Dependency Upgrade Planner
by Edric Vale
Safe dependency upgrade plans: changelog-aware risk scoring, test hints, and rollback paths.
Skills for security audits, static analysis, vulnerability triage, and compliance checks. Ship safer software and meet regulatory requirements faster.
318 live security & compliance skills for Windsurf.
by Edric Vale
Safe dependency upgrade plans: changelog-aware risk scoring, test hints, and rollback paths.
by Roy Yuen
Prevent vulnerabilities before they happen by forcing early security framing and secure-by-default design patterns.
by Roy Yuen
A high-performance wrapper to route security tasks directly to the Anthropic-Cybersecurity-Skills library.
A premium library of 399 vulnerability patterns and DeFi attack vectors for AI-driven bug hunting and security audits.
by Timoranjes
Comprehensive security auditing for AI agents, covering prompt injection, tool permissions, and data leakage risks.
Expert AI guidance for ISO-compliant cleanroom design, HVAC filtration setup, and controlled environment installation.
by Timoranjes
Automated security audit and health check for software dependencies across polyglot projects.
A fast, free 3-point accessibility screen (text contrast, image alt text, form labels) to spot the most common ADA/WCAG problems before they cost you.
by Timoranjes
Audit frontend code for WCAG 2.2 AA compliance with prioritized remediation steps and deep semantic analysis.
Stop leaving your AI startup exposed to malicious users trying to steal your proprietary system prompts or bypass your paywalls. The AI Prompt Injection Defense Shield is an automated code review agent that deeply analyzes your Next.js or Python backend, instantly detecting insecure LLM input fields, un-sanitized API data streams, and weak prompt boundaries. By automatically generating the exact copy-paste code patches required to harden your AI wrapper against the latest OWASP top 10 LLM vulnerabilities, this skill allows solo developers and indie hackers to confidently launch their SaaS without the fear of massive, unexpected API billing spikes or catastrophic data leaks.
by LocoLoboZ
Automate the setup and optimization of Semgrep, SonarQube, and CodeQL for high-signal security testing.
by Summer
Automated factual verification using tiered official sources to eliminate hallucinations and circular reasoning.
by Kaymue
Get SOC2 Type II-ready in 90 days. 17 policy templates, 64 control mappings, automated AWS/GCP/GitHub evidence collection.
by Kaymue
Audit prompts and MCP tools for prompt injection. 47 attack patterns, OWASP LLM Top 10, generates adversarial tests. CVSS-scored.
Scan local SQL, CSV, JSON, seed, fixture, and log files for PII-indicating names plus email-, SSN-, card-, and phone-like values. Get file/line findings with matched values redacted by default—no network, writes, database connection, or compliance claim.
Evidence-first AI code review that discovers, verifies, prioritizes, and explains meaningful code problems.
by Joker
Enterprise security with NIST/ISO27001/zero-trust frameworks. Threat modeling, GDPR compliance, DevSecOps guidance.
by Jose Luis
Moderate toxic language, detect personal data leaks, and audit domain security configurations via MCP.
Red-team your own AI agent for prompt-injection and tool-misuse vulnerabilities before it ships — then fix them. Maps your attack surface, generates a defensive test plan with the safe behavior expected for each case, and gives a prioritized mitigations list. Defensive use only.
by GTDataworks
Generate source-safe repository audits and repair handoff bundles without mutating your code.
by Timoranjes
Professional-grade Kubernetes YAML auditor for security, API deprecations, and deployment best practices.
Messy, insecure, unfixable — that's what AI builds without architecture. This file is the architecture: 10 years of senior judgement on rendering, caching, security and SEO, so your agent builds it right from day one.
by Roy Yuen
Transform AI claims into verified, risk-assessed technical reports for production, DevOps, and enterprise governance.
by OnwireFlow
Makes your coding agent work like a senior developer: exact money with no rounding errors, configurable rules, real audit trails, honest testing and review. Any stack, any country.
Each skill on this page is a SKILL.md file built for security & compliance work and confirmed to run in Windsurf. Install one into .windsurf/skills/ (project) or ~/.windsurf/skills/ (global), start a new session, and Windsurf follows the workflow the creator encoded instead of improvising from a short prompt.
Listings are ranked by installs, upvotes and reviews, so what surfaces first is what other Windsurf users actually keep. Free and paid skills compete on the same page, and every listing shows its security scan result before you download anything.