Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
sairam0424 Skill Quality AuditSkill — Quality Audit (Four-Dimension Weighted Scoring)
-
sairam0424 Skill Vibe SecuritySkill — Vibe Security (Fast-Path Security Assessment)
-
sairam0424 Skill Mobile SecuritySkill — Mobile Security Architecture
-
sairam0424 Skill Security ReviewSkill — Security Review
-
sairam0424 Skill Threat ModelingSkill — Threat Modeling
-
sairam0424 Skill Doc Health AuditSkill — Documentation Health Audit
-
aeondave Bundle Test Driven DevelopmentUse when implementing persistent code, bug fixes, refactors, scripts, exploit tooling, harnesses, or skill utilities before writing implementation code. Applies when tests, reproducers, assertions, or verification can be written first; treat disposable spikes separately and convert them to tested code before claiming reliability.
-
aeondave Skill Deep Research GenericFile-backed deep research with recursive link-following, multi-tool web fetching, and step-by-step synthesis. Use when the user asks to research, investigate, analyze, or summarize a topic in depth; when a thorough answer requires gathering and cross-referencing multiple sources; or when output must be comprehensive, cited, and not limited by context window size. For CVE/exploit/threat-intel research → use deep-research-offensive.
Audited -
aeondave Skill RestlerAuth/lab ref: Stateful REST API fuzzer from OpenAPI specs. For testing complex API dependency chains, producer-consumer request sequencing, and replayable bug-bucket workflows for API reliability/security testing.
Audited -
aeondave Skill LazagneAuth/lab ref: LaZagne secret-exposure audit; browser/app/Wi-Fi/Git artifacts, user/admin context, defensive validation evidence.
-
aeondave Bundle SpiderfootAuth/lab ref: Automated OSINT platform with 200+ modules for target profiling: DNS, email, username, IP, ASN, breach data, dark web, social media, threat intel.
-
aeondave Bundle MimikatzAuth/lab ref: Mimikatz secret-exposure audit; LSASS, DPAPI, Kerberos tickets/keys, token/ticket artifacts, Windows lab validation.
-
aeondave Skill SnafflerAuth/lab ref: Snaffler AD share audit; accessible shares, sensitive file patterns, secret-risk indicators, evidence reporting.
-
aeondave Bundle Evidence Before ClaimsEvidence gate for security research, scanner triage, code review, and reporting. Use before confirming vulnerability impact, auth material, control results, cleanup, or root cause.
-
aeondave Bundle Deep Research OffensiveFile-backed offensive security research with recursive link-following, multi-tool fetching (Jina Reader, Tavily, Playwright), and step-by-step synthesis. Use when researching CVEs, vulnerabilities, exploits, attack chains, PoC code, OSINT targets, red team planning, or threat intelligence. Saves each useful page to intermediate files, follows linked sources recursively, and produces a comprehensive research document not limited by context size.
-
aeondave Skill MimipenguinAuth/lab ref: Linux secret-exposure audit; process/memory artifact review for authorized recovery and defensive validation.
-
aeondave Skill Loop Control And PivotsRetry discipline for stuck work. Use when an approach fails repeatedly, when grinding a side problem (env setup, missing tool, credentials, file transfer) instead of the goal, or when a debug/exploit/build attempt is not converging. Enforces evidence-first pivots, a 3-strikes rule, and honest BLOCKED reporting over thrash - while resisting premature give-up: pivot the dead path, but hold the objective while budget and untried approaches remain.
Audited -
aeondave Skill Offensive Web RoleScoped routing: Web Operator. Handles API mapping, request replay, vulnerability validation, and OWASP-tier finding formulation.
-
aeondave Bundle Game TechniqueAuth assessment: game security methodology; client integrity, anti-cheat, protocol replay, save formats, DRM/license checks, memory analysis.
-
aeondave Skill Offensive Osint RoleScoped routing: OSINT Operator. Focuses on leaked credentials, identity mapping, social footprint, and threat intelligence.
-
aeondave Bundle Webhook SiteAuth/lab ref: webhook.site: hosted out-of-band application security testing (OAST) collector - instantly generates a unique HTTPS URL plus DNSHook subdomain that records every HTTP request and DNS query, with a Web UI.
-
aeondave Bundle DalfoxAuth/lab ref: fast Go-based XSS scanner for parameter analysis and DOM-based XSS detection.
-
aeondave Bundle PrivesccheckAuth/lab ref: PrivescCheck Windows privilege review; services, tasks, registry policy, DLL/COM paths, stored-secret indicators.
-
aeondave Bundle Mobile TechniqueAuth assessment: mobile app security; Android/iOS static, storage, Frida/runtime, traffic, pinning, platform, API and crypto checks.
-
aeondave Bundle SearchsploitAuth/lab ref: Offline CLI search tool for Exploit-DB.
-
aeondave Skill MythrilAuth/lab ref: symbolic-execution-based security analyzer for Solidity and EVM bytecode.
Audited -
aeondave Bundle SemgrepAuth/lab ref: fast static analysis tool for finding security vulnerabilities, misconfigurations, and secrets in source code.
Audited -
aeondave Bundle Vuln ResearchAuth/lab ref: Exploit research workflow: a target software version or CVE: triage CVSS severity, find public PoCs on NVD/sploitus/PoC-in-GitHub/ExploitDB, assess exploitability, and locate Metasploit modules.
Audited -
aeondave Bundle GitleaksAuth/lab ref: Gitleaks secret scanning; repo/directory/stdin checks, regex+entropy rules, pre-commit/CI evidence, remediation workflow.
-
aeondave Bundle Design Before ImplementationUse before creative or multi-file implementation work: new features, behavior changes, refactors, new skills, offensive tooling workflows, exploit chains, research pipelines, or architecture decisions. Clarifies intent, scope, alternatives, constraints, success criteria, and non-goals before coding or executing.
-
aeondave Skill Linux PersistenceAuth/lab ref: Linux durability-risk audit; cron/systemd/SSH/PAM/LD_PRELOAD indicators, validation, cleanup and remediation notes.
-
aeondave Bundle BurpsuiteAuth/lab ref: Burp Suite: integrated web application security testing platform with proxy, scanner, intruder, and repeater.
-
h3y6e Bundle Writing BeatsWriting, exploit — assemble raw material into a journey of beats, grounding each term before a beat leans on it.
-
h3y6e Bundle Writing ShapeWriting, exploit — shape raw material into an article, paragraph by paragraph.
-
h3y6e Skill Ponytail AuditWhole-repo audit for over-engineering. Like ponytail-review, but scans the entire codebase instead of a diff: a ranked list of what to delete, simplify, or replace with stdlib/native equivalents. Use when the user says "audit this codebase", "audit for over-engineering", "what can I delete from this repo", "find bloat", "ponytail-audit", or "/ponytail-audit". One-shot report, does not apply fixes.
-
h3y6e Skill Token ComplianceCheck a codebase or implementation for token compliance — finding hardcoded values, wrong-tier token references, and inconsistent token application in consuming code. This checks how tokens are used in code, NOT how the tokens themselves are defined or structured. Trigger when someone says: are we using tokens correctly, find hardcoded values, token compliance check, find raw values, token misuse, are there any hex values in the code, checking token usage, or anything about whether tokens are being used consistently and correctly. Do NOT trigger for auditing the token definitions themselves — use token-audit for that.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include quality-audit, vibe-security, mobile-security. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.