Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
vibesec-advisory Bundle Approval Gate MapperUse when MAP milestones may require legal, security, procurement, implementation, finance, or executive review before customer sharing.
-
inbharatai Skill Soc2 HelperPrepare for SOC 2 audits — control mapping, evidence collection, gap analysis, and audit narrative writing.
-
inbharatai Skill Vuln ScannerIdentify security vulnerabilities in code and configurations — CVE lookup, SAST findings, and remediation guides.
-
inbharatai Skill Code ReviewerPerform thorough code reviews — bugs, security issues, performance bottlenecks, style violations, and architectural concerns.
-
inbharatai Skill Owasp CheckerCheck for OWASP Top 10 vulnerabilities — injection, broken auth, XSS, insecure deserialization, and misconfiguration.
-
vibesec-advisory Bundle Approved Answer MatcherUse when a security questionnaire question can be answered from vetted language while preserving caveats, confidence, and approval status.
-
vibesec-advisory Bundle Questionnaire Completion QAUse when a security questionnaire response set is ready for final review against sensitive details, unsupported claims, source gaps, and approval readiness.
-
vibesec-advisory Bundle Implementation Risk MapperUse when handoff details could create delivery, security, integration, data, timeline, or expectation risk for implementation.
-
vibesec-advisory Bundle Security Question ClassifierUse when security questionnaire questions need category, sensitivity, source mapping, ownership, and review routing before answers are matched.
-
vibesec-advisory Bundle Memory Sensitivity GatekeeperUse when proposed memory may include personal data, customer data, credentials, private URLs, regulated data, permission claims, approval claims, security posture, or internal-only context.
-
vibesec-advisory Bundle Questionnaire Intake Safety CheckUse when security questionnaire material, customer attachments, NDA context, or control details need data and confidentiality screening before drafting.
-
vibesec-advisory Bundle Memory Expiry And Rollback PlannerUse when a memory item needs retention rules, expiry, review cadence, snapshot handling, deletion path, rollback owner, and audit evidence before durable storage.
-
vibesec-advisory Bundle Playbook Inventory And Freshness AuditUse when a playbook, sales play, talk track, or enablement asset needs structured freshness, ownership, source, and risk review.
-
daemon-blockint-tech Bundle IfrsThis skill should be used when the user asks about IFRS, International Financial Reporting Standards, IFRS 15 revenue, IFRS 16 leases, IFRS 9 financial instruments, IFRS 10 consolidation, IAS 36 impairment, IFRS 13 fair value, IFRS disclosure notes, IFRS recognition, first-time adoption IFRS, or IFRS vs GAAP. Guides application and explanation of IFRS financial reporting—recognition and measurement by standard, presentation and disclosure (IAS 1, IFRS 7), fair value hierarchy, going concern and materiality, significant judgments and estimates, first-time adoption (IFRS 1), consolidation and business combinations, local GAAP convergence context, and audit-ready note disclosure structure—not US GAAP-only ASC deep dives (note high-level differences only), tax law advice, legal entity structuring, full external audit execution (auditor), ERP configuration (senior-software-engineer), or management accounting without a reporting-standards lens.
-
daemon-blockint-tech Bundle Aml CftThis skill should be used when the user asks about AML/CFT, counter-terrorist financing, CFT, terrorist financing, proliferation financing, PF, targeted financial sanctions, asset freeze, TF typology, charitable NPO due diligence, MVTS, FATF Recommendation 6, or STR terrorist financing. Guides CFT/PF risk—TF typologies (self-funding, charitable fronts, MVTS, trade-based TF), PF and dual-use red flags, TFS and asset-freeze workflows (conceptual), CFT STR/SAR narrative structure, NPO due diligence, correspondent and cross-border TF risks, FATF R6–R8 alignment, sanctions screening integration, CFT training and independent review, exam readiness—not full AML program (KYC, CDD, TM, MLRO) → aml-compliance; sanctions vendor config only; law enforcement tactics; legal determinations. Peers: aml-compliance, compliance-engineer, auditor, commercial-counsel, information-security-engineer.
