Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
sethdford Skill Data ClassificationClassify organizational data by sensitivity level and define handling, storage, and access requirements.
-
sethdford Skill Forensic Analysis GuideConduct forensic analysis to determine attack vectors, scope of compromise, and evidence for legal proceedings.
-
sethdford Skill Cryptography SelectionSelect appropriate cryptographic algorithms and parameters for encryption, hashing, key derivation, and digital signatures.
-
sethdford Skill Detection EngineeringBuild detection engineering capabilities including threat modeling, detection hypothesis development, and hypothesis testing.
-
sethdford Skill Log Analysis SecurityAnalyze logs to investigate security incidents, identify attack patterns, and build detection rules.
-
sethdford Skill Dockerfile Best PracticesDockerfile best practices, layer optimization, multi-stage builds, security, and image size reduction.
-
sethdford Skill Security Champion ProgramEstablish security champion program to embed security expertise across teams and improve security culture.
-
sethdford Skill Data Flow Diagram SecurityCreate and analyze DFDs (Data Flow Diagrams) with security focus, identifying data flows across trust boundaries, storage, and processing points. Use when modeling system architecture for threat analysis.
-
sethdford Skill Security PracticesEstablish security practices that protect systems and data without paralyzing development. Use when scaling security or responding to threats.
-
sethdford Skill Penetration Test ScopeDefine penetration test scope, objectives, and constraints to align testing with business goals and compliance requirements.
-
sethdford Skill Secure Architecture ReviewReview system architecture and design for security flaws, compliance gaps, and architectural improvements.
-
sethdford Skill Security Metrics DashboardCreate security metrics dashboards to track program effectiveness, trends, and KPIs for leadership reporting.
-
sethdford Skill Data Integrity PatternsConstraints, triggers, audit trails, referential integrity, and data validation.
-
sethdford Skill Network SegmentationDesign and implement network segmentation to limit lateral movement and contain breaches.
-
sethdford Skill Input Validation PatternsDesign and implement input validation patterns (whitelisting, boundary checks, type validation) to prevent injection and buffer overflow attacks.
-
sethdford Skill Security Awareness TrainingDevelop and deliver security awareness training to build organizational security culture and reduce human risk.
-
sethdford Skill Security Policy TemplateDevelop organization-wide security policies covering access control, data handling, incident response, and vendor management.
-
sethdford Skill Root Cause Analysis SecurityConduct root-cause analysis (RCA) to identify underlying causes of security incidents and prevent recurrence.
-
sethdford Skill Certificate ManagementManage digital certificates for HTTPS, mutual TLS, code signing, and infrastructure security.
-
sethdford Skill Privacy Impact AssessmentConduct Privacy Impact Assessments (PIA) to evaluate privacy risks and compliance for data processing activities.
-
sethdford Skill Zero Trust ArchitectureDesign and implement zero-trust architecture to authenticate and authorize all access, eliminating trust based on location.
-
ashutoshsrivastava17 Skill Security Architecture ReviewReview system architecture for security — authentication flows, data encryption, network segmentation, trust boundaries, and threat surface analysis. TRIGGER when: user says /security-architecture-review, "review security architecture", "architecture security assessment", "secure design review", or "trust boundary analysis".
-
ashutoshsrivastava17 Skill Asset ManagementManage IT assets across their full lifecycle: inventory tracking, lifecycle management, license compliance, disposal procedures, and cost allocation for complete asset visibility and control. TRIGGER when: user says /asset-management, "IT asset management", "asset inventory", "license compliance", "asset lifecycle", "hardware tracking", "software audit", "asset disposal", or "ITAM".
Audited -
ashutoshsrivastava17 Skill Workflow Automation ReviewReview automated workflows for reliability, error handling, monitoring gaps, and optimization opportunities. Assess automation maturity and recommend improvements. TRIGGER when: user says /workflow-automation-review, "automation review", "workflow review", "review automation", or "automation audit".
Audited -
ur-grue Bundle Source ProtectionProduces a structured source-protection assessment for a specific source in a specific story, covering risk level, communication security guidance, legal protections available, editorial handling recommendations, and a pre-publication checklist.
-
vril-labs Skill Container ScannerScan container images for vulnerabilities — Trivy, Clair, or Snyk integration. Use when securing containers, implementing CI security, or auditing image vulnerabilities.
-
vril-labs Skill CurateEvolve the Spellbook library. Scan external sources for new skills worth indexing, review observations for improvement opportunities, brainstorm new primitives, investigate existing skills for consolidation or deletion, research power user patterns and best practices. Use when: "curate", "evolve spellbook", "what should we build", "find new skills", "audit the library", "consolidate skills", "what's new in the ecosystem", "spellbook maintenance", "improve primitives".
-
vril-labs Skill Service Mesh ConfiguratorConfigure service mesh (Istio, Linkerd) for microservices — traffic management, security, and observability. Use when implementing service-to-service communication, mTLS, traffic splitting, or advanced networking.
-
vril-labs Bundle Xss PreventionXSS Prevention
-
kernel8901 Bundle Lighthouse FixerRun Lighthouse audit and get AI fix suggestions. Use when improving performance.
-
thedaviddias Bundle Dependency AuditUse when reviewing a project's security posture, setting up CI pipelines, or responding to a reported vulnerability in a dependency.
-
thedaviddias Bundle Permissions PolicyUse when reviewing HTTP response headers for defense-in-depth security hardening on any web application.
-
thedaviddias Bundle Stack Trace ExposureUse when reviewing error handling middleware, API route handlers, or server responses for security-sensitive information disclosure.
-
thedaviddias Bundle Cross Origin SecurityUse when reviewing scripts, client components, bundles, or runtime behavior related to Handle cross-origin requests securely. Inspect both source code and the browser execution path so fixes target the real bottleneck or bug.
-
thedaviddias Bundle Cross Origin IsolationUse when reviewing security-sensitive web apps, SharedArrayBuffer usage, worker-heavy apps, editors, or measurement features that require cross-origin isolation. Check both headers and real browser behavior.
-
thedaviddias Bundle Token Storage SecurityUse when reviewing authentication implementation, setting up a new auth system, or evaluating whether the current token storage approach exposes the application to XSS-based token theft.
Audited
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include data-classification, forensic-analysis-guide, cryptography-selection. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.