Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
daemon-blockint-tech Bundle Anti False Positive Decision MakingGuides decision frameworks when false positives are costly—thresholds, evidence bars, and escalation so actions are not taken on weak signals. Covers FP/FN trade-offs, base rates, corroboration, tiered response (monitor vs act), security/compliance alert tuning, screening workflows, HITL gates, precision/recall/FDR, decision rationale docs, and alert fatigue. Use when the user mentions false positive, reduce false positives, alert tuning, too many false alarms, precision vs recall, when to escalate, evidence threshold, anti false positive, decision threshold, base rate, corroboration before action, alert fatigue, screening false positive, or don't block on weak signal—not for production ML classifiers (data-scientist, ml-ops-engineer), legal determinations (commercial-counsel), detection rules without decision policy (domain security/AML skills), or generic brainstorming (executive-mentor).
-
daemon-blockint-tech Bundle Scada Ics Cyber Security SpecialistGuides OT/ICS and SCADA cyber security—Purdue zones, IEC 62443 and NIST SP 800-82 (practitioner), OT asset inventory (PLCs, RTUs, HMIs, historians), secure remote access, OT patch/vuln management, ICS protocol monitoring (Modbus, DNP3, OPC, BACnet high level), safety-first IR, OT threat classes (TRITON, Industroyer), hardening roadmaps, IT/OT convergence. Use for OT program scope, ICS segmentation, OT vuln/patch, detection/IR playbooks, vendor remote access, IEC 62443 or NIST 800-82 gaps—not IT network pentest (network-pentester), web apps (web-pentester), HIL bench only (hardware-in-the-loop-security-tester), GRC only (compliance-specialist), SOC triage (soc-analyst), or IT IR without OT safety (incident-responder). Safety over aggressive testing; no unsafe live-plant steps.
-
daemon-blockint-tech Bundle Embedded Real Time Software EngineerGuides embedded real-time firmware—MCU tradeoffs, bare-metal vs RTOS (FreeRTOS/Zephyr patterns), task priorities/deadlines/jitter, ISR deferred work, stack/heap policy, WCET/timing analysis, concurrency and priority inversion, drivers/HAL, JTAG/SWD/trace, power modes, MISRA C awareness, safety-aware automotive/medical/industrial patterns without certification claims. Use for embedded firmware, RTOS scheduling, drivers/HAL, IRQ design, memory policy, WCET, bring-up, low-power—not HIL security (hardware-in-the-loop-security-tester), backend apps (senior-software-engineer), SCADA/OT (scada-ics-cyber-security-specialist), server perf (performance-engineer), RTL-only without firmware, CI gates (build-validator), tiering only (mission-critical).
-
daemon-blockint-tech Bundle Hardware In The Loop Security TesterGuides security assessment of embedded and cyber-physical systems on hardware-in-the-loop (HIL) test benches—bench setup, ECU/ECM or PLC targets, bus interfaces (CAN/CAN-FD, LIN, automotive Ethernet, Modbus at high level), fault injection and stimulus design, simulated plant/environment integration, attack-surface monitoring on real hardware, reproducible test cases, lab safety interlocks, and evidence capture for firmware and vehicle security teams. Use for HIL security testing, ECU security assessment, CAN bus security, PLC HIL test, fault injection lab, embedded hardware security—not web/API pentest (web-pentester), network-only pentest (network-pentester), malware/binary RE only (reverse-engineer), SOC operations (soc-analyst), AI red team (ai-redteam), classified ISSO paperwork (information-systems-security-officer-classified-specialist), or pure software CI without hardware (build-validator).
-
daemon-blockint-tech Bundle Technical Program Manager Security CvdGuides technical program management for security coordinated vulnerability disclosure (CVD)— disclosure policy, intake and triage SLAs, researcher coordination, fix/remediation tracking, embargo and publication timelines, CVE/advisory coordination, bug bounty program operations, and cross-functional gates (security engineering, legal, comms, product). Use when running a CVD or responsible disclosure program, disclosure calendar, bounty ops, or unblocking multi-team remediation for reported vulnerabilities—not for hands-on pentest (offensive-security-analyst), SOC triage (defensive-security-analyst), vuln scanning in CI (devsecops), enterprise security strategy (cybersecurity), generic non-security programs (technical-program-manager), or contract redlines (commercial-counsel).
