Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
aibot88 Bundle Legal Audit 2Audit current legal posture — identify gaps in policies, contracts, and compliance
3 -
aibot88 Bundle Review Auth 2Production-readiness audit for authentication. Use when auth code changes or when auth feels fragile, unclear, or unsafe. Covers OIDC, sessions, tokens, route protection, and secret management.
3 -
aibot88 Bundle Rust Strict 2Rust security, strictness, and vulnerability prevention rules. Use when writing, reviewing, or auditing Rust code. Complements rust-skills (179 general rules) with security-focused rules: unsafe audit, unwrap/expect bans, error handling hierarchy, secret handling, concurrency safety, input validation for Tauri commands, and release profile hardening. Derived from production Rust projects.
3 -
aibot88 Bundle Sast Report 2Consolidate all SAST vulnerability results from the sast/ folder into a single final report ranked by severity and confidentiality impact. Reads all *-results.md files and produces sast/final-report.md. Run after all vulnerability detection skills complete. Use when asked to generate a final report, consolidate findings, or summarize security results.
3 -
aibot88 Bundle Simple Earn 2Binance Simple-earn request using the Binance API. Authentication requires API key and secret key.
3 -
aibot88 Bundle Sub Account 2Binance Sub-account request using the Binance API. Authentication requires API key and secret key.
3 -
aibot88 Bundle Truthfinder 2Always-active web search safety skill. Classifies every website into SAFE, CAUTION, RISKY, or BLOCKED before reading or citing it. Reads and evaluates real user reviews and feedback to surface genuine sentiment. Detects fake, paid, or astroturfed reviews. Filters misinformation, malware, phishing, and data-harvesting sites. Never visits or relays content from dangerous sources. Protects the user's personal data and software from any site that could steal or exploit it.
3 -
aibot88 Bundle Warden Scan 2Automated SAST + dependency vulnerability scan. Runs Semgrep (code vulnerabilities) and pip-audit (CVE-matched dependencies) and writes a structured JSON report. Use when asked to "scan for vulnerabilities", "run a security scan", "check for CVEs", or "audit dependencies".
3 -
javiertarazon Skill Laravel Expert 2Senior Laravel Engineer role for production-grade, maintainable, and idiomatic Laravel solutions. Focuses on clean architecture, security, performance, and modern standards (Laravel 10/11+).
-
javiertarazon Skill Pentest Checklist 2This skill should be used when the user asks to "plan a penetration test", "create a security assessment checklist", "prepare for penetration testing", "define pentest scope", "foll...
-
javiertarazon Skill Solidity Security 2Master smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns. Use when writing smart contracts, auditing existing contracts, or implementin...
-
javiertarazon Skill Sast Configuration 2Configure Static Application Security Testing (SAST) tools for automated vulnerability detection in application code. Use when setting up security scanning, implementing DevSecOps practices, or aut...
-
javiertarazon Skill Metasploit Framework 2This skill should be used when the user asks to "use Metasploit for penetration testing", "exploit vulnerabilities with msfconsole", "create payloads with msfvenom", "perform post-exp...
-
javiertarazon Skill Nodejs Best Practices 2Node.js development principles and decision-making. Framework selection, async patterns, security, and architecture. Teaches thinking, not copying.
-
javiertarazon Skill Production Code AuditAutonomously deep-scan entire codebase line-by-line, understand architecture and patterns, then systematically transform it to production-grade, corporate-level professional quality with optimizations
-
javiertarazon Skill Laravel Security Audit 2Security auditor for Laravel applications. Analyzes code for vulnerabilities, misconfigurations, and insecure practices using OWASP standards and Laravel security best practices.
-
javiertarazon Skill Vulnerability Scanner 2Advanced vulnerability analysis principles. OWASP 2025, Supply Chain Security, attack surface mapping, risk prioritization.
