Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
ashutoshsrivastava17 Skill Expense ReviewReview and analyze expenses with categorization, trend analysis, anomaly detection, policy compliance checks, and cost reduction recommendations. TRIGGER when: user says /expense-review, "review expenses", "expense analysis", "spending review", "cost analysis", "expense audit".
Audited -
ashutoshsrivastava17 Skill Compliance CheckCheck compliance against regulatory frameworks including GDPR, SOC2, HIPAA, PCI-DSS, and industry-specific requirements. Perform gap analysis and generate a prioritized remediation plan. TRIGGER when: user says /compliance-check, asks to check compliance, audit regulatory requirements, perform a gap analysis, or assess regulatory readiness.
Audited -
ashutoshsrivastava17 Skill Access ReviewReview access control implementation — authentication, authorization, RBAC/ABAC policies, and least-privilege compliance. TRIGGER when: user says /access-review, asks about access control, wants to audit permissions, or needs to review auth implementation.
-
ashutoshsrivastava17 Skill Pen Test PlanPlan penetration testing engagements: scope definition, methodology selection (OWASP, PTES), rules of engagement, testing phases, reporting format, and remediation tracking. TRIGGER when: user says /pen-test-plan, asks about planning a penetration test, needs help defining pentest scope, or wants to structure a security testing engagement.
-
ashutoshsrivastava17 Skill Code ReviewReview code or pull requests for security vulnerabilities, correctness, performance, and style. Provide actionable, categorized feedback. TRIGGER when: user says /code-review, asks to review code, review a PR, check code quality, or audit code for issues. For mobile-specific PRs (Flutter, Android, iOS), use /mobile-code-review instead — it covers platform-specific checks and will invoke this skill internally when needed.
-
ashutoshsrivastava17 Skill Time AuditConduct personal time audits including activity logging, category analysis, time-waste identification, optimization recommendations, and habit design to help individuals reclaim productive hours. TRIGGER when: user says /time-audit, "audit my time", "where does my time go", "time tracking analysis", "I'm always busy but not productive", or "help me find more time".
Audited -
ashutoshsrivastava17 Skill Security ReviewSecurity-focused code review — identify vulnerabilities, insecure patterns, and OWASP Top 10 issues in code changes. TRIGGER when: user says /security-review, asks for a security review of code, wants to check code for vulnerabilities, or needs a secure code audit.
-
ashutoshsrivastava17 Skill Audit PreparationPrepare for financial audits — document checklist, reconciliation review, internal control testing, timeline planning, and auditor communication. TRIGGER when: user says /audit-preparation, needs to prepare for a financial audit, or asks about audit readiness.
Audited -
ashutoshsrivastava17 Skill Compliance AuditConduct security compliance audits: control mapping across frameworks (SOC2, ISO 27001, NIST), evidence collection, gap identification, remediation planning, and audit preparation. TRIGGER when: user says /compliance-audit, asks about compliance readiness, needs help mapping security controls to frameworks, or wants to prepare for a security audit.
Audited -
ashutoshsrivastava17 Skill Cyber RiskAssess cyber risks — threat landscape, vulnerability assessment, asset criticality, attack scenarios, quantitative risk estimation (FAIR), and mitigation. TRIGGER when: user says /cyber-risk or asks about cybersecurity risk assessment.
Audited -
ashutoshsrivastava17 Skill Zero Trust ReviewReview zero trust architecture — identity verification, device trust, network segmentation, least privilege, and continuous validation. TRIGGER when: user says /zero-trust-review or asks about zero trust implementation.
Audited -
ashutoshsrivastava17 Skill Mobile SecurityHarden mobile apps against attacks — certificate pinning, code obfuscation, root/jailbreak detection, biometric auth, secure storage, reverse engineering prevention, and app integrity checks across Flutter, Android (Kotlin/Java), and iOS (Swift/ObjC). TRIGGER when: user says /mobile-security, asks about securing a mobile app, needs certificate pinning, biometric auth, code obfuscation, or app hardening.
