Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
abelrguezr Bundle Archive Extraction Path TraversalSecurity skill for detecting, testing, and mitigating archive extraction path traversal vulnerabilities (Zip-Slip, CVE-2025-8088, etc.). Use this skill whenever the user mentions archives (ZIP, RAR, TAR, 7-ZIP), file extraction, path traversal, zip-slip, archive security, or wants to test archive handling code. Also trigger when users ask about secure archive extraction, vulnerable code patterns, or creating security test cases for archive utilities.
-
abelrguezr Bundle IOS Pasteboard PentestHow to test iOS applications for pasteboard security vulnerabilities. Use this skill whenever you need to analyze iOS app clipboard usage, check for sensitive data exposure via UIPasteboard, or perform static/dynamic analysis of iOS pasteboard implementations. Make sure to use this skill when pentesting iOS apps and you need to check clipboard/pasteboard security, analyze data sharing mechanisms, or look for sensitive information leakage through UIPasteboard.
-
abelrguezr Bundle Ibm Mq PentestingPentest IBM MQ message brokers on port 1414. Use this skill whenever the user mentions IBM MQ, message queues, port 1414, punch-q, pymqi, or needs to enumerate/exploit IBM MQ instances. This skill covers enumeration of queue managers, channels, and queues, plus exploitation techniques including message dumping and remote code execution via PCF commands.
-
abelrguezr Bundle Iscsi PentestingPentest iSCSI (Internet Small Computer Systems Interface) services on port 3260. Use this skill whenever you need to enumerate, authenticate, or mount iSCSI targets during security assessments. Trigger this skill when you see port 3260 open, need to discover iSCSI targets, want to access remote block storage, or are investigating storage vulnerabilities during penetration testing.
-
abelrguezr Bundle Redis PentestingPentest Redis instances (port 6379) for enumeration, authentication bypass, data exfiltration, and RCE. Use this skill whenever the user mentions Redis, port 6379, key-value stores, in-memory databases, or needs to test Redis security. This includes checking for authentication, dumping databases, exploiting misconfigurations, and testing for known CVEs like CVE-2025-49844, CVE-2025-46817, CVE-2025-46818.
-
abelrguezr Bundle Apache PentestingApache web server pentesting and exploitation techniques. Use this skill whenever the user mentions Apache, web server vulnerabilities, .htaccess, mod_rewrite, PHP handlers, CVE-2021-41773, confusion attacks, LFI, RCE, or any Apache-related security testing. This includes checking PHP extensions, exploiting misconfigurations, testing for path traversal, handler confusion, and accessing restricted files.
-
abelrguezr Bundle Django PentestDjango security testing and exploitation. Use this skill whenever the user mentions Django applications, web app pentesting, SSTI vulnerabilities, pickle deserialization, session cookie attacks, or Django-specific CVEs. Trigger for any Django security assessment, vulnerability testing, or exploitation scenarios.
-
abelrguezr Bundle Golang Connect VulnerabilityTest for Go HTTP CONNECT method path normalization bypass vulnerabilities. Use this skill when analyzing Go web applications for path traversal issues, when investigating HTTP CONNECT method handling, or when security testing Go-based servers. This skill helps identify cases where the CONNECT method bypasses standard path normalization that other HTTP methods apply. Make sure to use this skill whenever you're testing Go web servers, investigating path traversal vulnerabilities, or analyzing HTTP method handling in Go applications.
-
abelrguezr Bundle Joomla PentestPentest Joomla CMS installations. Use this skill whenever the user mentions Joomla, wants to enumerate a Joomla site, check for Joomla vulnerabilities, perform brute-force attacks on Joomla, exploit Joomla RCE vulnerabilities, or assess Joomla security. Trigger for any Joomla-related security testing, vulnerability assessment, or penetration testing tasks.
-
abelrguezr Bundle Moodle PentestSecurity assessment and penetration testing for Moodle learning management systems. Use this skill whenever the user mentions Moodle, LMS security, educational platform pentesting, or needs to assess Moodle installations for vulnerabilities. Trigger for any Moodle-related security work including reconnaissance, vulnerability scanning, exploitation, or post-exploitation activities.
-
abelrguezr Bundle Zabbix PentestZabbix security assessment and exploitation. Use this skill whenever the user mentions Zabbix monitoring, CVE-2024-22120, Zabbix SQLi, Zabbix cookie forgery, Zabbix RCE, or any Zabbix-related security testing. Trigger for Zabbix web UI assessment, port 10051/10050 enumeration, session cookie analysis, blind SQLi exploitation, admin privilege escalation, and post-exploitation activities on Zabbix infrastructure.
-
abelrguezr Bundle Lfi2rce PhpinfoHow to exploit Local File Inclusion (LFI) to Remote Code Execution (RCE) using PHPInfo() output. Use this skill whenever you need to escalate LFI vulnerabilities to RCE, especially when phpinfo() pages are accessible, or when you're testing for file inclusion vulnerabilities that could lead to code execution. Make sure to use this skill when you find LFI sinks combined with phpinfo() endpoints, or when you need to convert file inclusion into command execution on PHP applications.
