Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
tonone-ai Skill Resp Playbook 2Write an incident response playbook for a threat scenario — detection, containment, eradication, recovery. Use when asked to "write an IR playbook", "build an incident response runbook", or "how do we respond to ransomware".
-
tonone-ai Skill Warden Scan 2Automated SAST + dependency vulnerability scan. Runs Semgrep (code vulnerabilities) and pip-audit (CVE-matched dependencies) and writes a structured JSON report. Use when asked to "scan for vulnerabilities", "run a security scan", "check for CVEs", or "audit dependencies".
-
tonone-ai Skill Change Recon 2Audit existing changelog and deprecation practices — find missing entries, undocumented breaks, and stale deprecations. Use when asked to "audit our changelog", "find undocumented breaking changes", or "check for stale deprecations".
-
tonone-ai Skill Compat Audit 2Audit a proposed API change for breaking changes — classification and impact assessment. Use when asked "is this a breaking change", "will this break clients", or "assess the impact of this API change".
-
tonone-ai Skill Compat Recon 2Audit existing API for breaking change risks and missing compatibility controls. Use when asked to "find breaking change risks in our API", "audit our compatibility controls", or "what could break clients".
-
tonone-ai Skill Schema Recon 2Audit existing API schemas across a codebase — find inconsistencies and coverage gaps. Use when asked to "audit our API schemas", "find schema inconsistencies", or "check spec coverage".
-
tonone-ai Skill Warden Audit 2Full security audit — secrets, dependencies, IAM, auth, injection, XSS, HTTPS, rate limiting, public storage. Use when asked for "security audit", "check for vulnerabilities", "security review", or "are we secure".
-
tonone-ai Skill Warden Recon 2Security reconnaissance — full inventory of secrets management, IAM, dependencies, auth, encryption, audit logging, and compliance gaps. Use when asked about "security posture", "how secure is this", or "security assessment".
-
tonone-ai Skill Audit Controls 2Internal legal controls review — approval workflows, contract lifecycle, access to sensitive docs. Use when asked to "audit our controls", "review approval workflows", or "who can access sensitive contracts".
-
bbgnsurftech Bundle Scanning For Gdpr Compliance 4This skill enables Claude to scan applications and data systems for GDPR compliance issues. It identifies potential violations related to data protection, privacy rights, consent management, and other regulatory requirements. Use this skill when the user asks to "scan for GDPR compliance", check "GDPR compliance", or audit for "data privacy". The skill leverages the `gdpr-compliance-scanner` plugin to perform a comprehensive assessment and generate a detailed report.
-
bbgnsurftech Bundle Managing Ssltls Certificates 2This skill enables Claude to manage and monitor SSL/TLS certificates using the ssl-certificate-manager plugin. It is activated when the user requests actions related to SSL certificates, such as checking certificate expiry, renewing certificates, or listing installed certificates. Use this skill when the user mentions "SSL certificate", "TLS certificate", "certificate expiry", "renew certificate", or similar phrases related to SSL/TLS certificate management. The plugin can list, check, and renew certificates, providing vital information for maintaining secure connections.
-
bbgnsurftech Bundle Validating Authentication Implementations 2This skill enables Claude to validate authentication implementations against security best practices and industry standards. It analyzes various authentication methods, including JWT, OAuth, session-based authentication, and API keys. Use this skill when you need to perform an authentication security check, assess password policies, evaluate MFA implementation, or analyze session security. Trigger this skill with phrases like "validate authentication," "authentication check," or "authcheck."
-
bbgnsurftech Bundle Finding Security Misconfigurations 2This skill enables Claude to identify potential security misconfigurations in various systems and configurations. It leverages the security-misconfiguration-finder plugin to analyze infrastructure-as-code, application configurations, and system settings, pinpointing common vulnerabilities and compliance issues. Use this skill when the user asks to "find security misconfigurations", "check for security vulnerabilities in my configuration", "audit security settings", or requests a security assessment of a specific system or file. This skill will assist in identifying and remediating potential security weaknesses.
-
bbgnsurftech Skill 000 Jeremy Content Consistency Validator 2Validates messaging consistency across website, GitHub repositories, and local documentation. Generates comprehensive read-only discrepancy reports showing where messaging conflicts or inconsistencies exist. Activates when user mentions "consistency check", "validate documentation", "check for mixed messaging", "audit content consistency", or before updating internal paperwork.
-
frank-luongt Skill Owasp Top10 2<!-- AUTO-GENERATED by export-skills.py — DO NOT EDIT -->
-
frank-luongt Skill Iam Security 2<!-- AUTO-GENERATED by export-skills.py — DO NOT EDIT -->
-
diegosouzapw Bundle Account Security Validation 2Validate account security and authentication protocols.
