Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
xalgord Skill Implementing Threat Intelligence Lifecycle ManagementImplement a structured threat intelligence lifecycle encompassing planning, collection, processing, analysis, dissemination, and feedback stages to produce actionable intelligence for organizational decision-making.
Audited -
xalgord Skill Implementing Iso 27001 Information Security ManagementISO/IEC 27001:2022 is the international standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). This skill covers the complete
Audited -
xalgord Skill Implementing Container Image Minimal Base With DistrolessReduce container attack surface by building application images on Google distroless base images that contain only the application runtime with no shell, package manager, or unnecessary OS utilities.
Audited -
xalgord Skill Implementing Hardware Security Key AuthenticationImplements FIDO2/WebAuthn hardware security key authentication including registration ceremonies, authentication flows, YubiKey enrollment, and passkey migration strategies. Builds a complete relying party server using the python-fido2 library that supports cross-platform authenticators, resident key (discoverable credential) workflows, and user verification policies. Activates for requests involving FIDO2 implementation, WebAuthn registration, hardware security key enrollment, YubiKey integration, or passkey migration from password-based authentication.
Audited -
xalgord Skill Implementing Passwordless Auth With Microsoft EntraImplements passwordless authentication using Microsoft Entra ID with FIDO2 security keys, Windows Hello for Business, Microsoft Authenticator passkeys, and certificate-based authentication to eliminate password-based attacks. Activates for requests involving passwordless deployment, FIDO2 passkey configuration, phishing-resistant MFA, or Microsoft Entra authentication method policies.
Audited -
xalgord Skill Implementing Web Application Logging With ModsecurityConfigure ModSecurity WAF with OWASP Core Rule Set (CRS) for web application logging, tune rules to reduce false positives, analyze audit logs for attack detection, and implement custom SecRules for application-specific threats. The analyst configures SecRuleEngine, SecAuditEngine, and CRS paranoia levels to balance security coverage with operational stability. Activates for requests involving WAF configuration, ModSecurity rule tuning, web application audit logging, or CRS deployment.
Audited -
xalgord Skill Implementing Epss Score For Vulnerability PrioritizationIntegrate FIRST's Exploit Prediction Scoring System (EPSS) API to prioritize vulnerability remediation based on real-world exploitation probability within 30 days.
Audited -
codyswanngt Bundle Lisa DoctorAudit whether the current repository is ready to use Lisa. Runs grouped read-only checks across project detection, Lisa config, runtime distribution surfaces, tracker/source preflight access, automation prerequisites, optional GitHub Project coordination, and optional wiki delegation, then reports PASS/WARN/FAIL/SKIP results plus an overall readiness verdict (`READY`, `READY_WITH_WARNINGS`, or `NOT_READY`).
-
codyswanngt Bundle Lisa Security ReviewSecurity review methodology. STRIDE threat modeling, OWASP Top 10 vulnerability checks, auth/validation/secrets handling review, and mitigation recommendations.
-
npbuilds Bundle Skill HealthRun health checks on skills to detect issues: oversized SKILL.md, poor trigger descriptions, missing progressive disclosure, excessive token usage, trigger conflicts between skills, or structural problems. Use when the user wants to audit skills, check health, optimize token efficiency, or find problems in their skill collection.
-
npbuilds Bundle Vault ReaderRead structured artifacts from an Obsidian vault following the vault's CLAUDE.md frontmatter schema. Supports four operations: slug lookup, frontmatter filter (with `where` predicates validated against the schema), 1-hop wikilink graph, and substring/regex text search. Strictly read-only — never writes to the vault, never creates cache files. Returns a retrieval report with matches, schema validation status, and filter audit trail. Use when a calling skill needs to check "does this vault already have an answer / claim / context for X?" before doing expensive external work. Schema-strict and fail-closed — invalid queries are rejected rather than returning misleading results.
-
npbuilds Bundle Kahneman FramingReference framing effects, attribute substitution (replacing a hard question with an easier one), Einstellung effect (functional fixedness in problem-solving), and Type III errors (right answer to wrong question). Use when binding-vow's audit subdomain checks for cognitive failure modes in problem statements, or when diagnosing why a formulation feels off.
-
npbuilds Bundle Statement GraderScore a problem statement on six axes — specificity, falsifiability, scope, audience-fit, answerability, root-vs-symptom — using calibrated 1-5 rubrics. Use as the keystone audit step in binding-vow's six-eyes orchestrator, or directly when checking whether a problem statement is good enough to act on. Returns per-axis scores plus reformulation hints; any axis below 3/5 triggers the re-state loop.
-
npbuilds Bundle Faction DesignDesign factions with internal structure, competing interests, and dynamic relationships. Reference when creating political entities, organizations, secret societies, or any group that acts with purpose in the world. Covers the pyramid technique, SUPREME method, fractal organizational modeling, and a "no clean side" case-study library.
-
npbuilds Bundle Answerability TesterTest whether a problem statement is answerable in principle: could any evidence resolve it? Coordinates with philosophy/epistemology/evidence-evaluator to assess what evidence type would resolve the question and whether such evidence exists or is accessible. Use in binding-vow's Phase 6 audit. Returns answerable/unanswerable status, the evidence pathway, or flags the statement as values-disguised-as-fact.
-
npbuilds Bundle Falsifiability CheckerTest whether a problem statement (treated as a claim) is falsifiable in Popperian terms: what observation would prove it wrong? Thin coordinator over philosophy/philosophy-of-science/demarcation-judge that translates problem-statement framing into the claim-shaped input demarcation-judge expects. Use in binding-vow's Phase 6 audit, especially for statements containing implicit predictions or causal claims.
