Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
ferroxlabs Skill Wayland Full Sales AssetWrite a complete long-form direct-response sales letter end-to-end: temperature, four-layer open, three locks, body and bullets, proof, and a Cascade Close. Use when the user wants a full sales letter built from scratch using The Donahoe Method, reviewing at each major beat. Do NOT use when the user only needs an audit of existing copy (use wayland-conversion-audit), a close rebuild (use wayland-close-rebuild), or a VSL (use wayland-vsl-build).
37 -
ferroxlabs Skill Wayland Listing OptimizeAudit and optimize a single product listing end to end: diagnose the conversion bottleneck, run a full audit, rewrite the listing, and produce an A/B test plan to validate the change. Use when the user wants a structured multi-step process to improve one listing's copy, structure, and conversion levers. Do NOT use for a quick catalog triage pass (use listing-audit-pick) or a single-line copy tweak.
Audited 37 -
ferroxlabs Skill Wayland Listing Audit PickPick one product listing from an inventory source, run a quick audit on it, and produce targeted improvement recommendations. A fast, deterministic triage pass over a catalog. Use when the user wants to surface a single weak listing from their inventory and get an immediate audit plus recommendations. Do NOT use when the user already has the specific listing in hand and just wants a deep rewrite (use the full listing-optimize workflow instead).
Audited 37 -
ferroxlabs Skill Convert TemperatureClassify reader temperature on the 5-level scale: Ice Cold / Cool / Warm / Hot / Boiling. Sets length, depth, education burden, and approach for every other Method primitive that follows. Use when starting a new asset and you need to calibrate how much teaching, proof, and persuasion to load before writing. Not for auditing an existing asset's tone (use convert-audit) and not for designing the offer (use funnels-offer).
Audited 37 -
ferroxlabs Skill Wayland Bullshit Clean BatchBatch Bullshit Filter: scan a directory of markdown drafts, run the Filter on each, and save a cleaned version of every draft. Use when the user has a folder of markdown copy drafts and wants the whole set filtered and cleaned in one pass. Do NOT use for a single draft (use wayland-bullshit-clean) or when the user wants a scored audit rather than an automated cleanup.
37 -
ferroxlabs Skill Wayland Launch Readiness AuditPre-launch readiness audit workflow. Builds a required-asset checklist for the launch type, runs a gap analysis with severity flags against what is already built, and produces a go/no-go recommendation with rationale. Use when the user wants a structured pre-launch audit to decide whether the launch is ready to go. Do NOT use when the user wants to build launch assets from scratch (use the full launch workflow) or has a single quick question.
Audited 37 -
ferroxlabs Skill Convert Four QuestionsRun the Four Questions diagnostic before any copy is written: Why You / Why Me / Why This / Why Now answered from the customer's perspective in one specific sentence each. Produces the briefing the rest of the Method writes against. Use when starting a new sales page, VSL, email, or any direct-response asset and you need a customer-perspective brief before drafting a single sentence. Not for auditing existing copy (use convert-audit) and not for writing the page itself (use convert-sales-page after this diagnostic).
Audited 37 -
ferroxlabs Skill Convert Bullshit FilterCoach a draft toward voice integrity - quotes the 3 weakest lines from the input draft, forces 3 alternative rewrites of each, diagnoses the dominant voice failure pattern, and returns a coaching artifact (no PASS / FAIL verdict). Use when running a final coaching pass on copy before shipping - sales pages, VSL scripts, emails, ads, headlines. Not for full Voice Rules pass (use convert-voice - Bullshit Filter is one rule of many in Voice; this is the deeper standalone coaching pass) and not for Method audit scoring (use convert-audit).
Audited 37 -
gigik2a Skill Audit TrailAudit trail e tracciabilità operazioni per PMI italiane: requisiti GDPR, SOX-lite, conservazione log, struttura evento immutabile, strumenti di implementazione, compliance per settori regolamentati (finance, sanità, PA).
