Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
gabrielmoreira Skill Security Review 9Complete a security review of the pending changes on the current branch
17 -
gabrielmoreira Skill Doc MaintenanceAudit top-level documentation (README, SPEC, PRODUCT) against recent git history to find drift shipped features missing from docs or features listed as upcoming that already landed. Proposes minimal edits, creates a branch, and opens a PR. Use when asked to review docs for accuracy, after major feature merges, or on a periodic schedule.
17 -
gabrielmoreira Skill Reverse Skill Router 2Use the reverse-skill repository from Codex for authorized reverse engineering, security analysis, CTF, and defensive testing tasks. Requires the reverse-skill repository to be available as the current workspace or an explicitly supplied local path.
17 -
gabrielmoreira Skill Security Guardian 2Use when legacy prompts or older framework flows reference `security-guardian` and you need the modern runtime to resolve that capability cleanly.
17 -
gabrielmoreira Skill Security Reviewer 2Use when legacy prompts or older framework flows reference `security-reviewer` and you need the modern runtime to resolve that capability cleanly.
17 -
gabrielmoreira Skill Grocery Budget Audit 2Summarise what Grocery Budget Audit does in one line. Use when asked to [trigger phrases the user would say]. Produces [the concrete artifact].
17 -
gabrielmoreira Skill Sensory Audit 2Summarise what Sensory Audit does in one line. Use when asked to [trigger phrases the user would say]. Produces [the concrete artifact].
17 -
gabrielmoreira Skill Skill Creator 42Create, edit, improve, or audit AgentSkills. Use when creating a new skill from scratch or when asked to improve, review, audit, tidy up, or clean up an existing skill or SKILL.md file. Also use when editing or restructuring a skill directory (moving files to references/ or scripts/, removing stale content, validating against the AgentSkills spec). Triggers on phrases like "create a skill", "author a skill", "tidy up a skill", "improve this skill", "review the skill", "clean up the skill", "audit the skill".
17 -
gabrielmoreira Skill Mcpwn Cve 2026 33032mcpwn-retry-exploit
17 -
gabrielmoreira Bundle Az Eu Website Privacy Audit Mirza ChiragovAzerbaijan + EU Website Privacy Compliance Audit
17 -
gabrielmoreira Skill Blog Audit 2Full-site blog health assessment scanning all blog files for quality scores, orphan pages, topic cannibalization, stale content, and AI citation readiness. Runs canonical batch analysis before site-wide checks. Produces per-post scores and a prioritized action queue. Use when user says "audit blog", "blog audit", "site audit", "blog health", "audit all posts", "check all blogs".
17 -
gabrielmoreira Skill Meta Compliance Audit BundleAuditable compliance bundle: deep-research with citations → signable .docx report → read-only PDF archive → memory note of audit findings.
17 -
gabrielmoreira Skill Bennett Time Audit 2Summarise what Bennett Time Audit does in one line. Use when asked to [trigger phrases the user would say]. Produces [the concrete artifact].
17 -
gabrielmoreira Bundle Achieving Cmmc Level 2 CompliancePrepare a defense-contractor environment for CMMC Level 2 certification: scope CUI and FCI, implement the 110 NIST SP 800-171 Rev 2 security requirements across 14 families, compute the SPRS score with the DoD Assessment Methodology, manage a compliant POA&M, and ready the organization for a C3PAO assessment. Use when an organization handles Controlled Unclassified Information (CUI) under a DoD contract, when a contract carries DFARS clause 252.204-7012/7019/7020/7021, when preparing for or responding to a CMMC assessment, when computing or improving an SPRS score, when building a System Security Plan or POA&M for 800-171, or when scoping which systems are in the CUI boundary. Keywords: CMMC, CMMC Level 2, NIST 800-171, SP 800-171 Rev 2, CUI, FCI, SPRS, DFARS 7012, C3PAO, POA&M, System Security Plan, DoD Assessment Methodology, 110 controls, defense industrial base, DIB, FedRAMP equivalency.
17 -
gabrielmoreira Skill Iso 42001 AI GovernanceAI governance audit using ISO 42001 standard. Ensures AI systems are developed and deployed responsibly with risk management, ethics, security, transparency, and compliance best practices.
17 -
gabrielmoreira Skill Loop Verifier 2Independent checker for release note drafts. Reviews accuracy against the changelog-scan data, tone, completeness, and flags breaking/security items. Use after draft-release-notes. Never let the drafter verify itself.
17 -
gabrielmoreira Bundle Morocco Ecommerce Compliance Audit Omar LaftouhLegal Compliance Audit — Moroccan E-commerce (Law 09-08 & Law 31-08)
17 -
gabrielmoreira Skill Claude Md ReviewAudit a CLAUDE.md file for the patterns that actually degrade Claude Code's output — vagueness, unnamed files, stale facts, and bloat. Use when asked to review, audit, improve, shrink, or fix a CLAUDE.md, and when a project's results feel inconsistent or Claude keeps rediscovering the same context.
17 -
gabrielmoreira Skill Monitoring Darkweb Sources 2Monitors dark web forums, marketplaces, paste sites, and ransomware leak sites for mentions of organizational assets, leaked credentials, threatened attacks, and threat actor communications to provide early warning intelligence. Use when establishing dark web monitoring coverage, investigating specific data breach claims, or enriching incident investigations with dark web context. Activates for requests involving dark web OSINT, leak site monitoring, credential exposure, Recorded Future dark web, or Tor hidden service intelligence.
