Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
gabrielmoreira Bundle Cursor Prod ChecklistProduction readiness checklist for Cursor IDE setup: security, rules, indexing, privacy, and team standards. Triggers on "cursor production", "cursor ready", "cursor checklist", "optimize cursor setup", "cursor onboarding".
17 -
gabrielmoreira Skill Finta Security BasicsSecure Finta fundraising data and investor information. Trigger with phrases like "finta security", "finta data privacy".
17 -
gabrielmoreira Skill Fondo Security BasicsApply security best practices for Fondo including OAuth token management, financial data protection, SOC 2 compliance, and access control. Trigger: "fondo security", "fondo data protection", "fondo SOC 2", "fondo access control".
17 -
gabrielmoreira Skill Gamma Security BasicsImplement security best practices for Gamma integration. Use when securing API keys, implementing access controls, or auditing Gamma security configuration. Trigger with phrases like "gamma security", "gamma API key security", "gamma secure", "gamma credentials", "gamma access control".
17 -
gabrielmoreira Bundle Klingai Audit LoggingImplement audit logging for Kling AI operations for compliance and security. Use when tracking API usage or preparing for audits. Trigger with phrases like 'klingai audit', 'kling ai audit log', 'klingai compliance log', 'video generation audit trail'.
17 -
gabrielmoreira Bundle Lindy Enterprise RbacConfigure enterprise role-based access control for Lindy AI workspaces. Use when setting up team permissions, managing workspace access, or implementing enterprise security policies with SSO/SCIM. Trigger with phrases like "lindy permissions", "lindy RBAC", "lindy access control", "lindy enterprise security", "lindy SSO".
17 -
gabrielmoreira Bundle Navan Security BasicsSecure Navan API credentials with OAuth 2.0 best practices, SSO/SAML, and SCIM provisioning. Use when hardening a Navan integration, rotating credentials, or configuring identity provider SSO. Trigger with "navan security", "navan sso", "navan credentials", "navan scim".
17 -
gabrielmoreira Skill Replit Known PitfallsAudit a Replit App for persistence, Secrets, publishing, port, authentication, and deployment mistakes. Use when reviewing Replit code or diagnosing a Preview-to-production mismatch. Trigger with phrases like "replit mistakes", "replit anti-patterns", "replit pitfalls", or "replit code review".
17 -
gabrielmoreira Bundle Scanning API SecurityDetect API security vulnerabilities including injection, broken auth, and data exposure. Use when scanning APIs for security vulnerabilities. Trigger with phrases like "scan API security", "check for vulnerabilities", or "audit API security".
17 -
gabrielmoreira Bundle Speak Security BasicsSecurity best practices for Speak API keys, audio data privacy, student data protection, and COPPA/FERPA compliance. Use when implementing security basics features, or troubleshooting Speak language learning integration issues. Trigger with phrases like "speak security basics", "speak security basics".
17 -
gabrielmoreira Bundle Analyse Dpa Fournisseur Hugo SalardAnalyse systématique d'un Data Processing Agreement (DPA) au regard de l'article 28 RGPD, des lignes directrices EDPB 07/2020 et 02/2024, des CCT 2021 (décision d'exécution 2021/914), des recommandations EDPB 01/2020 (mesures supplémentaires post-Schrems II), et du Règlement (UE) 2024/1689 (Règlement IA). Produit un rapport structuré clause par clause (18 clauses : 13 obligatoires + 5 complémentaires) avec diagnostic 🟢/🟡/🔴, remédiations prêtes à insérer, analyse détaillée des transferts internationaux, vérification Règlement IA, et questions à poser au fournisseur. Triggers : "analyse de DPA", "audit DPA", "vérifier un DPA", "DPA fournisseur", "data processing agreement", "art. 28 RGPD", "sous-traitant RGPD", "négociation DPA", "review DPA", "conformité contrat sous-traitance".
17 -
gabrielmoreira Bundle Detecting API Enumeration AttacksDetect API enumeration attacks (BOLA/IDOR, OWASP API1:2023) by writing SIEM detection rules that flag sequential or UUID identifier iteration, parameter tampering, and mixed 200/401/403 response patterns from API gateway and WAF logs. Use when investigating suspected object-level authorization abuse, building threat-hunting queries for API access-control bypass, or hardening API logging/rate-limiting against enumeration.
