Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
abelrguezr Bundle Bolt Cms PentestingHow to exploit Bolt CMS for Remote Code Execution (RCE) via Twig template injection. Use this skill when pentesting Bolt CMS installations, when you need to check for SSTI vulnerabilities in Bolt CMS, or when you have admin access to a Bolt CMS instance and want to escalate to RCE. This skill covers the complete exploitation chain from admin login to code execution.
-
abelrguezr Bundle Symfony PentestPentest Symfony applications - fingerprint versions, test for known CVEs (CVE-2019-18889, CVE-2025-64500, CVE-2024-51736, CVE-2025-47946, CVE-2026-24739), exploit APP_SECRET disclosure via _fragment, test PATH_INFO bypass, check for exposed .env files, debug routes, and common misconfigurations. Use this skill whenever the user mentions Symfony, PHP frameworks, web application security testing, or needs to assess a Symfony-based application (Drupal, Shopware, Ibexa, OroCRM all embed Symfony components).
-
abelrguezr Bundle Werkzeug Debug ExploitExploit Werkzeug/Flask debug console vulnerabilities for RCE. Use this skill whenever you encounter a Flask/Werkzeug application with debug mode enabled, need to bypass the console PIN protection, or want to exploit the Unicode request smuggling vulnerability. Trigger this skill for any Flask debug console attacks, PIN generation, or when you see /console endpoints in web pentesting.
-
abelrguezr Bundle Ruby JSON PollutionUse this skill whenever you're testing Ruby on Rails applications for deserialization vulnerabilities, JSON parsing issues, or authorization bypasses involving the _json parameter. Trigger this when you see JSON endpoints, Rails controllers, or need to test for parameter pollution attacks. Make sure to use this skill for any web application security testing involving Ruby backends, especially when dealing with JSON request bodies, API endpoints, or authorization checks.
-
abelrguezr Bundle Url Length ExploitExploit browser URL length limits (Chrome's 2MB limit) to leak secrets character-by-character. Use this skill whenever you need to extract hidden data from URLs, CTF challenges involving URL-based secrets, or when you suspect a target is vulnerable to URL length overflow attacks. This is especially useful for CTF writeups, pentesting web applications, or when you encounter challenges with URL-based secret leakage. Make sure to use this skill when you see URL-based secret challenges, CTF writeups mentioning URL limits, or any scenario where you need to extract data through URL manipulation.
-
abelrguezr Bundle Dom Invader AssistantUse this skill whenever the user needs help with DOM Invader in Burp Suite for detecting DOM XSS, prototype pollution, DOM clobbering, or other client-side vulnerabilities. Trigger when users mention Burp Suite's DOM Invader, want to test for DOM-based vulnerabilities, need help with canary injection, postMessage testing, or client-side security testing. Make sure to use this skill for any Burp Suite DOM security testing questions.
-
abelrguezr Bundle Javascript Hoisting XssJavaScript hoisting-based XSS attack techniques. Use this skill whenever the user is testing for XSS vulnerabilities, JavaScript injection, RXSS (Reflected XSS), or any scenario where they need to exploit JavaScript hoisting to bypass errors, inject code before declarations, or manipulate execution order. Trigger on mentions of hoisting, ReferenceError bypass, TypeError bypass, JS injection, or when analyzing JavaScript code for injection points.
-
abelrguezr Bundle Active Directory LapsUse this skill whenever you need to enumerate, read, or exploit LAPS (Local Administrator Password Solution) in Active Directory environments. Trigger when the user mentions LAPS, local admin passwords, AD computer objects, ms-mcs-AdmPwd, LAPS password enumeration, or any AD password management scenario. This skill covers checking LAPS status, reading LAPS passwords, finding delegated permissions, and persistence techniques.
-
abelrguezr Bundle Linux Privilege Escalation ChecklistUse this skill whenever you need to enumerate Linux privilege escalation vectors, check for local privilege escalation opportunities, or systematically assess a Linux system for privilege escalation paths. Trigger this when you have shell access to a Linux system and want to find ways to escalate from a low-privilege user to root. Also use this when analyzing a Linux system for security assessments, penetration testing, or when you've gained initial access and need to find privilege escalation vectors.
