Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
gabrielmoreira Bundle Executing Red Team ExerciseRun a stealthy, MITRE ATT&CK-mapped adversary emulation against an organization's people, processes, and technology, using C2 infrastructure (Cobalt Strike, Sliver, Brute Ratel, Mythic) through the full attack lifecycle to test SOC detection and response rather than just find vulnerabilities. Use when executing a full-scope red team exercise, adversary simulation/emulation, or a regulatory exercise (TIBER-EU, CBEST, AASE, iCAST) with executive authorization and a signed Rules of Engagement already in place.
17 -
gabrielmoreira Skill Solana Payments Wallets TradingPay people in SOL or USDC, buy and sell tokens, check prices, discover trending and new tokens, create and manage Solana wallets, stake SOL, earn yield through lending and managed vaults, borrow against collateral, set up DCA (dollar-cost averaging) and limit orders, provide liquidity across multiple DEXes, trade prediction markets, pay for APIs via x402, set up security permissions and spending limits, and track portfolio performance — all from the command line. No API keys, no private key env vars. Use when the user wants to send crypto, swap or trade tokens, browse what's trending, check balances, earn yield, borrow, set up recurring buys or limit orders, provide liquidity, bet on predictions, pay for web resources, or see how their holdings are doing.
17 -
gabrielmoreira Skill Feishu Safety GuideOne-click deployment Skill for Feishu security governance and message anti-data-leakage guide, responsible for Feishu message security, credential protection, permission auditing, interaction logging and periodic security reporting
17 -
gabrielmoreira Bundle Test StrengthMeasure whether Python tests detect behavior changes through diff-scoped mutation testing. Use when Codex needs to audit the strength of a pytest suite, evaluate whether tests cover changed code, investigate surviving mutants, or propose and verify targeted tests for missed behavior.
17 -
gabrielmoreira Skill Check Cache BugsAudit Claude Code setup for cache bugs (CC#40524): sentinel, --resume/--continue, attribution header + ArkNill B3/B4/B5
17 -
gabrielmoreira Skill Update Threat DBDelegate threat-intelligence research and updates to AgentSec, then validate the guide and landing mirrors.
17 -
gabrielmoreira Skill Hooks And EnforcementUse when setting up guardrails for AI coding agents to enforce quality, security, and auditability requirements that must never be bypassed, or when configuring Claude Code lifecycle hooks in settings.json.
17 -
gabrielmoreira Bundle Exploiting Adcs With CertipyUse Certipy to enumerate AD CS certificate authorities and templates over LDAP/RPC, then exploit ESC1-ESC16 misconfigurations - SAN abuse, NTLM relay to web enrollment (ESC8), Shadow Credentials, golden certificate forgery, and PKINIT/Schannel auth. Use during authorized penetration tests to escalate a domain foothold to Domain Admin, or to validate that certificate template ACLs and CA hardening detect these attacks.
17 -
gabrielmoreira Skill Redteam Mobile Detail PackDomain routing and boundary guidance for authorized mobile application security testing, including insecure storage, certificate pinning bypass, exposed components, and binary reverse engineering. Use when a task belongs to the mobile testing domain and needs scope, evidence, pivot, or exit criteria.
17 -
gabrielmoreira Skill Finding Deleted Feature FlagsFind feature flags that were soft-deleted in the active project within a recent time window. Use when the user asks "what flags were deleted in the last N days", "show me recently deleted feature flags", "who deleted flag X", "audit recent flag deletions", or anything similar. Handles the non-obvious gotcha that system.feature_flags exposes the deleted boolean but does not expose a deletion timestamp — the actual deleted-at time lives in the per-flag activity log and must be cross-referenced.
17 -
gabrielmoreira Skill Windows Safety GuideOne-click deployment Skill for Windows security policies, daily security audits, behavior auditing, file baselines, logging and nightly audit task management
17 -
gabrielmoreira Skill File Security ToolkitEncrypt/decrypt local files, redact sensitive information in documents, and validate password strength when handling private data or preparing files for sharing.
17 -
gabrielmoreira Skill Reproducibility CheckComprehensive reproducibility tool — audit Methods completeness for replication AND promote open science best practices (pre-registration, FAIR data, code sharing, replication design, reporting transparency); trigger when preparing a manuscript, reviewing methodological comple...
17 -
gabrielmoreira Bundle UbsRun Ultimate Bug Scanner (UBS) for code review. Use when reviewing code, checking for bugs, scanning for security issues, validating AI-generated code, or pre-commit quality checks.
