Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
abelrguezr Bundle Stack Shellcode ExploitCreate stack shellcode exploits for binary exploitation challenges. Use this skill whenever the user mentions buffer overflow, stack overflow, shellcode, ret2shellcode, EIP/RIP overwrite, pwntools exploitation, or needs to write an exploit that executes arbitrary code via stack-based vulnerabilities. Also trigger for Windows x64 ROP chains with VirtualAlloc to bypass NX/DEP protections.
-
abelrguezr Bundle Ids Ips EvasionIDS/IPS evasion techniques for network security testing and penetration testing. Use this skill whenever the user mentions IDS evasion, IPS bypass, network security testing, firewall evasion, packet manipulation, TTL manipulation, fragmentation attacks, checksum tricks, or any scenario where they need to test or bypass intrusion detection/prevention systems. This includes authorized penetration testing, security assessments, red team operations, and network security research.
-
abelrguezr Bundle Lpd PentestingHow to pentest Line Printer Daemon (LPD) services on port 515/tcp. Use this skill whenever you need to assess printer security, test LPD/LPRng implementations, enumerate printer services, or exploit LPD vulnerabilities. Trigger this skill for any task involving port 515, printer exploitation, LPRng testing, network printer security assessments, or when you discover an LPD service during reconnaissance.
-
abelrguezr Bundle PHP Ssrf TestingHow to identify and test for PHP Server-Side Request Forgery (SSRF) vulnerabilities. Use this skill whenever the user mentions PHP, SSRF, server-side request forgery, file_get_contents, WordPress remote functions, CRLF injection, or needs to test for vulnerabilities in PHP applications that make HTTP requests. Make sure to use this skill when analyzing PHP code for security issues, reviewing WordPress plugins/themes, or testing web applications for SSRF attack vectors.
-
abelrguezr Bundle Ssi Esi InjectionDetect and exploit Server Side Inclusion (SSI) and Edge Side Inclusion (ESI) injection vulnerabilities in web applications. Use this skill whenever you're doing web pentesting, testing for file inclusion vulnerabilities, cache poisoning attacks, or when you encounter .shtml/.shtm/.stm files, Surrogate-Control headers, or need to test for SSI/ESI injection points. This skill provides detection payloads, exploitation techniques, and methodology for SSI/ESI vulnerabilities.
-
abelrguezr Bundle Windows Access TokensUse this skill whenever analyzing Windows access tokens, investigating privilege escalation paths, enumerating user tokens, or working with Windows security tokens. Trigger this skill for any Windows security assessment involving token analysis, user privilege enumeration, impersonation scenarios, or when the user mentions access tokens, whoami, runas, token privileges, or Windows authentication mechanisms.
-
abelrguezr Bundle Com HijackingWindows COM hijacking techniques for authorized penetration testing and security research. Use this skill when the user needs to find hijackable COM components, create COM persistence mechanisms, or analyze COM-based attack vectors on Windows systems. This includes finding non-existent COM CLSIDs via ProcMon, hijacking Task Scheduler COM components, and TypeLib moniker hijacking. Always use only in authorized security testing contexts.
-
abelrguezr Bundle Sips Icc Oob Write ExploitHow to understand, test, and detect the macOS sips ICC profile out-of-bounds write vulnerability (CVE-2024-44236). Use this skill whenever the user mentions ICC profiles, sips vulnerability, CVE-2024-44236, macOS image processing exploits, heap corruption in color profiles, or needs to generate malicious ICC test files for security research. Also trigger for YARA rule creation for ICC anomalies, macOS security patching verification, or when analyzing embedded color profile attacks.
-
abelrguezr Bundle Defi Amm Hook Precision AuditAudit Uniswap v4 hooks for precision/rounding vulnerabilities and threshold-crossing exploits. Use this skill whenever the user mentions DeFi AMM security, Uniswap v4 hooks, custom accounting, precision drift, rounding abuse, or wants to analyze/audit DEX hook implementations. Also trigger for Bunni V2-style exploits, LDF vulnerabilities, or when reviewing beforeSwap/afterSwap callbacks with custom math.
