Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
diegosouzapw Bundle Saas Multi TenantSaaS Multi-Tenant Architecture workflow skill. Use this skill when the user needs Design and implement multi-tenant SaaS architectures with row-level security, tenant-scoped queries, shared-schema isolation, and safe cross-tenant admin patterns in PostgreSQL and TypeScript and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Security Audit V2Security Auditing Workflow Bundle workflow skill. Use this skill when the user needs Comprehensive security auditing workflow covering web application testing, API security, penetration testing, vulnerability scanning, and security hardening and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Solidity SecuritySolidity Security workflow skill. Use this skill when the user needs Master smart contract security best practices, vulnerability prevention, and secure Solidity development patterns and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
thomasmoreai Skill Fachanwalt Sozialrecht ErwerbsminderungsrenteVersicherter erhielt Ablehnung der Erwerbsminderungsrente oder ist ausgesteuert und fragt nach Rentenanspruch. §§ 43 240 SGB VI. Prüfraster: volle Erwerbsminderung unter 3 Stunden taeglich teilweise unter 6 Stunden Wartezeit 5 Jahre § 50 SGB VI 3 Jahre Pflichtbeitraege in letzten 5 Jahren § 43 Abs. 1 Nr. 2 SGB VI. Berufsschutz § 240 SGB VI Jahrgaenge vor 1961. Medizinische Befundlage Gutachten. Output: Widerspruchsschriftsatz oder Klagebaustein Erwerbsminderungsrente. Abgrenzung zu fachanwalt-sozialrecht-krankengeld-aussteuerung (Übergang).
Audited -
thomasmoreai Skill Fachanwalt Sozialrecht Widerspruch SozialleistungMandant hat Sozialleistungsbescheid erhalten und Anwalt formuliert Widerspruch. § 84 SGG Widerspruchsfrist ein Monat. Prüfraster: Frist (Bekanntgabe Vier-Tage-Fiktion § 37 Abs. 2 SGB X seit 1.1.2025 PostModG) aufschiebende Wirkung § 86a SGG Antrag § 86b SGG Tatsachen und Rechtsgrundlagen Beweisangebote. Output: Widerspruchsschriftsatz mit Begründung. Abgrenzung zu bescheid-frist-quick-check (Fristkontrolle vorab) und klage-sozialgericht (nach Widerspruchsbescheid).
Audited -
thomasmoreai Skill Draft Cybersecurity Website Terms And Cookie PoliciesGenerates Terms of Use and Cookie Policy documents for a cybersecurity company website, strictly limiting data usage to newsletters and event updates, prohibiting data sales, and emphasizing security protections.
Audited -
thomasmoreai Skill Expatriate Pensionsplanung Und TotalizationPensionsplanung für Expatriates: Totalisierungsabkommen, Doppelversicherungsvermeidung, Pensionsluecken. Normen: EG-VO 883/2004, bilaterale SV-Abkommen. Prüfraster: Entsendelaender, Sozialversicherungsrecht, Pensionsbeitraege, Lueckenanalyse. Output: Expatriate-Pensionsplan. Abgrenzung: nicht nationaler Durchführungsweg.
Audited -
thomasmoreai Bundle Azerbaijan Eu Website Privacy Compliance Audit Mirza ChiragoAudits a website for compliance with Azerbaijan's Law on Personal Data No. 998-IIIQ and, where applicable, EU GDPR plus ePrivacy/cookie consent rules. Inventories the privacy documents present (privacy policy, cookie policy, cookie banner, consent flow, controller and DPO contact, data subject rights channel, cross-border transfer disclosures, AZ operator-registration references) and scores each against the applicable statutory requirements. Produces a dual-layer report: a plain-language traffic-light summary for business owners plus a clause-by-clause findings table with article-level citations for lawyers. Assessment-only — no drafting. Use whenever the user shares a URL or privacy/cookie policy text for an AZ-based or AZ-targeted site; also when the user mentions an .az domain, Law 998, the AZ State Register, ePrivacy, an Art. 27 EU representative, or asks "is my site GDPR compliant", "do I need to register as an operator in Azerbaijan", or "is our cookie banner lawful" — even without the word "audit".
