Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
thomasmoreai Skill Us Hipaa SecurityHIPAA Security Rule expert for US healthcare compliance. Deep knowledge of 45 CFR Part 164 Subpart C, Administrative/Physical/Technical Safeguards, Required vs Addressable specifications, Risk Analysis, Business Associate Agreements, and HHS OCR enforcement.
Audited -
thomasmoreai Skill License Agreement SummaryProduces a structured U.S. IP license agreement summary covering parties, grant scope, exclusivity, territory, financial terms, restrictions, IP management, risk allocation, and termination. Use when summarizing IP license agreements, extracting deal terms, or flagging licensing risks. Trigger keywords: license agreement, IP license, royalty, exclusivity, field of use, sublicense, audit, termination.
Audited -
thomasmoreai Skill Solar Site LeaseDrafts U.S. solar site lease agreements between landowners and solar developers for long-term ground leases of solar PV facilities. Covers option and lease terms, rent structures, easements, construction and operations rights, decommissioning security, insurance and indemnity, tax and REC allocation, assignment and lender protections, defaults, and memorandum of lease. Use when drafting solar farm land leases, solar PV site leases, renewable energy land leases, or solar facility ground lease agreements.
Audited -
thomasmoreai Skill Ctpat Security ProfileDrafts a submission-ready C-TPAT Security Profile from verified company records for U.S. CBP enrollment, recertification, or validation prep. Use when preparing security profiles for importers, brokers, freight forwarders, or logistics participants. Trigger keywords: C-TPAT, CTPAT, CBP, security profile, customs compliance, validation visit, revalidation.
Audited -
diegosouzapw Bundle Firmware Analyst V2Download from vendor workflow skill. Use this skill when the user needs Expert firmware analyst specializing in embedded systems, IoT security, and hardware reverse engineering and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Gha Security ReviewGitHub Actions Security Review workflow skill. Use this skill when the user needs Find exploitable vulnerabilities in GitHub Actions workflows. Every finding MUST include a concrete exploitation scenario — if you can't build the attack, don't report it and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Pentest Commands V2Pentest Commands workflow skill. Use this skill when the user needs Provide a comprehensive command reference for penetration testing tools including network scanning, exploitation, password cracking, and web application testing. Enable quick command lookup during security assessments and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Production Audit V2Production Audit workflow skill. Use this skill when the user needs Audit a shipped repo for production-readiness gaps across RLS, webhooks, secrets, grants, Stripe idempotency, mobile UX, and deployment health and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Project Skill AuditProject Skill Audit workflow skill. Use this skill when the user needs Audit a project and recommend the highest-value skills to add or update and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Security Auditor V2security-auditor workflow skill. Use this skill when the user needs Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Security Auditor V3security-auditor workflow skill. Use this skill when the user needs Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Variant Analysis V2Variant Analysis workflow skill. Use this skill when the user needs Find similar vulnerabilities and bugs across codebases using pattern-based analysis. Use when hunting bug variants, building CodeQL/Semgrep queries, analyzing security vulnerabilities, or performing systematic code audits after finding an initial issue and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle API Security TestingAPI Security Testing Workflow workflow skill. Use this skill when the user needs API security testing workflow for REST and GraphQL APIs covering authentication, authorization, rate limiting, input validation, and security best practices and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
thomasmoreai Skill Know How LicenseDrafts Know-How License Agreements for licensing trade secrets, confidential processes, and proprietary methodologies where value derives from secrecy rather than patents. Reviews transaction documents to extract deal terms, financial structures, and exclusivity provisions. Use when drafting know-how licenses, trade secret licenses, technology transfer agreements, or confidential information licensing agreements.
Audited -
thomasmoreai Skill Ucc Lien ReleaseDrafts Evidence of UCC Lien Release documents proving termination of security interests perfected under the Uniform Commercial Code. Extracts UCC-1 filing numbers, party information, and collateral descriptions from uploaded documents for compliant drafting. Use for UCC lien releases, UCC-3 termination evidence, security interest discharge certificates, or asset purchase closings requiring proof of clear title.
