Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
gabrielmoreira Skill Supervisor BannersDark-slate SVG banner family — 1200×320 hero + 1200×60 section dividers — for governance, curation, and audit-style documentation
17 -
gabrielmoreira Skill Violation TriagerOrchestrate end-to-end SFI-TI3.2.2 workflow — fetch violations, classify, dispatch to remediation skills, generate report
17 -
gabrielmoreira Bundle Assisting With Soc2 Audit PreparationExecute automate SOC 2 audit preparation including evidence gathering, control assessment, and compliance gap identification. Use when you need to prepare for SOC 2 audits, assess Trust Service Criteria compliance, document security controls, or generate readiness reports. Trigger with phrases like "SOC 2 audit preparation", "SOC 2 readiness assessment", "collect SOC 2 evidence", or "Trust Service Criteria compliance".
17 -
gabrielmoreira Bundle Snowflake Governance Coverage AuditorAudit trusted Snowflake classification, tags, masking, row access, projection, join, aggregation, and privacy-policy evidence without reading customer data. Use when governance enforcement may be missing or ambiguous. Trigger with "Snowflake governance coverage", "policy precedence", "tag policy gaps", "classification failure", or "POLICY_CONTEXT verification".
17 -
gabrielmoreira Skill Cors Policy ValidatorValidate cors policy validator operations. Auto-activating skill for Security Fundamentals. Triggers on: cors policy validator, cors policy validator Part of the Security Fundamentals skill category. Use when working with cors policy validator functionality. Trigger with phrases like "cors policy validator", "cors validator", "cors".
17 -
gabrielmoreira Skill Path Traversal FinderManage path traversal finder operations. Auto-activating skill for Security Fundamentals. Triggers on: path traversal finder, path traversal finder Part of the Security Fundamentals skill category. Use when working with path traversal finder functionality. Trigger with phrases like "path traversal finder", "path finder", "path".
17 -
gabrielmoreira Skill Incident Response PlannerConfigure incident response planner operations. Auto-activating skill for Security Advanced. Triggers on: incident response planner, incident response planner Part of the Security Advanced skill category. Use when working with incident response planner functionality. Trigger with phrases like "incident response planner", "incident planner", "incident".
17 -
gabrielmoreira Skill Security Benchmark RunnerManage security benchmark runner operations. Auto-activating skill for Security Advanced. Triggers on: security benchmark runner, security benchmark runner Part of the Security Advanced skill category. Use when working with security benchmark runner functionality. Trigger with phrases like "security benchmark runner", "security runner", "security".
17 -
gabrielmoreira Skill Security Policy GeneratorGenerate security policy generator operations. Auto-activating skill for Security Advanced. Triggers on: security policy generator, security policy generator Part of the Security Advanced skill category. Use when working with security policy generator functionality. Trigger with phrases like "security policy generator", "security generator", "security".
17 -
gabrielmoreira Skill Research Us Loading SecurityPrepare United States loading, cargo securement, seal, yard, dock, and shipment security research briefs for logistics operations.
17 -
gabrielmoreira Bundle Building Adversary Infrastructure Tracking SystemBuild an automated adversary infrastructure tracking system in Python (dnspython, python-whois, shodan, networkx) that pivots across passive DNS, certificate transparency logs, WHOIS records, and IP enrichment to map threat-actor C2 networks and flag newly registered domains matching known patterns. Use when pivoting from known indicators to discover related C2 infrastructure or maintaining a continuously updated map of a threat actor's network.
17 -
gabrielmoreira Bundle Building Threat Intelligence Enrichment In SplunkBuild automated IOC enrichment pipelines in Splunk Enterprise Security by ingesting threat feeds into KV Store collections and correlating them against security events via lookup tables, modular inputs, and the Threat Intelligence Framework. Use when wiring threat intel into Splunk correlation searches to flag IOC matches and cut SOC triage time.
17 -
gabrielmoreira Bundle Detecting Anomalies In Industrial Control SystemsDeploys anomaly detection for OT/ICS environments using machine learning on OT network baselines, physics-based process models, and Modbus/DNP3/OPC UA traffic analysis to flag deviations, rogue devices, and mismatches against historian data. Use for continuous OT monitoring, baselining deterministic SCADA polling, or investigating alerts from Nozomi Guardian/Dragos needing deeper protocol analysis.
17 -
gabrielmoreira Bundle Detecting T1548 Abuse Elevation Control MechanismDetect abuse of elevation control mechanisms (T1548), including Windows UAC bypass via auto-elevating binaries like fodhelper.exe and Linux sudo/setuid/setgid exploitation, by monitoring registry changes, integrity-level transitions, and parent-child process relationships via Sysmon and Windows Security events. Use when hunting privilege-escalation activity or validating elevation-abuse detection coverage.
