Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
gabrielmoreira Skill Changelog ScanScan recent merges to main (and noteworthy direct commits) since a given window (last tag or date in state). Extract titles, labels, types, linked issues, and signals for breaking changes or security. Produces structured input for a release notes drafter. Use in changelog-drafter loops.
17 -
gabrielmoreira Skill Act PassRun the 7-step Artificial Critical Thinking pass — Materiality → Hypothesise → Alternatives → Disconfirmers → Audit priors → Severity → Commit-with-marker
17 -
gabrielmoreira Skill Ciso Assistant Basic Risk AssessmentGuide users through a basic risk assessment workflow in CISO Assistant, from asset identification to scenario creation. Use when: (1) User wants to start a risk assessment from scratch (2) User mentions "risk assessment", "identify risks", "threat scenarios", or "risk register" (3) User asks about qualitative vs quantitative risk approaches (4) User needs help identifying assets, threats, or creating risk scenarios Covers: risk approach selection (qualitative/quantitative), organizational context gathering, asset identification (primary/supporting), threat catalog usage, scenario generation from threat-asset combinations, risk assessment/study creation.
17 -
gabrielmoreira Skill Buzz ReconPR and community reconnaissance — audit current press coverage, social presence, community health, and competitor PR. Use when asked to "audit our PR", "what's our community state", "how do we compare in press", or before planning a launch or community initiative.
17 -
gabrielmoreira Skill Keep ReconCustomer success reconnaissance — audit current onboarding completion, health signals, NRR, churn patterns, and CS motion. Use when asked to "audit our customer success", "why are customers churning", "what's our NRR", or before designing any CS playbook.
17 -
gabrielmoreira Skill Pave AuditAudit developer experience — measure onboarding time, build speed, deployment friction, and developer satisfaction. Use when asked to "DX audit", "developer experience review", "why is development slow", "onboarding assessment", or "DORA metrics".
17 -
gabrielmoreira Skill Volt PowerPower management audit — analyze sleep modes, wake sources, power state machines, radio duty cycles, and battery life estimates. Use when asked to "audit power usage", "optimize battery life", "review power management", "why is my battery draining", "power budget analysis", or "sleep mode review".
17 -
gabrielmoreira Bundle Analyzing Security HeadersAnalyze HTTP security headers of web domains to identify vulnerabilities and misconfigurations. Use when you need to audit website security headers, assess header compliance, or get security recommendations for web applications. Trigger with phrases like "analyze security headers", "check HTTP headers", "audit website security headers", or "evaluate CSP and HSTS configuration".
17 -
gabrielmoreira Skill Assemblyai Security BasicsApply AssemblyAI security best practices for API keys, PII, and access control. Use when securing API keys, implementing PII redaction, or configuring temporary tokens for browser-side streaming. Trigger with phrases like "assemblyai security", "assemblyai secrets", "secure assemblyai", "assemblyai API key security", "assemblyai PII".
17 -
gabrielmoreira Skill Brightdata Security BasicsApply Bright Data security best practices for secrets and access control. Use when securing API keys, implementing least privilege access, or auditing Bright Data security configuration. Trigger with phrases like "brightdata security", "brightdata secrets", "secure brightdata", "brightdata API key security".
17 -
gabrielmoreira Bundle Clickhouse Security BasicsSecure ClickHouse with user management, network restrictions, TLS, and audit logging. Use when hardening a ClickHouse deployment, creating restricted users, enforcing multi-tenant row isolation, or configuring network-level access controls. Trigger with "clickhouse security", "clickhouse user management", "secure clickhouse", "clickhouse TLS", "clickhouse access control", "clickhouse firewall".
17 -
gabrielmoreira Skill Coderabbit Security BasicsConfigure CodeRabbit for security-focused code review with secret detection and vulnerability scanning. Use when setting up security review rules, configuring secret detection in PRs, or hardening CodeRabbit configuration for compliance requirements. Trigger with phrases like "coderabbit security", "coderabbit secrets", "secure coderabbit", "coderabbit vulnerability detection", "coderabbit security review".
17 -
gabrielmoreira Bundle Configuring Service MeshesConfigure this skill configures service meshes like istio and linkerd for microservices. it generates production-ready configurations, implements best practices, and ensures a security-first approach. use this skill when the user asks to "configure service ... Use when appropriate context detected. Trigger with relevant phrases based on skill purpose.
