Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
ferroxlabs Bundle Tech Due DiligenceTechnical due diligence for acquisitions and investments covering code quality audits, architecture reviews, team capability assessments, infrastructure evaluation, security posture analysis, scalability assessment, technical debt quantification, and risk scoring. Includes audit checklists, interview guides, and report templates for investors and acquirers. Use when the user asks about tech due diligence, related techniques, best practices, or needs guidance in this domain. Do NOT use when the request is outside the scope of tech due diligence or requires a different specialized skill.
37 -
plurigrid Bundle Burp SuiteWeb application security testing with Burp Suite.
-
plurigrid Bundle Fix ReviewReview security fixes and patches for completeness and correctness.
-
plurigrid Bundle Code ReviewAutomated code review for pull requests using specialized review patterns. Analyzes code for quality, security, performance, and best practices. Use when reviewing code changes, PRs, or doing code audits.
-
plurigrid Bundle Sharp EdgesIdentifies error-prone APIs, dangerous configurations, and footgun designs that enable security mistakes. Use when reviewing API designs, configuration schemas, cryptographic library ergonomics, or evaluating whether code follows 'secure by default' and 'pit of success' principles. Triggers: footgun, misuse-resistant, secure defaults, API usability, dangerous configuration.
-
plurigrid Bundle Narya ProofsMechanically verified proofs from Narya event logs. Verifies queue consistency, replay determinism, non-leakage, and GF(3) conservation. Use for proving system invariants, audit trails, or formal verification of event-sourced systems.
-
plurigrid Bundle 2600 MagazineQuery and explore the 2600: The Hacker Quarterly magazine archive (1984-present) via DuckDB. Provides structured access to 168+ issues covering hacker culture, security, privacy, telephony, and digital rights without loading full content into context.
-
ferroxlabs Bundle Mobile Privacy GuideMobile privacy expertise covering app permission management, tracking prevention on iOS and Android, secure messaging app selection, device encryption, privacy-focused browser and DNS configuration, location tracking minimization, app audit methodology, and building a privacy-conscious mobile setup without sacrificing usability. Use when the user asks about mobile privacy guide, related techniques, best practices, or needs guidance in this domain. Do NOT use when the request is outside the scope of mobile privacy guide or requires a different specialized skill.
37 -
ferroxlabs Bundle Performance EngineerBecomes a senior performance engineer who identifies bottlenecks, designs optimization strategies, and conducts load testing using systematic profiling and benchmarking methodology. Use when the user needs performance analysis, load testing, bottleneck identification, latency optimization, or capacity planning. Do NOT use when writing new application features, conducting security audits, or designing system architecture from scratch.
37 -
ferroxlabs Bundle Smart Home ArchitectSmart home hub selection, automation routines, security and privacy considerations, voice control integration, energy monitoring, and system design for connected homes. Use when the user asks about smart home architect, or needs help with smart home hub selection, automation routines, security and privacy considerations, voice control integration, energy monitoring, and system design for connected homes. Do NOT use when the request requires professional specialized advice or falls outside the scope of smart home architect.
37 -
ferroxlabs Bundle Travel Safety ExpertProvide comprehensive personal safety guidance for travelers including destination assessment, personal security practices, scam awareness, emergency protocols, and health precautions Use when the user asks about travel safety expert, related techniques, best practices, or needs guidance in this domain. Do NOT use when the request is outside the scope of travel safety expert or requires a different specialized skill.
37 -
ferroxlabs Bundle Zero Trust ArchitectZero trust architecture expertise covering identity-first security, microsegmentation, policy engines, continuous verification, device trust, network security modernization, ZTNA implementation, service mesh security, identity provider integration, and least-privilege access design for eliminating implicit trust in enterprise environments. Use when the user asks about zero trust architect, zero trust architect best practices, or needs guidance on zero trust architect implementation. Do NOT use when the user needs a different specialized skill or is asking about an unrelated technology domain.
37 -
ferroxlabs Bundle API Security EngineerAPI security expertise covering OWASP API Security Top 10, API authentication and authorization patterns, API key management, rate limiting and throttling, JWT security best practices, OAuth 2.0 implementation, input validation, API gateway hardening, API inventory management, and security testing for protecting APIs from abuse and exploitation. Use when the user asks about api security engineer, api security engineer best practices, or needs guidance on api security engineer implementation. Do NOT use when the user needs a different specialized skill or is asking about an unrelated technology domain.
