Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
pramoddutta Skill Dependency Vulnerability ScannerAutomated scanning of project dependencies for known vulnerabilities using tools like npm audit, Snyk, and Dependabot patterns.
-
tonone-ai Skill Warden ReconSecurity reconnaissance — full inventory of secrets management, IAM, dependencies, auth, encryption, audit logging, and compliance gaps. Use when asked about "security posture", "how secure is this", or "security assessment".
-
tryboy869 Bundle Neo4j[Applies to: **/*] This guide defines the definitive best practices for writing Cypher queries and modeling data in Neo4j, ensuring readability, performance, and security for all team projects.
-
tryboy869 Bundle Nginx[Applies to: **/*] This guide defines the definitive NGINX configuration best practices for our team, focusing on modularity, security, performance, and maintainability.
-
tryboy869 Bundle Redis[Applies to: **/*] This guide provides definitive, actionable best practices for using Redis effectively, focusing on data modeling, performance, security, and cluster-aware client usage to build robust and scalable applications.
-
tonone-ai Skill Onboard AuditAudit the developer onboarding experience — measure TTFC and find friction points. Use when asked "why do developers drop off", "audit our onboarding", or "measure time to first call".
-
outlinedriven-odin-claude-plugin Bundle Security HardeningUse when adding security controls for untrusted input, auth/authz, data storage, or external integrations. Not for audit: use security-review. Not for finding: use security-finding-verification.
-
tonone-ai Skill Resp PlaybookWrite an incident response playbook for a threat scenario — detection, containment, eradication, recovery. Use when asked to "write an IR playbook", "build an incident response runbook", or "how do we respond to ransomware".
-
tonone-ai Skill Warden HardenProduce a hardening spec and implement it — auth patterns, security headers, rate limiting, input validation, secrets management, dependency hygiene. Use when asked to "harden this", "add security to this service", "what security do I need", or "secure this before launch".
-
tonone-ai Skill Audit ControlsInternal legal controls review — approval workflows, contract lifecycle, access to sensitive docs. Use when asked to "audit our controls", "review approval workflows", or "who can access sensitive contracts".
-
outlinedriven-odin-claude-plugin Bundle Ssotize Audit FoldUse when asked to find duplication, check consistency, establish or repair SSOT, consolidate facts, or when the user says "consolidate this" or "ssotize this". Not for remote or irreversible changes.
-
outlinedriven-odin-claude-plugin Bundle Build Program GraphUse when a multi-language program graph is needed for call paths, entrypoints, blast radius, or taint reachability. Not for overview (trailmark-structural) or snapshot (trailmark-structural).
-
outlinedriven-odin-claude-plugin Bundle Yara Rule AuthoringUse when writing, reviewing, optimizing, validating, or migrating YARA or YARA-X malware-detection rules, including CRX or DEX rules. Not for network IDS or memory-forensics rules.
-
outlinedriven-odin-claude-plugin Bundle Django Access ReviewUse when reviewing Django or DRF access control, IDOR, authorization, permissions, or tenant isolation. Not for Django query performance: use django-perf-review. No source or remote-system changes.
-
outlinedriven-odin-claude-plugin Bundle Entry Point AnalyzerUse when mapping state-changing external entry points in a smart-contract codebase by access level, auditing access control, or invoking an entry-points command. Read-only. Not for remote mutation.
-
outlinedriven-odin-claude-plugin Bundle Rust Security ReviewUse when asked for a Rust security or correctness audit of a crate, service, or library with unsafe, FFI, concurrency, async, or untrusted-input code. Not for general review: use security-review.
-
tonone-ai Skill Grid ResponsiveAudit or redesign responsive behavior of a layout — breakpoints, reflow, and content priority. Use when asked to "fix responsive behavior", "define breakpoints", or "how should this reflow on mobile".
