Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
tomevault-io Skill Privilege Escalation MethodsThis skill should be used when the user asks to "escalate privileges", "get root access", "become administrator", "privesc techniques", "abuse sudo", "exploit SUID binaries", "Kerberoasting", "pass-the-ticket", "token impersonation", or needs guidance on post-exploitation privilege escalation for Linux or Windows systems.
-
tomevault-io Bundle Documentation QA KnowledgeDocumentation QA knowledge base. Provides quality checklists, audit criteria, and metrics for documentation review. Use when this capability is needed.
-
tomevault-io Bundle Opaque Token Based Authentication PatternSecurity pattern for server-side token authentication (e.g., session IDs). Use when implementing session management, designing stateful authentication where server maintains token-to-principal mapping, or building systems requiring immediate token revocation. Specialization of Authentication pattern. Use when this capability is needed.
-
tomevault-io Bundle Audit AI OptimizationRun a single-session AI optimization audit on the codebase Use when this capability is needed.
-
tomevault-io Bundle Stack Upgrade Audit SwiftPlan a Swift / Xcode / iOS SDK upgrade — read release notes, scan for affected patterns, survey codemods, produce a risk-ranked migration plan. Use when this capability is needed.
-
tomevault-io Bundle Stack Upgrade Fix ExpressAction findings from stack-upgrade-audit-express. Apply mechanical edits (route paths, removed APIs), bump express + Node engines + middleware, verify build, commit per category. Local only. Use when this capability is needed.
-
tomevault-io Bundle Security Test PlanningPlan security testing strategies including OWASP testing, penetration test scoping, SAST/DAST integration, and threat-based test case design. Use when this capability is needed.
-
tomevault-io Bundle Temporal Determinism AuditAudit Temporal .NET workflow code for determinism/replay safety and produce compile-ready fixes. Use when this capability is needed.
-
tomevault-io Bundle Authn Authz ReviewWorkflow to review authentication and authorization flows (sessions, tokens, RBAC/ABAC) and produce fix guidance. Use when this capability is needed.
-
tomevault-io Skill Linux Privilege EscalationThis skill should be used when the user asks to "escalate privileges on Linux", "find privesc vectors on Linux systems", "exploit sudo misconfigurations", "abuse SUID binaries", "exploit cron jobs for root access", "enumerate Linux systems for privilege escalation", or "gain root access from low-privilege shell". It provides comprehensive techniques for identifying and exploiting privilege escalation paths on Linux systems.
-
tomevault-io Bundle Working With LockdowndComprehensive toolkit for interacting with iOS devices over WiFi using the Apple Lockdown Protocol (port 62078). Capabilities include device identification, real-time log streaming (syslog/os_trace), property querying (GetValue), and cryptographic secret extraction. Incorporates research from 'The Orchard' - woflo's research project regarding iOS 17+ security boundaries and WiFi capabilities. Use when this capability is needed.
-
tomevault-io Bundle Gmh5225 Awesome AI Security Adversarial Machine LearningAdversarial Machine Learning
-
tomevault-io Bundle Jasonmichaelbell78 Creator Sonash V0 Audit DocumentationSingle-Session Documentation Audit
-
tomevault-io Bundle Rails Audit ThoughtbotPerform comprehensive code audits of Ruby on Rails applications based on thoughtbot best practices. Use this skill when the user requests a code audit, code review, quality assessment, or analysis of a Rails application. The skill analyzes the entire codebase focusing on testing practices (RSpec), security vulnerabilities, code design (skinny controllers, domain models, PORO with ActiveModel), Rails conventions, database optimization, and Ruby best practices. Outputs a detailed markdown audit report grouped by category (Testing, Security, Models, Controllers, Code Design, Views) with severity levels (Critical, High, Medium, Low) within each category. Use when this capability is needed.
-
tomevault-io Bundle Layer 03 SecurityExpert knowledge for Security Layer modeling in Documentation Robotics Use when this capability is needed.
-
tomevault-io Bundle Security Design ReviewReviews designs and business goals for security vulnerabilities, data protection (in transit/at rest), authorization, and compliance alignment. Use when the user asks for a security review, threat modeling, attack surface analysis, data leakage prevention, or compliance/security assessment. Use when this capability is needed.
-
tomevault-io Bundle Quality Manager Qms Iso13485ISO 13485 Quality Management System implementation and maintenance for medical device organizations. Provides QMS design, documentation control, internal auditing, CAPA management, and certification support. Use when working with medical device quality systems, preparing for ISO 13485 audits, managing regulatory compliance documentation, setting up corrective actions, or building audit preparation programs. Useful for quality management, audit preparation, regulatory compliance, medical device documentation, and corrective action workflows. Use when this capability is needed.
-
tomevault-io Skill Ethical Hacking MethodologyThis skill should be used when the user asks to "learn ethical hacking", "understand penetration testing lifecycle", "perform reconnaissance", "conduct security scanning", "exploit vulnerabilities", or "write penetration test reports". It provides comprehensive ethical hacking methodology and techniques.