-
daemon-blockint-tech Bundle Robotics Automation Integration EngineerIntegrates and commissions robotic and factory automation—arms, cobots, AMRs/AGVs, gantries; PLC/PC interfaces; safety (light curtains, e-stops, STO); Profinet, EtherNet/IP, EtherCAT, Modbus; robot OEM APIs and teach-pendant workflows; vision-guided pick, conveyors, sortation, palletizing; MES/WMS/ERP handoffs; FAT/SAT, I/O mapping, HMI/SCADA at integration layer; ROS/ROS2 bridges where needed. Use for robotics integration, automation integration engineer, commission a robot cell, PLC robot integration, cobot integration, AMR integration, EtherNet/IP, Profinet, robot safety, FAT SAT automation, conveyor integration, vision guided robotics, factory automation—not MCU firmware (embedded-real-time-software-engineer), OT security (scada-ics-cyber-security-specialist), WMS logic (wms-developer), autonomy AI (tactical-ai-autonomy-developer), simulation-only (simulation-software-engineer), control apps only (control-software-developer).
-
daemon-blockint-tech Bundle Information Systems Security Officer Classified SpecialistGuides Information Systems Security Officer (ISSO) work for classified systems and enclaves—system security plan (SSP), control status, continuous monitoring, POA&M, assessor coordination, authorization packages, change impact, vulnerability interfaces, incident reporting to ISSM/PM, common control inheritance, documentation-level boundaries. Cleared environments; cross-domain rules at high level. Use when acting as ISSO, maintaining SSP or POA&M, supporting A&A or RMF, coordinating assessors, control inheritance, classified boundaries, or ATO packages—not classified portfolio (classified-cyber-security-senior-manager), CISO/board (chief-information-security-officer), SOC (soc-analyst), IR (incident-responder), engineering (information-security-engineer), audit automation (compliance-engineer), enterprise GRC (compliance-specialist), reference architecture (enterprise-security-architect), risk registers (security-risk-analyst), CISSP prep (certified-information-systems-security-professional).
-
ghosteken Bundle API Endpoint BuilderBuilds production-ready REST API endpoints with validation, error handling, authentication, and documentation. Follows best practices for security and scalability.
-
ghosteken Skill API Security TestingAPI security testing workflow for REST and GraphQL APIs covering authentication, authorization, rate limiting, input validation, and security best practices.
-
ghosteken Skill Web Security TestingWeb application security testing workflow for OWASP Top 10 vulnerabilities including injection, XSS, authentication flaws, and access control issues.
-
ghosteken Skill Nodejs Best PracticesNode.js development principles and decision-making. Framework selection, async patterns, security, and architecture. Teaches thinking, not copying.
-
ghosteken Skill Security And HardeningHardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services.
-
ghosteken Skill Top Web VulnerabilitiesProvide a comprehensive, structured reference for the 100 most critical web application vulnerabilities organized by category. This skill enables systematic vulnerability identification, impact assessment, and remediation guidance across the full spectrum of web security threats.
-
ghosteken Skill Logic LensAI-powered Claude Code skill that performs deep code review using formal logic and reasoning frameworks to detect bugs, anti-patterns, and security risks beyond what linters catch.
Audited -
ghosteken Skill Atlas LedgerCompanion to atlas-contract. Auto-invoked by its Final Audit on caught drift; also use after Post Reviews or user requests to record a mistake. Distills drift into WHEN/DON'T/INSTEAD clauses, writes to Atlas.md after confirmation.
Audited -
ghosteken Skill Security Scanning Security Sast'Static Application Security Testing (SAST) for code vulnerability
-
ghosteken Bundle Openclaw Github Repo Commander7-stage super workflow for GitHub repo audit, cleanup, PR review, and competitor analysis
-
unboundcompute Skill Writing Vuln ReportsTurn a confirmed finding into a clear, reproducible vulnerability report a maintainer or triager can act on without a back-and-forth. Use after a finding is confirmed (via the finding schema) and you need a writeup - a bug-bounty submission, a security advisory, an internal ticket, or a disclosure email. Covers the report structure that gets findings fixed, writing a reproduction that actually reproduces, justifying severity honestly, and the disclosure etiquette that keeps you in bounds.
