Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
abelrguezr Bundle Printnightmare HardeningWindows Print Spooler security hardening and PrintNightmare vulnerability remediation. Use this skill whenever the user mentions Print Spooler security, PrintNightmare, CVE-2021-1675, CVE-2021-34527, CVE-2021-34481, CVE-2022-21999, SpoolFool, Windows printer vulnerabilities, or needs to harden Windows systems against Print Spooler attacks. Also trigger for domain controller hardening, RPC printer service security, or when users ask about disabling the Print Spooler service.
-
abelrguezr Bundle Jinja2 SstiGenerate Jinja2 Server-Side Template Injection (SSTI) payloads and bypass techniques for web application security testing. Use this skill whenever you need to test for template injection vulnerabilities in Flask/Jinja2 applications, generate RCE payloads, bypass WAF filters, or enumerate template sandbox escapes. Trigger this skill for any web pentesting task involving Python templating engines, Flask applications, or when you suspect SSTI vulnerabilities.
-
abelrguezr Bundle Iframe Xss Csp PentestHow to test for iframe-based XSS, CSP bypasses, and SOP violations. Use this skill whenever the user mentions iframes, cross-site scripting, content security policy, sandbox attributes, credentialless iframes, or wants to test web application security around embedded content. Trigger for any pentesting task involving iframe injection, CSP evasion, or same-origin policy testing.
-
abelrguezr Bundle Ad Cs HardeningActive Directory Certificate Services (AD CS) security assessment and hardening. Use this skill whenever the user mentions AD certificates, certificate authorities, PKI, ESC vulnerabilities, certificate enumeration, or needs to assess/harden AD CS infrastructure. Make sure to use this skill for any AD CS security work, vulnerability assessments, or certificate-related hardening tasks.
-
abelrguezr Bundle Windows Credential ProtectionsCheck and analyze Windows credential protection mechanisms including WDigest, LSA PPL/PP, Credential Guard, RDP RestrictedAdmin, cached credentials, and Protected Users group. Use this skill whenever the user needs to assess Windows security posture, audit credential storage protections, investigate why credential dumping tools like Mimikatz fail, or understand Windows security features that protect against pass-the-hash and credential theft attacks.
-
abelrguezr Bundle Linux Jail EscapeTechniques for escaping from Linux chroot jails, restricted bash shells, and other sandboxed environments. Use this skill whenever you need to break out of a chroot, escape a restricted shell, bypass bash limitations, or escape from Python/Lua sandboxes. Trigger this when you're stuck in a limited environment and need to regain full system access, or when analyzing security controls that rely on chroot or shell restrictions.
-
abelrguezr Bundle Splunk Security AssessmentSecurity assessment skill for Splunk services. Use this skill whenever the user needs to enumerate Splunk installations, assess Splunk security configurations, document Splunk vulnerabilities, or perform authorized penetration testing on Splunk infrastructure. Trigger on mentions of Splunk, port 8090, Splunk Universal Forwarder, Splunkd, or security assessments involving Splunk services.
-
abelrguezr Bundle Android App PentestingAndroid application security testing and pentesting. Use this skill whenever the user needs to analyze Android APKs for security vulnerabilities, perform static or dynamic analysis, bypass SSL pinning, test exported components, extract APKs from devices, or conduct mobile security assessments. Trigger for any Android security testing, APK analysis, ADB operations, Frida instrumentation, or mobile app vulnerability assessment tasks.
-
abelrguezr Bundle Shizuku Android PentestUse this skill for Android security testing, privilege escalation analysis, and system API exploration using Shizuku. Trigger when users mention Android pentesting, security auditing, Shizuku, privileged APIs, ADB debugging, mobile security assessments, device forensics, or any Android device security investigation. This skill helps you leverage Shizuku's shell-level privileges without requiring root access.
-
abelrguezr Bundle IOS Serialization SecuritySecurity testing for iOS object serialization vulnerabilities. Use this skill whenever testing iOS apps for insecure deserialization, NSCoding/NSSecureCoding issues, NSKeyedArchiver/Unarchiver abuse, or Codable implementation flaws. Trigger when the user mentions iOS serialization, archiving, object persistence, NSCoder, or any iOS data encoding security concerns.
