Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
javimosch Skill BanditUse this skill when the user wants to find security issues in Python code, scan for vulnerabilities, check for unsafe imports, or audit Python security.
Audited -
javimosch Skill DeptryUse this skill when the user wants to check Python project dependencies for unused or missing packages, or audit dependency health.
Audited -
javimosch Skill DnsenumUse this skill when the user wants to enumerate DNS information about a domain for security testing or reconnaissance.
Audited -
javimosch Skill GhalintUse this skill when the user wants to github actions workflow linter for security best practices.
Audited -
javimosch Skill HorusecUse this skill when the user wants to scan for security vulnerabilities, perform SAST analysis, or check code for security issues.
Audited -
javimosch Skill LinkerdLinkerd service mesh CLI for observability and security.
Audited -
javimosch Skill LockenvUse this skill when the user wants to manage encrypted .env files, protect secrets in git repositories, or work with password-based secret vaults.
Audited -
javimosch Skill TalismanSecret scanner for git repositories
Audited -
javimosch Skill Cargo OutdatedUse this skill when the user wants to check for outdated Rust dependencies, see available dependency updates, or audit crate versions.
Audited -
javimosch Skill Dockerfile LintUse this skill when the user wants to lint Dockerfiles for best practices, security, and portability issues.
Audited -
javimosch Skill Audit WorkflowRun crawl/analyze/report workflow with squirrelscan using supercli.
Audited -
cyberstrikeus Skill Wstg Clnt 01 1Testing for Self DOM-Based XSS
Audited -
cyberstrikeus Skill Wstg InjectionWSTG input validation and injection testing - SQLi, XSS, SSTI, SSRF, command injection, XXE
-
cyberstrikeus Skill De Ae 07 Deae 07Cyber threat intelligence and other contextual information are integrated into the analysis
Audited -
cyberstrikeus Skill Gv Sc 09 Gvsc 09Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored througho
Audited -
cyberstrikeus Skill Wstg Logic Client APIWSTG business logic, client-side, and API security testing
Audited -
cyberstrikeus Skill Pr Ip 01 Prip 01A baseline configuration of information technology/industrial control systems is created and maintained incorporating security principles (e.g.
Audited -
cyberstrikeus Skill Pr Pt 01 Prpt 01Audit/log records are determined, documented, implemented, and reviewed in accordance with policy
Audited -
cyberstrikeus Skill Ra 7 Risk ResponseRespond to findings from security and privacy assessments, monitoring, and audits in accordance with organizational risk tolerance.
Audited -
cyberstrikeus Skill Platform Security Pr Ps Platform SecurityThe hardware, software (e.g., firmware, operating systems, applications), and services of physical and virtual platforms are managed consistent with t
Audited -
cyberstrikeus Skill Ac 4 22 Access OnlyProvide access from a single device to computing platforms, applications, or data residing in multiple different security domains, while preventing in
Audited -
cyberstrikeus Skill Mp 3 Media MarkingMark system media indicating the distribution limitations, handling caveats, and applicable security markings (if any) of the information;
Audited -
cyberstrikeus Skill T1499 004 Application Or System ExploitationAdversaries may exploit software vulnerabilities that can cause an application or system to crash and deny availability to users.
Audited -
cyberstrikeus Skill Ra 10 Threat HuntingEstablish and maintain a cyber threat hunting capability to: Search for indicators of compromise in organizational systems; and Detect, track, and dis
Audited -
cyberstrikeus Skill T1003 004 Lsa SecretsAdversaries with SYSTEM access to a host may attempt to access Local Security Authority (LSA) secrets, which can contain a variety of different credential materials, such as credentials for service...
-
cyberstrikeus Skill Po 1 1 Po11Identify and document all security requirements for the organization’s software development infrastructures and processes, and maintain the requiremen
Audited -
cyberstrikeus Skill Po 1 2 Po12Identify and document all security requirements for organization-developed software to meet, and maintain the requirements over time.
Audited -
cyberstrikeus Skill Po 4 1 Po41Define criteria for software security checks and track throughout the SDLC.
Audited -
cyberstrikeus Skill Ma 5 4 Foreign NationalsEnsure that: Foreign nationals with appropriate security clearances are used to conduct maintenance and diagnostic activities on classified systems on
Audited -
cyberstrikeus Skill T1003 001 Lsass MemoryAdversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
Audited -
cyberstrikeus Skill T1553 Subvert Trust ControlsAdversaries may undermine security controls that will either warn users of untrusted activity or prevent execution of untrusted programs.
-
cyberstrikeus Skill T1564 005 Hidden File SystemAdversaries may use a hidden file system to conceal malicious activity from users and security tools.
Audited -
cyberstrikeus Skill Technology Infrastructure Resilience Pr Ir Technology InfrasSecurity architectures are managed with the organization's risk strategy to protect asset confidentiality, integrity, and availability, and organizati
Audited -
cyberstrikeus Skill Pw 1 1 Pw11Use forms of risk modeling – such as threat modeling, attack modeling, or attack surface mapping – to help assess the security risk for the software.
Audited -
cyberstrikeus Skill Pw 1 2 Pw12Track and maintain the software’s security requirements, risks, and design decisions.
Audited -
cyberstrikeus Skill Pw 1 3 Pw13Where appropriate, build in support for using standardized security features and services (e.g., enabling software to integrate with existing log m...
Audited
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include bandit, deptry, dnsenum. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.