Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
diegosouzapw Bundle Attack Tree Construction V2Attack Tree Construction workflow skill. Use this skill when the user needs Build comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Burpsuite Project Parser V2Burp Project Parser workflow skill. Use this skill when the user needs Searches and explores Burp Suite project files (.burp) from the command line. Use when searching response headers or bodies with regex patterns, extracting security audit findings, dumping proxy history or site map data, or analyzing HTTP traffic captured in a Burp project and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Cc Skill Security Review V2Security Review Skill workflow skill. Use this skill when the user needs This skill ensures all code follows security best practices and identifies potential vulnerabilities. Use when implementing authentication or authorization, handling user input or file uploads, or creating new API endpoints and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Cc Skill Security Review V3Security Review Skill workflow skill. Use this skill when the user needs This skill ensures all code follows security best practices and identifies potential vulnerabilities. Use when implementing authentication or authorization, handling user input or file uploads, or creating new API endpoints and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Codebase Cleanup Deps AuditDependency Audit and Security Analysis workflow skill. Use this skill when the user needs You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Event Sourcing Architect V2Event Sourcing Architect workflow skill. Use this skill when the user needs Expert in event sourcing, CQRS, and event-driven architecture patterns. Masters event store design, projection building, saga orchestration, and eventual consistency patterns. Use PROACTIVELY for event-sourced systems, audit trail requirements, or complex domain modeling with temporal queries and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Event Sourcing Architect V3Event Sourcing Architect workflow skill. Use this skill when the user needs Expert in event sourcing, CQRS, and event-driven architecture patterns. Masters event store design, projection building, saga orchestration, and eventual consistency patterns. Use PROACTIVELY for event-sourced systems, audit trail requirements, or complex domain modeling with temporal queries and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Smtp Penetration Testing V2SMTP Penetration Testing workflow skill. Use this skill when the user needs Conduct comprehensive security assessments of SMTP (Simple Mail Transfer Protocol) servers to identify vulnerabilities including open relays, user enumeration, weak authentication, and misconfiguration and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Stride Analysis Patterns V2STRIDE Analysis Patterns workflow skill. Use this skill when the user needs Apply STRIDE methodology to systematically identify threats. Use when analyzing system security, conducting threat modeling sessions, or creating security documentation and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Anti Reversing Techniques V2anti-reversing-techniques workflow skill. Use this skill when the user needs AUTHORIZED USE ONLY: This skill contains dual-use security techniques. Before proceeding with any bypass or analysis: > 1 and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Protocol Reverse EngineeringProtocol Reverse Engineering workflow skill. Use this skill when the user needs Comprehensive techniques for capturing, analyzing, and documenting network protocols for security research, interoperability, and debugging and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
thomasmoreai Skill PatentPatent prior-art and landscape intelligence skill — not generic patent help. Commits to one of five sub-use-cases via forcing intake (novelty search / freedom-to-operate / competitive landscape / acquisition diligence / litigation prior-art) before any search runs. Searches Google Patents, Espacenet, USPTO, and optionally Lens.org for citation-graph signals. Output is an editable Word document (.docx) with verdict, ranked closest art (claim-text extracted), CPC-class-aware landscape, family-resolved hits, geographic coverage, FTO flags where applicable, strategy recommendations, and full audit log. Triggers: 'prior art search for [invention]', 'patent search on [topic]', 'freedom to operate analysis', 'FTO for [product]', 'patent landscape for [field]', 'is [invention] novel', 'patents on [topic]', 'competitive patent analysis', 'prior art for litigation', 'patent diligence on [company]'. Produces search signal, not legal advice — always recommends consulting a patent attorney before filing or licensing decis
Audited -
thomasmoreai Skill Nis2EU NIS2 Directive (Directive (EU) 2022/2555) compliance advisor for essential and important entities — entity classification, Art. 21 risk management measures, Art. 23 incident reporting timelines (24h/72h/1 month), Art. 20 governance obligations, supply chain security (Art. 26), gap assessments, policy drafting, ISO 27001 alignment, and penalty exposure analysis. Use for NIS2 readiness, transposition questions, ENISA guidelines, supervisory differences between essential and important entities, and cross-border coordination.
Audited -
thomasmoreai Skill BriefGenerate contextual briefings for legal work — daily summary, topic research, or incident response. Use when starting your day and need a scan of legal-relevant items across email, calendar, and contracts, when researching a specific legal question across internal sources, or when a developing situation (data breach, litigation threat, regulatory inquiry) needs rapid context.
Audited -
thomasmoreai Skill Glba ExpertGLBA expert for financial institutions. Deep knowledge of Gramm-Leach-Bliley Act including Safeguards Rule (16 CFR Part 314), Privacy Rule (16 CFR Part 313), FTC enforcement, information security program requirements, vendor management, and consumer privacy notices.
Audited -
thomasmoreai Skill Ip Portfolio SummarySummarizes and analyzes a U.S. corporate IP portfolio covering patents, trademarks, copyrights, and trade secrets. Use when conducting an IP audit, due diligence review, M&A assessment, licensing strategy, executive briefing, or portfolio optimization.
