Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
abelrguezr Bundle Large Bin AttackHow to exploit the Large Bin Attack vulnerability in glibc heap management. Use this skill whenever the user mentions heap exploitation, large bins, glibc vulnerabilities, binary exploitation challenges, or needs to overwrite arbitrary addresses in libc. Trigger for CTF challenges involving heap corruption, when global_max_fast manipulation is needed, or when the user asks about heap-based arbitrary write primitives.
-
abelrguezr Bundle Afp PentestPentest Apple Filing Protocol (AFP) services on port 548. Use this skill whenever you need to enumerate, exploit, or assess AFP file sharing services, Netatalk daemons, NAS appliances (QNAP, Synology, WD, TrueNAS), or legacy macOS file servers. Trigger for any AFP-related tasks including vulnerability scanning, brute-force testing, Netatalk CVE exploitation (CVE-2022-23121, CVE-2018-1160, CVE-2022-22995), or defensive hardening recommendations.
-
abelrguezr Bundle Epp PentestingPentest EPP (Extensible Provisioning Protocol) servers used for domain name management. Use this skill whenever the user mentions EPP, domain registrar testing, port 700, TLD security, registry vulnerabilities, or wants to assess domain name system infrastructure. This skill covers enumeration, XXE/SSRF exploitation, mTLS bypass testing, and domain hijacking attack paths.
-
abelrguezr Bundle Rpcbind PentestingHow to enumerate and exploit RPCBind/Portmapper services (port 111) during network penetration testing. Use this skill whenever you're scanning a target and find port 111 open, or when you need to enumerate RPC services, NFS shares, or NIS domains. Trigger this skill for any RPC-related reconnaissance, NFS exploitation, NIS password extraction, or when port 111 appears filtered but you suspect RPC services are running.
-
abelrguezr Bundle Cgi PentestingHow to test and exploit CGI vulnerabilities in web applications. Use this skill whenever the user mentions CGI scripts, ShellShock, Perl web scripts, .cgi endpoints, Apache CGI modules, or wants to test for command injection in web forms. This includes testing centralized CGI dispatchers, old PHP CGI vulnerabilities, and HTTP header-based attacks. Make sure to use this skill for any web pentesting task involving CGI endpoints, even if the user doesn't explicitly mention "CGI" but describes symptoms like parameter injection in web forms or unusual HTTP header behavior.
-
abelrguezr Bundle Git PentestHow to exploit exposed .git directories in web applications. Use this skill whenever the user mentions .git exposure, git directory dumping, git secrets, git-based pentesting, or wants to extract sensitive data from exposed version control. Make sure to use this skill for any web app security testing where .git folders might be accessible, even if the user doesn't explicitly mention 'git' - they might just say 'exposed directory' or 'download repo from web'.
-
abelrguezr Bundle Jsp Contextpath AbuseHow to exploit JSP getContextPath() vulnerabilities for XSS and link manipulation attacks. Use this skill whenever you're pentesting Java web applications with JSP files, when you find JSP endpoints that might be vulnerable to context path manipulation, or when you need to craft XSS payloads through URL path injection. Trigger this skill for any Java web app assessment involving JSP, servlets, or context path-based vulnerabilities.
-
abelrguezr Bundle Cache Poisoning PentestWeb cache poisoning and cache deception testing for security assessments. Use this skill whenever the user mentions cache vulnerabilities, CDN security, web cache poisoning, cache deception, HTTP caching issues, or wants to test for cache-related vulnerabilities in web applications. This includes testing for unkeyed inputs, header manipulation, path traversal cache attacks, and extension-based cache deception.
-
abelrguezr Bundle Csrf TestingCross-Site Request Forgery (CSRF) vulnerability testing and exploitation. Use this skill whenever the user mentions CSRF, cross-site request forgery, form submission attacks, session hijacking, web security testing, or needs to test web applications for CSRF vulnerabilities. Trigger for any request involving CSRF token bypass, CSRF PoC generation, or CSRF defense analysis.