-
abelrguezr Bundle IOS Universal Links PentestPentest iOS Universal Links by extracting entitlements, fetching apple-app-site-association (AASA) files, and identifying misconfigurations like over-broad paths, missing server validation, and wildcard subdomains. Use this skill whenever the user mentions iOS app security, universal links, deep links, AASA files, associated domains, or wants to test mobile app link handling vulnerabilities.
-
abelrguezr Bundle Java Rmi PentestingPentest Java RMI (Remote Method Invocation) services on ports 1090, 1098, 1099, 1199, 4443-4446, 8999-9010, 9999. Use this skill whenever the user mentions Java RMI, RMI registry, remote method invocation, JMX RMI, or needs to enumerate/exploit Java RMI services. This skill covers enumeration with remote-method-guesser, method signature bruteforcing, deserialization attacks, and known vulnerability checks.
-
abelrguezr Bundle Cisco Smart Install ExploitExploit Cisco Smart Install vulnerability (CVE-2018-0171) on port 4786 to exfiltrate device configurations. Use this skill whenever the user mentions Cisco switches, Smart Install, port 4786, CVE-2018-0171, or wants to extract configurations from Cisco network equipment during authorized penetration testing.
-
abelrguezr Bundle Rtsp PentestingHow to enumerate and test RTSP (Real Time Streaming Protocol) services on ports 554/8554. Use this skill whenever you need to assess RTSP cameras, streaming servers, or media services, check for authentication vulnerabilities, enumerate RTSP endpoints, or access video streams. Trigger this for any RTSP-related security testing, camera pentesting, or streaming service assessment, even if the user doesn't explicitly mention RTSP but describes testing IP cameras, surveillance systems, or video streaming services.
-
abelrguezr Bundle Snmp Rce ExploitationExploit SNMP services with write-accessible community strings to achieve remote code execution. Use this skill whenever you need to test SNMP security, enumerate SNMP services, inject commands via NET-SNMP-EXTEND-MIB, or gain shell access through SNMP misconfigurations. Trigger this for any SNMP pentesting task, especially when you have or suspect write-accessible community strings.
-
abelrguezr Bundle Ispconfig PentestHow to exploit CVE-2023-46818 and related vulnerabilities in ISPConfig hosting control panels. Use this skill whenever the user mentions ISPConfig, hosting control panel pentesting, CVE-2023-46818, language editor exploitation, or needs to test for PHP code injection in ISPConfig 3.2.x or 3.3.x. This skill provides automated exploit scripts, manual exploitation steps, and hardening guidance for ISPConfig security assessments.
-
abelrguezr Bundle Roundcube PentestExploit Roundcube webmail vulnerabilities and recover credentials. Use this skill whenever you need to test Roundcube installations, exploit CVE-2025-49113 authenticated RCE, decrypt Roundcube session data, or recover IMAP passwords from compromised Roundcube servers. Trigger this for any Roundcube-related pentesting, webmail exploitation, or post-exploitation credential recovery tasks.
-
abelrguezr Bundle Wordpress PentestPerform comprehensive WordPress security assessments including enumeration, vulnerability testing, and exploitation. Use this skill whenever the user needs to assess WordPress security, test for common WordPress vulnerabilities, enumerate WordPress sites, check for outdated plugins/themes, test XML-RPC attacks, or perform any WordPress-related penetration testing. Make sure to use this skill for any WordPress security testing, even if the user doesn't explicitly mention 'pentest' or 'security assessment'.
-
abelrguezr Bundle Macos Mdm ResearchResearch and analyze macOS Mobile Device Management (MDM) and Device Enrollment Program (DEP) configurations, enrollment processes, and security implications. Use this skill whenever investigating MDM implementations, analyzing device enrollment flows, researching MDM attack vectors, or documenting MDM security findings. Trigger on any mention of MDM, DEP, mobile device management, configuration profiles, SCEP, or Apple device enrollment.
