Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
ultroncore Bundle Find BugsFind bugs, security vulnerabilities, and code quality issues in local branch changes. Use when asked to review changes, find bugs, security review, or audit code on the current branch.
-
ultroncore Bundle Information Security Manager Iso27001ISO 27001 ISMS implementation and cybersecurity governance for HealthTech and MedTech companies. Use for ISMS design, security risk assessment, control implementation, ISO 27001 certification, security audits, incident response, and compliance verification. Covers ISO 27001, ISO 27002, healthcare security, and medical device cybersecurity.
-
nahisaho Bundle Co Compliance Audit ResponseDrafts audit-ready responses with traceable control evidence references. Use when PREPARING audit response packages, drafting responses to auditor inquiries, assembling evidence packages, or creating audit-ready documentation.
-
nahisaho Skill Co Compliance Learning CaptureCompliance learning capture and knowledge persistence. Records audit insights, control mapping patterns, and regulatory interpretation lessons. Use when FINISHING a compliance engagement, discovering a control mapping pitfall, or recording lessons for future compliance work.
-
nahisaho Skill Co Compliance Evidence CollectorDefines evidence requirements, collection cadences, and readiness tracking. Use when PLANNING evidence collection, defining evidence sets per control, setting collection schedules, or assessing evidence readiness for audit.
-
ultroncore Bundle Ffuf Web Fuzzingffuf Web Fuzzing
-
ultroncore Bundle Mutation TestingConfigure and run mutation testing to evaluate test suite quality, revealing gaps in coverage and security-critical logic verification.
-
ultroncore Bundle Security ScannerRoute security scanning tasks to the right tool — containers, secrets, SAST, SBOM, web apps
-
ultroncore Bundle Soc2 ComplianceUse when the user asks to prepare for SOC 2 audits, map Trust Service Criteria, build control matrices, collect audit evidence, perform gap analysis, or assess SOC 2 Type I vs Type II readiness.
-
ultroncore Bundle C Security ReviewC/C++ Security Review
-
ultroncore Bundle Claude Md ImproverAudit and improve CLAUDE.md files in repositories. Use when user asks to check, audit, update, improve, or fix CLAUDE.md files. Scans for all CLAUDE.md files, evaluates quality against templates, outputs quality report, then makes targeted updates. Also use when the user mentions "CLAUDE.md maintenance" or "project memory optimization".
-
ultroncore Bundle Gha Security ReviewGitHub Actions security review for workflow exploitation vulnerabilities. Use when asked to "review GitHub Actions", "audit workflows", "check CI security", "GHA security", "workflow security review", or review .github/workflows/ for pwn requests, expression injection, credential theft, and supply chain attacks. Exploitation-focused with concrete PoC scenarios.
-
ultroncore Bundle Yara Rule AuthoringDevelop YARA rules for malware detection, threat hunting, and file classification across malware families and attack tools.
-
ultroncore Bundle Semgrep Rule CreatorCreate custom Semgrep rules to detect project-specific vulnerability patterns and enforce security policies.
Audited -
ultroncore Bundle Static Code AnalysisMulti-tool static analysis combining CodeQL, Semgrep, and other SAST tools to find security vulnerabilities across polyglot codebases.
-
ultroncore Skill End To End EncryptionImplement end-to-end encryption (E2EE) for web and mobile applications using libsodium, Web Crypto API, and Signal Protocol patterns. Covers key exchange, symmetric encryption, digital signatures, sealed boxes, and key management without server-side key access.
-
ultroncore Skill Zero Knowledge ProofsImplement zero-knowledge proofs for privacy-preserving authentication, credential verification, and computation. Covers ZK-SNARKs with circom/snarkjs, Groth16 and PLONK proof systems, Merkle tree membership proofs, and ZK applications in Node.js and Rust.
-
ultroncore Bundle Claude Settings AuditAnalyze a repository to generate recommended Claude Code settings.json permissions. Use when setting up a new project, auditing existing settings, or determining which read-only bash commands to allow. Detects tech stack, build tools, and monorepo structure.
