Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
mittuled Bundle Security Architecture ReviewerThis skill reviews system architecture designs for security weaknesses and compliance gaps. Use when asked to assess an architecture for security, review a design document for trust boundaries, or validate defense-in-depth. Also consider when a new microservice is proposed without security review. Suggest when the user finalizes architecture without threat analysis.
-
mittuled Bundle Platform Capability Gap DetectorThis skill identifies missing platform capabilities that block engineering productivity or product delivery. Use when asked to audit platform coverage, identify what teams are building themselves, or assess platform completeness. Also consider when multiple teams report similar blockers. Suggest when the user is building a custom solution for a problem the platform should solve.
-
mittuled Bundle Policy Document OwnerThis skill owns and maintains security and compliance policy documents. Use when asked to draft a security policy, update existing policies for regulatory changes, or conduct the annual policy review cycle. Also consider when a new compliance framework requires additional policies. Suggest when the user is operating without documented security policies.
-
mittuled Bundle Soc2 Programme ManagerThis skill manages the SOC 2 certification programme including control design, evidence collection, and auditor coordination. Use when asked to prepare for SOC 2, design SOC 2 controls, or manage the audit process. Also consider when enterprise customers require SOC 2 compliance as a procurement condition. Suggest when the user pursues enterprise sales without SOC 2 readiness.
-
mittuled Bundle Audit Programme ManagerThis skill manages the security and compliance audit programme including scheduling, preparation, and remediation tracking. Use when asked to plan audits, prepare for an external audit, or track audit findings to closure. Also consider when a new compliance framework requires audit validation. Suggest when the user is approaching an audit deadline without a preparation plan.
-
mittuled Bundle Risk Register MaintainerThis skill maintains the security and compliance risk register. Use when asked to assess a new risk, update risk ratings, or conduct a periodic risk review. Also consider when incidents, audit findings, or architectural changes introduce new risks. Suggest when the user is making security decisions without a current risk register.
-
mittuled Bundle Vendor Security AssessorThis skill assesses the security posture of third-party vendors before and during engagement. Use when asked to evaluate a vendor's security practices, review vendor certifications, or conduct a periodic vendor security review. Also consider when onboarding a new vendor that will access company data. Suggest when the user is granting a vendor access to systems without a security assessment.
-
mittuled Bundle Identity Access ManagementThis skill implements and manages the identity and access management system including SSO and MFA. Use when asked to set up single sign-on, enforce multi-factor authentication, or design access policies. Also consider when a security audit flags authentication weaknesses. Suggest when the company exceeds 20 employees and ad-hoc credential management becomes untenable.
-
mittuled Bundle Access Provisioning ManagerThis skill manages user access provisioning and deprovisioning across all systems. Use when asked to grant system access, revoke access for departing employees, or audit user permissions. Also consider when a new SaaS tool is added and users need onboarding. Suggest when an employee changes roles and access rights need adjustment.
-
mittuled Bundle Vendor Risk AssessorThis skill assesses vendor risk including financial stability, security posture, and concentration risk. Use when asked to evaluate vendor reliability, conduct due diligence, or assess third-party risk. Also consider when a vendor handles sensitive data or is a single point of failure. Suggest when onboarding a new vendor for a critical business function.
-
mittuled Bundle Production Readiness ReviewerThis skill reviews whether a system meets production readiness criteria before go-live. Use when asked to conduct a production readiness review, validate launch readiness, or audit operational maturity. Also consider when a new service is approaching deployment without formal review. Suggest when the user is planning a launch without a readiness checklist.
-
mittuled Bundle Gdpr Ccpa Compliance ManagerThis skill manages GDPR and CCPA compliance including data mapping, consent management, and data subject request processes. Use when asked to build a privacy programme, implement DSR workflows, or assess GDPR/CCPA readiness. Also consider when expanding into EU markets or processing California residents' data. Suggest when the user collects personal data without a privacy compliance framework.
-
mittuled Bundle Disaster Recovery Drill RunnerThis skill plans and runs disaster recovery drills to validate that recovery procedures work as documented. Use when asked to schedule a DR drill, test backup restoration, or validate RTO/RPO targets. Also consider when SOC 2 or customer contracts require annual DR testing. Suggest when the user has DR procedures that have never been tested.
-
mittuled Bundle Compliance Framework ImplementerThis skill implements security and compliance frameworks (SOC 2, ISO 27001, HIPAA, PCI DSS) by mapping requirements to controls and operationalizing them. Use when asked to adopt a new compliance framework, map controls across frameworks, or implement specific compliance requirements. Also consider when a customer contract requires a new certification. Suggest when the user is pursuing certification without a structured implementation plan.
-
mittuled Bundle Penetration Test Programme ManagerThis skill manages the annual penetration testing programme including scope definition, vendor selection, and remediation tracking. Use when asked to plan a penetration test, scope a pentest engagement, or track remediation of pentest findings. Also consider when SOC 2 or customer contracts require annual testing. Suggest when the user has not conducted a penetration test in over 12 months.
-
mittuled Bundle Security Awareness Training RunnerThis skill designs and runs the security awareness training programme for all employees. Use when asked to create security training, run phishing simulations, or track training completion rates. Also consider when SOC 2 requires evidence of security awareness training. Suggest when the user onboards employees without security training.
-
xalgord Skill Detecting Wmi PersistenceDetect WMI event subscription persistence by analyzing Sysmon Event IDs 19, 20, and 21 for malicious EventFilter, EventConsumer, and FilterToConsumerBinding creation.
