Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
jihedbfr-art Bundle Enrichment And ContextUse when wiring asset, identity, and threat context into the SOC's data so every alert and query carries the context analysts need — the operational backbone behind fast triage.
-
jihedbfr-art Bundle Third Party Risk ManagementUse when running a vendor/third-party risk programme — assessing and monitoring the security of the vendors and suppliers whose access and services become your risk.
-
jihedbfr-art Bundle File Upload VulnerabilitiesUse when an app accepts file uploads — testing whether the upload can lead to code execution, stored XSS, or overwrite, and how to build a safe upload.
-
jihedbfr-art Bundle Epss And Exploit LikelihoodUse when prioritising vulnerabilities by how likely they are to be exploited — using EPSS and exploit-availability signals instead of severity alone.
-
jihedbfr-art Bundle Package Repo HardeningUse when securing internal package registries — the repositories that serve your organisation's dependencies, so they can't be abused to distribute malicious or confused packages.
-
jihedbfr-art Bundle As Rep RoastingUse when hunting for AD accounts that don't require Kerberos pre-authentication — crackable without any credentials — and how to remove the exposure.
-
jihedbfr-art Bundle Delegation AbuseUse when testing Kerberos delegation configurations in AD — unconstrained, constrained, and resource-based — for the paths they open to impersonation and domain compromise, plus the fixes.
-
jihedbfr-art Bundle Lsass ProtectionUse when hardening Windows hosts against credential theft from LSASS memory — Credential Guard, LSA protection, and the settings that make dumping tools come back empty.
-
jihedbfr-art Bundle Siem Use Case DevelopmentUse when developing SIEM use cases — the structured process of turning a security requirement into a deployed, documented detection with a response, not just a raw rule.
-
jihedbfr-art Bundle Idor And Broken Access ControlUse when testing whether a web app enforces access control server-side — horizontal and vertical privilege checks, function-level auth, and forced browsing — plus the fix.
-
jihedbfr-art Bundle Security Metrics For LeadershipUse when reporting security to executives and the board — translating technical security into business-risk terms and metrics that inform decisions and secure investment.
-
jihedbfr-art Bundle Artifact Signing SigstoreUse when signing and verifying software artifacts with Sigstore/cosign — establishing that artifacts are genuine and unmodified, with keyless signing that removes key-management pain.
-
jihedbfr-art Bundle Extracting IocsUse when turning malware analysis into indicators of compromise — the file, network, and host artifacts defenders use to detect and hunt the threat elsewhere.
-
jihedbfr-art Bundle Secrets Scanning In PipelinesUse when you want to stop credentials from being committed or built into artifacts — wiring secret scanning into pre-commit and CI so leaks are caught before they ship.
-
jihedbfr-art Bundle Malicious Package ResponseUse when a dependency you use turns out to be malicious or compromised — the response to a supply-chain incident where the threat is inside a package you already trusted and installed.
-
jihedbfr-art Bundle Vulnerable Dependency TriageUse when triaging flagged vulnerable dependencies — telling exploitable from merely-present so you fix what actually matters instead of chasing every CVE in the dependency tree.
-
jihedbfr-art Bundle Ad Hardening BaselineUse when you need a prioritised checklist of the Active Directory settings that shut most attack paths — the baseline that turns a soft domain into a hard target.
-
gl0di Skill Security GuideA security skill that DOCUMENTS dangerous patterns as examples of what NOT to do.
-
gl0di Skill Redteam GlossaryA documentation/glossary skill that lists common red-team tool names for security education, with no offensive instructions.
-
gl0di Skill Meta AuditorA documented meta-auditor skill that reads other skills' declared frontmatter metadata (name, description fields) from ~/.openclaw/skills/ to produce a compliance report. No executable code or secret values are read.
-
gl0di Skill Telegram StatusSends a daily security status summary to my own Telegram bot.
-
gl0di Skill Security Notesexplains common security hygiene concepts in plain English.
-
uygnoey Skill Compliance API Audit FeedEnable and use the Claude Platform Compliance API to retrieve and filter organization audit activity (by time range, user, or API key) for security and compliance workflows.
-
uygnoey Skill Enterprise Workspace Security BasicsEstablish baseline administrative and security practices for rolling out Claude in an organization, based on capabilities highlighted in the Claude for Enterprise announcement.
-
uygnoey Bundle Security Public Beta Rollout GuidePlan and run a Claude Security public-beta rollout for a Claude Enterprise organization — choose the access path (direct, partner platform, or services partner), scope scans by repository / directory / branch, schedule recurring runs, route findings into Slack/Jira/audit systems, and use the dismiss-with-reason and confidence-rating workflow to triage results, all anchored in the April 30, 2026 launch post.
