Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
autohandai-community-skills Bundle Building Soc Escalation MatrixBuild a structured SOC escalation matrix defining severity tiers, response SLAs, escalation paths, and notification procedures for security incidents.
-
autohandai-community-skills Bundle Nvidia Nemoclaw Maintainer DayRuns the daytime maintainer loop for NemoClaw, prioritizing items labeled with the current version target. Picks the highest-value item, executes the right workflow (merge gate, salvage, security sweep, test gaps, hotspot cooling, or sequencing), and reports progress. Use during the workday to land PRs and close issues. Designed for /loop (e.g. /loop 10m /nemoclaw-maintainer-day). Trigger keywords - maintainer day, work on PRs, land PRs, make progress, what's next, keep going, maintainer loop.
-
autohandai-community-skills Bundle Performing Vlan Hopping AttackSimulates VLAN hopping attacks using switch spoofing and double tagging techniques in authorized environments to test VLAN segmentation effectiveness and validate switch port security configurations against Layer 2 bypass attacks.
-
autohandai-community-skills Bundle Configuring Hsm For Key StorageHardware Security Modules (HSMs) are tamper-resistant physical devices that safeguard cryptographic keys and perform cryptographic operations in a hardened environment. Keys stored in an HSM never lea
-
autohandai-community-skills Bundle Detecting Golden Ticket AttacksDetect Kerberos golden ticket attacks by analyzing Windows Security event logs for anomalous TGT usage patterns. Parses Event IDs 4624, 4672, and 4768 from EVTX files to identify tickets with abnormal lifetimes, domain SID mismatches, and privilege escalation sequences where non-admin accounts receive admin-level privileges without corresponding group membership changes.
-
autohandai-community-skills Bundle Testing For Xss VulnerabilitiesTests web applications for Cross-Site Scripting (XSS) vulnerabilities by injecting JavaScript payloads into reflected, stored, and DOM-based contexts to demonstrate client-side code execution, session hijacking, and user impersonation. The tester identifies all injection points and output contexts, crafts context-appropriate payloads, and bypasses sanitization and CSP protections. Activates for requests involving XSS testing, cross-site scripting assessment, client-side injection testing, or JavaScript injection vulnerability testing.
-
yongjianwan Bundle Security GuidanceSecurity guidance and best practices for code development
-
autohandai-community-skills Bundle Containing Active Security BreachRapidly contain an active security breach by isolating compromised systems, blocking attacker communications, and preserving evidence while minimizing business disruption.
-
autohandai-community-skills Bundle Detecting Rdp Brute Force AttacksDetect RDP brute force attacks by analyzing Windows Security Event Logs for failed authentication patterns (Event ID 4625), successful logons after failures (Event ID 4624), NLA failures, and source IP frequency analysis.
-
autohandai-community-skills Bundle Hunting For Dns Based PersistenceHunt for DNS-based persistence mechanisms including DNS hijacking, dangling CNAME records, wildcard DNS abuse, and unauthorized zone modifications using passive DNS databases, SecurityTrails API, and DNS audit log analysis.
-
sboghossian-mini-claude-for-legal Skill Efirm Engagement Letter DraftUse when the eFirm matter creation workflow needs to auto-generate a firm-branded, bar-compliant engagement letter pre-populated from CRM, matter, fee-quote, and conflict-check data. Covers the eFirm-integrated version of the standalone engagement-letter draft skill, including e-signature workflow (DocuSign/Tawqi3i), audit trail, and downstream matter activation. P0 — no substantive work begins until the engagement letter is signed.
-
sboghossian-mini-claude-for-legal Skill Inst Tawqi3i Esignature BridgeUse when a Lebanese legal document requires electronic signature or cross-border e-notarization via the Tawqi3i (توقيعي) platform operated by the Lebanese Ministry of Interior. Handles direct sign flows within Louis, apostille auto-request generation, and multi-jurisdiction recognition checks (Lebanon, KSA, UAE). Provides audit-trail documentation for signed documents. Critical for any Lebanese cross-border transaction where physical notarization is impractical.
-
sboghossian-mini-claude-for-legal Skill Efirm Document Versioning RuleUse when a law firm needs to define, enforce, or explain its document versioning policy — covering naming conventions, version-number schemes, checkout/check-in controls, comparison workflows, privileged-document protections, and audit-trail requirements. Applies to all document types produced in eFirm (contracts, court filings, legal opinions, correspondence). Part of the eFirm firm-management product suite.
-
autohandai-community-skills Bundle Performing Csrf Attack SimulationTesting web applications for Cross-Site Request Forgery vulnerabilities by crafting forged requests that exploit authenticated user sessions during authorized security assessments.
-
autohandai-community-skills Bundle Detecting Email Account CompromiseDetect compromised O365 and Google Workspace email accounts by analyzing inbox rule creation, suspicious sign-in locations, mail forwarding rules, and unusual API access patterns via Microsoft Graph and audit logs.
-
autohandai-community-skills Bundle Configuring Ldap Security HardeningHarden LDAP directory services against common attacks including credential harvesting, LDAP injection, anonymous binding, and channel binding bypass. Covers LDAPS enforcement, channel binding, LDAP si
-
autohandai-community-skills Bundle Implementing Bgp Security With RpkiImplement BGP route origin validation using RPKI with Route Origin Authorizations, RPKI-to-Router protocol, and ROV policies on Cisco and Juniper routers to prevent route hijacking.
-
autohandai-community-skills Bundle Scanning Infrastructure With NessusTenable Nessus is the industry-leading vulnerability scanner used to identify security weaknesses across network infrastructure including servers, workstations, network devices, and operating systems.
