Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
denniswei9898 Bundle Skill ValidatorValidate and review a Claude Code skill against two quality frameworks. Trigger on "check skill", "validate skill", "review skill", "skill quality", "skill check", "audit skill", "skill 檢查", "檢核skill", "審查skill", "幫我看這個skill", "skill好不好", "上傳前審查", "pre-upload check", "create skill", "update skill", "新增skill", "修改skill". Accepts a SKILL.md path, folder path, or pasted content.
-
martin-pv Bundle Claude MdGenerate or update a project's CLAUDE.md file using structured interrogation of the codebase and user. Follows Apple's leaked CLAUDE.md patterns and Anthropic's best practices. Use when user wants to create, update, improve, audit, or rewrite their CLAUDE.md file, or when starting a new project that needs AI context.
-
martin-pv Bundle Code Review SpecialistComprehensive code review with security, performance, and quality analysis
-
ayushxx7 Bundle Project ShowcaseAutomate the creation of high-quality project showcases: UI captures, security scans, repo health audits, README injection, GitHub releases, and social media launches.
-
funkeomolere Bundle TisaxUse this skill when the user is preparing for, scoping, or assessing against TISAX (Trusted Information Security Assessment Exchange) for the automotive supply chain. Covers VDA ISA 6.0.3 (mandatory from 1 April 2024), all three assessment levels (AL1, AL2, AL3) with their verification approaches, all 10 assessment objectives and TISAX labels (Confidential, Strictly Confidential, Availability, Prototype, Special Data, Software, Connected, Trusted), prototype protection for suppliers handling pre-series vehicles or unreleased designs, the maturity level scale (level 3 minimum to pass), ENX portal registration, gap assessments, audit evidence checklists, and cross-framework mapping to ISO 27001:2022, NIST CSF 2.0, NIS2, and BSI IT-Grundschutz. Built for automotive suppliers, OEM service providers, and GRC consultants navigating the ENX TISAX process.
-
funkeomolere Bundle Spain EnsUse this skill when the user is preparing for, scoping, or assessing against Spain's Esquema Nacional de Seguridad (ENS) under Royal Decree 311/2022. Covers all three security categories (Basic, Medium, High), all 73 security measures across organisational, operational, and protective control families, ENS certification process by ENAC-accredited bodies, the May 2025 mandatory certification deadline for Medium and High systems, CCN-STIC guidance, gap assessments with measure citations, and cross-framework mapping to ISO 27001:2022, NIST CSF 2.0, NIS2, and GDPR. Built for Spanish public administrations, technology providers to the Spanish public sector, and GRC consultants.
-
funkeomolere Bundle Cyber Essentials PlusUse this skill when the user is preparing for, scoping, or assessing against UK Cyber Essentials or Cyber Essentials Plus certification. Covers all 5 technical controls under the Danzell (v3.3) scheme effective 27 April 2026, IASME assessor workflows, audit readiness, gap assessments, evidence checklists, and cross-framework mapping to ISO 27001:2022, NIST CSF 2.0, DORA, and the EU AI Act.
-
daniel-dona Skill Ontology Full AuditProvides instructions to orchestrate a complete ontology evaluation across 7 dimensions (syntax, text, translations, SKOS, OWL design, data quality, logic). Use before any ontology release to produce a comprehensive audit report with prioritized recommendations.
-
daniel-dona Bundle Ontology Skos AuditProvides a script and instructions to audit SKOS concept schemes for structural integrity — inScheme references, prefLabels, duplicates, notations, and hierarchy links. Use when validating SKOS thesauri, taxonomies, or concept schemes before release.
-
daniel-dona Bundle Ontology Typo AuditOntology Typo Audit
-
woosook0127 Skill Audit ReviewUse when work needs final independent audit for policy compliance, provenance, baseline preservation, artifact completeness, result credibility, merge/promotion readiness, or caveated AUDIT_PASS/AUDIT_FAIL decision.
-
woosook0127 Skill Artifact AuditUse for read-only audit of research notes, paper cards, plans, reports, drafts, and workflow artifacts for factual support, structure, cross-reference integrity, coverage gaps, and readiness before handoff.
-
woosook0127 Bundle Company WorkflowUse when Codex must operate the user's company-style durable workflow without OMX: supervisor routing, research/develop/debug/audit team state, file-based handoffs, task documents, quality gates, baseline preservation, scientific closure, and Codex-native skill orchestration.
-
mart337i Bundle OdooOdoo engineering workflows for addon development, codebase exploration, debugging, architecture/refactor review, manifest/docs sync, and routing to migration work. Use when the user mentions Odoo, addons, modules, manifests, models, XML views, security CSVs, record rules, Odoo shell, OWL/QWeb/assets, or when an Odoo codebase is detected.
-
hmzainjamil Skill Modernization AuditModernization Audit — Legacy System Analysis
-
hmzainjamil Skill Reportlab PDF MasterReportLab PDF Master — Branded Audit PDF Generator
-
rycen7822 Skill Github Code ReviewReview existing GitHub pull requests, patches, or git diffs for correctness, security, maintainability, and test coverage findings.
-
santosomar Bundle Attack Mob T1655 MasqueradingAnalyze MITRE ATT&CK T1655 Masquerading in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1655, Masquerading, or mobile ATT&CK. Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools.
-
santosomar Bundle Attack Ent T1036 MasqueradingAnalyze MITRE ATT&CK T1036 Masquerading in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1036, Masquerading, or enterprise ATT&CK. Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools.