37 -
ferroxlabs Bundle Cross Chain DeveloperCross-chain development expertise covering bridge architectures (lock-and-mint, burn-and-mint, liquidity networks), interoperability protocols (LayerZero, Chainlink CCIP, Axelar, Wormhole), chain abstraction patterns, multi-chain deployment strategies, and security considerations for cross-chain applications. Use when the user asks about cross chain developer, related techniques, best practices, or needs guidance in this domain. Do NOT use when the request is outside the scope of cross chain developer or requires a different specialized skill.
37 -
ferroxlabs Bundle Health Tech DeveloperGuide for developers building healthcare technology covering HIPAA compliance, HL7 and FHIR interoperability standards, EHR integration, patient data security, regulatory considerations, and navigating the unique technical challenges of healthcare software. Use when the user asks about health tech developer, related techniques, best practices, or needs guidance in this domain. Do NOT use when the request is outside the scope of health tech developer or requires a different specialized skill.
37 -
ferroxlabs Bundle Home Security PlannerComprehensive guide to home security planning covering physical security assessment methodology, door and window reinforcement techniques, strategic lighting placement, camera and alarm system selection, smart lock options, safe room concepts, neighborhood watch participation, vacation security measures, and package theft prevention strategies. Use when the user asks about home security planner, related techniques, best practices, or needs guidance in this domain. Do NOT use when the request is outside the scope of home security planner or requires a different specialized skill.
37 -
ferroxlabs Bundle NPM Dependency DoctorFix npm dependency conflicts, audit vulnerabilities, resolve lockfile issues, and plan upgrades - with exact commands for every common npm problem. Use when the user asks about npm dependency doctor, related techniques, best practices, or needs guidance in this domain. Do NOT use when the request is outside the scope of npm dependency doctor or requires a different specialized skill.
37 -
ferroxlabs Bundle Password Audit RunnerSystematic process to audit, identify weak passwords, check for breaches, update credentials, and establish a secure password management workflow. Use when the user asks about password audit runner, related techniques, best practices, or needs guidance in this domain. Do NOT use when the request is outside the scope of password audit runner or requires a different specialized skill.
Audited 37 -
paulasilvatech Skill Dotnet Best PracticesReview or improve .NET and C# code against solution/project best practices for documentation, architecture, dependency injection, resources, async, tests, configuration, Semantic Kernel, logging, performance, security, SOLID, and code quality. Use when asked for .net/c# or .NET/C# best practices or cleanup.
Audited -
paulasilvatech Skill Create Technical SpikeCreate time-boxed technical spike documents that answer critical implementation questions before development proceeds. Use this skill when the user asks to create a technical spike, research an API or architecture decision, document a proof of concept, evaluate performance or security options, or unblock development with an evidence-based recommendation.
Audited -
paulasilvatech Skill Apple Appstore ReviewerReview an iOS app codebase and metadata for likely Apple App Store rejection risks, compliance gaps, reviewer friction, and fast approval improvements. Use when asked to "review for App Store rejection", "check Apple review readiness", "audit IAP and privacy", "write reviewer notes", or "find App Store approval risks".
-
paulasilvatech Skill Salesforce Apex QualityReview or generate Salesforce Apex classes, triggers, handlers, batch jobs, and test classes with quality guardrails for bulk safety, explicit sharing, CRUD/FLS enforcement, SOQL injection prevention, PNB tests, trigger architecture, and modern Apex idioms. Use when asked to catch governor limit risks, security gaps, and Apex deployment quality issues.
Audited -
paulasilvatech Bundle Data Breach Blast RadiusPre-breach impact analysis: inventories sensitive data (PII, PHI, PCI-DSS, credentials), traces data flows, scores exposure vectors, and produces a regulatory blast radius report with fine ranges sourced verbatim from GDPR Art. 83, CCPA § 1798.155(a), and HIPAA 45 CFR § 160.404. Cost benchmarks from IBM Cost of a Data Breach Report (annually updated). All citations in references/SOURCES.md for verification. Use when asked: "assess breach impact", "what data could be exposed", "calculate blast radius", "data exposure analysis", "how bad would a breach be", "quantify data risk", "sensitive data inventory", "data flow security audit", "pre-breach assessment", "worst-case breach scenario", "breach readiness", "data risk report", "/data-breach-blast-radius". For any stack handling user data, health records, or financial information. Output labels law-sourced figures (exact) vs heuristic estimates (planning only). Does not replace legal counsel.
