Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
wyre-ai Skill Proofpoint Essentials User ManagementProofpoint Essentials mailbox user management within a customer org: list, get, create (including batch create), update, and delete mailbox-protected users.
-
fabioc-aloha Skill Act PassRun the 7-step Artificial Critical Thinking pass — Materiality → Hypothesise → Alternatives → Disconfirmers → Audit priors → Severity → Commit-with-marker
-
fabioc-aloha Skill Currency AuditComprehensive brain file review — external freshness, internal consistency, semantic accuracy — stamp only after full assessment
-
fabioc-aloha Skill Memory CurationMonitor, audit, and curate VS Code user memory (/memories/) for token efficiency, scope correctness, and value density
-
fabioc-aloha Skill Security ReviewDefend before attackers find the gaps - OWASP, STRIDE, and Microsoft SFI
-
s3yed Skill Fleet Self ReviewDaily fleet self-review — audit the Appie fleet for safety, errors/fabrications, and improvement opportunities; propose fixes and author custom skills capturing the learning. Read-only on systems; only writes reports + skills. Use when running the daily self-review routine (cron) or on demand.
-
s3yed Skill Security ScanningDesign, build, and maintain automated daily security scans for a multi-machine CTO fleet. Covers scan architecture, macOS-specific scripting quirks, SSL cert checking, supply-chain auditing, and CVE monitoring.
-
s3yed Skill Client Bot SecurityFull-spectrum security audit for client Telegram bots across a multi-gateway fleet (Hermes + OpenClaw). Covers bot inventory & topology mapping, token provisioning security, SSH key hygiene, authorized_keys audit, secrets map documentation, and bot lifecycle management (free→assigned→active→retired).
-
s3yed Skill Creator Brand IntelligenceResearch, audit, and build outreach for brand partnership opportunities. Covers auditing an existing brand portfolio for category gaps, identifying new brand categories that align with the creator's niche, finding specific brands that do recurring paid deals, researching contact methods (emails, forms, ambassador programs, affiliate networks), and prioritizing into a ranked outreach list. Use when the user asks about brand deals, sponsorships, partnerships, collabs, missing brand categories, or outreach lists.
-
s3yed Skill Productized Service BusinessValidate, launch, and deliver productized service businesses, service-first SaaS wedges, managed marketplaces, and audit/retainer offers. Use when the user asks which business idea is worth doing, wants competitor or Dutch/NL market validation, wants a monetization ladder, wants to validate a service before building software, or wants delivery SOPs/templates for a first paid client offer such as Review-to-Revenue / Customer Voice Conversion Audits.
-
dojogenesis Skill Audit Context BuildingDeep Context Builder Skill (Ultra-Granular Pure Context Mode)
-
dojogenesis Skill Community Claude Md GuardianAudits CLAUDE.md files for conflicts, stale rules, missing sections, and cross-file coherence. Produces a health report with auto-fix suggestions — audit only, no enforcement mechanism. Full version (adds a PreToolUse hook to enforce the ruleset going forward): `system-health:claude-md-guardian`. Use when: 'check claude.md', 'audit CLAUDE.md', 'fix claude.md', 'claude md health'.
-
dojogenesis Skill Release SpecificationProduces a production-ready release specification document (Full or Lean format) including current-state audit, technical architecture with code examples, implementation plan, and risk assessment. Use when 'write a release spec', 'create a release specification for vX.X.X', or 'ground this spec in the codebase'.
-
dojogenesis Skill Codebase Audit GroundingProduces a quantified current-state report (test count, aria markers, error boundaries, storage usage, dependencies) used to anchor specifications in measured reality rather than assumptions. Use when: 'audit the codebase before speccing', 'ground this spec in reality', 'what does the code actually look like', 'measure before I write the spec'.
-
wasabeef Skill Multi RoleParallel analysis with multiple roles and integrated report. Trigger with "analyze from multiple perspectives", "multi-role analysis", "check both security and performance".
-
dojogenesis Skill SemgrepSemgrep Security Scan
-
dojogenesis Skill Health AuditHealth Audit Skill
-
wyre-ai Bundle Datto Rmm AuditDatto RMM audit data structure covering hardware inventory (CPU, RAM, disks, motherboard, BIOS), software inventory, network interfaces, and ESXi/printer audits, along with audit collection cadence and data freshness semantics.
-
wyre-ai Skill Msp TerminologyMSP industry terminology: acronyms, roles, contract and billing concepts, and the vocabulary used across PSA, RMM, documentation, and security platforms.