17 -
gabrielmoreira Bundle Customerio Security BasicsApply Customer.io security best practices. Use when implementing secure credential storage, PII handling, webhook signature verification, or GDPR/CCPA compliance. Trigger: "customer.io security", "customer.io pii", "secure customer.io", "customer.io gdpr", "customer.io webhook verify".
17 -
gabrielmoreira Bundle Elevenlabs Security BasicsApply ElevenLabs security best practices for API keys, webhook HMAC validation, and voice data protection. Use when securing API keys, validating webhook signatures, or auditing ElevenLabs security configuration. Trigger with "elevenlabs security", "elevenlabs secrets", "secure elevenlabs", "elevenlabs API key security", "elevenlabs webhook signature", "elevenlabs HMAC".
17 -
gabrielmoreira Bundle Grammarly Access ReadinessAudit a Grammarly API OAuth configuration offline for recognized organization access, least-privilege scopes, and documented API coverage. Use when reviewing Grammarly Enterprise or institution-wide Grammarly for Education API readiness, OAuth scope changes, or an AI/plagiarism access discrepancy. Trigger with "Grammarly OAuth readiness", "Grammarly API scopes", or "Grammarly institution-wide access". Do not use for obtaining credentials, making API calls, or submitting documents.
17 -
gabrielmoreira Bundle Grammarly License GovernorProduce a review-only plan from a sanitized Grammarly License Management snapshot, identifying non-admin users whose last activity is before an explicit cutoff. Use when governing unused seats without exposing identity data or mutating Grammarly. Trigger with "review Grammarly inactive licenses", "Grammarly seat audit", or "analyze a sanitized Grammarly license snapshot".
17 -
gabrielmoreira Bundle Performing Security AuditsAnalyze code, infrastructure, and configurations by conducting comprehensive security audits. It leverages tools within the security-pro-pack plugin, including vulnerability scanning, compliance checking, and cryptography review. Use when assessing security or running audits. Trigger with phrases like 'security scan', 'audit', or 'vulnerability'.
17 -
gabrielmoreira Skill Salesforce Security BasicsApply Salesforce security best practices for Connected Apps, OAuth, and field-level security. Use when securing API credentials, implementing least privilege access, or auditing Salesforce security configuration. Trigger with phrases like "salesforce security", "salesforce secrets", "secure salesforce", "salesforce connected app security", "salesforce FLS".
17 -
gabrielmoreira Bundle Scanning Database SecurityProcess use when you need to work with security and compliance. This skill provides security scanning and vulnerability detection with comprehensive guidance and automation. Trigger with phrases like "scan for vulnerabilities", "implement security controls", or "audit security".
17 -
gabrielmoreira Bundle Supabase Policy GuardrailsEnforce organizational governance for Supabase projects: shared RLS policy library with reusable templates, table and column naming conventions, migration review process with CI checks, cost alert thresholds, and security audit scripts scanning for common misconfigurations. Use when establishing Supabase standards across teams, creating RLS policy templates, setting up migration review workflows, or auditing existing projects for security and cost issues. Trigger with phrases like "supabase governance", "supabase policy library", "supabase naming convention", "supabase migration review", "supabase cost alert", "supabase security audit", "supabase RLS template".
17 -
gabrielmoreira Bundle Validating Csrf ProtectionValidate CSRF protection implementations for security gaps. Use when reviewing form security or state-changing operations. Trigger with 'validate CSRF', 'check CSRF protection', or 'review token security'.
17 -
gabrielmoreira Skill Agency Autonomous Optimization ArchitectIntelligent system governor that continuously shadow-tests APIs for performance while enforcing strict financial and security guardrails against runaway costs.
17 -
gabrielmoreira Bundle Detecting Attacks On Historian ServersDetect cyber attacks on OT historian servers (OSIsoft PI, Ignition, GE Proficy, Wonderware InSQL) using a Python detector that flags unauthorized queries, data manipulation, and lateral-movement indicators as historians pivot between IT and OT networks. Use when monitoring historians bridging IT/OT zones for compromise, investigating historian-specific CVE exploitation, or validating historian data integrity after a suspected OT incident.
17 -
gabrielmoreira Bundle Detecting Command And Control Over DnsDetect command-and-control (C2) traffic tunneled over DNS from tools like Iodine, dnscat2, dns2tcp, and Cobalt Strike DNS beacon, using Shannon entropy analysis of query subdomains, ML-based DGA classification, passive DNS correlation, and Zeek/Suricata signatures. Use when investigating suspected DNS tunneling, classifying DGA domains, detecting DNS beaconing, or building DNS anomaly rules for a SOC/SIEM.