17 -
gabrielmoreira Bundle Implementing Google Workspace Phishing ProtectionConfigures Google Workspace advanced phishing and malware protection settings in the Admin Console — pre-delivery message scanning, attachment protection, spoofing/impersonation detection, and Enhanced Safe Browsing enforcement. Use when hardening Gmail against phishing, spoofing, and malware, or when tuning Workspace email security policies.
17 -
gabrielmoreira Bundle Implementing Hardware Security Key AuthenticationBuilds a FIDO2/WebAuthn relying party server with the python-fido2 library, covering registration and authentication ceremonies, YubiKey enrollment, resident key (discoverable credential/passkey) workflows, and user verification policies. Use when implementing phishing-resistant MFA with hardware security keys, building a WebAuthn relying party, enrolling YubiKeys for a workforce, or migrating password-based authentication to passkeys.
17 -
gabrielmoreira Bundle Performing Bandwidth Throttling Attack SimulationSimulate bandwidth throttling and network degradation attacks using tc, iperf3, and Scapy in authorized lab environments to test QoS controls, application resilience, and monitoring detection of traffic manipulation. Use when validating how VoIP, video, or other real-time applications and network monitoring tools respond to degraded bandwidth or slowloris-style throttling attacks.
17 -
gabrielmoreira Bundle Performing Threat Landscape Assessment For SectorConducts a sector-specific threat landscape assessment (financial, healthcare, energy, government, etc.) by profiling targeting threat actors, mapping attack vectors and MITRE ATT&CK TTPs with the attackcti/pandas Python stack, and analyzing exploited CVEs and incident trends from ISAC and vendor reports. Use when producing CTI for risk management or board-level reporting on an industry's threat exposure.
17 -
gabrielmoreira Bundle Testing API For Broken Object Level AuthorizationTests REST and GraphQL APIs for Broken Object Level Authorization (BOLA/IDOR, OWASP API1:2023) by intercepting API calls, identifying object ID parameters (numeric IDs, UUIDs, slugs), and systematically substituting IDs belonging to other users to check whether the server enforces per-object authorization. Use when asked to test BOLA or IDOR in an API, verify object-level authorization, or assess an API for access control bypass.
17 -
gabrielmoreira Skill Performing Macos Privilege EscalationEscalating from a low-privileged user (or unprivileged process) to root on macOS during authorized engagements by abusing the user-preserved sudo PATH, Dock/app masquerading, sudo-password phishing, AuthorizationExecuteWithPrivileges helpers, vulnerable privileged XPC/LaunchDaemon helpers, writable LaunchDaemon plists, PackageKit/zsh logic bombs, kernel credential races, and Time Machine snapshot mounts.
17 -
gabrielmoreira Skill Building Soc Metrics And Kpi TrackingBuilds SOC performance metrics and KPI tracking dashboards measuring Mean Time to Detect (MTTD), Mean Time to Respond (MTTR), alert quality ratios, analyst productivity, and detection coverage using SIEM data. Use when SOC leadership needs operational visibility, continuous improvement tracking, or executive-level reporting on security operations effectiveness.
17 -
gabrielmoreira Skill Correlating Security Events In QradarCorrelates security events in IBM QRadar SIEM using AQL (Ariel Query Language), custom rules, building blocks, and offense management to detect multi-stage attacks across network, endpoint, and application log sources. Use when SOC analysts need to investigate QRadar offenses, build correlation rules, or tune detection logic for reducing false positives.
17 -
gabrielmoreira Skill Testing For Regex Dos RedosTesting web applications for Regular Expression Denial of Service (ReDoS), where crafted input forces a backtracking regex engine into super-linear (polynomial or exponential) processing time, hanging worker threads and causing denial of service. Also covers blind regex injection for char-by-char secret exfiltration when the attacker controls the pattern. Activates when input is matched against complex validators or when stored regex rules are attacker-influenced.
17 -
gabrielmoreira Skill Platform Architecture AnalyzeAnalyze a Salesforce project against the Salesforce Well-Architected framework (Trusted / Easy / Adaptable). Use when the developer asks to "review the architecture", "run a Well-Architected check", "audit this project", "is this project well-architected?", "assess security/governor-limit/packageability risk across the project", or wants a holistic code-and-metadata health report. Grades the criteria that are observable from code and metadata (sharing/FLS, bulkification, selective SOQL, trigger-handler separation, legacy tech, packageability) with file:line evidence, and emits a human checklist for governance/process pillars it cannot see (security matrix, BCP, roadmaps, AI governance). Distinct from `dx-code-analyzer-run` (single-tool Code Analyzer scan of Apex) — this skill is a multi-pillar architectural review that orchestrates several analysis skills and maps findings to Well-Architected. Read-only: it grades and advises, never edits.
