Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
jihedbfr-art Bundle Insecure Data StorageUse when checking how a mobile app stores data — finding the secrets, tokens, and PII left in readable local storage that anyone with the device (or a backup) can extract.
-
jihedbfr-art Bundle Ssh HardeningUse when securing SSH access to Linux hosts — key-based auth, disabling weak options, and cutting the exposure of the most-attacked service on the internet.
-
jihedbfr-art Bundle Mitm And Arp SpoofingUse in a lab or authorised test to understand adversary-in-the-middle attacks on a local network — ARP spoofing and interception — and, crucially, the controls that stop them.
-
jihedbfr-art Bundle Xxe InjectionUse when an app parses XML you can influence — testing whether external entities let you read files, reach internal services, or cause DoS — and the parser hardening that stops it.
-
jihedbfr-art Bundle Sudo HardeningUse when reviewing or writing sudoers configuration — granting elevated access without handing out shell escapes or effectively-root privileges by accident.
-
jihedbfr-art Bundle Alert EnrichmentUse when detections fire with too little context — adding asset, identity, and threat data automatically so analysts triage faster and with better decisions.
-
jihedbfr-art Bundle Operationalising A HuntUse when turning a hunt into lasting value — converting findings into detections, documenting the hunt, and feeding results back so the programme improves instead of repeating itself.
-
jihedbfr-art Bundle Intel RequirementsUse when defining what intelligence to collect — establishing intelligence requirements so the programme answers real questions instead of collecting everything and hoping.
-
jihedbfr-art Bundle Iso 27001 IsmsUse when standing up or running an ISO 27001 information security management system — building the risk-driven management framework, not just a binder of policies, and getting certified.
-
jihedbfr-art Bundle Policy WritingUse when writing security policies people actually follow — clear, actionable, enforceable documents that drive behaviour, not shelfware written to satisfy an auditor.
-
jihedbfr-art Bundle Network Access ControlUse when controlling which devices are allowed onto the network — 802.1X and NAC — so an unauthorised device can't just plug in and join, and posture is checked before access.
-
jihedbfr-art Bundle Android Static AnalysisUse when you have an Android APK and want to read it for secrets, weak configuration, and vulnerable code without running it — the first pass on any mobile assessment.
-
jihedbfr-art Bundle Deep Link And Ipc AbuseUse when testing a mobile app's inter-process communication surface — deep links, URL schemes, intents, and exported components that other apps (or the web) can invoke maliciously.
-
jihedbfr-art Bundle Play Appstore HardeningUse when hardening a mobile app for release — the ship-side controls, store security requirements, and configuration that reduce risk before and after publishing to the app stores.
-
jihedbfr-art Bundle Suid Sgid AuditUse when auditing a Linux host for SUID/SGID binaries — files that run with their owner's privileges — to find the ones that hand a low-priv user a path to root.
-
jihedbfr-art Bundle Lateral Movement HuntingUse when hunting for an attacker moving between hosts — the authentication patterns, remote-execution, and access anomalies that reveal lateral movement across the network.
-
jihedbfr-art Bundle Dark Web MonitoringUse when monitoring criminal forums, marketplaces, and leak sites for threats to your organisation — exposed credentials, data leaks, and chatter — done legally and safely.
-
jihedbfr-art Bundle Risk AssessmentUse when you need to identify, score, and prioritise security risks in a way people actually act on — turning "this feels dangerous" into a ranked, defensible register.
-
jihedbfr-art Bundle Soc 2 ReadinessUse when preparing for a SOC 2 audit — understanding the Trust Services Criteria, Type I vs Type II, and getting the controls and evidence in place to pass without last-minute panic.
-
jihedbfr-art Bundle Packet Capture AnalysisUse when you need to read what's actually on the wire — capturing and analysing traffic with tcpdump and Wireshark to investigate an incident, confirm a finding, or debug.
-
jihedbfr-art Bundle Selinux ApparmorUse when applying mandatory access control on Linux — keeping SELinux or AppArmor enforcing (not disabled) so a compromised process is confined to what it's meant to do.
-
xjli360 Bundle Sealeap Taotie Amazon Inventory Page Health CheckRun a health check on the Manage Inventory page: triage inactive and search-suppressed listings, read available, inbound, unfulfillable and reserved quantities with their reasons, audit estimated fees against own measurements, complete missing attributes flagged by the listing quality dashboard, and review merchant-fulfilled handling-time settings. Use for 商品搜不到、非在售原因、搜索结果中禁止显示、库存预留是什么、运营中心调拨、不可售库存怎么处理、预估费用不对、缺失属性提示、商品信息质量面板、自发货处理时间. Do not use to change prices in bulk or to file removal orders without confirming the current fee schedule.
