Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
killvxk Bundle Triaging Security Incident使用 NIST SP 800-61r3 和 SANS PICERL 框架对安全事件进行初始分类,确定严重性、范围和所需响应行动。 按类型对事件分类,根据业务影响分配优先级,并路由到相应的响应团队。适用于事件分类、 安全告警分类、严重性评估、事件优先级排序或初始事件分析等请求场景。
-
killvxk Bundle Correlating Threat Campaigns关联不同时间和组织的安全事件、IOC 和对手行为,识别统一的威胁活动,将其归因于共同的威胁行为者,并提取共享指标以改善检测效果。适用于多起事件出现重叠指标、需要跨组织分析行业范围内攻击活动,或构建活动级别情报产品时。适用于涉及活动分析、事件聚类、跨组织 IOC 关联或 MISP 关联引擎的请求。
-
killvxk Bundle Profiling Threat Actor Groups通过聚合 TTP 文档、历史活动数据、工具指纹和来自多个情报源的归因指标,为 APT 组织、犯罪组织和黑客活动组织开发全面的威胁行为者画像。适用于就行业特定威胁向管理层汇报、更新威胁模型假设,或针对特定对手优先部署防御控制措施。当涉及 MITRE ATT&CK 组织、Mandiant APT 画像、CrowdStrike 对手命名或行业特定威胁简报时激活。
-
killvxk Bundle Testing Websocket API Security测试 WebSocket API 实现中的安全漏洞,包括 WebSocket 升级时缺少身份认证、跨站 WebSocket 劫持(Cross-Site WebSocket Hijacking,CSWSH)、通过 WebSocket 消息进行的注入攻击、输入校验不足、通过消息泛洪实施拒绝服务,以及通过 WebSocket 帧造成的信息泄露。测试人员使用 Burp Suite 拦截 WebSocket 握手和消息,构造恶意 payload,并测试 WebSocket 通道上的授权绕过。适用于 WebSocket 安全测试、WS 渗透测试、CSWSH 攻击或实时 API 安全评估相关请求。
-
killvxk Bundle Conducting API Security Testing对 REST、GraphQL 和 gRPC API 进行安全测试,识别认证、授权、速率限制、输入验证和业务逻辑中的漏洞。测试人员以 OWASP API 安全 Top 10 作为测试框架,结合 Burp Suite 拦截、Postman 集合和自定义脚本,在每个权限级别测试端点安全性。
-
killvxk Bundle Testing For Xss Vulnerabilities通过向反射型、存储型和 DOM 型上下文注入 JavaScript 载荷,测试 Web 应用程序的跨站脚本(XSS)漏洞, 演示客户端代码执行、会话劫持和用户冒充。测试人员识别所有注入点和输出上下文,构造适合上下文的载荷, 并绕过净化和 CSP 保护。适用于 XSS 测试、跨站脚本评估、客户端注入测试或 JavaScript 注入漏洞测试等请求场景。
-
killvxk Bundle Performing Service Account Audit审计企业基础设施中的服务账户,识别孤立账户、过度特权账户和不合规账户。本技能涵盖在 Active Directory、云平台中发现服务账户,评估权限级别,识别缺失负责人,以及执行生命周期策略。
-
killvxk Bundle Containing Active Security Breach通过隔离受攻陷系统、阻断攻击者通信并保全证据,同时最大程度减少业务中断,快速遏制活跃安全攻陷。
-
killvxk Bundle Performing Security Headers Audit审计 HTTP 安全头,包括 CSP、HSTS、X-Frame-Options 和 Cookie 属性,以识别缺失或配置错误的浏览器级防护。
-
killvxk Bundle Detecting Insider Threat Behaviors检测内部威胁行为指标,包括异常数据访问、非工作时间活动、大量文件下载、权限滥用和离职相关的数据盗取。
-
killvxk Bundle Detecting Insider Threat With Ueba使用 Elasticsearch/OpenSearch 实施用户和实体行为分析(UEBA),构建行为基线、计算异常分数、执行对等组分析,并检测内部威胁指标,如数据外泄、权限滥用和未授权访问模式。
-
killvxk Bundle Performing Iot Security Assessment通过测试硬件接口、固件、网络通信、云 API 和配套移动应用程序,对 IoT 设备及其生态系统执行全面的安全评估。 测试人员使用固件提取与分析、通过 UART 和 JTAG 进行硬件调试、网络协议分析以及运行时利用等技术, 识别 IoT 各层的漏洞。适用于 IoT 安全测试、嵌入式设备评估、固件安全分析或智能设备渗透测试等请求场景。
-
