Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
frank-luongt Bundle Security Compliance Compliance Check 3<!-- AUTO-GENERATED by export-skills.py — DO NOT EDIT -->
-
frank-luongt Bundle Security Scanning Security Hardening<!-- AUTO-GENERATED by export-skills.py — DO NOT EDIT -->
-
frank-luongt Skill Security Scanning Security Hardening 2<!-- AUTO-GENERATED by export-skills.py — DO NOT EDIT -->
-
frank-luongt Bundle Mobile Security Coder 3<!-- AUTO-GENERATED by export-skills.py — DO NOT EDIT -->
-
frank-luongt Bundle Backend Security Coder 3<!-- AUTO-GENERATED by export-skills.py — DO NOT EDIT -->
-
frank-luongt Bundle Threat Modeling Expert 3<!-- AUTO-GENERATED by export-skills.py — DO NOT EDIT -->
-
frank-luongt Bundle Container Security Guide 3<!-- AUTO-GENERATED by export-skills.py — DO NOT EDIT -->
-
frank-luongt Skill Cwe Sans Top25 3<!-- AUTO-GENERATED by export-plugins.py — DO NOT EDIT -->
-
frank-luongt Bundle Security Scanning Security Dependencies 3<!-- AUTO-GENERATED by export-skills.py — DO NOT EDIT -->
-
frank-luongt Skill Owasp API Top10 4<!-- AUTO-GENERATED by export-plugins.py — DO NOT EDIT -->
-
frank-luongt Skill Security Scanning Security Hardening 3<!-- AUTO-GENERATED by export-skills.py — DO NOT EDIT -->
-
frank-luongt Skill Secrets Management 4<!-- AUTO-GENERATED by export-plugins.py — DO NOT EDIT -->
-
frank-luongt Skill Container Security Guide 4<!-- AUTO-GENERATED by export-plugins.py — DO NOT EDIT -->
-
j4flmao Bundle RbacRole-Based Access Control and OIDC integration skill for advanced harness engineering.
-
j4flmao Bundle PHP PureUse this skill when building PHP applications without a framework — PSR standards, routing, middleware, database access, error handling, and security. This skill enforces: PSR-4 autoloading, PSR-7 request/response, PSR-15 middleware, PSR-11 container, PSR-3 logging. Requires PHP 8.1+. Do NOT use for: Laravel, Symfony, WordPress, or framework-specific PHP development.
-
j4flmao Bundle PHP ZendUse this skill when the user says 'Zend', 'Laminas', 'Zend Framework', 'Laminas MVC', 'laminas-servicemanager', 'laminas-db', 'laminas-form', 'laminas-inputfilter', 'laminas-router', 'laminas-view', 'laminas-module', 'Mezzio', 'laminas-stratigility', 'API Platform', 'Doctrine ORM', 'Zend Framework 3', 'ZF3', 'Zend Expressive'. Covers: Laminas MVC project structure, Module system, ServiceManager DI, routing, controllers, database (laminas-db + Doctrine), forms, validation, views, Mezzio middleware, API development, security, testing. Do NOT use this for: Laravel (use php-laravel), plain PHP (use php-pure), or Symfony-specific questions.
-
j4flmao Bundle Edr XdrManage endpoint detection and response, EDR/XDR platforms, detection rules, and incident investigation. Use when the user asks about EDR, XDR, endpoint detection, CrowdStrike, Defender, SentinelOne, or detection rule.
-
j4flmao Bundle Security API SecurityUse this skill when asked about API security, OWASP API Top 10, rate limiting, API authentication, JWT security, OAuth2, API key management, API gateway, WAF, API abuse, request signing, or API threat modeling. This skill enforces: OWASP API Top 10 threat modeling, authentication/authorization patterns (JWT, OAuth2, API keys), rate limiting with tiered policies (token bucket, sliding window, per-user/per-endpoint), input validation and WAF rules, request signing, and audit logging. Do NOT use for: web application security (XSS, CSRF), network security (TLS, mTLS), or container security.
-
j4flmao Bundle Devops Gitops AdvancedUse when the user asks about advanced GitOps, multi-cluster GitOps, ArgoCD ApplicationSets, sync waves, sync phases, progressive delivery with GitOps, cluster bootstrapping, or GitOps at scale. Covers: ApplicationSet generators (cluster, git, matrix, SCM provider, pull request), sync wave orchestration, phased rollouts, image updater, multi-cluster management with ArgoCD, cluster bootstrapping with Crossplane/Cluster API, secrets management in GitOps (SealedSecrets, External Secrets, SOPS), and GitOps at enterprise scale with RBAC, projects, and audit. Do NOT use for: basic GitOps introduction (gitops), basic ArgoCD setup (argo-cd), or Flux setup.
-
j4flmao Bundle Security Data SecurityUse this skill when implementing data security: encryption at rest/transit, key management (KMS, HSM), data masking (static, dynamic), column-level security, data privacy (GDPR, CCPA), data classification, data anonymization, tokenization. This skill enforces: encryption strategy selection, key management architecture, masking rules, column-level access controls, anonymization technique, compliance controls. Do NOT use for: network security (firewalls, VPCs), identity and access management (IAM), application security scanning.