-
abelrguezr Bundle Android Adb PentestingAndroid ADB pentesting and device exploration. Use this skill whenever the user needs to interact with Android devices via ADB, including connecting to devices, managing packages, transferring files, capturing screens, analyzing logs, or performing backup/restore operations. Trigger for any Android device testing, mobile security assessment, or ADB command execution tasks.
-
abelrguezr Bundle Adb PentestAndroid Debug Bridge (ADB) pentesting and exploitation. Use this skill whenever the user mentions ADB, Android debugging, port 5555, mobile device exploitation, Android security testing, wireless debugging, or any scenario involving connecting to Android devices for security assessment. This includes enumeration, privilege escalation, data extraction, payload delivery, and pivoting through ADB. Trigger even if the user doesn't explicitly say "ADB" but describes connecting to an Android device, accessing mobile services, or testing Android security.
-
abelrguezr Bundle Echo Service PentestingHow to identify, test, and document echo services (port 7 TCP/UDP) during network security assessments. Use this skill whenever you're scanning networks, analyzing open ports, or investigating unusual service behavior. Trigger this skill when you see port 7 open, need to verify echo service behavior, want to understand echo service security implications, or are documenting network reconnaissance findings. Don't forget to use this skill even if you're just curious about what an echo service is or how it works.
-
abelrguezr Bundle Prestashop PentestHow to exploit PrestaShop vulnerabilities including XSS-to-RCE escalation and account takeover attacks. Use this skill whenever the user mentions PrestaShop, e-commerce security testing, PrestaXSRF, CVE-2025-61922, ps_checkout module vulnerabilities, or needs to test PrestaShop installations for security issues. This skill covers exploitation techniques for PrestaShop 8.X.X and 1.7.X.X versions.
-
abelrguezr Bundle Lfi2rce PHP FiltersExploit Local File Inclusion (LFI) vulnerabilities in PHP applications using filter chains to achieve Remote Code Execution (RCE). Use this skill whenever the user mentions LFI, file inclusion, PHP filters, php://filter, or wants to exploit PHP vulnerabilities to read files or execute code. Also trigger for requests about php://temp, iconv filters, base64 encoding tricks, or PHP filter chain generation.
-
abelrguezr Bundle Javascript Execution Xs LeakHow to perform JavaScript execution XS (cross-site) leak attacks for security testing. Use this skill when you need to extract data from a target through JavaScript execution patterns, especially when dealing with XSS vulnerabilities that can communicate with parent windows or external endpoints. Make sure to use this skill whenever the user mentions XSS data exfiltration, JavaScript-based data leaks, cross-origin communication attacks, or needs to extract secrets/flags through JavaScript execution.
-
abelrguezr Bundle PDF Injection PentestPDF injection vulnerability testing and exploitation. Use this skill whenever you need to test for PDF injection vulnerabilities, craft PDF injection payloads, analyze PDF structures for injection points, or assess PDF generation libraries for security issues. Trigger this skill for any task involving PDF security, PDF XSS, PDF-based SSRF, or when reviewing code that generates PDFs from user input. Don't forget to use this skill even if the user just mentions "PDF security" or "PDF vulnerabilities" without explicitly asking for injection testing.
-
abelrguezr Bundle Xss Data ExfiltrationGenerate JavaScript payloads for XSS data exfiltration during authorized penetration testing. Use this skill whenever you need to extract sensitive data (cookies, page content, internal ports) from a compromised browser context through various channels (images, XHR, fetch, beacon, location). This is for security testing only - ensure you have explicit authorization before using these techniques.
-
abelrguezr Bundle Dcsync AssessmentActive Directory DCSync attack methodology for security assessments. Use this skill when testing AD environments for DCSync vulnerabilities, analyzing replication permissions, or documenting DCSync attack paths. Trigger when users mention DCSync, AD replication attacks, secretsdump, Mimikatz dcsync, or need to enumerate/assess DCSync permissions in authorized penetration testing scenarios.