-
abelrguezr Bundle HTTP Bypass AuditorHow to audit and test for HTTP 403/401 bypass vulnerabilities. Use this skill whenever the user mentions access control testing, forbidden page bypasses, authentication bypass, 403 errors, 401 errors, HTTP method fuzzing, header manipulation, path traversal testing, or any web security testing involving restricted resources. Make sure to use this skill when users want to test if they can access protected endpoints through various bypass techniques, even if they don't explicitly mention 'bypass' or '403'.
-
abelrguezr Bundle Imagemagick Security HardeningConfigure and audit ImageMagick security policies to prevent RCE and DoS vulnerabilities. Use this skill whenever you need to secure ImageMagick installations, review policy.xml files, harden image processing services, or investigate ImageMagick-related security issues. Trigger this skill for any ImageMagick configuration, policy review, or image processing security task.
-
abelrguezr Bundle Sharepoint PentestHow to enumerate, exploit, and post-exploit Microsoft SharePoint environments. Use this skill whenever the user mentions SharePoint, IIS, ASP.NET web applications, ViewState exploitation, or needs to assess SharePoint security. Make sure to use this skill for any SharePoint-related security assessment, vulnerability testing, or incident response involving SharePoint servers, even if they don't explicitly mention 'SharePoint' but describe IIS/ASP.NET environments with _layouts or _vti_bin paths.
-
abelrguezr Bundle HTTP Header PentestingHow to test and exploit HTTP header vulnerabilities during web security assessments. Use this skill whenever you need to test HTTP headers for security issues, including header injection, cache poisoning, request smuggling, header bypass techniques, or analyzing security headers. Trigger this skill for any web pentesting task involving HTTP headers, proxy manipulation, or header-based attacks—even if the user doesn't explicitly mention "headers" but describes testing web applications, proxies, or security configurations.
-
abelrguezr Bundle Exploit Aspnet ViewstateExploit ASP.NET ViewState deserialization vulnerabilities. Use this skill whenever you need to assess, enumerate, or exploit __VIEWSTATE parameters in ASP.NET applications. This includes discovering MachineKeys, generating payloads with YSoSerial.Net, and handling various .NET version configurations (pre-4.5 and 4.5+). Trigger this skill for any ASP.NET ViewState security assessment, penetration testing, or vulnerability research involving __VIEWSTATE, __VIEWSTATEGENERATOR, or __VIEWSTATEENCRYPTED parameters. Make sure to use this skill when you see ASP.NET applications with ViewState parameters, need to test for deserialization vulnerabilities, or are investigating potential MachineKey exposure.
-
abelrguezr Bundle Connection Pool Timing AttackHow to perform timing-based XSS attacks exploiting browser connection pool limits. Use this skill whenever you need to leak data through timing side-channels, exploit Chrome's 6 concurrent connection limit per origin, perform blind XSS exfiltration, or extract secrets when direct data exfiltration is blocked. Make sure to use this skill for any timing-based attack, connection pool exploitation, or when you need to extract data from a blind XSS scenario where traditional exfiltration methods are blocked.
-
abelrguezr Bundle Service Worker Xss TestingHow to test for service worker vulnerabilities and XSS abuse vectors. Use this skill whenever the user mentions service workers, SW exploitation, push notifications, importScripts abuse, DOM clobbering with service workers, or wants to audit web applications for service worker security issues. This skill helps identify and exploit service worker vulnerabilities including arbitrary JS upload + XSS registration, JSONP manipulation, and importScripts hijacking.
-
abelrguezr Bundle Dsrm CredentialsHow to access and leverage Directory Services Restore Mode (DSRM) credentials on Active Directory Domain Controllers. Use this skill whenever the user mentions DSRM, domain controller local administrator access, Active Directory credential extraction, DC local admin, DsrmAdminLogonBehavior, or any scenario involving accessing the local Administrator account on a domain controller for security testing, penetration testing, or assessment purposes.
