Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
gabrielmoreira Skill Replit Enterprise RbacConfigure Replit Teams roles, SSO/SAML, custom groups, and organization-level access control. Use when setting up team permissions, configuring SSO, managing deployment access, or auditing organization security on Replit. Trigger with phrases like "replit SSO", "replit RBAC", "replit enterprise", "replit roles", "replit permissions", "replit SAML", "replit teams admin".
17 -
gabrielmoreira Skill Replit Security BasicsApply Replit security best practices: Secrets management, REPL_IDENTITY tokens, Auth headers, and public Repl safety. Use when securing API keys, validating request identity, or auditing Replit security configuration. Trigger with phrases like "replit security", "replit secrets", "secure replit", "replit public safety", "replit identity token".
17 -
gabrielmoreira Skill Runway Security BasicsRunway security basics — AI video generation and creative AI platform. Use when working with Runway for video generation, image editing, or creative AI. Trigger with phrases like "runway security basics", "runway-security-basics", "AI video generation".
17 -
gabrielmoreira Bundle Sentry Enterprise RbacConfigure enterprise role-based access control, SSO/SAML2, and SCIM provisioning in Sentry. Use when setting up organization hierarchy, team permissions, identity provider integration, API token governance, or audit logging for compliance. Trigger: "sentry rbac", "sentry permissions", "sentry team access", "sentry sso setup", "sentry scim", "sentry audit log".
17 -
gabrielmoreira Bundle Sentry Security BasicsConfigure Sentry security settings and data protection. Use when setting up PII scrubbing, managing sensitive data, configuring data scrubbing rules, or hardening Sentry for compliance. Trigger with phrases like "sentry security", "sentry PII", "sentry data scrubbing", "secure sentry", "sentry GDPR".
17 -
gabrielmoreira Skill Vastai Security BasicsApply Vast.ai security best practices for API keys and instance access. Use when securing API keys, hardening SSH access to GPU instances, or auditing Vast.ai security configuration. Trigger with phrases like "vastai security", "vastai secrets", "secure vastai", "vastai API key security", "vastai ssh security".
17 -
gabrielmoreira Bundle Vercel Enterprise RbacConfigure Vercel enterprise RBAC, access groups, SSO integration, and audit logging. Use when implementing team access control, configuring SAML SSO, or setting up role-based permissions for Vercel projects. Trigger with phrases like "vercel SSO", "vercel RBAC", "vercel enterprise", "vercel roles", "vercel permissions", "vercel access groups".
17 -
gabrielmoreira Bundle Vercel Security BasicsApply Vercel security best practices for secrets, headers, and access control. Use when securing API keys, configuring security headers, or auditing Vercel security configuration. Trigger with phrases like "vercel security", "vercel secrets", "secure vercel", "vercel headers", "vercel CSP".
17 -
gabrielmoreira Bundle Windsurf Audit LoggingConfigure AI interaction audit logging for compliance. Activate when users mention "audit logging", "compliance logging", "ai interaction logs", "security audit", or "activity tracking". Handles compliance and audit configuration. Use when analyzing or auditing windsurf audit logging. Trigger with phrases like "windsurf audit logging", "windsurf logging", "windsurf".
17 -
gabrielmoreira Bundle Matter Allocation InstructionFirm-matter matching, matter instruction drafting, firm onboarding checklist, and instruction audit for in-house legal ops teams. Match a new matter to the right panel firm by practice area, jurisdiction, complexity, and cost tier. Produce a structured matter instruction with scope, timeline, budget, staffing, and reporting requirements. Generate an onboarding checklist covering conflict clearance, engagement letter, OCG acknowledgment, e-billing setup, and platform access. Audit an existing instruction for completeness and produce a remediation note. Trigger on: 'which firm should handle this', 'instruct the firm', 'write the instruction', 'matter instruction template', 'onboard the firm', 'set up the matter', 'conflict check', 'e-billing setup', 'is our instruction complete', 'review our instruction', 'instruction gap', 'allocate this matter'.