-
gigik2a Bundle Skill UpdaterMeta-skill per l'aggiornamento automatico di tutte le skill dell'utente. Usa SEMPRE questa skill quando l'utente dice "aggiorna le skill", "controlla aggiornamenti skill", "manutenzione skill", "migliora le skill", "skill update", "audit skill", "revisione skill", "ottimizza le skill", "le skill sono aggiornate?", "verifica skill", "refresh skill". Attivala anche quando viene eseguita come task schedulato per la manutenzione periodica mensile.
-
gigik2a Bundle UX Copy ReviewRevisione UX e copywriting homepage e landing page per PMI italiane. Report DOCX 10-12 pagine con annotazioni prima/dopo e piano azione prioritizzato. Trigger: "revisione UX", "UX review", "il sito non converte", "homepage non funziona", "migliorare la homepage", "copy sito web", "testi sito", "CTA", "call to action", "proposta di valore", "landing page review", "conversion rate", "nessuno mi contatta dal sito", "revisione testi", "UX copy", "copywriting sito", "audit conversione". Input: URL sito, pagine da analizzare (default homepage + max 4 landing), settore, target cliente ideale, obiettivo conversione. Analizza gerarchia visiva, proposta di valore, CTA, copy, accessibilita. Per ogni problema: riferimento sezione, diagnosi, riscrittura proposta. Output: report DOCX + JSON strutturato. Fascia 349-499 EUR consulenza web PMI. Tono empatico e diretto.
-
gigik2a Bundle Verifica Pe TerziSkill per la verifica e il controllo di qualità dei Progetti Esecutivi (PE) iliad Italia S.p.A. redatti da fornitori o appaltatori terzi. Usa SEMPRE questa skill quando l'utente dice "verificare il PE", "controllare il progetto", "revisionare gli elaborati", "check PE terzi", "verifica conformità PE iliad", "controllare se il progetto è completo", "trovare le non conformità nel PE", "revisione PE fornitore", "approvare il PE", "audit PE iliad", "checklist verifica progetto esecutivo", "il PE è corretto?", "mancano documenti?".
-
gigik2a Skill Impianti ElettriciSkill specializzata su impianti elettrici italiani. Usa sempre questa skill per: normativa (D.M. 37/2008, DPR 462/2001, D.Lgs. 81/2008), norme CEI (64-8, 11-27, 0-21, EN 61439), protezioni (differenziali AC/A/F/B, magnetotermici, SPD, AFDD), impianti di terra (TT/TN, dispersori, CEI 64-12), fotovoltaico e BESS (CEI 0-21, dimensionamento stringa), quadri BT/MT (CEI EN 61439, selettività, forme), verifiche (Zs, isolamento, terra, CEI 64-8/6), ATEX (zone, modi Ex, CEI EN 60079), motori e avviamento (DOL, Y-Δ, VFD, classi IE), cabine MT/BT (trasformatori, relè 50/51/51N, Icc), scariche atmosferiche (LPS, CEI EN 62305, captatori, calate), illuminazione (LED, lux, emergenza CEI EN 50172, DALI), ricarica EV (wallbox, EVSE, CEI 64-8 sez.722), ambienti speciali (ospedali IT-M, piscine, cantieri CEE), domotica (KNX, BTicino MyHome), efficienza energetica (cosφ, armoniche, THD, audit), dimensionamento cavi, caduta di tensione, DdC, errori comuni.
-
gigik2a Bundle Verifica PacchettoQuesta skill deve essere usata quando l'utente vuole "verificare il pacchetto", "controllare il pacchetto autorizzativo", "check del pacchetto iliad", "revisionare la SCIA", "controllare i documenti del sito", "verificare la completezza del pacchetto", "controllare la coerenza dei dati", "trovare errori nel pacchetto", "audit del pacchetto autorizzativo", "verifica RT vs Asseverazioni", "controllo residui template", "check preesistenze fittizie", "verifica ENAC Ciampino", oppure quando carica documenti di un pacchetto SCIA art. 45 per impianti iliad e chiede una verifica sistematica secondo la checklist aggiornata v0.5.0 (aree A-H, lezioni L1-L22).
