Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
techwavedev Skill Privilege Escalation MethodsThis skill should be used when the user asks to "escalate privileges", "get root access", "become administrator", "privesc techniques", "abuse sudo", "exploit SUID binaries", "K...
-
techwavedev Bundle Auth Implementation PatternsMaster authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems. Use when implementing auth systems, securing APIs, or debugging security issues.
-
lev-os Skill Ucc Lien ReleaseDrafts Evidence of UCC Lien Release documents proving termination of security interests perfected under the Uniform Commercial Code. Extracts UCC-1 filing numbers, party information, and collateral descriptions from uploaded documents for compliant drafting. Use for UCC lien releases, UCC-3 termination evidence, security interest discharge certificates, or asset purchase closings requiring proof of clear title.
-
techwavedev Bundle Security Requirement ExtractionDerive security requirements from threat models and business context. Use when translating threats into actionable requirements, creating security user stories, or building security test cases.
-
techwavedev Skill Security Scanning Security SastStatic Application Security Testing (SAST) for code vulnerability analysis across multiple languages and frameworks
-
lev-os Skill Audit Compensation CharterDrafts board-adopted charters establishing Audit and Compensation Committees for U.S. corporations, covering composition, independence, delegated powers, meeting protocol, reporting, and annual review. Adapts for public (SEC/SOX/exchange) or private governance regimes. Use when creating or refreshing committee charters, preparing for IPO governance readiness, onboarding directors, or conducting governance cleanup. Trigger keywords: audit committee charter, compensation committee charter, board governance, SOX compliance, Rule 10A-3, exchange-standard committees.
-
techwavedev Bundle Dependency Management Deps AuditYou are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.
-
lev-os Skill Incident To Billing PolicyDrafts Medicare incident-to billing compliance policies for healthcare practices. Covers eligibility criteria, direct supervision, documentation standards, audit programs, and FCA risk mitigation under 42 CFR 410.26, Medicare Benefit Policy Manual Ch. 15 §60.1, and 42 U.S.C. §1395x(s)(2)(A). Use when creating or updating incident-to policies, responding to OIG scrutiny, or establishing NPP billing compliance programs.
-
lev-os Skill Know How License AgreementDrafts U.S. know-how (trade secret) license agreements covering scope, exclusivity, field-of-use, territory, consideration, confidentiality, tech transfer, diligence, and compliance. Use when licensing confidential technical information, manufacturing processes, trade secrets, non-patent IP, or process know-how; trigger keywords: know-how license, trade secret license, technology transfer agreement, confidential information license, process license, technical know-how, manufacturing know-how.
-
lev-os Skill Managing Audit PreparationStructures external audit preparation with PBC list management, supporting documentation, and inquiry responses. Use when preparing for external audit, organizing PBC items, or responding to audit inquiries.
-
lev-os Skill Managing Compliance AuditsStructures coding compliance audit programs with sampling methodology and corrective action plans. Use when conducting compliance audits, designing audit samples, or implementing corrective actions.
-
techwavedev Bundle Security Compliance Compliance CheckYou are a compliance expert specializing in regulatory requirements for software systems including GDPR, HIPAA, SOC2, PCI-DSS, and other industry standards. Perform compliance audits and provide im...
-
techwavedev Skill Security Scanning Security HardeningCoordinate multi-layer security scanning and hardening across application, infrastructure, and compliance controls.
-
lev-os Skill Security AgreementDrafts UCC Article 9 security agreements granting first-priority liens on specified collateral. Covers party identification, collateral descriptions, representations/warranties, default/remedies, and perfection requirements. Use when drafting security agreements, granting liens, creating collateral pledges, or documenting secured financing transactions.
-
lev-os Bundle Skill DecompileDecompile any SKILL.md into deterministic YAML for structural security analysis. Extracts permissions, surfaces, risk signals, and produces a scored verdict.
-
lev-os Skill Vendor Security AssessmentDrafts a Vendor Security Assessment Questionnaire evaluating third-party cybersecurity posture, data handling, and regulatory compliance. Vendor responses become binding contractual representations with executive certification. Use during vendor due diligence, third-party risk management, procurement security review, or subprocessor evaluation.
-
lev-os Skill Breach NotificationDrafts legally compliant data breach notification letters to affected consumers under multi-state and federal statutes (HIPAA, GLBA, state AG requirements). Use when drafting breach notices, security incident consumer notifications, or data compromise letters.
-
lev-os Bundle Security Best PracticesPerform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.
-
lev-os Skill Insurance Certificate ComplianceProduces requirement-by-requirement CRE insurance certificate compliance reviews by analyzing ACORD 25 certificates and endorsements against Access Agreement terms. Use when the user mentions COI review, insurance compliance, ACORD 25 analysis, Additional Insured verification, primary/non-contributory status, waiver of subrogation, vendor insurance audit, CGL compliance, umbrella follow-form, broker-ready deficiency instructions, certificate holder vs. additional insured, AI endorsements (CG 20 10, CG 20 37), or carrier rating checks.
-
lev-os Skill Nda Government DataDrafts Non-Disclosure Agreements for protecting sensitive government data across classified, CUI, SBU, and PII categories with federal regulatory compliance (FOIA, FISMA, NIST, Privacy Act, Trade Secrets Act). Covers security clearance requirements, mandatory disclosure protocols, NISPOM-compliant destruction, and government-specific remedies. Use when drafting NDAs for government contractors, federal data sharing agreements, or confidentiality agreements involving government entities.
