Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
lev-os Skill Motion To Avoid LienDrafts a Motion to Avoid Lien under 11 U.S.C. § 522(f) for bankruptcy proceedings. Produces a litigation-ready motion with caption, impairment calculations, legal argument, and prayer for relief. Use when filing lien avoidance motions in Chapter 7, 11, or 13 cases, stripping judicial liens or nonpossessory nonpurchase-money security interests that impair debtor exemptions.
-
lev-os Skill Pledge Agreement SecuritiesDrafts perfected-security-interest Pledge Agreements for securities collateral under UCC Article 9. Use when drafting securities pledge agreements, stock pledge documents, collateral assignments, or security interest grants in investment property securing loans or credit facilities.
-
lev-os Skill Promissory Note ResidentialDrafts enforceable residential promissory notes with party identification, principal/interest terms, payment schedules, default/acceleration provisions, and security instrument cross-references. Ensures TILA awareness and state usury compliance. Use when drafting promissory notes for residential mortgages, deeds of trust, or seller-financed home sales; trigger keywords: promissory note, residential note, mortgage note, deed of trust note, seller financing note, balloon note.
-
lev-os Skill Copyright License Agreement MediaDrafts a Copyright License Agreement for media content between a Licensor and Licensee. Covers exclusive/non-exclusive grants, enumerated §106 rights, territory, term, compensation, audit rights, attribution, termination, and sell-off periods. Use when the user needs an IP license for media assets (images, video, music, software, written works, multimedia).
-
lev-os Bundle Path RationalizationAudit and clean shell PATH pollution in .bashrc, .zshrc, .zshenv, .profile. Use when PATH has junk, wrong binary resolves, temp dirs in PATH, or duplicates.
-
iradoweck Skill Pci ComplianceMaster PCI DSS (Payment Card Industry Data Security Standard) compliance for secure payment processing and handling of cardholder data.
-
lev-os Skill Tenant Estoppel CertificateDrafts tenant estoppel certificates for commercial real estate acquisitions and financings. Produces numbered certifications binding tenants to lease representations for reliance by purchasers and lenders during due diligence. Covers lease terms, rent status, defaults, options, claims, and security deposits. Use when drafting estoppel certificates, tenant certifications, lease verification documents, or property acquisition due diligence instruments.
-
lev-os Skill Trademark License AgreementDrafts a U.S. Trademark License Agreement governing a licensor's grant of rights to a licensee for authorized use of registered or common law marks. Covers exclusivity, field of use, territory, quality control, royalties, audit rights, and termination. Use when drafting IP licensing deals, brand licensing arrangements, co-branding agreements, or any transaction requiring controlled trademark use by a third party.
-
lev-os Skill Managing Cybersecurity ComplianceEvaluates cybersecurity programs against SEC, FINRA, and state regulatory requirements. Use when assessing cybersecurity compliance, implementing security frameworks, or responding to cyber requirements.
-
lev-os Skill Managing Cybersecurity HealthcareStructures healthcare cybersecurity programs with PHI protection, incident response, and risk assessment. Use when managing healthcare cybersecurity, protecting health data, or conducting security risk assessments.
-
lev-os Skill Managing Open Banking IntegrationStructures open banking API integration with data sharing, consent management, and security requirements. Use when implementing open banking, managing API integrations, or evaluating data sharing frameworks.
-
iradoweck Skill Threat Modeling ExpertExpert in threat modeling methodologies, security architecture review, and risk assessment. Masters STRIDE, PASTA, attack trees, and security requirement extraction. Use PROACTIVELY for security architecture reviews, threat identification, or building secure-by-design systems.
-
lev-os Skill Security Deposit Letter Of CreditDrafts an irrevocable standby letter of credit securing a commercial lease deposit under ISP98 and UCC Article 5. Covers documentary draw conditions, evergreen/expiry mechanics, transferability, and partial draws. Use when drafting standby LCs for lease security deposits, replacing cash deposits with LC instruments, or structuring beneficiary draw requirements.
-
lev-os Skill Nydfs Infosec ProgramDrafts a comprehensive Information Security Program compliant with NYDFS Cybersecurity Regulation (23 NYCRR 500). Covers CISO designation, risk assessment, access controls, encryption, monitoring, incident response, notification, and annual certification for covered financial services entities. Use when drafting cybersecurity programs, NYDFS compliance policies, or information security policies for financial institutions. Trigger keywords: NYDFS, 23 NYCRR 500, cybersecurity regulation, information security program, CISO policy, financial services cybersecurity.
-
iradoweck Skill Top Web VulnerabilitiesProvide a comprehensive, structured reference for the 100 most critical web application vulnerabilities organized by category. This skill enables systematic vulnerability identification, impact assessment, and remediation guidance across the full spectrum of web security threats.
-
iradoweck Skill Cc Skill Security ReviewThis skill ensures all code follows security best practices and identifies potential vulnerabilities. Use when implementing authentication or authorization, handling user input or file uploads, or creating new API endpoints.
-
iradoweck Skill Event Sourcing ArchitectExpert in event sourcing, CQRS, and event-driven architecture patterns. Masters event store design, projection building, saga orchestration, and eventual consistency patterns. Use PROACTIVELY for event-sourced systems, audit trail requirements, or complex domain modeling with temporal queries.
