Tags

Best Security Audit Skills for AI Agents

902 Security Audit skills for AI coding assistants — ranked by popularity.

This collection provides modular skill definitions for AI agents configured for security auditing. Developers can plug these files into tools like Claude Code, Cursor, or Codex to automate specific investigative workflows. The skills cover distinct domains ranging from low-level memory manipulation and reverse engineering to smart contract analysis and infrastructure auditing. Whether you are performing a manual review of Solidity code, automating web application testing, or securing Windows desktop environments, these skills offer defined context for your agent. Instead of general prompting, you gain access to targeted methodologies for identifying vulnerabilities. This repository is built for security engineers and developers who need to integrate specialized research capabilities directly into their coding environment. By using these structured skill files, you ensure your AI assistant follows professional standards for identifying potential exploits, reviewing GitHub pull requests, or managing secrets through 1Password integration.

Top Security Audit skills

reverse-engineering-tools

gmh5225

Guide for reverse engineering tools and techniques used in game security research. Use this skill when working with debuggers, disassemblers, memory analysis tools, binary analysis, or decompilers for game security research.

73204

game-hacking-techniques

gmh5225

Guide for game hacking techniques and cheat development. Use this skill when researching memory manipulation, code injection, ESP/aimbot development, overlay rendering, or game exploitation methodologies.

42128

github-code-review

ruvnet

Comprehensive GitHub code review with AI-powered swarm coordination

13135

windows-ui-automation

martinholovsky

Expert in Windows UI Automation (UIA) and Win32 APIs for desktop automation. Specializes in accessible, secure automation of Windows applications including element discovery, input simulation, and process interaction. HIGH-RISK skill requiring strict security controls for system access.

17126

qa-tester

svilupp

Browser automation QA testing skill. Systematically tests web applications for functionality, security, and usability issues. Reports findings by severity (CRITICAL/HIGH/MEDIUM/LOW) with immediate alerts for critical failures.

29113

solidity-security

wshobson

Master smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns. Use when writing smart contracts, auditing existing contracts, or implementing security measures for blockchain applications.

15115

1password

openclaw

Set up and use 1Password CLI (op). Use when installing the CLI, enabling desktop app integration, signing in (single or multi-account), or reading/injecting/running secrets via op.

2799

reviewing-code

CaptainCrouton89

Systematically evaluate code changes for security, correctness, performance, and spec alignment. Use when reviewing PRs, assessing code quality, or verifying implementation against requirements.

21105

senior-security

davila7

Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing. Includes security assessment tools, threat modeling, crypto implementation, and security automation. Use when designing security architecture, conducting penetration tests, implementing cryptography, or performing security audits.

3191

ghidra

mitsuhiko

Reverse engineer binaries using Ghidra's headless analyzer. Decompile executables, extract functions, strings, symbols, and analyze call graphs without GUI.

16105

supabase-rls-policy-generator

hopeoverture

This skill should be used when the user requests to generate, create, or add Row-Level Security (RLS) policies for Supabase databases in multi-tenant or role-based applications. It generates comprehensive RLS policies using auth.uid(), auth.jwt() claims, and role-based access patterns. Trigger terms include RLS, row level security, supabase security, generate policies, auth policies, multi-tenant security, role-based access, database security policies, supabase permissions, tenant isolation.

11109

reviewing-nextjs-16-patterns

djankies

Review code for Next.js 16 compliance - security patterns, caching, breaking changes. Use when reviewing Next.js code, preparing for migration, or auditing for violations.

11106

software-security

project-codeguard

A software security skill that integrates with Project CodeGuard to help AI coding agents write secure code and prevent common vulnerabilities. Use this skill when writing, reviewing, or modifying code to ensure secure-by-default practices are followed.

2186

security-header-generator

Dexploarer

Generates security HTTP headers (CSP, HSTS, CORS, etc.) for web applications to prevent common attacks. Use when user asks to "add security headers", "setup CSP", "configure CORS", "secure headers", or "HSTS setup".

599

security-compliance

davila7

Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and risk assessments, managing security operations and incident response, and embedding security throughout the SDLC.

