Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
swan-gtm Bundle Won Deal Icp FinderUse this skill when someone wants to know who actually pays them — auditing closed-won deals to derive a proven ideal customer profile instead of an aspirational one, then building a look-alike target list from it. Produces a revenue-ranked deal table, two to four named ICP archetypes with searchable criteria, and a ranking of the acquisition sources that produced the money. Trigger phrasings: "audit my biggest deals", "which customers made us the most money", "analyse my closed-won", "what's my real ICP", "find more customers like my best ones", "look-alike accounts", "revenue by account", "which channel produced our best deals", "ICP refresh before planning".
-
swan-gtm Skill Mutual Action Plan BuilderUse this skill when a deal is live and you need to align the buyer on a shared path to value — when a champion asks "so what are the next steps," when you're heading into scoping, POC, security review, or procurement, when a deal has slipped once or stalled with no mutual timeline, when you just can't tell who on the buyer side actually owns the decision, or when you want to stop pushing a one-sided close plan and turn a skeptical buying committee into co-owners. Drafts a co-created Mutual Action Plan (MAP): a value summary written in the buyer's own words, the full buying committee (not just your champion), and milestones written as BUYER EVIDENCE — "impact validated by multiple stakeholders," "exec sponsor assigned a team" — never as seller activities like "demo done" or "proposal sent."
-
swan-gtm Bundle Procurement NavigationNavigate the buyer procurement gauntlet from selected to signed. Use when a verbally-won deal enters security review, legal redlines, and vendor onboarding, and the close date starts slipping at contract stage. Maps the gauntlet early, pre-bakes the artifact pack, runs security, legal, and privacy reviews in parallel on a mutual close plan, and negotiates procurement without giving away the deal the sales team already won. Produces a gauntlet map, an artifact pack checklist, and a parallel-track close plan. Rule: a deal is not won until it clears the buying machinery; map the gauntlet before the proposal, not after selection. Trigger phrases: procurement, security questionnaire, stuck in legal, DPA, vendor onboarding, close date slipping at contract stage.
-
swan-gtm Bundle Email DeliverabilityUse this skill when emails hit spam, open rates drop, a domain or IP gets blocklisted, or a sender wants a deliverability audit before scaling volume. Triggers: "why are we going to spam", "audit my email setup", "open rates dropped", "we got blocklisted", "warm up this domain", "check my deliverability". Produces a severity-ranked audit or a root-cause diagnosis with a recovery plan and the thresholds to monitor.
-
borghei Bundle Softwarelizenz AgbPrüfung von Software-Lizenz- und Nutzungs-AGB: Einräumung von Nutzungsrechten (§ 31 UrhG), zustimmungsbedürftige Handlungen und Erschöpfungsgrundsatz bei Gebrauchtsoftware (§ 69c UrhG, UsedSoft), AGB-Inhaltskontrolle von Weitergabe- und Audit-Klauseln (§§ 305, 307 BGB). Use when Lizenzbedingungen für Software gestaltet oder auf Wirksamkeit geprüft werden.
-
borghei Bundle Ki Monitoring KonzeptKonzept zur laufenden Überwachung eines produktiv eingesetzten KI-Systems – Performance-Metriken, Daten- und Concept-Drift, Fairness, Robustheit, Logging Art. 12 KI-VO, menschliche Aufsicht Art. 14 KI-VO, Vorfallsmanagement und Audit-Intervalle nach ISO/IEC 42001. Use when ein KI-System produktiv läuft oder vor Inbetriebnahme das Monitoring-Konzept festgelegt werden muss.
-
dragoon0x Skill MicrocopyUI microcopy patterns including button labels, error messages, tooltips, and instructional text.
-
dragoon0x Skill Brand AuditComprehensive brand auditing, touchpoint analysis, and brand consistency assessment.
-
dragoon0x Skill Motion AuditMotion design review, animation performance, and motion consistency checking.
-
dragoon0x Skill Enterprise AdminEnterprise admin panel design, role management, audit logs, organizational hierarchy, and enterprise UX patterns.
-
clowlove Bundle Security ScanComprehensive security scanning for code, dependencies, and infrastructure. Detects vulnerabilities, misconfigurations, and security risks.
-
clowlove Bundle AI Code ReviewAI-powered code review with security scanning, performance analysis, and best practices checking. Supports multiple languages and frameworks.
-
clowlove Bundle Repo Reference AuditAudit and bulk-correct repository self-references across multi-file, multi-language codebases. Covers repo name typos, clone URLs, placeholder tokens, and cross-reference consistency after renames or refactors.
-
bromso Skill Access ControlDesign IAM, RBAC/ABAC, least privilege, and MFA strategy
-
bromso Skill Attack SurfaceMap and minimize the attack surface
-
bromso Skill Compliance GapAssess gaps against security frameworks
-
bromso Skill Compliance MapMap controls to compliance frameworks
-
bromso Skill Security RolesDefine security roles, responsibilities, and RACI matrix
-
bromso Skill Asset InventoryCatalog hardware, software, data, and service assets with criticality
-
bromso Skill Dependency ScanAudit dependencies for known CVEs and license risks
-
bromso Skill Lessons LearnedConduct post-incident review with root cause and improvement actions
-
bromso Skill Security PolicyDefine organizational security policies, standards, and procedures
-
bromso Skill Security CultureDesign security awareness program and culture-building initiatives
-
bromso Skill Security TestingPlan SAST, DAST, SCA, and penetration testing program
-
bromso Skill Audit ReadinessAssess readiness for formal audit — evidence completeness, control effectiveness
-
bromso Skill Anomaly DetectionDefine behavioral baselines and anomaly detection rules
-
bromso Skill Backup ValidationPlan backup strategy, testing, and restoration verification
-
bromso Skill Incident ResponseCreate incident response plan with severity levels and playbooks
-
bromso Skill Security TrainingDesign security training program by role
-
bromso Skill Container SecuritySecure container images, registries, runtime, and orchestration
-
bromso Skill Forensic ReadinessDesign forensic data collection, preservation, and chain of custody
-
bromso Skill Secrets ManagementDesign secrets management strategy
-
bromso Skill Security ChecklistGenerate security checklist for a specific context
-
bromso Skill Auditor SelectionEvaluate and select audit firms
-
bromso Skill Incident Response PlanCreate data breach and security incident response plan
-
bromso Skill Business ContinuityCreate business continuity plan with RPO/RTO targets
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include won-deal-icp-finder, mutual-action-plan-builder, procurement-navigation. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.