Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
abelrguezr Bundle Kerberos Double HopHow to understand and work around the Kerberos double hop authentication problem in Windows environments. Use this skill whenever you need to authenticate across multiple hops in Active Directory, troubleshoot Kerberos authentication failures between servers, set up PowerShell remoting across multiple systems, or work with WinRM/SSH in multi-hop scenarios. This applies to penetration testing, security assessments, and legitimate administrative tasks where you need to chain authentication through intermediate servers.
-
abelrguezr Bundle Windows Acl AnalysisAnalyze and explain Windows Access Control Lists (ACLs), DACLs, SACLs, and ACEs for security auditing, privilege escalation research, permission troubleshooting, or hardening. Use this skill whenever the user mentions Windows permissions, access control, ACLs, DACLs, SACLs, ACEs, file/folder permissions, security descriptors, privilege escalation, or anything related to Windows access control mechanisms. Trigger even if the user doesn't explicitly use these terms but is asking about who can access what on Windows systems.
-
abelrguezr Bundle Slirp Nat Heap ExploitationAnalyze and understand VirtualBox Slirp NAT packet heap exploitation vulnerabilities. Use this skill whenever the user needs to understand Slirp NAT heap corruption, mbuf allocator exploitation, UMA zone hijacking, or similar allocator-based vulnerabilities in network stacks. Also use when analyzing packet buffer overflows, heap grooming techniques, or when creating educational content about VirtualBox security research.
-
abelrguezr Bundle Hadoop PentestHow to enumerate and exploit Apache Hadoop clusters during penetration testing. Use this skill whenever you need to assess Hadoop security, test HDFS/WebHDFS access, exploit YARN RCE vulnerabilities, or check for CVE-2023-26031. Trigger on any mention of Hadoop, HDFS, YARN, MapReduce, distributed data processing security, or when you see ports 50030, 50060, 50070, 50075, 50090, 8088, 8042, 8031, 8032, 9870, 9864, or 14000 in a pentest engagement.
-
abelrguezr Bundle Browser Extension Xss TestingHow to test browser extensions for XSS vulnerabilities including iframe-based XSS, DOM-based XSS, and clickjacking attacks. Use this skill whenever the user mentions browser extension security testing, Chrome extension vulnerabilities, XSS in extensions, web_accessible_resources exploitation, or CSP bypass in extensions. Make sure to use this skill for any pentesting task involving browser extensions, even if the user doesn't explicitly mention XSS.
-
abelrguezr Bundle Active Directory PentestUse this skill whenever you need to enumerate, attack, or escalate privileges in an Active Directory environment. Trigger on any AD-related tasks including reconnaissance, credential attacks, Kerberos abuse, trust exploitation, privilege escalation, or post-exploitation. Make sure to use this skill when the user mentions Active Directory, domain enumeration, Kerberos attacks, AD pentesting, Windows domain security, or any AD attack methodology.
-
abelrguezr Bundle Blockchain Security AnalystExpert guidance on blockchain and cryptocurrency security, privacy mechanisms, and Web3 threat analysis. Use this skill whenever the user asks about blockchain concepts, Bitcoin/Ethereum transactions, privacy attacks, DeFi security, smart contract vulnerabilities, or Web3 red teaming. Trigger for any questions about cryptocurrency privacy, transaction analysis, consensus mechanisms, or blockchain security best practices—even if the user doesn't explicitly mention "security" or "blockchain."
-
abelrguezr Bundle Clipboard Hijacking AnalysisAnalyze clipboard hijacking (pastejacking) attacks, ClickFix campaigns, and IUAM-style verification page lures. Use this skill whenever investigating phishing campaigns that use clipboard manipulation, fake CAPTCHA pages, or social engineering to execute commands via Win+R/Terminal paste. Also use for threat hunting clipboard-based attacks, analyzing pastejacking payloads, or building detection rules for clipboard-to-console attack chains.
-
abelrguezr Bundle Pam HardeningLinux PAM security auditing, backdoor detection, and hardening. Use this skill whenever the user mentions PAM configuration, authentication security, Linux hardening, credential harvesting detection, SSH security, or any post-exploitation concerns related to authentication. Also trigger for security audits, penetration testing, or when investigating suspicious login behavior.