-
tomevault-io Bundle Langchain Security ScanDefensive security scan for LangChain / LangGraph applications. Detects unsafe agents (PythonREPLTool, ShellTool), retriever trust-boundary violations, output parser injection, callback handlers leaking secrets to logs, and missing tool input validation. Invoke when the user asks to "review", "audit", or "scan" code using langchain, langgraph, or related extensions. Use when this capability is needed.
-
tomevault-io Bundle Plugin Security CheckerAdvanced security scanner for Claude Code plugins with 91 specialized pattern agents. Detects vulnerabilities, code obfuscation, and security anti-patterns across plugin manifests, agents, and scripts. Use when this capability is needed.
-
tomevault-io Bundle Helixdevelopment Helixagent Generating Security Audit ReportGenerating Security Audit Reports
-
tomevault-io Bundle Li Lance Android Seraphim Framework Common Security StandardSecurity Standards
-
tomevault-io Bundle Slack Auth SecurityOAuth flows, token management, and security best practices for Slack apps. Use when implementing app distribution, multi-workspace installations, token storage and rotation, managing scopes and permissions, or securing production Slack applications. Use when this capability is needed.
-
tomevault-io Bundle Stack Upgrade Audit ExpressPlan an Express major and/or Node.js runtime upgrade — read release notes, scan for affected patterns (route syntax, removed APIs), survey middleware co-bumps, produce a risk-ranked migration plan. Use when this capability is needed.
-
tomevault-io Bundle Gemini Config ManagementExpert guide for configuring Google Gemini CLI. Covers global vs project settings.json, Trusted Folders, Policy Engine, and environment variables. Use when configuring Gemini settings, managing trusted folders, setting up security policies, or troubleshooting configuration precedence. Delegates to gemini-cli-docs for official references. Use when this capability is needed.
-
tomevault-io Bundle Nixos ManagingUse when managing NixOS systems — rebuilding, configuring, deploying, installing, or building images. Covers flakes, modules, secret management, VM management, disk imaging, remote deployment, and common anti-patterns to avoid.
-
tomevault-io Bundle Fix DependenciesFix all vulnerabilities on the current branch using npm audit. Local branch only — no ADO/GitHub queries. Use when this capability is needed.
-
tomevault-io Bundle Tigerai Enterprise PatternsApplies TigerAI enterprise-grade design patterns when generating n8n workflows — Atomic Orchestration, Universal Worker (FastAPI), Specification-Driven Development (SDD), and security/governance constraints. Use when the user mentions enterprise / production / 企業級 / 原子化 / orchestration / FastAPI worker / SDD, or when a workflow involves heavy compute (PDF/MP3/image processing), regulated data, or multi-team handoff. Drives architectural decisions like loop transparency (batchSize=1), location-transparent workers, and mandatory error/audit annotations. Use when this capability is needed.
-
tomevault-io Bundle Goth Echo SecurityThis skill should be used when the user asks to "integrate goth with echo", "oauth echo framework", "echo authentication", "goth session management", "oauth security", "secure oauth", "gorilla sessions", or needs help with session storage, security patterns, or Echo framework integration for Goth. Use when this capability is needed.
-
tomevault-io Bundle Automated Standards EnforcementUse when creating or modifying any repository to establish automated quality enforcement (linting, spelling, tests, SAST, security). Applies by default unless user explicitly refuses. Ensures clean build policy with minimal developer friction.
-
tomevault-io Bundle Zero Trust ArchitectureUse when designing security architectures, implementing zero trust principles, or evaluating security posture. Covers never trust always verify, microsegmentation, identity-based access, and ZTNA patterns.
-
tomevault-io Bundle Sickn33 Antigravity Awesome Skills Anti Reversing Techniques> **AUTHORIZED USE ONLY**: This skill contains dual-use security techniques. Before proceeding with any bypass or analysis:
-
tomevault-io Bundle Ms365 Tenant ManagerComprehensive Microsoft 365 tenant administration skill for setup, configuration, user management, security policies, and organizational structure optimization for Global Administrators Use when this capability is needed.
-
tomevault-io Bundle Trivy Offline Vulnerability ScanningUse Trivy vulnerability scanner in offline mode to discover security vulnerabilities in dependency files. This skill covers setting up offline scanning, executing Trivy against package lock files, and generating JSON vulnerability reports without requiring internet access. Use when this capability is needed.
-
tomevault-io Bundle Audit Docs DelegationAudit skills and memory files for docs-management delegation compliance. Detects hardcoded Claude Code data and verifies proper delegation patterns. Use when this capability is needed.
-
tomevault-io Bundle Sandbox ConfigurationCentral authority for Claude Code sandboxing and isolation. Covers sandboxed bash tool, /sandbox command, filesystem isolation (blocked access, custom paths), network isolation (domain restrictions, proxy support), OS-level enforcement (bubblewrap on Linux, Seatbelt on macOS), sandbox configuration options, escape hatches (dangerouslyDisableSandbox, allowUnsandboxedCommands), and sandbox security limitations. Assists with configuring sandbox settings, understanding isolation mechanisms, and troubleshooting sandbox issues. Delegates 100% to docs-management skill for official documentation. Use when this capability is needed.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include Privilege Escalation Methods, documentation-qa-knowledge, opaque-token-based-authentication-pattern. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.