scope hint after the mode token (concept, category, module, or path) narrows what gets audited.
-
gmickel Bundle Flow Next Audit 3Audit .flow/memory/ entries against current code and keep, update, consolidate, replace, delete, or harden each. Use when asked to audit memory or graduate a recurring lesson into a gate.
-
rongxinzy Bundle Git Repo Audit深度分析 Git 仓库历史,识别高频变更的热点文件、分析代码的实际贡献归属关系、并扫描历史提交中的密钥泄露等安全隐患。当用户提及分析仓库、查看代码归属、寻找热点文件或安全风险扫描,或询问团队协作、代码审查分配、技术债务与安全审计等关键词时触发。
-
edwinhu Skill Audit ArchiveUse when archiving footnote URLs to perma.cc during a Bluebook footnote audit - 'archive the links', 'perma the URLs', 'these links will rot', 'add perma.cc archives to the footnotes', 'the journal wants archived URLs', or reaching Phase 6 of a bluebook-audit run.
-
matiascomercio Skill Ac Safety Harden Supply Chain SecHardens package-manager supply chain configuration with minimum release age policies, dry-run gates, and optional dependency security review. Triggers on keywords: harden supply chain, supply chain security, minimum release age, package age gate
-
davidtoby Bundle Video Bilingual Subtitle Delivery 2Create, repair, audit, and deliver bilingual video subtitles with English speech timing and Chinese aligned on the same subtitle event. Use when asked to add English/Chinese subtitles to a video, fix subtitle sync, fill missing Chinese lines, produce softsub or hardcode MP4 deliverables, or turn a messy subtitle workflow into a reliable repeatable delivery process.
-
borda Skill Integration 2Adapter over `codemap-py integrate` — audit, plan, source-wire, locally sync, and demonstrate the codemap-py integration with its supported consumers. Trigger with `/codemap-py:integration audit|plan|apply|sync|demo [--runtime {claude,codex,both}] ...`. Default (no args) is `audit`. Skip for: running a structural query (use `/codemap-py:query-code`); explicit standalone index rebuild (use `/codemap-py:scan-codebase`).
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include executive-override, video-bilingual-subtitle-delivery, integration. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.