Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
abelrguezr Bundle Kerberos Ticket HarvestingHow to harvest Kerberos tickets from Windows systems using Mimikatz and Rubeus. Use this skill whenever you need to extract, dump, triage, renew, or convert Kerberos tickets from Windows environments during security assessments, penetration testing, or red team operations. Trigger this skill for any Windows Kerberos ticket manipulation tasks, including lsass memory extraction, ticket export, and offline cracking preparation.
-
abelrguezr Bundle Postmessage Race Condition ExploitHow to exploit postMessage vulnerabilities using race conditions to steal sensitive data from parent pages. Use this skill whenever the user mentions postMessage, iframe exploitation, cross-origin communication vulnerabilities, race conditions in web security, stealing data from parent windows, or any scenario where an iframe needs to intercept messages before the parent page processes them. This is especially useful for CTF challenges, bug bounties, or security assessments involving blob documents, isolated iframes, or message-passing between windows.
-
abelrguezr Bundle Windows Enterprise Ipc ExploitationAnalyze and document Windows local privilege escalation chains in enterprise software (endpoint agents, auto-updaters, driver utilities). Use this skill whenever investigating IPC vulnerabilities, auto-updater hijacking, TOCTOU race conditions, or supply-chain attacks in products like Netskope, ASUS DriverHub, MSI Center, Acer Control Centre, or similar enterprise tools. Also use when creating detection rules for these attack patterns or documenting privilege escalation paths for security assessments.
-
abelrguezr Bundle IOS Backup ForensicsiOS backup forensics for messaging app analysis and 0-click exploit detection. Use this skill whenever investigating iOS devices for spyware, analyzing encrypted backups, extracting messaging attachments (iMessage/WhatsApp/Signal/Telegram/Viber), or scanning for structural file format exploits. Trigger on any iOS forensics task, backup analysis, or mobile device investigation involving Apple devices.
-
abelrguezr Bundle Telecom Network ExploitationTelecom network security assessment and exploitation techniques for GTP, 5G core, and industrial cellular routers. Use this skill whenever the user mentions telecom networks, mobile core protocols (GTP, PFCP, NAS), 5G security testing, SGSN/GGSN/PGW/AMF/SMF exploitation, industrial cellular routers (Milesight UR-series), GRX/IPX roaming backbones, or any mobile network penetration testing. This skill covers reconnaissance, protocol exploitation, covert channels, privilege escalation on network elements, and detection evasion in telecom environments.
-
abelrguezr Bundle Macos Mdm Enrollment ResearchSecurity research skill for understanding and testing macOS MDM/DEP enrollment vulnerabilities. Use this skill when investigating MDM security, analyzing DEP enrollment processes, researching mobile device management attack surfaces, or conducting authorized penetration testing on macOS device enrollment systems. This skill covers binary instrumentation techniques, DEP profile analysis, and MDM security assessment methodologies.
-
abelrguezr Bundle Csp Bypass ResearchContent Security Policy (CSP) bypass research and testing for security assessments. Use this skill when analyzing CSP configurations, testing bypass techniques for authorized security assessments, or researching CSP vulnerabilities. Trigger when users mention CSP, Content-Security-Policy, CSP bypass, security policy testing, web security assessments involving CSP, or need to understand CSP bypass vectors for defensive purposes.
-
abelrguezr Bundle Ad External Forest TrustActive Directory external forest trust exploitation methodology. Use this skill whenever the user mentions forest trusts, cross-domain access, AD trust enumeration, SID history abuse, RBCD across forests, inter-realm TGT/TGS, or any scenario involving multiple Active Directory domains with trust relationships. Trigger for trust-based lateral movement, cross-forest privilege escalation, or when analyzing trust configurations for security assessments.
-
abelrguezr Bundle Resource Based Constrained DelegationExecute Resource-based Constrained Delegation (RBCD) attacks in Active Directory environments. Use this skill whenever the user needs to exploit write permissions on computer accounts to gain privileged access, perform S4U attacks, enumerate RBCD configurations, or troubleshoot Kerberos delegation issues. Trigger this skill for any AD Kerberos delegation task, machine account manipulation, or when the user mentions RBCD, msDS-AllowedToActOnBehalfOfOtherIdentity, S4U2Self, S4U2Proxy, or constrained delegation abuse.
