Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
usmanskillsmd Skill Implementing Iso 27001 Information Security ManagementISO/IEC 27001:2022 is the international standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). This skill covers the complete
-
usmanskillsmd Skill Analyzing Malware Family Relationships With MalpediaUse the Malpedia platform and API to research malware family relationships, track variant evolution, link families to threat actors, and integrate YARA rules for detection across malware lineages.
-
usmanskillsmd Skill Implementing Epss Score For Vulnerability PrioritizationIntegrate FIRST's Exploit Prediction Scoring System (EPSS) API to prioritize vulnerability remediation based on real-world exploitation probability within 30 days.
-
usmanskillsmd Skill Implementing Network Segmentation With Firewall ZonesDesign and implement network segmentation using firewall security zones, VLANs, ACLs, and microsegmentation policies to restrict lateral movement and enforce least-privilege network access.
-
usmanskillsmd Skill Implementing Web Application Logging With ModsecurityConfigure ModSecurity WAF with OWASP Core Rule Set (CRS) for web application logging, tune rules to reduce false positives, analyze audit logs for attack detection, and implement custom SecRules for a
-
usmanskillsmd Skill Implementing Github Advanced Security For Code ScanningConfigure GitHub Advanced Security with CodeQL to perform automated static analysis and vulnerability detection across repositories at enterprise scale.
-
vbrevik Skill Memstack Security Csp HeadersUse this skill when the user says 'CSP', 'Content-Security-Policy', 'security headers', 'HSTS', 'X-Frame-Options', 'clickjacking', 'unsafe-inline', 'unsafe-eval', or needs to audit, generate, or fix HTTP security headers for a web application. Do NOT use for API route audits or dependency scanning.
-
vbrevik Skill Memstack Security Owasp Top10Use this skill when the user says 'OWASP audit', 'OWASP top 10', 'security audit', 'vulnerability assessment', 'full security check', or needs a comprehensive web application security review against OWASP Top 10 categories. Do NOT use for dependency audits or secret scanning alone.
-
vbrevik Skill Memstack Security Rls CheckerUse this skill when the user says 'check RLS', 'audit RLS', 'RLS policies', 'row level security', 'Supabase security audit', or needs to verify table-level access control. Audits Supabase Row Level Security policies across all tables. Do NOT use for non-Supabase projects or writing RLS policies from scratch.
-
vbrevik Skill Memstack Security Rls Guardian🔒 Rls Guardian — MemStack™ Pro
-
juanmarchetto Bundle Oss ReadinessEvaluate if your project is ready for open source. 5 specialist agents audit in parallel — licensing, documentation, security, community readiness, API surface — then synthesize a unified readiness score with prioritized fixes. Use when: open source my project, ready for open source, prepare for public release, open source checklist, publish my code, should I open source this.
-
lsantosweb Skill Security AuditorUse for security review, auth and authorization design, OWASP-aligned audits, dependency risk review, threat modeling, and pre-deployment hardening.
-
vbrevik Skill Memstack Development API DesignerUse this skill when the user says 'design API', 'API endpoints', 'REST API', 'API designer', 'route structure', 'API architecture', or is designing RESTful API routes, request/response schemas, and endpoint organization. Do NOT use for API security audits or database design.
-
vbrevik Skill Memstack Security Secrets ScannerUse this skill when the user says 'scan for secrets', 'check for leaked keys', 'secrets scanner', 'hardcoded credentials', 'API key leak', or needs to detect exposed secrets in source code. Do NOT use for dependency vulnerabilities or RLS auditing.
-
vbrevik Skill Memstack Security Dependency AuditUse this skill when the user says 'dependency audit', 'npm audit', 'pip audit', 'cargo audit', 'security vulnerabilities', 'outdated packages', 'supply chain', or needs to scan project dependencies for vulnerabilities, abandoned packages, and upgrade risks. Do NOT use for application-level security or secrets scanning.
-
juanmarchetto Bundle Architecture ReviewerAudit code against architecture documentation. Detects drift between what was designed and what was built. Compares ARCHITECTURE.md, ADRs, and README technical sections against actual code structure, imports, and dependencies. Use when: architecture, drift, review architecture, code vs design, structural audit, architecture compliance, design doc.
-
vbrevik Bundle DastRun Dynamic Application Security Testing (DAST) using Nuclei against running web applications. Produces STIG V-ID-tagged findings from runtime behavior (security headers, TLS config, cookie flags, error disclosure, auth endpoints). Feeds into /stig-compliance as a dynamic evidence source alongside /static-analysis (SAST). Use when (1) a dev server is running and you want to verify runtime security posture, (2) /stig-compliance review needs dynamic evidence for controls that cannot be verified statically (headers, TLS, cookie attributes), (3) before deployment to check runtime security configuration. Requires a running target URL.
-
vbrevik Skill Webhook DesignerUse when the user says 'webhook', 'webhook handler', 'webhook endpoint', 'receive webhooks', 'webhook security', or needs to build a secure webhook receiver with validation and idempotency.