Audited -
unboundcompute Skill Finding Crypto MisuseFind exploitable cryptographic misuse, not theoretical weakness: reused nonces (stream and counter/GCM keystream reuse, ECDSA private-key recovery from a repeated per-signature secret), padding oracles that decrypt ciphertext, hash length-extension on naive MAC constructions, predictable or reused IVs and keys, and a hash chosen for the wrong job. Use when reviewing code that encrypts, signs, authenticates, or hashes, or when a protocol rolls its own crypto. The finding is a concrete recovery or forgery, not "weak algorithm."
Audited -
unboundcompute Skill Finding Fail Open FlawsFind security controls that grant access when they should deny it: an authorization check that returns allow on error or timeout, an empty or wildcard allowlist that matches everything, a default-allow branch when input is missing or unrecognized, and a caught exception that swallows a denial and continues. Use when reviewing authentication, authorization, or any gate whose failure path matters, or when a check "passes" for reasons you have not confirmed. The dangerous default is allow; prove every gate denies by default.
Audited -
unboundcompute Skill Auditing Electron Ipc TrustAudit an Electron desktop app for untrusted renderer content that reaches a Node or operating-system capability, after the webPreferences and the preload bridge surface are resolved. Covers nodeIntegration enabled with contextIsolation off, a preload that exposes raw ipcRenderer or a generic invoke passthrough, an ipcMain handler that trusts renderer input as a path, command, or URL, remote or attacker-influenced content loaded through loadURL with navigation unlocked, shell.openExternal called on a renderer-controlled string, and a custom protocol or deeplink routed into a privileged action without validation. Use when reviewing webPreferences, the preload and contextBridge surface, IPC handlers, and remote-content loading, not renderer-side markup injection the client-side DOM skill owns. Untrusted content in a renderer is the source, a Node or operating-system capability is the sink, and input crossing the bridge without validation while isolation is off is the bug.
Audited -
unboundcompute Skill Auditing Saml And Oidc FlowsAudit federated single sign-on for the flaws that let an attacker forge or replay an identity: signature wrapping and signature stripping on signed assertions, unsigned or unverified tokens accepted, redirect_uri and audience manipulation, missing state and nonce allowing replay and cross-site request forgery, and identity confusion where one provider's assertion is honored for another account. Use when reviewing a SAML or OIDC integration, an identity-provider connection, or any login that trusts an external assertion. The verification step is the target.
Audited -
unboundcompute Skill Auditing Directory Sync TrustAudit bulk directory synchronization (LDAP, HR-system, IdP, or cross-directory feeds) between an external identity source and an application for trust misplaced in the sync feed: a sync that trusts a source attribute (group, department, an admin-like flag) to set local privilege or tenancy without validating it, a connector authenticated by a broad credential that can read and reshape the whole directory, a mapping that lets an external group name land on a privileged internal group, a sync that matches accounts by a spoofable key (email, external id) so an attacker record merges into an existing identity, and a source deletion that does not propagate so departed users linger. Use when an external directory feed drives account and privilege state and the application's trust in that feed is the boundary. The attacker-influenced source record is the source, the over-privileged, merged, or lingering internal account is the sink, and the unvalidated attribute mapping or spoofable match key is the bug.
Audited -
unboundcompute Skill Hunting Bugs With A Code GraphHunt security bugs across a whole codebase by reasoning over its structure (call graph and dataflow) instead of grepping for keywords. Use when you have source access to an authorized target (your own code, an OSS project, or an in-scope engagement) and want systematic coverage of a bug taxonomy rather than a single hunch; when the question is "who calls this, what reaches this sink, which peer function is unguarded." Orients on an unfamiliar codebase, enumerates the full bug taxonomy before drilling in, and turns structural leads into decided findings.
