Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
blackpearl-ai Skill Agency Infrastructure MaintainerExpert infrastructure specialist focused on system reliability, performance optimization, and technical operations management. Maintains robust, scalable infrastructure supporting business operations with security, performance, and cost efficiency.
-
blackpearl-ai Skill Agency Runbook Incident ResponseThe Agency Incident Response Runbook: SRE, DevOps, security, and root cause recovery orchestration.
-
blackpearl-ai Skill Agency Threat Detection EngineerExpert detection engineer specializing in SIEM rule development, MITRE ATT&CK coverage mapping, threat hunting, alert tuning, and detection-as-code pipelines for security operations teams.
-
blackpearl-ai Skill Agency Blockchain Security AuditorExpert smart contract security auditor specializing in vulnerability detection, formal verification, exploit analysis, and comprehensive audit report writing for DeFi protocols and blockchain applications.
-
blackpearl-ai Skill Agency Security Compliance AuditorExpert technical compliance auditor specializing in SOC 2, ISO 27001, HIPAA, and PCI-DSS audits — from readiness assessment through evidence collection to certification.
-
blackpearl-ai Skill Agency Security Incident ResponderDigital forensics and incident response specialist who leads breach investigations, contains active threats, coordinates crisis response, and writes post-mortems that prevent recurrence.
-
blackpearl-ai Skill Agency Threat Intelligence AnalystCyber threat intelligence specialist who tracks adversary groups, maps attack campaigns to MITRE ATT&CK, produces actionable intelligence reports, and builds detection rules that catch real threats.
-
gl0di Skill Ad Threat HunterA blue-team detection-engineering skill that hunts for offensive AD tooling usage via Sysmon and SIEM telemetry.
-
jihedbfr-art Bundle JWT AttacksUse when an API authenticates with JSON Web Tokens — testing for algorithm confusion, none-alg, weak secrets, and unchecked claims, plus how to validate tokens correctly.
-
jihedbfr-art Bundle Grpc SecurityUse when securing or testing a gRPC API — authentication, input validation, and the differences from REST that change how you attack and defend it.
-
jihedbfr-art Bundle Mass AssignmentUse when an API binds request data straight onto objects — testing whether you can set fields you shouldn't, like role or ownership, and how to bind safely.
-
jihedbfr-art Bundle Vpn SecurityUse when assessing or hardening a VPN — IPsec or WireGuard configuration, authentication, and the exposure a remote-access gateway creates — so the tunnel doesn't become the way in.
-
jihedbfr-art Bundle Dns SecurityUse when securing DNS infrastructure — DNSSEC, resolver filtering, and detecting tunnelling and exfiltration — because DNS is both a control point and an attacker's favourite covert channel.
-
jihedbfr-art Bundle Webhook SecurityUse when building or reviewing webhook endpoints — verifying that inbound events are authentic and can't be forged, replayed, or used to attack your internal network.
-
jihedbfr-art Bundle Tls InspectionUse when checking a service's TLS configuration on the wire — protocol versions, cipher suites, and certificate validity — to find weak crypto and misconfiguration.
-
jihedbfr-art Bundle Ids Ips TuningUse when deploying or tuning network intrusion detection/prevention — cutting false positives without going blind, and placing sensors where they actually see the traffic.
-
jihedbfr-art Bundle Endpoint HuntingUse when hunting on endpoint telemetry — the process, persistence, and injection patterns that reveal compromise on hosts, using the richest data source available to a hunter.
-
jihedbfr-art Bundle Anomaly BaseliningUse when hunting requires knowing what normal looks like — establishing baselines of normal behaviour so anomalies stand out, the foundation most hunts depend on.
-
jihedbfr-art Bundle Broken AuthenticationUse when testing how an API authenticates callers — token issuance, validation, expiry, and credential endpoints — for the flaws that let an attacker forge or steal identity.
-
jihedbfr-art Bundle API Gateway HardeningUse when deciding where and how to enforce API security controls — using the gateway as the consistent choke point for auth, rate limits, and schema instead of per-service reinvention.
-
jihedbfr-art Bundle Ssl Pinning BypassUse in an authorised assessment to bypass certificate pinning so you can inspect a mobile app's TLS traffic — and understand what pinning does and doesn't protect.
-
jihedbfr-art Bundle Mobile API TrafficUse when testing the backend a mobile app talks to — intercepting and testing the API, because the real attack surface is often the server, not the app on the device.
-
jihedbfr-art Bundle Race ConditionsUse when reviewing code for TOCTOU and concurrency bugs with a security impact — the double-spend, the check that goes stale before the use, the shared state two requests corrupt.
-
jihedbfr-art Bundle Beaconing DetectionUse when hunting for command-and-control beaconing in network telemetry — the regular-interval callbacks that reveal C2 even when the destination and payload are unknown.
-
jihedbfr-art Bundle Living Off The LandUse when hunting for attackers abusing legitimate built-in tools (LOLBins) — the PowerShell, WMI, and signed-binary abuse that blends in with normal admin activity.
-
jihedbfr-art Bundle Actor TrackingUse when tracking a threat actor over time — attributing activity, following their evolving tradecraft, and turning "who and how" into defensive advantage.
-
jihedbfr-art Bundle IOS Static AnalysisUse when you have an iOS app (IPA) and want to read it statically for secrets, weak configuration, and binary protection gaps — without running it.
-
jihedbfr-art Bundle Xss TestingUse when checking whether a web app reflects or stores input that executes as script in a victim's browser — covers reflected, stored, and DOM XSS plus the output-encoding fix.
-
jihedbfr-art Bundle Excessive Data ExposureUse when an API returns more data than the client needs — testing whether responses leak fields the user shouldn't see, and how to filter at the server.
-
jihedbfr-art Bundle Secrets At RESTUse when protecting stored secrets and sensitive data at rest — envelope encryption and secret managers — so a database or disk breach doesn't hand over plaintext.
-
jihedbfr-art Bundle Dns And Proxy HuntingUse when hunting DNS and web-proxy logs for C2, exfiltration, and malicious domains — high-value logs that reveal what hosts are really talking to.
-
jihedbfr-art Bundle Misp And SharingUse when running a threat-intel sharing platform and exchanging intelligence — using MISP and STIX/TAXII to manage, share, and consume intel with the wider community.
-
jihedbfr-art Bundle Network SegmentationUse when designing or reviewing network segmentation — dividing a network so a foothold in one zone can't reach everything, and verifying the boundaries actually hold.
-
jihedbfr-art Bundle Firewall Rule ReviewUse when auditing a firewall rule set for overly-permissive, shadowed, or stale rules — the accumulated cruft that quietly widens what's allowed through.
-
jihedbfr-art Bundle Csrf TestingUse when testing whether an app performs state-changing actions without verifying intent — letting a malicious page act as a logged-in victim — and how to stop it.
-
jihedbfr-art Bundle Ssti TestingUse when user input reaches a server-side template engine — testing for template injection that can escalate to remote code execution, and how to render untrusted data safely.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include agency-infrastructure-maintainer, agency-runbook-incident-response, agency-threat-detection-engineer. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.