-
outlinedriven-odin-claude-plugin Bundle Trailmark StructuralUse when a target needs a Trailmark summary of languages, entrypoints, dependencies, or a snapshot of hotspots, taint, blast radius, subgraphs. Not for graph queries: use build-program-graph.
-
outlinedriven-odin-claude-plugin Bundle Semgrep Security ScanUse when a user asks for a Semgrep security scan or fast pattern-based scan of a codebase. Not for authoring or porting rules: use semgrep-rule-authoring.
-
abelrguezr Bundle Crypto Ctf HelperHelp with cryptography challenges for CTFs, security research, and hacking. Use this skill whenever the user mentions crypto, encryption, decryption, hashes, RSA, AES, CTF challenges, cryptographic attacks, or anything related to breaking or analyzing cryptographic systems. This includes recognizing cipher types, identifying vulnerabilities, applying known attacks, and working with crypto primitives.
-
abelrguezr Bundle Audio SteganographyExtract hidden data from audio files using steganography techniques. Use this skill whenever the user mentions audio forensics, hidden messages in audio, spectrogram analysis, WAV file investigation, DTMF tones, modem sounds, or any audio file that might contain concealed data. This includes CTF challenges, security investigations, or any scenario where audio files need to be analyzed for hidden payloads.
-
abelrguezr Bundle Idor Bola TestingHow to find and exploit IDOR (Insecure Direct Object Reference) and BOLA (Broken Object Level Authorization) vulnerabilities in web applications and APIs. Use this skill whenever the user mentions IDOR, BOLA, authorization testing, object-level access control, parameter tampering, user ID enumeration, or wants to test if endpoints properly verify that callers are authorized to access specific objects. Make sure to use this skill for any web security testing involving user IDs, order IDs, file IDs, or any object references in URLs, query parameters, request bodies, or headers.
-
abelrguezr Bundle Word Macro AnalyzerAnalyze and reverse engineer Word macros for security research. Use this skill whenever you need to examine VBA macros in Word documents, identify obfuscation techniques, detect junk code patterns, analyze macro forms for hidden data, or investigate potentially malicious macro behavior. Make sure to use this skill for any Word document macro analysis, VBA code review, or macro security assessment tasks.
-
outlinedriven-odin-claude-plugin Bundle Constant Time AnalysisUse when reviewing cryptographic code for timing side-channels, statically in compiled output or at runtime with statistical timing tests. Not for known-answer vectors: use wycheproof.
-
outlinedriven-odin-claude-plugin Bundle Semgrep Rule AuthoringUse when a vulnerability or pattern and target language need a new Semgrep rule, or an existing rule needs porting to another language. Not for running scans: use semgrep-security-scan.
-
abelrguezr Bundle Stego WorkflowSteganography analysis workflow for CTF challenges and security investigations. Use this skill whenever the user mentions steganography, hidden data, stego files, image analysis, audio forensics, file carving, or needs to find hidden payloads in files. Trigger for any file analysis task where hidden content might be embedded, including images, audio, documents, or suspicious binaries. Make sure to use this skill when users ask about extracting hidden messages, analyzing suspicious files, or solving steganography CTF challenges.
-
abelrguezr Bundle Mythic C2 FrameworkHow to set up and use the Mythic C2 framework for authorized red teaming and security testing. Use this skill whenever the user needs to install Mythic, configure agents (Apollo, Poseidon, etc.), set up C2 profiles, or execute common red team operations like lateral movement, privilege escalation, or credential access. Make sure to use this skill when the user mentions Mythic, C2 frameworks, red teaming, penetration testing, or authorized security assessments involving command and control infrastructure.
-
abelrguezr Bundle 2fa Bypass TestingSecurity testing skill for auditing 2FA/MFA/OTP implementations. Use this skill whenever you need to test two-factor authentication security, audit MFA implementations, check for OTP bypass vulnerabilities, or perform authorized penetration testing on authentication systems. This skill covers direct endpoint access, token manipulation, session hijacking, rate limiting analysis, and other 2FA bypass techniques for security assessments. Make sure to use this skill when the user mentions 2FA testing, MFA security, OTP vulnerabilities, authentication bypass, or any security assessment involving multi-factor authentication.
