Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
killvxk Bundle Implementing API Security Testing With 42crunch使用42Crunch平台实施全面的API安全测试,对OpenAPI规范执行静态审计(Static Audit)和动态合规扫描(Conformance Scanning)。
-
killvxk Bundle Implementing Email Security With Dmarc Dkim Spf通过检查域名的 SPF、DKIM 和 DMARC DNS 记录,审计并验证电子邮件身份验证配置。 使用 dnspython 查询 TXT 记录,验证 SPF 语法和查询次数,核查 DKIM 选择器记录, 解析 DMARC 策略,识别可能导致电子邮件欺骗的错误配置。并生成修复建议。
-
killvxk Bundle Performing Web Application Vulnerability Triage使用 OWASP 风险评级方法论对 DAST/SAST 扫描器的 Web 应用程序漏洞发现进行分类,区分真阳性和假阳性,并确定修复优先级。
-
killvxk Bundle Analyzing Threat Actor Ttps With Mitre Navigator使用 ATT&CK Navigator 和 attackcti Python 库将高级持续性威胁(APT)组织的战术、技术和过程(TTP)映射到 MITRE ATT&CK 框架。分析人员查询 STIX/TAXII 数据以获取组织-技术关联,生成 Navigator 层文件进行可视化,并将防御覆盖与对手画像进行对比。
-
killvxk Bundle Performing Threat Emulation With Atomic Red Team使用 atomic-operator Python 框架执行 Atomic Red Team 测试,进行 MITRE ATT&CK 技术验证。 从 YAML 原子测试加载测试定义、运行攻击模拟并验证检测覆盖率。适用于测试 SIEM 检测规则、 验证 EDR 覆盖率或开展紫队演练。
-
killvxk Bundle Performing Threat Intelligence Sharing With Misp使用 PyMISP 在 MISP 平台上创建、丰富和共享威胁情报事件,包括 IOC 管理、情报源集成、STIX 导出及社区共享工作流
-
killvxk Bundle Building Threat Intelligence Enrichment In Splunk使用查询表、模块化输入和威胁情报框架,在 Splunk Enterprise Security 中构建自动化威胁情报富化流水线
-
killvxk Bundle Performing Threat Landscape Assessment For Sector通过分析威胁行为者定向攻击模式、常见攻击向量和行业特定漏洞,开展行业特定威胁态势评估,为组织风险管理提供决策依据
-
killvxk Bundle Testing API For Broken Object Level Authorization测试REST和GraphQL API中的越权对象访问(BOLA/IDOR)漏洞,即已认证用户通过操纵API请求中的对象标识符 来访问或修改属于其他用户的资源。测试人员拦截API调用,识别对象ID参数(数字ID、UUID、slug), 并系统性地替换为其他用户的ID,以确定服务器是否执行了对象级授权。 对应OWASP API安全Top 10 2023 API1(越权对象访问)。
-
killvxk Bundle Implementing Conduit Security For Ot Remote Access按照IEC 62443区域和管道模型实现OT远程访问的安全管道架构,部署跳板服务器、启用MFA的网关、会话录制和基于审批的工作流,在不直接暴露OT网络的情况下控制供应商和工程师对工业控制系统的访问。
-
killvxk Bundle Performing Threat Modeling With Owasp Threat Dragon使用 OWASP Threat Dragon 创建数据流图,运用 STRIDE 和 LINDDUN 方法论识别威胁,并生成威胁模型报告用于安全设计审查。
-
killvxk Bundle Performing Wireless Security Assessment With Kismet使用 Kismet 通过被动射频监控进行无线网络安全评估,检测流氓接入点(Rogue AP)、隐藏 SSID、弱加密和未授权客户端。
-
killvxk Bundle Detecting Broken Object Property Level Authorization检测和测试OWASP API3:2023对象属性级授权失效(BOPLA)漏洞,包括过度数据暴露和批量赋值攻击。
-
killvxk Bundle Implementing Continuous Security Validation With Bas部署违规和攻击模拟(BAS)工具,通过安全模拟整个杀伤链中的真实攻击技术,持续验证安全控制有效性。
-
killvxk Bundle Implementing Security Information Sharing With Stix2使用 stix2 Python 库创建、验证和共享 STIX 2.1 威胁情报对象。涵盖指标、恶意软件、活动、关系、Bundle 和 TAXII 2.1 发布。
-
killvxk Bundle Implementing Threat Intelligence Lifecycle Management实现结构化威胁情报生命周期,涵盖规划、收集、处理、分析、传播和反馈阶段,为组织决策生产可操作情报。
-
killvxk Bundle Implementing Web Application Logging With Modsecurity配置带有 OWASP 核心规则集(CRS)的 ModSecurity WAF,实现 Web 应用程序日志记录, 调整规则以减少误报,分析审计日志进行攻击检测,并为应用程序特定威胁实现自定义 SecRules。 分析师配置 SecRuleEngine、SecAuditEngine 和 CRS 偏执级别,以在安全覆盖范围和运营稳定性之间取得平衡。 适用于涉及 WAF 配置、ModSecurity 规则调整、Web 应用审计日志或 CRS 部署的场景。
-
killvxk Bundle Implementing Iso 27001 Information Security ManagementISO/IEC 27001:2022 是建立、实施、维护和持续改进信息安全管理体系(ISMS)的国际标准。本技能涵盖从范围界定到认证的完整生命周期。
-
