Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
cogine-ai Bundle Supabase Postgres Best PracticesUse when writing, reviewing, or optimizing Supabase or Postgres queries, schema designs, indexes, row-level security policies, or database configuration for performance and correctness.
-
peteromallet Skill Planning 2> **Authority status (M11):** Zero-authority history. All repair, audit, and deployment authority has been migrated to canonical delegation. This document is retained for reference only — it must not be used to materialize commands, grant authority, or drive automated actions.
-
delphicleancode Skill Delphi Code Review 2Delphi code review checklist — quality, security, performance, SOLID, memory
-
jorgerosal Bundle Wp Woocommerce Dev 2WooCommerce extension code review for HPOS compatibility, payment gateway security, cart optimization, and template overrides. Use when reviewing WooCommerce extension code, payment gateway development, shipping methods, custom product types, cart operations, checkout customization, or when user mentions "WooCommerce review", "WooCommerce extension", "WooCommerce plugin", "payment gateway", "shipping method", "HPOS", "High-Performance Order Storage", "wc_get_orders", "WC_Payment_Gateway", "WC_Shipping_Method", "cart fragments", "WooCommerce hooks", "WooCommerce template", "shop_order", "WooCommerce performance", "Action Scheduler", "WooCommerce REST API", "WooCommerce Blocks", "checkout block", "woocommerce_checkout". Detects HPOS issues, CRUD violations, payment security anti-patterns, performance problems, and template override mistakes in WooCommerce 8.2+ through 10.x code.
-
jorgerosal Bundle Wp Performance Review 2WordPress performance code review and optimization analysis. Use when reviewing WordPress PHP code for performance issues, auditing themes/plugins for scalability, optimizing WP_Query, analyzing caching strategies, checking code before launch, or detecting anti-patterns, or when user mentions "performance review", "optimization audit", "slow WordPress", "slow queries", "high-traffic", "scale WordPress", "code review", "timeout", "500 error", "out of memory", or "site won't load". Detects anti-patterns in database queries, hooks, object caching, AJAX, template loading, and editor-side performance.
-
theinterneti Skill Self Review Checklist 2Use this skill before submitting code for review or merging a pull request. Covers a pre-merge checklist of common mistakes to catch across code quality, testing, security, and documentation. Invoke when the user says "review my code", "pre-merge check", "self-review", "am I ready to submit", or before opening a PR.
-
zebbern Skill Red Team Tools And MethodologyThe assistant provides red team methodologies, bug bounty hunting workflows, and tool configurations from top security researchers. Activate when users ask about "red team methodology," "bug bounty workflow," "reconnaissance automation," "XSS hunting," "subdomain enumeration," or "security researcher techniques."
-
agentflocks Bundle Analyzing Dns Logs For ExfiltrationAnalyzes DNS query logs to detect data exfiltration via DNS tunneling, DGA domain communication, and covert C2 channels using entropy analysis, query volume anomalies, and subdomain length detection in SIEM platforms. Use when SOC teams need to identify DNS-based threats that bypass traditional network security controls.
-
agentflocks Bundle Analyzing Windows Amcache ArtifactsParses and analyzes the Windows Amcache.hve registry hive to extract evidence of program execution, application installation, and driver loading for digital forensics investigations. Uses Eric Zimmerman's AmcacheParser and Timeline Explorer for artifact extraction, SHA-1 hash correlation with threat intel, and timeline reconstruction. Activates for requests involving Amcache forensics, program execution evidence, Windows artifact analysis, or application compatibility cache investigation.
-
agentflocks Bundle Analyzing Network Packets With ScapyCraft, send, sniff, and dissect network packets using Scapy for protocol analysis, network reconnaissance, and traffic anomaly detection in authorized security testing
-
agentflocks Bundle Reverse Engineering IOS App With FridaReverse engineers iOS applications using Frida dynamic instrumentation to understand internal logic, extract encryption keys, bypass security controls, and discover hidden functionality without source code access. Use when performing authorized iOS penetration testing, analyzing proprietary protocols, understanding obfuscated logic, or extracting runtime secrets from iOS binaries. Activates for requests involving iOS reverse engineering, Frida iOS hooking, Objective-C/Swift method tracing, or iOS binary analysis.
Audited -
jasonxzwen Skill Security ReviewLoad when a task needs security-sensitive code, auth, user input, secrets, API endpoints, payments, injection risk, or unsafe IO reviewed; use code-review for broader review.