-
abelrguezr Bundle Wifi PentestWi-Fi security testing and penetration testing. Use this skill whenever the user mentions Wi-Fi attacks, wireless security testing, WEP/WPA/WPS cracking, Evil Twin attacks, deauthentication, handshake capture, PMKID attacks, WPA Enterprise testing, KARMA/MANA attacks, or any wireless network assessment. This skill covers reconnaissance, attack execution, and credential capture for Wi-Fi networks.
-
abelrguezr Bundle Macos User ManagementHow to enumerate, analyze, and understand macOS user accounts, privilege levels, and external authentication systems. Use this skill whenever the user mentions macOS users, user enumeration, privilege escalation, admin accounts, sudo access, external accounts, or any macOS security assessment involving user management. This includes penetration testing, security audits, system administration, or understanding macOS user privilege structures.
-
abelrguezr Bundle Android Avd PentestHow to set up and configure Android Virtual Devices (AVD) for mobile application security testing. Use this skill whenever the user needs to create Android emulators for testing APKs, wants to configure emulators with proxy settings for traffic interception, needs writable system images for certificate installation, or is doing any mobile pentesting that requires Android emulation. Make sure to use this skill for any Android emulator setup, AVD creation, or mobile app testing scenarios.
-
abelrguezr Bundle Android Insecure Updater AuditAudit Android applications for insecure in-app update mechanisms that could lead to remote code execution. Use this skill whenever you need to assess Android apps for plugin/dynamic feature vulnerabilities, analyze update metadata encryption, identify insecure TLS configurations, or test for RCE via malicious plugin injection. Trigger this skill for any Android security assessment involving app updates, plugin systems, or dynamic code loading.
-
abelrguezr Bundle Android Native ReversingHow to reverse engineer Android native libraries (.so files) for security analysis, malware triage, and vulnerability research. Use this skill whenever you need to analyze, decompile, or instrument Android native code, extract JNI bindings, dump runtime-decrypted libraries, or patch ELF initializers. Make sure to use this skill when you mention Android .so files, native libraries, JNI, Frida instrumentation, ELF analysis, or any Android security/reversing task involving native code.
-
abelrguezr Bundle Livewire Hydration ExploitationExploit Laravel Livewire v3 deserialization vulnerabilities for RCE. Use this skill whenever the user mentions Livewire, Laravel, deserialization attacks, CVE-2025-54068, Livewire snapshots, hydration abuse, or any web application using Livewire v3. Trigger even if the user just says "test this Livewire app" or "check for deserialization" on a Laravel site.
-
abelrguezr Bundle Active Directory Security DescriptorsHow to work with Active Directory security descriptors (SDDL) for penetration testing and security assessments. Use this skill whenever the user mentions security descriptors, SDDL, ACL manipulation, WMI access, WinRM access, hash dumping, DAMP, or any technique related to modifying object permissions in Active Directory. Also trigger when users want to create persistence mechanisms, escalate privileges through ACL changes, or understand how security descriptors store permissions in Windows/AD environments.
-
abelrguezr Bundle IOS Cve 2020 27950 ExploitiOS kernel exploitation for CVE-2020-27950 (mach_msg trailer memory leak). Use this skill whenever the user mentions iOS kernel vulnerabilities, mach_msg exploitation, kernel memory leaks, CVE-2020-27950, or wants to understand/write PoCs for XNU kernel heap-based vulnerabilities. This skill covers the vulnerability mechanics, exploit development, and practical implementation.
-
abelrguezr Bundle Eigrp PentestEIGRP network protocol pentesting and attack methodology. Use this skill whenever the user needs to test EIGRP routing security, perform reconnaissance on EIGRP networks, craft EIGRP packets for route injection, or understand EIGRP attack vectors. Trigger for EIGRP vulnerability assessment, routing protocol security testing, network penetration testing involving Cisco routing protocols, or when analyzing EIGRP traffic for security issues.
