Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
finchipaiorg Skill Draft Requests For ProductionDrafting a plaintiff's first set of requests for production in a breach of contract and trade secret misappropriation action requires linking request categories to the pleaded claims and defenses, including a Definitions and Instructions section, and specifying ESI format requirements.
-
finchipaiorg Skill Draft Saas Subscription AgreementDraft an enterprise SaaS subscription agreement for a healthcare platform procurement, together with a drafting issues memo, using the available commercial, legal, negotiation, and security materials.
-
finchipaiorg Skill Hls Draft Enterprise Saas Vendor OnboardingDrafts a tailored healthcare SaaS vendor onboarding questionnaire and internal cover memo that addresses AI/ML governance, security and incident-response enhancements, applicable consumer health-data privacy considerations, and cross-border data handling.
-
finchipaiorg Skill Draft Data Room Population Plan S02Guides preparation of a data room population plan with critical DDRL review, regulatory filing-check validation, open-source audit staleness assessment, LGPL copyleft risk identification, anti-assignment consent tracking, and resolution of instruction conflicts.
-
finchipaiorg Skill Draft Markup Counterparty Saas AgreementRedlined SaaS agreement and order form with commentary markup and a risk-prioritized commentary memo for a specialized life sciences data platform, evaluated against the company playbook and a security assessment.
-
finchipaiorg Skill Identify Issues In State Environmental Compliance OrderGuides preparation of a defense memorandum for a state environmental compliance order by assessing each alleged violation against facility permit records, audit findings, inspection documentation, and monitoring data.
-
finchipaiorg Skill Its Draft Restricted Party Screening ProceduresDrafts a restricted party screening procedures chapter for an export management and compliance program that addresses identified audit findings and remediation commitments, specifies the beneficial ownership collection mechanism, describes the screening-calibration trade-off between false positives and false negatives, identifies record-retention considerations using general legal authorities, and integrates military end-use screening requirements.
-
finchipaiorg Skill Draft Motion For Preliminary InjunctionA preliminary injunction memorandum in a trade secret and non-compete matter should analyze the governing preliminary-injunction factors, connect the requested relief to record evidence of alleged misappropriation and ongoing harm, and assess enforceability of any restrictive covenant under the applicable jurisdiction’s law.
-
finchipaiorg Skill Hls Extract Regulatory Compliance Obligations TelehealthProduces a structured regulatory obligations register and narrative memo for a digital health telehealth platform launch, covering data-use agreements, clinical decision support analysis, telehealth prescribing rules, biometric privacy laws, remote monitoring billing requirements, and open vendor audit findings.
-
finchipaiorg Skill Extract Compliance Findings From Internal Audit ReportAgents summarize audit findings while also assessing audit independence, limitations in transaction-monitoring testing, sanctions-disclosure considerations, customer classification risks, and the basis for any disagreement over management severity adjustments.
-
finchipaiorg Skill Draft Enterprise Saas Agreement Deal PointsDraft a master subscription agreement for an enterprise software-as-a-service customer from a deal points memo and internal playbook, with a required privacy/security exhibit and a cover memo identifying judgment calls and open issues.
-
finchipaiorg Skill Hls Extract Pharma Data Privacy ComplianceCompiles a regulatory obligation register for a pharmaceutical digital health platform launch covering healthcare privacy and security, consumer communications consent, anti-kickback and patient-assistance-program structure, substance-use-disorder confidentiality, multi-jurisdiction breach notification, professional licensure, and consumer health-data notification obligations.
-
finchipaiorg Skill Draft Opposition To Motion To DismissOpposing a motion to dismiss claims for restrictive covenant breach, trade secret misappropriation, and tortious interference requires demonstrating that each count's factual allegations satisfy the applicable pleading standard, integrating the factual allegations and any incorporated materials referenced in the complaint.
-
finchipaiorg Skill Draft Markup Of Data Processing AgreementDPA markups with commentary memos fail when the analysis does not distinguish mandatory legal requirements from policy-driven positions and commercial preferences, and when the commentary does not connect security-history concerns to the relevant privacy and security provisions.
-
finchipaiorg Skill Ecvc Draft Stockholder Written ConsentA stockholder written consent for a financing transaction should be drafted to address any authorized share shortfall, coordinate any charter amendment with the issuance of a new security class or series, evaluate equity incentive plan provisions that automatically increase the reserve and their interaction with any plan-imposed issuance cap, and condition issuance on the charter amendment becoming effective with the appropriate state filing office.
-
finchipaiorg Skill Ecvc Draft Markup Bridge LoanMark up a bridge loan agreement from the company's perspective by checking each provision against the agreed term sheet, aligning any security package with the agreed secured or unsecured structure, narrowing financial covenants to operationally workable concepts, reviewing change-of-control language for financing carve-outs, calibrating lender-consent mechanics, and addressing how any outstanding convertible instruments interact with the note conversion mechanics.
-
finchipaiorg Skill Hls Extract Reimbursement Terms PayorExtracts and catalogs reimbursement terms from a managed care payor contract and any related exhibits, focusing on methodologies, rate structures, escalation mechanics, discount provisions, audit and recoupment mechanics, value-based care terms, and termination-related payment obligations, benchmarked against general industry playbook conventions.
-
finchipaiorg Skill Hls Identify Stark Compliance Program IssuesReviews a Stark Law compliance program, physician arrangement documents, and internal audit materials to identify exception-citation deficiencies, in-office ancillary services same-building issues, holdover-arrangement issues, and compliance-officer reporting-independence gaps.
-
finchipaiorg Skill Draft Markup Counterparty MsaRedlined master services agreement with bracketed commentary and a cover memo summarizing key issues and negotiation strategy, evaluated against the applicable contracting playbook and available vendor security documentation.
