Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
majiayu000 Bundle Citation CheckAudit citation existence and fabrication risk, in-text/reference parity, DOIs, claim support, and style.
567 -
majiayu000 Bundle Soc2 ReadinessAssess SOC 2 readiness across the Trust Services Criteria and produce a gap remediation plan. Use when asked to prepare for a SOC 2 audit, run a SOC 2 readiness/gap assessment, scope controls, or get audit-ready. Produces a readiness report — scope & criteria, a control-by-control status, a weighted readiness score, prioritised gaps with owners, and the evidence each control needs.
567 -
majiayu000 Bundle Audit VerifyPhase 5: Verify all corrections were applied correctly
567 -
majiayu000 Bundle Farm InspectRun full code inspection with all audit agents in parallel. Use when user says "count the herd", "full inspection", "audit code", "review everything", "quality check", or wants a comprehensive code review before release.
567 -
majiayu000 Bundle Hunting BugsAudits codebases for common bug patterns and anti-patterns including timezone issues, null safety, type coercion, async handling, and performance problems. Searches for known problematic patterns and provides actionable fixes. Use when asked to find bugs, audit for issues, check for common problems, or hunt for bugs in codebase.
567 -
majiayu000 Bundle Memory AuditAudit embedded code for stack overflow risks, heap fragmentation, static allocation patterns, and memory leaks. Use when investigating OOM crashes, optimizing memory usage, or reviewing memory-critical code on constrained devices.
567 -
majiayu000 Bundle Review DebugAudit debug logging and diagnostics for ungated disk writes, missing coverage, and overhead
567 -
majiayu000 Bundle Spec CheckerPerform specification-to-code compliance analysis. Determine whether a codebase implements exactly what the documentation states, across logic, invariants, flows, assumptions, math, and security guarantees.
567 -
majiayu000 Bundle Tiered AuditAudit a codebase using three escalation tiers: git history analysis, targeted deep-dives, and full codebase review with gating.
567 -
majiayu000 Bundle Auth ReviewReview authentication and authorization design including OAuth, JWT, token expiration, RBAC/ABAC, and privilege escalation risks.
567 -
majiayu000 Bundle Bc SecurityImplement BigCommerce security — OAuth token management, API authentication, webhook verification, CSP, input validation, PCI compliance, and app security best practices. Use when hardening integrations or reviewing security posture.
567 -
majiayu000 Bundle Better AuthBetter Auth is comprehensive, framework-agnostic authentication/authorization framework for TypeScript with built-in email/password, social OAuth, and powerful plugin ecosystem for advanced features.
567 -
majiayu000 Bundle Btp Ba2 CLIInteract with the Binarly Transparency Platform (BTP) via CLI commands for uploading firmware, running scans, downloading BA2 archives, and pushing custom rules. Use when you need to interact with the Binarly Transparency Platform or working with BA2s.
567 -
majiayu000 Bundle Phx Deps UpdateBump outdated Hex deps — inventory, snapshot changelogs, update, fix breaks, split reviewable PRs (patches bundled, majors solo). Use to upgrade/bump Elixir dependencies or when versions fall behind. NOT for deps.get failures (/phx:investigate).
567 -
majiayu000 Bundle Edr EvasionEDR/AV bypass — hook unhooking, direct/indirect syscalls, PPID spoofing, process injection, AMSI bypass, ETW patching, memory encryption, behavioral evasion
567 -
majiayu000 Bundle Fuzzing Operations SkillComprehensive fuzzing operations with AFL++, libFuzzer, and OSS-Fuzz integration
567 -
majiayu000 Bundle Hunt AspnetHunt ASP.NET-specific surface — ViewState deserialization (signed-only vs encrypted), machineKey recovery, dual-parser MAC-bypass anti-pattern, request-validator bypass, trace.axd/elmah.axd disclosure, load-balanced ViewState cross-node failures, SafeControl enumeration via reflection, customErrors mode=Off stack-trace leaks, classic Webforms .aspx/.asmx/.svc surface. Built for ASP.NET Webforms + WCF + SharePoint farms.
567 -
majiayu000 Bundle Hunt NosqliHunt NoSQL Injection — MongoDB operator injection ($where, $regex, $gt, $ne), CouchDB, Redis command injection, auth bypass via NoSQLi, data dump. Use when target uses MongoDB/Mongoose, CouchDB, Redis, or shows NoSQL error messages.
567 -
majiayu000 Bundle Hunt ThreatConduct proactive, hypothesis-driven threat hunting. Use when performing advanced hunting based on threat intelligence, TTPs, or anomalies. For Tier 3 analysts or dedicated threat hunters. Supports iterative search, pivoting, and comprehensive documentation.
567 -
majiayu000 Bundle Jekyll Hyde· Review product, engineering, design, and business decisions with Jekyll/Hyde lenses. Triggers: 'jekyll', 'hyde', 'decision review', 'strategy review', 'red-team', 'dark pattern'.