17 -
gabrielmoreira Bundle Uk Citation Verification Matei ClejVerifies UK case-law citations, pinpoint references and quotations against the official public register — The National Archives' Find Case Law — and statutory references against legislation.gov.uk, before a document that cites them is relied on, served or filed. Every check returns a graded verdict: VERIFIED, MISMATCH (the citation resolves to a different case — the classic AI miscitation), NOT ON REGISTER, OUTSIDE COVERAGE (the register cannot answer — absence proves nothing), or UNCHECKABLE (a law-report citation). The grading exists because there are two ways to get this wrong: citing a case that does not exist, and accusing a real case of not existing. Use when asked to check citations, verify a case exists, confirm a quotation is verbatim, check a pinpoint paragraph, audit a draft's authorities, screen a document for hallucinated cases, or check a statutory provision is in force. Not a substitute for reading the judgment: existence is not authority.
17 -
gabrielmoreira Bundle Analyzing Uefi Bootkit PersistenceAnalyzes UEFI bootkit persistence (SPI flash implants, ESP modifications, Secure Boot bypass, UEFI variable manipulation) using chipsec for firmware integrity verification, detecting known families like BlackLotus, LoJax, and MoonBounce. Use for UEFI malware analysis, firmware persistence investigation, or Secure Boot bypass detection.
17 -
gabrielmoreira Bundle Configuring Pfsense Firewall RulesConfigures pfSense firewall rules, NAT policies, IPsec/OpenVPN tunnels, and traffic shaping to enforce network segmentation and control traffic between zones such as DMZ, internal, guest, and IoT. Use when deploying a pfSense perimeter or internal firewall, setting up port-forwarding NAT, configuring site-to-site or remote-access VPNs, or applying QoS/bandwidth policies.
17 -
gabrielmoreira Bundle Detecting Email Account CompromiseDetect compromised O365 and Google Workspace email accounts by analyzing Unified Audit Logs and Azure AD sign-in logs for impossible travel, inbox rule creation/deletion (Set-InboxRule, New-InboxRule), external mail forwarding rules, and unusual Microsoft Graph API access or OAuth token use. Use when investigating suspected business email compromise (BEC), account takeover, or mailbox persistence via malicious inbox rules.
17 -
gabrielmoreira Bundle Detecting Insider Threat BehaviorsDetect insider threat behavioral indicators including unusual data access, off-hours activity, mass file downloads, privilege abuse, and resignation-correlated data theft. Use when proactively threat-hunting for malicious or negligent insider activity, or when investigating a departing or disgruntled employee for potential data theft.
17 -
gabrielmoreira Bundle Operationalizing Misp Threat FeedsStand up MISP, enable and cache curated threat feeds (CIRCL, abuse.ch, Feodo Tracker), apply warninglists to suppress false positives, query indicators with PyMISP, and export attributes as auto-generated Suricata/Sigma/Wazuh detection rules. Use when maturing a MISP instance to actively drive detection, curating threat feeds with quality controls, or automating IOC-to-detection pipelines for the SIEM/IDS.
17 -
gabrielmoreira Bundle Performing Steganography DetectionDetects and extracts hidden data embedded in images, audio, and other media files using steganalysis tools such as StegDetect, zsteg, stegsolve, binwalk, steghide, and OpenStego to uncover covert communication channels. Use when investigating suspected data hiding or exfiltration via media files, espionage/insider-threat cases, or anomalies in media file properties found during standard file analysis.
17 -
gabrielmoreira Bundle Testing For Email Header InjectionTests web application email functionality (contact forms, password reset, newsletter subscriptions) for CRLF/SMTP header injection using Burp Suite and OWASP ZAP, checking whether attackers can inject headers, modify recipients, or abuse forms for spam relay. Use when testing any user-input-driven email-sending feature during a penetration test.
17 -
gabrielmoreira Skill Short Drama Delivery AuditInternal deterministic delivery gate for meta-short-drama. Verifies real-provider image/video receipts, parent-owned paid-submission dispositions, runtime fallback evidence, decodability, and content-versus-final duration with ffprobe.
17 -
gabrielmoreira Skill Secure Workflow GuideGuides through Trail of Bits' 5-step secure development workflow. Runs Slither scans, checks special features (upgradeability/ERC conformance/token integration), generates visual security diagrams, helps document security properties for fuzzing/verification, and reviews manual security areas. Use when securing a smart contract end to end rather than hunting one bug, checking a project on every check-in or before deployment, triaging a Slither report, or asking where to start on smart contract security.
17 -
gabrielmoreira Skill Software Code ReviewApplies systematic code review patterns and checklists. Use when reviewing PRs or diffs for correctness, security, readability, maintainability, and AI-generated changes.
17 -
gabrielmoreira Skill Lookup NsgFinds the Network Interface Card (NIC) and associated Network Security Group (NSG) for a VM given its public IP address.