-
j4flmao Bundle Soc OperationsManage SOC operations, tiered analyst workflows, shift handovers, and security incident escalation. Use when the user asks about SOC, security operations center, SOC analyst, SOC tier, security monitoring, or SOC metrics.
-
j4flmao Bundle Apm ObservabilityUse this skill when the user says 'APM', 'observability', 'monitoring', 'Datadog', 'New Relic', 'Grafana', 'Prometheus', 'OpenTelemetry', 'distributed tracing', 'metrics', 'logging', 'SLI', 'SLO', 'error budget', 'application performance monitoring', 'trace', 'span', 'telemetry', 'instrumentation', 'RUM', 'synthetics', 'alerting'. Covers: metrics collection, distributed tracing, log aggregation, alerting and on-call, dashboards, SLI/SLO/error budget, RUM, synthetics, OpenTelemetry instrumentation, cost optimization for observability tools. Do NOT use for: infrastructure monitoring only (use monitoring skill), SIEM/security monitoring (use security skill).
-
j4flmao Skill Attack PatternsAttack Patterns & MITRE ATT&CK
-
j4flmao Skill Threat ModelingPerform threat modeling using the STRIDE methodology and security-by-design principles before coding.
-
j4flmao Bundle Dev Loop Security AuditorUse when the user asks about security auditing, vulnerability scanning, security review, dependency vulnerabilities, SAST, DAST, penetration testing, or security best practices. Do NOT use for: code review (dev-loop-code-review), or performance profiling (dev-loop-performance-profiler).
-
j4flmao Bundle Mobile SecurityUse this skill when the user asks about mobile security, secure storage, certificate pinning, SSL pinning, biometric authentication, data encryption, ProGuard, obfuscation, or OWASP Mobile Top 10.
-
j4flmao Skill Persona Staff Backend EngineerAdopts the mindset and thought process of a Staff-level Backend Engineer focusing on Zero-trust Security, Observability, Stateless APIs, and Concurrency control.
-
j4flmao Bundle Siem EngineeringDesign SIEM architecture, onboard log sources, create correlation rules, manage use cases, and tune detection. Use when the user asks about SIEM, Splunk, Wazuh, Elastic Security, Microsoft Sentinel, log source, correlation rule, or SIEM use case.
-
j4flmao Bundle Blockchain DefiUse this skill when asked about decentralized finance, DeFi protocols, AMM mechanics, lending and borrowing protocols, perpetual futures, yield farming, liquidity mining, liquid staking, restaking, yield optimization, DeFi security, MEV, and protocol composability. Covers AMM design (Uniswap, Curve, Balancer), lending protocols (Aave, Compound, Morpho), derivatives (dYdX, GMX, Synthetix), liquid staking (Lido, Rocket Pool, EigenLayer restaking), and yield strategies (Yearn, Convex). Do NOT use for: general smart contract development (use blockchain-application), blockchain core protocol (use blockchain-core), or web3 UI integration (use blockchain-web3).
-
j4flmao Bundle Management Risk ManagementUse this skill when the user says 'risk management', 'risk register', 'risk assessment', 'risk mitigation', 'project risk', 'technical risk', 'risk matrix', 'risk analysis', 'probability impact', 'risk log'. Identify, assess, and plan responses for project and technical risks. Do NOT use for: security vulnerability scanning or compliance audits.
-
j4flmao Skill Red Team OperatorAdopts the persona of a Principal Red Team Operator for conceptual security analysis and APT simulation.
-
j4flmao Skill Persona Security EngineerAdopts the persona of a Staff-level Security Engineer. Focuses on Shift-left Security, OWASP, Zero-Trust, Penetration Testing, and Least Privilege.
-
j4flmao Skill Blue Team Soc OperationsMaster methodologies for SIEM architecture, incident response, and threat hunting.
-
mvanhorn-printing-press-libra Bundle Pp DataforseoEvery DataForSEO endpoint, plus auto-mode routing, cost estimates, keyword pre-cleaning, and a local SQLite store no... Trigger phrases: `check keyword volume`, `track rank on my sitemap`, `audit backlinks for`, `estimate dataforseo cost`, `ai visibility for`, `use dataforseo`, `run dataforseo-pp`.
-
j4flmao Bundle SecurityUse this skill when the user asks about security team operations, AppSec, vulnerability management, security review, threat modeling, security incident response, CVE, or compliance.
-
j4flmao Bundle Code ReviewUse this skill when the user says 'review this code', 'code review', 'review PR', 'check this implementation', 'is this code good', 'LGTM?', 'feedback on code', or wants a structured code review. Covers: correctness, architecture, clarity, performance, security, and test quality. Produces a structured review with severity levels: MUST, SHOULD, CONSIDER. Works with any language/stack. Do NOT use this for: debugging (use debugging-strategy), writing code, or architectural planning.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include security-compliance-compliance-check, security-scanning-security-hardening, security-scanning-security-hardening. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.