Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
abelrguezr Bundle PHP Perl Extension BypassBypass PHP disable_functions, open_basedir, and safe_mode restrictions using the legacy perl PHP extension (CVE-2007-4596) or PHP-CGI argument injection (CVE-2024-4577). Use this skill whenever you need to execute commands, read arbitrary files, or escalate privileges on a PHP server where standard PHP functions are blocked. Trigger this when you encounter PHP restrictions during web application pentesting, need to bypass WAF rules targeting PHP functions, or want to enumerate what's possible on a compromised PHP endpoint.
-
abelrguezr Bundle Macos Xpc SecuritymacOS XPC security verification and connection hardening. Use this skill whenever you're implementing XPC services, reviewing XPC connection code, auditing macOS IPC security, or need to understand XPC authentication vulnerabilities. Trigger this for any XPC listener implementation, connection validation, audit token usage, or when checking for PID reuse attacks, certificate verification, or hardened runtime requirements.
-
abelrguezr Bundle Imagick Disable Functions BypassSecurity testing skill for detecting and exploiting ImageMagick/ImageTragick vulnerabilities to bypass PHP disable_functions restrictions. Use this skill whenever the user mentions PHP security testing, disable_functions bypass, ImageMagick vulnerabilities, ImageTragick, CVE-2016-3714, or needs to test for command injection through image processing libraries. Also trigger when users ask about PHP hardening bypass, ImageMagick policy.xml configuration, or security auditing of PHP applications with image upload functionality.
-
abelrguezr Bundle PHP Bypass TechniquesSecurity research skill for understanding and documenting PHP function bypass techniques including disable_functions, safe_mode, and open_basedir restrictions. Use this skill when users ask about PHP security testing, penetration testing PHP applications, researching PHP vulnerabilities, documenting bypass methods for authorized security assessments, or analyzing PHP configuration weaknesses. Trigger on mentions of PHP security, disabled functions, safe_mode bypass, proc_open exploitation, LD_PRELOAD attacks, or PHP pentesting.
-
bbgnsurftech Bundle Fuzzing ApisPerform API fuzzing to discover edge cases, crashes, and security vulnerabilities. Use when performing specialized testing. Trigger with phrases like "fuzz the API", "run fuzzing tests", or "discover edge cases".
-
bbgnsurftech Bundle Scanning For SecretsScan for exposed secrets, API keys, and credentials in code. Use when auditing for secret leaks. Trigger with 'scan for secrets', 'find exposed keys', or 'check credentials'.
-
bbgnsurftech Bundle Plugin AuditorAutomatically audits claude code plugins for security vulnerabilities, best practices, claude.md compliance, and quality standards when user mentions audit plugin, security review, or best practices check. specific to claude-code-plugins repositor...
-
bbgnsurftech Bundle Encrypting And Decrypting DataValidate encryption implementations and cryptographic practices. Use when reviewing data security measures. Trigger with 'check encryption', 'validate crypto', or 'review security keys'.
-
bbgnsurftech Bundle Checking Infrastructure ComplianceUse when you need to work with compliance checking. This skill provides compliance monitoring and validation with comprehensive guidance and automation. Trigger with phrases like "check compliance", "validate policies", or "audit compliance".
-
bbgnsurftech Bundle Performing Security AuditsThis skill allows claude to conduct comprehensive security audits of code, infrastructure, and configurations. it leverages various tools within the security-pro-pack plugin, including vulnerability scanning, compliance checking, cryptography revi...
-
bbgnsurftech Bundle Validating Pci Dss ComplianceValidate PCI-DSS compliance for payment card data security. Use when auditing payment systems. Trigger with 'validate PCI-DSS', 'check payment security', or 'audit card data'.
-
bbgnsurftech Bundle Assisting With Soc2 Audit PreparationAutomate SOC 2 audit preparation including evidence gathering, control assessment, and compliance gap identification. Use when you need to prepare for SOC 2 audits, assess Trust Service Criteria compliance, document security controls, or generate readiness reports. Trigger with phrases like "SOC 2 audit preparation", "SOC 2 readiness assessment", "collect SOC 2 evidence", or "Trust Service Criteria compliance".
-
bbgnsurftech Bundle Analyzing DependenciesCheck dependencies for known security vulnerabilities and outdated versions. Use when auditing third-party libraries. Trigger with 'check dependencies', 'scan for vulnerabilities', or 'audit packages'.
-
bbgnsurftech Bundle Performing Penetration TestingPerform security penetration testing to identify vulnerabilities. Use when conducting security assessments. Trigger with 'run pentest', 'security testing', or 'find vulnerabilities'.
-
bbgnsurftech Bundle Automating API TestingAutomate API endpoint testing including request generation, validation, and comprehensive test coverage for REST and GraphQL APIs. Use when testing API contracts, validating OpenAPI specifications, or ensuring endpoint reliability. Trigger with phrases like "test the API", "generate API tests", or "validate API contracts".
-
bbgnsurftech Bundle Scanning For Data Privacy IssuesScan for data privacy issues and sensitive information exposure. Use when reviewing data handling practices. Trigger with 'scan privacy issues', 'check sensitive data', or 'validate data protection'.