17 -
gabrielmoreira Bundle AI Audit Trail Larissa Meredith FlisterThis skill builds a structured audit trail of an AI-assisted task: what the tool was asked to do, what materials it was given, what it produced, how the output was verified, and what was ultimately relied upon. It documents the workflow for supervision and later review without ruling on privilege or disclosure, so the record stays accurate rather than self-serving.
17 -
gabrielmoreira Bundle Hunting For Webshell ActivityRuns a hypothesis-driven threat hunt for web shell deployment (T1505.003) on internet-facing servers by analyzing file creation in web directories, suspicious child-process spawning from web server processes, and anomalous HTTP request patterns. Use when hunting for web shells after a public-facing app compromise, when EDR/SIEM alerts fire on webserver process anomalies, or during incident response on internet-facing infrastructure.
17 -
gabrielmoreira Skill Redteam Network Detail PackDomain routing and boundary guidance for authorized network-layer security testing, including exposed services, protocol downgrade, man-in-the-middle risks, and segmentation bypasses. Use when a task belongs to the network testing domain and needs scope, evidence, pivot, or exit criteria.
17 -
gabrielmoreira Skill Controlflow VerifyUse after a ControlFlow plan is saved and before implementation. Runs tier-gated adversarial verification inline: structural audit, assumption/mirage detection, and cold-start executability simulation.
17 -
gabrielmoreira Skill Anti Reversing TechniquesUnderstand anti-reversing, obfuscation, and protection techniques encountered during software analysis. Use this skill when analyzing malware evasion techniques, when implementing anti-debugging protections for CTF challenges, when reverse engineering packed binaries, or when building security research tools that need to detect virtualized environments.
17 -
gabrielmoreira Skill AI Search Visibility AuditAudit whether a website can be found, crawled, and cited by AI answer engines such as ChatGPT Search, Perplexity, Google AI Overviews, and Microsoft Copilot. Use when someone asks why their brand is missing from AI answers, whether AI crawlers can read their site, how to get cited by ChatGPT or Perplexity, or asks for a GEO or AEO (generative / answer engine optimization) review. Produces a citation baseline across buyer-intent prompts, a crawler-access check, a citability review of named pages, and a ranked fix list. Not for keyword rank tracking, paid search, or pages behind a login.
17 -
gabrielmoreira Bundle Contribute PreparePrepare an OSS contribution locally after a read-only contribution audit. Creates explicitly scoped candidate records, repository dossiers, worktrees, test evidence, and gate results, but never publishes to GitHub. Use when the user has selected an issue and asks to set up, research, implement, test, or draft the contribution. Trigger with "/contribute-prepare" or "prepare this contribution locally".
17 -
gabrielmoreira Bundle Lindy Install AuthSet up a Lindy account and authenticated webhook trigger. Use when onboarding to Lindy, configuring bearer authentication for webhook triggers, or connecting Lindy agents to your application. Trigger with phrases like "install lindy", "setup lindy", "lindy auth", "configure lindy webhook", "lindy webhook secret".
17 -
gabrielmoreira Skill Replit Cost TuningOptimize Replit costs: deployment sizing, seat audit, egress control, and plan selection. Use when analyzing Replit billing, reducing deployment costs, or implementing usage monitoring and budget controls. Trigger with phrases like "replit cost", "replit billing", "reduce replit costs", "replit pricing", "replit expensive", "replit budget".
17 -
gabrielmoreira Bundle Gouvernance Des Societes Cotees Gillan SalehSkill open source d'analyse documentaire à vocation scientifique sur la gouvernance des sociétés cotées françaises (SBF 120). Il agrège, sous forme d'index sourcés à la page près, le corpus réglementaire et doctrinal 2020-2025 — rapports AMF et HCGE, Code AFEP-MEDEF, doctrine AMF, priorités ESMA, rapport sénatorial Rietmann/Gay, guide Paris Europlace — complété par recherche web. Sa règle fondatrice est le zéro invention : chaque chiffre, citation et page provient d'une source vérifiée, mot pour mot, en distinguant strictement le régulateur (AMF, ESMA) de la soft law (HCGE, AFEP-MEDEF). Quatre usages : restitution sourcée, analyse longitudinale, audit d'émetteur sur une grille de 13 blocs, croisement thématique multi-émetteurs. Ni conseil juridique, ni conseil en investissement.
