Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
majiayu000 Bundle Mitre Att Ck SkillMITRE ATT&CK framework mapping and analysis
567 -
majiayu000 Bundle Stix Taxii Intelligence SkillSTIX/TAXII threat intelligence format and sharing
567 -
majiayu000 Bundle Burp Suite Web Security SkillWeb application security testing with Burp Suite integration
567 -
majiayu000 Bundle Security Check Snkrheadz Laptopセキュリティスキャン実行。gitleaks、pre-commitフック、秘密情報検出。トリガー: security, gitleaks, pre-commit, secrets, scan
567 -
majiayu000 Bundle Immutable Audit Trail ArchivingArchive immutable audit trails for accountability.
567 -
majiayu000 Bundle Scoring 0x Shashi Web3 Audit SkillsQuantitative scoring framework for measuring audit quality with objective metrics to evaluate performance, track improvement over time, and identify areas needing attention. Use when benchmarking audit thoroughness, comparing engagement quality, or building quality gates into CI pipelines.
567 -
majiayu000 Bundle Skills 0x Shashi Web3 Audit SkillsRoot skill definition for the Web3 Audit Plugin providing AI-powered smart contract security auditing across EVM, Solana, Move, Cairo, CosmWasm, and TON platforms. Use as the top-level entry point for understanding plugin capabilities, supported chains, and skill routing.
567 -
majiayu000 Bundle Audit Rene Kuhm Opencode OhmyopencodAuditoría completa del proyecto: dependencias, seguridad, performance, código. Genera reporte actionable.
567 -
majiayu000 Bundle Add Admin Endpoints Tassadar2499 NovatuneAdd admin API endpoints with proper authorization, audit logging, and rate limiting (project)
567 -
majiayu000 Bundle Commands 0x Shashi Web3 Audit SkillsStructured command patterns for invoking audit capabilities through slash commands. Use when triggering /audit, /scan, /checklist, /report, /severity, /patterns, or other slash commands that map to underlying skills and load the correct context for each workflow.
567 -
majiayu000 Bundle Ops Chief Of StaffAutomate enterprise operations (compliance, HR recruiting, finance ops) with audit trails and approvals; use when asked to design or run administrative autonomous workflows.
567 -
majiayu000 Bundle Fix Review 0x Shashi Web3 Audit SkillsVerify that bug fixes correctly address reported vulnerabilities without introducing new issues. Use when reviewing protocol team fix submissions, during re-audit engagements, or in contest mitigation review phases on Sherlock and Code4rena.
567 -
majiayu000 Bundle Draconian Rls AuditDefault-Deny security posture for Supabase. Mandates strict RLS and 'WITH CHECK' clauses.
567 -
majiayu000 Bundle Add Audit Logging Tassadar2499 NovatuneImplement tamper-evident audit logging with hash chain verification for admin actions (project)
567 -
majiayu000 Bundle Security Checklist Yebot Rad Cc PluginsSecurity review checklist for features and changes
567 -
majiayu000 Bundle Add Rate Limiting Tassadar2499 Novatune 2Configure rate limiting policies for API endpoints with sliding window limits
567 -
majiayu000 Bundle Moai Platform Auth0 2Auth0 security specialist covering attack protection, multi-factor authentication, token security, sender constraining, and compliance. Use when implementing Auth0 security features, configuring attack defenses, setting up MFA, or meeting regulatory requirements.
567 -
majiayu000 Bundle Cis ControlsExpert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments, safeguard-level guidance, asset inventory, software inventory, data protection, secure configuration, account management, access control, continuous vulnerability management, audit log management, email and web browser protections, malware defenses, network infrastructure management, network monitoring and defense, application software security, incident response, penetration testing, and CIS Controls mapping to NIST CSF, ISO 27001, SOC 2, and CMMC. Use for any question about CIS Controls, CIS Benchmarks, Implementation Groups, or prioritized cyber hygiene for any organization size.
567 -
majiayu000 Bundle Static Analysis 0x Shashi Web3 Audit SkillsIntegrate automated static analysis tools (Slither, Mythril, Aderyn, Semgrep) into the audit workflow to catch known vulnerability patterns before manual review. Use when starting an audit to establish a coverage baseline, or when configuring static analysis tooling for a project.