17 -
gabrielmoreira Bundle Detecting Lateral Movement With SplunkDetect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs, SMB traffic, and remote service (WMI/PsExec/RDP) abuse. Use when hunting for MITRE ATT&CK TA0008 lateral movement activity or investigating suspected pivoting between hosts during an incident, with Splunk as the SIEM.
17 -
gabrielmoreira Bundle Hunting For Domain Fronting C2 TrafficDetects domain fronting C2 traffic by analyzing SNI-vs-HTTP-Host-header mismatches in proxy logs and inspecting TLS certificate discrepancies with pyOpenSSL. Use when hunting for command-and-control traffic hidden behind legitimate CDN domains, or when investigating proxy/TLS logs for signs of domain fronting evasion.
17 -
gabrielmoreira Bundle Hunting For Scheduled Task PersistenceRuns a hypothesis-driven threat hunt for Windows Scheduled Task persistence (T1053), guiding SIEM/EDR queries against task creation events (e.g. Event ID 4698), suspicious task actions, and unusual scheduling patterns. Use when hunting for scheduled-task persistence, after threat intel flags related campaigns, during incident response, or when alerts fire on schtasks/at.exe activity.
17 -
gabrielmoreira Bundle Hunting For Startup Folder PersistenceDetects T1547.001 startup folder persistence by monitoring Windows startup directories for suspicious file creation, cross-referencing Autoruns entries, and running a Python watchdog script for real-time filesystem monitoring. Use when hunting for malware or implants that survive reboot via startup-folder placement, or when validating autoruns/EDR findings against known-good startup baselines.
17 -
gabrielmoreira Bundle Hunting For Suspicious Scheduled TasksHunts for adversary persistence and execution via Windows scheduled tasks (T1053.005) by analyzing Security Event ID 4698 task-creation events, suspicious task properties, and unusual execution patterns from schtasks.exe/at.exe. Use after detecting schtasks or at.exe in process creation logs, during incident response to enumerate persistence on compromised hosts, or when Event ID 4698 fires for an unusual task.
17 -
gabrielmoreira Bundle Hunting For T1098 Account ManipulationHunts for MITRE ATT&CK T1098 account manipulation - shadow admin creation, SID history injection, group membership changes, and credential modifications - by analyzing Windows Security Event Log IDs 4738, 4728, 4732, 4756, 4670, and 5136. Use when investigating suspected privilege persistence in Active Directory, after detecting anomalous group/credential changes, or during incident response to trace account tampering.
17 -
gabrielmoreira Bundle Implementing API Key Security ControlsImplements secure API key generation with sufficient entropy, server-side hashing (SHA-256/bcrypt) instead of plaintext storage, per-key scoping to endpoints/IPs/rate limits, zero-downtime rotation, and automated leak monitoring across GitHub repos, logs, and client-side code. Use when designing API key formats, building key rotation or revocation workflows, or protecting server-to-server API credentials from leakage, brute force, and abuse.
17 -
gabrielmoreira Bundle Performing Directory Traversal TestingTest web applications for path traversal and Local/Remote File Inclusion vulnerabilities by manipulating file path parameters, applying encoding and filter-bypass techniques, automating discovery with ffuf and dotdotpwn, and reading high-value files or achieving code execution. Use during authorized penetration tests of file download, view, or include functionality, or when assessing APIs that accept file names or file paths as parameters.
17 -
gabrielmoreira Bundle Performing Ssl Tls Security AssessmentAssess SSL/TLS server configurations using the sslyze Python scanning library to evaluate supported protocol versions, cipher suite strength, certificate chain validation, HSTS enforcement, OCSP stapling, and known vulnerabilities such as Heartbleed and ROBOT. Use when conducting a security assessment of a server's TLS configuration or verifying remediation of cipher/certificate weaknesses.
17 -
gabrielmoreira Bundle Testing API Security With Owasp Top 10Systematically assesses REST, GraphQL, and gRPC API endpoints against the OWASP API Security Top 10 (2023) using Burp Suite and Postman for automated and manual testing. Use during authorized API penetration tests, before deploying new endpoints to production, or when validating API gateway controls and rate limiting.
17 -
gabrielmoreira Skill Supply Chain Risk AuditorAudits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration, and install-time script execution. Use when asked to audit dependencies, assess supply-chain or third-party package risk, or review a dependency tree before an engagement.
17
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include validating-csrf-protection, hunting-for-t1098-account-manipulation, changelog-scan. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.