Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
jmagly-ai-writing-guide Skill Security AuditPerform comprehensive security assessment
-
techwavedev Skill Malware AnalystExpert malware analyst specializing in defensive malware research, threat intelligence, and incident response. Masters sandbox analysis, behavioral analysis, and malware family identification.
-
orcaqubits Skill Ap2 Dispute AccountabilityImplement AP2 dispute resolution and accountability — cryptographic evidence, liability allocation, chargeback handling, and audit trail construction. Use when building dispute handling, fraud investigation, or compliance systems for agentic payments.
-
lev-os Bundle LevUse when routing intent into Lev lifecycle work, clarifying an uncertain next step, or invoking and diagnosing the Lev CLI and runtime.
-
techwavedev Skill Audit SkillsExpert security auditor for AI Skills and Bundles. Performs non-intrusive static analysis to identify malicious patterns, data leaks, system stability risks, and obfuscated payloads across Windows, macOS, Linux/Unix, and Mobile (Android/iOS).
-
techwavedev Skill Backend Security CoderExpert in secure backend coding practices specializing in input validation, authentication, and API security. Use PROACTIVELY for backend security implementations or security code reviews.
-
techwavedev Skill Find BugsFind bugs, security vulnerabilities, and code quality issues in local branch changes. Use when asked to review changes, find bugs, security review, or audit code on the current branch.
-
techwavedev Skill File UploadsCareful about security and performance. Never trusts file extensions. Knows that large uploads need special handling. Prefers presigned URLs over server proxying.
-
techwavedev Skill Burpsuite Project ParserSearches and explores Burp Suite project files (.burp) from the command line. Use when searching response headers or bodies with regex patterns, extracting security audit findings, dumping proxy history or site map data, or analyzing HTTP traffic captured in a Burp project.
-
techwavedev Skill Mobile Security CoderExpert in secure mobile coding practices specializing in input validation, WebView security, and mobile-specific security patterns.
-
techwavedev Skill Zeroize AuditDetects missing zeroization of sensitive data in source code and identifies zeroization removed by compiler optimizations, with assembly-level analysis, and control-flow verification. Use for auditing C/C++/Rust code handling secrets, keys, passwords, or other sensitive data.
-
techwavedev Skill Fix ReviewVerify fix commits address audit findings without new bugs
-
lev-os Skill DsrDoodlestein Self-Releaser - fallback release infrastructure for when GitHub Actions is throttled. Local builds, cross-platform releases, supply chain security. Use when: GH Actions slow, local release, build hosts, dsr command.
-
lev-os Bundle Skill BuilderUse when creating skills, converting docs/repos/PDFs to skills, installing external skills, auditing skill security, or merging skills
-
techwavedev Skill Nodejs Best PracticesNode.js development principles and decision-making. Framework selection, async patterns, security, and architecture. Teaches thinking, not copying.
-
techwavedev Skill Security AuditComprehensive security auditing workflow covering web application testing, API security, penetration testing, vulnerability scanning, and security hardening.
-
lev-os Skill Pr Review[WHAT] Unified PR review combining code quality, tests, and security [HOW] Routes by PR scope: quick (<200 LOC) -> standard (200-800) -> deep (>800 or security-sensitive) [WHEN] PR reviews, code audits, architecture validation
-
lev-os Skill Board Committee CharterDrafts board committee charters for Audit and Compensation Committees tailored to public/private status, exchange listing (NYSE/NASDAQ), and governance requirements. Covers composition, independence, authority, meeting procedures, and reporting. Use when creating or updating audit committee charters, compensation committee charters, or corporate oversight committee formations.
-
lev-os Skill C Tpat Security ProfileDrafts a U.S. C-TPAT Security Profile for CBP submission covering physical, personnel, procedural, conveyance, and IT security domains. Use when preparing C-TPAT enrollment, certification, validation, or recertification profiles, or assembling a CBP-ready security narrative. Trigger: C-TPAT, CBP security profile, supply chain security, trusted trader, customs validation.
-
lev-os Skill Geo SchemaSchema.org structured data audit and generation optimized for AI discoverability — detect, validate, and generate JSON-LD markup
-
techwavedev Skill Supply Chain Risk AuditorIdentifies dependencies at heightened risk of exploitation or takeover. Use when assessing supply chain attack surface, evaluating dependency health, or scoping security engagements.
