Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
gabrielmoreira Skill Exploiting Reverse Tab NabbingIdentifying and exploiting reverse tabnabbing, where a link opened with target="_blank" without rel="noopener" gives the newly opened (attacker-controlled) page a reference to the originating window via window.opener, allowing it to redirect the original tab to a phishing clone. Activates when assessing user-controllable links, outbound links, or any anchor/window.open that opens new tabs.
17 -
gabrielmoreira Skill Test Quality AnalysisAnalyze test code quality to detect coverage-only tests, test smells, and low-value assertions. Use when asked to "analyze test quality", "find coverage-only tests", "audit our tests", "are these tests valuable", "find test smells", or "which tests should we delete". Scores tests 1-5 on real value and produces prioritized improvement reports.
17 -
gabrielmoreira Skill Lookup Nsg For VnetChecks every subnet in a Virtual Network for an associated Network Security Group, and also inspects each NIC attached to those subnets for NIC-level NSG coverage.
17 -
gabrielmoreira Bundle Validating Authentication ImplementationsValidate authentication mechanisms for security weaknesses and compliance. Use when reviewing login systems or auth flows. Trigger with 'validate authentication', 'check auth security', or 'review login'.
17 -
gabrielmoreira Skill Csrf Protection ValidatorValidate csrf protection validator operations. Auto-activating skill for Security Fundamentals. Triggers on: csrf protection validator, csrf protection validator Part of the Security Fundamentals skill category. Use when working with csrf protection validator functionality. Trigger with phrases like "csrf protection validator", "csrf validator", "csrf".
17 -
gabrielmoreira Skill Https Certificate CheckerValidate https certificate checker operations. Auto-activating skill for Security Fundamentals. Triggers on: https certificate checker, https certificate checker Part of the Security Fundamentals skill category. Use when working with https certificate checker functionality. Trigger with phrases like "https certificate checker", "https checker", "https".
17 -
gabrielmoreira Skill Xss Vulnerability ScannerScan xss vulnerability scanner operations. Auto-activating skill for Security Fundamentals. Triggers on: xss vulnerability scanner, xss vulnerability scanner Part of the Security Fundamentals skill category. Use when working with xss vulnerability scanner functionality. Trigger with phrases like "xss vulnerability scanner", "xss scanner", "xss".
17 -
gabrielmoreira Skill Certificate Lifecycle ManagerManage certificate lifecycle manager operations. Auto-activating skill for Security Advanced. Triggers on: certificate lifecycle manager, certificate lifecycle manager Part of the Security Advanced skill category. Use when working with certificate lifecycle manager functionality. Trigger with phrases like "certificate lifecycle manager", "certificate manager", "certificate".
17 -
gabrielmoreira Bundle Implementing Network Segmentation With Firewall ZonesDesigns and implements network segmentation using firewall security zones, VLANs, inter-zone ACLs, and workload-level microsegmentation to restrict east-west lateral movement and enforce least-privilege access. Use when architecting security zones, writing inter-zone firewall policies, or meeting PCI DSS/HIPAA/NIST 800-53/zero-trust segmentation requirements for dynamic or traditional network environments.
17 -
gabrielmoreira Bundle Implementing Threat Intelligence Lifecycle ManagementBuild out a full CTI program around the six-phase threat intelligence lifecycle (direction, collection, processing, analysis, dissemination, feedback), including defining intelligence requirements, building a collection pipeline, normalizing data, and tracking dissemination feedback. Use when standing up or maturing a threat intelligence program, defining intelligence requirements, or designing collection-to-dissemination workflows for a CTI team.
17 -
gabrielmoreira Bundle Implementing Web Application Logging With ModsecurityConfigure ModSecurity WAF with the OWASP Core Rule Set (CRS) for web application audit logging, tuning SecRuleEngine, SecAuditEngine, and CRS paranoia levels to reduce false positives, and writing custom SecRules for application-specific threats. Use when deploying or tuning a ModSecurity WAF, analyzing audit logs for attack detection, or reducing CRS false positives.
17 -
gabrielmoreira Skill Implementing Usb Device Control PolicyImplements USB device control policies to restrict unauthorized removable media access on endpoints, preventing data exfiltration and malware introduction via USB devices. Use when deploying device control via Group Policy, Intune, or EDR platforms to enforce USB restrictions. Activates for requests involving USB control, removable media policy, device control, or data loss prevention via USB.
