Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
thomasmoreai Skill Trademark License AgreementDrafts a U.S. Trademark License Agreement governing a licensor's grant of rights to a licensee for authorized use of registered or common law marks. Covers exclusivity, field of use, territory, quality control, royalties, audit rights, and termination. Use when drafting IP licensing deals, brand licensing arrangements, co-branding agreements, or any transaction requiring controlled trademark use by a third party.
Audited -
thomasmoreai Skill Audit ComplianceCheck that your legal compliance is still in good shape. Pick what to check: your privacy policy, your privacy vendor list, or your contract templates. I surface what's drifted or out of date and what to fix. I never change anything on my own.
Audited -
thomasmoreai Skill Regulatory ComplianceMulti-sector regulatory compliance skill for industry-specific regulations. Use when the user needs assistance with regulatory frameworks, compliance programs, regulatory investigations, or industry-specific requirements across sectors. Triggers on keywords like "regulatory", "compliance program", "regulated industry", "agency", "enforcement", "regulatory investigation", "consent decree", "compliance audit", "regulatory risk".
Audited -
thomasmoreai Skill Incident To Billing PolicyDrafts Medicare incident-to billing compliance policies for healthcare practices. Covers eligibility criteria, direct supervision, documentation standards, audit programs, and FCA risk mitigation under 42 CFR 410.26, Medicare Benefit Policy Manual Ch. 15 §60.1, and 42 U.S.C. §1395x(s)(2)(A). Use when creating or updating incident-to policies, responding to OIG scrutiny, or establishing NPP billing compliance programs.
Audited -
diegosouzapw Bundle Metasploit Framework V2Metasploit Framework workflow skill. Use this skill when the user needs ⚠️ AUTHORIZED USE ONLY > This skill is for educational purposes or authorized security assessments only. > You must have explicit, written permission from the system owner before using this tool. > Misuse of this tool is illegal and strictly prohibited and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Semgrep Rule Creator V2Semgrep Rule Creator workflow skill. Use this skill when the user needs Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. Use when writing Semgrep rules or building custom static analysis detections and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Web Security Testing V2Web Security Testing Workflow workflow skill. Use this skill when the user needs Web application security testing workflow for OWASP Top 10 vulnerabilities including injection, XSS, authentication flaws, and access control issues and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Attack Tree ConstructionAttack Tree Construction workflow skill. Use this skill when the user needs Build comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Broken Authentication V2Broken Authentication Testing workflow skill. Use this skill when the user needs Identify and exploit authentication and session management vulnerabilities in web applications. Broken authentication consistently ranks in the OWASP Top 10 and can lead to account takeover, identity theft, and unauthorized access to sensitive systems and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Burpsuite Project ParserBurp Project Parser workflow skill. Use this skill when the user needs Searches and explores Burp Suite project files (.burp) from the command line. Use when searching response headers or bodies with regex patterns, extracting security audit findings, dumping proxy history or site map data, or analyzing HTTP traffic captured in a Burp project and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Cc Skill Security ReviewSecurity Review Skill workflow skill. Use this skill when the user needs This skill ensures all code follows security best practices and identifies potential vulnerabilities. Use when implementing authentication or authorization, handling user input or file uploads, or creating new API endpoints and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Code Review Checklist V2Code Review Checklist workflow skill. Use this skill when the user needs Comprehensive checklist for conducting thorough code reviews covering functionality, security, performance, and maintainability and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Code Review Checklist V3Code Review Checklist workflow skill. Use this skill when the user needs Comprehensive checklist for conducting thorough code reviews covering functionality, security, performance, and maintainability and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Linux Shell Scripting V2Linux Production Shell Scripts workflow skill. Use this skill when the user needs Provide production-ready shell script templates for common Linux system administration tasks including backups, monitoring, user management, log analysis, and automation. These scripts serve as building blocks for security operations and penetration testing environments and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Mobile Security Coder V2mobile-security-coder workflow skill. Use this skill when the user needs Expert in secure mobile coding practices specializing in input validation, WebView security, and mobile-specific security patterns and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Nodejs Best Practices V2Node.js Best Practices workflow skill. Use this skill when the user needs Node.js development principles and decision-making. Framework selection, async patterns, security, and architecture. Teaches thinking, not copying and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Nodejs Best Practices V3Node.js Best Practices workflow skill. Use this skill when the user needs Node.js development principles and decision-making. Framework selection, async patterns, security, and architecture. Teaches thinking, not copying and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Production Code Audit V2Production Code Audit workflow skill. Use this skill when the user needs Autonomously deep-scan entire codebase line-by-line, understand architecture and patterns, then systematically transform it to production-grade, corporate-level professional quality with optimizations and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
Audited 54 -
thomasmoreai Bundle Security Review OpenaiPerform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.
