Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
wufufu770 Skill Exploiting Template Injection VulnerabilitiesPerform exploiting template injection vulnerabilities assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
-
wufufu770 Skill Performing Cryptographic Audit Of ApplicationPerform performing cryptographic audit of application assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
Audited -
wufufu770 Skill Reverse Engineering Dotnet Malware With DnspyPerform reverse engineering dotnet malware with dnspy assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
-
wufufu770 Skill Conducting Internal Network Penetration TestPerform conducting internal network penetration test assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
-
wufufu770 Skill Executing Active Directory Attack SimulationPerform executing active directory attack simulation assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
-
wufufu770 Skill Performing External Network Penetration TestPerform performing external network penetration test assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
-
wufufu770 Skill Analyzing Cobalt Strike Beacon ConfigurationPerform analyzing cobalt strike beacon configuration assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
Audited -
wufufu770 Skill Analyzing Cobaltstrike Malleable C2 ProfilesPerform analyzing cobaltstrike malleable c2 profiles assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
Audited -
wufufu770 Skill Performing Network Traffic Analysis With ZeekPerform performing network traffic analysis with zeek assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
Audited -
wufufu770 Skill Reverse Engineering Malware With GhidraPerform reverse engineering malware with ghidra assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
Audited -
wufufu770 Skill Analyzing Typosquatting Domains With DnstwistPerform analyzing typosquatting domains with dnstwist assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
Audited -
wufufu770 Skill Performing Ip Reputation Analysis With ShodanPerform performing ip reputation analysis with shodan assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
Audited -
wufufu770 Skill Performing Web Application Vulnerability TriagePerform performing web application vulnerability triage assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
Audited -
wufufu770 Skill Exploiting Ms17 010 Eternalblue Vulnerability>- Detects and exploits MS17-010 (EternalBlue), a critical remote code execution flaw in Microsoft's SMBv1 implementation, using Nmap's ms-1…
-
wufufu770 Skill Performing Dynamic Analysis With Any RunPerform performing dynamic analysis with any run assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
Audited -
wufufu770 Skill Conducting Wireless Network Penetration TestPerform conducting wireless network penetration test assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
Audited -
wufufu770 Skill Performing Network Traffic Analysis With TsharkPerform performing network traffic analysis with tshark assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
Audited -
wufufu770 Skill Analyzing Certificate Transparency For PhishingPerform analyzing certificate transparency for phishing assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
Audited -
wufufu770 Skill Performing Static Malware Analysis With Pe StudioPerform performing static malware analysis with pe studio assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
Audited -
wufufu770 Skill Performing Bandwidth Throttling Attack SimulationPerform performing bandwidth throttling attack simulation assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
Audited -
wufufu770 Skill Exploiting Zerologon Vulnerability Cve 2020 1472Exploiting Zerologon Vulnerability (CVE-2020-1472)
-
wufufu770 Skill Analyzing Macro Malware In Office DocumentsPerform analyzing macro malware in office documents assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
Audited -
wufufu770 Skill Deobfuscating Powershell Obfuscated MalwarePerform deobfuscating powershell obfuscated malware assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
Audited -
wufufu770 Skill Analyzing Malware Behavior With Cuckoo SandboxPerform analyzing malware behavior with cuckoo sandbox assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
Audited -
wufufu770 Skill Exploiting Vulnerabilities With Metasploit FrameworkUses the Metasploit Framework (msfconsole and its exploit, auxiliary, and post-exploitation modules) to validate that identified CVEs and vu…
-
wufufu770 Skill Performing Wireless Security Assessment With KismetPerforming Wireless Security Assessment with Kismet
-
tangledgroup Bundle Pyzmq 27 1 0Complete toolkit for Python bindings to ZeroMQ (pyzmq 27.x) covering socket types, messaging patterns, async/await integration, security mechanisms, and distributed computing architectures. Use when building Python applications requiring high-performance messaging, pub/sub systems, request-reply patterns, load balancing, or inter-process communication with ZeroMQ's decentralized architecture.
-
tangledgroup Bundle Pacote 21 5 0Inspect, download, and extract npm packages without installing them first using pacote 21.5 via npx. Supports registry packages, git repositories, local files, directories, and remote tarballs for package inspection, dependency analysis, manifest retrieval, security verification with Sigstore attestations, and offline extraction workflows. Use when inspecting npm package contents, extracting tarballs for analysis, retrieving manifests without installation, verifying package attestations, or working with offline package sources.
-
netvar1337 Bundle Masriyan 01 Recon OsintPassive and active reconnaissance, subdomain enumeration, DNS analysis, technology fingerprinting, and OSINT data correlation for authorized security assessments
-
netvar1337 Bundle Router Reverse Skill Router Firmware PentestFirmware / IoT penetration chain. Start from a raw .bin / .img blob and run the full loop: reverse engineering → extraction → emulation → exploitation. The methodology follows the nine phases of OWASP FSTM; the toolchain centers on binwalk v3, unblob, EMBA, Firmadyne, and AFL++. Applicable scenarios: router/camera/smart-home firmware auditing, firmware upgrade package reversing, IoT CVE reproduction, embedded 0-day hunting. Trigger keywords: firmware, IoT, binwalk, unblob, UART, JTAG, squashfs, UBI, JFFS2, Firmadyne, QEMU full-system emulation, EMBA, firmware pentest, router firmware, embedded exploitation, bootloader, NVRAM, FAT, firmware analysis toolkit.
-
netvar1337 Skill Binary Analysis AnalystPerform deep exploit-focused binary analysis by tracing attacker-reachable paths to validated vulnerability primitives.
-
netvar1337 Bundle Masriyan 09 Web SecurityOWASP Top 10 testing, injection vulnerability detection, API security assessment, authentication testing, and web vulnerability reporting for authorized assessments
-
netvar1337 Bundle Masriyan 12 Log AnalysisSecurity log parsing, anomaly detection, SIEM query building, Sigma rule creation, and correlation rule development across Splunk, Elastic, QRadar, and Microsoft Sentinel
-
netvar1337 Bundle Router Reverse Skill Router Database SecurityUse for authorized database security assessment covering PostgreSQL/MySQL/MSSQL/Mongo/Redis exposure, authz, UDF/command paths, and misconfiguration review.
-
netvar1337 Skill Detection EngineerCreate detection rules and hunting queries from malware analysis findings. Use when you need to write Sigma rules for SIEM, Suricata rules for network IDS, defang IOCs for safe sharing, or convert analysis findings into actionable detection content for SOC teams and threat hunters.
-
netvar1337 Bundle Masriyan 06 Threat HuntingIOC extraction, threat intelligence correlation, MITRE ATT&CK mapping, hunt hypothesis generation, and detection rule creation
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include exploiting-template-injection-vulnerabilities, performing-cryptographic-audit-of-application, reverse-engineering-dotnet-malware-with-dnspy. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.