killvxk Bundle Triaging Security Alerts In Splunk在 Splunk Enterprise Security 中对安全告警进行分类,通过 SPL 查询和事件审查(Incident Review) 仪表板对重要事件进行严重性分类、调查、关联相关遥测并做出升级或关闭决策。 适用于 SOC 分析师需要处理关联搜索产生的告警队列、确定调查优先级, 或需要为交接给二/三级分析师记录分类决策时。
-
killvxk Bundle Analyzing Security Logs With Splunk利用 Splunk Enterprise Security 和 SPL(Search Processing Language,搜索处理语言),通过日志关联、时间线重建和异常检测来调查安全事件。涵盖 Windows 事件日志、防火墙日志、代理日志和认证数据分析。适用于 Splunk 调查、SPL 查询、SIEM 日志分析、安全事件关联或基于日志的事件调查相关请求。
-
killvxk Bundle Analyzing Threat Intelligence Feeds分析结构化和非结构化威胁情报(CTI)推送,提取可操作的指标、对手战术和攻击活动上下文。适用于导入商业或开源 CTI 情报、评估情报质量、将数据规范化为 STIX 2.1 格式,或使用攻击活动溯源归因富化现有 IOC 时使用。
-
killvxk Bundle Configuring Ldap Security Hardening加固 LDAP 目录服务以防御常见攻击,包括凭据收集、LDAP 注入、匿名绑定和通道绑定绕过。涵盖 LDAPS 强制执行、通道绑定、LDAP 签名、访问控制列表及 LDAP 攻击监控。
-
killvxk Bundle Implementing Bgp Security With Rpki使用路由来源授权(ROA)、RPKI-to-Router 协议和 Cisco、Juniper 路由器上的 ROV 策略,实施 BGP 路由来源验证(RPKI),以防止路由劫持。
-
killvxk Bundle Performing API Rate Limiting Bypass通过操纵请求头、IP 地址、HTTP 方法、API 版本和编码方案,测试 API 限速(Rate Limiting) 实现中的绕过漏洞,以规避请求节流控制。测试人员识别限速响应头,确定执行机制, 并尝试包括 X-Forwarded-For 欺骗、参数污染、大小写变换和端点路径操纵在内的绕过手段。 映射至 OWASP API4:2023 无限制资源消耗。当请求涉及限速绕过、API 节流规避、 暴力破解防护测试或 API 滥用防御评估时触发。
-
killvxk Bundle Analyzing Threat Landscape With Misp使用 MISP(恶意软件信息共享平台)通过查询事件统计、属性分布、威胁行为者 galaxy 集群和标签趋势来分析威胁态势。使用 PyMISP 拉取事件数据、计算 IOC 类型分布、识别顶级威胁行为者和恶意软件家族,并生成含时序趋势的威胁态势报告。
-
caishengold Skill Security Report Writer当需要撰写安全评估报告、渗透测试报告、漏洞报告时使用。触发场景:安全评估报告、渗透测试报告、漏洞披露、风险评级。当用户提到"安全报告"、"渗透测试报告"、"漏洞报告"、"security report"、"pentest report"时应触发此技能。
-
caishengold Skill Physical Security Writer当需要撰写安防方案相关专业文案、行业指南、科普文章时使用。触发场景:实体安防方案/制度。当用户提到"安防方案"、"实体安防方案"、"制度"、"physical"、"security"时应触发此技能。
-
vincentchuwaichow Bundle Snowflake Identity Access SecurityUse this skill to review Snowflake identity and authorization: effective access across role hierarchy, ownership and future grants; custom, database, and application role choice; managed access schemas; authentication policies, MFA, SSO, SCIM, OAuth, key-pair, and workload identity federation; SERVICE and SERVICE_AGENT user types; and concrete privilege-escalation paths. Trigger on any question about who can do what in a Snowflake account, or how a principal proves identity. Static review only: it never executes a grant, never alters a user, and never accepts a credential.