1981

game-engine-resources

gmh5225

Guide for game engine development resources including engine source code, plugins, and development guides. Use this skill when researching game engines (Unreal, Unity, Godot, custom engines), engine architecture, or game development frameworks.

1485

web3-testing

wshobson

Test smart contracts comprehensively using Hardhat and Foundry with unit tests, integration tests, and mainnet forking. Use when testing Solidity contracts, setting up blockchain test suites, or validating DeFi protocols.

789

fix-dependabot-alerts

microsoft

Fix Dependabot security alerts by updating vulnerable npm dependencies. Use when the user mentions "dependabot", "security alerts", "vulnerability", "CVE", or wants to update packages with security issues.

1872

secrets-management

wshobson

Implement secure secrets management for CI/CD pipelines using Vault, AWS Secrets Manager, or native platform solutions. Use when handling sensitive credentials, rotating secrets, or securing CI/CD environments.

585

exploit-researcher

jpoley

Exploit researcher persona specializing in attack surface analysis, exploit scenario generation, and vulnerability chaining

681

stride-analysis-patterns

wshobson

Apply STRIDE methodology to systematically identify threats. Use when analyzing system security, conducting threat modeling sessions, or creating security documentation.

679

healthcheck

openclaw

Host security hardening and risk-tolerance configuration for OpenClaw deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, OpenClaw cron scheduling for periodic checks, or version status checks on a machine running OpenClaw (laptop, workstation, Pi, VPS).

1073

mobile-security

gmh5225

Guide for mobile game security on Android and iOS platforms. Use this skill when working with Android/iOS reverse engineering, mobile game hacking, APK analysis, root/jailbreak detection bypass, or mobile anti-cheat systems.

1469

reverse-engineer

sickn33

Expert reverse engineer specializing in binary analysis, disassembly, decompilation, and software analysis. Masters IDA Pro, Ghidra, radare2, x64dbg, and modern RE toolchains. Handles executable analysis, library inspection, protocol extraction, and vulnerability research. Use PROACTIVELY for binary analysis, CTF challenges, security research, or understanding undocumented software.

2261

How to choose a Security Audit skill

Select a skill based on your specific audit target. If auditing web interfaces, prioritize the qa-tester skill for browser-based diagnostics. For blockchain projects, solidity-security provides the necessary patterns to identify contract vulnerabilities. Verify that the skill scope aligns with your stack—such as choosing supabase-operations for backend data integrity or windows-ui-automation for desktop-bound applications. Always review the included documentation within the skill file to understand the expected output format and the specific constraints the agent will operate under during your audit.