-
thomasmoreai Skill Nydfs Infosec ProgramDrafts a comprehensive Information Security Program compliant with NYDFS Cybersecurity Regulation (23 NYCRR 500). Covers CISO designation, risk assessment, access controls, encryption, monitoring, incident response, notification, and annual certification for covered financial services entities. Use when drafting cybersecurity programs, NYDFS compliance policies, or information security policies for financial institutions. Trigger keywords: NYDFS, 23 NYCRR 500, cybersecurity regulation, information security program, CISO policy, financial services cybersecurity.
Audited -
thomasmoreai Skill Breach NotificationDrafts legally compliant data breach notification letters to affected consumers under multi-state and federal statutes (HIPAA, GLBA, state AG requirements). Use when drafting breach notices, security incident consumer notifications, or data compromise letters.
Audited -
thomasmoreai Skill Loan And Security AgreementDrafts a U.S. secured Loan and Security Agreement with UCC Article 9 security interests, perfection mechanics, covenants, and enforcement remedies. Use when documenting secured commercial loans, acquisition financing, working capital facilities, or equipment financing requiring perfected lien documentation.
Audited -
thomasmoreai Skill Loan Modification AgreementDrafts a U.S. commercial Loan Modification Agreement amending existing loan terms (interest rates, payment schedules, maturity dates, covenants) while preserving enforceability of original loan documents, security interests, and guarantees without novation. Use when restructuring commercial loans, extending maturities, modifying covenants, formalizing forbearance, or documenting workout arrangements.
Audited -
thomasmoreai Skill Pledge Agreement SecuritiesDrafts perfected-security-interest Pledge Agreements for securities collateral under UCC Article 9. Use when drafting securities pledge agreements, stock pledge documents, collateral assignments, or security interest grants in investment property securing loans or credit facilities.
Audited -
thomasmoreai Skill Promissory Note ResidentialDrafts enforceable residential promissory notes with party identification, principal/interest terms, payment schedules, default/acceleration provisions, and security instrument cross-references. Ensures TILA awareness and state usury compliance. Use when drafting promissory notes for residential mortgages, deeds of trust, or seller-financed home sales; trigger keywords: promissory note, residential note, mortgage note, deed of trust note, seller financing note, balloon note.
Audited -
thomasmoreai Skill Charity Filing ThresholdsResearches state-specific charitable solicitation filing requirements keyed to gross revenue, producing a citation-backed state-by-state compliance matrix of audit thresholds, financial-statement tiers, filing fees, and due dates. Use when building charity compliance matrices, researching nonprofit filing thresholds, charitable solicitation registration renewals, comparing state audit requirements for 501(c)(3) organizations, or when the user mentions audit threshold, review threshold, compilation requirement, charity filing deadline, or multi-state nonprofit compliance.
Audited -
thomasmoreai Skill Au Apra Cps 234 ExpertAPRA CPS 234 expert for Australian prudential information security. Reference-depth framework plugin with scope determination, evidence checklist, and SCF-backed assessment guidance.