567 -
majiayu000 Bundle Nauth GuideGuides how to integrate the NAuth package for user authentication in a .NET 8 project. Use when the user wants to add authentication, configure NAuth, use IUserClient, or understand the NAuth authentication flow.
567 -
majiayu000 Bundle Nist 800 53NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200 system categorization, control tailoring and overlays, privacy controls (PT family), supply chain risk management (SR family), assessment procedures (SP 800-53A), OSCAL, RMF integration (SP 800-37), and mapping to FedRAMP, FISMA, CMMC 2.0, and ISO 27001. Use for any federal system security controls, FISMA compliance, RMF step guidance, control narrative writing, or baseline tailoring question.
567 -
majiayu000 Bundle Nist AI RmfExpert NIST AI Risk Management Framework (AI RMF 1.0) advisor covering all four functions: GOVERN, MAP, MEASURE, MANAGE. Use this skill whenever a user asks about NIST AI RMF, AI risk management, AI trustworthiness, GOVERN function, MAP function, MEASURE function, MANAGE function, AI RMF Playbook, AI risk profiles, responsible AI, AI bias management, AI transparency, AI explainability, AI reliability, AI safety, NIST AI 100-1, AI risk assessment, AI incident response, or alignment to EU AI Act, ISO 42001, or NIST CSF via AI RMF. Trigger even if the user doesn't say "skill" — any NIST AI RMF or AI governance risk question should use this skill.
567 -
majiayu000 Bundle OAUTH LoginComplete OAuth login flow and store tokens for verification. Use when browser verification requires authenticated sessions.
567 -
majiayu000 Bundle Bknd Assign PermissionsUse when assigning permissions to roles in Bknd. Covers permission syntax (simple strings, extended format), permission effects (allow/deny), policies with conditions, entity-specific permissions, and fine-grained access control patterns.
567 -
majiayu000 Bundle Recon OsintComprehensive reconnaissance and OSINT — subdomain enumeration, CVE lookup, breach intelligence, DNS history, social profiling, attack surface mapping
567 -
majiayu000 Bundle Rug CheckerSolana token rug-pull risk analysis. 10-point on-chain check with visual report. Zero API keys. Read-only. Not financial advice.
567 -
majiayu000 Bundle Sf SecurityAudit Apex code for CRUD/FLS violations, sharing rule compliance, SOQL injection risks, and PII exposure. Scans entire codebases for security issues that cause AppExchange review failures. Use when asked about security review, AppExchange review readiness, CRUD/FLS audit, vulnerability scanning, or code security. Activate on mentions of "security audit", "AppExchange", "CRUD/FLS", "stripInaccessible", "with sharing", or "security review".
567 -
majiayu000 Bundle Vcp ContextInject VCP security and architecture standards into context. Run this at session start or after context compaction so the AI internalizes rules while writing code.
567 -
majiayu000 Bundle Vuln TriageTriage a vulnerability or scanner finding — assess real severity, exploitability, and how urgently to fix. Use when asked to triage a CVE, prioritize scanner/pentest findings, assess a vuln's risk, or decide what to patch first. Produces a triage verdict: CVSS-informed severity adjusted for your context, exploitability, real risk, a fix/mitigation, and an SLA — so you fix what matters, not just what's red.
567 -
majiayu000 Bundle X9 Parse QrYou parse EMVCo QR content strings into their TLV structure, validate the CRC-16 checksum, and extract the X9.150 payment URL.
567 -
majiayu000 Bundle X9 TemplateYou generate payment request template JSON files for testing the X9.150 specification. Templates are partial PaymentRequest payloads — qrgenerator.py adds runtime fields (id, revision, createdAt, timestamps, status, qrCodeContent, paymentNotification).
567 -
majiayu000 Bundle X9 ValidateYou validate JSON payloads against the X9.150 OpenAPI schema (spec/openapi.yaml). You auto-detect the schema type and report constraint violations with explanations.
567 -
majiayu000 Bundle Janitor AuditShow all your installed skills. Deprecated alias — use /janitor-report --brief.
567 -
majiayu000 Bundle Skill SharingSkillshare CLI reference and sharing workflows. Use when: (1) user says "share", "push", "sync skills", "skillshare", (2) managing extras (rules, commands, agents), (3) cross-machine sync, (4) team/org sharing setup, (5) hub or audit operations, (6) .skillignore configuration, (7) new team member onboarding with skills.
567 -
majiayu000 Bundle Idor Vulnerability TestingThis skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references," or "bypass authorization to access other users' data." It provides comprehensive guidance for detecting, exploiting, and remediating IDOR vulnerabilities in web applications.
567
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include citation-check, soc2-readiness, audit-verify. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.