Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
bolaflame1 Skill Claim AuditUse this skill for "audit citations", "check citations", "validate claims", "check my references", "audit my manuscript", "claim audit", "citation check", "plagiarism check", "verify citations", or when the user wants to verify that manuscript citations are accurate and that no sentences copy verbatim from source papers.
-
savagedamage Bundle IOS Security WizardUse when doing iOS security: Mach-O, dyld, entitlements.
-
chambear2809 Bundle Splunk Uba SetupUse when validating Splunk UBA / UEBA readiness, optional UBA Kafka ingestion app placement, and migration guidance to Splunk Enterprise Security Premier UEBA without installing standalone UBA servers.
-
chambear2809 Bundle Cisco Webex SetupUse when configuring Webex OAuth, meetings, audit, calling, quality, or Contact Center data in Splunk.
-
chambear2809 Bundle Widefield Security SetupUse when the user asks to onboard WideField Security, plan identity threat detection and response, connect WideField to identity/SIEM/SOAR/governance tools, or coordinate WideField child skill execution without using undocumented WideField APIs. Render, route, validate, and optionally delegate a WideField Security adoption workflow across Okta, Saviynt, Splunk SIEM, Google SecOps, and identity-threat doctor skills.
-
chambear2809 Bundle Cisco Collaboration SetupUse when planning or reviewing Splunk onboarding for Cisco Unified Communications Manager syslog, CDR, or CMR; Cisco Expressway syslog, CDR, or media evidence; Cisco Meeting Server syslog or XML CDR; or Cisco Meeting Management system and audit syslog. Render a privacy-safe, evidence-gated collaboration plan with deterministic SC4S classification and explicit RoomOS, BroadWorks, Webex, and ThousandEyes handoffs without applying changes.
-
chambear2809 Bundle Widefield Google Secops SetupUse when the user asks to ingest WideField Security into Google Security Operations, verify the WideField default parser, prepare feed handoffs, or collect parser evidence while failing closed for undocumented Google SecOps live feed mutation. Render and validate Google SecOps ingestion, webhook/feed, parser, and evidence assets for WideField Security log type WIDEFIELD_SECURITY.
-
chambear2809 Bundle Cisco Intersight SetupUse when configuring or validating Cisco Intersight audit, inventory, alarm, or metrics inputs in Splunk.
-
chambear2809 Bundle Splunk Vmware Ta SetupUse when the user asks about VMware, vCenter, ESXi logs, VMware metrics, VMware indexes, VMware extractions, or making VMware data ready for Splunk ITSI, Enterprise Security, Monitoring Console, or infrastructure dashboards. Install, render, configure, and validate Splunk Supported Add-on coverage for VMware, including the VMware app/add-on family, vCenter collection planning, ESXi syslog handoffs, event and metric index templates, deployment role placement, ITSI readiness, and post-ingest validation.
-
chambear2809 Bundle Widefield Splunk Siem SetupUse when the user asks to send WideField Security events to Splunk, create WideField HEC/index plumbing, validate WideField ingest, or prepare SIEM searches and dashboard readiness for identity threat detections. Render, apply, and validate Splunk SIEM readiness for WideField Security events using a WideField index, HEC token, schema-light spath searches, saved searches, macros, and starter dashboard assets.
-
chambear2809 Bundle Splunk Attack Analyzer SetupUse when a user asks for Attack Analyzer, SAA, phishing and malware analysis data ingestion, the `saa` index, `saa_indexes` macro, or Enterprise Security adaptive response readiness. Install, configure readiness, and validate Splunk Attack Analyzer platform integration using Splunk Add-on for Splunk Attack Analyzer (`Splunk_TA_SAA`, app 6999) and Splunk App for Splunk Attack Analyzer (`Splunk_App_SAA`, app 7000).
-
chambear2809 Bundle Splunk Windows Ta SetupUse when the user asks about Splunk_TA_windows, the Splunk Add-on for Microsoft Windows, WinEventLog or Perfmon inputs, Windows Security event onboarding, Sysmon, or Windows CIM readiness in Splunk. Install, render, configure, and validate the Splunk Add-on for Microsoft Windows (Splunk_TA_windows, Splunkbase 742). Renders reviewable inputs.local.conf overlays for WinEventLog (Security/System/Application, Defender, PowerShell), Perfmon, and WinHostMon inputs, creates the wineventlog and perfmon indexes, enforces UF/HF/search-tier placement, and maps source types to CIM data models.
