Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
abelrguezr Bundle Double Free ExploitationHow to identify, understand, and exploit double-free heap vulnerabilities in C programs. Use this skill whenever the user mentions double-free, heap corruption, memory allocator attacks, fast bin dup, tcache poisoning, or any heap-based vulnerability in C code. Also trigger when users are working on CTF challenges involving heap exploitation, analyzing malloc/free patterns, or debugging memory corruption issues.
-
abelrguezr Bundle Hardware Physical AccessPhysical security testing and hardware attack techniques. Use this skill whenever the user mentions physical access, BIOS/UEFI password recovery, hardware security testing, cold boot attacks, DMA attacks, BadUSB/HID implants, BitLocker bypass, chassis intrusion switches, or IR sensor bypass. Trigger for any physical penetration testing scenario, hardware forensics, or security assessment involving direct device access.
-
abelrguezr Bundle Pentest Hop By Hop HeadersUse this skill whenever testing web applications for HTTP header vulnerabilities, proxy misconfigurations, or when investigating hop-by-hop header handling issues. Trigger this skill for any pentesting task involving HTTP headers, X-Forwarded-For manipulation, cache poisoning, or proxy bypass techniques. Don't forget to use this skill when the user mentions headers, proxies, HTTP security testing, or web application penetration testing.
-
abelrguezr Bundle Esim Javacard SecuritySecurity research and analysis for eSIM/JavaCard vulnerabilities. Use this skill when investigating eUICC security, analyzing Java Card VM type-safety issues, testing for Remote SIM Provisioning (RSP) vulnerabilities, or researching smart card exploitation techniques. Trigger for any queries about eSIM security, Java Card bytecode verification, GSMA TS.48 profiles, or smart card penetration testing.
-
abelrguezr Bundle Macos PersistencemacOS persistence and auto-start location guide. Use this skill whenever the user asks about macOS persistence mechanisms, auto-start locations, launch agents, launch daemons, shell startup files, or any technique for maintaining access on macOS systems. This includes security testing, penetration testing, red teaming, or understanding how malware maintains persistence on macOS. Trigger for questions about launchd, cron, shell rc files, login items, terminal preferences, or any macOS startup/persistence technique.
-
abelrguezr Bundle IOS Pentesting ChecklistComprehensive iOS application security testing checklist. Use this skill whenever you need to pentest an iOS app, perform mobile security assessments, check for iOS vulnerabilities, analyze iOS data storage, test iOS authentication, or audit iOS applications for security issues. This skill covers data storage, keychain, IPC mechanisms, network security, cryptography, and more.
-
abelrguezr Bundle Dns PentestingPerform DNS security assessments and enumeration. Use this skill whenever the user needs to enumerate DNS servers, check for zone transfers, discover subdomains, validate DNSSEC configuration, or assess DNS security posture. Trigger on requests involving DNS reconnaissance, domain enumeration, DNS vulnerability scanning, or any DNS-related security testing.
-
abelrguezr Bundle Irc PentestingPerform IRC (Internet Relay Chat) security testing and enumeration. Use this skill whenever the user mentions IRC, IRC servers, port 6667, IRC channels, IRC operators, or wants to enumerate/test IRC services. Trigger for any IRC-related security assessment, vulnerability scanning, or reconnaissance tasks involving IRC protocols on ports 194, 6667, or 6660-7000.
-
abelrguezr Bundle Ntp PentestPentest NTP (Network Time Protocol) services on port 123/UDP and 4460/TCP. Use this skill whenever you need to enumerate NTP servers, check for monlist vulnerabilities, assess NTS security, or harden NTP configurations. Trigger this for any NTP assessment, time-sync security review, or when you see port 123/UDP open in a scan.
-
abelrguezr Bundle Pop3 PentestingHow to enumerate, test, and exploit POP3 mail servers during security assessments. Use this skill whenever the user mentions POP3, port 110, port 995, email server testing, mail server enumeration, or any task related to testing Post Office Protocol services. This includes banner grabbing, capability enumeration, brute force attacks, and identifying misconfigurations that expose credentials.
-
abelrguezr Bundle Rdp PentestingHow to enumerate, attack, and exploit RDP (Remote Desktop Protocol) services during penetration testing. Use this skill whenever the user mentions RDP, port 3389, remote desktop, Windows remote access, RDP enumeration, RDP brute force, RDP shadowing, session hijacking, or any RDP-related security testing. This skill covers nmap enumeration, credential testing, session stealing, RDP shadowing attacks, virtual channel tunneling, and post-exploitation techniques.
-
abelrguezr Bundle Ssh PentestingSSH/SFTP penetration testing and security assessment. Use this skill whenever the user needs to enumerate SSH services, test for vulnerabilities, check for weak configurations, attempt credential attacks, or assess SSH server security. Trigger on mentions of SSH, port 22, SFTP, remote access, SSH brute force, SSH enumeration, SSH vulnerabilities, or any SSH-related security testing tasks.