567 -
majiayu000 Bundle Variant Analysis 0x Shashi Web3 Audit SkillsSystematically hunt for every variant of a discovered vulnerability across the entire codebase. Use when a bug is found and all instances of the same root cause pattern must be identified, or when performing variant analysis during competitive audits on Code4rena or Sherlock.
567 -
majiayu000 Bundle Audit And Fix Whatifwedigdeeper Application TrackerSecurity audit with automatic fixes for vulnerabilities
567 -
majiayu000 Bundle Phx Deps Vet 2Record a vetted Hex package version in hex_vet.exs after a security review — manages the audit ledger, not the scanner. Use to approve a dep after /skill:phx-deps-audit findings or to initialize hex_vet.exs.
567 -
majiayu000 Bundle Phx Deps Vet 3Record a vetted Hex package version in hex_vet.exs after a security review — manages the audit ledger, not the scanner. Use to approve a dep after /phx-deps-audit findings or to initialize hex_vet.exs.
567 -
majiayu000 Bundle Differential Review 0x Shashi Web3 Audit SkillsCompare two versions of a codebase to identify security implications of changes. Use when reviewing protocol upgrades, verifying bug fixes, auditing dependency updates, or when only a subset of code has changed since the last audit.
567 -
majiayu000 Bundle Security Symfony 2Sicherheit & DSGVO - Atoll Tourisme. Use when reviewing security, implementing auth, or hardening code.
567 -
majiayu000 Bundle Generating Nest ServersPRIMARY expert for ALL NestJS and @lenne.tech/nest-server tasks. ALWAYS use this skill when working in projects with @lenne.tech/nest-server in package.json dependencies (supports monorepos with projects/*, packages/*, apps/* structure), or when asked about NestJS modules, services, controllers, resolvers, models, objects, tests, server creation, debugging, or any NestJS/nest-server development task. Handles lt server commands, security analysis, test creation, and all backend development. ALWAYS reads CrudService base class before working with Services.
567 -
majiayu000 Bundle Code Review Gate Majiayu000 Claude Skill RegistHuman code review gate for critical components. Activates automatically for security-sensitive paths, high-complexity code, or large changes. Activation trigger: [ACTIVATE:CODE_REVIEW_GATE_V1]
567 -
majiayu000 Bundle Security Symfony 3Seguridad & RGPD - Atoll Tourisme. Use when reviewing security, implementing auth, or hardening code.
567 -
majiayu000 Bundle Transport SecurityUse HTTPS for all endpoints, including internal services Use when implementing security best practices. Security category skill.
567 -
majiayu000 Bundle Audit Context Building 0x Shashi Web3 Audit SkillsSystematically build comprehensive understanding of a protocol before code-level analysis. Use when starting a new audit engagement, mapping trust boundaries and external dependencies, or when needing to identify all privileged roles and protocol invariants before manual review.
567 -
majiayu000 Bundle Phx Deps Update 2Bump outdated Hex deps — inventory, snapshot changelogs, update, fix breaks, split reviewable PRs (patches bundled, majors solo). Use to upgrade/bump Elixir dependencies or when versions fall behind. NOT for deps.get failures (/skill:phx-investigate).
567 -
majiayu000 Bundle Secure DependenciesRegularly audit dependencies for known vulnerabilities (npm audit, Snyk, Dependabot) Use when implementing security best practices. Security category skill.
567 -
majiayu000 Bundle Phx Deps Update 3Bump outdated Hex deps — inventory, snapshot changelogs, update, fix breaks, split reviewable PRs (patches bundled, majors solo). Use to upgrade/bump Elixir dependencies or when versions fall behind. NOT for deps.get failures (/phx-investigate).
567 -
majiayu000 Bundle Phx Deps Audit 2Audit Hex deps for supply-chain security risk — bidi chars, compile-time exec, maintainer changes, typosquats, CVEs. Use after mix deps.update, when checking if a package upgrade is safe, or reviewing mix.lock PR diffs.
567 -
majiayu000 Bundle Phx Deps Audit 3Audit Hex deps for supply-chain security risk — bidi chars, compile-time exec, maintainer changes, typosquats, CVEs. Use after mix deps.update, when checking if a package upgrade is safe, or reviewing mix.lock PR diffs.
567 -
majiayu000 Bundle Ln 773 Cors Configurator 2Configures CORS policy for development and production environments. Use when setting up cross-origin access for APIs.
567
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include MITRE ATT&CK Skill, STIX/TAXII Intelligence Skill, Burp Suite/Web Security Skill. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.