Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
intent-solutions-io Bundle Implementing Database Audit Logging 2This skill helps implement database audit logging for tracking changes and ensuring compliance. It is triggered when the user requests to "implement database audit logging", "add audit trails", "track database changes", or mentions "audit_log" in relation to a database. The skill provides options for trigger-based auditing, application-level logging, Change Data Capture (CDC), and parsing database logs. It generates a basic audit table schema and guides the user through selecting the appropriate auditing strategy.
-
oimiragieo Skill Dependency Analyzer 2Analyzes project dependencies, detects outdated packages, identifies breaking changes, and suggests safe update strategies. Helps maintain dependency health and security.
0 -
oimiragieo Bundle Telegram Polling 2Poll Telegram Bot API for new messages and route commands to agents. Implements 10-command bot with fail-closed allowlist, owner-only tier, two-step approve, audit logging, and replay-prevention offset tracking.
0 -
intent-solutions-io Bundle Generating Security Audit Reports 2This skill enables Claude to generate comprehensive security audit reports. It is designed to provide insights into an application or system's security posture, compliance status, and recommended remediation steps. Use this skill when the user requests a "security audit report", wants to "audit security", or needs a "vulnerability assessment report". The skill analyzes security data and produces a detailed report in various formats. It is best used to identify vulnerabilities, track compliance, and create remediation roadmaps. The skill can be activated via the command `/audit-report` or its shortcut `/auditreport`.
-
wufufu770 Skill Hunt Xss 4XSS 挖掘:反射/存储/DOM 三型,危险 sink 定位、上下文逃逸与绕过,OOB 门禁。触发词:XSS、跨站脚本、存储型。
-
intent-solutions-io Bundle Configuring Auto Scaling Policies 2This skill configures auto-scaling policies for applications and infrastructure. It generates production-ready configurations based on user requirements, implementing best practices for scalability and security. Use this skill when the user requests help with auto-scaling setup, high availability, or dynamic resource allocation, specifically mentioning terms like "auto-scaling," "HPA," "scaling policies," or "dynamic scaling." This skill provides complete configuration code for various platforms.
-
intent-solutions-io Bundle Checking Session Security 2This skill enables Claude to check session security implementations within a codebase. It analyzes session management practices to identify potential vulnerabilities. Use this skill when a user requests to "check session security", "audit session handling", "review session implementation", or asks about "session security best practices" in their code. It helps identify issues like insecure session IDs, lack of proper session expiration, or insufficient protection against session fixation attacks. This skill leverages the session-security-checker plugin.
-
intent-solutions-io Bundle Managing Container Registries 2This skill enables Claude to manage container registries, including ECR, GCR, and Harbor. It should be used when the user needs to create, configure, or manage container image registries. It helps generate production-ready configurations, implement best practices, and ensure a security-first approach. Use this skill when the user mentions terms like "container registry," "ECR," "GCR," "Harbor," "image repository," or requests assistance with managing container images. It's also helpful for generating configuration code for DevOps pipelines related to container registries.
-
wufufu770 Skill Security Headers 3安全响应头审计:CSP/HSTS/XFO/Referrer-Policy 缺陷评估与修复基线建议。触发词:安全头、CSP、响应头、headers。低危快速项,适合凑覆盖面。
-
wufufu770 Skill Exploiting Prototype Pollution In JavascriptPerform exploiting prototype pollution in javascript assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
-
intent-solutions-io Bundle Responding To Security Incidents 2Assists with security incident response, investigation, and remediation. This skill is triggered when the user requests help with incident response, mentions specific incident types (e.g., data breach, ransomware, DDoS), or uses terms like "incident response plan", "containment", "eradication", or "post-incident activity". It guides the user through the incident response lifecycle, from preparation to post-incident analysis. It is useful for classifying incidents, creating response playbooks, collecting evidence, constructing timelines, and generating remediation steps. Use this skill when needing to respond to a "security incident".
-
fabioc-aloha Skill Security Review 4Defend before attackers find the gaps - OWASP, STRIDE, and Microsoft SFI
-
fabioc-aloha Skill Secrets Management 4Secure token storage, VS Code SecretStorage API, credential management, environment variable migration
-
steph-dove Skill Fastapi Security AuditYou are running a security audit of the current change. Scope is the diff against the base branch and the immediate context of what it touches — not the whole tree, and not style or architecture. Report findings only; do not edit code.