-
npbuilds Bundle Worldbuilding CriticJudge whether an invented system — a magic system, an economy, a society, a technology — is actually SOUND, not merely internally consistent. Use after the consistency audit passes, when a world-bible needs a quality verdict, when designing or stress-testing a fantasy/SF system, or when the user asks "does this magic system / faction structure hold up?" Emits a diagnosis of the offending axioms and un-propagated consequences, never a score.
-
ulpi-io Skill Popup GeneratorWhen the user wants to add, optimize, or audit popups or modals for lead capture or offers. Also use when the user mentions "popup," "modal," "lightbox," "overlay," "exit-intent," "popup form," "modal design," "lead popup," "popup timing," or "popup triggers."
-
ulpi-io Bundle Security AuditorSecurity vulnerability expert covering OWASP Top 10 and common security issues. Use when conducting security audits or reviewing code for vulnerabilities.
-
ulpi-io Skill Backlink AnalysisWhen the user wants to analyze backlinks, audit link profile, or identify link issues. Also use when the user mentions "backlink analysis," "backlink audit," "referring domains," "toxic links," "link profile," or "disavow file."
-
ulpi-io Skill Sidebar GeneratorWhen the user wants to design, optimize, or audit a sidebar for blogs, docs, or content pages. Also use when the user mentions "sidebar," "blog sidebar," "content sidebar," "side panel," "sidebar navigation," "related content," "sidebar CTA," "doc sidebar," or "sidebar widgets."
-
ulpi-io Skill Security EngineerExpert in infrastructure security, DevSecOps pipelines, and zero-trust architecture design.
-
ulpi-io Bundle Technical AdvisoryExpert technical advisor with deep reasoning for architecture decisions, code analysis, and engineering guidance. Masters complex tradeoffs, system design, security architecture, performance optimization, and engineering best practices. Use when making critical architecture decisions, after implementing significant work, when debugging complex issues, encountering unfamiliar patterns, facing security/performance concerns, or evaluating multi-system tradeoffs. Provides comprehensive analysis with clear recommendations and rationale.
-
ulpi-io Bundle Express ProductionProduction-ready Express.js development covering middleware architecture, error handling, security hardening, testing strategies, and deployment patterns
-
ulpi-io Skill About Page GeneratorWhen the user wants to create, optimize, or audit About page content. Also use when the user mentions "about page," "about us," "company story," "our team," "about section," "company overview," "brand story," "team page," or "who we are."
-
ulpi-io Skill Tools Page GeneratorWhen the user wants to create, optimize, or audit free tools pages. Also use when the user mentions "free tools," "tools page," "toolkit," "free [X] tool," "free [X] calculator," "free [X] checker," "lead magnet tool," "programmatic tools," or "tools hub."
-
ulpi-io Skill Top Banner GeneratorWhen the user wants to add, optimize, or audit a top announcement bar or sticky banner. Also use when the user mentions "announcement bar," "top banner," "sticky bar," "promo banner," "discount banner," "student discount banner," "header banner," "announcement bar design," "sticky header," "promo bar," "urgency banner," or "lead capture bar."
-
ulpi-io Skill Alicloud Security Kms TestMinimal smoke test for KMS skill. Validate auth and read-only key listing path.
-
ulpi-io Skill Contact Page GeneratorWhen the user wants to create, optimize, or audit contact page and forms. Also use when the user mentions "contact page," "contact form," "get in touch," "support form," "contact us," "reach us," "contact information," "support contact," or "inquiry form."
-
ulpi-io Skill Social Share GeneratorWhen the user wants to add, optimize, or audit social share buttons (share article to X, LinkedIn, Facebook, etc.). Also use when the user mentions "share buttons," "social share," "share to X," "share to LinkedIn," "social sharing," "share icons," "share widget," "native share," "Web Share API," or "share intent URLs."
-
ulpi-io Skill Trust Badges GeneratorWhen the user wants to add or optimize trust badges, "Trusted by" logos, security seals, or social proof elements. Also use when the user mentions "trust badges," "trusted by," "security badges," "payment logos," "social proof," "trust seals," "SSL badge," "customer logos," "as seen in," or "trust signals."
-
ulpi-io Bundle AI Tool ComplianceAutomation skill for designing, verifying, and improving auth, cost, logging, and security compliance based on the internal AI tool mandatory implementation guide (P0/P1). Supports the full lifecycle of RBAC design, Gateway principles, Firestore policy, behavior logs, cost transparency, and the criteria verification system.
-
ulpi-io Bundle Database AdministratorSenior Database Administrator with expertise in PostgreSQL, MySQL, MongoDB, and enterprise database systems. Specializes in high availability architectures, performance tuning, backup strategies, and database security for production environments.
-
ulpi-io Bundle Vercel Security AccessVercel security and access controls including RBAC, SSO, deployment protection, firewall, bot defense, audit logs, and 2FA. Use when securing Vercel projects or managing access.
-
agents-store Skill ConformanceThis skill should be used when the user asks to "check the implementation against the documents", "audit the platform", "does the code do what the spec says", "test the whole stack against the requirements", "conformance review", "what is actually built", or runs /macstack-dev:check --code. Produces a dated audit pair — a technical conformance review and its business-language twin — with one verdict per case id.
-
agents-store Bundle Codemap ReviewThis skill should be used when the user asks to "review code", "check this file", "what's wrong with this code", "review my PR", "code quality check", "find issues in this code", or wants feedback on readability, style, security, or common beginner mistakes. Provides structured review with "why" explanations, not just "what" fixes. Also triggers when a developer asks "is this code okay", "what can I improve", or "check my work".
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include implementing-threat-intelligence-lifecycle-management, implementing-iso-27001-information-security-management, implementing-container-image-minimal-base-with-distroless. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.