17 -
gabrielmoreira Bundle Screening Alert Adjudication Amir FadaviAdjudicates whether a hit generated by sanctions, PEP, or adverse-media screening is a true positive, false positive, or requires human escalation. Use whenever a user presents a screening alert, a name match against a watchlist (OFAC SDN, EU consolidated list, UK OFSI, UN list, PEP list, adverse media hit, etc.), or asks to clear a screening hit / reduce false positives / determine whether a flagged name is actually the listed party. Use even when the user describes the task casually — "is this person actually on the sanctions list", "did we get a real match", "clear this alert", "I have a hit on X" — these are all screening-adjudication tasks. Produces a deterministic determination with full audit trail (structured JSON + human-readable narrative). Designed for use by compliance analysts and screening systems.
17 -
gabrielmoreira Skill Agency Infrastructure MaintainerExpert infrastructure specialist focused on system reliability, performance optimization, and technical operations management. Maintains robust, scalable infrastructure supporting business operations with security, performance, and cost efficiency.
17 -
gabrielmoreira Bundle Building Soc Escalation MatrixBuild a structured SOC escalation matrix defining severity tiers, response SLAs, tiered escalation paths, and notification procedures for security incidents, using context-driven criteria that combine business risk, asset criticality, and data sensitivity. Use when designing or revising how a SOC triages and escalates incidents across analyst tiers.
17 -
gabrielmoreira Bundle Detecting Dependency ConfusionDetect and prevent dependency confusion (public-over-private package name resolution) in npm, PyPI, and Maven by enumerating claimable internal package names with tools like `confused` and OWASP `dep-scan`, then enforcing source restrictions via `.npmrc`, `pip.conf`/`pyproject.toml`, and Maven `settings.xml`. Use when onboarding a repo to a supply-chain security program, auditing lockfiles/manifests for confusable dependencies, or after an incident that may have leaked internal package names.
17 -
gabrielmoreira Bundle Hunting For Ntlm Relay AttacksDetects NTLM relay attacks (MITRE T1557.001) by analyzing Windows Event ID 4624 logon type 3 with NTLMSSP authentication, flagging IP-to-hostname mismatches, Responder/LLMNR poisoning signatures, SMB signing status, and anomalous cross-domain authentication patterns. Use when investigating credential-relay activity in Active Directory or building detections for NTLM relay and coercion-based attacks.
17 -
gabrielmoreira Bundle Performing Vlan Hopping AttackSimulates VLAN hopping attacks using switch spoofing and 802.1Q double tagging techniques in authorized lab environments to test VLAN segmentation effectiveness and switch port security. Use during an authorized penetration test to validate trunk port hardening, confirm DTP is disabled on access ports, and demonstrate Layer 2 segmentation bypass risk to network teams.
17 -
gabrielmoreira Bundle Testing Websocket API SecurityTests WebSocket API implementations for missing upgrade-handshake authentication, Cross-Site WebSocket Hijacking (CSWSH), message injection, insufficient input validation, message-flooding DoS, and information leakage, using Burp Suite's WebSocket interception and the wscat CLI to craft malicious payloads. Use for real-time API penetration testing or CSWSH/authorization-bypass assessments on WebSocket channels.
17 -
gabrielmoreira Skill Paper Artifact RuntimeInternal cross-platform artifact persistence, assembly, citation-audit, and PDF compilation runtime for meta-paper-write.
17 -
gabrielmoreira Skill Csharp InteropCsWin32, LibraryImport, ConPTY, Native AOT, runtime marshalling, plugin security, and VT parsing
17 -
gabrielmoreira Skill Audit Agents SkillsAudit Claude Code agents, skills, and commands for quality and production readiness. Use when evaluating skill quality, checking production readiness scores, or comparing agents against best-practice templates.
17 -
gabrielmoreira Bundle Clerk ObservabilityImplement monitoring, logging, and observability for Clerk authentication. Use when setting up monitoring, debugging auth issues in production, or implementing audit logging. Trigger with phrases like "clerk monitoring", "clerk logging", "clerk observability", "clerk metrics", "clerk audit log".
17 -
gabrielmoreira Skill Exa Security BasicsSecure Exa API keys, implement content moderation, and manage domain restrictions. Use when securing API keys, auditing Exa security configuration, or implementing content safety filtering. Trigger with phrases like "exa security", "exa secrets", "secure exa", "exa API key security", "exa content moderation".
17
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include windows-safety-guide, reproducibility-check, hunting-for-webshell-activity. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.