-
iradoweck Skill Linux Privilege EscalationExecute systematic privilege escalation assessments on Linux systems to identify and exploit misconfigurations, vulnerable services, and security weaknesses that allow elevation from low-privilege user access to root-level control.
-
lev-os Skill Managing Retirement PlanningStructures retirement income analysis with Social Security optimization, distribution sequencing, and longevity modeling. Use when planning retirement income, optimizing Social Security, or modeling retirement spending.
-
iradoweck Skill Security And HardeningHardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services.
-
iradoweck Skill API Security Best PracticesImplement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilities
-
iradoweck Bundle Auth Implementation PatternsBuild secure, scalable authentication and authorization systems using industry-standard patterns and modern best practices.
-
iradoweck Skill Security AuditComprehensive security auditing workflow covering web application testing, API security, penetration testing, vulnerability scanning, and security hardening.
-
lev-os Bundle Convex Performance AuditAudits Convex performance for reads, subscriptions, write contention, and function limits. Use for slow features, insights findings, OCC conflicts, or read amplification.
-
lev-os Skill Collateral Assignment Of ContractsDrafts a Collateral Assignment of Contracts assigning a borrower's contractual rights as security for debt under UCC Article 9. Triggers when securing lender interests in contract rights, drafting pre-closing security documents, or structuring collateral packages for U.S. commercial credit facilities.
-
lev-os Skill Confidentiality Security AgreementDrafts enforceable U.S. Employee Confidentiality and Security Agreements protecting proprietary information, trade secrets, and digital assets, with layered confidential-information definitions, security and acceptable-use obligations, incident reporting protocols, termination property-return procedures, and post-employment restrictive covenants. Incorporates state-specific enforceability standards, DTSA whistleblower immunity notice, and NLRA Section 7 savings clauses. Use when onboarding employees, updating confidentiality policies, or drafting NDA-style employment agreements (trigger keywords: confidentiality agreement, employee NDA, security agreement, trade secret, acceptable use, incident reporting, post-employment restrictions).
-
lev-os Skill Corrective Action PlanDrafts healthcare Corrective Action Plans (CAPs) responding to CMS survey deficiencies, Joint Commission findings, state inspection citations, or internal audit results. Structures root cause analysis, remediation steps, accountability, timelines, and monitoring. Use when drafting plans of correction, responding to immediate jeopardy findings, condition-level citations, or standard-level deficiencies.
-
lev-os Skill Ctpat Security ProfileDrafts a submission-ready C-TPAT Security Profile from verified company records for U.S. CBP enrollment, recertification, or validation prep. Use when preparing security profiles for importers, brokers, freight forwarders, or logistics participants. Trigger keywords: C-TPAT, CTPAT, CBP, security profile, customs compliance, validation visit, revalidation.
-
lev-os Skill Employee Confidentiality AgreementDrafts enforceable Employee Confidentiality and Security Agreements protecting trade secrets, proprietary information, and digital assets. Incorporates DTSA whistleblower notice, state-specific enforceability, NLRA carveouts, and data privacy compliance. Use when onboarding employees, updating confidentiality policies, or creating security agreements for data privacy and cybersecurity contexts.
-
lev-os Skill Managing Clinical Trial ComplianceEvaluates clinical trial regulatory compliance with FDA/IRB requirements and audit readiness. Use when auditing trial compliance, preparing for FDA inspections, or managing regulatory requirements.
-
lev-os Bundle Swiftui Performance AuditAudit and improve SwiftUI runtime performance from code review and architecture. Use for requests to diagnose slow rendering, janky scrolling, high CPU/memory usage, excessive view updates, or layout thrash in SwiftUI apps, and to provide guidance for user-run Instruments profiling when code review alone is insufficient.
-
lev-os Skill Mortgage Deed Of TrustDrafts recording-ready residential Mortgages or Deeds of Trust with jurisdiction-appropriate instrument selection, uniform covenants, default/foreclosure provisions, and execution formalities. Use when drafting mortgage instruments, deeds of trust, security instruments for home loans, or real estate financing documents.
-
lev-os Skill Consumer Breach Notice LetterDrafts U.S. consumer-facing data breach notification letters compliant with state statutes. Use when a security incident involving personal information requires consumer notice — first, interim, or follow-up. Covers jurisdiction-aware content, incident disclosure, compromised-data specificity, mitigation steps, support services, and delivery requirements. Trigger: data breach notice, consumer notification, personal information incident, identity theft letter, substitute notice.
-
lev-os Skill Managing API Banking AnalysisStructures banking API evaluation with functionality assessment, security review, and integration planning. Use when evaluating banking APIs, planning API integration, or assessing API security.
-
lev-os Skill Analyzing Tokenization ApplicationsEvaluates real-world asset tokenization with legal structure, market infrastructure, and liquidity analysis. Use when analyzing tokenization, evaluating security tokens, or assessing asset digitization.
-
lev-os Skill Corrective Action Plan DeficienciesDrafts a regulator-ready Corrective Action Plan (CAP) for U.S. healthcare facilities responding to inspection, survey, or audit deficiencies. Covers root-cause analysis, remediation steps, accountability, milestones, monitoring, and validation. Trigger when the user mentions CAP, plan of correction, deficiency citation, scope/severity remediation, correction timeline, or sustainability monitoring for CMS, state, or Joint Commission findings.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include security-and-hardening, analyzing-tokenization-applications, managing-retirement-planning. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.