-
abelrguezr Bundle Windows Kernel Token Theft AnalysisAnalyze and explain Windows kernel privilege escalation via token theft when arbitrary kernel R/W primitives are available. Use this skill when investigating kernel vulnerabilities, reviewing exploit code, understanding EPROCESS token manipulation, or developing defensive controls against token theft attacks. Trigger for any questions about Windows kernel exploitation, EPROCESS structures, token stealing techniques, or kernel vulnerability analysis.
-
abelrguezr Bundle Windows Named Pipe ImpersonationWindows local privilege escalation via named pipe client impersonation. Use this skill whenever the user mentions privilege escalation, named pipes, ImpersonateNamedPipeClient, Potato attacks, PrintSpoofer, RoguePotato, JuicyPotato, EFSRPC, or wants to escalate from a privileged user to SYSTEM on Windows. This skill helps generate exploit code, identify coercion triggers, and troubleshoot impersonation issues.
-
abelrguezr Bundle Log4shell Jndi ExploitationHow to discover, verify, and exploit JNDI/Log4Shell vulnerabilities in Java applications. Use this skill whenever the user mentions Log4j, JNDI, LDAP injection, CVE-2021-44228, Java deserialization, or needs to test for remote code execution through logging libraries. Make sure to use this skill for any Java application security testing involving logging frameworks, especially when HTTP headers, user input, or configuration files might be logged.
-
abelrguezr Bundle Ad Privileged GroupsActive Directory privileged group enumeration and exploitation. Use this skill whenever the user mentions Active Directory groups, privilege escalation, AD security assessment, domain enumeration, or needs to identify and exploit privileged group memberships. This includes scenarios involving Backup Operators, DnsAdmins, Print Operators, Server Operators, Account Operators, and other AD privileged groups. Make sure to use this skill for any AD security testing, penetration testing, or red teaming task involving group-based privilege escalation.
-
abelrguezr Bundle Windows Uiaccess BypassWindows UIAccess privilege escalation research and testing. Use this skill when investigating Admin Protection bypasses, UIAccess token manipulation, integrity level escalation, or secure directory validation weaknesses. Trigger for any Windows security research involving AppInfo service, RAiLaunchAdminProcess, UIPI bypasses, or High IL process injection techniques. Also use when enumerating writable paths in protected directories or analyzing signed UIAccess binary vulnerabilities.
-
abelrguezr Bundle Ret2lib Arm64 ExploitationHow to exploit ret2lib vulnerabilities on ARM64 binaries with stack buffer overflows. Use this skill whenever the user mentions ret2lib, ROP exploitation, ARM64 binary exploitation, printf format string leaks, stack buffer overflows on aarch64, or needs to bypass NX/ASLR/PIE protections. This skill covers both non-ASLR scenarios and ASLR/PIE bypass using printf leaks from the stack.
-
abelrguezr Bundle Rop Syscall ExploitCreate ROP chains to execute syscalls (like sys_execve) for binary exploitation. Use this skill whenever you're working on binary exploitation challenges, need to build ROP chains for static binaries, want to call syscalls from a buffer overflow, or are dealing with NX-protected binaries where you need to execute /bin/sh. This is essential for CTF challenges, security research, and understanding return-oriented programming with syscall invocation.
-
abelrguezr Bundle Wide Source Code SearchUse this skill whenever you need to search for leaked credentials, secrets, API keys, or vulnerability patterns across code repositories. Trigger this when investigating potential data leaks, searching for exposed secrets in public repos, hunting for security vulnerabilities in code, or performing external reconnaissance on a target's codebase. Don't forget to use this even if you're just checking if a company's repos might contain sensitive information.
-
abelrguezr Bundle Python Class PollutionAnalyze Python code for class pollution vulnerabilities (Python's prototype pollution), identify vulnerable merge functions, and demonstrate exploitation techniques for authorized security testing. Use this skill whenever the user mentions Python security, prototype pollution, class pollution, merge vulnerabilities, __class__ manipulation, __globals__ access, or needs to audit Python code for object injection attacks.
-
abelrguezr Bundle Electron App PentestSecurity testing for Electron desktop applications. Use this skill whenever the user needs to audit, test, or analyze Electron apps for vulnerabilities like nodeIntegration misconfigurations, contextIsolation bypasses, XSS-to-RCE chains, preload script issues, shell.openExternal exploits, or V8 heap snapshot tampering. Trigger for any Electron security assessment, vulnerability research, or penetration testing of desktop apps built with Electron.