-
vincentchuwaichow Bundle Contabo Live Storage Operations GuardLive-guard skill for Contabo Object Storage (S3-compatible) bucket operations including inventory audit, access policy review, retention policy enforcement, and deletion workflows. Hard-stops any bucket deletion requested without verified backup evidence and a documented rollback plan. Use when the user needs to manage, audit, or delete Contabo Object Storage buckets or objects.
-
vincentchuwaichow Bundle Java Deserialization And Parser SecurityUse this skill when statically reviewing the JVM's untrusted-deserialization and data-parsing surface for remote-code-execution and injection risk — Java native ObjectInputStream gadget chains (and the ObjectInputFilter/JEP 290 control), SnakeYAML bare Constructor, Jackson polymorphic default typing without a PolymorphicTypeValidator, XML external-entity (XXE) exposure across every parser factory, and reflective/expression sinks fed by untrusted input. Trigger when a user provides code that deserializes bytes or parses YAML/JSON/XML from a request, message, uploaded file, or external API, or asks whether a parser is safe. Reads source and sanitized configuration only; it never executes code or deserializes a payload.
-
vincentchuwaichow Bundle PHP Session Upload Deserialization ReviewUse this skill to statically review PHP code for object-injection risk from unserialize() on untrusted input, session fixation/hijacking from missing session_regenerate_id() or weak session cookie hardening, and unsafe file-upload handling that trusts the client or stores/executes uploads inside the webroot. Use when reviewing a PHP application for deserialization, authentication-session, or upload-handling security issues. Static review only; it never executes payloads, uploads, or requests against any system, and every unserialize()/session/upload claim is grounded in the current php.net manual rather than memory.
-
vincentchuwaichow Bundle Databricks Unity Catalog GovernanceUse this skill to review Unity Catalog governance design for privilege correctness, ownership clarity, and least-privilege enforcement: three-level namespace design, GRANT inheritance, ownership, workspace-catalog binding, governed tags, storage credentials, and audit completeness. Reads UC metadata and privilege assignments only; never executes grants and never requires credentials.
-
vincentchuwaichow Bundle Dotnet Aspnetcore Identity Authz ReviewUse this skill when reviewing how an ASP.NET Core application authenticates and authorizes requests — authentication schemes, JWT TokenValidationParameters, cookie and session security, policy-based authorization, authorization handlers, claims trust, role-versus-resource authorization, multi-tenant isolation, privilege-escalation paths, and negative-test coverage. Trigger when a user provides ASP.NET Core authentication or authorization source (Program.cs, JWT bearer or cookie configuration, authorization policies, authorization handlers, controller authorize attributes) or sanitized configuration, asks whether their auth boundary is safe, or wants to know whether a tenant or role check can be bypassed. This skill reviews source and sanitized configuration statically; it never runs the application, mints or inspects tokens, or contacts an identity provider.