-
abelrguezr Bundle Pentest DappsHow to pentest decentralized applications (DApps). Use this skill whenever the user mentions DApps, Web3 applications, blockchain applications, smart contracts, or wants to audit/penetrate test any decentralized application. This includes NFT platforms, DeFi protocols, cross-chain bridges, and any application that interacts with blockchain technology. Make sure to use this skill when the user asks about Web3 security, DApp vulnerabilities, or blockchain application testing.
-
abelrguezr Bundle Deserialization PentestHow to identify and exploit insecure deserialization vulnerabilities across PHP, Python, NodeJS, Java, .NET, and Ruby. Use this skill whenever the user mentions deserialization, serialization, object injection, gadget chains, ysoserial, pickle, unserialize, ObjectInputStream, BinaryFormatter, Marshal, or any related vulnerability testing. Make sure to use this skill for any web application security testing involving serialized data, ViewState parameters, cookies with serialized objects, or when analyzing code for deserialization sinks.
-
abelrguezr Bundle Web Vulnerability MethodologyComprehensive web vulnerability assessment methodology and checklist. Use this skill whenever the user mentions web pentesting, vulnerability assessment, security testing, bug bounty hunting, web application security, OWASP testing, or any security audit of web applications. This skill provides a systematic approach to finding vulnerabilities across all attack vectors including proxies, user input, authentication, file handling, APIs, frameworks, and more. Make sure to use this skill for any web security testing task, even if the user doesn't explicitly mention 'pentesting' or 'vulnerability assessment'.
-
abelrguezr Bundle Tcache ExploitationHow to identify and exploit Tcache bin attacks in heap vulnerabilities. Use this skill whenever the user mentions heap exploitation, tcache, malloc, free, heap overflow, double free, use-after-free, libc leaks, malloc_hook, free_hook, or any heap-related binary exploitation challenge. This skill covers Tcache poisoning, Tcache index attacks, and common CTF patterns for Glibc 2.26+.
-
abelrguezr Bundle IOS PentestingiOS application security testing and pentesting. Use this skill whenever the user needs to test iOS apps for security vulnerabilities, analyze IPA files, perform static/dynamic analysis, check data storage security, test local authentication, or conduct mobile security assessments. Make sure to use this skill for any iOS security testing, app analysis, vulnerability assessment, or mobile pentesting tasks, even if the user doesn't explicitly mention 'pentesting' or 'security testing'.
-
abelrguezr Bundle Mongodb PentestSecurity assessment and penetration testing for MongoDB databases. Use this skill whenever the user needs to enumerate MongoDB instances, test for authentication bypass, check for ObjectID prediction vulnerabilities, assess MongoBleed (CVE-2025-14847) exposure, or perform authorized security testing on MongoDB services on ports 27017/27018. Trigger for any MongoDB security assessment, vulnerability scanning, or penetration testing task.
-
abelrguezr Bundle Whois PentestingPerform WHOIS enumeration and security testing on port 43 services. Use this skill whenever you need to enumerate domain/IP/ASN registration data, test WHOIS services for vulnerabilities, follow referral chains, or compare WHOIS vs RDAP data. Trigger this skill for any task involving WHOIS queries, domain registration lookups, IP allocation data, or testing legacy WHOIS infrastructure for injection vulnerabilities or rogue server abuse.
-
abelrguezr Bundle X11 PentestingPerform X11 (X Window System) security assessments and exploitation on port 6000. Use this skill whenever the user mentions X11, port 6000, X Window System, graphical interface pentesting, or needs to enumerate/exploit unauthenticated X11 access. This includes checking for anonymous connections, capturing screenshots, keylogging, remote desktop viewing, and obtaining shells through X11 vulnerabilities.
-
abelrguezr Bundle Jira Confluence PentestSecurity assessment and penetration testing for Jira and Confluence instances. Use this skill whenever the user needs to enumerate Jira/Confluence privileges, test for known vulnerabilities (CVE-2023-22527, CVE-2023-22515, CVE-2024-21683), assess plugin security, or perform reconnaissance on Atlassian products. Trigger on requests about Jira security, Confluence pentesting, Atlassian vulnerability scanning, privilege enumeration, or RCE testing against these platforms.
