Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
santosomar Bundle Attack Ics T0866 Exploitation Of Remote ServicesAnalyze MITRE ATT&CK T0866 Exploitation of Remote Services in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0866, Exploitation of Remote Services, or ics ATT&CK. Adversaries may exploit a software vulnerability to take advantage of a programming error in a program, service, or within the operating system software or kernel itself to enable remote service abuse.
-
santosomar Bundle Attack Mob T1664 Exploitation For Initial AccessAnalyze MITRE ATT&CK T1664 Exploitation for Initial Access in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1664, Exploitation for Initial Access, or mobile ATT&CK. Adversaries may exploit software vulnerabilities to gain initial access to a mobile device.
-
santosomar Bundle Attack Ent T1003 002 Security Account ManagerAnalyze MITRE ATT&CK T1003.002 Security Account Manager in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1003.002, Security Account Manager, or enterprise ATT&CK. Adversaries may attempt to extract credential material from the Security Account Manager (SAM) database either through in-memory techniques or through the Windows Registry where the SAM database is stored.
-
santosomar Bundle Attack Mob T1658 Exploitation For Client ExecutionAnalyze MITRE ATT&CK T1658 Exploitation for Client Execution in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1658, Exploitation for Client Execution, or mobile ATT&CK. Adversaries may exploit software vulnerabilities in client applications to execute code.
-
santosomar Bundle Attack Ent T1036 003 Rename Legitimate UtilitiesAnalyze MITRE ATT&CK T1036.003 Rename Legitimate Utilities in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1036.003, Rename Legitimate Utilities, or enterprise ATT&CK. Adversaries may rename legitimate / system utilities to try to evade security mechanisms concerning the usage of those utilities.
-
santosomar Bundle Attack Ent T1210 Exploitation Of Remote ServicesAnalyze MITRE ATT&CK T1210 Exploitation of Remote Services in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1210, Exploitation of Remote Services, or enterprise ATT&CK. Adversaries may exploit remote services to gain unauthorized access to internal systems once inside of a network.
-
santosomar Bundle Attack Ent T1190 Exploit Public Facing ApplicationAnalyze MITRE ATT&CK T1190 Exploit Public-Facing Application in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1190, Exploit Public-Facing Application, or enterprise ATT&CK. Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
-
santosomar Bundle Attack Ent T1203 Exploitation For Client ExecutionAnalyze MITRE ATT&CK T1203 Exploitation for Client Execution in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1203, Exploitation for Client Execution, or enterprise ATT&CK. Adversaries may exploit software vulnerabilities in client applications to execute code.
-
lc198707 Bundle Anti LieUse when audited OpenClaw conversations or outgoing Feishu/Slack/channel messages contain concrete business numbers such as revenue, percentages, stock prices, contract values, costs, market share, or funding and need evidence checks plus red/yellow/green audit stamps after sends.
-
santosomar Bundle Attack Ent T1212 Exploitation For Credential AccessAnalyze MITRE ATT&CK T1212 Exploitation for Credential Access in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1212, Exploitation for Credential Access, or enterprise ATT&CK. Adversaries may exploit software vulnerabilities in an attempt to collect credentials.
-
santosomar Bundle Attack Mob T1404 Exploitation For Privilege EscalatioAnalyze MITRE ATT&CK T1404 Exploitation for Privilege Escalation in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1404, Exploitation for Privilege Escalation, or mobile ATT&CK. Adversaries may exploit software vulnerabilities in order to elevate privileges.
-
santosomar Bundle Attack Ent T1068 Exploitation For Privilege EscalatioAnalyze MITRE ATT&CK T1068 Exploitation for Privilege Escalation in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1068, Exploitation for Privilege Escalation, or enterprise ATT&CK. Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
-
artemgurzhii Skill Ember 2 RecommendationsPractical advice for teams that must stay on Ember 2.x for now — pinning, security hygiene, what to backport, what to leave alone, when to declare upgrade-impossible-without-rewrite. Use when triaging a frozen 2.x codebase, when justifying upgrade budget, or when scoping the smallest viable maintenance footprint.
-
testonohm Skill Security And HardeningHardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services.