-
abelrguezr Bundle Ntlm Credential TheftTechniques for capturing NetNTLMv2 hashes through Windows authentication coercion. Use this skill whenever the user needs to steal NTLM credentials, capture NetNTLMv2 hashes, perform SMB authentication attacks, exploit writable shares for credential theft, or coerce Windows authentication to an attacker-controlled SMB server. Trigger for any request involving NTLM relay, NetNTLMv2 capture, Windows credential harvesting, SMB lure attacks, or authentication bypass techniques.
-
abelrguezr Bundle Integer Overflow ExploitationHow to identify, analyze, and exploit integer overflow and underflow vulnerabilities in C/C++, Rust, and Go code. Use this skill whenever the user mentions integer overflow, underflow, arithmetic bugs, size calculation vulnerabilities, heap overflow from integer issues, or wants to audit code for numeric type vulnerabilities. Also use when analyzing binary exploitation challenges involving arithmetic operations, buffer size calculations, or memory allocation based on user-controlled numeric input.
-
abelrguezr Bundle Ret2win ExploitHow to solve ret2win CTF challenges by exploiting buffer overflows to call a hidden win function. Use this skill whenever the user mentions ret2win, buffer overflow exploitation, calling a win/flag function, CTF binary exploitation, stack overflow to redirect execution, or any challenge where you need to overwrite a return address to execute a specific function. This applies to 32-bit and 64-bit binaries, with or without ASLR/PIE protections.
-
abelrguezr Bundle Distcc PentestHow to identify and exploit Distcc vulnerabilities on port 3632. Use this skill whenever the user mentions Distcc, port 3632, distributed compilation, or needs to test for CVE-2004-2687. Make sure to use this skill for any network service enumeration that reveals port 3632, or when the user wants to check for remote code execution via Distcc misconfigurations.
-
abelrguezr Bundle Pentest KibanaHow to pentest Kibana instances on port 5601. Use this skill whenever you need to assess Kibana security, enumerate Kibana services, check for authentication bypass, explore Elasticsearch data through Kibana, or identify vulnerabilities in the Elastic Stack. Trigger this skill for any Kibana-related security assessment, port 5601 enumeration, or Elastic Stack penetration testing.
-
abelrguezr Bundle Hsqldb PentestingHow to pentest HSQLDB (HyperSQL Database) services on port 9001. Use this skill whenever the user mentions HSQLDB, port 9001, Java database exploitation, JDBC attacks, or needs to interact with HSQLDB during security assessments. This skill covers connection methods, default credentials, Java Language Routines for system property enumeration, and file writing techniques for reverse shells.
-
abelrguezr Bundle Nfs PentestingPentest NFS (Network File System) services on port 2049. Use this skill whenever the user mentions NFS, network file sharing, port 2049, showmount, nfs exports, or needs to enumerate/mount/exploit NFS shares. This skill helps with NFS enumeration, mounting shares, exploiting misconfigurations like no_root_squash, escaping export directories, and privilege escalation via NFS.
-
abelrguezr Bundle GRAPHQL PentestSecurity testing for GraphQL endpoints. Use this skill whenever you need to test GraphQL APIs for vulnerabilities, enumerate schemas, detect exposed endpoints, or assess security configurations. Trigger this skill for any GraphQL security assessment, penetration testing, or API security review involving GraphQL endpoints.
-
abelrguezr Bundle Laravel PentestLaravel application security testing and exploitation. Use this skill whenever the user mentions Laravel, PHP web application pentesting, APP_KEY exploitation, cookie decryption, deserialization attacks, or any Laravel-specific vulnerability research. This skill covers APP_KEY brute-forcing, cookie forgery, RCE via gadget chains, file upload bypasses, and environment override attacks.
-
abelrguezr Bundle Client Side Template Injection CstiHow to detect and exploit Client Side Template Injection (CSTI) vulnerabilities in web applications. Use this skill whenever the user mentions template injection, AngularJS, VueJS, Mavo, or wants to test for client-side code execution vulnerabilities. Also trigger when users ask about XSS via template engines, JavaScript injection through templates, or when they find double curly braces in web forms that might be processed by a template engine.
-
abelrguezr Bundle Phar DeserializationHow to exploit PHP PHAR deserialization vulnerabilities. Use this skill whenever you need to test for or exploit deserialization vulnerabilities in PHP applications, especially when dealing with file inclusion via phar:// protocol, file operations like file_get_contents(), fopen(), file_exists(), md5_file(), filemtime(), or filesize(). Make sure to use this skill when you find PHP code that processes file paths with phar:// protocol or when you can control file paths in PHP applications.
-
abelrguezr Bundle Cookie TossingHow to identify and exploit cookie tossing vulnerabilities in web applications. Use this skill whenever the user mentions cookie attacks, session manipulation, subdomain cookie control, session fixation, CSRF token manipulation, or wants to test for cookie-related vulnerabilities in web security assessments. Make sure to use this skill for any pentesting task involving cookies, session handling, or subdomain security.
