Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
netvar1337 Bundle Masriyan 19 Grc ComplianceGovernance, risk, and compliance — risk assessment and scoring, control mapping across NIST CSF 2.0 / ISO 27001:2022 / SOC 2 / CIS Controls v8, gap analysis, audit evidence preparation, and security policy generation
-
netvar1337 Bundle 401 403 Bypass401/403 访问拒绝绕过方法论。当遇到管理后台、API 端点返回 401/403 Forbidden 时使用。覆盖路径操纵、HTTP 方法篡改、Header 注入、协议降级、组合攻击
-
netvar1337 Bundle Claude Red Fuzzing Offensive Vuln ClassesExploit development curriculum covering core vulnerability classes with real-world CVE case studies: stack/heap buffer overflows, use-after-free, integer overflows, format strings, type confusion, and race conditions. Use when learning or teaching vuln classes, researching specific CVE patterns, or building exploit dev knowledge.
-
netvar1337 Bundle Masriyan 17 Mobile SecurityAndroid and iOS application security testing — static and dynamic analysis, APK/IPA inspection, OWASP MASVS/MASTG verification, secure-storage and transport review, and mobile malware triage for authorized assessments
-
netvar1337 Bundle Masriyan 08 Network SecurityNetwork traffic analysis, PCAP parsing, IDS/IPS rule creation, firewall configuration auditing, and network anomaly detection
-
netvar1337 Skill Crypto Vulnerability AnalystAnalyze cryptographic design and implementation for misuse, key-management weaknesses, and protocol-level exploit opportunities.
-
netvar1337 Bundle Claude Red Fuzzing Offensive Fuzzing CourseWeek 2 of the exploit development curriculum. Covers fuzzing methodology: target selection, corpus generation, coverage-guided fuzzing with AFL++/libFuzzer, structured fuzzing, and triage/deduplication. Use when setting up fuzz campaigns, selecting harness strategies, or triaging fuzzer output.
-
netvar1337 Bundle Malware Report WriterCreate professional malware analysis reports for enterprise security teams and incident response. Use when you need to write, structure, or improve a malware analysis report, produce executive summaries, author YARA rules, or format IOCs and detection rules for professional delivery.
-
netvar1337 Bundle Masriyan 15 Blue Team DefenseSystem hardening, detection engineering, security baseline monitoring, patch management, defense-in-depth architecture, and security posture improvement
-
netvar1337 Bundle Claude Red Exploit Dev Offensive MitigationsSecurity mitigation reference and bypass catalog: ASLR, DEP/NX, RELRO, stack canaries, CFI, sandboxing, seccomp. Covers both detection of enabled mitigations and known bypass techniques. Use when assessing target hardening or planning exploit mitigation bypasses.
-
netvar1337 Bundle Masriyan 03 Exploit DevelopmentProof-of-concept development, payload crafting, shellcode analysis, and exploitation technique research for authorized security testing
-
netvar1337 Bundle Masriyan 02 Vulnerability ScannerDependency auditing, CVE detection, configuration security review, CVSS scoring, and prioritized vulnerability reporting
-
netvar1337 Bundle Claude Red Exploit Dev Offensive Exploit DevelopmentExploit development operational guide: environment setup, debugging workflow, PoC development lifecycle, writing reliable exploits, using pwntools/pwndbg, heap exploitation techniques, and weaponization considerations. Use when actively developing exploits or setting up an exploit dev environment.
-
netvar1337 Bundle Waf Bypass MethodologyWAF 绕过统一方法论。当漏洞利用 payload 被 WAF 拦截返回 403/406 时使用。覆盖编码绕过、分块传输、HTTP 方法切换、参数污染、Payload 变形等通用绕过技术
-
wufufu770 Skill Hunt XssXSS 挖掘:反射/存储/DOM 三型,危险 sink 定位、上下文逃逸与绕过,OOB 门禁。触发词:XSS、跨站脚本、存储型。
Audited -
wufufu770 Skill C ReviewPerform c review assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
Audited -
wufufu770 Skill 006 Fp CheckTL;DR
-
wufufu770 Bundle Src API TestingPerform src api testing assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
-
wufufu770 Bundle Src Auth BypassPerform src auth bypass assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
-
wufufu770 Skill Git CleanupPerform git cleanup assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
Audited -
wufufu770 Skill Security Headers安全响应头审计:CSP/HSTS/XFO/Referrer-Policy 缺陷评估与修复基线建议。触发词:安全头、CSP、响应头、headers。低危快速项,适合凑覆盖面。
Audited -
wufufu770 Skill Src Session StartPerform src session start assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
-
wufufu770 Skill Rust ReviewPerform rust review assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
Audited -
wufufu770 Skill Prototype PollutionJS 原型污染:客户端/服务端入口点识别、gadget 分析、向 XSS/RCE 的利用升华。触发词:原型污染、prototype pollution、__proto__。
-
wufufu770 Skill Security ArsenalPerform security arsenal assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
-
wufufu770 Skill Hunt SharepointPerform hunt sharepoint assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
Audited -
wufufu770 Bundle Offensive OsintPerform offensive osint assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
-
wufufu770 Skill Static Analysis"Reuse this database" - label: "<db_path_2> (language: cpp, created: 2026-02-23)" description: "Reuse this database" - label: "Build a new database" description: "Create a fresh database in a new output directory" ``` After selection: - **If user picks an existing database:** Set `$OUTPUT_DIR` to its parent directory (or the directory containing it), set `$DB_NAME` to the selected path, then proceed to extensions → analysis. - **If user picks "Build new":** Resolve a new `$OUTPUT_DIR`, execute b
Audited -
wufufu770 Skill Firebase Apk ScannerPerform firebase apk scanner assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
-
wufufu770 Skill Dimensional AnalysisPerform dimensional analysis assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
Audited -
wufufu770 Skill Audit Context BuildingUnderstand a codebase before looking for bugs in it - what each function assumes, what it guarantees, and what it depends on elsewhere. Use…
Audited -
wufufu770 Skill Agentic Actions AuditorPerform agentic actions auditor assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
Audited -
wufufu770 Skill Exploiting Adcs With CertipyUse Certipy to enumerate AD CS certificate authorities and templates over LDAP/RPC, then exploit ESC1-ESC16 misconfigurations - SAN abuse, N…
Audited -
wufufu770 Skill Claude In Chrome TroubleshootingPerform claude in chrome troubleshooting assessment during authorized security testing. Use this skill when indicators of the vulnerability class are
Audited -
wufufu770 Skill Performing Ssl Stripping AttackPerform performing ssl stripping attack assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
-
wufufu770 Skill Performing Vlan Hopping AttackPerform performing vlan hopping attack assessment during authorized security testing. Use this skill when indicators of the vulnerability class are present in the target environment.
Audited
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include masriyan-19-grc-compliance, 401-403-bypass, claude-red-fuzzing-offensive-vuln-classes. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.