-
thomasmoreai Skill Geldwaesche Sicherungsmassnahmen IcpAufbau und Haertung interner Sicherungsmassnahmen ICP nach § 6 GwG. Anwendungsfall Verpflichteter muss ICP aufbauen oder bestehendes Kontrollsystem verbessern. Normen § 4 GwG Bestellung GwG-Beauftragter § 6 GwG interne Massnahmen § 7 GwG Gruppen-Compliance BaFin-Auslegungs- und Anwendungshinweise. Prüfraster Richtlinien Prozesse Kontrollen Eskalationen Schulungen Audit-Trail Vier-Augen-Prinzip. Output ICP-Handbuch mit Richtlinien Kontrollmatrix Eskalationswegen und Schulungsplan. Abgrenzung zu geldwäsche-risikoanalyse-unternehmen und geldwäsche-audit-internal-revision.
Audited -
thomasmoreai Skill Write Validation DocumentationWrite IQ/OQ/PQ validation documentation for computerized systems in regulated environments. Covers protocols, reports, test scripts, deviation handling, and approval workflows. Use when validating R or other software for regulated use, preparing for a regulatory audit, documenting qualification of computing environments, or creating and updating validation protocols and reports for new or re-qualified systems.
Audited -
thomasmoreai Skill Geldwaesche Risikoanalyse UnternehmenRisikobasierte AML/CFT-Risikoanalyse nach § 5 GwG für Verpflichtete. Anwendungsfall Unternehmen muss gesetzlich vorgeschriebene Risikoanalyse erstellen oder aktualisieren. Normen § 5 GwG Risikoanalyse § 6 GwG interne Sicherungsmassnahmen FATF-Empfehlungen BaFin-AuA. Prüfraster Produkte Kundenstruktur Laender Vertriebskanaele Transaktionen bestehende Kontrollen Risikoniveau. Output Risikoanalysedokument mit Risikoklassifizierung Kontrolllueckenbewertung und Massnahmenplan für Behoerdenvorlage. Abgrenzung zu geldwäsche-sicherungsmassnahmen-icp und geldwäsche-audit-internal-revision.
Audited -
thomasmoreai Skill Generating Compliance ReportsGenerate comprehensive compliance reports for security standards. Use when creating compliance documentation. Trigger with 'generate compliance report', 'compliance status', or 'audit compliance'.
Audited -
thomasmoreai Skill Fachanwalt Sozialrecht OrientierungEinstieg in den Skill-Verbund Sozialrecht. Orientierung im Sozialrecht Fachanwaltschaft nach § 14 FAO Weiterbildungspflicht. SGB I bis XIV im Überblick SGB II Buergergeld SGB VI Rente SGB V Krankenversicherung SGB IX Reha SGB XI Pflege. Verfahren SGG drei Instanzen SG LSG BSG. verifizierbare Quellen lizenzpflichtige Literaturquellen Kasseler Kommentar. Output: Routing-Empfehlung zu passendem Folge-Skill. Abgrenzung zu mandat-triage-sozialrecht (Eingangstriage) und sozialrecht-fallaufnahme-routing (Master-Routing).
Audited -
thomasmoreai Skill Umweltbericht UmweltpruefungMandant greift Bebauungsplan wegen unzureichender Umweltprüfung oder fehlendem Umweltbericht an. § 2 Abs. 4 BauGB § 2a BauGB Umweltbericht. Prüfraster: Schutzgueter nach Anhang 1 BauGB Mensch Tiere Pflanzen Boden Wasser Luft Klima Landschaft Kultur Nullvariante Alternativen FFH-Vertraeglichkeit § 1a Abs. 4 BauGB. Beschleunigtes Verfahren § 13a BauGB ohne Umweltprüfung. Output: Umweltprüfungs-Audit und Angriffspunkte Normenkontrolle. Abgrenzung zu artenschutz-naturschutz-planung (Artenschutz) und beteiligung-frueh-foermlich.
Audited -
thomasmoreai Skill Gdpr Compliance AuditGuides a comprehensive organisational data protection audit against key GDPR requirements including Articles 5, 24, 25, 28, 30, 32, 35, and 37. Includes 50+ control points covering principles, accountability, security, and governance. Activate when performing compliance audits, preparing for supervisory authority inspections, or assessing organisational GDPR maturity. Keywords: data protection audit, compliance audit, GDPR audit, control points, accountability.
Audited -
thomasmoreai Skill Related Party Transaction PolicyDrafts a board-adoptable Related Party Transaction Policy for U.S. corporations governing identification, Audit Committee review, approval, and disclosure of related party transactions. Enforces SEC Item 404(a)/Regulation S-K compliance and stock exchange listing standards. Use when creating or updating RPT policies for public or private companies, or when drafting corporate governance documents addressing conflicts of interest.