-
wyre-ai Skill Rocketcyber AppsRocketCyber application inventory: detecting, categorizing, and monitoring applications across managed endpoints, including approved-vs-unapproved software, app-level threat detection, and software compliance reporting.
-
wyre-ai Skill Bec ResponseBusiness Email Compromise detection and first response: the signals that reveal it in CIPP/M365 audit logs, mailbox and forwarding rules, and connected email security vendor alerts; the order-dependent response sequence (session revocation, forwarding-rule audit, mailbox rule and delegate cleanup, password reset, MFA re-enrollment, lateral-spread check, recipient notification); and what a defensible incident timeline must capture for insurance or bank-fraud claims.
-
wyre-ai Skill Huntress BillingHuntress billing and summary reports: what each report type contains, the list/get tools for both, and the monthly reconciliation, QBR security summary, and cost-analysis workflows an MSP builds from them.
-
wyre-ai Skill Huntress SignalsHuntress security signals: how signals differ from incidents, the signal types, listing and filtering by organization, and the threat-hunting and pattern-analysis workflows built on signal data.
-
wyre-ai Skill Blumira ResolutionsBlumira resolution types (Valid, Not Applicable, False Positive): how to choose between them, their effect on security metrics and detection tuning, and the org- and MSP-level resolve calls.
-
wyre-ai Skill Rocketcyber AccountsRocketCyber's provider/customer account hierarchy: sub-account navigation, account CRUD operations, account settings, security policy configuration, and multi-tenant MSP patterns.
-
wyre-ai Bundle Superops AssetsSuperOps.ai RMM asset inventory: asset status and platform enums, hardware, network, OS and association fields, software inventory, disk usage, patch status, activity history, and the GraphQL queries and script-execution mutations behind them. Includes health-check, patch-compliance, and software-audit workflows plus remote-action readiness checks.
-
wyre-ai Skill Knowbe4 UsersKnowBe4 user and group management: user lifecycle and status, group creation and membership, risk scores and risk score history, user event tracking, provisioning, and group-based targeting for campaigns.
-
wyre-ai Skill Rocketcyber IncidentsRocketCyber security incident lifecycle: severity levels, verdicts (Malicious/Suspicious/Benign), status transitions, SOC analyst triage patterns, and cross-vendor PSA ticket correlation.
-
wyre-ai Bundle Liongard DetectionsLiongard's change and anomaly detection layer: detections generated by inspection-to-inspection comparison, detection types/severities/status lifecycle, configurable alert rules and notification channels, custom metrics with JMESPath expressions and threshold evaluation, and the platform timeline audit trail.
-
wyre-ai Skill Ninjaone AlertsNinjaOne alerts and the conditions behind them: retrieving device alerts, dismissing individual alerts and bulk resets, alert summaries, severity and priority levels, common hardware/service/security/connectivity alert types and thresholds, alert webhooks, and triage workflows.
-
wyre-ai Skill Inforcer Audit EventsInforcer's read-only record of changes and activity: searching and filtering auditEvents by type and date window (the search is account-wide — there is no tenant filter), enumerating the event-type catalog to build valid filters, and the continuationToken paging audit searches require.
-
wyre-ai Skill Abnormal Security CasesAbnormal Security abuse mailbox cases: user-reported email submissions, case statuses and judgments, the case lifecycle, bulk and remediation actions, and phishing simulation handling.
-
wyre-ai Skill Knowbe4 ReportingKnowBe4 security awareness reporting: phishing summary statistics, training completion rates, risk score overviews, trend analysis, organizational benchmarks, and executive dashboards, including how to interpret metrics and communicate posture to stakeholders.
-
wyre-ai Skill Proofpoint PeopleProofpoint People-Centric Security fundamentals: Very Attacked People (VAP) reports, attack index scoring, click susceptibility, top clickers, and user risk categorization for targeting security controls and training.
-
wyre-ai Skill Nutanix Monitoring AiopsThe Nutanix operational-intelligence read surface: `monitoring_execute` for alerts, alert policies, events, and audit logs, and `aiops_execute` for capacity planning, VM rightsizing recommendations, and workload performance analysis — the namespaces behind health checks and capacity reports.
-
fabioc-aloha Skill Architecture AuditComprehensive **project** consistency review across code, documentation, diagrams, and configuration
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include Proofpoint Essentials User Management, act-pass, currency-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.