Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
dicklesworthstone-pi-agent-rust Bundle Scanning For SecretsDetect exposed secrets, API keys, and credentials in code. Use when auditing for secret leaks. Trigger with 'scan for secrets', 'find exposed keys', or 'check credentials'.
-
dicklesworthstone-pi-agent-rust Bundle Validating Cors PoliciesValidate CORS policies for security issues and misconfigurations. Use when reviewing cross-origin resource sharing. Trigger with 'validate CORS', 'check CORS policy', or 'review cross-origin'.
-
dicklesworthstone-pi-agent-rust Bundle Performing Penetration TestingPerform security penetration testing to identify vulnerabilities. Use when conducting security assessments. Trigger with 'run pentest', 'security testing', or 'find vulnerabilities'.
-
dicklesworthstone-pi-agent-rust Bundle Scanning For Gdpr ComplianceScan for GDPR compliance issues in data handling and privacy practices. Use when ensuring EU data protection compliance. Trigger with 'scan GDPR compliance', 'check data privacy', or 'validate GDPR'.
-
dicklesworthstone-pi-agent-rust Bundle Scanning For Xss VulnerabilitiesExecute this skill enables AI assistant to automatically scan for xss (cross-site scripting) vulnerabilities in code. it is triggered when the user requests to "scan for xss vulnerabilities", "check for xss", or uses the command "/xss". the skill identifies ref... Use when appropriate context detected. Trigger with relevant phrases based on skill purpose.
-
modest-curator478 Skill Hubspot AuditAUTO-TRIGGER: Apply this skill when the user asks about auditing, cleaning up, reviewing, or improving their HubSpot instance. Trigger phrases include: "audit our HubSpot," "clean up HubSpot," "HubSpot is a mess," "inherited a HubSpot instance," "our workflows are broken," "deal stages don't make sense," "leads aren't routing correctly," "HubSpot hygiene," or any request to assess the health or structure of a HubSpot CRM. Also trigger when the user is starting a new role and mentions evaluating the existing HubSpot setup they inherited. Do NOT trigger for general HubSpot how-to questions or feature requests that are not about auditing an existing instance.
-
diegosouzapw Bundle Credential ManagerMANDATORY security foundation for OpenClaw. Consolidate scattered API keys and credentials into a secure .env file with proper permissions. Includes GPG encryption for high-value secrets, credential rotation tracking, deep scanning, and backup hardening. Use when setting up OpenClaw, migrating credentials, auditing security, or enforcing the .env standard. This is not optional — centralized credential management is a core requirement for secure OpenClaw deployments.
54 -
diegosouzapw Bundle Claude Settings Audit 2Analyze a repository to generate recommended Claude Code settings.json permissions. Use when setting up a new project, auditing existing settings, or determining which read-only bash commands to allow. Detects tech stack, build tools, and monorepo structure.
54 -
diegosouzapw Bundle Flutter Expert Rootcastleco> ⚠️ **AUTHORIZED USE ONLY** — This skill is intended for authorized security professionals only. Use only against systems you own or have explicit written permission to test. Unauthorized use may violate applicable laws.
54 -
diegosouzapw Bundle Deployment Engineer Rootcastleco> ⚠️ **AUTHORIZED USE ONLY** — This skill is intended for authorized security professionals only. Use only against systems you own or have explicit written permission to test. Unauthorized use may violate applicable laws.
54 -
diegosouzapw Bundle Hlab AuditorHLab Auditor Skill
54 -
diegosouzapw Bundle Program Security BasicsProgram Security Basics
54 -
diegosouzapw Bundle Global SecurityYour approach to handling global security. Use this skill when working on files where global security comes into play.
54 -
diegosouzapw Bundle Backend Architect Rootcastleco> ⚠️ **AUTHORIZED USE ONLY** — This skill is intended for authorized security professionals only. Use only against systems you own or have explicit written permission to test. Unauthorized use may violate applicable laws.
