Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
gabrielmoreira Skill Wooyun LegacyWooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws, misconfiguration) and 33 vulnerability classes. Use for ANY security testing, auditing, or code review of web apps, APIs, or business systems — even without explicit "security" keywords. Triggers: penetration testing, security audit, vulnerability, bug bounty, payment security, IDOR, password reset, weak credentials, unauthorized access, race condition, parameter tampering, code review, 渗透测试, 安全审计, 漏洞挖掘, 支付安全, 越权, 逻辑漏洞, 业务安全, SRC, 代码审计. Also triggers on implicit intent: "test this endpoint", "find bugs", "can I bypass this", "帮我测测这个接口", "这个参数能不能改", "帮我找bug".
17 -
gabrielmoreira Bundle Continuous Exposure MonitoringTurns one-shot external recon into a continuous monitoring program. Covers the scheduled re-scan-and-diff loop (baseline snapshot -> interval sleep -> re-scan -> asset/finding delta -> threshold-gated webhook alert), the scan-to-scan diff engine (new/removed/changed assets by a tracked-attribute table, new/resolved findings by a stable cross-scan fingerprint), adversary CTI / chatter monitoring across six public feeds (ransomwatch, ransomware.live, HackerNews Algolia search, Reddit security-subreddit RSS, GitHub Gist code-search, public Telegram channel scraping) with a source-kind-aware severity engine (leak-site/forum/telegram/paste tiers, CRITICAL through INFO), literal/glob/regex watchlist pattern matching, full-corpus capture with retroactive rescan on new watchlist entries, infrastructure-tracking-over-time discipline (certificate-transparency, passive-DNS, port/service, and typosquat re-enumeration cadence, and what a genuine 'perimeter drift' event looks like in the diff output), a five-state finding-
17 -
gabrielmoreira Skill Github Evidence KitGenerate, export, load, and verify forensic evidence from GitHub sources. Use when creating verifiable evidence objects from GitHub API, GH Archive, Wayback Machine, local git repositories, or security vendor reports. Handles evidence storage, querying, and re-verification against original sources.
17 -
gabrielmoreira Bundle Social Asset ProductionPlan, create, export, and review social-ready visual assets such as profile pictures, banners, post images, article covers, thumbnails, carousel slides, short-video covers, and platform crop variants. Use when Codex is asked to make or audit social graphics, crop-safe images, profile-circle previews, banner previews, text-safe layouts, or export packages for social platforms.
17 -
gabrielmoreira Bundle Legal Mdl Audit Ignacio Adrian LererAudits legal AI outputs and workflows for honest compression: unnecessary complexity, false simplicity, excessive caveats, hidden uncertainty and poor cost per legally acceptable output.
17 -
gabrielmoreira Bundle Swift CspExpert SWIFT Customer Security Programme (CSP) advisor covering the Customer Security Controls Framework (CSCF v2026). Use this skill whenever a user asks about SWIFT CSP, CSCF controls, SWIFT security attestation, KYC-SA portal, SWIFT architecture types (A1/A2/A3/A4/B), mandatory vs advisory controls, independent assessment, SWIFT secure zone, secure flow zone, MFA for operators, SWIFT messaging security, payment fraud prevention on SWIFT, gap analysis for CSCF, or compliance with SWIFT's 32 controls (25 mandatory, 7 advisory in v2026) across the three objectives: Secure Your Environment, Know and Limit Access, Detect and Respond. Control 2.4 (Back-Office Data Flow Security) is now mandatory in v2026. v2026 attestation window is July 1– December 31, 2026. Trigger for any SWIFT CSP or CSCF compliance question.
17 -
gabrielmoreira Skill Fleet Compliance Audit PrepPrepare a transport operation for a regulatory audit — the records an auditor asks for in order, the findings your own file will produce, and the gaps closed before the visit rather than during it. Use when asked to prepare for a DOT or FMCSA audit, a traffic commissioner or operator licence review, a fleet compliance inspection, or to run an internal transport compliance audit. Produces the records inventory, the self-audit findings by severity, the gap-closure plan, the audit-day logistics, and the evidence pack. Requirements are jurisdiction-specific and must be verified against the current regulation and your licence conditions.
