Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
mayurrathi Skill Cc Skill Security ReviewUse this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist a...
-
mayurrathi Skill Nodejs Best PracticesNode.js development principles and decision-making. Framework selection, async patterns, security, and architecture. Teaches thinking, not copying.
-
mayurrathi Skill Production Code AuditAutonomously deep-scan entire codebase line-by-line, understand architecture and patterns, then systematically transform it to production-grade, corporate-level professional quality with optimizations
-
mayurrathi Skill Stride Analysis PatternsApply STRIDE methodology to systematically identify threats. Use when analyzing system security, conducting threat modeling sessions, or creating security documentation.
-
mayurrathi Skill Security Pentesting BundleBundle of 90+ granular skills for Active Directory, Kerberos, Reverse Engineering, and Vulnerability analysis.
-
mayurrathi Skill API Security Best PracticesImplement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilities
-
mayurrathi Skill Dependency Management Deps AuditYou are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues,...
-
mayurrathi Skill Codebase Cleanup Deps AuditYou are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues,...
-
mayurrathi Skill Ethical Hacking MethodologyThis skill should be used when the user asks to "learn ethical hacking", "understand penetration testing lifecycle", "perform reconnaissance", "conduct security scanning", "exploit ...
-
mayurrathi Skill Security Compliance Compliance CheckYou are a compliance expert specializing in regulatory requirements for software systems including GDPR, HIPAA, SOC2, PCI-DSS, and other industry standards. Perform compliance audits and provide im...
-
mayurrathi Skill Security Scanning Security HardeningCoordinate multi-layer security scanning and hardening across application, infrastructure, and compliance controls.
-
mayurrathi Skill Threat Mitigation MappingMap identified threats to appropriate security controls and mitigations. Use when prioritizing security investments, creating remediation plans, or validating control effectiveness.
-
mayurrathi Skill Privilege Escalation MethodsThis skill should be used when the user asks to "escalate privileges", "get root access", "become administrator", "privesc techniques", "abuse sudo", "exploit SUID binaries", "K...
-
mayurrathi Skill Windows Privilege EscalationThis skill should be used when the user asks to "escalate privileges on Windows," "find Windows privesc vectors," "enumerate Windows for privilege escalation," "exploit Windows miscon...
-
mayurrathi Skill Wordpress Plugin DevelopmentWordPress plugin development workflow covering plugin architecture, hooks, admin interfaces, REST API, and security best practices.
-
mayurrathi Skill Security Scanning Security DependenciesYou are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security. Scan project dependencies across ecosystems to identify vulnerabilities, ass...
-
mayurrathi Skill Linux Privilege EscalationThis skill should be used when the user asks to "escalate privileges on Linux", "find privesc vectors on Linux systems", "exploit sudo misconfigurations", "abuse SUID binaries", "ex...
-
mayurrathi Skill Wordpress Penetration TestingThis skill should be used when the user asks to "pentest WordPress sites", "scan WordPress for vulnerabilities", "enumerate WordPress users, themes, or plugins", "exploit WordPress vu...
-
lhan-chding Bundle Research First Secure CodingResearch-first engineering workflow for non-trivial coding tasks that should be grounded in verified papers, official documentation, high-quality repositories, design discussions, or reproducible technical evidence before implementation. Use when Codex needs to design, implement, refactor, reproduce, extend, or review a substantial system; study related methods before coding; adapt architecture from similar projects; generate modular maintainable code with tests and run instructions; or handle tasks touching auth, secrets, external APIs, shell commands, databases, dependencies, file writes, or deployment. Do not use for trivial syntax fixes, tiny snippets, or toy examples that do not need research, architecture planning, or security review.
-
mayurrathi Skill Security Requirement ExtractionDerive security requirements from threat models and business context. Use when translating threats into actionable requirements, creating security user stories, or building security test cases.
-
mayurrathi Skill Security Scanning Security SastStatic Application Security Testing (SAST) for code vulnerability analysis across multiple languages and frameworks
-
claudiawong522 Skill Post Refactor Auditpost-refactor-audit
-
barispe Skill Security Test AdvisorBrings basic security-focused test ideas into QA planning and implementation, covering common web and API risks. Use when you want pragmatic security checks without a full security review.
-
gurulost Bundle Intense Job ChecklistRun a living checklist workflow for large, intense engineering tasks from kickoff through production sign-off. Use this skill whenever work spans multiple subsystems, requires repeated validation, or needs continuous tracking of findings, fixes, and sign-off readiness. This includes audits, multi-file refactors, migrations, major rollouts, production hardening, balance tuning, comprehensive test passes, codebase-wide cleanups, and any task where "done" requires proving that nothing was missed. Also use when the user says things like "do a thorough job", "make sure everything works", "audit this", "harden this", or "production-ready." Do not use for single-file quick fixes, informational Q&A, or narrow edits where checklist overhead adds no value.