-
paulasilvatech Bundle Github Actions HardeningReview, audit, author, and harden GitHub Actions workflows against Actions-specific threats: untrusted-input script injection, privileged trigger escalation, mutable action references, over-scoped GITHUB_TOKEN permissions, unsafe GITHUB_ENV/GITHUB_OUTPUT writes, secret exposure, OIDC misuse, and self-hosted runner risk. Use for .github/workflows/*.yml, secure my CI, pull_request_target danger, SHA pinning, or permissions lockdown.
-
paulasilvatech Bundle Github Actions EfficiencyAudit GitHub Actions workflow efficiency and recommend fixes that reduce CI runtime, runner minutes, and wasted workflow runs. Use when the user asks about caching, concurrency, path filters, matrix reduction, job optimization, workflow cost, or CI baseline design.
-
paulasilvatech Skill Competitor Ad IntelligenceAnalyze public competitor paid ads from Meta Ad Library and Google Ads Transparency Center, cluster creative hooks, inspect landing pages, infer funnel strategy, identify vulnerabilities, and recommend counter-plays. Use this skill when asked what ads a competitor is running, to tear down ad strategy, reverse-engineer a paid funnel, find paid ad angles, or audit the ad landscape.
Audited -
paulasilvatech Bundle Github Codespaces EfficiencyAudit and improve GitHub Codespaces efficiency. Use this skill when a user wants faster Codespaces startup, lower Codespaces spend, slim devcontainers, right-size machines, tune idle timeout, scope prebuilds, or create an efficient .devcontainer baseline.
-
ferroxlabs Bundle Customer Experience AuditCustomer experience assessment evaluating journey touchpoints, satisfaction metrics, support quality, feedback loops, and experience design to produce an actionable CX scorecard. Use when the user asks about customer experience audit, related techniques, best practices, or needs guidance in this domain. Do NOT use when the request is outside the scope of customer experience audit or requires a different specialized skill.
37 -
ferroxlabs Bundle Musical Theater PerformerExpert musical theater guidance covering audition preparation, triple threat training in singing/dancing/acting, repertoire building, rehearsal techniques, and performance excellence for stage musicals. Use when the user asks about musical theater performer, related techniques, best practices, or needs guidance in this domain. Do NOT use when the request is outside the scope of musical theater performer or requires a different specialized skill.
37 -
ferroxlabs Bundle Security Auditor SecuritySecurity vulnerability assessment expertise covering OWASP Top 10 deep dive, code review for security, dependency vulnerability scanning, SAST/DAST tools, security headers audit, authentication and authorization audit, and security assessment report writing for identifying and documenting application security weaknesses. Use when the user asks about security auditor, security auditor best practices, or needs guidance on security auditor implementation. Do NOT use when the user needs a different specialized skill or is asking about an unrelated technology domain.
Audited 37 -
ferroxlabs Bundle Security Hardening SprintStructured workflow for conducting a security hardening sprint on an existing application or infrastructure. Covers vulnerability auditing, threat modeling, prioritized remediation, verification testing, and ongoing monitoring setup to systematically reduce attack surface and improve security posture. Use when the user wants to security hardening sprint or needs a structured multi-step process for this goal. Do NOT use when the request is a single-step task or requires professional advice beyond educational guidance.
37 -
ferroxlabs Bundle Communication Skills AuditComprehensive evaluation of written, verbal, presentation, and listening communication skills with targeted improvement recommendations for professional settings Use when the user asks about communication skills audit, related techniques, best practices, or needs guidance in this domain. Do NOT use when the request is outside the scope of communication skills audit or requires a different specialized skill.
37 -
ferroxlabs Bundle Database Performance AuditDatabase performance assessment evaluating query efficiency, indexing strategy, connection management, configuration, and scaling readiness to produce an actionable performance scorecard. Use when the user asks about database performance audit, related techniques, best practices, or needs guidance in this domain. Do NOT use when the request is outside the scope of database performance audit or requires a different specialized skill.
37 -
tomevault-io Bundle Hivemoot Hivemoot Security ReviewerSkill: Security Reviewer
-
plurigrid Bundle Harness WritingWriting effective fuzzing harnesses for security testing.
-
plurigrid Bundle Hogwash RemovalAudit code and documentation for mathematical cargo-culting, inflated claims, and category-theoretic hogwash. Use when reviewing READMEs, module docs, comments, or papers that reference category theory, type theory, or abstract math. Detects misuse of technical terminology, analogy-dressed-as-theorem, name-dropping citations, and overclaimed novelty.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include tech-due-diligence, burp-suite, fix-review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.