-
lev-os Skill Managing Internal AuditStructures internal audit planning and execution with risk assessment, testing, and findings documentation. Use when planning internal audits, conducting audit testing, or documenting audit findings.
-
lev-os Skill Nonprofit Board MinutesDrafts legally compliant non-profit board meeting minutes with attendance, quorum, resolutions, conflict-of-interest recusals, and executive session notation. Formats output for IRS Form 990 audit, state AG scrutiny, and permanent corporate records. Use when drafting official board minutes, recording board resolutions, or creating non-profit governance records.
-
lev-os Skill Hipaa BaaDrafts HIPAA/HITECH-compliant Business Associate Agreements governing PHI/ePHI handling between covered entities and business associates. Covers Privacy Rule and Security Rule obligations, breach notification, subcontractor flow-downs, individual-rights support, and state-law overlays. Use when drafting or updating a BAA, negotiating vendor PHI access, or attaching HIPAA terms to a services agreement. Trigger keywords: BAA, business associate agreement, HIPAA contract, PHI vendor agreement, HITECH breach notice.
-
lev-os Bundle Codex AutoresearchRuns long Codex improve-verify loops with metrics and logged artifacts. Use when you want unattended overnight fix, debug, security, or ship workflows, not one-shot help.
-
techwavedev Skill Laravel Security AuditSecurity auditor for Laravel applications. Analyzes code for vulnerabilities, misconfigurations, and insecure practices using OWASP standards and Laravel security best practices.
-
techwavedev Skill Threat Modeling ExpertExpert in threat modeling methodologies, security architecture review, and risk assessment. Masters STRIDE, PASTA, attack trees, and security requirement extraction. Use for security architecture r...
-
techwavedev Bundle Vulnerability ScannerAdvanced vulnerability analysis principles. OWASP 2025, Supply Chain Security, attack surface mapping, risk prioritization.
-
techwavedev Bundle Code Review ChecklistComprehensive checklist for conducting thorough code reviews covering functionality, security, performance, and maintainability
-
lev-os Skill Taxpayer CorrespondenceDrafts structured taxpayer correspondence summarizing tax records, income, deductions, credits, and tax positions. Covers IRS/state inquiry responses, audit preparation, advisor-client communications, and filing support. Use when drafting tax summary letters, responding to tax authority notices, preparing audit defense correspondence, or organizing client tax records into structured summaries.
-
lev-os Skill Ucc Financing StatementDrafts UCC-1 Financing Statements and UCC-3 Amendments to perfect security interests under Article 9 of the Uniform Commercial Code. Handles debtor identification, collateral descriptions, filing jurisdiction, continuations, terminations, and assignments. Use when drafting UCC-1 filings, UCC-3 amendments, continuation statements, or any secured transaction perfection document.
-
lev-os Skill Ecp ManualDrafts an audit-ready Export Compliance Program manual covering EAR, ITAR, and OFAC requirements. Use when creating or updating an export compliance policy, international trade compliance program, or preparing enforcement defense documentation for regulatory review.
-
lev-os Skill Byod PolicyDrafts a Bring Your Own Device (BYOD) policy for U.S. employers governing personal device access to company systems. Covers MDM enrollment, encryption, remote wipe authority, privacy expectations, data classification, and regulatory overlays (HIPAA, GLBA, SOX, GDPR). Use when creating or updating BYOD policies, mobile device security policies, or personal device programs.
-
lev-os Skill Dd Form 254Drafts DD Form 254 Contract Security Classification Specifications for classified government contracts. Use when preparing security classification specs for prime contractors, subcontractors, SAP/SCI access, or facility clearance documentation per NISPOM (32 CFR Part 117) and DCSA regulations.
-
lev-os Skill Pos LicenseDrafts Software and POS System License Agreements for proprietary software use between licensor and licensee. Covers license grants, financial terms, IP, PCI-DSS data security, SLAs, and termination. Use when drafting POS software licenses, SaaS subscriptions, franchise technology licenses, or software distribution agreements.
-
techwavedev Skill Ssh Penetration TestingThis skill should be used when the user asks to "pentest SSH services", "enumerate SSH configurations", "brute force SSH credentials", "exploit SSH vulnerabilities", "perform SSH tu...
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include security-audit, malware-analyst, ap2-dispute-accountability. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.