-
abelrguezr Bundle Browser Extension ClickjackingAnalyze browser extensions for clickjacking vulnerabilities. Use this skill whenever you need to audit browser extensions (Chrome, Firefox, Edge) for security issues, review manifest.json files, test web_accessible_resources configurations, or investigate extension-based attacks. Trigger this skill for any pentesting task involving browser extensions, Chrome extensions, Firefox add-ons, or when analyzing extension security, even if the user doesn't explicitly mention 'clickjacking' or 'vulnerability'.
-
abelrguezr Bundle Http2 Request SmugglingHow to identify and exploit HTTP/2 request smuggling vulnerabilities in downgrade scenarios. Use this skill whenever the user mentions HTTP/2, request smuggling, H2.TE, H2.CL, HTTP downgrade attacks, proxy misconfigurations, or wants to test for HTTP/2 to HTTP/1.x translation vulnerabilities. Also trigger for CVE-2023-25690, CVE-2023-25950, CVE-2022-41721, or any HTTP/2 security testing.
-
abelrguezr Bundle Phishing AssessmentHow to conduct authorized phishing assessments and security awareness testing. Use this skill whenever the user mentions phishing campaigns, email security testing, social engineering assessments, credential harvesting simulations, GoPhish configuration, domain impersonation techniques, or security awareness training. Make sure to use this skill for any authorized security testing involving email-based attacks, MFA bypass scenarios, or help-desk social engineering simulations.
-
abelrguezr Bundle Android Debuggable ExploitationUse this skill whenever you need to analyze, test, or exploit debuggable Android applications during authorized security assessments. Trigger this when the user mentions Android app security testing, debuggable APKs, JDWP debugging, bypassing security checks, root detection bypass, or CVE-2024-31317 exploitation. This skill covers making apps debuggable, runtime code injection, and forcing debug mode on non-debuggable apps.
-
abelrguezr Bundle Android Play Store Location SpoofingHow to bypass regional restrictions on Google Play Store during Android app security testing. Use this skill whenever you need to access region-locked Android applications, test geo-restricted app behavior, or install apps unavailable in your current location for security assessment purposes. Trigger this when the user mentions Play Store restrictions, regional app availability, country-locked apps, or needs to test apps from different geographic regions.
-
abelrguezr Bundle Linux ForensicsPerform Linux digital forensics investigations. Use this skill whenever the user needs to investigate a Linux system for security incidents, malware, unauthorized access, or suspicious activity. This includes gathering system information, analyzing logs, checking for persistence mechanisms, examining file systems, recovering deleted files, and documenting findings. Trigger on requests involving Linux forensics, incident response, malware investigation, system compromise analysis, or security auditing of Linux systems.
-
abelrguezr Bundle Ad Certificate EnumerationActive Directory Certificate Services (AD CS) enumeration and vulnerability assessment. Use this skill whenever the user mentions AD certificates, PKI, certificate templates, AD CS, certificate authorities, or wants to enumerate/assess certificate infrastructure in Active Directory environments. Also trigger for requests about Certify, Certipy, certificate exploitation, ESC vulnerabilities, or any AD PKI security assessment.
-
abelrguezr Bundle Cet Shadow StackControl Flow Enforcement Technology (CET) and Shadow Stack analysis for binary exploitation. Use this skill whenever the user mentions CET, shadow stack, control flow integrity, ROP/JOP attacks, binary security protections, or needs to understand how modern CPU features prevent control-flow hijacking. Trigger for security research, binary analysis, exploitation learning, or when discussing hardware-level security mitigations.
-
abelrguezr Bundle Malware AnalysisMalware analysis and reverse engineering toolkit. Use this skill whenever the user needs to analyze suspicious files, extract IOCs, deobfuscate malware, analyze Android APKs, trace Node.js loaders, or perform any malware-related investigation. Trigger on mentions of malware, suspicious executables, PE/ELF analysis, Yara rules, ClamAV, Android malware, obfuscation, control-flow analysis, or any security investigation involving potentially malicious software.