17 -
gabrielmoreira Skill Alchemy Security BasicsApply Web3 security best practices for Alchemy-powered applications. Use when securing API keys, validating blockchain inputs, preventing private key exposure, or hardening dApp infrastructure. Trigger: "alchemy security", "web3 security", "protect private key", "alchemy API key security", "dApp security".
17 -
gabrielmoreira Bundle Auditing Access ControlAudit access control implementations for security vulnerabilities and misconfigurations. Use when reviewing authentication and authorization. Trigger with 'audit access control', 'check permissions', or 'validate authorization'.
17 -
gabrielmoreira Skill Clickup Security BasicsSecure ClickUp API tokens, implement least-privilege access, and audit usage. Use when securing API keys, rotating tokens, configuring per-environment credentials, or auditing ClickUp API access patterns. Trigger: "clickup security", "clickup secrets", "secure clickup token", "clickup API key rotation", "clickup access audit".
17 -
gabrielmoreira Bundle Cursor Compliance AuditCompliance and security auditing for Cursor IDE usage: SOC 2, GDPR, HIPAA assessment, evidence collection, and remediation. Triggers on "cursor compliance", "cursor audit", "cursor security review", "cursor soc2", "cursor gdpr", "cursor data governance".
17 -
gabrielmoreira Bundle Cursor Privacy SettingsConfigure Cursor privacy mode, data handling, telemetry, and sensitive file exclusion. Triggers on "cursor privacy", "cursor data", "cursor security", "privacy mode", "cursor telemetry", "cursor data retention".
17 -
gabrielmoreira Bundle Granola Security BasicsSecurity and privacy configuration for Granola meeting data. Use when reviewing data handling practices, configuring encryption, ensuring SOC 2/GDPR compliance, or securing meeting recordings. Trigger: "granola security", "granola privacy", "granola encryption", "granola SOC 2", "granola GDPR", "secure granola".
17 -
gabrielmoreira Bundle Klaviyo Security BasicsApply Klaviyo security best practices for API key management and access control. Use when securing API keys, configuring OAuth scopes, implementing webhook signature verification, or auditing Klaviyo security configuration. Trigger with phrases like "klaviyo security", "klaviyo secrets", "secure klaviyo", "klaviyo API key security", "klaviyo OAuth".
17 -
gabrielmoreira Bundle Onenote Security BasicsImplement secure authentication, token management, and permission scoping for OneNote Graph API. Use when hardening OneNote integrations, implementing least-privilege permissions, or managing token lifecycle. Trigger with "onenote security", "onenote permissions", "onenote token management", "onenote least privilege".
17 -
gabrielmoreira Skill Persona Security BasicsSecure Persona API keys, webhook secrets, PII handling in verification data. Use when working with Persona identity verification. Trigger with phrases like "persona security-basics", "persona security-basics".
17 -
gabrielmoreira Skill Posthog Enterprise RbacPostHog enterprise access control: organization/project hierarchy, member roles, scoped API keys, SSO/SAML configuration, and activity audit logging. Trigger: "posthog SSO", "posthog RBAC", "posthog enterprise", "posthog roles", "posthog permissions", "posthog SAML", "posthog access".
17 -
gabrielmoreira Skill Posthog Security BasicsSecure PostHog integration: API key management, project key vs personal key separation, secret rotation, scoped keys, and git-leak prevention. Trigger: "posthog security", "posthog secrets", "secure posthog", "posthog API key security", "posthog key rotation".
17 -
gabrielmoreira Skill Procore Security BasicsProcore security basics — construction management platform integration. Use when working with Procore API for project management, RFIs, or submittals. Trigger with phrases like "procore security basics", "procore-security-basics".
17 -
gabrielmoreira Skill Serpapi Security BasicsSecure SerpApi API keys and prevent credit abuse. Use when storing API keys, implementing backend proxies, or auditing SerpApi access patterns. Trigger: "serpapi security", "serpapi API key security", "secure serpapi".
17 -
gabrielmoreira Bundle Shopify Security BasicsApply Shopify security best practices for API credentials, webhook HMAC validation, and access scope management. Use when securing API keys, validating webhook signatures, or auditing Shopify security configuration. Trigger with phrases like "shopify security", "shopify secrets", "secure shopify", "shopify HMAC", "shopify webhook verify".
17
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include runway-security-basics, alchemy-security-basics, replit-enterprise-rbac. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.