17 -
gabrielmoreira Skill Container Security AuditorAudit container security auditor operations. Auto-activating skill for Security Advanced. Triggers on: container security auditor, container security auditor Part of the Security Advanced skill category. Use when analyzing or auditing container security auditor. Trigger with phrases like "container security auditor", "container auditor", "container".
17 -
gabrielmoreira Skill Encryption At REST CheckerValidate encryption at rest checker operations. Auto-activating skill for Security Advanced. Triggers on: encryption at rest checker, encryption at rest checker Part of the Security Advanced skill category. Use when working with encryption at rest checker functionality. Trigger with phrases like "encryption at rest checker", "encryption checker", "encryption".
17 -
gabrielmoreira Bundle Eu AI Act Report Oliver Schmidt PrietzGenerates a formal, structured AI Act compliance assessment report suitable for legal files, audit trails, and regulatory inquiries. This skill should be used when the user asks to "generate an AI Act report", "create a compliance assessment report", "document the AI Act analysis", "create a Prüfbericht", "export as Word document", or wants to consolidate prior AI Act skill outputs into a formal documented assessment.
17 -
gabrielmoreira Bundle Detecting Dns Exfiltration With Dns Query AnalysisDetect data exfiltration via DNS tunneling (tools like iodine, dnscat2, dns2tcp) by analyzing query entropy, subdomain length, query volume to single domains, TXT/CNAME/NULL record abuse, and oversized response payloads using passive DNS monitoring and statistical/ML methods. Use when hunting for covert DNS-based data exfiltration or building a passive DNS anomaly detection capability.
17 -
gabrielmoreira Bundle Implementing Network Access Control With Cisco IseDeploys Cisco Identity Services Engine (ISE) as a RADIUS policy server for 802.1X wired and wireless authentication, MAC Authentication Bypass, posture assessment, dynamic VLAN assignment, downloadable ACLs, and TrustSec Security Group Tags. Use when deploying enterprise NAC with ISE and Active Directory integration, enforcing endpoint posture compliance, or segmenting access with TrustSec instead of a generic 802.1X/PacketFence setup.
17 -
gabrielmoreira Bundle Performing Log Analysis For Forensic InvestigationCollect, parse, and correlate system, application, and security logs to reconstruct events and establish timelines during forensic investigations.
17 -
gabrielmoreira Bundle Performing Malware Hash Enrichment With VirustotalEnrich malware file hashes (MD5, SHA-1, SHA-256) using the VirusTotal API v3 to retrieve multi-engine detection rates, sandbox behavioral analysis, YARA rule matches, related indicators, and community threat intelligence. Use during SOC triage, incident response, or threat intelligence workflows to validate whether a file hash is malicious and gather context for IOC enrichment.
17 -
gabrielmoreira Skill Analyzing Security Logs With SplunkLeverages Splunk Enterprise Security and SPL (Search Processing Language) to investigate security incidents through log correlation, timeline reconstruction, and anomaly detection. Covers Windows event logs, firewall logs, proxy logs, and authentication data analysis. Activates for requests involving Splunk investigation, SPL queries, SIEM log analysis, security event correlation, or log-based incident investigation.
17 -
gabrielmoreira Skill Collecting Indicators Of CompromiseSystematically collects, categorizes, and distributes indicators of compromise (IOCs) during and after security incidents to enable detection, blocking, and threat intelligence sharing. Covers network, host, email, and behavioral indicators using STIX/TAXII formats and threat intelligence platforms. Activates for requests involving IOC collection, indicator extraction, threat indicator sharing, compromise indicators, STIX export, or IOC enrichment.
17 -
gabrielmoreira Skill Bypassing Macos Gatekeeper Tcc And SipAssessing and bypassing macOS userland and platform security controls during authorized engagements - Gatekeeper/quarantine notarization checks, the TCC (Transparency, Consent & Control) privacy database, System Integrity Protection (SIP/rootless), and the App Sandbox - using codesign, spctl, xattr, sqlite3 against TCC.db, csrutil, sandbox-exec, and AppleEvents/Automation abuse.
17 -
gabrielmoreira Skill Detecting Lateral Movement With ZeekDetect lateral movement in network traffic using Zeek (formerly Bro) log analysis. Parses conn.log, smb_mapping.log, smb_files.log, dce_rpc.log, kerberos.log, and ntlm.log to identify SMB file transfers, NTLM account spray activity, remote service execution, and anomalous internal connections.
17 -
gabrielmoreira Skill Analyzing Windows Event Logs In SplunkAnalyzes Windows Security, System, and Sysmon event logs in Splunk to detect authentication attacks, privilege escalation, persistence mechanisms, and lateral movement using SPL queries mapped to MITRE ATT&CK techniques. Use when SOC analysts need to investigate Windows-based threats, build detection queries, or perform forensic timeline analysis of Windows endpoints and domain controllers.
17
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include snowflake-governance-coverage-auditor, security-benchmark-runner, supervisor-banners. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.