Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
plurigrid Bundle Ostium Arbitrum PerpsInteract with Ostium Protocol -- a decentralized perpetual exchange on Arbitrum for RWA (Forex, Commodities, Indices, Stocks) and Crypto. Covers contract architecture, testnet deployment, SDK integration, oracle system, vault mechanics, and security auditing via Trail of Bits skills.
-
plurigrid Bundle Secure Workflow GuideGuide you through Trail of Bits' 5-step secure development workflow. Runs Slither scans, checks special features (upgradeability/ERC conformance/token integration), generates visual security diagrams, helps document security properties for fuzzing/verification, and reviews manual security areas. (project, gitignored)
-
plurigrid Bundle Skill Finder VerifierFind locally-created skills and verify provenance. Distinguishes locally-created from batch-installed by diffing against asi/skills/ baseline. Evaluates modified downloads for functional improvement. Triggers: new skills, local skills, skill audit, skill provenance, skill verification.
-
plurigrid Bundle Audit Context BuildingEnables ultra-granular, line-by-line code analysis to build deep architectural context before vulnerability or bug finding.
-
plurigrid Bundle Constant Time AnalysisDetects timing side-channel vulnerabilities in cryptographic code. Use when implementing or reviewing crypto code, encountering division on secrets, secret-dependent branches, or constant-time programming questions in C, C++, Go, Rust, Swift, Java, Kotlin, C#, PHP, JavaScript, TypeScript, Python, or Ruby.
-
plurigrid Bundle Wireless Network AuditAudit wireless networks (WiFi, BLE, Zigbee) for security vulnerabilities using aircrack-ng, bettercap, hcxtools, and bluetooth utilities. For authorized penetration testing and security assessments only.
-
newmindsgroup Skill Pentest CommandsProvide a comprehensive command reference for penetration testing tools including network scanning, exploitation, password cracking, and web application testing. Enable quick command lookup during security assessments.
Audited -
newmindsgroup Skill Security AuditorExpert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks.
Audited -
newmindsgroup Skill Variant AnalysisFind similar vulnerabilities and bugs across codebases using pattern-based analysis. Use when hunting bug variants, building CodeQL/Semgrep queries, analyzing security vulnerabilities, or performing systematic code audits after finding an initial issue.
Audited -
newmindsgroup Skill GRAPHQL ArchitectMaster modern GraphQL with federation, performance optimization, and enterprise security. Build scalable schemas, implement advanced caching, and design real-time systems.
Audited -
newmindsgroup Skill Saas Multi TenantDesign and implement multi-tenant SaaS architectures with row-level security, tenant-scoped queries, shared-schema isolation, and safe cross-tenant admin patterns in PostgreSQL and TypeScript.
Audited -
newmindsgroup Bundle Solidity SecurityMaster smart contract security best practices, vulnerability prevention, and secure Solidity development patterns.
-
newmindsgroup Skill Vibe Code AuditorAudit rapidly generated or AI-produced code for structural flaws, fragility, and production risks.
Audited -
newmindsgroup Skill Burp Suite TestingExecute comprehensive web application security testing using Burp Suite's integrated toolset, including HTTP traffic interception and modification, request analysis and replay, automated vulnerability scanning, and manual testing workflows.
-
newmindsgroup Skill Django Perf ReviewDjango performance code review. Use when asked to "review Django performance", "find N+1 queries", "optimize Django", "check queryset performance", "database performance", "Django ORM issues", or audit Django code for performance problems.
Audited -
newmindsgroup Skill Sast ConfigurationStatic Application Security Testing (SAST) tool setup, configuration, and custom rule creation for comprehensive security scanning across multiple programming languages.
Audited -
newmindsgroup Skill Vibers Code ReviewHuman review workflow for AI-generated GitHub projects with spec-based feedback, security review, and follow-up PRs from the Vibers service.
Audited -
newmindsgroup Bundle Wireshark AnalysisExecute comprehensive network traffic analysis using Wireshark to capture, filter, and examine network packets for security investigations, performance optimization, and troubleshooting.
-
newmindsgroup Skill Differential ReviewSecurity-focused code review for PRs, commits, and diffs.
-
newmindsgroup Skill File Path TraversalIdentify and exploit file path traversal (directory traversal) vulnerabilities that allow attackers to read arbitrary files on the server, potentially including sensitive configuration files, credentials, and source code.
Audited -
newmindsgroup Skill Gha Security ReviewFind exploitable vulnerabilities in GitHub Actions workflows. Every finding MUST include a concrete exploitation scenario — if you can't build the attack, don't report it.
Audited -
newmindsgroup Bundle Project Skill AuditAudit a project and recommend the highest-value skills to add or update.
