Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
thomasmoreai Skill Unclaimed Property PolicyDrafts an enterprise Escheatment and Unclaimed Property Policy covering property identification, dormancy matrices, due diligence notices, NAUPA-format reporting, remittance, recordkeeping, and audit preparedness across all US state jurisdictions. Use when establishing or updating an unclaimed property compliance framework, preparing for state audits, or evaluating voluntary disclosure programs.
Audited -
thomasmoreai Skill API Acceptable Use PolicyDrafts a standalone API Acceptable Use Policy (AUP) for incorporation by reference into a master API license or terms-of-service agreement. Produces a publication-ready template with prohibited-use matrix, developer security checklist, graduated enforcement framework, AI/ML training restrictions, and versioning playbook. Trigger when a user needs to draft or update an API AUP, separate behavioral rules from core API terms, define prohibited API uses, add enforcement or change-management mechanics, or mentions acceptable use policy, developer security requirements, or API enforcement.
Audited -
thomasmoreai Skill Medical Billing AnalysisProduces a litigation-ready analysis of medical bills and supporting records for personal injury, medical-malpractice, workers'-compensation, and disability cases. Validates CPT/HCPCS/ICD-10 codes against documentation, applies a per-charge causation screen, runs a UCR/FAIR Health/MPFS reasonableness review, surfaces unbundling, upcoding, duplicate and phantom billing, flags letter-of-protection inflation, identifies collateral-source and lien interfaces, and outputs a memo whose every finding cites document, page, and Bates. Trigger on: medical billing analysis, medical bill audit, billing reasonableness review, UCR review, CPT/ICD code review, NCCI/unbundling/upcoding review, billed vs. paid analysis, letter of protection (LOP) analysis, collateral source review, chargemaster markup, causation chain, IME rebuttal prep, demand-package billing exhibit, mediation statement billing section, lien interface identification.
Audited -
thomasmoreai Skill Ifap Aktenanlage BatchregisterBatchregister für Massenverfahren Insolvenzforderungsanmeldung anlegen: Anwendungsfall Insolvenzverwalter oder Prüfungsstelle erhaelt umfangreichen Stapel Forderungsanmeldungen nach § 174 InsO und muss strukturiertes Register aufbauen. § 175 InsO Tabelle, § 176 InsO Prüfungstermin. Prüfraster Gläubigerstamm, Prüfnummern, Status je Forderung, Wiedervorlagen, Audit-Trail, Fristen. Output Batchregister mit Eingangsprotokoll, Statusuebersicht und Fristenliste. Abgrenzung zu Intake-Kanalcheck für Eingangserfassung und zu Kommandocenter.
Audited -
thomasmoreai Skill Cyber Incident Response 72hSofortmassnahmen bei aktivem Cyber-Vorfall Ransomware Datenexfiltration oder Insider-Threat. Anwendungsfall Cyberangriff ist entdeckt und IT-rechtliche Meldepflichten sowie Beweissicherung muessen binnen Stunden eingeleitet werden. Normen Art. 33 DSGVO 72-Stunden-Meldung Datenpanne Art. 34 DSGVO Betroffeneninformation NIS2UmsuCG § 32 BSIG n.F. §§ 202a 303b StGB. Prüfraster Sofort-Eindaemmung Forensik-Sicherung DSGVO-Meldepflicht NIS-2-Fruehwarnung 24 Stunden Strafanzeige Cybersecurity-Versicherer Beweiskette. Output Sofortmassnahmen-Protokoll mit 72-Stunden-Plan Meldungsformulierung und Chain-of-Custody-Dokumentation. Abgrenzung zu fachanwalt-it-recht-cyber-vorfall-sofortmassnahmen und fachanwalt-it-recht-datenschutz-folgenabschaetzung.
Audited -
thomasmoreai Skill Insolvenzgeld 165 Sgb IiiArbeitnehmer eines insolventen Unternehmens will Insolvenzgeld beantragen oder Insolvenzverwalter bearbeitet Insolvenzgeld-Anmeldungen. Prüfraster § 165 ff. SGB III Anspruchs-Voraussetzungen Arbeitsentgelt letzte drei Monate vor Insolvenz-Ereignis. Insolvenz-Ereignis § 165 Abs. 1 SGB III Eroeffnung Abweisung mangels Masse Vollstreckungs-Aussichtslosigkeit. Antragsfrist zwei Monate § 324 SGB III Vor-Finanzierung Banken bis 75 Prozent. Output Antragsentwurf Bescheinigung Abrechnung Schnittstelle Sozialversicherungs-Beitraege. Abgrenzung: forderungsanmeldung-gläubiger für allgemeine Forderungsanmeldung.