-
finchipaiorg Skill Its Draft Markup Cfius NsaProduces a redline markup memorandum for a CFIUS national security agreement that narrows overbroad provisions, proposes sunset mechanisms for indefinite monitoring obligations, addresses foreign-investment nexus separation requirements, and harmonizes the agreement with overlapping industrial-security mitigation obligations.
-
finchipaiorg Skill Analyze Irs Idr For Completeness And Risk IssuesAn IDR analysis memorandum should address each request item, identify the legal and factual issues raised, estimate the associated tax and penalty exposure where possible, and recommend an audit strategy — not merely catalog what the IRS asked for.
-
finchipaiorg Skill Research Trade Secret Protections Departing EmployeeAnalyzing trade secret and restrictive covenant enforcement options following a departing employee scenario, using employment agreements, a forensic report, and exit documentation.
-
finchipaiorg Skill Map Eu AI Act Transparency Obligations To Existing Product DAgents produce a general EU AI Act overview by classifying the product under the relevant high-risk categories, identifying the applicable conformity assessment pathway, checking whether any existing risk assessment is adequate for AI-specific risk management, noting the EU database registration requirement, and addressing the practical tension between trade secret protection and mandatory transparency obligations.
-
finchipaiorg Skill Draft Motion Dismiss Dtsa 12b6Rule 12(b)(6) motion to dismiss a federal trade secret misappropriation complaint on federal and state trade secret law grounds, with an integrated memorandum of law.
-
finchipaiorg Skill Hls Analyze Counterparty Markup CtaReviews a site’s redline of a sponsor clinical trial agreement against a negotiation playbook to classify changes by risk level and recommend negotiating positions, with attention to intellectual property, indemnification, insurance, audit rights, publication, assignment, and program-wide precedent effects.
-
finchipaiorg Skill Compare Environmental Settlement Against PrecedentsComparative analysis memorandum assessing proposed consent decree settlement terms against precedent resolutions, evaluating structural and quantitative settlement differences, audit scope, officer certification provisions, and negotiation considerations for the board.
-
finchipaiorg Skill Its Extract National Security Factors CfiusProduces a CFIUS risk assessment memorandum for a foreign acquisition that identifies filing obligations, assesses the adequacy of proposed mitigation instruments, evaluates restricted-party and government-subsidy connections, and incorporates comparable foreign-regulatory precedent as a signal of likely review outcomes.
-
finchipaiorg Skill Its Compare Cfius Mitigation Vs NstProduces a structured gap analysis memo that maps each national-security-term requirement to the draft mitigation agreement, identifies deviations with side-by-side timing comparisons where relevant, distinguishes commercially motivated deviations from inadvertent gaps, and flags missing mandatory provisions when they appear in the source materials.
-
finchipaiorg Skill Hipaa Security Rule Baa Portfolio ImpactGap analysis of a business associate agreement portfolio against proposed privacy and security rule updates, identifying deficiencies in encryption, breach notification, patch management, and technical safeguard provisions in individual agreements and across the portfolio.
-
finchipaiorg Skill Compare Arbitration Clause Vs Institutional Rules ComplianceEnsures a clause-versus-rules compliance audit explains the practical consequences of a frozen rules reference, tests any waiver language against non-waivable challenges under the applicable curial law, and keeps the governing law analysis distinct from the seat analysis.
-
finchipaiorg Skill Extract Renewal Termination Dates Contract PortfolioBuilding a compliance tracker and summary memo from a contract portfolio audit, requiring deadline urgency flagging, auto-renewal risk identification, and prioritized recommendations.
-
mathieu0905 Bundle Article Logic EditorEdit, review, or rewrite articles, essays, papers, manuscripts, reports, proposals, and long-form prose with a global logic audit. Use when the user asks to improve coherence, argument flow, section order, paragraph transitions, concept introduction order, consistency across sections, claim-evidence alignment, method-limitation correspondence, or when prose sounds locally plausible but globally scattered or self-contradictory. Also use for Chinese requests about 改文章, 文章逻辑, 不连贯, 前后不一致, 概念突然出现, 顺序问题, or 方法和 limitation 不对应.
-
mathieu0905 Bundle Reference Authenticity AuditorAudit academic references and citations for authenticity, metadata accuracy, and claim support. Use when Codex is asked to verify whether references are real, detect fabricated or hallucinated citations, check BibTeX or bibliography entries, validate DOI/title/author/year/venue consistency, inspect citation contexts, confirm that cited papers support manuscript claims, or prepare a reference-integrity report for LaTeX, Markdown, Word, PDF, BibTeX, RIS, CSL JSON, or plain-text manuscripts.
-
persimmon-automation-labs Skill Quality Review Data LayerPrisma schema, query, and migration audit for Persimmon stack. Checks timestamps, indexes, enums, cascade rules, N+1, unbounded reads, transactions, migration hygiene, pgvector HNSW index, and connection pooling. Triggers on "data layer review", "schema audit", "prisma review", "database review", "pre-launch", "before shipping".
-
persimmon-automation-labs Skill Security Demo CredentialsDemo Credentials — Persimmon Patterns
-
persimmon-automation-labs Skill Quality Review Type SafetyTypeScript strict-mode audit for Persimmon stack. Checks tsconfig strictness, any leaks, non-null assertions, ts-ignore usage, missing return types, Zod validation at trust boundaries (Server Actions, API routes), and Prisma type usage. Triggers on "type safety review", "type audit", "strictness check", "pre-launch", "before shipping".
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include draft-requests-for-production, draft-saas-subscription-agreement, hls-draft-enterprise-saas-vendor-onboarding. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.