-
abelrguezr Bundle JWT PentestHow to assess JWT (JSON Web Token) security vulnerabilities in web applications. Use this skill whenever the user mentions JWT tokens, JSON Web Tokens, token security, authentication bypass, session hijacking, or needs to test JWT implementations for vulnerabilities like signature bypass, algorithm confusion, or key exposure. This skill covers the complete JWT assessment workflow from reconnaissance to exploitation.
-
abelrguezr Bundle Windows Cmd PentestWindows Command Line reference for penetration testing and security assessment. Use this skill whenever the user needs Windows CMD commands for reconnaissance, enumeration, privilege escalation, persistence, or post-exploitation activities. Trigger on requests about Windows pentesting, CMD commands, AD enumeration, system info gathering, or Windows security assessment.
-
abelrguezr Bundle RdpexecExecute commands on remote Windows systems via RDP. Use this skill whenever you need to run commands on a remote Windows machine through Remote Desktop Protocol, including authorized security testing, system administration, or troubleshooting remote Windows systems. Make sure to use this skill when the user mentions RDP, remote desktop, Windows remote access, or needs to execute commands on a remote Windows system.
-
abelrguezr Bundle Scmexec AnalysisAnalyze and understand SCMExec lateral movement techniques for security assessments. Use this skill when investigating Windows lateral movement, reviewing Service Control Manager abuse, analyzing SharpMove or similar tools, or when you need to understand how attackers create services to execute commands on remote systems. This skill helps with threat hunting, incident response, and security assessments involving Windows service-based command execution.
-
abelrguezr Bundle Wmi Lateral MovementWindows Management Instrumentation (WMI) techniques for authorized security testing and lateral movement assessment. Use this skill whenever you need to enumerate Windows systems, query WMI namespaces/classes, execute remote commands via WMI, or assess WMI-based attack vectors during penetration testing. Trigger this skill for any Windows security assessment involving WMI, remote process execution, system enumeration, or lateral movement testing.
-
abelrguezr Bundle Heap Overflow ExploitationHow to identify, analyze, and exploit heap overflow vulnerabilities in binary exploitation challenges and real-world scenarios. Use this skill whenever the user mentions heap overflows, memory corruption, heap grooming, tcache poisoning, fast-bin attacks, or any heap-related vulnerability in CTF challenges, binary analysis, or security research. This skill covers heap overflow fundamentals, exploitation techniques, heap grooming strategies, and real-world CVE analysis.
-
abelrguezr Bundle House Of Lore ExploitHow to perform a House of Lore (small bin attack) heap exploitation. Use this skill whenever the user mentions heap exploitation, small bin attacks, fake chunks, glibc heap vulnerabilities, or needs to insert fake chunks into small bins for arbitrary read/write. Trigger for CTF challenges involving heap corruption, glibc 2.31+ exploitation, or when the user needs to bypass malloc sanity checks using fake chunk linking.
-
abelrguezr Bundle Linux Environment VariablesHow to manage, configure, and secure Linux environment variables. Use this skill whenever the user needs to set, modify, or understand environment variables on Linux systems, configure proxies, hide command history, manage SSL certificates, customize prompts, or troubleshoot variable inheritance issues. Trigger for any task involving export, unset, PATH, proxy settings, HISTCONTROL, or environment variable security.
-
abelrguezr Bundle IOS Pentesting BasicsiOS security architecture and pentesting fundamentals. Use this skill whenever the user mentions iOS security, mobile app pentesting, iOS app analysis, Info.plist inspection, Keychain investigation, data protection classes, sandboxing, or anything related to iOS penetration testing. This skill provides the foundational knowledge needed to understand iOS security mechanisms and how to investigate them during security assessments.
-
abelrguezr Bundle Imap PentestPentest IMAP email servers for vulnerabilities, information disclosure, and credential testing. Use this skill whenever the user mentions IMAP, email server testing, port 143, port 993, email enumeration, or wants to assess email service security. Trigger for any IMAP-related reconnaissance, banner grabbing, authentication testing, or mailbox enumeration tasks.
-
abelrguezr Bundle House Of Force ExploitHow to perform House of Force heap exploitation attacks. Use this skill whenever the user mentions heap exploitation, House of Force, top chunk manipulation, arbitrary memory allocation, malloc manipulation, or wants to allocate chunks at specific addresses. Also trigger for CTF challenges involving heap overflows, top chunk size overwrites, or when the user needs to calculate evil_size for heap attacks. Make sure to use this skill for any binary exploitation task involving glibc heap manipulation, even if they don't explicitly say "House of Force".
-
abelrguezr Bundle House Of Roman ExploitExploit glibc heap vulnerabilities using House of Roman attack for RCE without leaks. Use this skill whenever the user mentions heap exploitation, glibc 2.23-2.27, fastbin attacks, unsorted bin attacks, malloc hook overwrites, or needs to achieve code execution in CTF challenges with old libc versions. Trigger for any heap-based binary exploitation task where the target uses glibc 2.23-2.27 and you need RCE without prior information leaks.