Audited -
thomasmoreai Skill Compliance ChecklistGenerate a prioritised compliance checklist for GDPR, SOC 2, ISO 27001, FCA, HIPAA, or other frameworks with a gap analysis. Use when asked for a compliance checklist, gap analysis, readiness assessment, or audit preparation for any regulatory framework. Produces a structured checklist with prioritised gaps, quick wins, and evidence requirements. Optimised for Opus 4.7 and newer models. Not a substitute for legal or compliance professional advice.
Audited -
thomasmoreai Skill Vendor Privacy AuditOn-site and remote vendor audit procedures per GDPR Article 28(3)(h). Covers audit planning, evidence collection methodologies, finding classification, remediation tracking, and audit report generation for processor compliance verification.
Audited -
thomasmoreai Skill Compliance Audit InsuranceConduct compliance audits for insurance agencies. TRIGGERS - Use when user needs help with compliance-audit-insurance related tasks.
Audited -
thomasmoreai Skill Monitor Data IntegrityDesign and operate a data integrity monitoring programme based on ALCOA+ principles. Covers detective controls, audit trail review schedules, anomaly detection patterns (off-hours activity, sequential modifications, bulk changes), metrics dashboards, investigation triggers, and escalation matrix definition. Use when establishing a data integrity monitoring programme for GxP systems, preparing for inspections where data integrity is a focus area, after a data integrity incident requiring enhanced monitoring, or when implementing MHRA, WHO, or PIC/S guidance.
Audited -
thomasmoreai Skill Supplementary MeasuresGuides implementation of technical, contractual, and organisational supplementary measures for international data transfers per EDPB Recommendations 01/2020. Covers encryption, pseudonymisation, split processing, audit rights, transparency obligations, and internal policies. Keywords: supplementary measures, encryption, pseudonymisation, EDPB recommendations, transfer safeguards.
Audited -
thomasmoreai Skill Conduct Gxp Audit Pjt222Conduct a GxP audit of computerized systems and processes. Covers audit planning, opening meetings, evidence collection, finding classification (critical/major/minor), CAPA generation, closing meetings, report writing, and follow-up verification. Use for scheduled internal audits, supplier qualification audits, pre-inspection readiness assessments, for-cause audits triggered by deviations or data integrity concerns, or periodic compliance posture reviews of validated systems.
Audited -
thomasmoreai Skill Data Breach Consumer NoticeDrafts U.S. consumer data breach notification letters satisfying multi-state breach-notice content rules and sector regimes (HIPAA, GLBA, PCI). Produces compliance scoping tables, data-element disclosures, remediation summaries, and consumer protection guidance tailored to incident facts and recipient cohorts. Use for multi-state breach letters, consumer breach notification, security incident notice, PII exposure notice, or sector-specific breach compliance.
Audited -
thomasmoreai Skill Geldwaesche Bussgeld ReputationStrukturierung von Bußgeldriskien Geschäftsleiterhaftung und Reputationsschaeden bei GwG-Verstoessen. Anwendungsfall Bußgeldbescheid nach GwG ist eingegangen oder negative Berichterstattung droht. Normen § 52 GwG Bußgelder bis 5 Mio EUR oder 10 Prozent Jahresumsatz § 130 OWiG Aufsichtspflichtverletzung. Prüfraster Bußgeldrisko Geschäftsleitungsverantwortung Pressekommunikation Kundenkommunikation Remediation Schadensbegrenzung. Output Massnahmenplan mit Widerspruchsstrategie PR-Linie Remediation-Nachweis und Haftungsabsicherung. Abgrenzung zu geldwäsche-behoerdenverfahren und geldwäsche-audit-internal-revision.
Audited -
thomasmoreai Skill Geldwaesche Simulation TestlaufSimulation eines Compliance-Arbeitstags mit Onboarding Alerts Verdachtsprüfung und Behoerdenfragen. Anwendungsfall Team will GwG-Workflows trainieren oder Plugin demonstrieren. Deckt Onboarding Alert UBO-Luecke Sanktionshit Verdachtsprüfung Schulung und Behoerdenfrage ab. Output Simulationsprotokoll mit Tagesereignissen Fehlerhinweisen und Lernnotizen. Abgrenzung zu geldwäsche-kommandocenter (Echtbetrieb) und geldwäsche-audit-internal-revision.