Audited -
diegosouzapw Bundle Openclaw Github Repo Commander V2OpenClaw GitHub Repo Commander workflow skill. Use this skill when the user needs 7-stage super workflow for GitHub repo audit, cleanup, PR review, and competitor analysis and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
Audited 54 -
diegosouzapw Bundle Security Requirement Extraction V2Security Requirement Extraction workflow skill. Use this skill when the user needs Derive security requirements from threat models and business context. Use when translating threats into actionable requirements, creating security user stories, or building security test cases and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Security Scanning Security Sast V2SAST Security Plugin workflow skill. Use this skill when the user needs 'Static Application Security Testing (SAST) for code vulnerability and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Dependency Management Deps Audit V2Dependency Audit and Security Analysis workflow skill. Use this skill when the user needs You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Security Compliance Compliance CheckRegulatory Compliance Check workflow skill. Use this skill when the user needs You are a compliance expert specializing in regulatory requirements for software systems including GDPR, HIPAA, SOC2, PCI-DSS, and other industry standards. Perform comprehensive compliance audits and provide implementation guidance for achieving and maintaining compliance and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Security Scanning Security Hardeningsecurity-scanning-security-hardening workflow skill. Use this skill when the user needs Coordinate multi-layer security scanning and hardening across application, infrastructure, and compliance controls and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
Audited 54 -
diegosouzapw Bundle Security Compliance Compliance Check V2Regulatory Compliance Check workflow skill. Use this skill when the user needs You are a compliance expert specializing in regulatory requirements for software systems including GDPR, HIPAA, SOC2, PCI-DSS, and other industry standards. Perform comprehensive compliance audits and provide implementation guidance for achieving and maintaining compliance and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Security Scanning Security DependenciesDependency Vulnerability Scanning workflow skill. Use this skill when the user needs You are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security. Scan project dependencies across multiple ecosystems to identify vulnerabilities, assess risks, and provide automated remediation strategies and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Security Scanning Security Hardening V2security-scanning-security-hardening workflow skill. Use this skill when the user needs Coordinate multi-layer security scanning and hardening across application, infrastructure, and compliance controls and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
Audited 54 -
diegosouzapw Bundle Security Scanning Security Dependencies V2Dependency Vulnerability Scanning workflow skill. Use this skill when the user needs You are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security. Scan project dependencies across multiple ecosystems to identify vulnerabilities, assess risks, and provide automated remediation strategies and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
thomasmoreai Skill Team SocialOrchestrate the social benefits team for Bürgergeld, ALG I unemployment benefits, health insurance, Kindergeld, and Jobcenter interactions.
Audited -
thomasmoreai Skill Curate HistoryShow audit history for a specific obligation
Audited -
thomasmoreai Skill Infringement TriageInfringement triage across trademark, copyright, patent, and trade secret — a flag list with the factors cutting each way, not a finding. Use when assessing whether someone is infringing your IP or whether you might be infringing theirs, when a knockoff or copycat surfaces, or when deciding whether a matter is worth pursuing and how.
Audited -
thomasmoreai Skill Calculating AlimentyUse when determining the amount of alimony under Polish KRO — calculating justified needs of the entitled person vs. earning/property capacity of the obligor (art. 135 KRO), applying equal-standard-of-living principle, setting up documentary evidence, drafting interim security motions under art. 754¹ KPC, or coordinating with the Fundusz Alimentacyjny when enforcement fails
Audited -
thomasmoreai Skill Deposition Ip SupplementProvides IP-specific deposition examination frameworks for patent, trademark, copyright, and trade secret cases. Covers inventor, infringer, licensing, and expert witnesses with question maps for claim construction, prior art, willfulness, Georgia-Pacific factors, likelihood of confusion, and trade secret identification. Use when preparing IP litigation depositions alongside @deposition-preparation and @deposition-expert-witness.
Audited -
thomasmoreai Skill Ip Infringement AnalysisProduces structured IP infringement memoranda evaluating patents, trademarks, copyrights, and trade secrets. Performs claim-by-claim patent comparisons, likelihood-of-confusion trademark tests, substantial similarity copyright assessments, and trade secret misappropriation evaluations with defense and remedies analysis. Use for infringement opinions, pre-filing assessments, cease-and-desist support, licensing disputes, or settlement valuation.
Audited -
thomasmoreai Skill Taxpayer CorrespondenceDrafts structured taxpayer correspondence summarizing tax records, income, deductions, credits, and tax positions. Covers IRS/state inquiry responses, audit preparation, advisor-client communications, and filing support. Use when drafting tax summary letters, responding to tax authority notices, preparing audit defense correspondence, or organizing client tax records into structured summaries.
Audited -
thomasmoreai Skill KlauselvorschlaegeLiefere konkrete Mustertexte für Vertragsklauseln mit dem KI-Anbieter. Bausteine Verschwiegenheit Belehrung §§ 203 204 StGB Subunternehmer no training Zero-Retention EU-Hosting Audit-Recht Löschkonzept Professional Secrecy Addendum für US-Anbieter Gerichtsstand Anlage Normtext. Bausteine sind Vorlagen keine fertigen Vertraege.
Audited -
thomasmoreai Skill Arckit Fr Pssi[COMMUNITY] Generate an Information System Security Policy (PSSI) for French public or private organisations — security objectives, principles, organisational structure, and applicable ANSSI/RGS standards
Audited -
thomasmoreai Skill Audit CrossrefsPhase 7: Convert hardcoded cross-references to auto-updating NOTEREF fields
Audited
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include calculating-alimenty, attack-tree-construction-v2, burpsuite-project-parser-v2. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.