Audited -
thomasmoreai Skill Fashion Luxus Kaltstart InterviewMandantenaufnahme Modehaus und IP-Audit-Erstgespraech: Neues Luxus-Mode-Mandat beginnt, Portfolio-Inventur und Prioritaeten-Matrix sind zu erstellen. Normen: BRAO § 43a, § 32 MarkenG, Art. 32 UMV. Prüfraster: IP-Audit-Fragenkatalog (Marken, Design, Urheberrecht, Patente), Portfolio-Inventur, Verletzungs-Risiko-Matrix, laufende Verfahren. Output Mandatsprofil, IP-Inventur-Tabelle, Prioritaeten-Matrix, naechste Schritte. Abgrenzung: Detailarbeiten in Spezialskills dieses Plugins; für USPTO siehe nyc-korrespondenz-und-conflict-check.
Audited -
thomasmoreai Skill Gdpr Audit PrepGdpr Audit Prep
Audited -
thomasmoreai Skill Conduct Gxp AuditConduct a GxP audit of computerized systems and processes. Covers audit planning, opening meetings, evidence collection, finding classification (critical/major/minor), CAPA generation, closing meetings, report writing, and follow-up verification. Use for scheduled internal audits, supplier qualification audits, pre-inspection readiness assessments, for-cause audits triggered by deviations or data integrity concerns, or periodic compliance posture reviews of validated systems.
Audited -
thomasmoreai Skill Compliance SummariesGenerates structured compliance summaries assessing regulatory posture, identifying gaps, and producing prioritized remediation roadmaps across finance (SEC, FINRA), healthcare (HIPAA, FDA), environmental (EPA), and data privacy (GDPR, CCPA) sectors. Use when drafting regulatory compliance reports, audit readiness assessments, or governance documents for executives, boards, or regulators. For sector-specific depth, defer to dedicated sibling skills (environmental-regulation-summaries, hipaa-privacy-notice, fcpa-compliance-policy, etc.).
Audited -
thomasmoreai Skill Audit Compensation CharterDrafts board-adopted charters establishing Audit and Compensation Committees for U.S. corporations, covering composition, independence, delegated powers, meeting protocol, reporting, and annual review. Adapts for public (SEC/SOX/exchange) or private governance regimes. Use when creating or refreshing committee charters, preparing for IPO governance readiness, onboarding directors, or conducting governance cleanup. Trigger keywords: audit committee charter, compensation committee charter, board governance, SOX compliance, Rule 10A-3, exchange-standard committees.
Audited -
thomasmoreai Skill Ccpa Right To DeleteImplements CCPA Section 1798.105 right to delete and CPRA amendments including service provider obligations, statutory exceptions for legal, security, and internal uses, consumer identity verification procedures, and 45-day response timeline management. Activate for CCPA deletion, CPRA right to delete, California privacy, consumer deletion queries.
Audited -
thomasmoreai Skill Far SubcontractDrafts FAR-compliant subcontract agreements between prime contractors and subcontractors under U.S. federal government prime contracts. Handles mandatory flow-down of FAR/DFARS/agency clauses, contract-type pricing, security/clearance, IP/data rights, and termination. Use when drafting government subcontracts, FAR flow-down clauses, or prime-sub agreements.
Audited -
thomasmoreai Skill Copyright License Agreement MediaDrafts a Copyright License Agreement for media content between a Licensor and Licensee. Covers exclusive/non-exclusive grants, enumerated §106 rights, territory, term, compensation, audit rights, attribution, termination, and sell-off periods. Use when the user needs an IP license for media assets (images, video, music, software, written works, multimedia).
Audited -
thomasmoreai Skill Disclosure Page GeneratorWhen the user wants to create, optimize, or audit an affiliate, sponsor, or paid partnership disclosure page. Also use when the user mentions "disclosure," "affiliate disclosure," "sponsored content," "FTC disclosure," or "paid partnership." For sitewide page planning, use website-structure.
Audited
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include trademark-license-agreement, audit-compliance, regulatory-compliance. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.