-
autohandai-community-skills Bundle Analyzing Network Packets With ScapyCraft, send, sniff, and dissect network packets using Scapy for protocol analysis, network reconnaissance, and traffic anomaly detection in authorized security testing
-
autohandai-community-skills Bundle Analyzing Threat Landscape With MispAnalyze the threat landscape using MISP (Malware Information Sharing Platform) by querying event statistics, attribute distributions, threat actor galaxy clusters, and tag trends over time. Uses PyMISP to pull event data, compute IOC type breakdowns, identify top threat actors and malware families, and generate threat landscape reports with temporal trends.
-
sboghossian-mini-claude-for-legal Skill Kb Ip MenaUse when a matter involves trademark registration, patent filing, copyright protection, trade-secret enforcement, or IP licensing in MENA jurisdictions (Saudi Arabia, UAE, Lebanon, Egypt, GCC). Covers national IP frameworks, WIPO treaties, Madrid Protocol trademark filing, GCC Patent Office, SAIP (KSA), MOEC (UAE), MOET (Lebanon), Egyptian Patent Office, and enforcement options including civil, criminal, and customs seizure. Triggers on trademark MENA, patent KSA/UAE, copyright Arab countries, IP licensing MENA, or counterfeit goods enforcement questions.
-
autohandai-community-skills Bundle Hunting Living Off The Land BinariesDetects abuse of Living Off The Land Binaries (LOLBAS) such as certutil, wmic, mshta, regsvr32, and rundll32 in Windows event logs and Sysmon telemetry. Builds detection rules by cross-referencing process creation events against the LOLBAS project database. Use when threat hunting for fileless attack techniques or building SIEM detection rules.
-
autohandai-community-skills Bundle Tracking Threat Actor InfrastructureThreat actor infrastructure tracking involves monitoring and mapping adversary-controlled assets including command-and-control (C2) servers, phishing domains, exploit kit hosts, bulletproof hosting, a
-
autohandai-community-skills Bundle Building Threat Intelligence PlatformBuilding a Threat Intelligence Platform (TIP) involves deploying and integrating multiple CTI tools into a unified system for collecting, analyzing, enriching, and disseminating threat intelligence. T
-
autohandai-community-skills Bundle Exploiting Nopac Cve 2021 42278 42287Exploit the noPac vulnerability chain (CVE-2021-42278 sAMAccountName spoofing and CVE-2021-42287 KDC PAC confusion) to escalate from standard domain user to Domain Admin in Active Directory environments.
-
sboghossian-mini-claude-for-legal Skill Template Client Data ExplainerUse when a law firm or enterprise client asks how Louis handles their data — during procurement review, onboarding, or a client trust conversation. Produces a plain-language explainer covering storage, processing, retention, sharing, training restrictions, encryption, access controls, audit trail, and deletion. For formal security questionnaire responses, pair with the vendor-security-questionnaire-responses template.
-
autohandai-community-skills Bundle Performing Hash Cracking With HashcatHash cracking is an essential skill for penetration testers and security auditors to evaluate password strength. Hashcat is the world's fastest password recovery tool, supporting over 300 hash types w
-
autohandai-community-skills Bundle Performing Web Cache Poisoning AttackExploiting web cache mechanisms to serve malicious content to other users by poisoning cached responses through unkeyed headers and parameters during authorized security tests.
-
autohandai-community-skills Bundle Conducting Mobile App Penetration TestConducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security Testing Guide (MASTG) to identify vulnerabilities in data storage, network communication, authentication, cryptography, and platform-specific security controls. The tester performs static analysis of application binaries, dynamic analysis at runtime, and API security testing to evaluate the complete mobile attack surface. Activates for requests involving mobile app pentest, iOS security assessment, Android security testing, or OWASP MASTG assessment.
-
sboghossian-mini-claude-for-legal Skill Docs Faq PackUse when a user asks a general question about the platform that is likely to have a standardized answer — pricing, security, supported jurisdictions, features, integrations, training, or how to get started. This skill compiles the top frequently asked questions from sales and support tickets, organized by category, to provide rapid accurate answers without routing to a full documentation section.
-
autohandai-community-skills Bundle Hunting For T1098 Account ManipulationHunt for MITRE ATT&CK T1098 account manipulation including shadow admin creation, SID history injection, group membership changes, and credential modifications using Windows Security Event Logs.
-
autohandai-community-skills Bundle Performing Ssl Tls Security AssessmentAssess SSL/TLS server configurations using the sslyze Python library to evaluate cipher suites, certificate chains, protocol versions, HSTS headers, and known vulnerabilities like Heartbleed and ROBOT.
-
autohandai-community-skills Bundle Building Detection Rule With Splunk SplBuild effective detection rules using Splunk Search Processing Language (SPL) correlation searches to identify security threats in SOC environments.
-
autohandai-community-skills Bundle Detecting Credential Dumping TechniquesDetect LSASS credential dumping, SAM database extraction, and NTDS.dit theft using Sysmon Event ID 10, Windows Security logs, and SIEM correlation rules
-
autohandai-community-skills Bundle Exploiting Constrained Delegation AbuseExploit Kerberos Constrained Delegation misconfigurations in Active Directory to impersonate privileged users via S4U2self and S4U2proxy extensions for lateral movement and privilege escalation.
-
autohandai-community-skills Bundle Exploiting Mass Assignment In REST ApisDiscover and exploit mass assignment vulnerabilities in REST APIs to escalate privileges, modify restricted fields, and bypass authorization controls by injecting unexpected parameters in API requests.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include nvidia-nemoclaw-maintainer-day, performing-vlan-hopping-attack, detecting-golden-ticket-attacks. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.