-
chambear2809 Bundle Splunk License Manager SetupUse when the user asks about configuring a Splunk Enterprise license manager, license master, license peer, License-Master-URI, license slave, license pool, license group, or license usage reporting. Render, preflight, apply, validate, and audit a Splunk Enterprise license manager and its license peers, including license install, license group activation (Enterprise, Forwarder, Free, Trial), license stacks, license pools (with byte or MAX quota and per-peer slave lists), license peer configuration via splunk edit licenser-localpeer, license messages and violations, and license usage reporting.
-
chambear2809 Bundle Splunk Syslog Web Proxy Ta SetupUse when the user asks to onboard, configure, render, or validate these web, proxy, DNS/DHCP, ADC, or appliance logs in Splunk. Shared render, install, and validation workflow for Splunk Supported Add-on parser and web/proxy profiles: Apache, NGINX, IIS, Tomcat, HAProxy, Squid, Blue Coat ProxySG, Forcepoint Web Security, Check Point Log Exporter, F5 BIG-IP, Citrix NetScaler, and Infoblox. Renders product- specific local file/UF, Windows UF, or SC4S/syslog transport handoffs with package-backed source types.
-
chambear2809 Bundle Widefield Okta Integration SetupUse when the user asks to connect WideField Security to Okta, configure Okta event hooks for WideField, validate shared-signal risk events, or build Okta evidence for WideField detect-and-remediate workflows. Render, validate, and safely apply the Okta side of a WideField Security integration, including OIN handoffs, Shared Signals receiver evidence, and documented Okta event hook creation, update, verification, or deactivation.
-
chambear2809 Bundle Splunk Enterprise Public Exposure HardeningUse when the user asks to expose Splunk Enterprise on the public internet, harden a Splunk search head against internet exposure, configure TLS / HSTS / CSP / mTLS / per-IP rate limit / DMZ heavy forwarder, lock down splunkd or the KV store, fix splunk.secret / pass4SymmKey defaults, evaluate against the latest SVD floor (10.4.0 / 10.2.2 / 10.0.5 / 9.4.10 / 9.3.11), or render nginx / HAProxy / WAF reference configs in front of Splunk. Render, preflight, apply, and validate hardening of an on-prem Splunk Enterprise deployment for public-internet exposure across all four edge surfaces (Splunk Web on 8000, HEC on 8088, Splunk-to-Splunk on 9997, splunkd REST on 8089) plus reference reverse-proxy / WAF / firewall templates and a structured operator handoff.
-
chambear2809 Bundle Splunk Enterprise Security InstallUse when the user asks to install, upgrade, bootstrap, post-install, or validate Splunk Enterprise Security. Install, post-install, and validate Splunk Enterprise Security (ES), including SplunkEnterpriseSecuritySuite, essinstall, standalone search-head and SHC deployer workflows, required ES framework apps, local splunk-ta packages, and Splunkbase app 263 fallback.
-
chambear2809 Bundle Splunk Security Appliance Ta SetupUse when the user asks for Carbon Black or Symantec EP supported add-on onboarding when package extraction has verified coverage. Render, install, and validate first-pass package-verified security appliance supported add-ons for Carbon Black and Symantec Endpoint Protection. Covers Splunk_TA_bit9-carbonblack and Splunk_TA_symantec-ep app IDs, versions, package-derived source types, file/syslog transport ownership, eventtypes, lookups, and readiness-doctor handoffs.
-
chambear2809 Bundle Splunk Appdynamics Security AI SetupUse when the user asks for AppDynamics Secure Application, application security monitoring, Secure Application policies, Secure Application APIs, Secure Application `policyConfigs`, Secure Application for OTel Java, Observability for AI, OpenAI or LangChain monitoring, Bedrock checks, GPU telemetry, or Cisco AI Pod AppDynamics handoffs. Render, validate, and delegate Splunk AppDynamics security and AI workflows, including Application Security Monitoring, Secure Application, Secure Application runtime policies, Secure Application `policyConfigs`, Secure Application APIs, Secure Application for OpenTelemetry Java, Observability for AI, OpenAI, LangChain, Bedrock, GPU readiness, and Cisco AI Pod handoffs.
-
chambear2809 Bundle Splunk Security Content Update SetupUse when the user asks to install, upgrade, review, or validate ESCU or Splunk security content. Render, install, and validate Splunk Enterprise Security Content Update readiness for DA-ESS-ContentUpdate, ES search-head placement, package delivery, Analytic Story Detail navigation, content inventory checks, correlation-search activation review, and ES configuration handoff.
