Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
iapro-community Bundle Skill Saas Dast ReconRun defensive, explicitly authorized SaaS DAST and recon with scope controls. Use when asked to scan an owned local, staging, preview, or approved production URL, API endpoint, SaaS app, tenant boundary, public web surface, auth flow, exposed files, headers, TLS, or OWASP Top 10 behavior using tools such as ZAP, Nuclei, Katana, httpx, and Subfinder.
-
iapro-community Skill Skill Threat ModelingConduz threat modeling estruturado com STRIDE-A, fluxos de dados, fronteiras de confiança, riscos priorizados e comparação incremental.
-
iapro-community Bundle Skill Saas Security ScanRun defensive, authorized local security scans for owned SaaS repositories. Use when asked to scan local code, dependencies, secrets, containers, IaC, API handlers, Supabase projects, multi-tenant SaaS isolation, or release/security gates with maintained OSS tools such as Semgrep, Gitleaks, Trivy, OSV-Scanner, and OWASP Dependency-Check.
-
iapro-community Skill Skill Google Workspace SyncUse for Google Workspace integrations with OAuth, Calendar, Meet, FreeBusy, Drive, Sheets, webhooks, least-privilege scopes, encrypted refresh tokens, idempotent writes, reconciliation jobs, consent revocation, validation, and sync audit trails.
-
williamzujkowski Bundle Iam Security ReviewerReview identity and access management using NIST SP 800-63B guidelines with MFA enforcement, password policy, and least privilege validation.
-
williamzujkowski Bundle Operating System Security Hardening CheckerVerify operating system hardening using CIS benchmarks with patch management, kernel hardening, and host-based firewall validation.
-
williamzujkowski Bundle Container Image OptimizerCreate optimized Dockerfiles with multi-stage builds, security hardening, and vulnerability scanning for minimal, secure container images.
-
williamzujkowski Bundle Application Security ValidatorValidate application security using OWASP Top 10 2021 and API Security Top 10 guidelines with injection prevention and access control checks.
-
williamzujkowski Bundle Cryptographic Security ValidatorValidate cryptographic implementations using NIST standards with TLS configuration, cipher suite analysis, and certificate lifecycle checks.
-
williamzujkowski Bundle Oscal Ssp ValidatorValidates OSCAL System Security Plan documents against schemas, profiles, and cross-reference requirements with tiered validation depth.
-
williamzujkowski Bundle Network Security Architecture ValidatorValidate network security architecture with firewall rule analysis, segmentation verification, and defense-in-depth assessment.
-
williamzujkowski Bundle Zero Trust Maturity AssessorEvaluate zero-trust architecture maturity using CISA ZTMM with identity verification, device trust, micro-segmentation, and continuous monitoring.
-
williamzujkowski Bundle Zero Trust Architecture DesignerDesign zero-trust architectures with identity-centric security, micro-segmentation, continuous verification, and CISA ZTMM maturity assessment.
-
williamzujkowski Bundle Incident Response Playbook GeneratorGenerate incident response playbooks for security incidents, outages, and disaster recovery with NIST SP 800-61 compliance and escalation paths.
-
williamzujkowski Bundle Software Supply Chain Security ValidatorValidate software supply chain security with SBOM generation, dependency scanning, provenance verification, and SLSA attestation.
-
tomevault-io Bundle NiktoWeb server scanner for dangerous files and misconfigurations Use when this capability is needed.
-
tomevault-io Bundle Yellow Seed Agentusagewidget Reviewing Securityセキュリティレビュー
-
felvieira Skill Repo AuditorSkill de auditoria inicial e continua do repositorio. Use quando precisar mapear stack real, convencoes, assets, testes, docs, riscos e pontos de integracao antes de executar outras skills. O resultado deve ser persistido em markdown reutilizavel para reduzir releitura e economizar tokens. Trigger em: "repo audit", "auditar repositorio", "mapear stack do projeto", "harnessability score", "repo-audit", "auditoria de repo", "fotografia do repo", "current.md", "mapear convencoes do projeto", "inventariar o codebase".
-
lyndonkl Bundle Design Evaluation Audit 2Scores designs on cognitive checklists with ranked fixes.
-
plurigrid Bundle Substitute Eraser 2This skill should be used when the user asks to "scan for TODOs", "find placeholders", "clean up stubs", "remove temporary code", "audit for incomplete code", or "erase substitutions from codebase". Scans existing files for placeholder tokens and generates remediation plan.
-
iapro-community Skill Skill Evolution API 2Use for WhatsApp automation with Evolution API, including instance lifecycle, QR pairing, inbound and outbound messages, webhooks, consent, tenant isolation, queues, idempotency, rate limits, retries, audit logs, and reliable delivery.
-
iapro-community Skill Skill Google Workspace Sync 2Use for Google Workspace integrations with OAuth, Calendar, Meet, FreeBusy, Drive, Sheets, webhooks, least-privilege scopes, encrypted refresh tokens, idempotent writes, reconciliation jobs, consent revocation, validation, and sync audit trails.
-
bkjohn2018 Skill Sop WritingWrites governance-ready standard operating procedures with precise scope, role accountability, step controls, and audit-ready evidence requirements. Use when users ask to draft, improve, or standardize SOPs for operational, finance, or data governance processes.