Audited -
unboundcompute Skill Auditing GRAPHQL Attack SurfaceAudit the attack surface a GraphQL API exposes that a plain endpoint does not: schema introspection left open, unbounded query depth and recursion, aliasing and field duplication that multiply cost, query batching that defeats rate limits and enables brute force, field-level authorization that a resolver skips even when the object check passed, and mutations reached without the guard their action needs. Covers the query and variables as the source, the resolver and the data or work it triggers as the sink, and the missing depth, cost, batch, or field guard as the bug. Use when reviewing a GraphQL schema, its resolvers, or a gateway that fronts one. Introspection and cost limits are one audit; per-field and per-mutation authorization is the other.
Audited -
unboundcompute Skill Auditing JWT Verification TrustAudit code that verifies a JSON Web Token for a signature or claims check that trusts token-supplied parameters, so an attacker can forge a token the server accepts, after the algorithm pinning and the key source are resolved. Covers an algorithm taken from the token header rather than pinned server-side, an RS256-to-HS256 key confusion where a public key is used as an HMAC secret, an accepted none algorithm or a verification call with signature checking off, a kid, jku, or x5u parameter sourcing a key from an untrusted location, audience, issuer, and expiry claims left unchecked, and an HMAC secret that is weak, guessable, or committed. Use when reviewing the verification call and its options in source, not the token-generation entropy the randomness skill owns or the OAuth flow the OIDC skill owns. A token with an attacker-chosen header or bytes is the source, a verification call that gates identity is the sink, and an unpinned algorithm or a token-sourced key is the bug.
Audited -
unboundcompute Skill Auditing Multi Tenant IsolationAudit whether every data operation is scoped to the caller's tenant, so a request in one tenant cannot read or write another's data. Covers a query or object lookup with the object identifier but no tenant predicate, a tenant taken from client-controlled input at the operation rather than the authenticated session, scoping applied on the list path but dropped on the detail, update, delete, or export path, a cache or storage key with no tenant segment, and a background job, report, or privileged connection that runs across tenants or bypasses the mandatory scope. Frames isolation as a systemic invariant, not a single-object reference bug, which a separate skill covers. Use when reviewing data access in a system that serves multiple tenants. The tenant used at the operation is the source, the tenant-scoped data operation is the sink, and a sink scoped by anything but the authenticated tenant is the bug.
Audited -
unboundcompute Skill Auditing Browser Extension TrustAudit a browser extension (Manifest V3) for a trust boundary another web page or extension can cross to reach a privileged capability, after the permission scope and the message-sender checks are resolved. Covers an externally_connectable or onMessageExternal handler that verifies an origin but not the calling script, a content-script-to-background message handler with no sender validation, host permissions broader than the extension needs, a web_accessible_resources page that acts on URL parameters, an injected content script writing page-controlled data to a DOM sink, and a weak or eval-permitting content-security policy. Use when reviewing the manifest, background and content scripts, and cross-context message passing, not the web-page DOM sink taxonomy the client-side DOM skill owns. An untrusted web origin or another extension is the source, a privileged extension API or DOM sink is the sink, and a message reaching it without a sender-and-origin check is the bug.
Audited -
unboundcompute Skill Auditing Scim Provisioning TrustAudit a SCIM 2.0 provisioning endpoint for trust misplaced in the identity provider that drives it: a provisioning API authenticated by a weak, shared, or long-lived bearer token anyone holding it can use to create users and grant groups, a handler that lets one tenant's client create or modify users in another tenant, a group or role pushed over SCIM that maps to more privilege than the source attribute should grant, a deprovisioning path that fails to disable a departed user so access lingers, and attribute updates (email, external id, admin flag) trusted without validation so an attacker reassigns an account. Use when an external identity source creates, updates, and deletes accounts over SCIM and the service provider's trust in that source is the boundary. The crafted or replayed SCIM request is the source, the unauthorized account, group, or lingering access is the sink, and the weak provisioning auth or unvalidated attribute mapping is the bug.