-
javiertarazon Skill Ssh Penetration Testing 2This skill should be used when the user asks to "pentest SSH services", "enumerate SSH configurations", "brute force SSH credentials", "exploit SSH vulnerabilities", "perform SSH tu...
-
javiertarazon Skill Attack Tree Construction 2Build comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders.
-
javiertarazon Skill Stride Analysis Patterns 2Apply STRIDE methodology to systematically identify threats. Use when analyzing system security, conducting threat modeling sessions, or creating security documentation.
-
aifinlab Bundle Claims Case Summary Audit Assistant 2���û���Ҫ�ѷ�ɢ�����������������ʺ�������ˡ����ˡ�������˻��ڲ�����ʹ�õİ���ժҪʱʹ�ñ� skill�������ڻ������������顢�¹ʾ���˵���������¼��סԺ���ϡ���Ժ��¼�����֤������鱨�桢�������桢������¼���¹�֤����������˾�����ϡ��˲м���������֤������ϵ֤�����������ϡ����ϼ�����������嵥�������������������ȣ���������������ʵ���ؼ�֤�ݡ���������㡢����������״̬������ѵ㡢����ʵ����ͺ�����˽��顣
-
javiertarazon Skill Linux Privilege Escalation 2This skill should be used when the user asks to "escalate privileges on Linux", "find privesc vectors on Linux systems", "exploit sudo misconfigurations", "abuse SUID binaries", "ex...
-
javiertarazon Skill Codebase Cleanup Deps Audit 2You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues,...
-
javiertarazon Skill Ethical Hacking Methodology 2This skill should be used when the user asks to "learn ethical hacking", "understand penetration testing lifecycle", "perform reconnaissance", "conduct security scanning", "exploit ...
-
javiertarazon Skill Privilege Escalation Methods 2This skill should be used when the user asks to "escalate privileges", "get root access", "become administrator", "privesc techniques", "abuse sudo", "exploit SUID binaries", "K...
-
javiertarazon Skill Windows Privilege Escalation 2This skill should be used when the user asks to "escalate privileges on Windows," "find Windows privesc vectors," "enumerate Windows for privilege escalation," "exploit Windows miscon...
-
javiertarazon Skill Wordpress Penetration Testing 2This skill should be used when the user asks to "pentest WordPress sites", "scan WordPress for vulnerabilities", "enumerate WordPress users, themes, or plugins", "exploit WordPress vu...
-
javiertarazon Skill Security Requirement Extraction 2Derive security requirements from threat models and business context. Use when translating threats into actionable requirements, creating security user stories, or building security test cases.
-
javiertarazon Skill Dependency Management Deps Audit 2You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues,...
-
javiertarazon Skill Security Compliance Compliance Check 2You are a compliance expert specializing in regulatory requirements for software systems including GDPR, HIPAA, SOC2, PCI-DSS, and other industry standards. Perform compliance audits and provide im...
-
javiertarazon Skill Incident Response Incident Response 2Use when working with incident response incident response
-
javiertarazon Skill Security Scanning Security Hardening 2Coordinate multi-layer security scanning and hardening across application, infrastructure, and compliance controls.
-
javiertarazon Skill Security Scanning Security Dependencies 2You are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security. Scan project dependencies across ecosystems to identify vulnerabilities, ass...
-
aifinlab Bundle Global Audit Trace 2用于审计追踪场景。适用于金融工作中的基础任务单元。
-
aifinlab Bundle Audit Trace Check 2面向基金合规与信息披露领域的留痕检查任务Skill,围绕「审计留痕检查助手」场景提供信息抽取、结构化分析与结果输出。
-
charlieviettq Skill Brief 2Generate contextual briefings for legal work — daily summary, topic research, or incident response. Use when starting your day and need a scan of legal-relevant items across email, calendar, and contracts, when researching a specific legal question across internal sources, or when a developing situation (data breach, litigation threat, regulatory inquiry) needs rapid context.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include legal-audit, review-auth, rust-strict. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.