-
sethdford Skill Pci Dss ReviewReview PCI-DSS compliance for payment card data security across network, systems, and processes.
-
sethdford Skill Siem Rule DesignDesign SIEM (Security Information & Event Management) detection rules to identify suspicious activity and attacks.
-
sethdford Skill Attack Tree ModelingBuild hierarchical attack trees showing how attackers decompose goals into sub-goals and exploits. Use when analyzing attack paths, prioritizing security investments, or assessing attacker effort and cost.
-
sethdford Skill Gdpr AssessmentAssess GDPR compliance for data processing, rights, privacy controls, and incident response obligations.
-
sethdford Skill Recovery ProceduresEstablish recovery procedures to restore systems, verify integrity, and validate business continuity after incidents.
-
sethdford Skill Secrets ManagementManage API keys, credentials, and secrets securely using vaults, environment variables, and rotation policies. Prevent secrets from being committed to code or exposed in logs.
-
sethdford Skill Session ManagementImplement secure session handling with proper token generation, storage, expiry, CSRF protection, and session invalidation.
-
sethdford Skill Threat IdentificationSystematically identify threats from threat libraries, historical CVEs, and attacker tactics. Use when augmenting STRIDE analysis with known threats from MITRE ATT&CK, CWE, or your industry.
-
sethdford Skill Containment StrategyDevelop containment strategies to isolate compromised systems, prevent lateral movement, and stop ongoing attacks.
-
sethdford Skill Owasp Top Ten CheckAudit application architecture and code against OWASP Top 10 vulnerabilities. Use when assessing application security posture and prioritizing fixes.
-
sethdford Skill Network TopologyDesign VPCs, subnets, security groups, load balancing, and DNS architecture. Plan for segmentation, DDoS protection, and failover. Use when architecting network infrastructure.
-
sethdford Skill Security Test PlanDevelop comprehensive security test plans covering functional security, vulnerability scanning, and attack scenarios.
-
sethdford Skill Audit PreparationPrepare for compliance audits by collecting evidence, organizing documentation, and coordinating with auditors.
-
sethdford Skill Evidence PreservationPreserve evidence during incident response to enable forensic analysis and maintain legal admissibility.
-
sethdford Skill Authorization DesignDesign authorization systems (access control, role-based permissions, principle of least privilege) to enforce fine-grained access policies.
-
sethdford Bundle Secure Coding ReviewReview code systematically for security vulnerabilities using OWASP Top 10, secure coding patterns, and static analysis best practices. Use when reviewing pull requests, conducting security code reviews, or implementing secure development practices.
-
sethdford Skill Security DocumentationDevelop comprehensive security documentation including policies, procedures, architecture, and runbooks.
-
sethdford Skill API Security ReviewReview API security including authentication, authorization, rate limiting, input validation, and data exposure.
-
sethdford Skill Compliance MappingMap security controls to compliance framework requirements (NIST, CIS, ISO 27001, PCI-DSS, HIPAA, GDPR, SOC 2).
-
sethdford Skill Incident CommunicationDevelop incident communication strategies for internal teams, customers, regulators, and media during and after security incidents.
-
sethdford Bundle Incident Response PlanDevelop comprehensive incident response plans with clear roles, procedures, communication protocols, and recovery workflows. Use when establishing IR processes, conducting tabletops, or updating response procedures after incidents.
-
sethdford Skill Authentication DesignDesign secure authentication systems with strong password policies, MFA, secure password reset, and session management.
-
sethdford Skill Security ArchitectureDesign security architecture covering authentication, authorization, data protection, and threat models. Use when building security-critical systems.
-
sethdford Skill Web Security HeadersConfigure security HTTP headers to mitigate XSS, clickjacking, MIME sniffing, and other browser-based attacks.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include expense-review, compliance-check, access-review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.