-
lev-os Skill Calculating Net Asset ValueStructures NAV calculation with security pricing, accruals, expense allocation, and reconciliation. Use when calculating fund NAV, pricing portfolios, or reconciling NAV components.
-
lev-os Skill Data Breach Consumer NoticeDrafts U.S. consumer data breach notification letters satisfying multi-state breach-notice content rules and sector regimes (HIPAA, GLBA, PCI). Produces compliance scoping tables, data-element disclosures, remediation summaries, and consumer protection guidance tailored to incident facts and recipient cohorts. Use for multi-state breach letters, consumer breach notification, security incident notice, PII exposure notice, or sector-specific breach compliance.
-
lev-os Skill Security ScannerScan installed plugins and skills for security risks including malicious code AND malicious natural language instructions. Use /security-scanner to audit before installation.
-
lev-os Bundle Multi Pass Bug HuntingSystematic audit-fix-rescan cycle for comprehensive bug elimination. Use when code review, deep audit, "find all bugs", or pre-release hardening.
-
lev-os Skill Geo Platform OptimizerPlatform-specific AI search optimization — audit and optimize for Google AI Overviews, ChatGPT, Perplexity, Gemini, and Bing Copilot individually
-
lev-os Skill Awa Compliance AuditProduces an enforcement-aware Animal Welfare Act compliance audit for USDA/APHIS-regulated facilities. Maps Form 7002 inspection citations to verified 9 C.F.R. Parts 1-3 requirements, analyzes NCI severity and recurrence patterns, evaluates core compliance programs (PVC, IACUC, housing, records, transport), and outputs a prioritized corrective action plan with proof artifacts. Use when auditing AWA compliance, reviewing USDA inspection reports, preparing for license renewal, conducting diligence, or assessing enforcement risk. Trigger: Animal Welfare Act, AWA, USDA, APHIS, Form 7002, IACUC, PVC, exhibitor, dealer, research facility.
-
lev-os Skill Chart Audit ProtocolDrafts healthcare chart audit protocols covering clinical documentation review, coding accuracy, and billing compliance. Aligns with Medicare CoPs, OIG Compliance Program Guidance, RAC preparedness, federal sentencing guidelines, and the 60-day overpayment rule. Use when drafting routine periodic audits, targeted risk reviews, proactive compliance measures, or post-regulatory-update assessments.
-
lev-os Skill Compliance SummariesGenerates structured compliance summaries assessing regulatory posture, identifying gaps, and producing prioritized remediation roadmaps across finance (SEC, FINRA), healthcare (HIPAA, FDA), environmental (EPA), and data privacy (GDPR, CCPA) sectors. Use when drafting regulatory compliance reports, audit readiness assessments, or governance documents for executives, boards, or regulators.
-
lev-os Skill Related Party Transaction PolicyDrafts a board-adoptable Related Party Transaction Policy for U.S. corporations governing identification, Audit Committee review, approval, and disclosure of related party transactions. Enforces SEC Item 404(a)/Regulation S-K compliance and stock exchange listing standards. Use when creating or updating RPT policies for public or private companies, or when drafting corporate governance documents addressing conflicts of interest.
-
cshara1 Skill Security And HardeningHardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services.
-
lev-os Skill Ip Portfolio SummarySummarizes and analyzes a U.S. corporate IP portfolio covering patents, trademarks, copyrights, and trade secrets. Use when conducting an IP audit, due diligence review, M&A assessment, licensing strategy, executive briefing, or portfolio optimization.
-
lev-os Skill Loc Security DepositDrafts irrevocable standby letters of credit serving as security deposits in commercial lease transactions. Use when a tenant provides an LOC alternative to a cash deposit, when drafting standby LOC instruments for lease security, or when structuring bank guarantees for tenant obligations under UCC Article 5 and ISP98.
-
lev-os Skill Information Security PolicyDrafts a board-approvable Information Security Policy covering data classification, access controls, encryption, incident response, breach notification, and enforcement. Tailored by industry and regulatory environment (HIPAA, GDPR, CCPA, GLBA, FERPA, PCI DSS). Use when drafting or overhauling an organization's foundational information security governance framework or cybersecurity policy.
-
lev-os Skill Lease Termination AgreementDrafts a mutual early lease termination agreement for U.S. commercial and residential properties. Covers party identification, termination mechanics, property surrender, financial settlement (prorated rent, security deposit accounting), mutual release with carve-outs, and execution formalities. Use when landlord and tenant agree to end a lease before expiration, when negotiating buyout terms, or resolving disputes through consensual termination.
-
lev-os Skill Loan And Security AgreementDrafts a U.S. secured Loan and Security Agreement with UCC Article 9 security interests, perfection mechanics, covenants, and enforcement remedies. Use when documenting secured commercial loans, acquisition financing, working capital facilities, or equipment financing requiring perfected lien documentation.
-
lev-os Skill Loan Modification AgreementDrafts a U.S. commercial Loan Modification Agreement amending existing loan terms (interest rates, payment schedules, maturity dates, covenants) while preserving enforceability of original loan documents, security interests, and guarantees without novation. Use when restructuring commercial loans, extending maturities, modifying covenants, formalizing forbearance, or documenting workout arrangements.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include privilege-escalation-methods, security-scanning-security-sast, security-requirement-extraction. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.