-
timwukp Bundle Fsi Compliance Checker 2Maps code, architecture, and infrastructure changes to specific control IDs in financial services compliance frameworks - PCI-DSS v4.0 for payment card data and MAS TRM for Singapore-regulated institutions - producing an audit-traceable findings report with per-control remediation. Use this instead of a general security review whenever a compliance framework (PCI-DSS, MAS TRM), regulator, audit, or cardholder-data scope is mentioned, even if the request is phrased as a code review or a yes/no compliance question. Triggers on: "PCI-DSS check", "MAS TRM", "is this compliant", "compliance review", "audit this change for banking regulations", "does logging this violate PCI", "cardholder data handling review".
-
shinpr-claude-code-workflows Skill Recipe Review 3Reviews completed implementation for governing-source compliance, scope economy, repository quality, and security, then applies user-approved corrections.
-
sysdig Bundle Sysdig SysqlSysQL query language reference for Sysdig Secure. Use when writing, debugging, or explaining SysQL graph queries against the Sysdig security datastore. Triggers on: SysQL queries, Sysdig inventory/vulnerability/posture/identity/runtime queries, "write a SysQL query", "query sysdig for", "find vulnerable images", "show me workloads", or any task involving MATCH/RETURN syntax against Sysdig entities. Also use when exploring the SysQL schema (entities, fields, relationships). Each query's entities and fields are validated against the live schema before it is shown and run, and the results are presented with follow-up suggestions.
-
sysdig Bundle Sysdig Runtime RemediateClose the runtime loop on a Sysdig-detected threat: turn the investigation context into proposed response actions, analyse the blast radius on the affected workload, and execute (or file) the actions the user approves — one at a time, with explicit confirmation. Triggers: "remediate this runtime threat", "respond to event <id>", "act on this incident", "isolate / kill / pause that container", "/sysdig-runtime-remediate". Not for vulnerability fixes (use sysdig-remediate) or threat investigation itself (use sysdig-runtime-investigate).
-
sysdig Bundle Sysdig Runtime InvestigateUse this skill when investigating a runtime threat detected by Sysdig end-to-end. Surfaces the highest-priority threat, scores vulnerability vs runtime correlations on a 1-5 confidence scale, deep-dives into network blast radius or suspicious-binary VirusTotal lookups depending on the event class, reconstructs the affected workload's activity audit trail (commands, connections, file accesses) as a timeline around the detection, and hands the case off to Jira or PagerDuty. Triggers on: "investigate runtime threat", "what is this Falco alert", "triage this SOC alert", "analyze runtime incident". Not for vulnerability prioritization (use `sysdig-investigate`) or remediation (use `sysdig-remediate`).
-
wundercorp Bundle GodmodeJailbreak LLMs: Parseltongue, GODMODE, ULTRAPLINIAN.
-
wundercorp Skill SherlockFind accounts for a username across 400+ platforms.
-
wundercorp Bundle UnbrokerAutonomously remove your info from data-broker sites.
-
wundercorp Bundle 1passwordSet up op CLI, sign in, and read or inject secrets.
-
tdak1509 Skill Code Review FullFull review of the current branch against main — runs the claim-check, the security/performance-leak review, and the clean-code check together. Use when the user asks for a full code review, a combined review, or just "review this branch" without specifying which kind.
-
tdak1509 Skill Code Review LeaksReview the current branch's diff against main for security and performance leaks — only in the changed files. Use when the user asks to review a PR, review changes, check for security issues, or check for performance regressions.
-
wundercorp Bundle Web PentestAuthorized web pentest: recon, proof-based exploits, report.
-
citxen Bundle Code ReviewReviews pending code changes for bugs, security issues, and maintainability problems. Use when the user asks to review code, check a diff, or look over changes before committing
-
wundercorp Bundle Oss ForensicsGitHub supply-chain forensics: recovery, IOCs, reporting.
-
wundercorp Skill Requesting Code ReviewPre-commit review: security scan, quality gates, auto-fix.
-
patsnap Bundle Rd Initiation ReviewR&D project initiation pre-screen and proposal audit for go/no-go decisions, public novelty boundary review, innovation-point assessment, and evidence-backed project rating. Use when the user asks for project initiation pre-screening, initiation review, proposal review, R&D project evaluation, proposal-package review, novelty pre-screening, innovation-point review, project rating, or wants a formal review around a concrete project, proposal, or research-package material set — even if they only provide the proposal and do not explicitly say "review".
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include claim-audit, ios-security-wizard, splunk-uba-setup. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.