Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
tonone-ai Skill Mark Recon 2Audit existing brand assets and usage — find inconsistencies, off-brand applications, and gaps. Use when asked to "audit our brand assets", "find off-brand usage", or "check brand consistency".
-
tonone-ai Skill Mesh Recon 2Audit existing service mesh configuration — find mTLS gaps, traffic policy issues, and observability holes. Use when asked to "audit our service mesh", "find mTLS gaps", or "review traffic policy issues".
-
tonone-ai Skill Mock Recon 2Audit existing mocks and test doubles — find contract drift, missing error cases, and stale fixtures. Use when asked to "audit our mocks", "find stale test fixtures", or "check for contract drift".
-
tonone-ai Skill Move Recon 2Audit existing animations in a codebase — find inconsistencies, missing reduced-motion support, and performance issues. Use when asked to "audit our animations", "check reduced-motion support", or "our animations are janky".
-
tonone-ai Skill Pave Audit 2Audit developer experience — measure onboarding time, build speed, deployment friction, and developer satisfaction. Use when asked to "DX audit", "developer experience review", "why is development slow", "onboarding assessment", or "DORA metrics".
-
tonone-ai Skill Plot Recon 2Audit existing visualizations in a codebase or notebook — find misleading charts and quality issues. Use when asked to "audit our charts", "find misleading visualizations", or "review chart quality".
-
tonone-ai Skill Port Recon 2Audit multi-language SDK coverage — find missing languages, inconsistencies, and maintenance gaps. Use when asked to "audit our SDK coverage", "find missing language SDKs", or "review SDK maintenance gaps".
-
tonone-ai Skill Resp Recon 2Audit existing incident response capability — playbook coverage, tooling gaps, and readiness. Use when asked to "audit our incident response", "assess IR readiness", or "find playbook coverage gaps".
-
tonone-ai Skill Sast Recon 2Audit existing application security tooling and code for OWASP Top 10 coverage. Use when asked to "audit our appsec tooling", "check OWASP Top 10 coverage", or "find code security gaps".
-
tonone-ai Skill Scope Oss 2Open source license compliance audit — flag GPL, LGPL, AGPL, copyleft risks. Use when asked to "check our open source licenses", "do we have GPL risk", or "run an OSS license audit".
-
tonone-ai Skill Siem Recon 2Audit existing SIEM deployment — log coverage, rule quality, and alert volume. Use when asked to "audit our SIEM", "find log coverage gaps", or "our alert volume is too high".
-
tonone-ai Skill Volt Power 2Power management audit — analyze sleep modes, wake sources, power state machines, radio duty cycles, and battery life estimates. Use when asked to "audit power usage", "optimize battery life", "review power management", "why is my battery draining", "power budget analysis", or "sleep mode review".
-
tonone-ai Skill Grid Responsive 2Audit or redesign responsive behavior of a layout — breakpoints, reflow, and content priority. Use when asked to "fix responsive behavior", "define breakpoints", or "how should this reflow on mobile".
-
tonone-ai Skill Warden Harden 2Produce a hardening spec and implement it — auth patterns, security headers, rate limiting, input validation, secrets management, dependency hygiene. Use when asked to "harden this", "add security to this service", "what security do I need", or "secure this before launch".
-
tonone-ai Skill Onboard Audit 2Audit the developer onboarding experience — measure TTFC and find friction points. Use when asked "why do developers drop off", "audit our onboarding", or "measure time to first call".
-
jmagly-ai-writing-guide Skill Security Engineering Quickref 2AUTO-INVOKE when user mentions cryptography, AEAD, KDF, chain of trust, signing key, auth factor, MFA, secret hygiene, supply chain trust, physical threat, DFIR readiness, or incident evidence handoff. Security-engineering quick reference — decision domains for crypto primitives, chain-of-trust, auth factors, degraded modes, supply-chain trust, physical-threat modeling, and DFIR readiness routing.
-
bbgnsurftech Bundle Checking Infrastructure Compliance 3Use when you need to work with compliance checking. This skill provides compliance monitoring and validation with comprehensive guidance and automation. Trigger with phrases like "check compliance", "validate policies", or "audit compliance".
-
bbgnsurftech Bundle Analyzing Dependencies 3Check dependencies for known security vulnerabilities and outdated versions. Use when auditing third-party libraries. Trigger with 'check dependencies', 'scan for vulnerabilities', or 'audit packages'.
-
bbgnsurftech Bundle Performing Penetration Testing 3Perform security penetration testing to identify vulnerabilities. Use when conducting security assessments. Trigger with 'run pentest', 'security testing', or 'find vulnerabilities'.
-
bbgnsurftech Bundle Implementing Database Audit Logging 3Use when you need to track database changes for compliance and security monitoring. This skill implements audit logging using triggers, application-level logging, CDC, or native logs. Trigger with phrases like "implement database audit logging", "add audit trails", "track database changes", or "monitor database activity for compliance".
-
bbgnsurftech Bundle Scanning For Gdpr Compliance 3Scan for GDPR compliance issues in data handling and privacy practices. Use when ensuring EU data protection compliance. Trigger with 'scan GDPR compliance', 'check data privacy', or 'validate GDPR'.
-
bbgnsurftech Bundle Scanning Input Validation Practices 3Scan for input validation vulnerabilities and injection risks. Use when reviewing user input handling. Trigger with 'scan input validation', 'check injection vulnerabilities', or 'validate sanitization'.
