Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
a5c-ai Bundle Constitution CreationEstablish project governing principles including dev guidelines, code quality standards, testing policies, UX requirements, performance benchmarks, and security constraints.
1.7k -
a5c-ai Bundle Cve Cwe Database SkillCVE and CWE database querying and management
1.7k -
a5c-ai Bundle Stix Taxii Intelligence SkillSTIX/TAXII threat intelligence format and sharing
1.7k -
a5c-ai Bundle Yara Rules SkillYARA rule creation, testing, and deployment
1.7k -
a5c-ai Bundle Web SecurityOWASP Top 10, security headers, CSP, XSS prevention, and vulnerability prevention.
1.7k -
a5c-ai Bundle Burp Suite Web Security SkillWeb application security testing with Burp Suite integration
1.7k -
a5c-ai Bundle Fuzzing Operations SkillComprehensive fuzzing operations with AFL++, libFuzzer, and OSS-Fuzz integration
1.7k -
a5c-ai Bundle Mitre Att Ck SkillMITRE ATT&CK framework mapping and analysis
1.7k -
a5c-ai Bundle Ghidra Ida Reverse Engineering SkillDeep integration with Ghidra and IDA Pro for binary analysis and reverse engineering
1.7k -
a5c-ai Bundle Tls SecurityExpert skill for TLS/SSL implementation and certificate management. Generate and validate TLS configurations, create and manage X.509 certificates, analyze cipher suite security, debug TLS handshake failures, and implement certificate pinning.
1.7k -
a5c-ai Bundle Dast ScannerDynamic Application Security Testing execution and management. Configure and execute OWASP ZAP and Nuclei scans, run authenticated scanning, manage scan policies and scope, correlate findings with SAST results, and generate comprehensive vulnerability reports.
1.7k -
a5c-ai Bundle Sast AnalyzerStatic Application Security Testing orchestration and analysis. Execute Semgrep, Bandit, ESLint security plugins, CodeQL, and other SAST tools. Parse, prioritize, and deduplicate findings across multiple tools with remediation guidance.
1.7k -
a5c-ai Bundle Mobile Security Testing SkillAndroid and iOS application security testing
1.7k -
a5c-ai Bundle Bug BountyBug bounty program management and security disclosure expertise for smart contracts. Covers program setup on Immunefi, vulnerability triage, responsible disclosure coordination, bounty payments, and post-disclosure analysis.
1.7k -
a5c-ai Bundle Mobile SecurityMobile application security skill for implementing OWASP MASVS compliance, secure storage, certificate pinning, biometric authentication, and security hardening across iOS and Android platforms.
1.7k -
a5c-ai Bundle Pwntools Exploitation SkillExploit development automation using pwntools framework
1.7k -
a5c-ai Bundle Crypto AnalyzerCryptographic implementation analysis and validation for encryption algorithms, key sizes, and certificate management
1.7k -
a5c-ai Bundle Hardware SecurityHardware and embedded security research capabilities. Interface with JTAG debuggers, analyze SPI/I2C communications, dump and analyze firmware, support fault injection, side-channel analysis, and hardware exploitation research.
1.7k -
a5c-ai Bundle Network Protocol Analysis SkillNetwork protocol capture, analysis, and fuzzing capabilities
1.7k -
a5c-ai Bundle Evm AnalysisDeep EVM bytecode analysis and decompilation capabilities for smart contract security, gas optimization, and reverse engineering. Provides tools for analyzing opcodes, storage layouts, proxy patterns, and bytecode verification.
1.7k -
a5c-ai Bundle OpenzeppelinExpert usage of OpenZeppelin Contracts library for secure smart contract development. Covers access control, token standards, governance, upgrades, and security utilities.
1.7k -
a5c-ai Bundle Solidity DevDeep expertise in Solidity language features, patterns, and best practices for secure smart contract development. Covers ERC standards, gas optimization, upgradeable contracts, and security patterns.
1.7k -
a5c-ai Bundle Incident ForensicsDigital forensics and incident response capabilities. Analyze memory dumps with Volatility, parse filesystem artifacts, extract browser forensics, analyze Windows event logs, create forensic timelines, recover deleted files, and generate forensic reports.
1.7k -
a5c-ai Bundle Offensive Security SkillOffensive security tools and techniques integration
1.7k -
a5c-ai Bundle Threat ModelerGenerate threat models using STRIDE, PASTA, or VAST methodologies
1.7k -
a5c-ai Bundle Binary Exploitation SkillAdvanced binary exploitation and mitigation bypass
1.7k -
a5c-ai Bundle Security ScanningAgentShield security audit with 5 scanning categories, 102 static analysis rules, and optional red-team simulation.
1.7k -
a5c-ai Bundle Dependency ScannerSoftware Composition Analysis (SCA) and dependency vulnerability scanning. Scan npm, pip, maven, gradle dependencies. Check CVE databases, generate SBOM (CycloneDX, SPDX), identify license compliance issues, and track EPSS scores for prioritization.
1.7k -
a5c-ai Bundle Homoglyph DetectorByte-level Unicode homoglyph detection for identifying invisible character substitutions in code
1.7k -
a5c-ai Bundle Debugger Integration SkillAdvanced debugging integration for vulnerability research
1.7k -
a5c-ai Bundle Security ScannerRun security scans including SAST, dependency scanning, and secret detection
1.7k -
a5c-ai Bundle Chain ForensicsOn-chain analysis and transaction forensics for blockchain security investigations. Provides capabilities for tracing fund flows, identifying suspicious patterns, MEV analysis, and generating forensic reports for incident response.
1.7k -
a5c-ai Bundle Vendor Risk MonitorContinuous vendor security monitoring for security ratings, breach notifications, and risk change detection
1.7k -
a5c-ai Bundle Static Analysis Tools SkillIntegration with security-focused static analysis tools
1.7k -
a5c-ai Bundle Openapi ValidatorValidate OpenAPI specifications for correctness, security, and best practices
1.7k -
a5c-ai Bundle Mythril SymbolicSymbolic execution analysis using Mythril for deep vulnerability detection in smart contracts. Supports configurable transaction depth, timeout settings, and proof-of-concept exploit generation.
1.7k
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include constitution-creation, CVE/CWE Database Skill, STIX/TAXII Intelligence Skill. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.