-
newmindsgroup Bundle Wcag Audit PatternsComprehensive guide to auditing web content against WCAG 2.2 guidelines with actionable remediation strategies.
-
newmindsgroup Bundle API Endpoint BuilderBuilds production-ready REST API endpoints with validation, error handling, authentication, and documentation. Follows best practices for security and scalability.
-
newmindsgroup Skill API Security TestingAPI security testing workflow for REST and GraphQL APIs covering authentication, authorization, rate limiting, input validation, and security best practices.
Audited -
newmindsgroup Skill Metasploit Framework⚠️ AUTHORIZED USE ONLY > This skill is for educational purposes or authorized security assessments only. > You must have explicit, written permission from the system owner before using this tool. > Misuse of this tool is illegal and strictly prohibited.
Audited -
newmindsgroup Skill Semgrep Rule CreatorCreates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. Use when writing Semgrep rules or building custom static analysis detections.
Audited -
newmindsgroup Skill Web Security TestingWeb application security testing workflow for OWASP Top 10 vulnerabilities including injection, XSS, authentication flaws, and access control issues.
Audited -
ferroxlabs Bundle Tenant Rights AdvisorLease review guidance, security deposit rights, repair obligations, eviction process understanding, and tenant protections for informed renting decisions. Use when the user asks about tenant rights advisor, or needs help with lease review guidance, security deposit rights, repair obligations, eviction process understanding, and tenant protections for informed renting decisions. Do NOT use when the request requires professional legal advice or falls outside the scope of tenant rights advisor.
37 -
ferroxlabs Bundle Authorization PatternsGuides expert-level authorization patterns implementation: security and design-patterns decision frameworks, production-ready patterns, and concrete templates for authorization patterns workflows. Use when the user asks about authorization patterns, authorization patterns configuration, or security best practices for authorization projects. Do NOT use when the user needs a different backend infrastructure capability -- check sibling skills in the backend infrastructure subcategory.
37 -
ferroxlabs Bundle Cybersecurity PersonalComprehensive guide to personal digital security covering password management strategies, two-factor authentication setup, VPN selection and usage, phishing recognition techniques, social engineering awareness, device security hardening, privacy settings for social media and browsers, data breach response procedures, and secure communication tools. Use when the user asks about cybersecurity personal, related techniques, best practices, or needs guidance in this domain. Do NOT use when the request is outside the scope of cybersecurity personal or requires a different specialized skill.
Audited 37 -
ferroxlabs Bundle Device Hardening GuideSystematically secure personal devices through OS hardening, router and network security, IoT device isolation, firmware management, and attack surface reduction for home and small office environments Use when the user asks about device hardening guide, related techniques, best practices, or needs guidance in this domain. Do NOT use when the request is outside the scope of device hardening guide or requires a different specialized skill.
37 -
ferroxlabs Bundle Digital Wellness AuditComprehensive digital wellness assessment covering screen time patterns, social media impact, notification overload, digital boundaries, online behavior health, and producing a personalized digital wellness improvement plan. Use when the user asks about digital wellness audit, related techniques, best practices, or needs guidance in this domain. Do NOT use when the request is outside the scope of digital wellness audit or requires a different specialized skill.
37 -
ferroxlabs Bundle Ip Protection OverviewCompares the four main types of intellectual property protection: copyright, trademark, patent, and trade secret. Explains what each protects, how protection is obtained, duration, registration processes, and when each type applies. Produces a structured comparison to help users identify which protections may apply to their work. Use when the user wants to understand intellectual property basics, needs to identify which IP protection applies to their creation, or wants to prepare for a consultation with an IP attorney. Do NOT use for filing patent or trademark applications, IP infringement analysis, licensing agreement drafting, or specific legal advice on IP disputes.
37 -
ferroxlabs Bundle Oss Security ResponderOpen source security response expertise covering CVE identification and reporting, security advisory creation, coordinated vulnerability disclosure, patch development and backporting, security policy implementation (SECURITY.md), and incident response workflows for open source maintainers. Use when the user asks about oss security responder, related techniques, best practices, or needs guidance in this domain. Do NOT use when the request is outside the scope of oss security responder or requires a different specialized skill.
37 -
ferroxlabs Bundle Rate Limiting PatternsGuides expert-level rate limiting patterns implementation: security and optimization decision frameworks, production-ready patterns, and concrete templates for rate limiting patterns workflows. Use when the user asks about rate limiting patterns, rate limiting patterns configuration, or security best practices for rate projects. Do NOT use when the user needs a different backend infrastructure capability -- check sibling skills in the backend infrastructure subcategory.
37
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include ostium-arbitrum-perps, secure-workflow-guide, skill-finder-verifier. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.