-
ultroncore Bundle Security Pen TestingUse when the user asks to perform security audits, penetration testing, vulnerability scanning, OWASP Top 10 checks, or offensive security assessments. Covers static analysis, dependency scanning, secret detection, API security testing, and pen test report generation.
-
ultroncore Bundle Insecure Defaults FinderSystematically identify weak configurations, hardcoded secrets, insecure defaults, and misconfigured security controls across a codebase.
-
ultroncore Bundle Skill Reviewer And EnhancerThis skill should be used when reviewing, auditing, or improving existing Claude Code skills to ensure they follow Anthropic best practices, have proper structure, use current domain-specific patterns, and include all necessary resources. It analyzes skill quality, identifies gaps, suggests improvements, and can automatically enhance skills with updated best practices. Trigger terms include review skill, audit skill, improve skill, enhance skill, update skill, check skill quality, skill best practices, fix skill, optimize skill, validate skill structure.
-
ultroncore Bundle Supply Chain Risk AuditorSupply Chain Risk Auditor
-
ultroncore Bundle Swiftui Performance AuditAudit and improve SwiftUI runtime performance from code review and architecture. Use for requests to diagnose slow rendering, janky scrolling, high CPU/memory usage, excessive view updates, or layout thrash in SwiftUI apps, and to provide guidance for user-run Instruments profiling when code review alone is insufficient.
-
npbuilds Skill Recommendation BriefAssembles the final EMPTOR BRIEF for a purchase decision and runs its pre-flight audit: ranked pick with confidence-and-because clauses, trade-off map, evaluation matrix, sensitivity, forensics flags, trust-checked merchants, freshness stamps, and the feedback footer. Use during emptor's brief phase after evaluation completes, or standalone to re-render an existing evaluation into the brief contract. Rejects and regenerates rather than delivering an unauditable brief.
-
npbuilds Bundle Infrastructure OrchestratorOrchestrate skill library management across the full lifecycle. Use when the user wants to create a new skill, audit the library, build a domain from scratch, run diagnostics, export skills, or perform any multi-step operation that involves coordinating multiple infrastructure tools — scaffold, registry, health, test, analyze, network, dashboard, export, or fork.
-
npbuilds Bundle Ip ValuationIP valuation frameworks for biotech assets including cost approach, market approach (comparable royalty rates), and income approach (relief-from-royalty). Covers royalty rate benchmarks by patent type, IP contribution analysis, trade secret valuation, and regulatory exclusivity value quantification. Activate when translating patent strength into financial value or modeling the impact of IP on asset economics.
-
npbuilds Skill Energy SecurityEnergy markets, transition dynamics, and resource security for investment analysis. Reference when evaluating oil and gas markets, renewable energy economics, nuclear renaissance, critical minerals, grid infrastructure, and ESG investing. Use when energy supply, demand, or policy shapes asset values.
-
ffsshhttiikk Skill Cryptography SecurityCryptographic security implementation
Audited -
ffsshhttiikk Skill Security ArchitectureSecurity system design principles
Audited -
ffsshhttiikk Skill Zero Trust ArchitectureImplementing zero trust security models that verify every request regardless of network location
-
ffsshhttiikk Skill Vulnerability AssessmentFinding and assessing security vulnerabilities
Audited -
ffsshhttiikk Skill API SecuritySecuring REST, GraphQL, and gRPC APIs against abuse, injection, broken authentication, and data exposure
-
ffsshhttiikk Skill Threat ModelingSystematic identification and prioritization of security threats to design effective countermeasures
-
ffsshhttiikk Skill Audit And ComplianceSecurity audit logging, compliance frameworks, and evidence collection for regulatory requirements
-
ffsshhttiikk Skill Security TestingTechniques and tools for testing application and infrastructure security including penetration testing, fuzzing, and vulnerability assessment
-
ffsshhttiikk Skill Container SecuritySecuring container images, runtimes, and orchestration platforms against vulnerabilities and misconfigurations
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include find-bugs, information-security-manager-iso27001, co-compliance-audit-response. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.