killvxk Bundle Implementing Github Advanced Security For Code Scanning配置 GitHub Advanced Security 与 CodeQL,在企业级别对仓库执行自动化静态分析和漏洞检测。
-
sheshiyer Bundle ReconSecurity reconnaissance. USE WHEN recon, reconnaissance, bug bounty, attack surface, infrastructure mapping, subdomain enumeration.
-
sheshiyer Bundle ArcplumeArcplume runs Grok through the Grok Build CLI's own OAuth-authenticated session (grok login) for image generation, with strict preflight validation, secret-safe handling, and headless CLI-driven execution -- no separate XAI_API_KEY billing. Video falls back to the billed xAI API. USE WHEN a user wants to generate an image via a locally logged-in Grok Build CLI session, e.g. 'generate an image with grok', 'use grok build', or 'use my logged-in grok session'.
-
sheshiyer Skill Jvm CoreShared reference for the JVM cluster: the language × framework decision (Kotlin vs Java; Spring Boot vs Quarkus vs Ktor), the build/test/coverage toolchain, the persistence choice (JPA/Hibernate vs Exposed), and the patterns → TDD → security → verification lifecycle. USE WHEN choosing a JVM stack, wiring persistence, or planning the test/security/release loop every JVM spoke shares.
-
jiayaoqijia Bundle Gate Info RiskcheckToken and address risk assessment. Use this skill ONLY when the user's query is exclusively about token/contract/address security with no other analysis dimensions. Trigger phrases: is this token safe, check contract risk, is this address safe, honeypot, rug. If the query ALSO mentions fundamentals, technicals, news, sentiment, or any other analysis dimension, use gate-info-research instead — it handles multi-dimension queries in a single unified report. Address risk mode (is this address safe) is exclusive to this skill and must NOT be routed to gate-info-research.
-
jiayaoqijia Bundle Ctf PwnProvides binary exploitation techniques for CTF challenges. Use when you already have a vulnerable native target or service and need to turn memory corruption or low-level primitives into code execution or privilege escalation, such as buffer overflows, format strings, heap bugs, ROP, ret2libc, shellcode, kernel exploitation, seccomp bypass, sandbox escape, or Windows/Linux exploit chains. Do not use it when the main blocker is understanding what the binary does; use reverse engineering first. Do not use it for pure web bugs, disk or packet forensics, or standalone crypto/math challenges.
-
jiayaoqijia Bundle Aegis Protocol SecurityAegisProtocol
-
jiayaoqijia Bundle Gate Info CoinanalysisSingle-coin comprehensive analysis. Use this skill ONLY when the user asks to analyze one coin with no additional explicit dimension (e.g., no separate risk check, no separate trend-only request). Trigger phrases: analyze SOL, how is BTC, is ETH worth buying. If the query ALSO mentions security/risk, event attribution, multi-coin comparison, or any other analysis dimension beyond single-coin comprehensive, use gate-info-research instead — it handles multi-dimension queries in a single unified report.