Audited -
thomasmoreai Skill Collateral Assignment Of ContractsDrafts a Collateral Assignment of Contracts assigning a borrower's contractual rights as security for debt under UCC Article 9. Triggers when securing lender interests in contract rights, drafting pre-closing security documents, or structuring collateral packages for U.S. commercial credit facilities.
Audited -
thomasmoreai Skill Insurance Certificate ComplianceProduces requirement-by-requirement CRE insurance certificate compliance reviews by analyzing ACORD 25 certificates and endorsements against Access Agreement terms. Use when the user mentions COI review, insurance compliance, ACORD 25 analysis, Additional Insured verification, primary/non-contributory status, waiver of subrogation, vendor insurance audit, CGL compliance, umbrella follow-form, broker-ready deficiency instructions, certificate holder vs. additional insured, AI endorsements (CG 20 10, CG 20 37), or carrier rating checks.
Audited -
thomasmoreai Skill Geldwaesche BehoerdenverfahrenBegleitung von Behoerdenverfahren BaFin-Prüfungen FIU-Nachfragen und Massnahmenbescheiden. Anwendungsfall Aufsichtsbehoerde hat Auskunftsersuchen gestellt oder Vor-Ort-Prüfung angekündigt. Normen § 51 GwG Aufsichtsrecht § 52 GwG Bußgelder § 43 GwG Verdachtsmeldepflicht BaFin-Merkblatt. Prüfraster Auskunftsersuchen Vor-Ort-Prüfung BaFin-Nachfragen FIU-Anfragen Massnahmenbescheid Widerspruchsfrist. Output Behoerdenverfahrens-Begleitprotokoll mit Antwortschreiben Widerspruchsbegründung und Remediation-Nachweis. Abgrenzung zu geldwäsche-audit-internal-revision und geldwäsche-bußgeld-reputation.
Audited -
thomasmoreai Skill Geldwaesche Schulung AwarenessZielgruppengerechte AML/KYC-Schulungen und Awareness-Massnahmen nach § 6 Abs. 2 Nr. 6 GwG. Anwendungsfall jaehrliche Pflichtschulung muss durchgeführt oder neue Mitarbeiter eingearbeitet werden. Normen § 6 Abs. 2 Nr. 6 GwG Schulungspflicht BaFin-Mindestanforderungen FATF-Empfehlungen. Prüfraster Zielgruppen Inhalte Red-Flag-Karten Tests Teilnahmeprotokolle Auffrischungskonzept. Output Schulungspaket mit Kursinhalt Tests Teilnahmeprotokoll und E-Learning-Konzept. Abgrenzung zu geldwäsche-sicherungsmassnahmen-icp und geldwäsche-audit-internal-revision.
Audited -
thomasmoreai Skill Invasive Testing Consent LetterDrafts a Phase II invasive testing consent letter that limits scope, locations, timing, data control, restoration, security, and risk allocation under an existing access, due diligence, or purchase and sale agreement. Use this skill when a counterparty requests soil borings, test pits, groundwater wells, soil vapor sampling, or other intrusive ESA activities. Trigger on keywords including "Phase II," "invasive testing," "environmental site assessment," "ESA," "borings," "test pits," "monitoring wells," "restoration bond," "PLL insurance," "access agreement," "consent letter," "IDW handling," or "environmental due diligence." Even if the user just says "they want to do borings on the site" or "draft consent for Phase II," use this skill.
Audited -
thomasmoreai Skill Security Deposit Letter Of CreditDrafts an irrevocable standby letter of credit securing a commercial lease deposit under ISP98 and UCC Article 5. Covers documentary draw conditions, evergreen/expiry mechanics, transferability, and partial draws. Use when drafting standby LCs for lease security deposits, replacing cash deposits with LC instruments, or structuring beneficiary draw requirements.
Audited -
thomasmoreai Skill Signature Request NmoralescyberPre-flight, configure, and route a FINALIZED contract for e-signature (DocuSign, Adobe Sign, Dropbox Sign, Notarius). Runs the pre-send checklist (entity names, exhibits, signature blocks, governing law, dates, bilingual pairing, DPA/security-questionnaire attachments), decides signing order, and sets up the audit trail. Use ONLY when the document is final and ready to send. Use legal:review-contract for review/redline (the step BEFORE this).