17 -
gabrielmoreira Skill Metric Gaslighting DetectorFind out how a dashboard, KPI report, or metrics slide is lying to you — before you repeat its story in a bigger room. Use when numbers feel too tidy, a narrative rests on one chart, or you inherited metrics you didn't define. Produces a deception audit: every metric graded for the eleven classic distortions (denominator games, survivorship, y-axis crimes, cherry-picked windows…), the story the data would tell under honest framing, and the three questions to ask the metric's owner.
17 -
gabrielmoreira Skill Nemoclaw Maintainer Find Review PrFind open PRs with the security label and Urgent or High Project Priority. Link each PR to its issue. Identify competing or superseded PRs and report review candidates. Use when looking for the next PR to review. Trigger keywords - find pr, find review, next pr, pr to review, duplicate pr, security pr.
17 -
gabrielmoreira Skill Adding Project Secret API Key AuthHow to gate a PostHog API endpoint with project secret API key (PSAK) auth — a project-scoped, user-less service credential. Use when adding PSAK support to a viewset action, allowing a new scope for PSAKs, handling synthetic users (ProjectSecretAPIKeyUser), or choosing PSAK-aware rate throttles. Trigger terms: PSAK, ProjectSecretAPIKey, project secret API key, phs_ token, service auth, programmatic endpoint auth.
17 -
gabrielmoreira Skill Infisical Sync SkillExpert knowledge for the Infisical Sync Hand — Infisical API reference, vault operations, error patterns, security guidance
17 -
gabrielmoreira Skill Derive Security From RiskDerives security requirements from a named threat.
17 -
gabrielmoreira Skill Gait Session TrackingGAIT session lifecycle management - branch creation, turn recording, audit logging for every NetClaw operation. Use when starting a new NetClaw session, recording a health check or config change, pinning a pre-change baseline, or viewing the audit trail for a troubleshooting session.
17 -
gabrielmoreira Skill Ise Incident ResponseRapid ISE endpoint investigation and quarantine workflow - endpoint lookup, auth history, posture review, human-authorized quarantine, ServiceNow Security Incident. Use when a SOC alert flags a compromised endpoint, an unauthorized device is detected on the network, an endpoint is doing port scanning or lateral movement, or you need to quarantine a MAC address in ISE.
17 -
gabrielmoreira Skill Slack Report DeliveryDeliver formatted network reports, audit results, topology diagrams, and compliance documentation to Slack channels with rich Block Kit formatting. Use when posting a health check report, sharing a security audit, delivering topology diagrams, or sending scheduled network reports to Slack.
17 -
gabrielmoreira Skill Webex Report DeliveryDeliver formatted network reports, audit results, topology diagrams, and compliance documentation to WebEx spaces with Adaptive Cards and markdown formatting. Use when posting a health check report, sharing a security audit, delivering topology diagrams, or sending scheduled network reports to WebEx.
17 -
gabrielmoreira Skill Using OacUse when starting any conversation — establishes how to find and use OAC skills, requiring Skill tool invocation BEFORE ANY response including clarifying questions, this is your secret weapon to best perform your tasks
17 -
gabrielmoreira Skill Mid Engagement Ir DetectionMethodology for detecting client SOC patches, attacker activity, and security-state changes that occur DURING a red-team engagement — and converting those observations into deliverable findings. Built from authorized red-team work where the client patched a confirmed SQLi within 30 minutes of detection AND an external attacker locked multiple new accounts during a single test session. Use when (a) running ANY active engagement against a monitored target, (b) a previously-confirmed finding stops reproducing, (c) baseline timing shifts unexpectedly, or (d) you notice response patterns changing during testing.