-
rvdbreemen Skill Init 2Bootstrap ADR Kit in a project, including instructions, an architecture audit, initial ADR proposals, and the pre-commit gate.
-
rvdbreemen Skill Audit 2Lint the ADRs and judge the code in one run, over a diff or the whole codebase. Read-only.
-
rvdbreemen Skill Review 2Audit a branch or pull request against ADRs and identify architectural decisions that are not documented yet.
-
rvdbreemen Skill Init 3Bootstrap ADR Kit in a project, including instructions, an architecture audit, initial ADR proposals, and the pre-commit gate.
-
rvdbreemen Skill Audit 3Lint the ADRs and judge the code in one run, over a diff or the whole codebase. Read-only.
-
rvdbreemen Skill Review 3Audit a branch or pull request against ADRs and identify architectural decisions that are not documented yet.
-
zauberzeug Bundle Audit Deck 2Hunt for one previously-undocumented defect, doc drift, missing test, or inconsistency; file it via Skill(create-card). AUTO-INVOKE on "find me a bug", "audit X", "check for inconsistencies", or /audit-deck. Inconsistencies are the primary lead.
-
zauberzeug Bundle Audit Deck 3Hunt for one previously-undocumented defect, doc drift, missing test, or inconsistency; file it via the `create-card` skill. AUTO-INVOKE on "find me a bug", "audit X", "check for inconsistencies", or /audit-deck. Inconsistencies are the primary lead. If the catalog location path is unreadable, fetch the body via the goc tool verb "skill", args ["audit-deck"].
-
wecode-ai Bundle Design QA内部原型 QA 助手。仅在 Product Design 原型、URL-to-code 或 image-to-code 产物已有视觉对照源与可渲染实现、需要在交付前做比对时使用。不用于广义 UX 点评、设计点评、产品审计或流程复审;这类面向用户的请求请路由到 audit。
-
ferroxlabs Skill Ijfw Plan Check 2Donahoe Loop audit gate before execution. Trigger: 'audit plan', 'check plan', 'review plan', 'plan audit', 'plan check', 'before we build', 'before execution', 'validate the plan', 'is this plan solid', 'plan review'. Owns pre-execution audit intent -- fires before any foreign plan-checker.
37 -
timharris707 Bundle Setup 2For a new TeamWorkflow installation, binding refresh, or drift audit after a pack release, inspect and bind the project workflow. Reuse explicit recorded decisions with their sources; ask about missing, conflicting, or changed authority and bindings.
-
tanstack Skill AI SandboxRun harness adapters (Claude Code, Codex, OpenCode) INSIDE isolated sandboxes via defineSandbox + withSandbox + a provider (localProcessSandbox / dockerSandbox). Covers declarative provisioning: createSecrets + secret/bearer, skills (agentSkill/gitSkill/mcpSkill/ fileSkill), plugins, instructions → canonical AGENTS.md + symlinks projected per harness; shallow-clone default with depth opt-out; serial/parallel setup callback over a persistent shell; snapshot-after-setup default with snapshotMaxAge TTL. It also covers portable snapshots after a successful terminal run with withPersistence before withSandbox and memorySandboxSnapshots for local examples. It covers named saves with snapshots.save, selected-checkpoint forks with snapshots.fork, and authorized artifact reads with snapshots.readArtifact. See docs/sandbox/portable-snapshots.md. It covers defineWorkspace (git/setup/scripts/skills/secrets/ instructions/plugins), defineSandboxPolicy (allow/ask/deny), lifecycle/resume, the SandboxHandle (fs/git/process/po
-
tanstack Skill Tanstack AI MemoryUse when wiring memoryMiddleware from @tanstack/ai-memory into a chat() call — covers the recall/save adapter contract, scope shape and server-side scope security, the recall-inject / deferred-save lifecycle, choosing an adapter (inMemory, redis, hindsight, mem0, honcho), and devtools events.
-
mangowhoiscloud Skill Grilling 2Design or audit GEODE's dependency-aware grilling flow and slash integration without speculative branch execution or parser-heavy interviews.