17 -
gabrielmoreira Skill Pr 3Use when reviewing an incoming GitHub pull request — runs the multi-level (L1-L5) audit against the PR's real diff range, posts findings as one batched review (inline, summary, or local-only), offers the standard fix chain on NEEDS_FIX, and optionally merges. The maintainer-side counterpart to /hyperflow:issue. Trigger with /hyperflow:pr, "review PR #N", "review this pull request <url>", "audit the PR", "check this contribution".
17 -
gabrielmoreira Skill Warden 2Security engineer — IAM, secrets, threat modeling, hardening, auth, and supply chain security.
17 -
gabrielmoreira Skill Blog Locale AuditAudit a directory of multilingual blog content for completeness, consistency, hreflang correctness, meta-tag parity, and freshness. Builds a translation coverage matrix, flags stale translations, validates hreflang and schema, and emits a prioritized report with runnable fix commands. Use when user says "locale audit", "blog locale-audit", "check translations", "multilingual audit", "translation check", "hreflang check", "Uebersetzungen pruefen".
17 -
gabrielmoreira Skill Xss Testing BurpsuiteIdentifying and validating cross-site scripting vulnerabilities using Burp Suite's scanner, intruder, and repeater tools during authorized security assessments.
17 -
gabrielmoreira Bundle Avoid AI Writing 2Audit and rewrite content to remove AI writing patterns ("AI-isms"). Use this skill when asked to "remove AI-isms," "clean up AI writing," "edit writing for AI patterns," "audit writing for AI tells," or "make this sound less like AI." Supports a detect-only mode, an edit-in-place mode for files, an optional voice profile (casual / professional / technical / warm / blunt), and an iterate-to-convergence pass.
17 -
gabrielmoreira Skill MaliciousFixture that tries to exfiltrate SSH keys and environment secrets.
17 -
gabrielmoreira Bundle Audit 4Use when the user wants a code review on recent changes — quality, spec, security, or performance feedback. Triggers a multi-level (L1-L5) review with a standalone Reviewer; on NEEDS_FIX, offers to apply findings via /hyperflow:plan. Trigger with /hyperflow:audit, "review this change", "review my PR", "audit the diff", "code review".
17 -
gabrielmoreira Bundle Executing Nist Rmf Authorization To OperateDrive a federal system through the NIST Risk Management Framework (SP 800-37 Rev 2) to an Authorization to Operate (ATO): Prepare, Categorize (FIPS 199), Select a control baseline (FIPS 200 / SP 800-53 Rev 5), Implement, Assess (SP 800-53A), Authorize, and Monitor continuously. Use when a system needs an ATO or a renewal, when working a FISMA/FedRAMP authorization package, when building or reviewing an SSP, SAR, or POA&M, when categorizing a system as Low/Moderate/High impact, when selecting or tailoring a control baseline, or when standing up continuous monitoring (ConMon) after authorization. Covers ATO, conditional ATO (cATO), and the artifacts assessors expect. Keywords: NIST RMF, 800-37, ATO, authorization to operate, FISMA, FedRAMP, SSP, SAR, POA&M, FIPS 199, FIPS 200, 800-53, 800-53A, control baseline, security categorization, continuous monitoring, authorizing official, system boundary, ongoing authorization.
17 -
gabrielmoreira Skill Workflow 3Use when a task is too large for turn-by-turn orchestration and should run through the big-task workflow lane: system-wide changes, large migrations, repo-wide audits, high-confidence verification, or tasks explicitly asking to run a workflow. Claude Code uses native dynamic workflows; Codex, OpenCode, and Grok use the portable workflow adapter. Trigger with /hyperflow:workflow, "run a workflow", "dynamic workflow", "big task", "large migration", "repo-wide audit".
17 -
gabrielmoreira Skill Security Review 11Defend before attackers find the gaps - OWASP, STRIDE, and Microsoft SFI
17 -
gabrielmoreira Skill Executing Red Team Exercise 2Executes comprehensive red team exercises that simulate real-world adversary operations against an organization's people, processes, and technology. The red team operates with stealth as a primary objective, employing the full attack lifecycle from initial reconnaissance through objective completion while testing the organization's detection and response capabilities. This differs from penetration testing by focusing on adversary emulation rather than vulnerability identification. Activates for requests involving red team exercise, adversary simulation, adversary emulation, or full-scope offensive security assessment.
17 -
gabrielmoreira Skill Verification 4Prove that a coding task is actually complete. Use this after meaningful code changes, when tests/builds fail or are skipped, before marking a plan or goal complete, and whenever acceptance depends on runtime, security, recovery, performance, or cross-module evidence.
17 -
gabrielmoreira Skill Security AuditorExpert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks.
17 -
gabrielmoreira Skill Tracking Threat Actor Infrastructure 2Threat actor infrastructure tracking involves monitoring and mapping adversary-controlled assets including command-and-control (C2) servers, phishing domains, exploit kit hosts, bulletproof hosting, a
17 -
gabrielmoreira Skill Janitor ValueShow whether each skill is earning its context-window cost — combined tokens-used view sorted by waste. Use when the user asks 'are my skills worth it', 'what's my context budget', 'which skills are dead weight', or wants to audit skill value, token cost, or usage. Trigger with '/janitor-value'.
17 -
gabrielmoreira Skill API Security TestingAPI security testing workflow for REST and GraphQL APIs covering authentication, authorization, rate limiting, input validation, and security best practices.
17 -
gabrielmoreira Skill Web Security TestingWeb application security testing workflow for OWASP Top 10 vulnerabilities including injection, XSS, authentication flaws, and access control issues.
17
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include security-review, doc-maintenance, reverse-skill-router. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.