-
abelrguezr Bundle Crlf Injection PentestHow to test for CRLF (Carriage Return Line Feed) injection vulnerabilities in web applications. Use this skill whenever you need to assess HTTP header injection, response splitting, or newline-based bypasses during web security testing. Trigger this skill when the user mentions CRLF, HTTP header injection, response splitting, newline injection, URL encoding attacks, or any scenario involving user input reflected in HTTP headers. Also use when testing for XSS via header injection, cache poisoning, or SSRF through HTTP request smuggling.
-
abelrguezr Bundle Crypto Symmetric CtfHow to exploit symmetric cryptography vulnerabilities in CTF challenges. Use this skill whenever you encounter encryption, tokens, cookies, crypto challenges, or any CTF task involving AES, CBC, ECB, CTR, GCM, padding oracles, MACs, or stream ciphers. Trigger this for any challenge mentioning encryption modes, ciphertext, IVs, nonces, or authentication tags.
-
abelrguezr Bundle Cors BypassTest for Cross-Origin Resource Sharing (CORS) misconfigurations and bypass vulnerabilities. Use this skill whenever you need to audit web applications for CORS security issues, test Origin header validation, check for credential leakage, or explore DNS rebinding attacks. Trigger this skill for any web security assessment involving cross-origin requests, API security testing, or when investigating potential data exfiltration through CORS. Make sure to use this skill when the user mentions CORS, cross-origin, Origin header, web security testing, API security, or any scenario involving browser-based access to external resources.
-
abelrguezr Bundle Brute Force AssistantUse this skill for authorized penetration testing and security assessments involving brute force attacks, password cracking, and credential testing. Trigger this skill when users need to test authentication systems, crack password hashes, generate custom wordlists, or perform service-specific brute force operations. Make sure to use this skill whenever the user mentions password cracking, hash cracking, brute force testing, credential testing, wordlist generation, or any authentication security assessment, even if they don't explicitly ask for 'brute force'.
-
abelrguezr Bundle Iframe TrapsHow to build iframe trap attacks for XSS exploitation. Use this skill whenever the user mentions XSS, iframe attacks, credential harvesting, payment skimmers, or wants to persist XSS payloads by trapping victims in iframes. Also use when discussing modern navigation API tricks, overlay attacks, or bypassing content blockers with local frames.
-
abelrguezr Bundle Windows Av Edr Defense ResearchUse this skill for Windows AV/EDR defense research, detection engineering, and authorized security assessments. Trigger when users need to understand AV/EDR bypass techniques for building detections, analyzing malware behavior, conducting authorized penetration testing, or researching Windows security mechanisms. This skill covers AMSI, ETW, Defender, PPL, DLL sideloading, and other Windows security features from a defensive perspective.
-
abelrguezr Bundle Ntlm HardeningGuide for understanding NTLM authentication, configuring NTLM security settings, and hardening Windows environments against NTLM-based attacks. Use this skill whenever the user asks about NTLM authentication, LM/NTLMv1/NTLMv2 protocols, Pass-the-Hash attacks, NTLM relay attacks, configuring LMCompatibilityLevel, or Windows authentication security. Also use when users need to parse NTLM challenges from network captures, understand NTLM reflection attacks, or harden systems against credential theft.
-
abelrguezr Bundle Open Redirect PentestDetect and exploit open redirect vulnerabilities in web applications. Use this skill whenever you need to test for open redirect bugs, analyze redirect parameters, bypass URL validation filters, or chain redirects with XSS/SSRF. Trigger this skill for any web security testing involving URL redirects, OAuth flows, login redirects, or when you see parameters like next=, url=, redirect=, return=, dest=, or similar redirect-related inputs.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include crypto-ctf-helper, audio-steganography, idor-bola-testing. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.