17 -
gabrielmoreira Skill Analyzing Macos Persistence And AutostartEnumerating, planting, and hunting macOS persistence and auto-start (ASEP) locations during authorized engagements - LaunchAgents/LaunchDaemons, shell rc files, login items, cron/at/periodic jobs, login/logout hooks, Dock and Terminal/iTerm2 preferences, audio/QuickLook/Spotlight plugins, PAM modules, Authorization plugins, emond, and StartupItems - and mapping each to its trigger, required privilege, and sandbox/TCC implications.
17 -
gabrielmoreira Skill Performing Scada Hmi Security AssessmentPerform security assessments of SCADA Human-Machine Interface (HMI) systems to identify vulnerabilities in web-based HMIs, thin-client configurations, authentication mechanisms, and communication channels between HMI and PLCs, aligned with IEC 62443 and NIST SP 800-82 guidelines.
17 -
gabrielmoreira Skill Implementing Soar Automation With PhantomImplements Security Orchestration, Automation, and Response (SOAR) workflows using Splunk SOAR (formerly Phantom) to automate alert triage, IOC enrichment, containment actions, and incident response playbooks. Use when SOC teams need to reduce manual analyst work, standardize response procedures, or integrate multiple security tools into automated workflows.
17 -
gabrielmoreira Skill Hunting For Command And Control BeaconingDetect C2 beaconing patterns in network traffic using frequency analysis, jitter detection, and domain reputation to identify compromised endpoints communicating with adversary infrastructure.
17 -
gabrielmoreira Skill Performing Threat Hunting With Yara RulesUse YARA pattern-matching rules to hunt for malware, suspicious files, and indicators of compromise across filesystems and memory dumps. Covers rule authoring, yara-python scanning, and integration with threat intel feeds.
17 -
gabrielmoreira Skill Exploiting Os Command InjectionIdentifying and exploiting OS command injection vulnerabilities in web applications where user input is passed to a system shell, leading to arbitrary command execution. Covers in-band, blind, and out-of-band detection across Linux and Windows, separator and filter-bypass variants, and escalation to full RCE.
17 -
gabrielmoreira Skill Detecting Bluetooth Low Energy AttacksDetects and analyzes Bluetooth Low Energy (BLE) security attacks including sniffing, replay attacks, GATT enumeration abuse, and Man-in-the-Middle interception. Uses Ubertooth One and nRF52840 sniffers for packet capture, the bleak Python library for GATT service enumeration, and crackle for BLE encryption cracking. Use when assessing IoT device BLE security, monitoring for BLE-based attacks on wireless infrastructure, or performing authorized BLE penetration testing. Activates for requests involving BLE security assessment, Ubertooth sniffing, GATT enumeration, or BLE replay detection.
17 -
gabrielmoreira Skill Token Waste EliminationAudit and eliminate token waste from cognitive architecture memory files -- instructions, prompts, skills, and agents
17 -
gabrielmoreira Skill Adobe Security BasicsApply Adobe security best practices for OAuth credentials, secret rotation, I/O Events webhook signature verification, and least-privilege scoping. Use when securing API credentials, implementing webhook validation, or auditing Adobe security configuration. Trigger with phrases like "adobe security", "adobe secrets", "secure adobe", "adobe credential rotation", "adobe webhook signature".
17 -
gabrielmoreira Skill Attio Security BasicsSecure Attio API integrations -- token scoping, secret management, scope auditing, webhook signature verification, and rotation procedures. Trigger: "attio security", "attio secrets", "secure attio", "attio API key security", "attio scopes", "attio token rotation".
17 -
gabrielmoreira Skill Replit Data HandlingImplement secure data handling on Replit: PostgreSQL, KV Database, Object Storage, and data security patterns. Use when handling sensitive data, connecting databases, implementing data access patterns, or ensuring secure data flow in Replit-hosted applications. Trigger with phrases like "replit data", "replit database", "replit PostgreSQL", "replit storage", "replit data security", "replit GDPR".
17 -
gabrielmoreira Skill HTTP Header Security AuditExecute http header security audit operations. Auto-activating skill for Security Fundamentals. Triggers on: http header security audit, http header security audit Part of the Security Fundamentals skill category. Use when analyzing or auditing http header security audit. Trigger with phrases like "http header security audit", "http audit", "http".
17 -
gabrielmoreira Skill License Compliance ScannerScan license compliance scanner operations. Auto-activating skill for Security Fundamentals. Triggers on: license compliance scanner, license compliance scanner Part of the Security Fundamentals skill category. Use when working with license compliance scanner functionality. Trigger with phrases like "license compliance scanner", "license scanner", "license".