-
bbgnsurftech Bundle Checking Owasp Compliance 3Check compliance with OWASP Top 10 security risks and best practices. Use when performing comprehensive security audits. Trigger with 'check OWASP compliance', 'audit web security', or 'validate OWASP'.
-
bbgnsurftech Bundle Scanning Container Security 3Use when you need to work with security and compliance. This skill provides security scanning and vulnerability detection with comprehensive guidance and automation. Trigger with phrases like "scan for vulnerabilities", "implement security controls", or "audit security".
-
bbgnsurftech Bundle Validating Csrf Protection 3Validate CSRF protection implementations for security gaps. Use when reviewing form security or state-changing operations. Trigger with 'validate CSRF', 'check CSRF protection', or 'review token security'.
-
bbgnsurftech Bundle Responding To Security Incidents 3Guide security incident response, investigation, and remediation processes. Use when you need to handle security breaches, classify incidents, develop response playbooks, gather forensic evidence, or coordinate remediation efforts. Trigger with phrases like "security incident response", "ransomware attack response", "data breach investigation", "incident playbook", or "security forensics".
-
bbgnsurftech Skill Scanning For Secrets 2This skill helps you scan your codebase for exposed secrets and credentials. It uses pattern matching and entropy analysis to identify potential security vulnerabilities such as API keys, passwords, and private keys. Use this skill when you want to proactively identify and remediate exposed secrets before they are committed to version control or deployed to production. It is triggered by phrases like "scan for secrets", "check for exposed credentials", "find API keys", or "run secret scanner".
-
bbgnsurftech Skill Encrypting And Decrypting Data 2This skill enables Claude to encrypt and decrypt data using various algorithms provided by the encryption-tool plugin. It should be used when the user requests to "encrypt data", "decrypt a file", "generate an encrypted file", or needs to secure sensitive information. This skill supports various encryption methods and ensures data confidentiality. It is triggered by requests related to data encryption, decryption, or general data security needs.
-
bbgnsurftech Skill Plugin Auditor 2Automatically audits Claude Code plugins for security vulnerabilities, best practices, CLAUDE.md compliance, and quality standards when user mentions audit plugin, security review, or best practices check. Specific to claude-code-plugins repository standards.
-
bbgnsurftech Skill Validating Pci Dss Compliance 2This skill uses the pci-dss-validator plugin to assess codebases and infrastructure configurations for compliance with the Payment Card Industry Data Security Standard (PCI DSS). It identifies potential vulnerabilities and deviations from PCI DSS requirements. Use this skill when the user requests to "validate PCI compliance", "check PCI DSS", "assess PCI security", or "review PCI standards" for a given project or configuration. It helps ensure that systems handling cardholder data meet the necessary security controls.
-
bbgnsurftech Skill Checking Infrastructure Compliance 4This skill allows Claude to check infrastructure compliance against industry standards such as SOC2, HIPAA, and PCI-DSS. It analyzes existing infrastructure configurations and reports on potential compliance violations. Use this skill when the user asks to assess compliance, identify security risks related to compliance, or generate reports on compliance status for SOC2, HIPAA, or PCI-DSS. Trigger terms include: "compliance check", "SOC2 compliance", "HIPAA compliance", "PCI-DSS compliance", "compliance report", "infrastructure compliance", "security audit", "assess compliance".
-
bbgnsurftech Skill Performing Penetration Testing 4This skill enables automated penetration testing of web applications. It uses the penetration-tester plugin to identify vulnerabilities, including OWASP Top 10 threats, and suggests exploitation techniques. Use this skill when the user requests a "penetration test", "pentest", "vulnerability assessment", or asks to "exploit" a web application. It provides comprehensive reporting on identified security flaws.
-
bbgnsurftech Skill Automating API Testing 2This skill automates API endpoint testing, including request generation, validation, and comprehensive test coverage for REST and GraphQL APIs. It is used when the user requests API testing, contract testing, or validation against OpenAPI specifications. The skill analyzes API endpoints and generates test suites covering CRUD operations, authentication flows, and security aspects. It also validates response status codes, headers, and body structure. Use this skill when the user mentions "API testing", "REST API tests", "GraphQL API tests", "contract tests", or "OpenAPI validation".
-
bbgnsurftech Skill Scanning For Data Privacy Issues 2This skill enables Claude to automatically scan code and configuration files for potential data privacy vulnerabilities using the data-privacy-scanner plugin. It identifies sensitive data exposure, compliance violations, and other privacy-related risks. Use this skill when the user requests to "scan for data privacy issues", "check privacy compliance", "find PII leaks", "identify GDPR violations", or needs a "privacy audit" of their codebase. The skill is most effective when used on projects involving personal data, financial information, or health records.
-
bbgnsurftech Bundle Performing Security Audits 2This skill allows Claude to conduct comprehensive security audits of code, infrastructure, and configurations. It leverages various tools within the security-pro-pack plugin, including vulnerability scanning, compliance checking, cryptography review, and infrastructure security analysis. Use this skill when a user requests a "security audit," "vulnerability assessment," "compliance review," or any task involving identifying and mitigating security risks. It helps to ensure code and systems adhere to security best practices and compliance standards.
-
tonone-ai Skill Zero Audit 2Audit an existing environment against zero trust principles — find implicit trust and over-privileged access. Use when asked to "audit against zero trust", "find implicit trust", or "find over-privileged access".
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include mark-recon, mesh-recon, mock-recon. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.