-
bbgnsurftech Bundle Implementing Database Audit LoggingUse when you need to track database changes for compliance and security monitoring. This skill implements audit logging using triggers, application-level logging, CDC, or native logs. Trigger with phrases like "implement database audit logging", "add audit trails", "track database changes", or "monitor database activity for compliance".
-
bbgnsurftech Bundle Validating Cors PoliciesValidate CORS policies for security issues and misconfigurations. Use when reviewing cross-origin resource sharing. Trigger with 'validate CORS', 'check CORS policy', or 'review cross-origin'.
-
bbgnsurftech Bundle Scanning For VulnerabilitiesThis skill enables comprehensive vulnerability scanning using the vulnerability-scanner plugin. it identifies security vulnerabilities in code, dependencies, and configurations, including cve detection. use this skill when the user asks to scan fo...
-
bbgnsurftech Skill Logging API RequestsLog API requests with correlation IDs, performance metrics, and security audit trails. Use when auditing API requests and responses. Trigger with phrases like "log API requests", "add API logging", or "track API calls".
-
bbgnsurftech Skill Auditing Wallet SecurityAudit crypto wallet security including private key management and transaction signing. Use when auditing wallet security practices. Trigger with phrases like "audit wallet", "check security", or "verify signatures".
-
bbgnsurftech Bundle Auditing Access ControlAudit access control implementations for security vulnerabilities and misconfigurations. Use when reviewing authentication and authorization. Trigger with 'audit access control', 'check permissions', or 'validate authorization'.
-
bbgnsurftech Bundle Scanning For Gdpr ComplianceScan for GDPR compliance issues in data handling and privacy practices. Use when ensuring EU data protection compliance. Trigger with 'scan GDPR compliance', 'check data privacy', or 'validate GDPR'.
-
bbgnsurftech Bundle Generating Security Audit ReportsGenerate comprehensive security audit reports for applications and systems. Use when you need to assess security posture, identify vulnerabilities, evaluate compliance status, or create formal security documentation. Trigger with phrases like "create security audit report", "generate security assessment", "audit security posture", or "PCI-DSS compliance report".
-
bbgnsurftech Bundle Managing Ssltls CertificatesThis skill enables claude to manage and monitor ssl/tls certificates using the ssl-certificate-manager plugin. it is activated when the user requests actions related to ssl certificates, such as checking certificate expiry, renewing certificates, ...
-
bbgnsurftech Skill Scanning API SecurityScan APIs for security vulnerabilities including injection, broken auth, and data exposure. Use when scanning APIs for security vulnerabilities. Trigger with phrases like "scan API security", "check for vulnerabilities", or "audit API security".
-
bbgnsurftech Bundle Configuring Auto Scaling PoliciesUse when you need to work with auto-scaling. This skill provides auto-scaling configuration with comprehensive guidance and automation. Trigger with phrases like "configure auto-scaling", "set up elastic scaling", or "implement scaling".
-
bbgnsurftech Bundle Configuring Service MeshesThis skill configures service meshes like istio and linkerd for microservices. it generates production-ready configurations, implements best practices, and ensures a security-first approach. use this skill when the user asks to "configure service ...
-
bbgnsurftech Bundle Validating Authentication ImplementationsValidate authentication mechanisms for security weaknesses and compliance. Use when reviewing login systems or auth flows. Trigger with 'validate authentication', 'check auth security', or 'review login'.
-
bbgnsurftech Bundle Checking Hipaa ComplianceCheck HIPAA compliance for healthcare data security requirements. Use when auditing healthcare applications. Trigger with 'check HIPAA compliance', 'validate health data security', or 'audit PHI protection'.
-
bbgnsurftech Bundle Scanning Input Validation PracticesScan for input validation vulnerabilities and injection risks. Use when reviewing user input handling. Trigger with 'scan input validation', 'check injection vulnerabilities', or 'validate sanitization'.
-
bbgnsurftech Bundle Checking Owasp ComplianceCheck compliance with OWASP Top 10 security risks and best practices. Use when performing comprehensive security audits. Trigger with 'check OWASP compliance', 'audit web security', or 'validate OWASP'.
-
bbgnsurftech Bundle Checking Session SecurityAnalyze session management implementations to identify security vulnerabilities in web applications. Use when you need to audit session handling, check for session fixation risks, review session timeout configurations, or validate session ID generation security. Trigger with phrases like "check session security", "audit session management", "review session handling", or "session fixation vulnerability".
-
bbgnsurftech Skill Monitoring Cross Chain BridgesMonitor cross-chain bridge security, liquidity, and transaction status across networks. Use when monitoring cross-chain asset transfers. Trigger with phrases like "monitor bridges", "check cross-chain", or "track bridge transfers".
-
bbgnsurftech Bundle Scanning Database SecurityUse when you need to work with security and compliance. This skill provides security scanning and vulnerability detection with comprehensive guidance and automation. Trigger with phrases like "scan for vulnerabilities", "implement security controls", or "audit security".
-
bbgnsurftech Bundle Managing Container RegistriesUse when you need to work with containerization. This skill provides container management and orchestration with comprehensive guidance and automation. Trigger with phrases like "containerize app", "manage containers", or "orchestrate deployment".
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include php-perl-extension-bypass, macos-xpc-security, imagick-disable-functions-bypass. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.