-
gigik2a Skill Diagnosi Energetica EgeEGE certificato UNI CEI 11339 per Diagnosi Energetica (DE) di edifici e impianti industriali. Attiva SEMPRE per: diagnosi energetica, audit energetico, EGE, REDE, efficientamento edifici, EEM, IPE, baseline, inventario energetico, UNI TS 11300, D.Lgs 102/2014, schede rilievo, sopralluogo energetico, validazione modello, APE, analisi bollette, ripartizione consumi, simulazione edificio-impianto, costi-benefici interventi, Conto Termico, TEE, cappotto, caldaia condensazione, pompa di calore, fotovoltaico, LED edifici, TR VAN TIR, ESCo EPC, fonderie, audit industriale, IPMVP, schede ENEA ES-PA, portafoglio PA.
-
gigik2a Bundle Verifica Progetto TerziResponsabile del controllo qualità progettuale Cellnex: verifica la conformità di progetti redatti da fornitori/appaltatori terzi rispetto alle linee guida tecniche Cellnex. Usa SEMPRE questa skill per: verifica progetto terzi Cellnex, controllo progetto fornitore, revisione elaborati tecnici appaltatore, check list verifica progetto Cellnex, conformità CNP_TS21 progetto, revisione relazione di calcolo fornitore, approvazione progetto sito TLC, non conformità progetto Cellnex, audit tecnico progetto, revisione progetto esecutivo appaltatore, controllo qualità progettuale TLC, accettazione elaborati tecnici. Attivala anche per "controllare il progetto del fornitore", "verificare se il progetto è conforme", "revisionare gli elaborati", "approvare il progetto", "trovare le non conformità nel progetto".
-
gigik2a Skill Tokenizzazione ImmobiliareEsperto in tokenizzazione immobiliare: aspetti tecnici (blockchain, smart contract, ERC-1400/ERC-3643), legali (MiCAR, DLT Pilot Regime, normativa italiana 2025, SPV, ECSP), finanziari (STO, DCF, NAV, IRR, waterfall) e strutture non finanziarie (utility token, token d'accesso, preacquisto, membership, civic token). Usa SEMPRE questa skill quando l'utente menziona tokenizzazione immobiliare, security token, STO, utility token immobiliare, token d'accesso a immobili, frazionamento di proprietà su blockchain, REIT tokenizzati, piattaforme di tokenizzazione, rendimenti da token su immobili, SPV immobiliare digitale, NPL immobiliari tokenizzati, development token, strutture per raccogliere fondi senza configurare un investimento finanziario, o qualsiasi altra domanda che combina real estate con blockchain/DLT — anche se non usa esplicitamente la parola "skill".
-