Audited -
thomasmoreai Skill Umweltrecht Compliance SchulungAnlagenbetreiber muss Umwelt-Compliance-Schulungen und Jahresaudit-Plaene erstellen für Immissionsschutzbeauftragte Abfallverantwortliche. Normen BImSchG §§ 53-58 KrWG §§ 59 60 WHG §§ 64 65. Prüfraster Schulungspflichten Dokumentationspflichten Audit-Planung. Output Schulungsplan-Template Jahresaudit-Checkliste. Abgrenzung zu umweltrecht-immissionsschutz-bimschg (Genehmigung) und umweltrecht-abfall-circular-economy (Abfall-Compliance).
Audited -
thomasmoreai Skill Review Contract NmoralescyberReview an executed-or-draft B2B contract (MSA, SOW, SaaS agreement, DPA, license, partnership, contractor IP assignment, reseller agreement) against the organization's negotiation playbook — flag clause-by-clause deviations, generate redlines with fallback positions, and prioritize must-haves vs. concessions. Use when the user pastes or attaches a counterparty's contract and asks to "review", "redline", "negotiate", "flag issues in", "find risks in", or "give negotiation strategy for" that contract. Do NOT use for standalone NDAs (use legal:triage-nda), for auditing the user's own customer-facing legal docs like ToS, privacy policies, refund policies, or HIPAA notices (use legal:legal-audit), for listing what agreements are already on file with a vendor (use legal:vendor-check), for asking whether a planned action or feature is compliant with a regulation (use legal:compliance-check), for severity-by-likelihood risk scoring without a contract document (use legal:legal-risk-assessment), or for sending an alrea
Audited -
thomasmoreai Skill Vendor Security AssessmentDrafts a Vendor Security Assessment Questionnaire evaluating third-party cybersecurity posture, data handling, and regulatory compliance. Vendor responses become binding contractual representations with executive certification. Use during vendor due diligence, third-party risk management, procurement security review, or subprocessor evaluation.
Audited -
thomasmoreai Skill Retention Exception MgmtManages retention exception workflows including request-approval processes, duration limits, periodic review cycles, documentation requirements, and audit trail maintenance. Covers legitimate grounds for extending retention beyond scheduled periods and governance controls to prevent indefinite data hoarding. Activate for retention exception, retention extension, data hoarding prevention, retention override queries.
Audited -
thomasmoreai Skill Consumer Breach Notice LetterDrafts U.S. consumer-facing data breach notification letters compliant with state statutes. Use when a security incident involving personal information requires consumer notice — first, interim, or follow-up. Covers jurisdiction-aware content, incident disclosure, compromised-data specificity, mitigation steps, support services, and delivery requirements. Trigger: data breach notice, consumer notification, personal information incident, identity theft letter, substitute notice.
Audited -
thomasmoreai Skill Confidentiality Security AgreementDrafts enforceable U.S. Employee Confidentiality and Security Agreements protecting proprietary information, trade secrets, and digital assets, with layered confidential-information definitions, security and acceptable-use obligations, incident reporting protocols, termination property-return procedures, and post-employment restrictive covenants. Incorporates state-specific enforceability standards, DTSA whistleblower immunity notice, and NLRA Section 7 savings clauses. Use when onboarding employees, updating confidentiality policies, or drafting NDA-style employment agreements (trigger keywords: confidentiality agreement, employee NDA, security agreement, trade secret, acceptable use, incident reporting, post-employment restrictions).
Audited -
thomasmoreai Skill Employee Confidentiality AgreementDrafts enforceable Employee Confidentiality and Security Agreements protecting trade secrets, proprietary information, and digital assets. Incorporates DTSA whistleblower notice, state-specific enforceability, NLRA carveouts, and data privacy compliance. Use when onboarding employees, updating confidentiality policies, or creating security agreements for data privacy and cybersecurity contexts.
Audited -
thomasmoreai Skill Legal Eagle Wdzhwsh4067Legal basics assistant for developers, founders, and small teams. Use to summarize contracts, identify practical risk questions, prepare lawyer-ready issue lists, draft plain-English emails, compare SaaS terms, review NDAs, organize privacy/security obligations, and create negotiation notes. Not legal advice.
Audited -
thomasmoreai Skill Evidence GenerationUse this skill when generating ISO 27001 or NIST SP 800-53 audit evidence packs, compliance reports, evidence narratives, reviewer-ready control matrices, or when the user asks about audit evidence, compliance evidence, evidence packages, audit documentation, or ISO/NIST evidence.
Audited -
thomasmoreai Skill Conduct Gxp Audit 2Conduct a GxP audit of computerized systems and processes. Covers audit planning, opening meetings, evidence collection, finding classification (critical/major/minor), CAPA generation, closing meetings, report writing, and follow-up verification. Use for scheduled internal audits, supplier qualification audits, pre-inspection readiness assessments, for-cause audits triggered by deviations or data integrity concerns, or periodic compliance posture reviews of validated systems.