-
anylegal-ai Skill QAQuality assurance review — 6-dimension checklist covering template compliance, factual accuracy, completeness, track changes, research audit, and instruction cross-reference.
-
chen3feng Skill Python Code Audit SweepRun a quick non-behavioral audit of a Python repo and split findings into bug / dead-code / style PRs.
-
thewinterdojer Bundle Code ReviewAudit recent code changes or the current repository for correctness, regression risk, conflicting logic, unnecessary code, and pragmatic hardening opportunities. Use when the user asks to review or audit recent changes, inspect a refactor, review a fresh repo, or assess the current codebase for bugs, cleanup, and low-risk improvements without over-engineering.
-
evaluris-solutions Bundle Hedera Smart Contract AuditSecurity audit playbook for Hedera EVM contracts — Slither and Mythril wiring, HIP-1195 hook/allowance abuse checks, HTS precompile reentrancy review, manual checklist distinct from vanilla Ethereum, structured findings report with CVSS scoring guidance for DLT quirks. Use when user mentions audit Hedera contract, Slither Hedera, Mythril, HIP-1195, HTS reentrancy, bug bounty prep Hedera.
-
evaluris-solutions Bundle Hedera Asset Tokenization StudioOperate Hedera Asset Tokenization Studio (ATS) — installation, hybrid ERC-3643 + ERC-1400-style security token flows, investor onboarding with identity registry concepts, transfer restrictions, corporate actions, integrating ATS with external compliance systems. Use when user mentions ATS Hedera, Asset Tokenization Studio, ERC-1400 Hedera, corporate actions tokenized equity, investor onboarding ATS.
-
wyverncw Bundle Omni Code ExpertThe ultimate universal programming assistant. Activates for ALL code-related tasks across every programming language, markup language, query language, hardware description language, build system, config format, DSL, and esoteric language known to computing. Covers 100+ languages across 19 categories: general-purpose, systems/low-level, web, markup, query/database, functional, scripting/automation, scientific/data, mobile, game dev, embedded/firmware, hardware description, logic/declarative, legacy, esoteric, DSLs, build/config, AI/symbolic, and modern niche languages. Provides language-specific best practices, security vulnerability detection and remediation, architecture guidance, performance optimization, debugging, build configuration, testing, and deployment across all platforms.
-
marcelorusso Skill Second BrainUse a local Markdown second-brain repository for persistent, auditable memory. Use when Codex needs prior context, user preferences, project history, decisions, research notes, references, meeting/session summaries, task briefs, governance state, bootstrap status, encryption/sync status, or durable knowledge outside the current conversation; also use when asked to add, update, search, organize, audit, bootstrap, synchronize, encrypt, decrypt, capture, synthesize, or summarize second-brain memory from a repository derived from second-brain-template.
-
limin112 Bundle Goal长期目标续推 skill,支持多 thread 并行。设置一个跨多轮对话的目标(写代码、写文章、做迁移、跑实验等任何任务),自动续推直到完成或被 ESC 中断。当用户输入 /goal、或描述一个需要持续多轮才能完成的目标("把所有 X 改成 Y"、"重构 Z 直到测试全过"、"批量生成 N 篇文章直到达标"、"持续优化直到 ...")时使用。基于 OpenAI Codex CLI 的 /goal 机制移植,核心是 completion audit 防过早完成 + 用 /loop 自动续推 + thread 隔离。
-
evaluris-solutions Bundle Hcs ConsensusUse Hedera Consensus Service — create/update/delete topics, submit messages with optional submit keys, subscribe via TopicMessageQuery, REST pagination for topic messages, chunk oversized payloads past transaction limits, ordered timestamps for audit trails. Use when user mentions HCS, consensus topic, submit message, mirror subscribe topic, ordered log, event sourcing, audit log chain, supply chain provenance, chunked messages.
-
evaluris-solutions Bundle Hts Evm HybridCall Hedera Token Service from Solidity via HTS system contract at 0x167 — associate, mint, transfer HTS tokens inside contracts, differences vs ERC-20 facade on HTS tokens, reentrancy considerations for precompile calls, 2023 HTS allowance exploit lessons. Use when user mentions HTS precompile, IHederaTokenService, associateToken Solidity, HTS from contract, reentrancy Hedera precompile, Uniswap-style hooks on Hedera.