17 -
gabrielmoreira Bundle Detecting Dll Sideloading AttacksDetect DLL side-loading and search-order hijacking (MITRE T1574) where adversaries plant malicious DLLs for legitimate signed applications to load, by analyzing Sysmon Event ID 7 DLL-load events, checking signatures/hashes against known-good versions, and flagging path anomalies with EDR tools like CrowdStrike, MDE, or SentinelOne. Use when investigating EDR alerts on unsigned DLLs, hunting for APT persistence via trojanized applications, or triaging incidents involving DLL hijacking.
17 -
gabrielmoreira Bundle Detecting Dnp3 Protocol AnomaliesDetect anomalies in DNP3 communications used in SCADA/ICS systems by monitoring unauthorized control commands, firmware update attempts, protocol violations, and deviations from baseline traffic using deep packet inspection and machine learning approaches. Use when securing energy-sector or other OT/ICS networks, investigating suspicious DNP3 master/outstation activity, or building an anomaly-based IDS for industrial control traffic.
17 -
gabrielmoreira Bundle Detecting Pass The Ticket AttacksDetect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous ticket usage patterns, with detection queries for Splunk and Elastic SIEM. Use when investigating incidents involving stolen or replayed Kerberos tickets, building detection rules or threat hunting queries for ticket abuse, or validating SOC monitoring coverage for credential-theft attack techniques.
17 -
gabrielmoreira Bundle Detecting Rdp Brute Force AttacksDetect RDP brute force attacks by parsing Windows Security Event Logs (EVTX files, via python-evtx) for failed logon patterns (Event ID 4625, Logon Type 10/3), correlating with successful logons (Event ID 4624), and analyzing NLA failures and source IP frequency. Use when investigating exposed RDP endpoints, building SIEM detection rules for credential guessing, or confirming whether a compromised account followed a brute-force pattern.
17 -
gabrielmoreira Bundle Exploiting HTTP Request SmugglingDetects and exploits HTTP request smuggling caused by Content-Length/Transfer-Encoding parsing discrepancies between front-end and back-end servers, using Burp Suite Repeater (auto Content-Length disabled), the HTTP Request Smuggler extension, and smuggler.py. Use during authorized tests of multi-tier architectures behind a reverse proxy, load balancer, or CDN to find desync flaws and bypass front-end controls.
17 -
gabrielmoreira Bundle Hunting For Cobalt Strike BeaconsDetect Cobalt Strike beacon command-and-control traffic using default TLS certificate signatures (serial 8BB00EE), JA3/JA3S/JARM fingerprints, HTTP malleable C2 profile pattern matching, and beacon jitter/interval analysis, built with Zeek network logs, Suricata IDS rules, and Python PCAP analysis. Use when hunting for Cobalt Strike beacon callbacks in network traffic or building detection rules for this C2 framework.
17 -
gabrielmoreira Bundle Hunting For Dcom Lateral MovementHunt for DCOM-based lateral movement (MITRE ATT&CK T1021.003) by detecting abuse of MMC20.Application, ShellBrowserWindow, and ShellWindows COM objects via Sysmon Event ID 1/3 correlation, WMI event analysis, and RPC endpoint mapper traffic on port 135. Use when investigating suspicious mmc.exe/dllhost.exe child processes, building T1021.003 detections, or auditing DCOM exposure during purple-team exercises.
17 -
gabrielmoreira Bundle Hunting For Dns Based PersistenceHunts for DNS-based persistence mechanisms such as DNS hijacking, dangling CNAME records enabling subdomain takeover, wildcard DNS abuse, and unauthorized zone or NS delegation changes, using passive DNS history (SecurityTrails API), Route53/Azure DNS/Cloudflare audit logs, and zone transfer analysis. Use when investigating suspected DNS hijacking or subdomain takeover, or when threat hunting for DNS record tampering that persists across credential rotations and endpoint reimaging.
17 -
gabrielmoreira Bundle Implementing Siem Use Case TuningTune SIEM detection rules in Splunk and Elastic to reduce false positives by analyzing alert volumes, creating context-aware exclusion lists, adjusting thresholds against environmental baselines, and measuring precision/recall efficacy metrics. Use when a SOC is drowning in noisy alerts and needs to tune correlation searches or detection rules, or when measuring and reporting alert-to-incident conversion rates.
17 -
gabrielmoreira Bundle Testing For Broken Access ControlSystematically tests web applications and APIs for broken access control (OWASP A01:2021), including privilege escalation, missing function-level checks, insecure direct object references, and multi-tenant data leakage, using Burp Suite with the Authorize extension. Use during authorized penetration tests or RBAC/multi-tenant authorization audits.