-
abelrguezr Bundle Delivery Receipt Side ChannelHow to execute delivery receipt side-channel attacks on E2EE messengers (WhatsApp, Signal, Threema). Use this skill whenever the user wants to probe messaging protocols for timing leaks, fingerprint devices, monitor user behavior through RTT analysis, or understand silent delivery receipt vulnerabilities. Trigger on any request about messenger security testing, protocol-level reconnaissance, device fingerprinting via messaging apps, or covert channel exploitation.
-
abelrguezr Bundle Macos Objective C AnalysisAnalyze and understand Objective-C code in macOS binaries for security research, reverse engineering, and privilege escalation. Use this skill whenever you need to read Objective-C source code, analyze Mach-O binaries with class-dump, understand iOS/macOS app internals, or work with Objective-C runtime concepts in a security context. Trigger this skill for any macOS binary analysis, Objective-C code review, or when investigating app behavior through class/method inspection.
-
abelrguezr Bundle Android Work Profile BypassAndroid Enterprise Work Profile security testing and bypass techniques. Use this skill whenever the user mentions Android Work Profiles, MDM bypass, Intune required apps, BYOD security testing, CVE-2023-21257, or any scenario involving Android Enterprise device management security assessment. This skill covers reconnaissance, exploitation chains, and post-exploitation opportunities for Work Profile environments.
-
abelrguezr Bundle Dotnet Soap Wsdl ExploitationExploit .NET SOAP/WSDL client proxy vulnerabilities for NTLM relay, arbitrary file writes, and RCE. Use this skill whenever you need to test for SoapHttpClientProtocol abuse, WSDL import vulnerabilities, or HttpWebClientProtocol scheme-agnostic bugs in .NET applications. Trigger this skill for any .NET web service testing, SOAP endpoint analysis, WSDL import functionality, or when investigating Barracuda, Ivanti, Umbraco, PowerShell, or SSIS SOAP-related vulnerabilities.
-
abelrguezr Bundle Ldap HardeningHow to harden Active Directory against LDAP relay attacks using LDAP signing and channel binding. Use this skill whenever the user mentions LDAP security, AD hardening, LDAP signing, channel binding, LDAP relay prevention, Active Directory security, or wants to protect Domain Controllers from MITM/relay attacks. Make sure to use this skill even if they don't explicitly say "hardening" or "security" — if they're asking about LDAP configuration, GPO settings for DCs, or protecting against Kerberos/NTLM relays, this skill applies.
-
abelrguezr Bundle Leaked Handle ExploitationWindows local privilege escalation via leaked handle exploitation. Use this skill whenever the user mentions Windows privilege escalation, handle enumeration, process handle leaks, inherited handles, or needs to escalate from a low-privileged process to SYSTEM/administrator. Also trigger when users ask about Windows security testing, handle-based attacks, or finding privilege escalation vectors in Windows environments.
-
abelrguezr Bundle Lua Sandbox SecuritySecurity research and penetration testing for Lua sandbox environments. Use this skill when analyzing Lua VM security in game clients, embedded applications, or scripting engines. Trigger when users mention Lua sandboxes, embedded Lua, game client security, bytecode exploitation, sandbox escape, or need to enumerate Lua environments for security assessments. Also use when hardening Lua environments or reviewing Lua security configurations.
-
abelrguezr Bundle Macos Firewall Bypass AuditAudit and test macOS firewall configurations for potential bypass vulnerabilities. Use this skill whenever you need to assess macOS firewall security, check for known bypass techniques, enumerate allowed traffic, inspect PF rules, or validate Network Extension filter configurations. This skill helps security professionals identify weaknesses in firewall rules, test for CVE-2024-44206 and other recent vulnerabilities, and harden macOS systems against firewall evasion attacks.
-
abelrguezr Bundle Macos File Extension AppsmacOS security skill for enumerating file extension handlers and URL scheme handlers via LaunchServices database. Use this skill whenever analyzing macOS systems for privilege escalation, investigating default app handlers, auditing file associations, or researching application capabilities. Trigger when users mention file extensions, URL schemes, LaunchServices, default apps, or macOS application handlers.