-
daemon-blockint-tech Bundle AuditorThis skill should be used when the user asks to plan or execute internal audit, IT audit, risk-based audit planning, control testing, audit evidence, workpaper documentation, SOC 2 audit support, SOX ITGC testing, walkthroughs, operating effectiveness, deficiency or finding write-ups, remediation retest, or audit report summaries for management or the audit committee. Guides assurance engagements—scoping, framework mapping (COSO, COBIT concepts, SOC 2 trust criteria), design vs operating effectiveness, sampling, ITGC themes (access, change, operations), vendor audit coordination, and governance reporting—not penetration testing (security-engineer, ai-redteam), building controls from scratch (compliance-engineer), legal interpretation (commercial-counsel), PCAOB financial statement audit detail, or blockchain investigation.
-
daemon-blockint-tech Bundle Soc AnalystGuides SOC operations—alert triage, SIEM/EDR investigation, enrichment, playbook execution, false-positive closure, escalation decisions, and detection tuning feedback. Use when working SOC queues, investigating suspicious alerts, correlating events, documenting analyst notes, or deciding escalate vs close—not for declared incident command, timelines, evidence preservation, or regulatory comms (incident-responder), incident program design (incident-management-engineer), binary/firmware RE (reverse-engineer), red team operations (red-team-specialist), or enterprise security strategy (cybersecurity).
-
daemon-blockint-tech Bundle D3fend HardenGuides cybersecurity hardening controls using MITRE D3FEND—authentication, application hardening, credential management, message integrity, platform security, and source code defenses. Covers MFA, certificate pinning, control flow integrity, encryption, input validation, and secure configuration. Use when hardening systems, configuring auth, implementing encryption, or reviewing code security—not for detection rules (d3fend-detect), network segmentation (d3fend-isolate), or incident response (d3fend-evict).
-
daemon-blockint-tech Skill Build ValidatorValidate plans, designs, and implementations before execution to prevent costly mistakes. Cover architecture review, security audit, scalability assessment, cost analysis, compliance check, and risk identification. Produce go/no-go decisions with specific remediation steps. Triggers on "review this plan", "validate architecture", "check for mistakes", "is this production ready", "audit this design", "what could go wrong", "pre-flight check", "build review", "quality gate", "risk assessment", "cost estimate", or "compliance check".
-
daemon-blockint-tech Bundle Mission CriticalGuides mission-critical system framing—tiering (mission-critical vs business-critical vs important), availability/integrity/continuity objectives, dependency and blast-radius mapping, architecture patterns (active-active, geo-redundancy, deterministic behavior), change/release governance, monitoring and escalation by criticality, and generic regulatory/contractual drivers (finance, healthcare, public safety, defense industrial base). Use when classifying criticality, setting RTO/RPO/MTPD and integrity targets, designing redundant architectures, mapping failure domains, governing Tier 0/1 releases, or ops escalation—not SRE error budgets only (site-reliability-engineer), HRO/prevention culture only (zero-tolerance-for-failure), incident command (incident-responder), recovery engineering only (cyber-resilience-engineer), enterprise security architecture only (enterprise-security-architect), ADRs without tiering (senior-system-architecture), or classified ATO only (classified-cyber-security-senior-manager).
-
daemon-blockint-tech Bundle Commercial CounselGuides commercial contract review and negotiation support for B2B agreements—MSAs, SaaS/order forms, vendor and customer contracts, DPAs, SLAs, limitation of liability, indemnity, IP, payment terms, and redline/issue logs with business impact notes. Use when reviewing or negotiating commercial terms, comparing vendor or customer paper, drafting negotiation positions, or triaging contract risk before sign-off—not for SOC/ISO GRC programs or vendor questionnaire ops (compliance-specialist), technical audit evidence (compliance-engineer), revenue recognition under ASC 606 (senior-revenue-accountant), or product requirements (business-analyst), strategy (business-consultant). Corporate/board: corporate-counsel. AI architecture for contract review: applied-ai-architect-commercial-enterprise. M&A economics mandate: transaction-principal. Drafting assistance only; human counsel must approve.