-
abelrguezr Bundle Soap Threadlocal Auth BypassHow to identify and exploit SOAP/JAX-WS ThreadLocal authentication bypass vulnerabilities in Java web services. Use this skill whenever the user mentions SOAP endpoints, JAX-WS handlers, authentication bypass, ThreadLocal, WebLogic, JBoss, GlassFish, or any SOAP-based Java web service security testing. Also trigger when users are investigating SOAP header-based authentication, middleware authentication caching, or Java EE security handler chains. This skill covers reconnaissance, exploitation, and validation of ThreadLocal-based authentication bypass attacks.
-
abelrguezr Bundle Unicode Injection PentestHow to find and exploit Unicode injection vulnerabilities in web applications. Use this skill whenever you're testing for XSS, SQLi, or other injection vulnerabilities and want to try Unicode-based bypass techniques. Trigger this when you encounter input validation, WAF filters, or encoding issues that might be vulnerable to Unicode normalization attacks, emoji injection, or Windows Best-Fit character mapping exploits.
-
abelrguezr Bundle Xss Sniff LeakHow to leak script content using MIME type sniffing vulnerabilities. Use this skill whenever the user mentions XSS, content sniffing, X-Content-Type-Options, leaking JavaScript files, MIME type attacks, or needs to extract script content from a target. Trigger for any web security testing involving script disclosure, even if the user doesn't explicitly mention 'sniffing' or 'MIME type'.
-
abelrguezr Bundle Pyscript PentestPyScript vulnerability assessment and pentesting. Use this skill whenever the user mentions PyScript, Pyodide, browser-based Python, web application security testing, XSS in Python contexts, SSRF via Python libraries, or needs to assess PyScript implementations for security issues. Trigger for any security review, penetration testing, or vulnerability research involving PyScript or Python-in-browser technologies.
-
abelrguezr Bundle Threat ModelingCreate comprehensive threat models for applications and systems using established methodologies like STRIDE, DREAD, and PASTA. Use this skill whenever the user needs to identify security vulnerabilities, assess system risks, create data flow diagrams, or document potential threats and mitigations. Trigger for any request involving security architecture review, vulnerability assessment, attack surface analysis, or security planning for software projects.
-
abelrguezr Bundle Linux Privilege EscalationHow to analyze and exploit Linux privilege escalation through user ID manipulation (ruid, euid, suid). Use this skill whenever the user mentions privilege escalation, SUID binaries, setuid/setreuid/setresuid functions, execve/system calls, or needs to understand how Linux user IDs work in security contexts. Make sure to use this skill for any Linux security analysis involving user identity, privilege boundaries, or binary execution mechanisms.
-
abelrguezr Bundle Macos Red TeamingmacOS red teaming and offensive security operations. Use this skill whenever the user mentions macOS penetration testing, MDM abuse (JAMF, Kandji), Active Directory attacks on macOS, keychain extraction, or any macOS-specific offensive security tasks. This includes scenarios where the user wants to enumerate macOS systems, abuse MDM configurations, extract credentials from keychains, or perform AD-based attacks from macOS hosts.
-
abelrguezr Bundle Android Tapjacking TestTest Android applications for tapjacking vulnerabilities. Use this skill whenever you're doing Android app security testing, pentesting, or analyzing exported activities for clickjacking risks. Trigger when the user mentions tapjacking, clickjacking, overlay attacks, exported activities, or Android UI security testing.
-
abelrguezr Bundle IOS App Extensions PentestiOS app extension security testing. Use this skill whenever the user needs to test iOS app extensions for security vulnerabilities, analyze extension configurations, or perform static/dynamic analysis on iOS app extensions. Trigger for any iOS security testing involving app extensions, custom keyboards, share extensions, Today widgets, or extension-related security assessments. Don't wait for the user to explicitly mention "extensions" - if they're doing iOS app security testing, check for extensions.
-
abelrguezr Bundle Network Services Pentesting RusersdEnumerate usernames from hosts running the rusersd protocol (ports 512-514). Use this skill whenever you need to discover user accounts on a target system, perform network reconnaissance, or when rusersd, rusers, or RPC port mapper services are mentioned. This is a critical enumeration technique for penetration testing and security assessments.
-
abelrguezr Bundle Couchdb PentestPentest CouchDB databases on ports 5984/6984. Use this skill whenever the user mentions CouchDB, document databases, port 5984, port 6984, or needs to enumerate/exploit CouchDB instances. This includes database enumeration, credential testing, privilege escalation, and RCE exploitation.
-
abelrguezr Bundle Fastcgi PentestingPentest FastCGI services (typically port 9000) for enumeration, RCE, and SSRF exploitation. Use this skill whenever you need to test FastCGI/PHP-FPM services, probe for misconfigurations, craft FastCGI payloads for RCE, or leverage SSRF to reach internal FastCGI listeners. Trigger on mentions of FastCGI, PHP-FPM, port 9000, FPM status pages, or when you need to exploit FastCGI misconfigurations.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include archive-extraction-path-traversal, ios-pasteboard-pentest, ibm-mq-pentesting. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.