-
abelrguezr Bundle Wsgi PentestingUse this skill for WSGI/uWSGI post-exploitation attacks including magic variable exploitation, SSRF-to-uWSGI pivots via gopher protocol, and backdoor deployment. Trigger when the user mentions WSGI, uWSGI, uwsgi protocol, magic variables, UWSGI_FILE, SSRF to backend, or needs to exploit WSGI misconfigurations for RCE.
-
abelrguezr Bundle Cookie Bomb AnalysisAnalyze, detect, and understand cookie bomb attacks for security assessments. Use this skill whenever the user mentions cookie attacks, HTTP request size issues, DoS via cookies, browser cookie limits, or needs to test for cookie-based denial of service vulnerabilities. Trigger for any pentesting task involving HTTP headers, cookie manipulation, or request smuggling scenarios.
-
abelrguezr Bundle Xssi Cross Site Script InclusionHow to detect and test for Cross-Site Script Inclusion (XSSI) vulnerabilities in web applications. Use this skill whenever you're doing web application security testing, penetration testing, or vulnerability assessment and need to check for XSSI issues. This includes testing for static JavaScript exposure, dynamic JavaScript with authentication, JSONP callback hijacking, and non-script file inclusion attacks. Make sure to use this skill when reviewing JavaScript endpoints, JSONP implementations, or any scenario where scripts might be loaded from different origins.
-
abelrguezr Bundle Vectored Overloading Pe InjectionWindows PE injection technique using Vectored Exception Handlers (VEHs) and hardware breakpoints to disguise malicious code as legitimate DLLs. Use this skill when analyzing or implementing Vectored Overloading attacks, investigating VEH-based evasion techniques, understanding how attackers bypass kernel-level telemetry by hijacking the Windows loader, or when you need to detect this technique in security tools. Trigger this skill for any questions about VEH injection, hardware breakpoint exploitation, module overloading, or Windows loader manipulation.
-
abelrguezr Bundle Tls CertificatesParse, analyze, and convert X.509 certificates and TLS-related files. Use this skill whenever the user mentions certificates, TLS, SSL, X.509, PEM, DER, PKCS#12, PKCS#7, certificate parsing, certificate validation, or anything related to cryptographic certificates and trust chains. Also use when users need to inspect certificate fields, convert between formats, or understand certificate security issues.
-
abelrguezr Bundle Macos KeychainAnalyze and enumerate macOS Keychain entries for security assessments. Use this skill whenever you need to inspect keychain contents, understand ACL permissions, extract credentials, or perform keychain security analysis on macOS systems. Make sure to use this skill when the user mentions keychain, macOS credentials, password extraction, ACL analysis, or any macOS security assessment involving stored secrets.
-
abelrguezr Bundle Pptp PentestingHow to enumerate and pentest PPTP (Point-to-Point Tunneling Protocol) services on port 1723. Use this skill whenever the user mentions PPTP, port 1723, GRE protocol, remote access tunneling, or needs to assess PPTP security during authorized penetration testing. This skill covers enumeration, brute force attacks, and known PPTP vulnerabilities.
-
abelrguezr Bundle Nats PentestingPentest NATS message bus and JetStream services. Use this skill whenever you need to enumerate, exploit, or assess NATS servers (port 4222/tcp), capture credentials via DNS hijacking, loot JetStream streams for secrets, or harden NATS deployments. Trigger this skill for any NATS-related security testing, credential harvesting, or message broker assessment tasks.
-
abelrguezr Bundle Rexec PentestingPentest and exploit Rexec (port 512) services. Use this skill whenever you encounter port 512/tcp open during enumeration, need to brute-force rexec credentials, extract credentials from network captures, or exploit legacy r-services. Trigger for any rexec-related tasks including nmap scanning, hydra brute-forcing, credential sniffing, or post-exploitation command execution.