-
arturseo-geo Bundle WordpressPublish, manage, and optimize WordPress content via the WordPress REST API. Use this skill whenever the user wants to create or update WordPress posts, pages, or custom post types; manage categories, tags, or taxonomies; upload media or set featured images; work with Gutenberg blocks; configure WooCommerce products; query or bulk-edit content; or automate any WordPress workflow. Trigger for any mention of WordPress, WP, WooCommerce, Gutenberg, wp-json, wp-cli, plugins, themes, or publishing to a WordPress site. Also trigger when the user wants to migrate, audit, or batch-process WordPress content.
-
aggel008 Bundle Project KnowledgeHelps Codex build a clear knowledge base for any code project, so you do not need to re-explain the same repo over and over. Use it when you want short, durable docs about what the project does, how it is built, and how it runs. Good for new projects, inherited codebases, and messy repos with no clear documentation. Trigger on requests like: "опиши проект", "собери базу знаний проекта", "заполни документацию проекта", "create project docs", "audit project docs".
-
yipintangzsp Bundle AI Security AuditAI 安全审计服务 | 漏洞扫描 | 模型安全 | 数据隐私 | 合规审计神器
-
yipintangzsp Bundle Onchain Audit链上项目安全审计 - 项目风险评估
-
kurianoff Bundle Policy ReviewInteractive policy document review workflow with AI-assisted rewrites. Use this skill whenever the user uploads a policy document (markdown, docx, PDF, or text) and wants to review, approve, rewrite, or reject individual statements. Triggers on: "review this policy", "help me approve this document", "policy review", "review these statements", "go through this policy with me", or any request to systematically walk through a governance/compliance/HR/security policy and make approve/reject/rewrite decisions on each part. Also triggers when the user uploads a file that looks like a policy and asks to "edit", "refine", "clean up", or "improve" it statement by statement. Use this skill even if the user only wants to review part of a policy or a single section.
-
kurianoff Bundle Soc2 PoliciesSOC 2 policy management dashboard with persistent progress tracking across sessions. Use this skill whenever the user mentions SOC 2 policies, compliance templates, policy dashboard, or wants to manage a set of governance/compliance policy documents as a collection. Triggers on: "SOC 2 dashboard", "show my policies", "policy templates", "SOC 2 readiness", "compliance dashboard", "open the dashboard", "where did I leave off", "resume my policy review", "export my policies", "audit trail", or any request to view, manage, or track progress across multiple policy documents. Also triggers when the user uploads multiple policy files at once and wants to organize them. This skill chains with the policy-review skill — use this skill for the dashboard/collection layer and hand off to policy-review for individual document review.
-
davidjelinekk Bundle TaxComprehensive personal and SMB tax management suite for bookkeeping, tax preparation, tax optimization, and IRS audit risk assessment. Covers federal and Illinois state taxes, LLC/S-Corp entity structures, pass-through entity taxation, estimated payments, and multi-entity coordination. Triggers on: tax, taxes, bookkeeping, tax prep, tax preparation, tax planning, tax optimization, deductions, IRS, audit risk, estimated taxes, quarterly taxes, Schedule C, 1099, W-2, K-1, LLC tax, S-Corp, QBI, SALT, depreciation, Section 179, home office deduction, mileage deduction, child tax credit, 529 plan, tax return, tax filing, IL tax, Illinois tax.
-
davidjelinekk Bundle Tax Audit RiskIRS audit risk assessment skill that scores tax returns for audit probability, identifies specific red flags with quantified thresholds, calculates penalty exposure, and recommends documentation improvements. Covers 30+ audit triggers including Schedule C deduction ratios, charitable donation percentages, home office claims, vehicle use, S-Corp reasonable compensation, hobby loss rules, related party transactions, crypto reporting, and Illinois-specific triggers. Uses weighted risk scoring (1-100 scale) with letter grades. Triggers on: audit risk, IRS audit, audit probability, red flags, audit triggers, DIF score, penalty, penalties, audit defense, documentation, statute of limitations, hobby loss, reasonable compensation, audit exposure, tax risk, compliance risk, IL audit.
-
yipintangzsp Bundle Whale Wallet巨鲸钱包追踪 Skill
-
yipintangzsp Bundle Airdrop Claim空投自动领取 Skill
-
yipintangzsp Bundle Lp Lock CheckLP 锁定检测 Skill
-
yipintangzsp Bundle Whale Tracker 2Whale 追踪 Skill
-
yipintangzsp Bundle Contract Audit合约安全审计 Skill
-
yipintangzsp Bundle Shitcoin Alert土狗币预警 Skill
-
yipintangzsp Bundle Honeypot Detect貔貅币检测 Skill
-
yipintangzsp Bundle Airdrop Detector空投检测 Skill
-
yipintangzsp Bundle Transfer Monitor链上转账监控 Skill
-
yipintangzsp Bundle New Token Scanner新币扫描器 Skill
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include implementing-iso-27001-information-security-management, analyzing-malware-family-relationships-with-malpedia, implementing-epss-score-for-vulnerability-prioritization. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.