-
sheshiyer Bundle SecupdatesSecurity news aggregation from tldrsec, no.security, and other sources. USE WHEN security news, security updates, what's new in security, breaches, security research, sec updates.
-
sheshiyer Bundle AnnualreportsAnnual security report aggregation and analysis. USE WHEN annual reports, security reports, threat reports, industry reports, update reports, analyze reports, vendor reports, threat landscape.
-
sheshiyer Bundle WebassessmentWeb security assessment. USE WHEN web assessment, pentest, security testing, vulnerability scan, threat modeling a web app.
-
sheshiyer Skill Conducty ReviewEnd-of-plan review sweep. Audits the plan's executed prompts, records verdicts with evidence, extracts failure patterns, computes velocity metrics, prepares carry-forward intelligence. Use when the user says "review", "audit", "review this plan", or at the end of a plan before [[conducty-improve]].
-
sheshiyer Bundle Vercel OptimizeObservability-first Vercel optimization audit — pull production metrics, gate investigations deterministically, and emit version-aware cost/perf recommendations. USE WHEN auditing a deployed Vercel app for cost or performance issues.
-
sheshiyer Skill Jvm OrchestratorRoute a JVM task to the right skill among 16 specialists — Kotlin language/coroutines/Exposed/Ktor, Java coding standards, the Spring Boot stack (patterns, TDD, security, verification), the Quarkus stack (patterns, TDD, security, verification), JPA/Hibernate, and Compose Multiplatform UI. USE WHEN a user is building, testing, securing, or shipping a Kotlin or Java service but hasn't named the framework or the specific concern.
-
sheshiyer Skill Electron SecurityThe Electron hardening checklist — context isolation, sandbox, no nodeIntegration, strict CSP, navigation/window.open allowlists, IPC input validation, and safe handling of remote content. USE WHEN auditing or hardening an Electron app, reviewing webPreferences, or before shipping. Follows Electron's official security recommendations.
-
ashfordeou Bundle QualityUse when scoping or preparing AS9100 aerospace quality management work: map an audit focus area to the aerospace clauses (operational risk, configuration management, product safety, counterfeit prevention, external providers, special processes), assemble the minimum audit evidence for each clause, and determine when a corrective action record closes a nonconformance. AS9100 is ISO 9001:2015 plus aerospace-specific requirements, so audits demonstrate the QMS against both. Trigger: AS9100 audit, quality management system, QMS, aerospace clause, audit evidence, counterfeit prevention, corrective action, nonconformance, special processes.
-
ashfordeou Bundle Supplier ControlUse when you must control externally provided processes, products, and services: classify the supplier risk from part criticality and quality and delivery history, derive the required controls (on-site audit, monitoring frequency, delegated verification, flow-down), and check the supplier record for evaluation, approved supplier list, monitoring, re-evaluation, and flow-down completeness before approving the supplier. Produces the risk class, the control set, and the approval verdict that gate purchase release. Trigger: supplier evaluation, approved supplier list, flow down, external provider, supplier monitoring.
-
ashfordeou Bundle Tcas Resolution AdvisoryUse when you must evaluate a TCAS II resolution advisory for an own aircraft against a single intruder from measured range and altitude state: select the sensitivity level from the own altitude band, compute the modified tau closing time with the DMOD term, apply the horizontal threat test and the altitude test against the tau and ALIM thresholds, and choose the climb or descend advisory sense from the intruder position. Produces the sensitivity level, the modified tau, the threat verdict and the resolution advisory sense that gate a TCAS logic assessment. Trigger: TCAS II, traffic alert and collision avoidance, resolution advisory, modified tau, DMOD, sensitivity level, intruder threat logic, climb descend advisory.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include implementing-api-security-testing-with-42crunch, implementing-email-security-with-dmarc-dkim-spf, performing-web-application-vulnerability-triage. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.