-
evaluris-solutions Bundle Hts Compliance TokenDesign compliance-grade fungible tokens on HTS for regulated securities and RWA — KYC workflows, freeze/unfreeze for regulatory holds, wipe after freeze for court-ordered scenarios, pause for emergencies, admin key rotation, mapping HTS roles to ERC-3643 modules (registry, compliance). Use when user mentions security token, RWA, investor accreditation, transfer restrictions, regulator freeze, ERC-3643, T-REX, compliance officer, or corporate treasury policy on Hedera.
-
gomining-ai Bundle Gomining AcademyGoMining Academy educational platform — courses, articles, and certifications. Covers GoMining Basics Course (10 lessons on ecosystem, miners, tokenomics, veGOMINING, card), Bitcoin and Mining Course (7 lessons on Bitcoin fundamentals, mining mechanics, security), 79+ articles on crypto basics, DeFi, product guides (Simple Earn, Miner Wars, Platinum+), and completion certificates.
-
sabakan0123 Skill Security Scanステージング環境にデプロイ済みのサーバーに対してランタイム検証を実行する。HTTPヘッダー・動的プローブ・認証テストに特化。手動呼び出し専用: /security-scan [環境名]
-
sabakan0123 Skill Security ReviewPR・ブランチの変更差分(git diff)を静的解析してセキュリティ脆弱性を検出する。開発中・PRレビュー時に使用。手動呼び出し専用: /security-review
-
4n9le-bot Skill Lune Paper SearchUse when the user asks to find, locate, or look up academic papers — especially research from top-tier conferences (NeurIPS, ICML, ICLR, CCS, USENIX Security, etc.). Prefer Lune's `search_papers` tool over general web search; it returns hybrid-ranked (vector + BM25 + Cohere rerank) results with abstracts, AI TL;DRs, citation counts, and CDN PDF URLs.
-
hungrytech Bundle Plugin IntrospectorWhite-box monitoring and self-improvement meta-plugin for Claude Code workflow plugins. Monitors tool usage, token consumption, API calls, and execution patterns. Analyzes collected data to generate data-driven improvement proposals. Activated by keywords: "introspector", "monitor", "analyze plugin", "token usage", "dashboard", "evaluate", "optimize", "improve plugin", "security", "compliance".
-
suhel-nz Bundle Refresh AI Sdk SkillsAudit this repo's skills against current official AI SDK, AI Elements, and shadcn/ui docs, then recommend or apply updates needed to keep the skills current. Use when the user asks to check for SDK drift, refresh the skill repo, review upstream changes, or update skills after AI SDK or AI Elements releases.
-
atharva-188 Skill Deep Code ReviewProduction-grade code review skill. Use when reviewing pull requests, auditing code quality, checking for security vulnerabilities, evaluating architecture decisions, or preparing code for production. Covers security, performance, maintainability, and correctness.
-
ucsc-vlaa Skill GuardianclawSecurity review layer for OpenClaw. Provides a pre-action checklist for evaluating consequential operations such as outbound communications, financial transactions, file transfers, and permanent data modifications. Load at session start to activate.
-
lumoswyy Skill FletcherDefamiliarization audit for empirical output. Systematically interrogates every feature of a figure, table, or set of results — not just the main finding. Named for Jason Fletcher, who asked about the spike at t=1 when everyone else was looking at t=2. Use when you have output and are about to interpret or report it.
-
lumoswyy Skill Referee2Systematic audit and review by Referee 2. Two modes — "deck" reviews slide presentations for rhetoric, visual quality, and compile cleanliness; "code" performs cross-language replication and econometric audit of empirical pipelines. Use when reviewing slides, auditing code, or verifying replication.
-
lumoswyy Bundle Consistency CheckerComprehensive Academic Manuscript Consistency Audit
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include attack-ics-t0866-exploitation-of-remote-services, attack-mob-t1664-exploitation-for-initial-access, attack-ent-t1003-002-security-account-manager. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.