-
abelrguezr Bundle Ethernetip PentestHow to enumerate and pentest EtherNet/IP industrial devices on port 44818. Use this skill whenever the user mentions EtherNet/IP, industrial control systems, Rockwell Automation, PLC devices, or port 44818. Also trigger for ICS/SCADA reconnaissance, factory automation security testing, or when investigating industrial Ethernet protocols. Make sure to use this skill for any pentesting task involving industrial automation networks, even if the user doesn't explicitly name EtherNet/IP.
-
abelrguezr Bundle Bacnet EnumerationEnumerate BACnet devices on building automation networks. Use this skill whenever the user mentions BACnet, building automation, HVAC control systems, port 47808, or needs to discover and enumerate devices on industrial control networks. This skill helps identify BACnet devices, extract device information, and assess building automation security.
-
abelrguezr Bundle File Inclusion PentestSecurity testing skill for identifying and exploiting Local File Inclusion (LFI) and Remote File Inclusion (RFI) vulnerabilities. Use this skill whenever you need to test for path traversal vulnerabilities, file inclusion attacks, PHP wrapper exploitation, or LFI2RCE techniques during security assessments. Trigger this skill when users mention file inclusion, path traversal, LFI, RFI, directory traversal, PHP include vulnerabilities, or need to test for arbitrary file read/write access.
-
abelrguezr Bundle HTTP Connection ContaminationHow to test for HTTP connection contamination vulnerabilities in web applications. Use this skill whenever you need to audit HTTP/2+ connection coalescing, test reverse proxy routing, investigate potential security issues with wildcard TLS certificates, or assess shared infrastructure risks. Make sure to use this skill when you mention HTTP/2, HTTP/3, connection coalescing, reverse proxy misconfiguration, wildcard certificates, or any scenario involving multiple subdomains on shared infrastructure.
-
abelrguezr Bundle House Of Orange ExploitHouse of Orange heap exploitation technique for glibc < 2.26. Use this skill whenever the user mentions heap exploitation, glibc vulnerabilities, malloc_printerr abuse, _IO_FILE structure forgery, or needs to exploit a heap overflow in older libc versions. This skill guides users through the complete House of Orange attack chain including top chunk manipulation, unsorted bin attacks, and fake _IO_FILE structure creation for arbitrary code execution.
-
abelrguezr Bundle House Of Spirit ExploitHouse of Spirit heap exploitation guide. Use this skill whenever the user mentions heap exploitation, fake chunks, tcache poisoning, fastbin attacks, binary exploitation with heap vulnerabilities, or needs to create fake heap chunks for CTF challenges. This skill helps create fake heap chunks that bypass glibc security checks to achieve arbitrary memory allocation.
-
abelrguezr Bundle Reverse Shell GuideGuide for understanding and generating reverse shell payloads in authorized penetration testing and security research. Use this skill when the user needs to create reverse shell payloads for security testing, understand reverse shell concepts, work with MSFVenom, or troubleshoot shell connections. Trigger for any request about reverse shells, payload generation, post-exploitation access, or security testing that involves establishing remote command execution.
-
abelrguezr Bundle Network TunnelingNetwork tunneling and port forwarding techniques for authorized security assessments. Use this skill when you need to pivot through networks, forward ports, create SOCKS proxies, or establish covert channels during penetration testing, red teaming, or security research. Covers SSH tunneling, Meterpreter/Cobalt Strike pivoting, DNS/ICMP tunneling, and modern tools like Chisel, Ligolo-ng, and FRP. Make sure to use this skill whenever the user mentions pivoting, port forwarding, SOCKS proxy, network tunneling, SSH tunnel, or needs to access internal networks through compromised hosts.
-
abelrguezr Bundle IOS Webview PentestUse this skill whenever testing iOS applications for WebView vulnerabilities, analyzing WebView configurations, investigating WebView-based security issues, or performing mobile security assessments on iOS apps. Trigger this skill for any iOS WebView security testing, static analysis of WebView implementations, dynamic analysis with Frida, protocol handler testing, or native method exposure checks.
-
abelrguezr Bundle Finger PentestHow to enumerate and exploit the Finger protocol (port 79) during security assessments. Use this skill whenever you need to enumerate users on a target system, check for finger service vulnerabilities, perform banner grabbing on port 79, or test for command injection and finger bounce attacks. Trigger this skill when the user mentions finger protocol, port 79, user enumeration, or needs to assess finger service security.
-
abelrguezr Bundle Pentesting RloginPentest Rlogin (port 513) services on target systems. Use this skill when you need to test for Rlogin vulnerabilities, attempt unauthorized access via .rhosts files, or enumerate Rlogin services during security assessments. Trigger this skill for any Rlogin-related reconnaissance, authentication testing, or brute force attempts on port 513.
-
abelrguezr Bundle HTTP Response Smuggling DesyncHTTP Response Smuggling and Desync attack testing. Use this skill whenever the user needs to test for HTTP response queue desynchronisation vulnerabilities, wants to steal victim responses, perform cache poisoning, or exploit response splitting. Trigger on requests about HTTP smuggling, response desync, proxy desynchronisation, cache poisoning via HTTP, or stealing other users' responses through HTTP request smuggling.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include double-free-exploitation, hardware-physical-access, pentest-hop-by-hop-headers. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.