-
daemon-blockint-tech Bundle Supply Chain ManagerGuides supply chain management—sourcing and supplier qualification, procurement and PO governance, demand forecasting and inventory policy, logistics and fulfillment (3PL, Incoterms, lead times), supplier scorecards, cost and TCO analysis, supply risk and continuity, and SCM KPI dashboards. Use when designing supply strategy, running RFQs, setting safety stock, resolving stockouts or excess inventory, improving OTIF, dual-sourcing critical parts, or building supplier business reviews—not for contract legal redlines (commercial-counsel), vendor security assessments (information-security-engineer), DC construction delivery programs (senior-data-center-capacity-delivery-manager), compute GL and invoice reconciliation (compute-accounting-manager), SaaS quote-to-order (deal-operations-administrator), or enterprise strategy cases (business-consultant).
-
daemon-blockint-tech Bundle Sensor Fusion EngineerGuides multi-sensor perception fusion for autonomous and robotic systems—sensor models and noise; extrinsic/intrinsic calibration; time synchronization; coordinate frames and transforms; data association and gating; Kalman-family filters (EKF/UKF) and factor graphs at high level; track management (MOT); LiDAR–camera–radar–IMU–GNSS integration patterns; uncertainty representation; evaluation metrics (NEES, RMSE, track continuity); simulation and bag replay. Use when designing or debugging fusion stacks, calibration/sync, state estimation, multi-object tracking, sensor fusion architecture, fusion metrics, or rosbag/sim replay—not full autonomy behavior and mission rules (tactical-ai-autonomy-developer), MCU drivers/RTOS only (embedded-real-time-software-engineer), plant PLC/DCS control applications (control-software-developer), HIL security bench testing (hardware-in-the-loop-security-tester), or adversarial ML on models unless fusion-robustness focus (ai-adversarial-robustness-engineer).
-
daemon-blockint-tech Bundle Tech Writer ResearcherWrite and research technical documentation. Cover information architecture, style guides, API documentation, user research, content strategy, and documentation operations. Triggers on "write technical documentation", "create API docs", "developer tutorial", "information architecture", "style guide", "content strategy", "documentation audit", "user research", or "technical writing". Developer learning programs and curriculum: developer-education-lead.
-
daemon-blockint-tech Bundle Cryptographer SpecialistThis skill should be used when the user asks for a cryptographer, cryptography review, help to choose a cipher (AES-GCM, ChaCha20-Poly1305, ECDH, RSA tradeoffs), key management, PKI design, TLS configuration, protocol security or handshake review, authenticated encryption, digital signature scheme design, post-quantum migration at architecture level, ProVerif or Tamarin modeling concepts, nonce reuse or IV misuse analysis, HKDF vs password hashing (Argon2), HSM or KMS usage patterns, secure randomness, side-channel and constant-time requirements, or cryptographic agility and algorithm deprecation—not general OWASP web app review only (information-security-engineer), secure coding checklists without crypto depth, Solidity or smart contract audits, blockchain wallet tracing, legal export classification, or shipping custom production crypto without design and review gates.
-
daemon-blockint-tech Bundle Senior Software EngineerGuides senior software engineering across languages and stacks—system and service design, RFCs, code review, refactoring, reliability patterns, testing strategy, performance analysis, technical decomposition, and engineering leadership on delivery teams. Use when designing services or modules, writing technical specs, reviewing PRs for architecture and correctness, improving legacy code, choosing trade-offs (coupling, consistency, latency), estimating complex work, or mentoring engineers—not for stack-specific full-stack UI delivery (senior-fullstack-developer), deployment rollout strategy (deployment-strategist), infrastructure/IaC (infrastructure-engineer), dedicated perf profiling and load testing (performance-engineer), org-wide security programs (cybersecurity), or cross-system ADRs and architecture review (senior-system-architecture).