Audited -
thomasmoreai Skill Texas Tdpsa ComplianceTexas Data Privacy and Security Act (TDPSA) compliance. No revenue threshold applies to all businesses. Covers data broker registration requirements, biometric identifier provisions under CUBI, consumer rights, AG enforcement, and 30-day cure period. Effective July 1, 2024.
Audited -
thomasmoreai Skill Triage Nda NmoralescyberRapidly triage an inbound standalone NDA (mutual or unilateral) and classify it GREEN (sign under standard delegation), YELLOW (counsel review needed), or RED (full legal review / counterproposal). Use when the user attaches or pastes an NDA and asks "is this standard?", "can we sign this?", "any landmines in this NDA?", "screen this NDA", "GREEN/YELLOW/RED this", or any equivalent fast-screen request — especially to catch embedded non-solicits, non-competes, residuals, perpetual confidentiality, hidden IP grants, or missing carveouts. Do NOT use for full multi-page commercial agreements with confidentiality sections embedded (use legal:review-contract), for drafting an NDA from scratch or responding to an NDA request (use legal:legal-response or legal:review-contract for the counterproposal pass), for checking what NDAs are already on file with a counterparty (use legal:vendor-check), for auditing the user's own NDA template (use legal:legal-audit), or for sending an already-approved NDA for signature (use l
Audited -
thomasmoreai Skill Compliance And AuditUse when a project requires a compliance framework mapping, when risks need formal documentation, when audit evidence must be collected, or when producing a compliance attestation before release. Applies to SOC 2, ISO 27001, GDPR, PCI DSS, NIST CSF, and DORA.
Audited -
thomasmoreai Skill Applying Zus ProceduresUse when navigating ZUS procedures — rejestracja płatnika (ZFA/ZPA/ZUA/ZCNA), zgłoszenie pracowników, zasiłki chorobowy / macierzyński / opiekuńczy (Z-3, Z-15A/B), emerytura (EMP), renta (N-9), świadczenie rehabilitacyjne (Np-7), ulgi w spłacie (RSR/RSO/RSU), odwołanie do sądu ubezpieczeń społecznych (art. 477⁹ KPC). Formularze, PUE ZUS, terminy (SUS, ZasChMac, EmRenFUS), ścieżka odwoławcza
Audited -
thomasmoreai Skill Lease Termination AgreementDrafts a mutual early lease termination agreement for U.S. commercial and residential properties. Covers party identification, termination mechanics, property surrender, financial settlement (prorated rent, security deposit accounting), mutual release with carve-outs, and execution formalities. Use when landlord and tenant agree to end a lease before expiration, when negotiating buyout terms, or resolving disputes through consensual termination.
Audited -
thomasmoreai Skill Tenant Estoppel CertificateDrafts tenant estoppel certificates for commercial real estate acquisitions and financings. Produces numbered certifications binding tenants to lease representations for reliance by purchasers and lenders during due diligence. Covers lease terms, rent status, defaults, options, claims, and security deposits. Use when drafting estoppel certificates, tenant certifications, lease verification documents, or property acquisition due diligence instruments.
Audited -
diegosouzapw Bundle Variant AnalysisVariant Analysis workflow skill. Use this skill when the user needs Find similar vulnerabilities and bugs across codebases using pattern-based analysis. Use when hunting bug variants, building CodeQL/Semgrep queries, analyzing security vulnerabilities, or performing systematic code audits after finding an initial issue and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Zeroize Audit V2zeroize-audit — Claude Skill workflow skill. Use this skill when the user needs Detects missing zeroization of sensitive data in source code and identifies zeroization removed by compiler optimizations, with assembly-level analysis, and control-flow verification. Use for auditing C/C++/Rust code handling secrets, keys, passwords, or other sensitive data and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Laravel Expert V2Laravel Expert workflow skill. Use this skill when the user needs Senior Laravel Engineer role for production-grade, maintainable, and idiomatic Laravel solutions. Focuses on clean architecture, security, performance, and modern standards (Laravel 10/11+) and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Pci Compliance V2PCI Compliance workflow skill. Use this skill when the user needs Master PCI DSS (Payment Card Industry Data Security Standard) compliance for secure payment processing and handling of cardholder data and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Pci Compliance V3PCI Compliance workflow skill. Use this skill when the user needs Master PCI DSS (Payment Card Industry Data Security Standard) compliance for secure payment processing and handling of cardholder data and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include conduct-gxp-audit-pjt222, legal-eagle-wdzhwsh4067, unclaimed-property-policy. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.