-
abelrguezr Bundle Java Deserialization PentestJava deserialization vulnerability assessment and exploitation. Use this skill whenever the user mentions Java deserialization, ObjectInputStream, readObject, gadget chains, ysoserial, or any Java serialization security testing. Trigger for pentesting Java applications, analyzing serialized payloads, generating exploit code, or hardening Java deserialization. Make sure to use this skill for any Java security assessment involving serialization, even if the user doesn't explicitly mention 'deserialization' but talks about Java object streams, RMI, or serialized data.
-
abelrguezr Bundle Postmessage Iframe ExploitSecurity testing skill for detecting and exploiting postMessage vulnerabilities through iframe location manipulation. Use this skill when testing web applications for postMessage security issues, when you need to check if nested iframes can be hijacked, when auditing cross-origin communication, or when investigating potential data exfiltration through postMessage. Trigger this skill for any pentesting task involving postMessage, iframe security, cross-origin communication vulnerabilities, or when the user mentions testing for message hijacking, iframe location manipulation, or wildcard postMessage receivers.
-
abelrguezr Bundle Ssti Server Side Template InjectionServer-Side Template Injection (SSTI) detection and exploitation. Use this skill whenever the user mentions template injection, SSTI, Jinja, Twig, FreeMarker, Velocity, Thymeleaf, or any template engine vulnerability. Also trigger when users need to test web applications for template injection vulnerabilities, identify template engines, or craft SSTI payloads for security assessments. Make sure to use this skill for any web security testing involving template engines, even if the user doesn't explicitly say "SSTI" or "template injection".
-
abelrguezr Bundle Mte Memory TaggingMemory Tagging Extension (MTE) analysis and bypass for ARM binary exploitation. Use this skill whenever working with ARM binaries, analyzing memory protections, debugging MTE-related crashes (SIGSEGV with SEGV_MTESERR/SEGV_MTEAERR), investigating use-after-free or buffer overflow vulnerabilities on ARM systems, or when the user mentions MTE, memory tagging, ARM security, KASAN, or hardware memory protections. This skill covers MTE fundamentals, detection, and bypass techniques including speculative execution attacks like TikTag.
-
abelrguezr Bundle Defi Amm Cache Exploit AuditAudit DeFi AMMs for virtual balance cache exploitation vulnerabilities. Use this skill whenever you're reviewing AMM code, analyzing DeFi protocol security, investigating accounting bugs, or looking for cache-related exploits in weighted pools, stableswap implementations, or any protocol that caches derived state (virtual balances, TWAP snapshots, invariant helpers). Trigger this when users mention AMM audits, DeFi security reviews, cache invalidation issues, or when examining code with packed storage arrays and proportional updates.
-
abelrguezr Bundle Anti Forensic DetectionHow to detect and investigate anti-forensic techniques used by attackers. Use this skill whenever you need to identify timestamp manipulation, data hiding, log tampering, EDR evasion, or other anti-forensic activity during incident response, threat hunting, or forensic investigations. Make sure to use this skill when analyzing suspicious systems, investigating potential compromises, or reviewing artifacts that may have been tampered with.
-
abelrguezr Bundle Vlan Segmentation BypassBypass VLAN segmentation during network pentesting engagements. Use this skill whenever you need to pivot laterally across VLAN boundaries, test VLAN isolation, or assess Layer-2 network security. Trigger this skill for any task involving VLAN hopping, trunk configuration, DTP exploitation, double-tagging attacks, voice-VLAN hijacking, or when analyzing VLAN-related CVEs. Don't forget to use this skill even if the user just mentions "VLAN," "trunk," "802.1Q," or "network segmentation" in a security testing context.
-
abelrguezr Bundle Macos Iokit AnalysisUse this skill whenever analyzing macOS kernel drivers, IOKit vulnerabilities, or reverse engineering macOS kernel extensions. Trigger for any macOS security research involving IOKit, driver analysis, IORegistry inspection, kernel extension investigation, or when the user mentions macOS drivers, KEXT files, IOKit services, or kernel-level security analysis. Also use when investigating recent macOS CVEs related to IOKit (IOHIDFamily, IOGPUFamily, etc.) or when the user needs to enumerate driver selectors, inspect IORegistry, or understand IOKit communication patterns.
