Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
joogy06 Skill Rhel Server AdminUse when administering Red Hat Enterprise Linux 9 systems — dnf/rpm package management, subscription-manager, user/group management, SSH hardening, systemd services, firewalld, NetworkManager/nmcli networking, LVM/Stratis storage, kernel tuning, security hardening (CIS, SELinux, fail2ban), Cockpit web console, backup/restore, and on-prem VM guest tools (Proxmox, VMware, Hyper-V). Parent skill for the rhel-* skill family.
-
joogy06 Bundle Saas ArchitectureUse when designing or building SaaS applications — multi-tenancy models (silo/pool/bridge), tenant isolation, subscription and billing integration (Stripe/Paddle), onboarding flows, feature flags and entitlements, usage metering, API rate limiting, tenant-aware data partitioning, SaaS operational patterns (noisy neighbor, tenant health), and SaaS security (data isolation, compliance, SOC2).
-
joogy06 Bundle Dep Currency CheckUse when checking dependency currency and known CVEs in any project with manifests — pyproject.toml / package.json / Cargo.toml / go.mod / Gemfile / pom.xml. Surfaces stale library versions and known vulnerabilities BEFORE AI design agents propose using them. Callable from forge Step 1 (advisory), alf Step 2a (data extraction), pre-commit hooks (POSIX `.sh` + Windows hardened `.ps1`), standalone CLI, the `G_DEP_CURRENCY` gate in `_meta/gates.py`, and as a scope_delta source for critical CVEs in direct deps. Trigger on - "check deps", "what versions are stale", "CVE check", "dependency audit", "is this lib current", "freshness check", forge Step 1 auto-invoke when manifests detected.
-
joogy06 Skill Ubuntu Web ServersUse when configuring web servers on Ubuntu 24.04 LTS — Nginx, Apache, Caddy setup and tuning, virtual hosts, SSL/TLS certificates, Let's Encrypt/certbot, reverse proxy patterns, load balancing, HTTP/2/3, security headers, and performance optimization. Part of the ubuntu-* skill family.
-
joogy06 Skill Ubuntu Server AdminUse when administering Ubuntu Server 24.04 LTS systems — package management, user/group management, SSH hardening, systemd services, UFW/nftables firewall, netplan networking, LVM/disk management, kernel tuning, security hardening (CIS, AppArmor, fail2ban), backup/restore, and on-prem VM guest tools (Proxmox, VMware, Hyper-V). Parent skill for the ubuntu-* skill family.
-
joogy06 Bundle Windows Ps SecurityUse when hardening Windows systems via PowerShell — Windows Firewall (NetSecurity), Windows Defender/Microsoft Defender, BitLocker drive encryption, audit policy and event log analysis, local security policy, credential management (SecureString, Windows Credential Manager), AppLocker, Windows Update management, and security compliance scanning. Part of the windows-ps-* skill family.
-
joogy06 Skill Python Auth SecurityUse when implementing authentication (OAuth, OIDC, SAML, JWT, sessions), authorization (RBAC, ABAC), user management, multi-tenant isolation, API security, or applying OWASP security patterns in Python web applications. Covers Flask and FastAPI security patterns.
-
joogy06 Bundle Development LifecycleUse at the start of any development task — feature, bugfix, refactor, or infrastructure change. Defines mandatory SDLC phases that must be completed with evidence before work is considered done. Enforces testing, security review, and documentation gates.
-
joogy06 Bundle Woocommerce DeveloperUse when building or modifying WooCommerce themes, customizing checkout or product pages, working with WooCommerce hooks and templates, integrating payment gateways, using the WooCommerce REST API, or writing any PHP code that touches WooCommerce. Includes mandatory security patterns.
-
joogy06 Bundle Ledger Error DiagnosisUse when a ledger will not agree — a trial balance that does not balance, a bank or control account that will not reconcile, a VAT return that does not tie to the VAT control account, a balance sheet where net assets do not equal shareholders' funds, or suspected duplicate, missing, mis-signed or mis-period transactions. Covers the arithmetic signatures that identify an error class from the difference alone, the detection query for each class, and the correction protocol that fixes the books without destroying the audit trail.
-
joogy06 Bundle Ms Office Security PythonUse when hardening Python code that touches Microsoft Office files or Microsoft 365 APIs — covers the consolidated security checklist for the ms-office-python-* family, the YAML rule manifest (17 Office-specific rules), and the runnable Python validator (python3 -m ms_office_security_check). All output is advisory-only; defers generic SAST to bandit/semgrep, dependency CVEs to dep-currency-check/pip-audit, secrets to gitleaks/trufflehog, and SBOM to cyclonedx/syft. Part of the ms-office-python-* skill family.
-
planifest Bundle Code QualityExplain code, security tool output, or configuration text — outputs clear EXPLANATION, SECURITY IMPLICATIONS, CONFIGURATION EXPLANATION, or ANSWER sections depending on input type. Use when you need a plain-language breakdown of what code or config does.
-
planifest Bundle Code ReviewerPerform a comprehensive code review of a snippet or diff — assessing correctness, security, performance, readability, and edge cases, with prioritised recommendations and suggested improvements. Use when reviewing PRs or auditing code quality.
-
rweisssieker-xp Skill Powerbi Compliance Evidence PackCreate audit-ready evidence packs for Power BI reports and datasets. Use for KPI approval, RLS testing, source reconciliation, data privacy, assumptions, deployment approvals, and compliance reviews.
