Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
javimosch Skill Dotenv Linterdotenv-linter — linter for .env files. Checks for formatting issues, duplicates, alphabetization, and security concerns.
Audited -
javimosch Skill Pip AuditUse this skill when the user wants to audit Python dependencies for known vulnerabilities, check requirements files for CVEs, or scan Python environments for security issues.
Audited -
javimosch Skill SastsweepUse this skill when the user wants to sast security scanner and vulnerability research cli.
Audited -
javimosch Skill SonarqubeSonarQube scanner for code quality and security analysis.
Audited -
javimosch Skill TerrascanInfrastructure as code security scanner.
Audited -
javimosch Skill CherrybombUse this skill when the user wants to audit API specifications, validate OpenAPI specs, or perform API security testing.
Audited -
javimosch Skill Claude RedUse this skill when the user needs offensive security expertise — penetration testing, vulnerability assessment, red team operations, bug bounty hunting, or security research for authorized engagements.
Audited -
cyberstrikeus Skill Data Security Pr Ds Data SecurityData are managed consistent with the organization's risk strategy to protect the confidentiality, integrity, and availability of information
Audited -
cyberstrikeus Skill T1655 MasqueradingAdversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools.
Audited -
cyberstrikeus Skill Mp 8 Media DowngradingEstablish [organization-defined] that includes employing downgrading mechanisms with strength and integrity commensurate with the security category...
Audited -
cyberstrikeus Skill T0820 Exploitation For EvasionAdversaries may exploit a software vulnerability to take advantage of a programming error in a program, service, or within the operating system software or kernel itself to evade detection.
Audited -
cyberstrikeus Skill T1562 010 Downgrade AttackAdversaries may downgrade or use a version of system features that may be outdated, vulnerable, and/or does not support updated security controls.
-
cyberstrikeus Skill T1564 009 Resource ForkingAdversaries may abuse resource forks to hide malicious code or executables to evade detection and bypass security applications.
Audited -
cyberstrikeus Skill T1185 Browser Session HijackingAdversaries may take advantage of security vulnerabilities and inherent functionality in browser software to change content, modify user-behaviors, and intercept information as part of various brow...
Audited -
cyberstrikeus Skill Ac 4 25 Data SanitizationWhen transferring information between different security domains, sanitize data to minimize [organization-defined] in accordance with [organization-de
Audited -
cyberstrikeus Skill Au 8 Time StampsUse internal system clocks to generate time stamps for audit records;
Audited -
cyberstrikeus Skill Pl 3 System Security Plan UpdateSystem Security Plan Update
Audited -
cyberstrikeus Skill Ps 6 Access AgreementsDevelop and document access agreements for organizational systems;
Audited -
cyberstrikeus Skill T1547 005 Security Support ProviderAdversaries may abuse security support providers (SSPs) to execute DLLs when the system boots.
-
cyberstrikeus Skill T1134 Access Token ManipulationAdversaries may modify access tokens to operate under a different user or system security context to perform actions and bypass access controls.
Audited -
cyberstrikeus Skill Ac 16 9 Attribute Reassignment Regrading MechanismsChange security and privacy attributes associated with information only via regrading mechanisms validated using [organization-defined].
Audited -
cyberstrikeus Skill Ac 4 12 Data Type IdentifiersWhen transferring information between different security domains, use [organization-defined] to validate data essential for information flow decisions
Audited -
cyberstrikeus Skill At 2 2 Insider ThreatProvide literacy training on recognizing and reporting potential indicators of insider threat.
Audited -
cyberstrikeus Skill Cm 4 Impact AnalysesAnalyze changes to the system to determine potential security and privacy impacts prior to change implementation.
Audited -
cyberstrikeus Skill Pm 26 Complaint ManagementImplement a process for receiving and responding to complaints, concerns, or questions from individuals about the organizational security and privacy
Audited -
cyberstrikeus Skill Ps 1 Policy And ProceduresDevelop, document, and disseminate to [organization-defined]: [organization-defined] personnel security policy that: Procedures to facilitate the impl
Audited -
cyberstrikeus Skill Ps 4 Personnel TerminationUpon termination of individual employment: Disable system access within [organization-defined]; Terminate or revoke any authenticators and credentials
Audited -
cyberstrikeus Skill Ps 9 Position DescriptionsIncorporate security and privacy roles and responsibilities into organizational position descriptions.
Audited -
cyberstrikeus Skill T1202 Indirect Command ExecutionAdversaries may abuse utilities that allow for command execution to bypass security restrictions that limit the use of command-line interpreters.
Audited -
cyberstrikeus Skill T1601 002 Downgrade System ImageAdversaries may install an older version of the operating system of a network device to weaken security.
Audited -
cyberstrikeus Skill Ac 2 4 Automated Audit ActionsAutomatically audit account creation, modification, enabling, disabling, and removal actions.
Audited -
cyberstrikeus Skill Ac 4 30 Filter Mechanisms Using Multiple ProcessesWhen transferring information between different security domains, implement content filtering mechanisms using multiple processes.
Audited -
cyberstrikeus Skill Ac 4 31 Failed Content Transfer PreventionWhen transferring information between different security domains, prevent the transfer of failed content to the receiving domain.
Audited -
cyberstrikeus Skill Ac 4 19 Validation Of MetadataWhen transferring information between different security domains, implement [organization-defined] on metadata.
Audited -
cyberstrikeus Skill Pm 10 Authorization ProcessManage the security and privacy state of organizational systems and the environments in which those systems operate through authorization processes;
Audited -
cyberstrikeus Skill T1430 002 Impersonate Ss7 NodesAdversaries may exploit the lack of authentication in signaling system network nodes to track the location of mobile devices by impersonating a node.
Audited
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include cherrybomb, dotenv-linter, pip-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.