Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
cyberstrikeus Skill Cis Ubuntu1804 V220 5 2 4 45.2.4.4 Ensure the audit log directory is 0750 or more restrictive
Audited -
cyberstrikeus Skill Cis Ubuntu1804 V220 5 2 4 55.2.4.5 Ensure audit configuration files are 640 or more restrictive
-
cyberstrikeus Skill Cis Ubuntu1804 V220 5 2 4 65.2.4.6 Ensure audit configuration files are owned by root
-
cyberstrikeus Skill Cis Ubuntu1804 V220 5 2 4 75.2.4.7 Ensure audit configuration files belong to group root
-
cyberstrikeus Skill Cis Ubuntu1804 V220 5 2 4 85.2.4.8 Ensure audit tools are 755 or more restrictive
Audited -
cyberstrikeus Skill Cis Ubuntu1804 V220 5 2 4 95.2.4.9 Ensure audit tools are owned by root
Audited -
cyberstrikeus Skill Cis Ubuntu2004 V300 1 2 2 1Ensure updates, patches, and additional security software are installed
Audited -
diegosouzapw Bundle File Path Traversal V2File Path Traversal Testing workflow skill. Use this skill when the user needs Identify and exploit file path traversal (directory traversal) vulnerabilities that allow attackers to read arbitrary files on the server, potentially including sensitive configuration files, credentials, and source code and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Gha Security Review V2GitHub Actions Security Review workflow skill. Use this skill when the user needs Find exploitable vulnerabilities in GitHub Actions workflows. Every finding MUST include a concrete exploitation scenario — if you can't build the attack, don't report it and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Laravel Security AuditLaravel Security Audit workflow skill. Use this skill when the user needs Security auditor for Laravel applications. Analyzes code for vulnerabilities, misconfigurations, and insecure practices using OWASP standards and Laravel security best practices and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
Audited 54 -
diegosouzapw Bundle Wcag Audit Patterns V2WCAG Audit Patterns workflow skill. Use this skill when the user needs Comprehensive guide to auditing web content against WCAG 2.2 guidelines with actionable remediation strategies and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle API Endpoint Builder V2API Endpoint Builder workflow skill. Use this skill when the user needs Builds production-ready REST API endpoints with validation, error handling, authentication, and documentation. Follows best practices for security and scalability and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle API Security Testing V2API Security Testing Workflow workflow skill. Use this skill when the user needs API security testing workflow for REST and GraphQL APIs covering authentication, authorization, rate limiting, input validation, and security best practices and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Codebase Audit Pre PushPre-Push Codebase Audit workflow skill. Use this skill when the user needs Deep audit before GitHub push: removes junk files, dead code, security holes, and optimization issues. Checks every file line-by-line for production readiness and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Smtp Penetration TestingSMTP Penetration Testing workflow skill. Use this skill when the user needs Conduct comprehensive security assessments of SMTP (Simple Mail Transfer Protocol) servers to identify vulnerabilities including open relays, user enumeration, weak authentication, and misconfiguration and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Vulnerability Scanner V2Vulnerability Scanner workflow skill. Use this skill when the user needs Advanced vulnerability analysis principles. OWASP 2025, Supply Chain Security, attack surface mapping, risk prioritization and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Vulnerability Scanner V3Vulnerability Scanner workflow skill. Use this skill when the user needs Advanced vulnerability analysis principles. OWASP 2025, Supply Chain Security, attack surface mapping, risk prioritization and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Audit Context Building V2Deep Context Builder Skill (Ultra-Granular Pure Context Mode) workflow skill. Use this skill when the user needs Enables ultra-granular, line-by-line code analysis to build deep architectural context before vulnerability or bug finding and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
Audited 54 -
diegosouzapw Bundle Backend Security Coder V2backend-security-coder workflow skill. Use this skill when the user needs Expert in secure backend coding practices specializing in input validation, authentication, and API security. Use PROACTIVELY for backend security implementations or security code reviews and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Backend Security Coder V3backend-security-coder workflow skill. Use this skill when the user needs Expert in secure backend coding practices specializing in input validation, authentication, and API security. Use PROACTIVELY for backend security implementations or security code reviews and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Laravel Security Audit V2Laravel Security Audit workflow skill. Use this skill when the user needs Security auditor for Laravel applications. Analyzes code for vulnerabilities, misconfigurations, and insecure practices using OWASP standards and Laravel security best practices and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
Audited 54 -
diegosouzapw Bundle Supply Chain Risk AuditorSupply Chain Risk Auditor workflow skill. Use this skill when the user needs Identifies dependencies at heightened risk of exploitation or takeover. Use when assessing supply chain attack surface, evaluating dependency health, or scoping security engagements and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Swiftui Performance AuditSwiftUI Performance Audit workflow skill. Use this skill when the user needs Audit SwiftUI performance issues from code review and profiling evidence and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Threat Modeling Expert V2Threat Modeling Expert workflow skill. Use this skill when the user needs Expert in threat modeling methodologies, security architecture review, and risk assessment. Masters STRIDE, PASTA, attack trees, and security requirement extraction. Use PROACTIVELY for security architecture reviews, threat identification, or building secure-by-design systems and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Codebase Audit Pre Push V2Pre-Push Codebase Audit workflow skill. Use this skill when the user needs Deep audit before GitHub push: removes junk files, dead code, security holes, and optimization issues. Checks every file line-by-line for production readiness and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
cyberstrikeus Skill Cis Ubuntu2004 V300 6 3 2 1Ensure audit log storage size is configured
Audited -
cyberstrikeus Skill Cis Ubuntu2004 V300 6 3 2 2Ensure audit logs are not automatically deleted
Audited -
cyberstrikeus Skill Cis Ubuntu2004 V300 6 3 2 3Ensure system is disabled when audit logs are full
Audited -
cyberstrikeus Skill Cis Ubuntu2004 V300 6 3 2 4Ensure system warns when audit logs are low on space
Audited -
cyberstrikeus Skill Cis Ubuntu2004 V300 6 3 4 16.3.4.1 Ensure audit log files mode is configured (Automated)
-
cyberstrikeus Skill Cis Ubuntu2004 V300 6 3 4 26.3.4.2 Ensure audit log files owner is configured (Automated)
-
cyberstrikeus Skill Cis Ubuntu2004 V300 6 3 4 36.3.4.3 Ensure audit log files group owner is configured (Automated)
-
cyberstrikeus Skill Cis Ubuntu2004 V300 6 3 4 46.3.4.4 Ensure the audit log file directory mode is configured (Automated)
Audited -
cyberstrikeus Skill Cis Ubuntu2004 V300 6 3 4 56.3.4.5 Ensure audit configuration files mode is configured (Automated)
-
cyberstrikeus Skill Cis Ubuntu2004 V300 6 3 4 66.3.4.6 Ensure audit configuration files owner is configured (Automated)
-
cyberstrikeus Skill Cis Ubuntu2004 V300 6 3 4 76.3.4.7 Ensure audit configuration files group owner is configured (Automated)
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include cis-ubuntu1804-v220-5-2-4-4, cis-ubuntu1804-v220-5-2-4-5, cis-ubuntu1804-v220-5-2-4-6. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.