-
rweisssieker-xp Skill Powerbi Requirements InterviewerRun structured Power BI requirements interviews for business users. Use to collect outcome, KPI, grain, dimensions, source systems, security, refresh, acceptance, and delivery constraints before experts build anything.
-
rweisssieker-xp Skill Powerbi AI Security Exposure AnalyzerUse when Power BI security exposure must be analyzed across RLS, OLS, sharing, export, sensitivity labels, external guests, PII, groups, workspaces, and tenant settings.
-
rweisssieker-xp Skill Powerbi Audit Ready AI Evidence TrailUse when AI-generated Power BI recommendations, insights, DAX, Power Query, KPI definitions, or process actions need auditable sources, assumptions, tests, approvals, confidence, and change history.
-
rweisssieker-xp Skill Powerbi Security Identity Source PackUse when Power BI sources or governance depend on identity, security, access, Entra ID, Okta, Ping Identity, SailPoint, CyberArk, BeyondTrust, IAM, PAM, RBAC, access reviews, or privileged access.
-
rweisssieker-xp Skill Powerbi AI Regulated Bi Evidence VaultUse when regulated BI artifacts need audit evidence for KPI changes, source lineage, tests, approvals, AI recommendations, human confirmation, SOX, GxP, ISO, GDPR, or similar controls.
-
rweisssieker-xp Skill Powerbi Automated Security Exposure ScanUse when Power BI needs automated scanning for RLS, sharing, export, external guests, PII, sensitivity labels, groups, workspaces, and tenant security exposure.
-
rweisssieker-xp Skill Powerbi Tax Compliance Audit Source PackUse when Power BI sources include tax, compliance, audit, GRC, controls, risk, SOX, VAT, indirect tax, audit management, Workiva, Diligent, SAP GRC, AuditBoard, Vertex, Avalara, or ONESOURCE.
-
kienbui1995 Skill QA AuditUse when conducting quality audits — reviewing process compliance, identifying gaps between defined process and actual practice, conducting structured inspections (code review audits, test quality reviews), and producing audit reports with remediation plans.
-
kienbui1995 Skill UX AuditUse when conducting a heuristic evaluation of an existing interface, identifying usability problems, or prioritizing UX improvements
-
kienbui1995 Skill Security ReviewUse when reviewing code for security vulnerabilities, auth issues, data exposure, or before deploying to production
-
kienbui1995 Skill Blockchain AuditUse when reviewing smart contracts for security vulnerabilities, auditing web3 patterns, or preparing for a formal audit
-
kienbui1995 Skill TaxonomyCreate, validate, audit, and govern Amplitude event taxonomy across a product. Uses mcp__Amplitude__get_event_properties, mcp__Amplitude__get_project_context, mcp__Amplitude__query_amplitude_data.
-
kienbui1995 Skill Qc Security TestingUse when testing security from a QC perspective — OWASP Top 10 test cases, authentication and authorization testing, input validation testing, security regression testing, and integrating security checks into the QC process.
-
williamcorrea23 Skill Sap API PolicySAP API Management policy design and governance — security, traffic, mediation, lifecycle
-
williamcorrea23 Bundle Sap HousekeepingKeep a SAP NetWeaver / S/4HANA system's logs, traces, spool, job logs, ABAP dumps, audit logs and work directory from filling the filesystem — via the SAP standard reorganization jobs (RSBTCDEL2, RSPO1041, RSSNAPDL, RSBDCREO …) and safe OS-level cleanup, on Linux/Windows/AIX. Use for "clean up logs/traces", "/usr/sap is full", "reorg spool/jobs/dumps", "housekeeping jobs", "delete old work-dir files", "audit log cleanup". Hands DB log/trace cleanup to sap-db-command-reference. Cited to SAP Note 16083 + help.sap.com.
-
williamcorrea23 Skill Sap Btp Audit LogSAP BTP Audit Log Service — audit trail capture, configuration, compliance (SOC 2, GDPR), audit log viewer, retention policies, OAuth audit integration. Use when implementing audit logging on BTP, configuring compliance audit trails, or capturing security-relevant events.
-
williamcorrea23 Bundle Vaibe Sap DeveloperDevelop and review SAP ABAP, CDS, HANA SQLScript/AMDP, RAP, OData/Fiori, integrations, enhancements, testing, and security with Clean Core guidance. Use when a request needs a broad SAP development workflow or its local Vaibe reference patterns.
-
williamcorrea23 Bundle Pr TriagePR triage: audit open PRs, deep review selected ones, draft and post review comments. Args: "all" to review all, PR numbers to focus (e.g. "42 57"), "en"/"fr" for language, no arg = audit only in French.
-
kienbui1995 Skill Authentication PatternsUse when implementing auth - OAuth 2.0, JWT, session management, API keys, RBAC, or reviewing auth security
-
kienbui1995 Skill Replay UX AuditSynthesize multiple session replays into a UX friction map identifying systemic usability issues. Uses mcp__Amplitude__list_session_replays, mcp__Amplitude__get_session_replay_events, mcp__Amplitude__get_session_replays.
-
kienbui1995 Skill Extension SecuritySecure browser extensions — CSP configuration, minimal permissions, content script XSS prevention, and handling sensitive data safely.
-
garyld1962 Skill ThesisInterrogate to discover the single-sentence product or architectural thesis, then audit all planned features and decisions against it.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include rhel-server-admin, saas-architecture, dep-currency-check. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.