Audited -
thomasmoreai Skill Us Sox ExpertSarbanes-Oxley Act of 2002 (SOX) expert for ICFR-relevant IT and security work. Deep knowledge of 15 U.S.C. §§ 7201 et seq., §302/§404/§906 certifications, accelerated/non-accelerated filer scoping, ITGC testing across the four classic domains (Access, Change, Operations, Development), entity-level controls, IT-dependent manual controls, deficiency evaluation, SOC 1 vendor reliance, and the SEC/PCAOB/DOJ enforcement triangle.
Audited -
thomasmoreai Skill Arckit Ca Soia[COMMUNITY] Generate a Canada Security of Information Act handling plan — Special Operational Information (SOI) register, marking and handling matrix, transmission channels, compartments and need-to-know, destruction and sanitisation, CSIS Act §16 and §19 coordination, RCMP NSP liaison, breach response, personnel reliability prerequisites.
Audited -
thomasmoreai Skill Schutzrechts PortfolioUnternehmen oder Kanzlei muss IP-Portfolio verwalten und anstehende Fristen im Blick behalten. Schutzrechtsportfolio-Verwaltung. Prüfraster: Eintragungen Verlaengerungen Jahresgebühren Benutzungsnachweise Fristkalender. Output: Fristenkalender und Portfolio-Audit mit Luecken Verfall und Benutzungsfragen. Abgrenzung zu schutzschrift-eilverfuegung (Verletzungsverteidigung) und markenanmeldung-dpma.
Audited -
thomasmoreai Skill Swift CspExpert SWIFT Customer Security Programme (CSP) advisor covering the Customer Security Controls Framework (CSCF v2025). Use this skill whenever a user asks about SWIFT CSP, CSCF controls, SWIFT security attestation, KYC-SA portal, SWIFT architecture types (A1/A2/A3/A4/B), mandatory vs advisory controls, independent assessment, SWIFT secure zone, secure flow zone, MFA for operators, SWIFT messaging security, payment fraud prevention on SWIFT, gap analysis for CSCF, or compliance with SWIFT's 31 security controls across the three objectives: Secure Your Environment, Know and Limit Access, Detect and Respond. Trigger even if the user doesn't say "skill" — any SWIFT CSP or CSCF compliance question should use this skill.
Audited -
thomasmoreai Skill Hipaa AssessorAssess a target system against HIPAA Privacy Rule, Security Rule, and Breach Notification Rule using the hipaa-foundation repository, including entity-role triage, addressable-spec handling, domain selection, evidence mapping, and structured draft output.
Audited -
thomasmoreai Skill Audit ArchiveArchives non-permanent URLs in legal document footnotes using the perma.cc API, then writes the resulting perma.cc links back to the DOCX file. Use this during a Bluebook audit workflow after footnote data has been extracted.
Audited -
thomasmoreai Skill Security AgreementDrafts UCC Article 9 security agreements granting first-priority liens on specified collateral. Covers party identification, collateral descriptions, representations/warranties, default/remedies, and perfection requirements. Use when drafting security agreements, granting liens, creating collateral pledges, or documenting secured financing transactions.
Audited -
thomasmoreai Skill Admin ReviewReviews administrative case documents for procedural compliance across 38 checkpoints, covering filing, summons, handling outcomes, evidence, and rights protection. Use when auditing public security administrative case files in txt format for legal procedure violations.
Audited -
thomasmoreai Skill Pruefer Uebergabe PaketÜbergabepaket für Prüferwechsel im 3D-Review zusammenstellen: aktueller Stand, offene Positionen. Normen: §§ 174 ff. InsO. Prüfraster: Fortschrittsstand, kritische Punkte, Dokumentation. Output: Übergabedokument für naechsten Prüfer. Abgrenzung: nicht Audit-Trail.
Audited -
thomasmoreai Skill Gesellschafts ComplianceGesellschafts-Compliance-Tracker – Initialisierung, Fälligkeitsbericht, Status-Update, Gesundheits-Audit, Export. Pflegt eine compliance-tracker.yaml aus der Gesellschaftstabelle, berechnet Einreichungsfristen nach Rechtsträger und Rechtsordnung und zeigt auf, was in den nächsten 30/60/90 Tagen fällig ist. Trigger: "Gesellschafts-Compliance", "Einreichungsfristen", "Bilanzpublizität", "Transparenzregister", "Jahresabschluss einreichen", "was ist fällig".