54 -
diegosouzapw Bundle Mobile Security Coder Avdelag1Use this skill when
54 -
diegosouzapw Bundle Minecraft Bukkit Pro Rootcastleco> ⚠️ **AUTHORIZED USE ONLY** — This skill is intended for authorized security professionals only. Use only against systems you own or have explicit written permission to test. Unauthorized use may violate applicable laws.
54 -
diegosouzapw Bundle Security Auditor Rootcastleco> ⚠️ **AUTHORIZED USE ONLY** — This skill is intended for authorized security professionals only. Use only against systems you own or have explicit written permission to test. Unauthorized use may violate applicable laws.
54 -
diegosouzapw Bundle Secure Code Guardian Majiayu000Secure Code Guardian
54 -
diegosouzapw Bundle Power Bi Security Rls Best PracticesPower BI Security and Row-Level Security Best Practices
54 -
diegosouzapw Bundle Account Security ValidationValidate account security and authentication protocols.
54 -
javiertarazon Skill Laravel ExpertSenior Laravel Engineer role for production-grade, maintainable, and idiomatic Laravel solutions. Focuses on clean architecture, security, performance, and modern standards (Laravel 10/11+).
-
javiertarazon Skill Pentest ChecklistThis skill should be used when the user asks to "plan a penetration test", "create a security assessment checklist", "prepare for penetration testing", "define pentest scope", "foll...
-
javiertarazon Skill Solidity SecurityMaster smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns. Use when writing smart contracts, auditing existing contracts, or implementin...
-
javiertarazon Skill Sast ConfigurationConfigure Static Application Security Testing (SAST) tools for automated vulnerability detection in application code. Use when setting up security scanning, implementing DevSecOps practices, or aut...
-
javiertarazon Skill Metasploit FrameworkThis skill should be used when the user asks to "use Metasploit for penetration testing", "exploit vulnerabilities with msfconsole", "create payloads with msfvenom", "perform post-exp...
-
javiertarazon Skill Nodejs Best PracticesNode.js development principles and decision-making. Framework selection, async patterns, security, and architecture. Teaches thinking, not copying.
-
javiertarazon Skill Laravel Security AuditSecurity auditor for Laravel applications. Analyzes code for vulnerabilities, misconfigurations, and insecure practices using OWASP standards and Laravel security best practices.
-
javiertarazon Skill Ssh Penetration TestingThis skill should be used when the user asks to "pentest SSH services", "enumerate SSH configurations", "brute force SSH credentials", "exploit SSH vulnerabilities", "perform SSH tu...
-
javiertarazon Skill Attack Tree ConstructionBuild comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders.
-
javiertarazon Skill Stride Analysis PatternsApply STRIDE methodology to systematically identify threats. Use when analyzing system security, conducting threat modeling sessions, or creating security documentation.
-
javiertarazon Skill Linux Privilege EscalationThis skill should be used when the user asks to "escalate privileges on Linux", "find privesc vectors on Linux systems", "exploit sudo misconfigurations", "abuse SUID binaries", "ex...
-
javiertarazon Skill Codebase Cleanup Deps AuditYou are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues,...
-
javiertarazon Skill Ethical Hacking MethodologyThis skill should be used when the user asks to "learn ethical hacking", "understand penetration testing lifecycle", "perform reconnaissance", "conduct security scanning", "exploit ...
-
javiertarazon Skill Privilege Escalation MethodsThis skill should be used when the user asks to "escalate privileges", "get root access", "become administrator", "privesc techniques", "abuse sudo", "exploit SUID binaries", "K...
-
javiertarazon Skill Windows Privilege EscalationThis skill should be used when the user asks to "escalate privileges on Windows," "find Windows privesc vectors," "enumerate Windows for privilege escalation," "exploit Windows miscon...
-
javiertarazon Skill Wordpress Penetration TestingThis skill should be used when the user asks to "pentest WordPress sites", "scan WordPress for vulnerabilities", "enumerate WordPress users, themes, or plugins", "exploit WordPress vu...
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include backend-architect-rootcastleco, mobile-security-coder-avdelag1, hlab-auditor. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.