-
daemon-blockint-tech Bundle Senior Revenue AccountantApply ASC 606/IFRS 15 to revenue recognition and contract analysis. Cover performance obligations, deferred revenue, commission accounting, revenue metrics (ARR, NRR, GRR), and audit preparation. Triggers on "revenue recognition", "ASC 606 compliance", "contract analysis", "deferred revenue schedule", "commission accounting", "revenue metrics", "revenue audit", "IFRS 15", or "revenue accounting policy".
-
daemon-blockint-tech Bundle Asset Liability ManagementGuides asset-liability management (ALM)—matching asset and liability cash flows and risks; interest rate risk (duration, convexity, key rate duration); surplus and risk appetite; liability-driven investment (LDI), immunization, and hedging (rates, inflation, FX); insurer, pension, and bank ALM; stress testing; ALM policy and ALCO reporting; capital metrics at high level—not trade execution, security selection alone, pension plan design, actuarial reserving, or assumption governance alone. Use when the user mentions asset liability management, ALM, duration gap, interest rate risk ALM, liability driven investing, immunization portfolio, ALCO, surplus at risk, key rate duration, ALM policy, or match assets and liabilities—not pensions (pension-retirement-funds), actuarial models (actuary), assumptions (assumption-setting), P&C (property-casualty-insurance), life/health products (life-health-insurance), equity research (financial-analyst), or actuarial consulting (actuarial-consulting).
-
daemon-blockint-tech Bundle Zero Tolerance For FailureGuides failure-prevention culture and operational excellence for mission-critical engineering— zero-defect aspiration vs error budgets; HRO principles; defense-in-depth; fail-safe/fail-closed; verification gates and independent checks; redundancy and graceful degradation; pre-mortems and FMEA; stop-the-line; defect escape, near-miss, and repeat-incident metrics; leadership against normalization of deviance—not blame culture. Use for failure-prevention programs, HRO practices, verification gates, fail-safe design, pre-mortem/FMEA, stop-the-line, near-miss reporting, or defect-escape metrics—not SRE error budgets only (site-reliability-engineer), incident command only (incident-management-engineer), backup/restore only (cyber-resilience-engineer), CI lint only (build-validator), agile coaching, HR discipline, or classified ATO without ops-excellence lens (classified-cyber-security-senior-manager).
-
daemon-blockint-tech Bundle Incident Management EngineerGuides incident management engineering—severity models, escalation policies, on-call design, paging and comms tooling (PagerDuty/Opsgenie/Slack), incident lifecycle workflows, status pages, blameless postmortems, and reliability metrics (MTTD, MTTR, incident rate). Use when designing or improving incident response programs, on-call rotations, escalation paths, incident tooling integrations, postmortem templates, or SEV definitions—not for hands-on outage debugging (devops), security investigations (defensive-security-analyst), security IR policy (cybersecurity), multi-team program tracking (technical-program-manager), or individual customer technical tickets (support-engineer), or exec/VIP and community customer escalation programs (community-executive-escalations-program-manager). For incident **message** drafting and approval workflows, use communication-lead.
-
daemon-blockint-tech Bundle People Operations SpecialistGuides people operations (HR ops)—employee lifecycle administration, HRIS workflows, onboarding and offboarding checklists, handbook and policy rollout, benefits and payroll coordination, performance review cycles, leave and PTO process, and people data hygiene. Use when running new-hire onboarding, offboarding, HR policy communications, performance cycle logistics, org change updates in HRIS, or employee-facing process design—not for corporate board governance (corporate-counsel), commercial contract redlines (commercial-counsel), SOC audit evidence (compliance-engineer), or customer success onboarding (customer-ops-specialist). Escalate employment law questions to qualified counsel.
