Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
killvxk Bundle Building Threat Feed Aggregation With Misp部署 MISP(恶意软件信息共享平台)来聚合、关联和分发来自多个来源的威胁情报推送,用于集中式 IOC 管理和自动化 SIEM 集成。
-
killvxk Bundle Exploiting Insecure Data Storage In Mobile识别并利用 Android 和 iOS 移动应用程序中的本地数据不安全存储漏洞,包括未加密数据库、全局可读文件、不安全的 SharedPreferences、明文凭据存储以及 Keychain/Keystore 使用不当。适用于针对 OWASP M9(不安全数据存储)开展移动渗透测试,或评估 MASVS-STORAGE 合规性。适用于移动数据存储安全、本地存储利用、SharedPreferences 分析或移动数据泄露评估等请求场景。
-
killvxk Bundle Implementing Delinea Secret Server For Pam为特权访问管理(PAM)实施 Delinea Secret Server,包括 密钥库配置、基于角色的访问策略、自动密码轮换、 会话录制,以及与 Active Directory 和云平台的集成。 适用于 PAM 部署、特权凭据保管、 密钥服务器管理或密码轮换自动化相关请求。
-
killvxk Bundle Implementing Dmarc Dkim Spf Email SecuritySPF、DKIM 和 DMARC 是邮件认证的三大支柱,共同防止域名伪造、验证消息完整性并定义处理未认证邮件的策略。正确实施可显著减少冒充组织域名的钓鱼攻击。
-
killvxk Bundle Implementing Rapid7 Insightvm For Scanning部署和配置 Rapid7 InsightVM 安全控制台(Security Console)和扫描引擎(Scan Engines),在企业环境中执行认证和非认证漏洞扫描。
-
killvxk Bundle Implementing API Schema Validation Security使用OpenAPI规范和JSON Schema实现API Schema验证,强制执行输入/输出契约,防止注入、数据泄露和批量赋值攻击。
-
killvxk Bundle Performing Ot Vulnerability Scanning Safely使用被动监控、原生协议查询和经过精心控制的Tenable OT Security主动扫描,在OT/ICS环境中安全执行漏洞扫描,在不破坏工业过程或导致旧版控制器崩溃的情况下识别漏洞。
-
killvxk Bundle Performing Threat Hunting With Elastic Siem使用 KQL/EQL 查询、检测规则和 Timeline 调查在 Elastic Security SIEM 中执行主动威胁狩猎, 识别绕过自动检测的威胁。适用于 SOC 团队针对特定 ATT&CK 技术进行狩猎、调查异常行为, 或使用 Elasticsearch 和 Kibana Security 验证检测覆盖缺口。
-
killvxk Bundle Performing Web Application Penetration Test遵循 OWASP Web 安全测试指南(WSTG)方法论,对 Web 应用程序执行系统化安全测试,识别认证、授权、 输入验证、会话管理和业务逻辑中的漏洞。测试人员以 Burp Suite 作为主要拦截代理,结合手动测试技术 发现自动化扫描器遗漏的缺陷。适用于 Web 应用渗透测试、OWASP 测试、应用安全评估或 Web 漏洞测试等请求场景。
-
killvxk Bundle Triaging Security Incident With Ir Playbook使用结构化 IR Playbook 对安全事件进行分类和优先排序,确定严重性、分配响应团队并启动适当的响应程序。
-
killvxk Bundle Exploiting Prototype Pollution In Javascript检测并利用客户端和服务器端应用程序中的 JavaScript 原型链污染漏洞,通过属性注入实现 XSS、RCE 和身份验证绕过。
-
killvxk Bundle Implementing API Security Posture Management实施API安全态势管理,持续发现、分类并基于风险对API评分,同时在API生命周期中强制执行安全策略。
-
killvxk Bundle Implementing Google Workspace Admin Security实施全面的 Google Workspace 安全加固,包括管理控制台 配置、抗钓鱼 MFA 强制执行、DLP 策略、电子邮件认证 (SPF/DKIM/DMARC)、OAuth 应用控制和外部共享限制。 适用于 Google Workspace 加固、G Suite 安全配置 或云办公安全管理相关请求。
-
killvxk Bundle Performing S7comm Protocol Security Analysis对西门子SIMATIC S7 PLC使用的S7comm和S7CommPlus协议进行安全分析,识别漏洞,包括重放攻击、完整性绕过、未授权的CPU停止命令以及针对S7-300、S7-400、S7-1200和S7-1500控制器弱点的程序下载操控。
-
killvxk Bundle Performing Soap Web Service Security Testing通过分析 WSDL 定义,测试 XML 注入(XML Injection)、XXE、WS-Security 绕过和 SOAPAction 欺骗,对 SOAP Web 服务执行安全测试。