-
vincentchuwaichow Bundle M365 Defender Xdr Security OperationsMicrosoft 365 Defender XDR Security Operations
-
vincentchuwaichow Bundle M365 Purview Data Security ComplianceMicrosoft 365 Purview Data Security and Compliance
-
vincentchuwaichow Bundle Netsuite Data Governance Privacy SkillFlashlight skill for auditing PII exposure paths, data retention and purge policies, field-level access restrictions, privacy controls, and export configurations in NetSuite. T0 static review — no live account connection or actual personal data required. TRIGGER when: user asks to review PII field access, audit data retention settings, check field-level security on sensitive records, assess privacy controls, identify PII in saved searches, review export control permissions, or evaluate GDPR/CCPA readiness of a NetSuite configuration. Trigger phrases: PII exposure, field-level security, data retention policy, GDPR compliance, personal data access, export controls, consent tracking, sensitive field access. DO NOT TRIGGER when: the user needs role and permission architecture review beyond PII fields (use netsuite-identity-access-role-permission-skill), SOX audit trail review (use netsuite-audit-controls-sox-skill), integration data-flow security (use netsuite-integration-migration-skill), subsidiary data segrega
-
vincentchuwaichow Bundle Snowflake Compliance Evidence AuditorUse this skill to establish whether a Snowflake control is provable to an auditor: evidence collection from ACCESS_HISTORY, LOGIN_HISTORY, grant history and Trust Center, control mapping with named gaps, audit-period coverage, evidence freshness and retention limits, and segregation-of-duties analysis derived from the grant graph. Trigger when the question is proof rather than configuration. It never implements a control and never states a compliance conclusion.
-
vincentchuwaichow Bundle Netsuite Oneworld Multisubsidiary SkillFlashlight skill for reviewing NetSuite OneWorld multi-entity configurations: subsidiary hierarchies, intercompany account boundaries, cross-subsidiary visibility restrictions, multi-currency settings, and tax-jurisdiction nexus alignment. T0 static review — no live account connection required. TRIGGER when: user asks to review subsidiary structure, audit intercompany accounts, check cross-subsidiary role scoping, validate tax nexus coverage, assess consolidation configuration, or diagnose OneWorld hierarchy issues. Trigger phrases: subsidiary hierarchy, intercompany elimination, cross-subsidiary access, multi-currency consolidation, tax nexus, due-to due-from, legal entity registration, OneWorld configuration. DO NOT TRIGGER when: the user needs authentication or OAuth/TBA token review (use netsuite-sso-oauth-tba-skill), role/permission assignment analysis beyond subsidiary scoping (use netsuite-identity-access-role-permission-skill), SOX audit evidence generation (use netsuite-audit-controls-sox-skill), or
-
vincentchuwaichow Bundle Salesforce Infrastructure Audit SkillSalesforce Infrastructure Audit Skill
-
vincentchuwaichow Bundle Incident To Remediation ProtocolUse this skill when a security incident must be triaged, contained, remediated, and reviewed in a Zero Trust assume-breach posture across Microsoft 365 and Dynamics 365 environments. Defines the end-to-end flow from detection through severity triage, containment approval, investigation, remediation, and post-incident review. Applies Zero Trust principles — verify explicitly, use least privilege, assume breach — throughout. Does not serve as an authorization to isolate devices, block users, or make configuration changes; all containment and remediation actions require human approval from the security owner or incident commander. Does not replace a qualified SecOps team or Microsoft Defender XDR specialist.
-
vincentchuwaichow Bundle Prometheus Alerting Cardinality ReviewUse this skill when reviewing Prometheus or AlertManager configuration for cardinality, alerting correctness, scrape security, remote_write safety, or retention adequacy. Trigger when a user provides prometheus.yml, alertmanager.yml, recording rules YAML, alerting rules YAML, or asks whether their Prometheus setup is production-ready.
-
vincentchuwaichow Bundle Sap Integration Platform Businessops ProtocolCross-functional coordination protocol governing handoff contracts between SAP Integration, Platform Engineering, and Business Operations. Activates on failed integration flows, API throttling, event delivery failures, broken partner integrations, data replication failures, middleware instability, and business-process outage. Advisory and audit only — no live mutation.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include triaging-security-incident, correlating-threat-campaigns, profiling-threat-actor-groups. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.