Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
kitfunso Skill Design Review 2Designer's eye QA: finds visual inconsistency, spacing issues, hierarchy problems, AI slop patterns, and slow interactions — then fixes them. Iteratively fixes issues in source code, committing each fix atomically and re-verifying with before/after screenshots. For plan-mode design review (before implementation), use /plan-design-review. Use when asked to "audit the design", "visual QA", "check if it looks good", or "design polish". Proactively suggest when the user mentions visual inconsistencies or wants to polish the look of a live site.
-
24601 Skill Design Review 2Designer's eye QA: finds visual inconsistency, spacing issues, hierarchy problems, AI slop patterns, and slow interactions — then fixes them. Iteratively fixes issues in source code, committing each fix atomically and re-verifying with before/after screenshots. For plan-mode design review (before implementation), use /plan-design-review. Use when asked to "audit the design", "visual QA", "check if it looks good", or "design polish". Proactively suggest when the user mentions visual inconsistencies or wants to polish the look of a live site.
34 -
brainally Skill Porters Five ForcesPerform Porter's Five Forces analysis — competitive rivalry, supplier power, buyer power, threat of substitutes, and threat of new entrants. Use when analyzing industry dynamics, assessing competitive forces, or evaluating market attractiveness.
-
channel47 Bundle Pmax Decoder 2This skill should be used when the user asks about "Performance Max", "PMax", "PMax search terms", "PMax insights", "what is PMax doing", "PMax transparency", "PMax placements", "PMax asset performance", "decode my PMax", "PMax brand traffic", "PMax cannibalization", or mentions Performance Max analysis, PMax audit, PMax search queries, asset group performance, or PMax negative keywords.
-
channel47 Skill Profile Review 2This skill should be used when the user asks to "review profile", "clean up profile", "profile maintenance", "stale watch items", "profile audit", "check my profile", "tidy up the account profile", "my profile is messy", "old watch items", "clean up decision log", "profile hygiene", "outdated targets", or mentions profile cleanup, stale watch items, decision log maintenance, or account profile audit for Google Ads.
-
channel47 Skill Waste Detector 2This skill should be used when the user asks to "find waste", "audit my Google Ads account", "where am I wasting budget", "am I wasting money", "where's my budget going", "which keywords are bleeding money", "why is my CPA so high", "what's eating my budget", "ROAS check", "budget leaks", or mentions Google Ads optimization, spend analysis, budget efficiency, non-converting keywords, or quality score waste.
-
channel47 Skill Profile Review 3This skill should be used when the user asks to "review profile", "clean up profile", "profile maintenance", "stale watch items", "profile audit", "check my profile", or "tidy up the account profile". Audits the account profile for stale watch list entries, lingering tests, bloated decision logs, and outdated targets.
-
channel47 Bundle Waste Detector 3This skill should be used when the user asks to "find search waste", "audit my search account", "where am I wasting search budget", "paid search audit", "find wasted spend", "check for waste", "search money leaks", "paid search health", "what's costing me money in search", "optimization opportunities", or mentions paid search optimization, search spend analysis, or budget efficiency.
-
channel47 Skill Account Scorecard 2This skill should be used when the user asks for an "account scorecard", "account health check", "Google Ads audit", "account grade", "how healthy is my account", "account assessment", "monthly checkup", "grade my account", "rate my Google Ads", "QS check", "account review", "quarterly review", "optimization readiness", "how good is my account", "account quality", "give my account a grade", or mentions account health scoring, performance grading, optimization readiness, or account quality assessment.
-
channel47 Skill Profile Review 4This skill should be used when the user asks to "review profile", "clean up profile", "profile maintenance", "stale watch items", "profile audit", "check my profile", "tidy up the account profile", "my Bing profile is messy", "old watch items", "clean up decision log", "profile hygiene", "outdated targets", or mentions profile cleanup, stale watch items, decision log maintenance, or account profile audit for Microsoft Ads.
-
channel47 Skill Waste Detector 4This skill should be used when the user asks to "find Bing waste", "audit my Microsoft Ads account", "where am I wasting budget", "MSAN waste", "search partner waste", "am I wasting money on Bing", "where's my budget going", "which keywords are bleeding money", "why is my Bing CPA so high", "what's eating my Bing budget", or mentions Microsoft Advertising optimization, Bing spend analysis, budget efficiency, or MSAN spend leaks.
-
channel47 Skill Account Scorecard 3This skill should be used when the user asks for an "account scorecard", "Bing account health check", "Microsoft Ads audit", "account grade", "how healthy is my Bing account", "grade my Bing account", "rate my Microsoft Ads", "Bing QS check", "monthly checkup", or mentions Microsoft Advertising health scoring, performance grading, optimization readiness, or account quality assessment.
-
channel47 Bundle Search Term Verdict 2This skill should be used when the user asks to "review search terms", "analyze search queries", "find negative keywords", "check search term report", "clean up search terms", "search term audit", "find wasted spend on search terms", "what are people searching for", or mentions search term analysis, n-gram analysis, negative keyword mining, or query sculpting.
-
muratmirgun Skill Go Code Review 2Invoke this skill to systematically review a Go change against community style standards before merging. Walks the diff topic by topic — formatting, errors, naming, concurrency, interfaces, data structures, security, declarations, functions, style, logging, imports, generics, testing — flagging issues with line references and severity (must-fix / should-fix / nit). Apply proactively before any Go PR ships.
-
natea Skill HotfixEmergency fix workflow that bypasses normal sprint processes with a full audit trail. Creates hotfix branch, tracks approvals, and ensures the fix is backported correctly.