-
killvxk Bundle Analyzing Office365 Audit Logs For Compromise通过 Microsoft Graph API 解析 Office 365 统一审计日志,检测邮件转发规则创建、收件箱委托、可疑 OAuth 应用授权以及其他账户失陷指标。
-
killvxk Bundle Analyzing Threat Actor Ttps With Mitre AttackMITRE ATT&CK 是基于真实世界观察的全球可访问的对手战术、技术和过程(TTP)知识库。本技能涵盖系统性地将威胁行为者行为映射到 ATT&CK 框架、使用 ATT&CK Navigator 构建技术覆盖热力图、识别检测差距,以及生成将观察到的 IOC 关联到 Enterprise、Mobile 和 ICS 矩阵中特定对手技术的可执行情报报告。
-
killvxk Bundle Building Threat Intelligence Feed Integration构建自动化威胁情报(Threat Intelligence)源集成管道,将 STIX/TAXII 源、 开源威胁情报和商业 TI 平台接入 SIEM 和安全工具,实现实时 IOC 匹配和告警。 适用于 SOC 团队需要通过自动化源接入、标准化、评分和分发到检测系统来 将威胁情报付诸实践的场景。
-
killvxk Bundle Performing Cryptographic Audit Of Application密码学审计(Cryptographic Audit)系统性地审查应用程序对密码学原语、协议和密钥管理的使用,以识别弱算法、不安全模式、硬编码密钥、熵不足和协议配置错误等漏洞。本技能涵盖构建自动化密码学审计工具,扫描 Python 和配置文件中的常见密码学弱点。
-
killvxk Bundle Testing API For Mass Assignment Vulnerability测试 API 是否存在批量赋值(mass assignment,自动绑定)漏洞——攻击者可在 API 请求中附加额外参数,从而修改本不应被访问的对象属性。测试人员识别可写端点,向请求体注入未公开字段(role、isAdmin、price、balance),验证服务器是否在未过滤的情况下将这些字段绑定到数据模型。属于 OWASP API3:2023 Broken Object Property Level Authorization 范畴。适用于批量赋值测试、参数绑定滥用、自动绑定漏洞或 API 过度发布(over-posting)相关请求。
-
killvxk Bundle Detecting Qr Code Phishing With Email Security检测并防止二维码网络钓鱼(Quishing)攻击,该攻击通过在邮件图片中嵌入恶意 URL 来绕过传统邮件安全防护。
-
killvxk Bundle Exploiting Broken Function Level Authorization测试 API 的函数级授权破坏(BFLA)漏洞,即普通用户可以通过直接调用来执行管理功能或访问特权 API 端点。测试人员识别管理员和特权端点,然后通过操纵 HTTP 方法、URL 路径和请求参数尝试使用普通用户凭据访问这些端点。对应 OWASP API5:2023 函数级授权破坏。适用于 BFLA 测试、管理员端点绕过、函数级访问控制测试或 API 权限提升等请求场景。
-
killvxk Bundle Implementing API Threat Protection With Apigee使用Google Apigee策略实施API威胁防护,包括JSON/XML威胁防护、OAuth 2.0、SpikeArrest和高级API安全(Advanced API Security),防御OWASP Top 10攻击。
-
mouadja02 Bundle Senior SecopsSecOps — app security, vuln management, compliance verification, secure dev practices
-
mouadja02 Bundle Secret ScanningGitHub secret scanning — push protection, custom patterns, alert remediation
-
mouadja02 Bundle Senior SecuritySecurity engineering toolkit for threat modeling, vulnerability analysis, secure architecture, and penetration testing. Includes STRIDE analysis, OWASP guidance, cryptography patterns, and security scanning tools
-
mouadja02 Bundle Gdpr CompliantGDPR-compliant engineering — API design, data modeling, consent, retention, audit trails
-
mouadja02 Bundle Audit IntegrityAppSec audit integrity — output quality standards, honesty rules, continuous improvement
-
mouadja02 Bundle Security ReviewCodebase security scan — data flow tracing, OWASP top 10, secrets, dependency CVEs