17 -
gabrielmoreira Skill Password Strength AnalyzerAnalyze password strength analyzer operations. Auto-activating skill for Security Fundamentals. Triggers on: password strength analyzer, password strength analyzer Part of the Security Fundamentals skill category. Use when analyzing or auditing password strength analyzer. Trigger with phrases like "password strength analyzer", "password analyzer", "analyze password strength r".
17 -
gabrielmoreira Skill Security Headers GeneratorGenerate security headers generator operations. Auto-activating skill for Security Fundamentals. Triggers on: security headers generator, security headers generator Part of the Security Fundamentals skill category. Use when working with security headers generator functionality. Trigger with phrases like "security headers generator", "security generator", "security".
17 -
gabrielmoreira Skill Vulnerability Report GeneratorGenerate vulnerability report generator operations. Auto-activating skill for Security Advanced. Triggers on: vulnerability report generator, vulnerability report generator Part of the Security Advanced skill category. Use when working with vulnerability report generator functionality. Trigger with phrases like "vulnerability report generator", "vulnerability generator", "vulnerability".
17 -
gabrielmoreira Bundle Implementing Iso 27001 Information Security ManagementGuides implementation of an ISO/IEC 27001:2022 Information Security Management System (ISMS) end to end: gap analysis and scoping, risk assessment methodology, Annex A control selection, Statement of Applicability (SoA) creation, and continuous improvement. Use when scoping a new ISMS, preparing for ISO 27001 certification or audit, or selecting and documenting Annex A controls for a compliance program.
17 -
gabrielmoreira Skill Detecting Fileless Attacks On EndpointsDetects fileless malware and in-memory attacks that execute entirely in RAM without writing persistent files to disk, evading traditional antivirus. Use when building detections for PowerShell-based attacks, reflective DLL injection, WMI persistence, and registry-resident malware. Activates for requests involving fileless malware detection, in-memory attacks, PowerShell exploitation, or living-off-the-land techniques.
17 -
gabrielmoreira Skill Analyzing Network Traffic For IncidentsAnalyzes network traffic captures and flow data to identify adversary activity during security incidents, including command-and-control communications, lateral movement, data exfiltration, and exploitation attempts. Uses Wireshark, Zeek, and NetFlow analysis techniques. Activates for requests involving network traffic analysis, packet capture investigation, PCAP analysis, network forensics, C2 traffic detection, or exfiltration detection.
17 -
gabrielmoreira Skill Analyzing IOS App Security With ObjectionPerforms runtime mobile security exploration of iOS applications using Objection, a Frida-powered toolkit that enables security testers to interact with app internals without jailbreaking. Use when assessing iOS app security posture, bypassing client-side protections, dumping keychain items, inspecting filesystem storage, and evaluating runtime behavior. Activates for requests involving iOS security testing, Objection runtime analysis, Frida-based iOS assessment, or mobile runtime exploration.
17 -
gabrielmoreira Skill Analyzing Network Flow Data With NetflowParse NetFlow v9 and IPFIX records to detect volumetric anomalies, port scanning, data exfiltration, and C2 beaconing patterns. Uses the Python netflow library to decode flow records, builds traffic baselines, and applies statistical analysis to identify flows with abnormal byte counts, connection durations, and periodic timing patterns.
17 -
gabrielmoreira Skill Analyzing Network Traffic With WiresharkCaptures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations on authorized network segments.
17 -
gabrielmoreira Skill Exploiting Bgp Hijacking VulnerabilitiesAnalyzes and simulates BGP hijacking scenarios in authorized lab environments to assess route origin validation, RPKI deployment, and BGP monitoring defenses against prefix hijacking and route leak attacks on internet routing infrastructure.
17 -
gabrielmoreira Skill Monitoring Scada Modbus Traffic AnomaliesMonitors Modbus TCP traffic on SCADA and ICS networks to detect anomalous function code usage, unauthorized register writes, and suspicious communication patterns. The analyst uses deep packet inspection with pymodbus, Scapy, and Zeek to baseline normal PLC/RTU communication behavior, then applies statistical and rule-based anomaly detection to identify reconnaissance, parameter manipulation, and denial-of-service attacks targeting Modbus devices on port 502. Activates for requests involving Modbus traffic analysis, SCADA network monitoring, ICS anomaly detection, PLC security monitoring, or OT network threat detection.
17
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include performing-threat-hunting-with-yara-rules, implementing-iso-27001-information-security-management, exploiting-reverse-tab-nabbing. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.