17 -
gabrielmoreira Skill Competition Container RuntimeInternal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for live container runtime analysis, mounted secrets, sidecars, namespaces, init containers, entrypoint drift, and route-to-container resolution. Use when the user asks why a live container differs from manifests, where a mounted secret is consumed, how a sidecar or init container changes runtime state, or which route resolves to which live container. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.
17 -
gabrielmoreira Skill Claude SecurityThe Claude Security menu — pick a job: scan the codebase (the whole repository or a scoped part of it), scan changes (this branch's or a pull request's diff, or one commit), or suggest patches (findings turned into targeted patch files, each verified by a panel of agents, that you apply when you choose).
17 -
gabrielmoreira Bundle Analyzing DependenciesAnalyze dependencies for known security vulnerabilities and outdated versions. Use when auditing third-party libraries. Trigger with 'check dependencies', 'scan for vulnerabilities', or 'audit packages'.
17 -
gabrielmoreira Bundle Apollo Enterprise RbacEnterprise role-based access control for Apollo.io. Use when implementing team permissions, restricting data access, or setting up enterprise security controls. Trigger with phrases like "apollo rbac", "apollo permissions", "apollo roles", "apollo team access", "apollo enterprise security".
17 -
gabrielmoreira Bundle Apollo Security BasicsApply Apollo.io API security best practices. Use when securing Apollo integrations, managing API keys, or implementing secure data handling. Trigger with phrases like "apollo security", "secure apollo api", "apollo api key security", "apollo data protection".
17 -
gabrielmoreira Skill Castai Webhooks EventsConfigure CAST AI webhook notifications for cluster events and audit logs. Use when setting up alerts for node scaling, cost threshold events, or integrating CAST AI events with Slack, PagerDuty, or custom endpoints. Trigger with phrases like "cast ai webhooks", "cast ai notifications", "cast ai slack alerts", "cast ai events".
17 -
gabrielmoreira Bundle Clerk Incident RunbookManage incident response for Clerk authentication issues. Use when handling auth outages, security incidents, or production authentication problems. Trigger with phrases like "clerk incident", "clerk outage", "clerk down", "auth not working", "clerk emergency".
17 -
gabrielmoreira Skill Cohere Security BasicsApply Cohere security best practices for API key management and access control. Use when securing API keys, implementing key rotation, or auditing Cohere security configuration. Trigger with phrases like "cohere security", "cohere secrets", "secure cohere", "cohere API key security", "cohere key rotation".
17 -
gabrielmoreira Skill Fathom Security BasicsSecure Fathom API keys and handle meeting data privacy. Trigger with phrases like "fathom security", "fathom api key safety", "fathom privacy".
17 -
gabrielmoreira Skill Framer Security BasicsApply Framer security best practices for secrets and access control. Use when securing API keys, implementing least privilege access, or auditing Framer security configuration. Trigger with phrases like "framer security", "framer secrets", "secure framer", "framer API key security".
17 -
gabrielmoreira Bundle Linear Enterprise RbacImplement enterprise role-based access control with Linear. Use when setting up team permissions, OAuth scopes, SAML SSO, SCIM provisioning, or audit logging. Trigger: "linear RBAC", "linear permissions", "linear SSO", "linear enterprise access", "linear role management", "linear SCIM".
17 -
gabrielmoreira Bundle Linear Multi Env SetupConfigure Linear across development, staging, and production environments. Use when setting up per-environment API keys, secret management, or environment-specific Linear configurations. Trigger: "linear environments", "linear staging", "linear dev prod", "linear environment setup", "multi-environment linear".
17 -
gabrielmoreira Bundle Notion Enterprise RbacConfigure Notion enterprise access control with OAuth, workspace permissions, and audit logging. Use when implementing OAuth public integrations, managing multi-workspace access, or building permission-aware Notion applications. Trigger with phrases like "notion SSO", "notion RBAC", "notion enterprise", "notion OAuth", "notion permissions", "notion multi-workspace".
17 -
gabrielmoreira Bundle Notion Security BasicsApply Notion API security best practices for integration tokens, OAuth2 flows, least-privilege capabilities, and page-level access control. Use when securing integration tokens, configuring OAuth2 for public integrations, rotating credentials, or auditing which pages an integration can access. Trigger with phrases like "notion security", "notion secrets", "secure notion", "notion API key security", "notion token rotation", "notion OAuth2", "notion permissions audit".
17
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include klingai-audit-logging, testing-for-broken-access-control, finta-security-basics. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.