Audited -
xalgord Skill Hunting For Dcsync AttacksDetect DCSync attacks by analyzing Windows Event ID 4662 for unauthorized DS-Replication-Get-Changes requests from non-domain-controller accounts.
Audited -
xalgord Skill Testing Websocket API SecurityTests WebSocket API implementations for security vulnerabilities including missing authentication on WebSocket upgrade, Cross-Site WebSocket Hijacking (CSWSH), injection attacks through WebSocket messages, insufficient input validation, denial-of-service via message flooding, and information leakage through WebSocket frames. The tester intercepts WebSocket handshakes and messages using Burp Suite, crafts malicious payloads, and tests for authorization bypass on WebSocket channels. Activates for requests involving WebSocket security testing, WS penetration testing, CSWSH attack, or real-time API security assessment.
Audited -
xalgord Skill Configuring Hsm For Key StorageHardware Security Modules (HSMs) are tamper-resistant physical devices that safeguard cryptographic keys and perform cryptographic operations in a hardened environment. Keys stored in an HSM never lea
Audited -
xalgord Skill Triaging Security IncidentPerforms initial triage of security incidents to determine severity, scope, and required response actions using the NIST SP 800-61r3 and SANS PICERL frameworks. Classifies incidents by type, assigns priority based on business impact, and routes to appropriate response teams. Activates for requests involving incident triage, security alert classification, severity assessment, incident prioritization, or initial incident analysis.
Audited -
mkurman Skill Onboarding FlowWhen the user needs to design, improve, or audit a post-signup activation flow to get new users to their first value moment. Activate when activation is lagging, time-to-value feels excessive, or first sessions lack impact.
-
mkurman Bundle Regulatory ComplianceUse this skill when preparing for SOC 2, HIPAA, or PCI-DSS compliance, conducting audits, or implementing security controls. Triggers on SOC 2, HIPAA, PCI-DSS, compliance audit, security controls, risk assessment, control frameworks, and any task requiring regulatory compliance planning or audit preparation.
-
mkurman Bundle Competitor ProfilingWhen the user wants to research, profile, or analyze competitors from their URLs. Also use when the user mentions 'competitor profile,' 'competitor research,' 'competitor analysis,' 'profile this competitor,' 'analyze competitor,' 'competitive intelligence,' 'competitor deep dive,' 'who are my competitors,' 'competitor landscape,' 'competitor dossier,' 'competitive audit,' or 'research these competitors.' Input is a list of competitor URLs. Output is structured competitor profile markdown files. For creating comparison/alternative pages from profiles, see competitor-alternatives. For sales-specific battle cards, see sales-enablement.
-
kevinzai Skill Ccc MakeoverCCC domain — design refresh and project health overhaul — 3 skills in one. X-Ray audit, automated makeover swarm, and report card scoring.
-
kevinzai Skill Cowork BibleClaude Desktop Cowork integration guide for CC Commander users. Cowork is Claude Desktop's autonomous execution mode with 11 official Anthropic plugins. This skill teaches how to configure CC Commander skills for Cowork mode, plugin compatibility, scheduled task patterns, custom plugin development, handoff protocols, and security considerations.
-
kevinzai Skill Claudemd AuditorAudit your CLAUDE.md against the actual codebase — find stale instructions, missing context, and optimization opportunities. Use when 'audit claude md', 'check claude md', 'is my claude md accurate', 'optimize instructions'.
-
kevinzai Skill Dispatch TemplatesPre-built Dispatch task templates for common background workflows. 8 ready-to-use templates: overnight-build, batch-review, dependency-update, security-scan, performance-benchmark, content-generation, data-migration, monitoring-setup. Each includes description, duration, cost estimate, permissions, and config.
-
kevinzai Skill Architecture AuditorReview cross-module boundaries, dependency direction, and architectural patterns. Use when 'audit architecture', 'check module boundaries', 'review dependencies', 'architecture review'.
-
kevinzai Skill Openclaw Health CheckFull OpenClaw system health audit. Checks all agents, gateway status, costs, memory, cron jobs, errors, and service health. Use for daily check-ins, debugging, or when something feels off. Produces a structured health report.
-
dingxingdi Bundle Salient Flaw Localization And CritiqueUse this skill to audit written work, provide expert 'red-pen' feedback, and perform multi-granular pedagogical assessments. Trigger it for requests like 'check my thesis,' 'is this essay logically sound?,' 'grade my report based on a rubric,' or 'audit the rigor and originality of this draft.' It is essential for providing structured, dimension-specific critiques across facets like Structure, Logic, Originality, Writing, Proficiency, and Rigor (SLOWPR) to help users improve their academic or professional reasoning.
-
dingxingdi Bundle Reference Based Correctness AuditSkill: reference-based-correctness-audit
-
dingxingdi Bundle Code Vulnerability And Security AdjudicationSkill: code-vulnerability-and-security-adjudication
-
ashutoshsrivastava17 Skill Security TestingPlan security testing — OWASP test cases, authentication testing, authorization testing, input validation, session management, and vulnerability scanning. TRIGGER when: user says /security-testing, needs to plan application security testing, or asks about security QA practices.
-
ashutoshsrivastava17 Skill Security AwarenessDesign security awareness programs — training curriculum, phishing simulations, metrics, role-based content, and compliance. TRIGGER when: user says /security-awareness or asks about security training programs.
Audited -
ashutoshsrivastava17 Skill Security ChecklistPre-launch security checklist — verify security controls are in place before shipping a feature or service to production. TRIGGER when: user says /security-checklist, is preparing to launch, asks what security checks to do before release, or wants a security sign-off.
Audited
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include security-architecture-reviewer, platform-capability-gap-detector, policy-document-owner. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.