-
abelrguezr Bundle Rsync PentestPentest rsync file sharing services on port 873. Use this skill whenever you need to enumerate, access, or exploit rsync services. Trigger this skill for any rsync-related tasks including module enumeration, authentication testing, file transfer, brute force attacks, or post-exploitation configuration analysis. Make sure to use this skill when you see port 873 open, need to test rsync shares, or want to transfer files via rsync.
-
abelrguezr Bundle Flask PentestingHow to exploit Flask web application vulnerabilities including session cookie manipulation, secret key brute-forcing, and SSRF attacks. Use this skill whenever the user mentions Flask applications, session cookies, web pentesting, SSTI vulnerabilities, or needs to decode/sign/craft Flask session cookies. Make sure to use this skill for any Flask-related security testing, cookie analysis, or web application exploitation tasks.
-
abelrguezr Bundle Jboss PentestSecurity assessment and enumeration of JBoss application servers. Use this skill whenever the user mentions JBoss, JBoss AS, JBoss EAP, or needs to enumerate Java application servers, check for default credentials, find exposed management consoles, or assess JMX vulnerabilities. Trigger for any web application security testing involving JBoss servers, even if the user doesn't explicitly name JBoss but describes Java EE application server assessment.
-
abelrguezr Bundle Nginx PentestAudit and test Nginx servers for common misconfigurations and vulnerabilities. Use this skill whenever you need to assess Nginx security, check for LFI vulnerabilities, test for HTTP request splitting, analyze proxy configurations, or identify dangerous directives. Trigger this skill for any Nginx security assessment, configuration review, or penetration testing task involving Nginx web servers.
-
abelrguezr Bundle Timing Side Channel AttackHow to perform timing-based side-channel attacks using performance.now() to extract hidden data from web applications. Use this skill whenever you need to brute-force secrets, flags, or sensitive data by measuring response time differences. Trigger this when the user mentions timing attacks, performance.now, side-channel extraction, CTF challenges with time-based vulnerabilities, or any scenario where response time correlates with secret data.
-
abelrguezr Bundle Format String ExploitHow to exploit format string vulnerabilities in C programs. Use this skill whenever the user mentions format strings, printf vulnerabilities, sprintf/fprintf issues, GOT overwrites, arbitrary memory read/write, stack leaks, or any C program that takes user input as a format string. Also trigger for CTF challenges involving format string bugs, pwn tasks with printf-family functions, or when analyzing binaries for format string vulnerabilities.
-
abelrguezr Bundle IOS ExploitationiOS exploitation research and analysis. Use this skill whenever the user mentions iOS security, exploit mitigations, kernel/userland heap analysis, PAC/BTI/ASLR/DEP, XNU kernel structures, iOS exploit chains, or any iOS security research task. This skill helps understand iOS hardening mechanisms, analyze kernel heap structures, work with exploitation tools like Ghidra/BinDiff, and understand modern iOS exploit patterns.
-
abelrguezr Bundle Off By One Heap ExploitHow to exploit off-by-one heap overflow vulnerabilities in glibc. Use this skill whenever the user mentions heap exploitation, off-by-one vulnerabilities, glibc heap attacks, tcache poisoning, chunk size corruption, or any scenario where a single-byte write can corrupt heap metadata. Also trigger for CVE-2023-6779, syslog exploits, safe-linking bypasses, or when analyzing heap-based vulnerabilities in CTF challenges or real-world targets.
-
abelrguezr Bundle Stack Overflow ExploitationHow to analyze and exploit stack overflow vulnerabilities in binary programs. Use this skill whenever the user mentions stack overflows, buffer overflows, EIP/RIP control, return address manipulation, CTF binary exploitation, or needs help finding offsets and crafting exploits for vulnerable programs. This includes ret2win, shellcode placement, ROP chains, and analyzing real-world CVEs with stack-based vulnerabilities.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include large-bin-attack, afp-pentest, epp-pentesting. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.