Audited -
thomasmoreai Skill Infringement Triage StubbiInfringement triage across trademark, copyright, patent, and trade secret — a flag list with the factors cutting each way, not a finding.
Audited -
thomasmoreai Skill Field Of Use Restriction ClauseDrafts enforceable Field of Use restriction clauses for U.S. IP licensing agreements (patent, software, trade secret, know-how). Covers permitted and restricted applications, sublicense limits, derivative-use treatment, audit and compliance mechanics, and remedy framework. Use when narrowing licensee exploitation rights, setting enforcement triggers, or preserving licensor rights outside scope during negotiation or formation. Triggers: field of use, permitted use, restricted use, sublicensing, derivative works, audit rights, IP licence scope, patent software licensing.
Audited -
thomasmoreai Skill Mortgage Deed Of TrustDrafts recording-ready residential Mortgages or Deeds of Trust with jurisdiction-appropriate instrument selection, uniform covenants, default/foreclosure provisions, and execution formalities. Use when drafting mortgage instruments, deeds of trust, security instruments for home loans, or real estate financing documents.
Audited -
thomasmoreai Skill Consent AuditPrueft Einwilligungs-Flows auf DSGVO-Konformitaet: DOI-Token-Ablauf, Widerruf-Workflow, Cookie-Banner
-
thomasmoreai Skill Citation AuditorAudit a markdown file by chunking it, extracting claims with structured output, routing each claim to verifier skills, aggregating verdicts, and rendering annotated markdown.
Audited -
thomasmoreai Skill Ksb D12 K0014Regulatory Compliance Framework: Compliance risk assessment and management, audit readiness and inspection preparation, corrective ac...
Audited -
thomasmoreai Skill Nda Government DataDrafts Non-Disclosure Agreements for protecting sensitive government data across classified, CUI, SBU, and PII categories with federal regulatory compliance (FOIA, FISMA, NIST, Privacy Act, Trade Secrets Act). Covers security clearance requirements, mandatory disclosure protocols, NISPOM-compliant destruction, and government-specific remedies. Use when drafting NDAs for government contractors, federal data sharing agreements, or confidentiality agreements involving government entities.
Audited -
thomasmoreai Skill Know How License AgreementDrafts U.S. know-how (trade secret) license agreements covering scope, exclusivity, field-of-use, territory, consideration, confidentiality, tech transfer, diligence, and compliance. Use when licensing confidential technical information, manufacturing processes, trade secrets, non-patent IP, or process know-how; trigger keywords: know-how license, trade secret license, technology transfer agreement, confidential information license, process license, technical know-how, manufacturing know-how.
Audited -
thomasmoreai Skill Residential LeaseDrafts jurisdictionally compliant U.S. residential lease agreements with required disclosures, security deposit compliance, and Fair Housing Act conformance. Conducts state-specific landlord-tenant law research and produces execution-ready leases. Use when drafting residential leases, rental agreements, landlord-tenant contracts, or tenancy agreements.
Audited -
thomasmoreai Skill Compliance CheckerCheck affiliate content for FTC compliance and platform rules. Triggers on: "check my content for compliance", "FTC disclosure check", "is this legal", "review for compliance", "check affiliate disclosure", "am I FTC compliant", "audit my content", "compliance review", "legal check", "platform rules check", "check before publishing", "disclosure audit", "review my ad copy".
Audited -
thomasmoreai Skill C Tpat Security ProfileDrafts a U.S. C-TPAT Security Profile for CBP submission covering physical, personnel, procedural, conveyance, and IT security domains. Use when preparing C-TPAT enrollment, certification, validation, or recertification profiles, or assembling a CBP-ready security narrative. Trigger: C-TPAT, CBP security profile, supply chain security, trusted trader, customs validation.
Audited
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include citation-auditor, c-tpat-security-profile, us-hipaa-security. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.