Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
ferroxlabs Bundle Shell Scripting MasterAdvanced shell scripting expert covering shell and Zsh patterns, robust error handling (set -euo pipefail), argument parsing (getopts, manual), portability across shells and OS, testing shell scripts (bats, shellcheck), process management, text processing pipelines, and script security practices. Use when the user asks about shell scripting master, shell scripting master best practices, or needs guidance on shell scripting master implementation. Do NOT use when the user needs a different specialized skill or is asking about an unrelated technology domain.
37 -
ferroxlabs Bundle Authentication PatternsGuides expert-level authentication patterns implementation: security and web-development decision frameworks, production-ready patterns, and concrete templates for authentication patterns workflows. Use when the user asks about authentication patterns, authentication patterns configuration, or security best practices for authentication projects. Do NOT use when the user needs a different backend infrastructure capability -- check sibling skills in the backend infrastructure subcategory.
Audited 37 -
ferroxlabs Bundle Declutter Organize HomeSystematic home decluttering and organization workflow from initial audit and system design through room-by-room execution and long-term maintenance habits for a permanently organized living space. Use when the user wants to declutter organize home or needs a structured multi-step process for this goal. Do NOT use when the request is a single-step task or requires professional advice beyond educational guidance.
37 -
ferroxlabs Bundle Developer Tools BuilderDeveloper tools design and implementation covering CLI design patterns, SDK architecture, API design best practices, documentation strategy, developer experience optimization, plugin systems, error message design, versioning and changelog management, and developer onboarding flows. Includes code examples, DX audit checklists, and distribution patterns. Use when the user asks about developer tools builder, related techniques, best practices, or needs guidance in this domain. Do NOT use when the request is outside the scope of developer tools builder or requires a different specialized skill.
37 -
ferroxlabs Bundle Email Security HardenerEmail security expertise covering SPF, DKIM, and DMARC configuration for domain protection, phishing detection techniques, email encryption with PGP and S/MIME, secure email provider evaluation, email header analysis, business email compromise prevention, and building organizational email security policies. Use when the user asks about email security hardener, related techniques, best practices, or needs guidance in this domain. Do NOT use when the request is outside the scope of email security hardener or requires a different specialized skill.
37 -
ferroxlabs Bundle Wallet Security AdvisorCryptocurrency wallet security expertise covering cold storage setup, hardware wallet configuration, multisig wallet deployment, seed phrase management, recovery planning, phishing and social engineering prevention, transaction verification, approval hygiene, and operational security practices for protecting digital assets. Use when the user asks about wallet security advisor, related techniques, best practices, or needs guidance in this domain. Do NOT use when the request is outside the scope of wallet security advisor or requires a different specialized skill.
37 -
ferroxlabs Bundle Waste Reduction PlannerConducts a household waste audit and produces a zero-waste action plan organized by waste stream (trash, recycling, compost, hazardous). Gathers the user's current waste habits, housing situation, and local services to produce a prioritized reduction plan with estimated waste diversion percentages and cost savings. Use when the user asks about reducing household waste, starting a zero-waste journey, improving recycling habits, or conducting a waste audit. Do NOT use for commercial or industrial waste management, hazardous waste disposal procedures, composting setup details (use composting-starter-guide), or municipal waste policy analysis.
37 -
ferroxlabs Bundle Wcag Compliance AuditorAudit digital products against WCAG 2.1/2.2 standards, determine conformance levels, identify failures, and produce actionable remediation plans with prioritized fixes. Use when the user asks about wcag compliance auditor, related techniques, best practices, or needs guidance in this domain. Do NOT use when the request is outside the scope of wcag compliance auditor or requires a different specialized skill.
37 -
ferroxlabs Bundle Work Life Balance AuditStructured evaluation of time allocation, role satisfaction, burnout indicators, and boundary effectiveness across work and personal domains. Produces a balance scorecard with specific recommendations for sustainable adjustment. Use when the user asks about work life balance audit, related techniques, best practices, or needs guidance in this domain. Do NOT use when the request is outside the scope of work life balance audit or requires a different specialized skill.
37 -
ferroxlabs Bundle Airport Navigation GuideCreates a terminal-to-gate workflow with check-in timelines, security preparation steps, connection procedures, and gate-area logistics. Gathers flight details, airport, traveler experience level, and special needs to produce a timed step-by-step airport navigation plan from arrival at the airport to boarding the plane. Use when the user asks about airport navigation, check-in procedures, how early to arrive at the airport, connecting flight logistics, or getting through security efficiently. Do NOT use for flight booking strategies (use travel logistics skills), travel itinerary building (use trip-itinerary-builder), or airport lounge access evaluation.
37 -
ferroxlabs Bundle Mobile Security EngineerMobile application security covering certificate pinning implementation, secure local storage patterns, jailbreak and root detection, code obfuscation and tamper detection, API security for mobile clients, biometric authentication, secure key management, network security, reverse engineering defense, and compliance with OWASP MASVS. Use when the user asks about mobile security engineer, mobile security engineer best practices, or needs guidance on mobile security engineer implementation. Do NOT use when the user needs a different specialized skill or is asking about an unrelated technology domain.