-
fabioc-aloha Skill Test Quality Analysis 4Analyze test code quality to detect coverage-only tests, test smells, and low-value assertions. Use when asked to "analyze test quality", "find coverage-only tests", "audit our tests", "are these tests valuable", "find test smells", or "which tests should we delete". Scores tests 1-5 on real value and produces prioritized improvement reports.
-
rudironsoni Skill Dotnet Security 4Security hardening and best practices for .NET applications. Navigation skill covering OWASP Top 10, authentication, authorization, cryptography, secrets management, and secure coding. For building secure applications. Keywords: security, owasp, authentication, authorization, cryptography, jwt, oauth, secrets, hardening
-
rudironsoni Skill Dotnet Security Owasp 8Hardens .NET apps per OWASP Top 10 -- injection, auth, XSS, deprecated security APIs.
-
abelrguezr Bundle Xs Search Leaks 2How to perform XS-Search and XS-Leaks attacks to extract cross-origin information through browser side-channel vulnerabilities. Use this skill whenever the user mentions cross-origin attacks, XS-Leaks, XS-Search, side-channel attacks, browser security testing, iframe exploitation, performance API leaks, timing attacks, or wants to enumerate user state across origins. This skill covers event handlers, timing techniques, global limits, performance API exploitation, error message analysis, and readable attribute extraction.
-
abelrguezr Bundle Windows Lateral Movement 2Guide for understanding Windows lateral movement techniques in authorized security assessments. Use this skill when the user asks about lateral movement, PsExec, SmbExec, WmiExec, WinRM, DCOM, RDP, or any Windows remote execution methods during penetration testing, red teaming, or security assessments. Also trigger when users need to understand how attackers move through Windows networks, detect lateral movement, or harden systems against these techniques.
-
abelrguezr Bundle Linux Privilege Escalation 3Linux privilege escalation payloads and techniques for CTFs and authorized penetration testing. Use this skill whenever the user mentions privilege escalation, privesc, SUID binaries, setuid, escalating from www-data to root, overwriting libraries, or any Linux security testing scenario. This includes CTF challenges, authorized pentests, and security research.
-
abelrguezr Bundle Memcache Pentest 2How to interact with Memcache servers for pentesting and CTF challenges. Use this skill whenever you need to connect to a Memcache service (typically port 11211), read/write cache keys, enumerate stored data, check server statistics, or exploit Memcache vulnerabilities. Trigger this for any Memcache-related task including key enumeration, data exfiltration, cache poisoning, or analyzing Memcache configurations.
-
abelrguezr Bundle IOS Pentesting Basics 2iOS security testing operations including device identification, shell access, data transfer, app extraction, and decryption. Use this skill whenever the user needs to perform iOS pentesting tasks, identify iOS devices, access device shells, transfer data from iOS devices, extract or decrypt iOS apps, or install apps on iOS devices. Trigger for any iOS security assessment, mobile app testing, or iOS device forensics work.
-
abelrguezr Bundle Android App Pentesting 2Android application security testing and vulnerability assessment. Use this skill whenever the user needs to analyze Android APKs, test for security vulnerabilities, enumerate components, exploit intents/deep links, or assess AIDL/Binder services. Trigger for any Android security testing, mobile pentesting, APK analysis, or Android vulnerability research tasks.
-
abelrguezr Bundle Android Frida Pentest 2Android app pentesting with Frida - use this skill whenever you need to hook Java methods, bypass root checks, debugger detection, or decrypt data in Android apps. Trigger this for any Android security testing, APK analysis, OWASP MSTG challenges, or when you want to intercept cryptographic operations, root detection, or debugger checks in Android applications.
-
abelrguezr Bundle Ad External Forest Trust 2Active Directory external forest trust enumeration and testing. Use this skill when analyzing outbound trust relationships between domains, investigating trust account vulnerabilities, or performing authorized security assessments of AD trust configurations. Trigger when users mention domain trusts, forest trusts, trust relationships, cross-domain permissions, or need to enumerate AD trust configurations.
-
abelrguezr Bundle Macos Dyld Hijacking 2macOS dynamic library injection and dyld hijacking for security testing. Use this skill when analyzing macOS binaries for privilege escalation, checking for disabled library validation, exploiting @rpath vulnerabilities, or performing DYLD_INSERT_LIBRARIES attacks. Trigger when the user mentions macOS security testing, binary analysis, library injection, dyld hijacking, or privilege escalation on macOS systems.