Audited -
unboundcompute Skill Auditing Idp Initiated Flow TrustAudit identity-provider-initiated single sign-on for trust placed in an unsolicited assertion the application never asked for: an IdP-initiated SAML response the service provider accepts with no matching request so there is no request state to bind it to, an unsolicited assertion an attacker captures and replays or delivers to a victim to log them into an attacker-chosen account, a RelayState value trusted as a redirect target so it becomes an open redirect, an assertion with no or a too-wide audience so it is accepted by a service provider it was not meant for, and a missing replay defense (no one-time-use, weak expiry) that lets one assertion be used more than once. Use when an application accepts a login assertion it did not request and the validation of that unsolicited assertion is the boundary. The unsolicited or replayed assertion is the source, the unintended authenticated session is the sink, and the missing request binding, audience, or replay defense is the bug.
Audited -
unboundcompute Skill Reviewing Content Security PolicyReview a content security policy as a script-injection defense and judge whether it would actually stop injected script, with the discipline that a weak policy is a real finding mainly where an injection sink it would otherwise block exists. Covers a script source that allows inline script with no neutralizing nonce or hash, that allows arbitrary hosts or data URLs, or that trusts a host serving attacker-usable script; a nonce that is static, reused, low-entropy, or reflected from input; a missing base-uri or object-src that defeats an otherwise strong nonce policy; and a report-only header shipped as the only policy. Use when reviewing a policy in a response header, a meta tag, or config, alongside the pages it protects. The policy is the control under test, injected script is the sink it must block, and a gap the injection reaches is the bug.
Audited -
unboundcompute Skill Auditing Break Glass Account TrustAudit emergency break-glass and privileged-access accounts for the ways their standing power outlives the emergency they exist for: a break-glass account with a static, shared, or never-rotated credential that is a permanent superuser login rather than a sealed last resort, an emergency account excluded from the MFA, conditional-access, or logging controls covering other admins so its use is easy and invisible, a just-in-time elevation that grants more than the task needs or is not revoked when the task ends, an emergency-access path with no approval, time bound, or alerting so it is used routinely, and a break-glass use that triggers no review afterward. Use when a standing emergency identity or an elevation path holds power beyond ordinary admins and the controls around when and how it is used are the boundary. The break-glass credential or elevation request is the source, the unbounded or unaudited privileged access is the sink, and the missing rotation, control coverage, or use-time alerting is the bug.
-
unboundcompute Skill Auditing Machine Identity IssuanceAudit how a platform issues machine and workload identities (certificate authorities, workload-identity federation, service-mesh identity, attestation-based credentialing) for trust misplaced in the thing asking for one: a credential issued on a weak or forgeable proof (a self-asserted name, an unvalidated label, a reachable metadata endpoint) so forging the proof yields a real identity, an issuing authority not constrained to the names it may mint, a federation trust configured so broadly (a wildcard subject, unpinned issuer, missing audience) that an outside principal can assume it, a certificate with an over-long lifetime or no revocation, and an issuance path with no binding to a verified workload. Use when a platform decides what proof earns a machine identity and that is the boundary. The forgeable issuance proof or over-broad trust is the source, the illegitimately issued machine identity is the sink, and the weak attestation, unconstrained issuer, or over-broad federation trust is the bug.
Audited -
unboundcompute Skill Auditing Presigned Url Scope AbuseAudit presigned object-storage URLs for scope that grants more than the request intended: a signature that covers a broader key, prefix, or bucket than the user should reach, an overlong expiry, a method or content-type left unconstrained, or a signer identity whose permissions exceed the caller's. Covers presigned GET and PUT URLs for S3 and compatible stores, where the signed policy is the only boundary once the URL leaves the server, and where an attacker who edits the key, reuses the URL, or uploads a different object escapes the intended scope. Use when a service mints presigned URLs so clients read or write storage directly. The caller-influenced key or policy input is the source, the signing call is the sink, and the signed scope wider than the caller's entitlement is the bug.
Audited -
vibesec-advisory Bundle Sme Review PacketUse when blocked, sensitive, low-confidence, legal, security, privacy, or product-specific RFP questions need specialist review.
-
vibesec-advisory Bundle Escalation BriefUse when renewal risk needs leadership, legal, security, product, finance, or implementation review with facts separated from assumptions.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include anti-false-positive-decision-making, scada-ics-cyber-security-specialist, embedded-real-time-software-engineer. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.