-
unboundcompute Skill Auditing S3 Object Ownership TrustAudit object-storage ownership and per-object access for trust the bucket policy does not cover: an object uploaded by another account that keeps that uploader's ownership and ACL, a bucket where object ACLs still grant access despite a restrictive bucket policy, a cross-account write that lands an object the bucket owner cannot read or that carries a public grant, and a policy that scopes by prefix while an ACL on the object overrides it. Covers S3 and compatible stores where object ownership, object ACLs, and the bucket policy interact to decide who reads and controls each object. Use when a bucket receives objects from more than one principal and access is meant to be governed centrally. The cross-account or ACL-granted principal is the source, the object read or control is the sink, and the access the bucket policy did not intend is the bug.
Audited -
unboundcompute Skill Auditing Ble And Gatt AuthorizationAudit a Bluetooth Low Energy device for missing authorization on its GATT attributes: a characteristic performing a sensitive action or revealing sensitive data readable or writable by any peer, pairing or bonding that is not required or falls back to an unauthenticated Just Works mode with no link encryption, an authorization decision the device pushes to the mobile app instead of enforcing on the peripheral, and a replayable command a sniffer can capture and resend. Covers BLE peripherals, wearables, locks, medical and IoT devices, and their GATT services where a connected peer reads or writes characteristics. Use when a peer can connect over BLE and the peripheral's own enforcement of who may read or write each characteristic is the boundary. The unauthorized connected peer or captured command is the source, the sensitive read, write, or action on the peripheral is the sink, and the missing pairing, characteristic-level authorization, or replay protection is the bug.
Audited -
unboundcompute Skill Auditing Device Code And Pkce FlowsAudit the server side of the authorization-code-with-proof-key and device-authorization grants for bugs that let a stolen or guessed code become a token. Covers a token endpoint that issues without checking the proof-key verifier at all, that accepts the plain challenge method or a challenge-absent downgrade, or that binds the verifier to the client rather than to the specific code; and a device grant whose short user code is brute-forceable because polling is unthrottled, whose device code is not bound to the requesting client, or whose approval is not tied to the authenticated approver. Scoped to the proof-key and device-code specifics, not general federated login, which a separate skill covers. Use when reviewing a token endpoint or a device-authorization endpoint. The token request parameters are the source, token issuance is the sink, and an unenforced proof binding between them is the bug.
Audited -
unboundcompute Skill Auditing Grpc Service AuthorizationAudit a gRPC service for a method a caller can reach without the authorization the service assumes an interceptor enforces, after the interceptor coverage and the channel credentials are resolved. Covers authorization installed on the unary interceptor while the streaming chain omits it, a per-method authorization gap reachable at the wrong privilege, server reflection enabled in production exposing the full API, a plaintext channel with metadata trusted unverified, an absent message-size or recursion-depth limit inviting decode denial of service, and a transcoding gateway that does not apply the same auth filter as native gRPC. Use when reviewing service and interceptor registration, method handlers, and channel setup, not the certificate-validation mechanics the transport skill owns. A caller with forged or absent metadata is the source, a service method acting without an authorization check is the sink, and an interceptor that does not cover the method or stream is the bug.
Audited -
unboundcompute Skill Auditing Webauthn And Passkey FlowsAudit the server side of passwordless authentication for ceremony-verification bugs that let an attacker-shaped response become an authenticated session. Covers a registration or authentication ceremony whose challenge is not bound to a server-issued single-use value, an origin or relying-party identifier that is never checked or checked by substring, a user-verification flag ignored when policy required it, attestation accepted when it was required, a signature counter regression that hides a cloned authenticator, and the highest-severity case where a cryptographically valid assertion seats a session for a user other than the one the credential is bound to. Use when reviewing code that verifies a registration or authentication ceremony and establishes identity from the result. The attacker-shaped ceremony response is the source, the authenticated session is the sink, and a missing required check between them is the bug.
Audited
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include approval-gate-mapper, soc2-helper, vuln-scanner. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.