-
abelrguezr Bundle PHP Disable Functions Bypass 5Bypass PHP disable_functions restriction using the debug_backtrace() UAF vulnerability (PHP 7.0-7.4, *nix only). Use this skill when you need to execute system commands in PHP environments where functions like system(), exec(), shell_exec() are disabled. This is for authorized security testing and penetration testing only. Trigger this skill when the user mentions PHP disable_functions bypass, PHP UAF exploitation, PHP 7.x command execution, or any scenario involving restricted PHP function execution in a pentesting context.
-
phoroth Skill Quality Nonconformance 2Codified expertise for quality control, non-conformance investigation, root cause analysis, corrective action, and supplier quality management in regulated manufacturing. Informed by quality engineers with 15+ years experience across FDA, IATF 16949, and AS9100 enprojectnments. Includes NCR lifecycle management, CAPA systems, SPC interpretation, and audit methodology. Use when investigating non-conformances, performing root cause analysis, managing CAPAs, interpreting SPC data, or handling supplier quality issues.
3 -
galyarderlabs Bundle Executing Red Team Exercise 2Executes comprehensive red team exercises that simulate real-world adversary operations against an organization's people, processes, and technology. The red team operates with stealth as a primary objective, employing the full attack lifecycle from initial reconnaissance through objective completion while testing the organization's detection and response capabilities. This differs from penetration testing by focusing on adversary emulation rather than vulnerability identification. Activates for requests involving red team exercise, adversary simulation, adversary emulation, or full-scope offensive security assessment.
20 -
galyarderlabs Skill Iso 42001 AI Governance 2AI governance audit using ISO 42001 standard. Ensures AI systems are developed and deployed responsibly with risk management, ethics, security, transparency, and compliance best practices.
20 -
galyarderlabs Bundle Monitoring Darkweb Sources 2Monitors dark web forums, marketplaces, paste sites, and ransomware leak sites for mentions of organizational assets, leaked credentials, threatened attacks, and threat actor communications to provide early warning intelligence. Use when establishing dark web monitoring coverage, investigating specific data breach claims, or enriching incident investigations with dark web context. Activates for requests involving dark web OSINT, leak site monitoring, credential exposure, Recorded Future dark web, or Tor hidden service intelligence.
20 -
galyarderlabs Bundle Mapping Mitre Attack Techniques 2Maps observed adversary behaviors, security alerts, and detection rules to MITRE ATT&CK techniques and sub-techniques to quantify detection coverage and guide control prioritization. Use when building an ATT&CK-based coverage heatmap, tagging SIEM alerts with technique IDs, aligning security controls to adversary playbooks, or reporting threat exposure to executives. Activates for requests involving ATT&CK Navigator, Sigma rules, MITRE D3FEND, or coverage gap analysis.
20 -
galyarderlabs Bundle Tracking Threat Actor Infrastructure 2Threat actor infrastructure tracking involves monitoring and mapping adversary-controlled assets including command-and-control (C2) servers, phishing domains, exploit kit hosts, bulletproof hosting, a
20 -
galyarderlabs Bundle Generating Threat Intelligence Reports 2Generates structured cyber threat intelligence reports at strategic, operational, and tactical levels tailored to specific audiences including executives, security operations teams, and technical analysts. Use when producing finished intelligence products from raw collection data, creating sector threat briefings, or delivering post-incident intelligence assessments. Activates for requests involving CTI report writing, threat briefings, intelligence products, finished intelligence, or executive security reporting.
20 -
galyarderlabs Bundle Intercepting Mobile Traffic With Burpsuite 2Intercepts and analyzes HTTP/HTTPS traffic from mobile applications using Burp Suite proxy to identify insecure API communications, authentication flaws, data leakage, and server-side vulnerabilities. Use when performing mobile application penetration testing, assessing API security, or evaluating client-server communication patterns. Activates for requests involving mobile traffic interception, Burp Suite mobile proxy, API security testing, or mobile HTTPS analysis.
20 -
pjt222 Skill Manage Changelog 11Warten a changelog following Keep a Changelog format. Covers entry categorization (Added, Changed, Deprecated, Removed, Fixed, Security), version section management, and unreleased tracking. Verwenden wenn starting a new project that needs a changelog, adding entries nach completing features or fixes, preparing a release by promoting Unreleased entries to a versioned section, or converting a free-form changelog to Keep a Changelog format.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include implementing-database-audit-logging, dependency-analyzer, telegram-polling. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.