gigik2a Bundle Diritto Energia RegolazioneDiritto dell'energia e regolazione del settore energetico italiano (lato giuridico-amministrativo, complementare alle skill tecniche). Quadro normativo eurounitario e nazionale: Direttiva RED II 2018/2001, RED III 2023/2413, Direttiva Efficienza Energetica EED 2023/1791, Direttiva EPBD IV 2024/1275 (Case Green - recepimento entro 2026), Regolamento Mercato Elettrico (UE) 2019/943, REPowerEU, Pacchetto Fit for 55, Net-Zero Industry Act 2024, Critical Raw Materials Act. Recepimento italiano: D.Lgs. 199/2021 (FER), D.Lgs. 28/2011, D.Lgs. 102/2014 (efficienza energetica e audit obbligatorio grandi imprese), D.Lgs. 48/2020 (EPBD), TU energia D.Lgs. 387/2003, D.Lgs. 79/1999 (Bersani), L. 481/1995 (istituzione ARERA), D.Lgs. 152/2006 (Codice Ambiente - VIA, VAS, AIA, AUA). Procedure autorizzative impianti FER: Autorizzazione Unica AU art. 12 D.Lgs. 387/03 (procedimento unico, conferenza servizi, 90/180 gg), PAS Procedura Abilitativa Semplificata art. 6 D.Lgs. 28/2011 (30 gg silenzio assenso, soglie potenza), comunic
-
wgpsec Bundle OAUTH Sso AttackOAuth 2.0 / SSO / OpenID Connect 认证流程攻击。当目标有「使用 Google/GitHub/微信 登录」按钮、redirect_uri 参数、authorization_code 流程、或 /.well-known/openid-configuration 端点时使用。覆盖 redirect_uri 劫持、state 缺失 CSRF、token 泄露、scope 提升
-
wgpsec Bundle PHP BypassPHP 安全特性绕过:disable_functions 和 open_basedir 限制突破。当已获取 webshell 但命令执行函数被禁用或文件操作被 open_basedir 限制时使用
-
wgpsec Bundle Ot Ics AttackOT/ICS 工控系统攻击方法论。当目标涉及 SCADA/DCS/PLC 系统、发现 Modbus/DNP3/OPC UA/EtherNet-IP 等工控协议、或需要评估关键基础设施安全时使用。覆盖工控协议利用、PLC 攻击、HMI 渗透、IT/OT 边界突破
-
wgpsec Bundle Post Exploit WindowsWindows 系统后渗透全流程。当通过 RCE/webshell/RDP 获取到 Windows shell 后使用。覆盖系统信息收集、UAC 绕过、本地提权、凭据提取(SAM/LSASS/浏览器)、域信息侦察。适用于独立主机和域环境
-
wgpsec Bundle Java Exploit ChainJava 白盒审计漏洞利用链组装。当需要将 Java 审计中发现的多个漏洞组合为完整攻击路径、 或需要评估 Maven/Gradle 依赖中的已知 CVE 对项目的实际影响时触发。 核心: 单个中低危漏洞通过组合可升级为高危/Critical 利用链。 覆盖: 信息泄露→认证绕过→RCE 的典型链路、Gadget Chain 分析方法(ysoserial/marshalsec)、 Maven 依赖 CVE 审计与实际可利用性评估。
-
wgpsec Bundle Crypto Web AttackWeb 应用中的密码学攻击。当发现 Padding Oracle 错误信息、CBC 模式加密的 Token、可预测的随机数/Token、哈希长度扩展攻击机会时使用。覆盖 Padding Oracle(含 PadBuster 完整用法)、CBC bit-flip、弱随机数、哈希长度扩展、ECB 块重排。注意:JWT 攻击请使用 jwt-attack-methodology,Cookie 分析请使用 cookie-analysis
-
wgpsec Bundle Cors MisconfigurationCORS 跨域配置错误检测与利用。当目标 API 返回 Access-Control-Allow-Origin 响应头、需要跨域访问敏感数据、或发现 Origin 头被反射回响应中时使用。可导致用户敏感数据窃取
-
wgpsec Bundle Nosql InjectionNoSQL 注入检测与利用。当目标使用 MongoDB/CouchDB 等 NoSQL 数据库、登录表单使用 JSON body 提交、或参数中出现 $gt/$ne/$regex 等操作符时使用。覆盖操作符注入认证绕过、$regex 盲注数据提取、$where JS 注入、CouchDB 攻击、WAF 绕过
-
wgpsec Bundle Xss Methodology反射型/存储型/DOM XSS 的检测、利用和绕过。当 Web 应用有用户输入回显(搜索/评论/表单/URL参数)、或发现存储型内容输出点时使用。包含上下文分析决策树、WAF绕过技巧、CSP绕过方法、DOM Clobbering、mXSS、SVG XSS。优先于其他漏洞测试——XSS 是最低成本的高危漏洞,发现后立即构造 PoC