-
abelrguezr Bundle Malloc Hook ExploitGuide for exploiting __malloc_hook and __free_hook in binary exploitation challenges. Use this skill when working on CTF pwn challenges involving heap vulnerabilities, malloc/free hook overwrites, tcache poisoning, or Safe-Linking bypasses. Trigger when the user mentions malloc hook, free hook, heap exploitation, glibc hooks, tcache poisoning, or is solving binary exploitation challenges that involve heap memory corruption.
-
abelrguezr Bundle Relro AnalysisAnalyze RELRO (Relocation Read-Only) protections in ELF binaries, check protection status, and understand bypass techniques. Use this skill whenever the user mentions binary protections, ELF analysis, GOT (Global Offset Table), relocation, checksec, readelf, binary exploitation, or security hardening. Trigger for any questions about Partial RELRO, Full RELRO, -z relro, -z now, BIND_NOW, or how to check/enable RELRO in compiled binaries.
-
abelrguezr Bundle Ret2dlresolve ExploitHow to craft ret2dlresolve exploits for binary exploitation challenges. Use this skill whenever the user mentions ret2dlresolve, dl_runtime_resolve, GOT/PLT manipulation, binary exploitation without syscall gadgets, CTF pwn challenges without libc leaks, or needs to call system() in a binary without Full Relro. Trigger for any binary exploitation task involving dynamic linking, symbol resolution, or when standard ROP/syscall techniques aren't available.
-
abelrguezr Bundle Mutation Testing SolidityRun mutation testing on Solidity smart contracts using slither-mutate to find bugs your tests don't catch. Use this skill whenever you need to validate test suite quality, audit smart contract tests, or improve test coverage beyond line/branch metrics. Trigger when users mention mutation testing, slither-mutate, test quality, smart contract testing, or want to verify their tests actually assert correct behavior.
-
abelrguezr Bundle Rabbitmq PentestPentest RabbitMQ Management interfaces on port 15672. Use this skill whenever you need to assess RabbitMQ security, test default credentials, enumerate via the management API, publish messages to queues, or crack RabbitMQ authentication hashes. Trigger this for any RabbitMQ exposure, AMQP service testing, or when you see port 15672 open.
-
abelrguezr Bundle Debug Client Side JSHow to debug client-side JavaScript during XSS and web application security testing. Use this skill whenever you need to analyze JavaScript behavior, set persistent breakpoints, or debug JS code that changes with URL parameters. Essential for XSS testing, JavaScript vulnerability analysis, and understanding client-side logic. Make sure to use this skill when investigating client-side vulnerabilities, analyzing JavaScript execution flow, or when breakpoints keep resetting due to URL changes.
-
abelrguezr Bundle Xss PentestingCross-Site Scripting (XSS) vulnerability testing and exploitation. Use this skill whenever the user mentions XSS, cross-site scripting, web security testing, JavaScript injection, reflected XSS, stored XSS, DOM XSS, WAF bypass, or any web application security assessment involving script injection. Make sure to use this skill for any XSS-related testing, payload crafting, or vulnerability analysis.
-
abelrguezr Bundle Ad Password SprayingActive Directory password spraying and brute force methodology for authorized security assessments. Use this skill when conducting penetration tests, red team operations, or security audits on Active Directory environments where you have explicit written authorization. Covers password policy enumeration, spraying techniques with various tools (NetExec, kerbrute, Rubeus, SpearSpray), SAMR password change exploitation, and OWA/Google/Okta spraying. Make sure to use this skill whenever the user mentions password spraying, credential testing, AD brute force, or needs to enumerate valid credentials in an AD environment.
-
abelrguezr Bundle Msi WrapperCreate MSI installer wrappers for Windows privilege escalation and persistence. Use this skill when you need to wrap executables or batch files in MSI installers for authorized penetration testing, security assessments, or red team operations on Windows systems. Trigger this skill for any request involving MSI packaging, ExeMSI configuration, or Windows installer-based privilege escalation techniques.