-
xjli360 Bundle Sealeap Jiaotu Amazon Cross Marketplace Policy AuditRun a recurring cross-marketplace review that pulls each active marketplace's current fee schedule, new-seller incentive terms, and compliance requirement changes directly from official sources, then routes findings into operations, logistics, finance, and brand action lists. Findings are marketplace- and date-stamped at review time rather than assumed to persist, since fee and incentive terms are revised on independent schedules per marketplace. Use for 多站点费率变动核查、新卖家权益核对、跨站合规差异梳理、季度政策复盘、供应链与定价随政策调整. Do not use to apply one marketplace's fee change or incentive terms to another marketplace without checking that marketplace's own current announcement.
-
xjli360 Bundle Sealeap Yazi Amazon Event Eligibility Price Stack CheckRun a pre-event readiness check before major sale windows: audit listing and account health signals, confirm each promotion tool's current eligibility threshold directly in the seller backend, and reconcile the net customer-facing price across every stacked promotion against the currently visible reference price. Every eligibility threshold and stacking rule is treated as changeable and must be reverified in-platform before submission. Use for 大促开售前要检查什么、店铺与商品评分够不够报会员专享折扣、优惠券和秒杀能不能叠加、折后净价怎么算才不会报错、大促报名前的账号自查清单. Do not use to submit a promotion with a percentage or price copied from a prior period without re-checking the current backend eligibility page and price calculator.
-
xjli360 Bundle Sealeap Feilian Amazon Buyer Segment Price CalibrationAudit whether a reported shift toward value-driven, income-segmented buying behavior actually shows up in the account's own category conversion and price-band data before rebalancing keyword bidding, price bands, and the mix between high-consideration and everyday-replenishment items. Treats third-party consumer-sentiment findings as hypotheses to confirm with the account's own data, not as facts to act on directly. Use for 大促消费分层核实、价格带与关键词匹配复核、选品双轨结构评估、广告加码前的必要性判断、受影响SKU库存与清仓节奏规划. Do not use to assume a reported national consumer-sentiment shift applies to this account's category without checking its own conversion and price-band data first.
-
gl0di Bundle ExfilskillExfiltrates env secret directly — bad_taint_direct fixture.
-
ksmaster03 Skill Tool Stack Auditตรวจชุดเครื่องมือ/ซอฟต์แวร์ที่ใช้ หาความซ้ำซ้อนและช่องว่าง
-
uygnoey Skill Deep ReviewComprehensive code review that runs security, performance, and style reviews in parallel as subagents and synthesizes findings. Use when reviewing staged changes before a commit or PR.
-
jihedbfr-art Bundle Hypothesis Driven HuntingUse when you want to proactively hunt for threats the alerts missed — framing a testable hypothesis, searching the telemetry to prove or kill it, and turning findings into detections.
-
jihedbfr-art Bundle Enrichment PipelinesUse when building automated enrichment for indicators — adding context (reputation, WHOIS, relationships, geolocation) to raw IoCs so they become actionable intelligence.
-
jihedbfr-art Bundle Security HeadersUse when reviewing or hardening a web app's HTTP response headers — CSP, HSTS, and the rest — knowing which actually reduce risk and which are theatre.
-
jihedbfr-art Bundle Systemd HardeningUse when hardening Linux services with systemd unit directives — sandboxing a daemon so a compromise of it can't reach the rest of the system.
-
jihedbfr-art Bundle Tactical Vs StrategicUse when producing intelligence for different audiences — understanding the tactical, operational, and strategic levels so intel reaches the SOC, IR, and leadership in the form each needs.
-
jihedbfr-art Bundle Port And Service ScanningUse when you need to know what's actually listening on a host or range — open ports, the services behind them, and their versions — before assessing or hardening it.
-
jihedbfr-art Bundle Mobile Auth And BiometricsUse when assessing mobile authentication and biometric (Face ID / fingerprint) implementations — the local-auth mistakes that let an attacker bypass the lock without the biometric.
-
jihedbfr-art Bundle Auditd And LoggingUse when setting up Linux audit logging — configuring auditd to record the security-relevant events that let you detect and investigate compromise, without drowning in noise.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include insecure-data-storage, ssh-hardening, mitm-and-arp-spoofing. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.