-
abelrguezr Bundle Windows Token EscalationWindows local privilege escalation using SeDebug + SeImpersonate token copying. Use this skill when the user is doing Windows penetration testing, security assessments, or privilege escalation research and needs to escalate from Administrator to SYSTEM by copying tokens from privileged processes like lsass.exe, services.exe, or svchost.exe. Trigger this when users mention Windows privilege escalation, token manipulation, SeDebug, SeImpersonate, or need to gain SYSTEM access.
-
abelrguezr Bundle Windows Local PrivescWindows Local Privilege Escalation enumeration and exploitation. Use this skill whenever the user needs to enumerate privilege escalation vectors on a Windows system, check for misconfigurations, find credentials, or escalate from low privilege to SYSTEM. Trigger on requests about Windows privilege escalation, privesc enumeration, Windows security assessment, or when analyzing Windows systems for privilege escalation opportunities. Make sure to use this skill when the user mentions Windows, privilege escalation, SYSTEM access, service misconfigurations, credential harvesting, or any Windows security testing scenario.
-
abelrguezr Bundle IOS Exploit Chain AnalyzerAnalyze iOS zero-click attack chains, CoreAudio vulnerabilities, PAC bypass techniques, and CryptoTokenKit abuse patterns. Use this skill whenever the user mentions iOS security research, iMessage exploitation, zero-click attacks, CoreAudio/AudioConverterService vulnerabilities, arm64e PAC/RPAC bypass, kernel escalation, CryptoTokenKit abuse, BlastDoor bypass, or any iOS exploitation chain analysis. Also trigger for defensive hardening recommendations, vulnerability research, or when analyzing iOS security tutorials and CVE chains.
-
abelrguezr Bundle File Integrity MonitoringHow to set up file integrity monitoring (FIM) to detect unauthorized changes to files, systems, and configurations. Use this skill whenever the user needs to create file baselines, detect file modifications, monitor system changes, investigate potential compromises, or set up security monitoring. Trigger this skill for any request involving file hashing, change detection, system baselining, or security auditing—even if they don't explicitly mention "file integrity monitoring" or "FIM".
-
abelrguezr Bundle Macos Gcd AnalysisAnalyze Grand Central Dispatch (GCD) usage in macOS/iOS applications for security research and reverse engineering. Use this skill whenever the user needs to understand GCD queues, blocks, or parallelism in Objective-C/Swift code, hook GCD functions with Frida, or reverse engineer GCD structures in Ghidra. Trigger on mentions of dispatch_async, dispatch_sync, DispatchQueue, libdispatch, GCD queues, or any macOS/iOS concurrency analysis.
-
abelrguezr Bundle Windows Token Privilege EscalationWindows privilege escalation using token abuse techniques. Use this skill whenever the user mentions Windows privilege escalation, token privileges, Se* privileges, or needs to escalate from a lower-privileged user to SYSTEM/Administrator. Trigger for any Windows security assessment, penetration testing, or red team engagement where token-based privilege escalation is relevant.
-
abelrguezr Bundle Brop Blind Return Oriented ProgrammingHow to perform Blind Return Oriented Programming (BROP) attacks on vulnerable binaries without any information about the binary. Use this skill whenever the user mentions blind exploitation, BROP, return-oriented programming without binary info, stack overflow without binary knowledge, or needs to exploit a server that restarts after crashes. This skill covers finding vulnerable offsets, brute-forcing canaries, locating ROP gadgets, finding PLT entries, and exfiltrating binary data.
-
abelrguezr Bundle Forensic AnalysisDigital forensic analysis skill for investigating disk images, memory dumps, PCAPs, malware, and system artifacts. Use this skill whenever the user needs to perform forensic analysis on any digital evidence including disk images, memory dumps, network captures, suspicious files, or when investigating security incidents. Trigger this skill for any forensic investigation, incident response, malware analysis, or digital evidence examination tasks.
-
abelrguezr Bundle Ksmbd Cve 2025 37947 ExploitUse this skill when the user needs to understand, analyze, or exploit CVE-2025-37947 (ksmbd streams_xattr OOB write vulnerability) for local privilege escalation on Linux. Trigger this skill for any questions about ksmbd kernel exploitation, the msg_msg + pipe_buffer primitive, heap grooming strategies, or when the user mentions ksmbd, streams_xattr, CVE-2025-37947, or wants to perform kernel LPE on Ubuntu 22.04 with ksmbd enabled.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include kerberos-ticket-harvesting, postmessage-race-condition-exploit, windows-enterprise-ipc-exploitation. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.