Audited -
thomasmoreai Skill Information Security PolicyDrafts a board-approvable Information Security Policy covering data classification, access controls, encryption, incident response, breach notification, and enforcement. Tailored by industry and regulatory environment (HIPAA, GDPR, CCPA, GLBA, FERPA, PCI DSS). Use when drafting or overhauling an organization's foundational information security governance framework or cybersecurity policy.
Audited -
thomasmoreai Skill Compliance Policy AuditorAudit corporate policies or data-handling descriptions against regulatory frameworks (GDPR, SOC2, HIPAA). Use when users need to identify compliance gaps or risk levels in technical procedures.
Audited -
thomasmoreai Skill Audit Compensation Committee CharterDrafts a combined Audit and Compensation Committee charter for U.S. boards, tailored for public or private companies with listing-standard compliance, independence criteria, and SOX readiness. Triggers when the user needs a board committee charter, audit committee charter, compensation committee charter, or governance mandate for SEC/NYSE/NASDAQ compliance.
Audited -
thomasmoreai Skill Corrective Action Plan DeficienciesDrafts a regulator-ready Corrective Action Plan (CAP) for U.S. healthcare facilities responding to inspection, survey, or audit deficiencies. Covers root-cause analysis, remediation steps, accountability, milestones, monitoring, and validation. Trigger when the user mentions CAP, plan of correction, deficiency citation, scope/severity remediation, correction timeline, or sustainability monitoring for CMS, state, or Joint Commission findings.
Audited -
thomasmoreai Skill Kvkk ComplianceKVKK and GDPR compliance patterns - consent management, right to erasure, breach notification, audit logging, cookie consent, and data classification.
Audited -
thomasmoreai Skill Prepare Inspection ReadinessPrepare an organisation for regulatory inspection by assessing readiness against agency-specific focus areas (FDA, EMA, MHRA). Covers warning letter and 483 theme analysis, mock inspection protocols, document bundle preparation, inspection logistics, and response template creation. Use when a regulatory inspection has been announced or is anticipated, when a periodic self-assessment is due, when new systems have been implemented since the last inspection, or after a significant audit finding that may attract regulatory attention.
Audited -
thomasmoreai Skill Buergerversammlung Protokoll AuditMandant war bei Buergerversammlung und moechte Niederschrift auf Vollständigkeit prüfen. § 3 Abs. 1 BauGB Buergerversammlung Eroerterungstermin. Prüfraster: Einladung Tagesordnung Sitzungsleitung Wortbeitraege sinngemäße Niederschrift Vorfestlegungs-Anzeichen Auswertung für Mandantenchronologie. Output: Audit-Protokoll Buergerversammlung mit Bewertung Fehlstellen. Abgrenzung zu beteiligung-frueh-foermlich (Beteiligungsverfahren gesamt) und normenkontrollantrag-schriftsatz.
Audited -
thomasmoreai Skill Geldwaesche Audit Internal RevisionInterne Revision und Audit der AML/KYC-Kontrollen nach GwG. Anwendungsfall Compliance-Beauftragter oder externer Prüfer will AML-Kontrollsystem auf Wirksamkeit prüfen. Normen § 4 GwG interne Sicherungsmassnahmen § 6 GwG Risikomanagement FATF-Empfehlungen BaFin-Rundschreiben. Prüfraster AML-Kontrollen Stichproben Fallakten Screeningqualitaet Monitoring Verdachtsmeldungen Remediation. Output Revisionsbericht mit Befunden Massnahmenplan Priorisierung und Abschluss-Freigabe. Abgrenzung zu geldwäsche-sicherungsmassnahmen-icp (Aufbau) und geldwäsche-behoerdenverfahren (externe Prüfung).
Audited -
vamseeachanta Skill Session Corpus AuditAnalyze session quality trends — identify high-churn patterns, report waste, flag sessions exceeding 500 tool calls
Audited -
vamseeachanta Bundle Hermes Local ConfigurationClass-level Hermes local configuration and setup workflows, including config audit gotchas and Windows installation.
-
vamseeachanta Bundle Provider Session Quota OperationsClass-level provider/session operations for Codex, Codex, Gemini, Hermes, quotas, audit exporters, readiness dispatch, and utilization scorecards.
-
vamseeachanta Skill Hermes Config Audit GotchasAudit Hermes custom config keys and migrated skill settings safely, with verified command behavior and stale-path checks.
Audited -
vamseeachanta Skill Repo Ecosystem HygieneInterpret the daily read-only repo ecosystem hygiene audit and route remediation through approved workflows.
Audited
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include kvkk-compliance, saas-multi-tenant, security-audit-v2. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.