-
abelrguezr Bundle Android App Virtualization DetectionDetect and analyze Android application-level virtualization (app cloning/container frameworks like DroidPlugin). Use this skill whenever you need to investigate suspicious Android apps, analyze potential app virtualization abuse, check for permission escalation via shared UIDs, or detect stealthy code loading. Trigger this skill for any Android security analysis involving app containers, plugin frameworks, or when you suspect an app is running multiple APKs under a single process.
-
abelrguezr Bundle IOS Custom Uri Handlers PentestiOS security testing for custom URI handlers, deeplinks, and custom schemes. Use this skill whenever testing iOS apps for URL scheme vulnerabilities, deeplink security, custom protocol handling, Info.plist URL configuration, or inter-app communication attacks. Trigger this skill for any iOS pentest involving URL schemes, canOpenURL, LSApplicationQueriesSchemes, URL hijacking, OAuth token theft via custom schemes, or Frida-based URL fuzzing.
-
abelrguezr Bundle Wasm Memory Corruption XssExploit WebAssembly linear memory corruption to bypass XSS filters and achieve DOM XSS. Use this skill whenever the user mentions WebAssembly, WASM, Emscripten, linear memory corruption, memory overflow, heap corruption, XSS bypass, or any scenario where a web app uses WASM modules and sanitization might be bypassed through memory manipulation. This is especially relevant when investigating Emscripten-compiled applications with user-controlled data that gets rendered to the DOM.
-
abelrguezr Bundle Ad Cs PersistenceActive Directory Certificate Services (AD CS) domain persistence techniques for authorized security testing. Use this skill whenever the user needs to maintain long-term access to a compromised Active Directory environment through certificate-based methods. This includes golden certificates, rogue CA trust, malicious misconfigurations, and certificate renewal abuse. Trigger this skill for any AD CS persistence scenario, certificate forgery, NTAuth manipulation, or when the user mentions maintaining access after initial compromise, especially in environments with certificate-based authentication.
-
abelrguezr Bundle Powershell PentestingWindows PowerShell commands and techniques for penetration testing, reconnaissance, and post-exploitation. Use this skill whenever the user needs to perform Windows system enumeration, execute remote payloads, bypass AMSI/Defender, enumerate users/groups, check network configurations, handle credentials, or any other Windows pentesting task involving PowerShell. Trigger for any Windows security assessment, red team operation, or post-exploitation scenario.
-
abelrguezr Bundle Heap Security ChecksReference for libc heap memory function security checks and error messages. Use this skill whenever the user is debugging heap vulnerabilities, analyzing heap exploitation, studying glibc malloc/free internals, or needs to understand what specific heap error messages mean. Trigger on mentions of heap corruption, malloc/free errors, tcache, fastbins, unsorted bins, or any libc heap function security checks.
-
abelrguezr Bundle Linux Arm64 Kaslr BypassHow to bypass KASLR on arm64 Android kernels using the static linear map. Use this skill whenever the user mentions arm64 kernel exploitation, KASLR bypass, Android kernel exploits, physical to virtual address conversion, linear map, memstart_addr, or needs to calculate stable kernel addresses. This is essential for any arm64 Android kernel exploit that needs to patch kernel data structures without leaking the KASLR slide.
-
abelrguezr Bundle Macos Privilege EscalationmacOS privilege escalation techniques and triage. Use this skill whenever the user mentions macOS privilege escalation, privesc, gaining root, escalating privileges on macOS, TCC bypass, LaunchDaemon abuse, XPC vulnerabilities, or any macOS security research involving privilege escalation. Also use when analyzing macOS systems for privilege escalation vectors, reviewing macOS security configurations, or documenting macOS attack paths.
-
abelrguezr Bundle IOS Entitlements ExtractorExtract entitlements and mobile provision files from iOS app binaries (IPA files, compiled apps, or jailbroken device binaries). Use this skill whenever the user needs to analyze iOS app permissions, review embedded entitlements, extract plist data from compiled binaries, or perform iOS security testing. Trigger for any request involving iOS app binary analysis, entitlement extraction, mobile provision file recovery, or MASVS-PLATFORM security testing.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include kerberos-double-hop, windows-acl-analysis, slirp-nat-heap-exploitation. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.