-
santosomar Bundle Attack Ent T1003 004 Lsa SecretsAnalyze MITRE ATT&CK T1003.004 LSA Secrets in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1003.004, LSA Secrets, or enterprise ATT&CK. Adversaries with SYSTEM access to a host may attempt to access Local Security Authority (LSA) secrets, which can contain a variety of different credential materials, such as credentials for service accounts.(Citation: P…
-
santosomar Bundle Attack Ent T1496 003 Sms PumpingAnalyze MITRE ATT&CK T1496.003 SMS Pumping in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1496.003, SMS Pumping, or enterprise ATT&CK. Adversaries may leverage messaging services for SMS pumping, which may impact system and/or hosted service availability.(Citation: Twilio SMS Pumping) SMS pumping is a type of telecommunications fraud whereby a threat a…
-
santosomar Bundle Attack Ent T1689 Downgrade AttackAnalyze MITRE ATT&CK T1689 Downgrade Attack in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1689, Downgrade Attack, or enterprise ATT&CK. Adversaries may downgrade or use a version of system features that may be outdated, vulnerable, and/or does not support updated security controls.
-
santosomar Bundle Attack Ent T1003 001 Lsass MemoryAnalyze MITRE ATT&CK T1003.001 LSASS Memory in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1003.001, LSASS Memory, or enterprise ATT&CK. Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
santosomar Bundle Attack Ent T1668 Exclusive ControlAnalyze MITRE ATT&CK T1668 Exclusive Control in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1668, Exclusive Control, or enterprise ATT&CK. Adversaries who successfully compromise a system may attempt to maintain persistence by “closing the door” behind them – in other words, by preventing other threat actors from initially accessing or maintaining a footho…
-
santosomar Bundle Attack Ics T0820 Exploitation For EvasionAnalyze MITRE ATT&CK T0820 Exploitation for Evasion in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0820, Exploitation for Evasion, or ics ATT&CK. Adversaries may exploit a software vulnerability to take advantage of a programming error in a program, service, or within the operating system software or kernel itself to evade detection.
-
santosomar Bundle Attack Mob T1632 Subvert Trust ControlsAnalyze MITRE ATT&CK T1632 Subvert Trust Controls in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1632, Subvert Trust Controls, or mobile ATT&CK. Adversaries may undermine security controls that will either warn users of untrusted activity or prevent execution of untrusted applications.
-
santosomar Bundle Attack Ent T1564 009 Resource ForkingAnalyze MITRE ATT&CK T1564.009 Resource Forking in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1564.009, Resource Forking, or enterprise ATT&CK. Adversaries may abuse resource forks to hide malicious code or executables to evade detection and bypass security applications.
-
santosomar Bundle Attack Ent T1553 Subvert Trust ControlsAnalyze MITRE ATT&CK T1553 Subvert Trust Controls in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1553, Subvert Trust Controls, or enterprise ATT&CK. Adversaries may undermine security controls that will either warn users of untrusted activity or prevent execution of untrusted programs.
-
santosomar Bundle Attack Ent T1564 005 Hidden File SystemAnalyze MITRE ATT&CK T1564.005 Hidden File System in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1564.005, Hidden File System, or enterprise ATT&CK. Adversaries may use a hidden file system to conceal malicious activity from users and security tools.
-
santosomar Bundle Attack Mob T1430 002 Impersonate Ss7 NodesAnalyze MITRE ATT&CK T1430.002 Impersonate SS7 Nodes in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1430.002, Impersonate SS7 Nodes, or mobile ATT&CK. Adversaries may exploit the lack of authentication in signaling system network nodes to track the location of mobile devices by impersonating a node.(Citation: Engel-SS7)(Citation: Engel-SS7-2008)(Citation: 3GPP-Securit…
-
santosomar Bundle Attack Ent T1685 Disable Or Modify ToolsAnalyze MITRE ATT&CK T1685 Disable or Modify Tools in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1685, Disable or Modify Tools, or enterprise ATT&CK. Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair…
-
santosomar Bundle Attack Mob T1629 003 Disable Or Modify ToolsAnalyze MITRE ATT&CK T1629.003 Disable or Modify Tools in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1629.003, Disable or Modify Tools, or mobile ATT&CK. Adversaries may disable security tools to avoid potential detection of their tools and activities.
-
santosomar Bundle Attack Ent T1211 Exploitation For StealthAnalyze MITRE ATT&CK T1211 Exploitation for Stealth in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1211, Exploitation for Stealth, or enterprise ATT&CK. Adversaries may exploit vulnerabilities to evade detection by hiding activity, suppressing logging, or operating within trusted or unmonitored components.
-
santosomar Bundle Attack Ent T1134 Access Token ManipulationAnalyze MITRE ATT&CK T1134 Access Token Manipulation in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1134, Access Token Manipulation, or enterprise ATT&CK. Adversaries may modify access tokens to operate under a different user or system security context to perform actions and bypass access controls.
-
santosomar Bundle Attack Ent T1185 Browser Session HijackingAnalyze MITRE ATT&CK T1185 Browser Session Hijacking in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1185, Browser Session Hijacking, or enterprise ATT&CK. Adversaries may take advantage of security vulnerabilities and inherent functionality in browser software to change content, modify user-behaviors, and intercept information as part of various browser session hijacking…
-
santosomar Bundle Attack Ent T1597 001 Threat Intel VendorsAnalyze MITRE ATT&CK T1597.001 Threat Intel Vendors in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1597.001, Threat Intel Vendors, or enterprise ATT&CK. Adversaries may search private data from threat intelligence vendors for information that can be used during targeting.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include skill-validator, claude-md, Code Review Specialist. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.