-
wgpsec Bundle Python Web DebugPython Web 框架 Debug 模式利用。当目标是 Flask/Django/FastAPI/Tornado 应用且开启了 Debug 模式时使用。当看到 Werkzeug Debugger 页面(交互式 Python console)、Django 黄色调试页面(Settings/Traceback)、FastAPI 自动文档(/docs /redoc)、或错误页面泄露了 Python 堆栈跟踪和源码路径时使用。Werkzeug debugger PIN 计算是 CTF 和实战中的经典考点——通过读取 /etc/machine-id 和 MAC 地址即可算出 PIN 码获取 RCE。任何 Python Web 应用的错误页面、/console 路径、或泄露了 Flask/Django/Werkzeug 版本信息时都应使用此 skill
-
wgpsec Bundle Ssrf Methodology服务端请求伪造(SSRF)的检测与利用方法论。当目标有 URL 获取/预览/导入功能、PDF 生成、Webhook、远程图片加载、RSS 导入时使用。包含 IP 过滤绕过大全、协议利用(file/gopher/dict)、云元数据窃取、内网服务探测。即使参数名看起来无害(如 src、callback、next),只要涉及服务端发起请求的场景都应加载此 skill。
Audited -
wgpsec Bundle Ssti Methodology服务端模板注入(SSTI)的检测、引擎识别和利用。当目标是Flask/Jinja2/Django/Twig/Mako/Pug应用、存在用户输入回显、参数名含template/name/message/greeting时使用。Phase 0/1即覆盖快速检测和引擎识别,无须单独skill。如只需快速检测定位可直接使用Phase 0/1,无需阅读完整利用部分
-
wgpsec Bundle Websocket AttackWebSocket 安全测试。当目标使用 ws:// 或 wss:// 协议、页面 JS 中有 new WebSocket() 调用、或发现 101 Switching Protocols 响应时使用。覆盖 WS 劫持(CSWSH)、消息注入、认证绕过、信息泄露
Audited -
wgpsec Bundle PHP Auth Config AuditPHP 源码认证、配置与逻辑类漏洞审计。当在 PHP 白盒审计中需要检测认证绕过、 权限控制、安全配置、密码学误用或业务逻辑漏洞时触发。 覆盖 5 类风险: 认证绕过(硬编码凭据/弱比较/JWT 缺陷)、授权失控(IDOR/水平越权)、 安全配置(CORS/错误暴露/调试模式)、密码学误用(弱哈希/ECB/硬编码密钥)、业务逻辑(竞争条件/支付篡改)。
-
wgpsec Bundle Kafka AttackApache Kafka 未授权访问与利用。当发现目标开放 9092 端口、Kafka Broker 无认证、Schema Registry 或 Kafka Connect 暴露、或需要从 Kafka 窃取消息数据时使用。覆盖未授权访问、Topic 枚举与消息批量导出、Consumer Group 操作、Broker 配置窃取、ACL 操控、Schema Registry 利用、Kafka Connect 凭据窃取与恶意 Connector 注入、消息篡改与数据注入
-
wgpsec Bundle Redis AttackRedis 未授权访问与利用。当发现目标开放 6379 端口、Redis 服务无认证或弱密码、需要从 Redis 获取敏感数据或实现远程命令执行时使用。覆盖未授权访问、数据窃取、crontab 写入 RCE、主从复制 RCE、模块加载 RCE、webshell 写入、SSH 公钥注入、Lua 脚本注入、Pub/Sub 窃听、持久化文件利用
-
wgpsec Bundle PHP Type JugglingPHP 类型杂耍(Type Juggling)和 Magic Hash 攻击方法论。当目标是 PHP 应用且存在密码比较、哈希校验、认证逻辑时使用。当看到 PHP `==` 松散比较、MD5/SHA1 哈希校验、strcmp 比较、JSON 输入处理、is_numeric 检查时必须使用。当错误登录泄露了输入的 MD5 哈希值时,这是 Magic Hash 的强信号,立即使用。CTF/渗透中 PHP 认证绕过最常见的漏洞类型之一。即使只是看到 PHP 5.x 或响应中包含哈希值,也应考虑使用此 skill
-
wgpsec Bundle Java Auth Config AuditJava 源码认证与配置安全审计。当在 Java 白盒审计中需要检测认证绕过、权限缺陷或安全配置问题时触发。 覆盖 6 类风险: 认证绕过(Spring Security/Shiro Filter 链 URI 解析差异)、 越权(IDOR/水平越权/垂直越权)、JWT 安全(算法混淆/密钥泄露/Claims 验证)、 加密配置(弱算法/硬编码密钥/不安全随机数)、信息泄露(错误堆栈/Actuator/Debug 模式)、 业务逻辑漏洞(竞争条件/金额篡改/流程绕过)。
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include wayland-full-sales-asset, wayland-listing-optimize, wayland-listing-audit-pick. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.