-
bkjohn2018 Skill Data Standards ManagementDefines and maintains enterprise data standards for classification, access, quality, metadata, lineage, retention, integration, reference/master data, metrics, and analytical models. Use when creating a data standards catalog, mapping standards to DAMA-DMBOK capabilities and NIST SP 800-53 control considerations, or deciding what baseline requirements data products must satisfy. Use data-security-and-privacy-controls for asset-level security/privacy control design, policy-and-standard-writing for final mandatory language, and domain skills for implementation.
-
bkjohn2018 Skill Data Management FoundationsApplies DAMA-DMBOK aligned data management foundations across strategy, architecture, governance, quality, metadata, security, and lifecycle controls. Use when users ask for enterprise data management frameworks, operating models, role design, or maturity roadmaps. Use data-standards-management for detailed standards catalogs and data control requirements.
-
bkjohn2018 Skill Governance Ppt Deck WritingStructures governance presentation decks with clear decision narrative, control status, risk signals, and action tracking. Use when preparing steering committee, risk committee, audit, or executive governance slide decks.
-
bkjohn2018 Skill Finance AI Risk Control MappingMaps finance and accounting AI risks to governance, security, privacy, data, and internal control requirements using NIST AI RMF, NIST SP 800-53 concepts, DAMA-DMBOK, and finance control practices. Use when assessing AI use cases, agents, models, assistants, vendor AI, or automation for control objectives, owners, evidence, residual risk, and approval conditions.
-
felvieira Skill Security ReviewSkill do Security Reviewer para auditoria de segurança e boas práticas. Use quando precisar revisar código para vulnerabilidades, validar implementação de auth, checar OWASP Top 10, revisar CORS/CSRF/XSS, garantir DRY e clean code, ou qualquer review de segurança. Trigger em: "segurança", "security review", "vulnerabilidade", "OWASP", "XSS", "CSRF", "CORS", "injection", "HttpOnly", "cookie seguro", "DRY", "code review", "boas práticas", "audit", "pentest", "sanitização".
-
felvieira Skill Persona Driven Issue AuditSkill de auditoria em massa via personas simuladas: infere proto-personas do repositorio, confirma com o humano sem bloquear, e roda ate PR — encontra bugs, abre issues com dedup, analista comenta solucao, frota paralela abre PR onde a confianca e alta ou comenta wontfix, reviewer decide. Termina em issues residuais, nunca merge automatico. Trigger em: "simulando usuarios reais diferentes", "fazer a IA impersonar persona e testar o app", "encontrar bugs de usabilidade em massa antes do lancamento", "numa auditoria, como triar tudo isso", "frota de agentes paralelos abrindo PR", "regras de dedup de issue quando varios agentes reportam", "abrir PR automatica ou comentar wontfix", "escalar QA exploratorio com IA sem virar gargalo", "simular usuario nao tecnico testando o produto", "PRs deveriam ser aprovadas automaticamente", "nao tenho personas escritas, da pra gerar a partir do repo", "auditoria automatica do produto sem preparar nada antes", "inferir persona a partir do codigo do projeto".
-
dirtytrii Bundle GstackCodex adapter for Garry Tan's full gstack methodology across CEO/product pressure, CTO architecture, design, engineering, QA, security, shipping, documentation, and retrospectives. Use when the 总控/CEO or 架构/CTO role needs gstack method routing, implementation-plan hardening, or the user says gstack should help a role.
-
dirtytrii Bundle Gstack CsoGStack CSO method for broad infrastructure-first security posture review, threat areas, severity calibration, and safe remediation scope.
-
aidas-dev Skill Cilium NetworkUse when configuring Cilium CNI networking, writing network policies, debugging pod connectivity issues, setting up LB IPAM or L2 announcements for Service LoadBalancer IPs, enabling BGP route advertisement, configuring transparent encryption or Hubble observability, or managing Cilium security features (host firewall, Local Redirect Policy, CiliumCIDRGroup). Not for Gateway API (use cilium-gateway).
-
pedroiff0 Bundle Express Csp Runtime ConfigHow to pass server-side runtime config (API prefix, feature flags, user id, CSRF token) from an Express/EJS app to client JS when a strict Content-Security-Policy is in force (helmet default scriptSrc self, with no unsafe-inline). Use this whenever you need to inject a value the browser JS must read at runtime, but adding a script tag triggers a silent CSP block.
-
fworks-tech Skill The AuditorReviews code for security vulnerabilities, dependency risks, and access control issues. Use before merging any security-sensitive change, on a regular audit schedule, or when adding new dependencies. The Auditor assumes breach and reads code the way an attacker would.
-
fworks-tech Skill The DoormanValidates commit messages, PR titles, branch health, and repository standards. Use to enforce conventions locally and in CI, run health checks, and audit repository hygiene. Nothing gets in without proper credentials.
-
fworks-tech Skill Pull Request AssistantGenerates comprehensive pull request descriptions and conducts structured code reviews with security, performance, testing, and documentation focus areas. Use when opening a PR or reviewing one before merge.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include skill-saas-dast-recon, skill-threat-modeling, skill-saas-security-scan. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.