-
aojdevstudio Bundle Adversarial Review 2Deep implementation review that hunts for real bugs. Use when the user asks for adversarial review, review this implementation, audit my code, stress test this, find problems with this, ship-readiness review, is this ready to ship, check this against the plan, check this against the spec, find bugs in this, implementation audit. This skill is for IMPLEMENTATIONS — code, configs, scripts, pipelines. For plans and designs before implementation, use a plan-review or design-challenge skill instead.
-
xingfanxia Skill Gsd ProgressCheck project progress, show context, and route to next action (execute or plan). Use --forensic to append a 6-check integrity audit after the standard report.
-
xiaolai Skill Security ArsenalSecurity payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table. Use when you need specific payloads for XSS/SSRF/SQLi/XXE/NoSQLi/command injection/SSTI/IDOR/path-traversal/HTTP smuggling/WebSocket/MFA bypass, bypass techniques, or to check if a finding is submittable. Also use when asked about what NOT to submit.
-
petar-djukic Bundle Audit References 2Verify citations in a paper or document. Reads a markdown document, extracts every [@citation-id] pandoc citation, resolves each against references.yaml (CSL-YAML), fetches the cited papers (arXiv or Google Scholar), reads them, and checks whether the claims made in the citing text are supported by the sources. Produces an audit report with per-citation verdicts. Triggers: audit references, verify citations, check references, citation audit, verify bibliography, check my citations, are my references correct, fact-check citations, validate sources.
-
petar-djukic Bundle Audit References 3Verify citations in a paper or document. Reads a markdown document, extracts every [@citation-id] pandoc citation, resolves each against references.yaml (CSL-YAML), fetches the cited papers (arXiv or Google Scholar), reads them, and checks whether the claims made in the citing text are supported by the sources. Produces an audit report with per-citation verdicts. Triggers: audit references, verify citations, check references, citation audit, verify bibliography, check my citations, are my references correct, fact-check citations, validate sources.
-
petar-djukic Bundle Audit References 4Verify citations in a paper or document. Reads a markdown document, extracts every [@citation-id] pandoc citation, resolves each against references.yaml (CSL-YAML), fetches the cited papers (arXiv or Google Scholar), reads them, and checks whether the claims made in the citing text are supported by the sources. Produces an audit report with per-citation verdicts. Triggers: audit references, verify citations, check references, citation audit, verify bibliography, check my citations, are my references correct, fact-check citations, validate sources.
-
petar-djukic Bundle Audit References 5Verify citations in a paper or document. Reads a markdown document, extracts every [@citation-id] pandoc citation, resolves each against references.yaml (CSL-YAML), fetches the cited papers (arXiv or Google Scholar), reads them, and checks whether the claims made in the citing text are supported by the sources. Produces an audit report with per-citation verdicts. Triggers: audit references, verify citations, check references, citation audit, verify bibliography, check my citations, are my references correct, fact-check citations, validate sources.
-
luka-zivkovic Bundle Review Contract Gaps 2Produce a read-only semantic contract-gap pass for an exact implemented change, optionally subtracting a frozen pull-request review. Use only when explicitly asked for an implementation-aware second pass or standalone deep contract audit, especially for persisted values, shared configuration, public contracts, migrations, state transitions, or multiple producers and consumers. Discover against code before reading any supplied review, then return only source-verified omissions. Do not use as the primary PR review, before implementation exists, for fixes or test implementation, for posting comments, or for wording-only changes.
-
luka-zivkovic Bundle Review Contract Gaps 3Produce a read-only semantic contract-gap pass for an exact implemented change, optionally subtracting a frozen pull-request review. Use only when explicitly asked for an implementation-aware second pass or standalone deep contract audit, especially for persisted values, shared configuration, public contracts, migrations, state transitions, or multiple producers and consumers. Discover against code before reading any supplied review, then return only source-verified omissions. Do not use as the primary PR review, before implementation exists, for fixes or test implementation, for posting comments, or for wording-only changes.
-
luka-zivkovic Bundle Review Contract Gaps 4Produce a read-only semantic contract-gap pass for an exact implemented change, optionally subtracting a frozen pull-request review. Use only when explicitly asked for an implementation-aware second pass or standalone deep contract audit, especially for persisted values, shared configuration, public contracts, migrations, state transitions, or multiple producers and consumers. Discover against code before reading any supplied review, then return only source-verified omissions. Do not use as the primary PR review, before implementation exists, for fixes or test implementation, for posting comments, or for wording-only changes.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include reverse-engineering-ios-app-with-frida, init, review-contract-gaps. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.