-
abelrguezr Bundle Bruteforce Hash Few CharsHow to bruteforce MD5 hashes with partial matching (suffix or prefix attacks). Use this skill whenever the user mentions hash cracking, MD5 bruteforcing, partial hash matching, hash suffix attacks, loose comparison vulnerabilities, or CTF challenges involving hash manipulation. This is for security research, CTF competitions, and understanding hash collision attacks.
-
abelrguezr Bundle Air Keyboard ExploitExploit unauthenticated remote input injection in Air Keyboard iOS app (port 8888) and Android companion (port 55535). Use this skill whenever you need to discover, test, or exploit the Air Keyboard vulnerability on a local network, or when analyzing mobile apps with similar remote control attack surfaces. Also use for network reconnaissance of mobile remote-control utilities, crafting PoC exploits, or documenting findings in pentest reports.
-
abelrguezr Bundle Pentest Jdwp ExploitationExploit exposed Java Debug Wire Protocol (JDWP) services for remote code execution. Use this skill whenever you need to test JDWP vulnerabilities, enumerate Java debug services, or gain access to Java applications with debug ports exposed. Trigger on mentions of JDWP, Java debug ports, port 8000, Java application security testing, or debugging protocol exploitation.
-
abelrguezr Bundle Artifactory PentestingSecurity testing and vulnerability assessment for JFrog Artifactory instances. Use this skill whenever the user mentions Artifactory security, wants to test an Artifactory instance, needs to enumerate Artifactory vulnerabilities, or is doing penetration testing on package repositories. This skill covers reconnaissance, vulnerability identification, exploitation techniques, and post-exploitation for Artifactory.
-
abelrguezr Bundle Cache Poisoning Url DiscrepanciesHow to perform cache poisoning attacks by exploiting URL parsing discrepancies between cache proxies and web servers. Use this skill whenever the user mentions cache poisoning, CDN vulnerabilities, URL parsing issues, proxy discrepancies, or wants to test for cache-related security issues. This skill helps identify when cache servers and origin servers interpret URLs differently, allowing attackers to poison caches with malicious content.
-
abelrguezr Bundle Evil Twin Eap TlsHow to assess EAP-TLS enterprise WiFi for Evil Twin vulnerabilities. Use this skill whenever the user mentions WiFi security assessments, EAP-TLS testing, WPA2/3-Enterprise pentesting, identity leakage, TLS downgrade attacks, or rogue AP testing. This skill covers unauthenticated identity harvesting, TLS 1.3 downgrade exploitation, and Windows supplicant misconfiguration analysis.
-
abelrguezr Bundle Macos Apfs AnalysisAnalyze macOS APFS file system for security research, forensics, or privilege escalation. Use this skill whenever the user mentions APFS, Apple File System, macOS volumes, snapshots, firmlinks, diskutil commands, or needs to understand macOS storage architecture. Trigger for any macOS security analysis, forensic investigation, or system administration task involving file systems, volumes, or storage.
-
abelrguezr Bundle Oracle Tns PentestPentest Oracle TNS Listener on ports 1521-1529. Use this skill whenever the user mentions Oracle database, TNS listener, port 1521, Oracle enumeration, or needs to assess Oracle database security. This includes version detection, SID enumeration, credential testing, and vulnerability assessment. Trigger even if the user doesn't explicitly say "pentest" or "Oracle" but mentions database ports 1521-1529 or Oracle services.
-
abelrguezr Bundle Ajp PentestingPentest Apache JServ Protocol (AJP) services on port 8009. Use this skill whenever the user mentions AJP, Tomcat port 8009, Ghostcat vulnerability, or needs to enumerate/exploit AJP endpoints. This skill covers AJP protocol enumeration, CVE-2020-1938 Ghostcat exploitation, and AJP proxy setup for accessing Tomcat Manager.
-
abelrguezr Bundle Bitcoin Node PentestingHow to enumerate and assess Bitcoin nodes during security assessments. Use this skill whenever the user mentions Bitcoin nodes, cryptocurrency pentesting, ports 8333/18333/38333/18444, or wants to enumerate Bitcoin network infrastructure. This skill covers mainnet, testnet, signet, and regtest Bitcoin node enumeration using Nmap scripts and Shodan queries.