17 -
gabrielmoreira Skill Problem Framing AuditStep-back protocol — restate, generalise, specialise, invert, ask why, pre-mortem, check stakeholders, and audit framings before solving
17 -
gabrielmoreira Bundle 504 Frameworks Micronaut SecurityUse when you need to design, review, or improve security in Micronaut applications — including micronaut-security authentication, @Secured and intercept-url-map rules, JWT/session strategies, SecurityService checks, CORS, CSRF awareness for browser apps, rejection handlers, and sensitive-data-safe logging. This should trigger for requests such as Add Micronaut security support; Review Micronaut security configuration; Improve API authorization in Micronaut; Add JWT security in Micronaut; Harden Micronaut route authorization rules. Part of Plinth Toolkit
17 -
gabrielmoreira Bundle Release Launch ReadinessPlan, audit, and execute release and launch readiness for software, games, websites, products, campaigns, and public launches. Use when Codex is asked about release checklists, launch plans, deployment risk, feature flags, rollout plans, rollback plans, monitoring, support readiness, communications, incident response, post-launch review, or go-live readiness.
17 -
gabrielmoreira Skill 15 Social Listening GlobalUse when the user wants to monitor what is being said about the brand, competitors, and the category — channels and keywords to track, sentiment scoring, weekly and monthly listening reports, brand health metrics, early crisis detection, and content opportunities pulled from real conversations. Trigger on 'social listening', 'brand monitoring', 'sentiment analysis', 'what are people saying about us', 'track our mentions', 'monitor competitors online'. Also use when the user spotted a bad comment thread and wants to know if it is spreading. Not for — responding to a crisis already underway, see `66-crisis-playbook-global`; competitor strategy teardown, see `08-competitor-research-global`; auditing your own posts, see `39-content-audit-global`.
17 -
gabrielmoreira Skill Brand Impersonation ResponseRespond to a brand or executive impersonation incident — deepfaked executives, cloned support lines, fake apps, spoofed domains, or AI-generated scam content wearing your name. Use when a deepfake of a leader is circulating, customers report a fake version of your product or support channel, or to prepare the impersonation playbook before it happens. Produces an incident response: verification protocol, takedown sequencing by platform, customer and public communications, and the hardening plan. For general crisis comms use press-release/pm-crisis skills; for security incidents inside your systems use security-incident-response.
17 -
gabrielmoreira Bundle Sensitive Logging AuditAudit or fix sensitive-data exposure in Python SDK diagnostics, exceptions, logging, and telemetry.
17 -
gabrielmoreira Skill Senior BackendComprehensive backend development skill for building scalable backend systems using NodeJS, Express, Go, Python, Postgres, GraphQL, REST APIs. Includes API scaffolding, database optimization, security implementation, and performance tuning. Use when designing APIs, optimizing database queries, implementing business logic, handling authentication/authorization, or reviewing backend code.
17 -
gabrielmoreira Skill Dingtalk Channel ConnectUse a headed browser to automatically complete DingTalk channel integration for QwenPaw. Applicable when the user mentions DingTalk, developer console, Client ID, Client Secret, bot, Stream mode, binding or configuring a channel. Supports pausing when a login page is detected and resuming after the user logs in.
17 -
gabrielmoreira Skill Cisco Psirt AdvisoriesCheck whether a running Cisco software version is affected by a published PSIRT security advisory - by OS version, CVE, or advisory ID, with severity and CVSS. Covers IOS, IOS-XE, NX-OS, ASA, FTD, FMC and ACI. Use when asked if a device or fleet is vulnerable, when triaging a Cisco CVE, or when auditing software versions against Cisco advisories.
17 -
gabrielmoreira Skill Okx Agentic WalletOKX Agentic Wallet — the single skill for the user's wallet and on-chain execution. Use it whenever the user wants to operate their wallet or execute an on-chain action, including: login & accounts, balance / holdings, wallet address / deposit / receive, send / transfer, contract calls (approve / deposit / withdraw), transaction history & status, message signing, wallet export & policy; pay gas with a stablecoin (Gas Station, Solana); swap / trade / buy / sell / convert, get a quote; cross-chain bridge & track arrival; limit orders (buy dip / take profit / stop loss / buy above) plus cancel / list / resume them; broadcast / gas / simulate / track a transaction; look up any public address's holdings; security scanning (token / honeypot 蜜罐 / 貔貅, DApp phishing, tx & signature checks, approvals); audit log. Once matched, follow this skill's Intent Routing to dispatch to the exact action.