37 -
newmindsgroup Skill Broken AuthenticationIdentify and exploit authentication and session management vulnerabilities in web applications. Broken authentication consistently ranks in the OWASP Top 10 and can lead to account takeover, identity theft, and unauthorized access to sensitive systems.
Audited -
newmindsgroup Skill Claude Settings AuditAnalyze a repository to generate recommended Claude Code settings.json permissions. Use when setting up a new project, auditing existing settings, or determining which read-only bash commands to allow. Detects tech stack, build tools, and monorepo structure.
Audited -
newmindsgroup Skill Code Review ChecklistComprehensive checklist for conducting thorough code reviews covering functionality, security, performance, and maintainability
Audited -
newmindsgroup Bundle Linux Shell ScriptingProvide production-ready shell script templates for common Linux system administration tasks including backups, monitoring, user management, log analysis, and automation. These scripts serve as building blocks for security operations and penetration testing environments.
-
newmindsgroup Skill Mobile Security CoderExpert in secure mobile coding practices specializing in input validation, WebView security, and mobile-specific security patterns.
Audited -
newmindsgroup Skill Nodejs Best PracticesNode.js development principles and decision-making. Framework selection, async patterns, security, and architecture. Teaches thinking, not copying.
-
newmindsgroup Bundle Production Code AuditAutonomously deep-scan entire codebase line-by-line, understand architecture and patterns, then systematically transform it to production-grade, corporate-level professional quality with optimizations
-
newmindsgroup Bundle Vulnerability ScannerAdvanced vulnerability analysis principles. OWASP 2025, Supply Chain Security, attack surface mapping, risk prioritization.
-
newmindsgroup Skill Audit Context BuildingEnables ultra-granular, line-by-line code analysis to build deep architectural context before vulnerability or bug finding.
Audited -
newmindsgroup Skill Backend Security CoderExpert in secure backend coding practices specializing in input validation, authentication, and API security. Use PROACTIVELY for backend security implementations or security code reviews.
Audited -
newmindsgroup Skill Constant Time AnalysisAnalyze cryptographic code to detect operations that leak secret data through execution timing variations.
Audited -
newmindsgroup Skill Laravel Security AuditSecurity auditor for Laravel applications. Analyzes code for vulnerabilities, misconfigurations, and insecure practices using OWASP standards and Laravel security best practices.
Audited -
newmindsgroup Skill Threat Modeling ExpertExpert in threat modeling methodologies, security architecture review, and risk assessment. Masters STRIDE, PASTA, attack trees, and security requirement extraction. Use PROACTIVELY for security architecture reviews, threat identification, or building secure-by-design systems.
Audited -
newmindsgroup Skill Codebase Audit Pre PushDeep audit before GitHub push: removes junk files, dead code, security holes, and optimization issues. Checks every file line-by-line for production readiness.
Audited -
newmindsgroup Skill Ssh Penetration TestingConduct comprehensive SSH security assessments including enumeration, credential attacks, vulnerability exploitation, tunneling techniques, and post-exploitation activities. This skill covers the complete methodology for testing SSH service security.
Audited -
newmindsgroup Bundle Top Web VulnerabilitiesProvide a comprehensive, structured reference for the 100 most critical web application vulnerabilities organized by category. This skill enables systematic vulnerability identification, impact assessment, and remediation guidance across the full spectrum of web security threats.
-
newmindsgroup Bundle Attack Tree ConstructionBuild comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders.
-
newmindsgroup Skill Burpsuite Project ParserSearches and explores Burp Suite project files (.burp) from the command line. Use when searching response headers or bodies with regex patterns, extracting security audit findings, dumping proxy history or site map data, or analyzing HTTP traffic captured in a Burp project.
Audited -
newmindsgroup Bundle Cc Skill Security ReviewThis skill ensures all code follows security best practices and identifies potential vulnerabilities. Use when implementing authentication or authorization, handling user input or file uploads, or creating new API endpoints.
-
newmindsgroup Skill Event Sourcing ArchitectExpert in event sourcing, CQRS, and event-driven architecture patterns. Masters event store design, projection building, saga orchestration, and eventual consistency patterns. Use PROACTIVELY for event-sourced systems, audit trail requirements, or complex domain modeling with temporal queries.
Audited -
newmindsgroup Bundle Smtp Penetration TestingConduct comprehensive security assessments of SMTP (Simple Mail Transfer Protocol) servers to identify vulnerabilities including open relays, user enumeration, weak authentication, and misconfiguration.
-
newmindsgroup Bundle Stride Analysis PatternsApply STRIDE methodology to systematically identify threats. Use when analyzing system security, conducting threat modeling sessions, or creating security documentation.
-
newmindsgroup Bundle Anti Reversing TechniquesAUTHORIZED USE ONLY: This skill contains dual-use security techniques. Before proceeding with any bypass or analysis: > 1.
-
newmindsgroup Skill Security Bluebook BuilderBuild a minimal but real security policy for sensitive apps. The output is a single, coherent Blue Book document using MUST/SHOULD/CAN language, with explicit assumptions, scope, and security gates.
Audited -
newmindsgroup Skill Supply Chain Risk AuditorIdentifies dependencies at heightened risk of exploitation or takeover. Use when assessing supply chain attack surface, evaluating dependency health, or scoping security engagements.
Audited
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include shell-scripting-master, authentication-patterns, declutter-organize-home. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.