-
sheshiyer Skill Understanding Tauri Runtime AuthorityExplains how the Tauri runtime authority enforces security at execution time: ACL-based access control, capability resolution, scope injection, and command validation for secure IPC. USE WHEN debugging why a command is denied, configuring capabilities and scopes, or tracing how IPC requests get authorized.
-
sheshiyer Skill Understanding Tauri Lifecycle SecurityMaps Tauri application lifecycle security threats across development, build, distribution, and runtime phases, with mitigation strategies and best practices. USE WHEN threat-modeling a Tauri app end to end or hardening a specific lifecycle phase against attack.
-
jiayaoqijia Bundle Audit ClawAuditClaw
-
jiayaoqijia Bundle Okx SecurityUse this skill for security scanning: check transaction safety, is this transaction safe, pre-execution check, security scan, token risk scanning, honeypot detection, DApp/URL phishing detection, message signature safety, malicious transaction detection, approval safety checks, token approval management. Triggers: 'is this token safe', 'check token security', 'honeypot check', 'scan this tx', 'scan this swap tx', 'tx risk check', 'is this URL a scam', 'check if this dapp is safe', 'phishing site check', 'is this signature safe', 'check this signing request', 'check my approvals', 'show risky approvals', 'revoke approval', 'check if this approve is safe', token authorization, ERC20 allowance, Permit2. Covers token-scan, dapp-scan, tx-scan (EVM+Solana pre-execution), sig-scan (EIP-712/personal_sign), approvals (ERC-20/Permit2). Chinese: 安全扫描, 代币安全, 蜜罐检测, 貔貅盘, 钓鱼网站, 交易安全, 签名安全, 代币风险, 授权管理, 授权查询, 风险授权, 代币授权. Do NOT use for wallet balance/send/history — use okx-agentic-wallet.
-
killvxk Bundle Implementing Proofpoint Email Security Gateway部署和配置 Proofpoint Email Protection 作为安全邮件网关,在邮件到达用户收件箱之前检测并拦截钓鱼、恶意软件、BEC 和垃圾邮件。
-
killvxk Bundle Implementing Threat Modeling With Mitre Attack使用 MITRE ATT&CK 框架实施威胁建模,将对手 TTP 映射到组织资产, 评估检测覆盖缺口,并优化防御投资。 适用于 SOC 团队需要将检测工程与威胁态势对齐、对新环境开展威胁评估, 或为安全工具采购提供决策依据时。
-
killvxk Bundle Testing For Xss Vulnerabilities With Burpsuite在授权的安全评估过程中,使用 Burp Suite 的扫描器、Intruder 和 Repeater 工具识别和验证跨站脚本(XSS)漏洞。适用于 Web 应用渗透测试中检测反射型、存储型和 DOM 型 XSS,验证自动化扫描器报告的 XSS 发现,以及评估 CSP 和 XSS 过滤器的有效性时使用。
Audited
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include building-threat-feed-aggregation-with-misp, exploiting-insecure-data-storage-in-mobile, implementing-delinea-secret-server-for-pam. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.