-
abelrguezr Bundle Heap First Fit UafExploit first-fit heap vulnerabilities in glibc by creating overlapping chunks through unsorted bin splitting. Use this skill whenever the user mentions heap exploitation, use-after-free, glibc malloc, unsorted bins, tcache, CTF challenges involving memory corruption, or needs to create overlapping memory regions. Make sure to use this skill for any heap-based vulnerability analysis, even if the user doesn't explicitly mention 'first-fit' or 'unsorted bin'.
-
abelrguezr Bundle IOS Protocol HandlersiOS WebView Protocol Handler security testing. Use this skill whenever the user mentions iOS app security, URL schemes, custom protocol handlers, deep links, intent hijacking, or WebView vulnerabilities. This skill helps enumerate, test, and exploit iOS protocol handler vulnerabilities including URL scheme hijacking, deep link injection, and data exfiltration through custom schemes.
-
abelrguezr Bundle Perl Modperl Rce HunterUse this skill whenever analyzing Perl code for command injection vulnerabilities, especially in Apache mod_perl handlers, web applications with Perl backends, or when hunting for RCE through shell execution sinks like backticks, qx//, system(), or open() with pipes. Trigger this skill for any security review of Perl web code, pentesting Perl-based applications, or when investigating potential pre-auth RCE in mod_perl environments.
-
abelrguezr Bundle Rocket Chat PentestUse this skill when pentesting Rocket.Chat installations and you have admin access. This skill helps you exploit the webhook JavaScript execution feature to achieve Remote Code Execution (RCE). Trigger this skill when the user mentions Rocket.Chat, Rocket Chat, or wants to test Rocket.Chat security, especially if they have admin credentials or are doing authorized security assessments.
-
abelrguezr Bundle Ruby Rails PentestRuby on Rails and Ruby application security testing. Use this skill whenever you're pentesting Ruby applications, Rails apps, or need to check for Ruby-specific vulnerabilities like file upload RCE, Active Storage exploits, Rack middleware issues, ReDoS attacks, cookie forgery, or log injection. Trigger this for any Ruby/Rails security assessment, vulnerability research, or when analyzing Gemfile.lock for vulnerable versions.
-
abelrguezr Bundle Heap Freed Chunk ExploitationHow to exploit heap vulnerabilities that allow overwriting freed chunks. Use this skill whenever the user mentions heap exploitation, use-after-free, double-free, heap overflow, off-by-one overflow, freed chunk manipulation, tcache attacks, fastbin attacks, or any binary exploitation involving heap memory management. This skill covers techniques to overwrite pointers in freed chunks for exploitation.
-
abelrguezr Bundle Windows Seh ExploitHow to exploit Windows SEH-based stack overflows in 32-bit processes. Use this skill whenever the user mentions SEH overflow, structured exception handler exploitation, Windows x86 buffer overflow, nSEH/SEH overwrites, or needs to craft an exploit for a 32-bit Windows application with SEH chain corruption. This skill covers finding exact offsets, selecting POP POP RET gadgets, implementing jump-back techniques, handling bad characters, and delivering payloads over HTTP.
-
abelrguezr Bundle Python Web RequestsUse this skill whenever you need to make HTTP requests in Python, interact with web APIs, test web applications, or automate web interactions. This includes GET/POST requests, file uploads, session management, JSON APIs, security testing, and web application exploitation. Make sure to use this skill when the user mentions HTTP requests, API calls, web scraping, penetration testing, or any Python code that needs to communicate with web services.
-
abelrguezr Bundle Ldso Privesc CheckerCheck for ld.so library path privilege escalation vulnerabilities. Use this skill whenever the user mentions ld.so, library paths, /etc/ld.so.conf, ldconfig, shared library vulnerabilities, or wants to audit Linux systems for library loading misconfigurations. This skill helps identify writable paths in ld.so configuration that could allow privilege escalation through malicious library injection.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include bolt-cms-pentesting, symfony-pentest, werkzeug-debug-exploit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.