-
uygnoey Bundle Governance Via Compliance APIPlan Claude governance using the Claude Compliance API and the 28 launch integrations Anthropic announced on May 21, 2026. Use when an IT or security team is wiring Claude Enterprise and the Claude Platform into existing DLP, SASE, data-security, SIEM/SecOps, identity, eDiscovery, AI-SPM, or AI observability/telemetry stacks — or when a security/compliance platform vendor is deciding whether to apply to the integration network.
-
uygnoey Skill Security Review AutomationAutomate security review workflows with Claude Code by running ad-hoc checks before commits and adding pull-request reviews via GitHub Actions.
-
uygnoey Bundle Memory CurationAudit, correct, and scope what Claude keeps in memory across chat and Cowork. Use when the user asks what Claude remembers about them, wants to fix or delete a saved memory topic, keeps re-explaining the same context between chat and Cowork, is deciding whether to turn on "include sensitive topics in memory", or needs to know which categories are never stored and who controls availability on Team and Enterprise plans.
-
uygnoey Bundle Clue Style Detection Platform PlaybookPlan a Claude-powered detection and response platform in the style of CLUE (Claude Looks Up Evidence), the internal platform Anthropic's Detection Platform Engineering team built with Claude Code. Use when a defensive security team is deciding whether to wrap their SIEM and internal systems with a triage surface and a natural-language investigation surface, where to set the deterministic-vs-agentic boundary, what context sources to plug in via tools, and how to measure impact (false-positive rate, query and tool-call volume, hours saved, coverage of low-confidence signals).
-
jihedbfr-art Bundle Attack Emulation PlanningUse when planning an adversary emulation — mapping a real threat actor's behaviour to a scenario grounded in MITRE ATT&CK, so the engagement tests defences against threats that actually matter.
-
jihedbfr-art Bundle Ad Enumeration BloodhoundUse when you have a domain foothold and need to map Active Directory attack paths — collecting data with SharpHound and analysing it in BloodHound — plus what to fix.
-
jihedbfr-art Bundle Dcsync And Credential DumpingUse when demonstrating how domain and host credentials get harvested — DCSync, LSASS dumping, and cached secrets — and the controls and detections that stop it.
-
ksmaster03 Skill Fr Nfr Specเขียนสเปก requirement เป็นทางการระดับ SRS — Functional Requirements (FR) ที่มี ID ไม่ซ้ำ อะตอมมิก ทดสอบได้ + Non-functional Requirements (NFR) ทุกหมวด (performance, security, availability) ที่ "วัดผลได้" มี metric + target ชัดเจน. Write a formal Software Requirements Specification with uniquely-IDed FRs and measurable NFRs (p95 latency, uptime %, RTO/RPO). Trigger เมื่อผู้ใช้พิมพ์ /fr-nfr-spec หรือขอ "เขียน FR / NFR / SRS / functional spec / non-functional / requirement spec / สเปกระบบ".
-
ksmaster03 Skill Pentest Planวางแผนการทดสอบเจาะระบบแบบได้รับอนุญาต (authorized penetration testing) — กำหนด scope + Rules of Engagement, เลือก methodology (PTES/OWASP WSTG/NIST 800-115), จัดลำดับความรุนแรงด้วย CVSS, รายงานและ retest. Plan an authorized, scoped, legal pen test end-to-end. Trigger เมื่อผู้ใช้พิมพ์ /pentest-plan หรือขอ "pen test / penetration test / ทดสอบเจาะระบบ / rules of engagement / vulnerability assessment / VAPT / pentest report".
-
uygnoey Skill Closing The Patch GapPrioritizes and operationalizes software patching for an environment where AI models quickly reverse patches into exploits. Use when planning patch policy, reducing time-to-patch on internet-exposed systems, triaging large CVE backlogs with KEV and EPSS, or rolling out automated patch deployment.
-
uygnoey Bundle Government Deployment PlanningPlan a government or regulated-environment rollout of Claude Code and Claude Cowork through Claude for Government Desktop — authorization boundary, where data is stored and processed, SCIM-based delegated administration, spend caps, audit logging, and MDM distribution. Use when preparing an ATO package or security review, when a department needs to allocate seats and limits across sub-agencies, when finance needs consumption-based spend bounded against appropriated funds, or when answering IG and auditor questions about usage without exposing sensitive material.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include enrichment-and-context, third-party-risk-management, file-upload-vulnerabilities. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.