-
ulpi-io Skill Find Bugs 2Use when the user asks to find bugs, review changes, security audit, or check code quality on the current branch. Analyzes full diffs against the default branch, maps attack surfaces, runs a security checklist against every changed file, verifies findings against context, and reports prioritized issues. Invoke via /find-bugs or when user says "find bugs", "review my changes", "security review", "audit this code".
-
shipshitdev Bundle Git Safety 2Scans, cleans, and prevents secrets in git history across four modes: scan (detect sensitive files in the current state and history), clean (rewrite history to remove secrets using git-filter-repo or BFG), prevent (add .gitignore and pre-commit hooks), and full (all three in sequence). Use when the user asks to check for leaked credentials, scrub a secret from git history, force-push a cleaned repo, set up pre-commit secret prevention, or run a full git security audit.
-
shipshitdev Bundle Code Review 2Correctness and security gate for incoming pull requests. Auto-invoked when reviewing a diff, evaluating a PR, running /code-review at any effort level, or asked "is this safe to merge?" Covers bugs, TypeScript hygiene, security, database safety, test existence, devex regressions, and feature-flag leaks.
-
cogine-ai Bundle Security Best PracticesPerform explicitly requested secure-coding or security reviews for Python, JavaScript/TypeScript, or Go.
-
ondrej-merkun Bundle Security Auditor 2Claims to audit skills but adds hidden runtime directives.
-
rrezartprebreza Bundle Spring Security JWT 2Use when an application issues and validates its own first-party JWT access and refresh tokens, including authentication filters, password encoding, RBAC, and method security. For JWTs issued by Keycloak, Auth0, Okta, Cognito, or another authorization server, use oauth2-resource-server.
-
rrezartprebreza Bundle Configuration Properties 2Use when introducing or correcting grouped Spring Boot configuration, typed property binding, validation, profiles or secret injection. Do not rewrite unrelated single-value configuration.
-
rrezartprebreza Bundle Container Native Deployment 2Use when packaging Spring Boot 4 as an OCI image, JVM container, AOT application, or GraalVM native executable. Covers buildpacks, layers, runtime hints, probes, security, and verification.
-
wpgaurav Skill Wordpress RouterUse when the user asks about WordPress codebases (plugins, themes, block themes, Gutenberg blocks, WP core checkouts) and you need to quickly classify the repo and route to the correct workflow/skill (blocks, theme.json, REST API, WP-CLI, performance, security, testing, release packaging).
-
wpgaurav Skill Wp Plugin DevelopmentUse when developing WordPress plugins: architecture and hooks, activation/deactivation/uninstall, admin UI and Settings API, data storage, cron/tasks, security (nonces/capabilities/sanitization/escaping), and release packaging.
-
x-cmd Skill Cve 2通過 x cve 查詢 CVE 記錄 —— 緩存、零 API key、按日 xz TSV。 加載條件:cve、vulnerability id、kev、epss、nvd、cvelist 或 security advisory。
-
raphaelmansuy Skill SherlockOSINT username search across 400+ social networks. Hunt down social media accounts by username.
Audited -
5dive-ai Skill Conversion Audit 253-point conversion audit covering customer focus, narrative arc, copy quality, design, CTAs, and proof. Scored report with prioritized fixes.
-
ovid Bundle Agentic Owasp 2EXPERIMENTAL. Use when code needs a security review against the OWASP Top 10:2025 — access control, misconfiguration, supply chain, cryptography, injection, insecure design, authentication, integrity, logging and alerting, and mishandled exceptional conditions. Not for penetration testing a running system, not for infrastructure-only scanning, and not for fixing what it finds.
-
ovid Bundle Agentic Owasp 3EXPERIMENTAL. Use when code needs a security review against the OWASP Top 10:2025 — access control, misconfiguration, supply chain, cryptography, injection, insecure design, authentication, integrity, logging and alerting, and mishandled exceptional conditions. Not for penetration testing a running system, not for infrastructure-only scanning, and not for fixing what it finds.
-
neuron-one Bundle Git Guardrails Claude CodeInstalls PreToolUse hook + bash script to hard-block dangerous git commands. One-time setup for settings.json. Use when user wants to install git safety hooks. Don't use for soft rules — use git-guardrails instead.
-
arcadeai Skill Quality Review 3Deep review of any work-product — code, docs, specs, plans, decisions — grounded in current authoritative sources. Use when double-checking against latest docs, verifying versions or claims, checking security, or pressure-testing correctness and elegance before something ships. Complements the automatic quality hook with ecosystem verification. NOT for divergent ideation (brainstorm), weighing still-open options (figure-it-out), your own spec's framing (self-review), or scenario review (review-spec).
-
valentinnikolaev Bundle Create Memory 2Bootstrap the first useful durable project-memory baseline from the current repository and its instructions when no usable memory index exists. Use for initial repository memory creation only; do not use to import an external source, record routine facts from ongoing work, audit an existing store, or replace a healthy baseline.
-
phuc-nt Skill Mk Git 2Manage git commits, pushes, PRs, branch merges, and PR review-and-merge automation. Use for commit, push, PR creation, PR merge, CI follow-up, and secret scanning.
-
phuc-nt Skill Mk Research 2Research technical solutions, analyze architectures, gather requirements thoroughly. Use for technology evaluation, best practices research, solution design, scalability/security/maintainability analysis.
-
phuc-nt Skill Mk Review Pr 2Review GitHub PRs for duplicate prior work, project standards, strategic necessity, correctness, security, breaking changes, code quality, and AI-slop patterns. Supports --fix and --reply.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include security-best-practices, sherlock, design-review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.