54 -
diegosouzapw Bundle Top 100 Web Vulnerabilities Reference 2This skill should be used when the user asks to "identify web application vulnerabilities", "explain common security flaws", "understand vulnerability categories", "learn about injection attacks", "review access control weaknesses", "analyze API security issues", "assess security misconfigurations", "understand client-side vulnerabilities", "examine mobile and IoT security flaws", or "reference the OWASP-aligned vulnerability taxonomy". Use this skill to provide comprehensive vulnerability definitions, root causes, impacts, and mitigation strategies across all major web security categories.
54 -
tonone-ai Skill Hue Recon 2Audit existing color usage in a codebase — find inconsistencies, hardcoded values, and contrast failures. Use when asked to "audit our color usage", "find hardcoded hex values", or "check for contrast failures".
-
tonone-ai Skill Hue Token 2Audit or refactor a design token system for color — naming, structure, and coverage. Use when asked to "refactor our color tokens", "fix color token naming", or "improve token coverage for color".
-
tonone-ai Skill Brace Kb 2Build or audit knowledge base -- article structure, coverage gaps, deflection rate, and maintenance process. Use when asked to "build a knowledge base", "what docs are missing", "improve our self-serve rate", or "audit our help center".
-
tonone-ai Skill Form Exam 2Theory-backed design audit — names the principle violated, cites the source, shows the fix. Use when asked to "evaluate design quality", "check if this follows design principles", "theory check", "design exam", "audit against best practices", or "what's wrong with this design".
-
tonone-ai Skill Mint Unit 2Audit and improve unit economics — LTV, CAC, payback period, gross margin, contribution margin. Use when asked to "are our unit economics good", "what is our LTV/CAC", or "how do we improve gross margin".
-
tonone-ai Skill Siem Rule 2Write SIEM detection rules for a threat or TTP — SIGMA format, MITRE mapping, and test cases. Use when asked to "write a SIGMA rule", "build a detection rule for this TTP", or "map a SIEM rule to MITRE".
-
tonone-ai Skill Blue Recon 2Audit existing security controls and detection coverage — find gaps against MITRE ATT&CK. Use when asked to "audit our detection coverage", "where are our security control gaps", or "check our MITRE coverage".
-
tonone-ai Skill Buzz Recon 2PR and community reconnaissance — audit current press coverage, social presence, community health, and competitor PR. Use when asked to "audit our PR", "what's our community state", "how do we compare in press", or before planning a launch or community initiative.
-
tonone-ai Skill Cast Recon 2Survey existing forecasting code or models in a codebase — find gaps, stale models, and missing validation. Use when asked "what forecasting models do we have", "audit our forecasts", or "find stale models".
-
tonone-ai Skill Copy Audit 2Audit UX copy in a product or codebase — find passive errors, generic labels, missing states. Use when asked to "audit our UX copy", "our error messages are bad", or "review the microcopy".
-
tonone-ai Skill Edge Recon 2Audit existing CDN and edge configuration — find cache misses, missing headers, and performance gaps. Use when asked to "audit our CDN", "why is our cache hit rate low", or "find edge config gaps".
-
tonone-ai Skill Eval Recon 2Audit existing experimentation infrastructure and past experiments for methodology issues. Use when asked to "audit our experiments", "is our experimentation sound", or "review past test methodology".
-
tonone-ai Skill Feat Store 2Design or audit a feature store — serving, freshness, and sharing across models. Use when asked "do we need a feature store", "design a feature store", or "share features across models".
-
tonone-ai Skill Gate Recon 2Audit existing API quality controls — find missing lint rules, gaps in CI gates, and quality debt. Use when asked to "audit our API quality controls", "find missing lint rules", or "assess our API governance".
-
tonone-ai Skill Grid Recon 2Audit existing layout patterns in a codebase — find ad-hoc spacing, inconsistent grids, and missing primitives. Use when asked to "audit our layout patterns", "we have ad-hoc spacing everywhere", or "our grids are inconsistent".
-
tonone-ai Skill Hunt Recon 2Design a threat hunting program — maturity assessment, hunting calendar, and playbook library. Use when asked to "build a threat hunting program", "assess our hunting maturity", or "create a hunt playbook library".
-
tonone-ai Skill Keel Audit 2Operational efficiency audit — identify waste, redundancy, and friction across processes, tools, and team workflows. Use when asked to "audit our operations for waste", "where are we inefficient", "what tools are we paying for but not using", or "reduce operational overhead".
-
tonone-ai Skill Keep Recon 2Customer success reconnaissance — audit current onboarding completion, health signals, NRR, churn patterns, and CS motion. Use when asked to "audit our customer success", "why are customers churning", "what's our NRR", or before designing any CS playbook.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include resp-playbook, warden-scan, change-recon. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.