-
biancalana Skill Dependency AuditAnalyzes project dependencies for staleness, known vulnerabilities, license compatibility, and unused packages. Produces an actionable audit report with prioritized update recommendations. No external services required — uses local tooling and registry APIs.
-
cleverlab-ai Bundle Iso 17025Expert consultant for ISO/IEC 17025:2017 — the international standard for testing and calibration laboratory competence. Use when: (1) preparing for accreditation or surveillance audits, (2) building or reviewing quality management systems for laboratories, (3) writing procedures, policies or work instructions aligned with 17025, (4) generating audit checklists or gap analyses, (5) answering questions about laboratory requirements (impartiality, confidentiality, structure, resources, processes, management), (6) designing LIMS systems or laboratory software that must comply with 17025, (7) evaluating method validation, measurement uncertainty, metrological traceability, (8) handling nonconforming work, complaints, corrective actions, (9) preparing management reviews or internal audits. Supports both Polish (PL) and English (EN) languages.
-
cleverlab-ai Bundle Iso 17025 DeFachberater für DIN EN ISO/IEC 17025:2018 — die internationale Norm für die Kompetenz von Prüf- und Kalibrierlaboratorien. Verwenden Sie diesen Skill wenn: (1) Vorbereitung auf Akkreditierungs- oder Überwachungsaudits der DAkkS, (2) Aufbau oder Überprüfung von Qualitätsmanagementsystemen für Laboratorien, (3) Erstellung von Verfahren, Richtlinien oder Arbeitsanweisungen gemäß 17025, (4) Erstellung von Audit-Checklisten oder Gap-Analysen, (5) Beantwortung von Fragen zu Laboranforderungen (Unparteilichkeit, Vertraulichkeit, Struktur, Ressourcen, Prozesse, Management), (6) Entwurf von LIMS-Systemen oder Laborsoftware, die 17025-konform sein muss, (7) Bewertung von Methodenvalidierung, Messunsicherheit, metrologischer Rückverfolgbarkeit, (8) Umgang mit fehlerhafter Arbeit, Beschwerden, Korrekturmaßnahmen, (9) Vorbereitung von Managementbewertungen oder internen Audits. Deutsche Version (DE).
-
grishaangelovgh Bundle Code ReviewerExpert code reviewer specializing in code quality, security, performance, and maintainability across multiple programming languages. Use this skill when the user wants a PR review, code analysis, or suggestions for improvement. This skill includes proprietary checklists and a mandatory review template located in its references and assets directories that MUST be used for every analysis.
-
j9o Bundle Cfo ExpertTurn Claude into a seasoned CFO and accounting expert fluent in US GAAP, financial modeling, tax strategy, and corporate finance. Use this skill whenever the user asks about financial statements, accounting entries, bookkeeping, revenue recognition, budgeting, forecasting, cash flow analysis, financial ratios, tax planning, audit preparation, P&L review, balance sheet analysis, cost accounting, variance analysis, capital structure, valuations, DCF models, working capital, accounts receivable/payable, depreciation, amortization, equity compensation, debt covenants, board reporting, investor relations, or any finance/accounting question. Trigger even for casual phrasing like "does this P&L look right", "how do I book this", "what's our burn rate", "help me with my budget", or "tax implications of X". If in doubt about whether this skill applies, it probably does — finance touches everything.
-
fcistud Skill Security Review OpsSecurity triage and remediation prioritization workflows.
-
iimp0ster Skill Researching Threat ContextResearching Threat Context
-
iimp0ster Skill Defining Detection ObjectiveTranslates threat research into an actionable detection goal with clear scope boundaries. Defines detection hypothesis, noise tolerance targets, success criteria, and benign behavior exclusions. Use after threat research is complete to establish what the detection will alert on and what it will exclude before designing logic.
-
iimp0ster Skill Ingesting Threat IntelligenceIngesting Threat Intelligence
-
iimp0ster Skill Assembling Detection BlueprintAssembles all prior detection engineering outputs into a single deployment-ready detection blueprint document. Combines threat context, detection logic, data requirements, validation procedures, response guidance, and metadata into a structured markdown package. Use as the final step after skills 1-5 are complete to produce a shareable detection artifact.
-
fcistud Skill Dependency Risk AuditAudit dependencies for security, maintenance risk, and upgrade strategy.
-
anthroos Bundle Code ReviewAI code review for PR or local changes. 280+ checks across security, architecture, performance, testing, and code quality. Posts findings as GitHub PR comments with confidence scores.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include Cc Skill Security Review, Nodejs Best Practices, Production Code Audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.