-
abelrguezr Bundle Gnu Obstack ExploitHow to exploit GNU obstack function-pointer hijacking vulnerabilities. Use this skill whenever the user mentions obstack, GNU obstack, chunkfun, freefun, heap exploitation, libc leaks, function pointer hijacking, or binary exploitation involving allocator state corruption. This skill covers size_t desync primitives, OOB pointer writes, libc base leaking, and fake obstack construction for arbitrary code execution.
-
abelrguezr Bundle Webrtc Dos TestingSecurity testing skill for WebRTC DoS vulnerabilities involving race conditions between ICE consent verification and DTLS handshake. Use this skill whenever you need to test WebRTC media servers for the null cipher suite vulnerability, analyze WebRTC security configurations, or implement mitigations for DTLS handshake attacks. Trigger this skill for any WebRTC security assessment, media server hardening, or when investigating WebRTC-related DoS issues.
-
abelrguezr Bundle Bash Restriction BypassTechniques for bypassing Linux shell restrictions, WAF filters, and command injection defenses. Use this skill whenever you need to execute commands in restricted environments, bypass input validation, work around shell limitations, or understand how attackers might evade security controls. Trigger this for any task involving command obfuscation, restricted shell access, WAF bypass, security testing of input validation, or penetration testing scenarios where standard commands are blocked.
-
abelrguezr Bundle Android Burp Cert InstallHow to install Burp Suite CA certificates on Android devices for traffic interception during mobile security testing. Use this skill whenever you need to set up SSL/TLS interception on Android, configure proxy settings, install CA certificates on rooted or non-rooted devices, or handle Android 14+ APEX certificate challenges. Make sure to use this skill when the user mentions Android pentesting, Burp certificate installation, mobile security testing, SSL interception, or any Android device configuration for traffic analysis.
-
abelrguezr Bundle IOS Pentesting Without JailbreakiOS application security testing without requiring a jailbroken device. Use this skill whenever the user needs to pentest iOS apps, analyze mobile applications, perform dynamic instrumentation on iOS, or investigate iOS app security. This includes tasks like obtaining decrypted IPAs, patching entitlements for get_task_allow, enabling Developer Mode, running Frida/objection hooks, or using MobSF for automated analysis. Trigger this skill for any iOS security assessment, mobile app penetration testing, or iOS reverse engineering work.
-
abelrguezr Bundle Svn PentestPentest Subversion (SVN) servers on port 3690. Use this skill whenever you need to enumerate, exploit, or assess SVN repositories - whether you see port 3690 open, find svn:// or svn+ssh:// URLs, discover mod_dav_svn over HTTP(S), or need to extract credentials from version control systems. This skill covers anonymous access testing, credential brute-forcing, CVE exploitation (CVE-2024-46901, CVE-2024-45720), and secret extraction from repos.
-
abelrguezr Bundle Checkpoint Firewall ReconReconnaissance and vulnerability assessment for Check Point Firewall-1 systems. Use this skill whenever the user needs to enumerate Check Point firewalls, discover firewall/management station hostnames via port 264, or assess HTTP Security Server format string vulnerabilities (CAN-2004-0039). Trigger on mentions of Check Point, CP, Firewall-1, port 264, SecuRemote, or firewall enumeration tasks.
-
abelrguezr Bundle Rdp Session AbuseHow to abuse RDP sessions for lateral movement and pivoting in authorized penetration testing. Use this skill whenever the user mentions RDP sessions, remote desktop pivoting, session injection, RDPInception, or needs to test RDP security in an Active Directory environment. This skill covers finding RDP-accessible machines, injecting into RDP processes, accessing mounted drives via tsclient, and pivoting to external domains through RDP sessions.
-
abelrguezr Bundle Pie ExploitationHow to exploit Position Independent Executable (PIE) binaries by leaking addresses and calculating offsets. Use this skill whenever the user mentions PIE binaries, position-independent executables, address randomization, ASLR bypass, binary exploitation, CTF challenges with PIE, or needs to calculate base addresses from leaked addresses. Make sure to use this skill for any binary exploitation task involving memory addresses, even if the user doesn't explicitly mention PIE.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include printnightmare-hardening, jinja2-ssti, iframe-xss-csp-pentest. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.