-
abelrguezr Bundle PHP Deserialization PentestPHP deserialization exploitation for pentesting. Use this skill whenever you need to exploit PHP deserialization vulnerabilities, including spl_autoload_register abuse, phpggc gadget chains, PHPUnit PHPT coverage attacks, TCPDF POP chains, html2pdf phar:// exploitation, or GiveWP unauthenticated RCE. Trigger this skill for any PHP deserialization testing, gadget chain construction, or when analyzing PHP applications for unsafe unserialize() calls.
-
abelrguezr Bundle Active Directory Constrained DelegationHow to enumerate and exploit Kerberos Constrained Delegation in Active Directory for privilege escalation. Use this skill whenever the user mentions constrained delegation, S4U2self, S4U2proxy, msDS-AllowedToDelegateTo, TrustedToAuthForDelegation, Kerberos delegation attacks, or any scenario involving service account impersonation in AD environments. Also trigger for Rubeus s4u commands, Impacket getST with altservice, or when investigating delegation-based privilege escalation paths.
-
abelrguezr Bundle Windows Integrity LevelsWindows Integrity Levels analysis and manipulation for security research and privilege escalation assessment. Use this skill whenever the user asks about Windows integrity levels, Mandatory Integrity Control (MIC), process integrity, file integrity levels, or needs to understand how Windows restricts access based on integrity levels. Trigger for questions about checking integrity levels, modifying integrity levels, understanding integrity level restrictions, or analyzing Windows security boundaries.
-
abelrguezr Bundle Stack Pivoting ExploitationHow to exploit stack pivoting vulnerabilities using EBP2Ret, EBP chaining, and other pivot gadgets. Use this skill whenever the user mentions stack pivoting, EBP/RBP manipulation, leave;ret gadgets, pop rsp gadgets, xchg gadgets, or needs to control RSP/ESP in binary exploitation. Also use when dealing with off-by-one vulnerabilities that can modify saved frame pointers, or when standard ROP isn't available but you can control the frame pointer. Make sure to use this skill for any binary exploitation task involving stack pointer manipulation, function epilogue exploitation, or when you need to redirect execution flow through the frame pointer.
-
abelrguezr Bundle Android Frida PentestUse this skill whenever you need to perform dynamic analysis, hooking, or instrumentation on Android applications using Frida. Trigger this for any Android app security testing, reverse engineering, DEX dumping, anti-debugging bypass, runtime manipulation, or mobile pentesting tasks. Make sure to use this skill when the user mentions Android app analysis, Frida, dynamic instrumentation, hooking Java methods, DEX dumping, FLAG_SECURE bypass, or any mobile security testing.
-
abelrguezr Bundle Java Signedobject DeserializationIdentify and analyze Java SignedObject-gated deserialization vulnerabilities, including pre-auth reachability via error handlers. Use this skill whenever investigating Java deserialization issues, analyzing stack traces with SignedObject.getObject() calls, reviewing license/authentication endpoints, or assessing applications that use java.security.SignedObject for serialization. Trigger on mentions of SignedObject, Java deserialization, license validation, signature verification, or CVE-2025-10035 patterns.
-
abelrguezr Bundle Postmessage VulnerabilitiesHow to identify and exploit postMessage vulnerabilities in web applications. Use this skill whenever the user mentions postMessage, cross-origin communication, iframe messaging, event listeners, origin validation, or wants to test for message-based XSS, prototype pollution, or token theft. Trigger for any pentesting task involving JavaScript messaging APIs, cross-origin data flows, or third-party SDK integrations.
-
abelrguezr Bundle Kerberos AuthenticationKerberos authentication analysis and attack methodology for Active Directory environments. Use this skill whenever the user mentions Kerberos, AD authentication, ticket-based auth, Kerberoasting, AS-REP roasting, delegation abuse, golden tickets, or any Kerberos-related security testing. Trigger for pentesting scenarios, security assessments, or when analyzing AD authentication flows.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include stack-shellcode-exploit, ids-ips-evasion, lpd-pentesting. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.