More Security Audit skills

protocol-reverse-engineering
wshobson · 9 installs
information-security-manager-iso27001
davila7 · 11 installs
linkerd-patterns
wshobson · 6 installs
anti-reversing-techniques
wshobson · 12 installs
cookbook-audit
anthropics · 5 installs
zod-4
prowler-cloud · 12 installs
backend-security-coder
sickn33 · 24 installs
firebase
davila7 · 20 installs
api-security-best-practices
davila7 · 15 installs
attack-tree-construction
wshobson · 7 installs
equilateral-agents
Equilateral-AI · 5 installs
red-team-tools-and-methodology
davila7 · 7 installs
security-requirement-extraction
wshobson · 7 installs
blockchain-developer
sickn33 · 6 installs
ssh-penetration-testing
davila7 · 5 installs
security-review
affaan-m · 6 installs
firmware-analyst
sickn33 · 9 installs
memory-forensics
wshobson · 7 installs
gdpr-data-handling
sickn33 · 9 installs
pentest-commands
davila7 · 3 installs
skill-install
cexll · 4 installs
linux-production-shell-scripts
davila7 · 7 installs
sqlmap-database-penetration-testing
davila7 · 4 installs
wordpress-penetration-testing
davila7 · 9 installs
top-100-web-vulnerabilities-reference
davila7 · 5 installs
windows-privilege-escalation
davila7 · 3 installs
pentest-checklist
davila7 · 5 installs
secops-setup-antigravity
google · 4 installs
cloud-penetration-testing
davila7 · 3 installs
differential-review
trailofbits · 31 installs
binary-analysis-patterns
wshobson · 5 installs
risk-management-specialist
davila7 · 3 installs
threat-mitigation-mapping
wshobson · 5 installs
vulnerability-scanner
davila7 · 6 installs
cursor-privacy-settings
jeremylongshore · 6 installs
dma-attack-techniques
gmh5225 · 4 installs
pr-review
pytorch · 6 installs
aws-penetration-testing
davila7 · 4 installs
supabase-postgres-best-practices
davila7 · 4 installs
file-uploads
davila7 · 4 installs
security-scanning-tools
davila7 · 4 installs
qa-expert
daymade · 14 installs
redteam-plugin-development
promptfoo · 3 installs
agent-security-manager
ruvnet · 3 installs
red-team-tactics
davila7 · 3 installs
security-audit
ruvnet · 3 installs
gdpr-dsgvo-expert
davila7 · 8 installs
security-best-practices
openai · 7 installs
api-fuzzing-for-bug-bounty
davila7 · 9 installs
cursor-prod-checklist
jeremylongshore · 4 installs
security
parcadei · 5 installs
cursor-sso-integration
jeremylongshore · 4 installs
security-auditor
sickn33 · 5 installs
security-scanning-security-hardening
sickn33 · 3 installs
aws-advisor
tech-leads-club · 5 installs
find-bugs
davila7 · 5 installs
pci-compliance
wshobson · 3 installs
secure-workflow-guide
trailofbits · 3 installs
springboot-security
affaan-m · 5 installs
supabase-common-errors
jeremylongshore · 4 installs
supabase-policy-guardrails
jeremylongshore · 3 installs
code-review-checklist
vudovn · 3 installs
graphics-api-hooking
gmh5225 · 7 installs
ciso-assistant-basic-risk-assessment
intuitem · 3 installs
agent-code-review-swarm
ruvnet · 3 installs
graphql
davila7 · 6 installs
sast-configuration
wshobson · 3 installs
windows-kernel-security
gmh5225 · 7 installs
fix-review
sickn33 · 3 installs
insecure-defaults
trailofbits · 3 installs
k8s-security-policies
wshobson · 3 installs
secops-triage
google · 4 installs
vercel-webhooks-events
jeremylongshore · 3 installs
auth-patterns
davepoon · 7 installs
django-security
affaan-m · 5 installs
tech-debt-analyzer
ailabs-393 · 5 installs
django-verification
affaan-m · 5 installs
engineering-skills
alirezarezvani · 4 installs
idapython
mrexodia · 4 installs
cross-site-scripting-and-html-injection-testing
davila7 · 3 installs
google-workspace-cli
alirezarezvani · 9 installs
cursor-compliance-audit
jeremylongshore · 3 installs
agent-reviewer
ruvnet · 3 installs
fix-security-vulnerability
getsentry · 7 installs
static-analysis
gmh5225 · 5 installs
data-privacy-compliance
davila7 · 4 installs
defense-in-depth-validation
mrgoonie · 3 installs
anti-cheat-systems
gmh5225 · 8 installs
malware-analyst
sickn33 · 2 installs
agent-code-analyzer
ruvnet · 3 installs
agent-v3-security-architect
ruvnet · 3 installs
apktool
BrownFineSecurity · 7 installs
code-maturity-assessor
trailofbits · 4 installs
epic-permissions
epicweb-dev · 3 installs
pcap-analysis
benchflow-ai · 7 installs
semgrep-rule-creator
trailofbits · 4 installs

+782 more — browse all skills.

Frequently asked

How do these skills affect the agent's decision-making process?
These skills function as structured directives that guide the agent’s reasoning. By providing specific techniques for reverse engineering, memory injection, or smart contract analysis, they limit the agent to proven security workflows. This reduces hallucinations and ensures the agent focuses on relevant patterns, such as RLS optimization in Supabase or common Solidity exploits, during your audit.
Can I combine multiple skills for a single audit?
Yes. You can layer these skills to address complex attack surfaces. For instance, you might combine the github-code-review skill to analyze repository patterns with the solidity-security skill to drill down into smart contract logic. When using multiple agents or files, ensure the combined instructions do not conflict, allowing the agent to switch contexts between high-level review and granular technical investigation.

Browse other tags

Search skills

Search the agent skills registry