17 -
gabrielmoreira Bundle AI Assist Observability Audit17-dimension observability audit with tier activation, health scoring, and cost analysis. Covers logging, metrics, tracing, alerting, SLOs, profiling, security observability, and developer experience. Use when assessing observability posture, identifying telemetry gaps, or optimizing observability costs.
17 -
gabrielmoreira Bundle Nist 800 53NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200 system categorization, control tailoring and overlays, privacy controls (PT family), supply chain risk management (SR family), assessment procedures (SP 800-53A), OSCAL, RMF integration (SP 800-37), and mapping to FedRAMP, FISMA, CMMC 2.0, and ISO 27001. Use for any federal system security controls, FISMA compliance, RMF step guidance, control narrative writing, or baseline tailoring question.
17 -
gabrielmoreira Skill 40 Next Content Plan GlobalUse when the next period content plan must be built from last period DATA — keep and replicate winners, cut losers, at most two new hypotheses, a 70/20/10 mix, a four-week overview, and an owner per slot. Trigger on 'next content plan', 'content plan for next month', 'plan from the audit', 'what should we post next quarter', 'scale what worked', 'plan content using the numbers'. Also use when a report just landed and the user asks what to do with it. Not for — auditing the past period first, see `39-content-audit-global`; turning the plan into a dated calendar, see `01-content-calendar-global`; the next period ADS plan, see `57-next-ads-plan-global`.
17 -
gabrielmoreira Skill Drug Interaction InterventionDocument a pharmacist's clinical intervention — the interaction or error spotted, what was done, what the prescriber decided, and the outcome — so the record shows the catch and the care that followed. Use when asked to document a clinical intervention, record a prescriber call about an interaction, log a near-miss, or build an intervention record for audit or remuneration. Produces the intervention record with severity and evidence, the prescriber-call script, the outcome and follow-up, and the aggregate reporting fields. A documentation framework for a licensed pharmacist; every interaction and severity judgement must be verified against current references.
17 -
gabrielmoreira Bundle Home Contractor Quote DecoderDecode a home renovation or repair quote — allowances that aren't prices, exclusions that become change orders, payment schedules that shift risk, and what a comparable-bids check should cover. Use when someone asks 'is this contractor quote fair', 'decode this renovation bid', 'what should be in a contractor contract', or 'why do these three bids differ so much'. Produces a section-by-section decode, the allowance and exclusion audit, payment-schedule risk analysis, and the questions that make bids comparable.
17 -
gabrielmoreira Skill KataOrchestrate an improvement cycle: diagnose, select methodology, execute, record, persist. The meta-pattern that connects all skills into a coherent workflow. USE WHEN: improve, audit, review, full treatment, kata, run the loop, comprehensive improvement, what does this project need.
17 -
gabrielmoreira Bundle Nemoclaw Contributor Implement IssueImplement an accepted NemoClaw GitHub issue in the current checkout. Use when a user asks to pick up an issue for implementation, implement or fix a named issue, or add the issue's tests. Confirm accepted scope, deliver the smallest independently valuable capability slice, and record validation and remaining gates without publishing a PR. Ask which lifecycle stage they want when "work on this issue" could mean planning or implementation. Do not use for issue planning, PR publication, independent security review, or maintainer loops. Trigger keywords - pick up issue for implementation, implement issue, fix issue, code issue, add issue tests.
17 -
gabrielmoreira Skill ClawkeeperInstall, configure, verify, and debug the Clawkeeper watcher stack in this workspace. Use when a user asks to set up `clawkeeper`, initialize `remote` or `local` mode, enable `clawkeeper-watcher`, wire `clawkeeper-bands`, diagnose `context-judge` routing, inspect watcher logs, fix mode/config mismatches, or troubleshoot startup, audit, hardening, rollback, drift monitoring, or bridge notification issues.
17
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include dingtalk_channel_connect, 40-next-content-plan-global, wooyun-legacy. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.