Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
aradotso Skill Meccha Chameleon Game Trainer DetectionDetect and document game trainer/cheat tool patterns for security research and anti-cheat development
-
aradotso Skill Minecraft Vape Client Security AnalysisAnalyze and understand cheat client patterns, injection techniques, and anti-cheat evasion in Minecraft modding
-
aradotso Skill Game Cheat Detection And Security AnalysisAnalyze and detect game cheating tools, trainers, and malicious software targeting multiplayer games
-
aradotso Skill Deltarune Chapter5 Trainer Detection AnalysisAnalyze and understand game trainer/cheat software patterns for anti-cheat research and educational security analysis
-
jshsakura Skill Powershell Security HardeningUse when a task needs PowerShell-focused hardening across script safety, admin automation, execution controls, or Windows security posture.
-
kmshihab7878 Skill AuditScore the AI OS out of 100 across the Four Cs (Context, Connections, Capabilities, Cadence). Read-only by default. Surfaces top 3 leverage gaps and recommends one next improvement. Saves audit to docs/audits/YYYY-MM-DD.md and logs a one-line entry in decisions/log.md.
-
kmshihab7878 Skill Level UpWeekly improvement loop. Asks 5 reflection questions, maps answers to Three Ms, recommends ONE next skill/script/connection/doc/cadence change, and produces a shippable artifact plan. Does not build anything until the user approves. Pairs with /audit.
-
kmshihab7878 Skill UltrathinkCognitive depth engine for Claude Code. Defines 5 thinking modes (quick → council), activation triggers, quality bars, reasoning scaffolds, and the ultrathink protocol for complex multi-domain decisions. Use when a task requires deep synthesis before action — architecture decisions, security reviews, strategic planning, cross-system design. Pairs with /ultraplan for full execution.
-
kmshihab7878 Skill Osint ReconOSINT investigation and reconnaissance workflows. Username enumeration, domain intelligence, dark web monitoring, social media analysis, and structured investigation methodology. Use for authorized OSINT research, threat intelligence, and security investigations.
-
kmshihab7878 Skill Coremind SecAutonomous Security Ecosystem — 14 AI-powered agents, 48 tools, 9 attack chains for macOS native pentesting
-
kmshihab7878 Skill Security ReviewSecurity review and hardening patterns. OWASP Top 10 checklist, secrets scanning, auth patterns, input validation, and container security. Use when auditing code, reviewing PRs for security, or implementing auth/authz.
-
kmshihab7878 Skill Offensive SecurityAI-powered offensive security testing patterns. Penetration testing methodology, vulnerability assessment workflows, CTF challenges, and security tool integration. Use for authorized security testing, CTF competitions, and defensive security research.
-
kmshihab7878 Skill Weekly Operating ReviewFriday weekly OS health pass. Runs /audit, then /level-up, then refreshes kb/wiki/_hot.md from current state. Single command instead of three. Logs the run. Does not build artifacts.
-
wondermonger-daydreaming Skill Sign The GenreEpistemic-integrity technique for catching one failure with three faces: an INDICATIVE claim borrowed against ground it doesn't hold. A forecast wearing the grammar of a witness; a paraphrase wearing the label of a transcript; a beautiful self-account wearing the authority of a true one. Use when: (1) about to write "output", "result", "verified", "observed", or "done" — is it the literal artifact, or your reading of it? (2) reporting what a run/test/command produced — did you observe it, or expect it? (3) auditing your own motives or narrating your own work (diary, commit message, post-mortem) — is the noble frame the true one? (4) compressing a long source into a summary presented as the source. The fix is one move: SIGN THE GENRE — name what each piece actually is (witness vs forecast, transcript vs reading, appetite vs duty); don't relabel a false thing, replace it. Includes the residue-test for telling a true self-audit from a pretty one.
-
pantheon-org Bundle Dockerfile ValidatorValidates, lints, and secures Dockerfiles by running syntax checking, detecting security vulnerabilities, validating layer ordering, checking for hardcoded secrets, verifying base image tags, and analyzing build optimization. Use when validating Dockerfile syntax, checking security best practices, optimizing image builds, auditing container security, or debugging Dockerfile errors. Applies to all Dockerfile variants (Dockerfile, Dockerfile.prod, Dockerfile.dev, etc.).
-
pantheon-org Bundle Makefile ValidatorComprehensive toolkit for validating, linting, and optimizing Makefiles. Use when working with Makefiles (Makefile, makefile, *.mk files), validating build configurations, checking for best practices, identifying security issues, or debugging Makefile problems. Concrete capabilities include detecting missing .PHONY declarations, validating tab indentation in recipes, checking variable expansion safety, identifying hardcoded credentials, and flagging missing prerequisites or syntax errors.
-
pantheon-org Bundle Bash Script ValidatorComprehensive toolkit for validating, linting, and optimizing bash and shell scripts. Use this skill when working with shell scripts (.sh, .bash), validating script syntax, detecting unquoted variables, checking POSIX compliance, identifying unsafe command substitutions, validating shebang lines, finding security vulnerabilities, or debugging shell script problems.
-
mk-organization-1 Bundle Clawsec NanoclawUse when checking for security vulnerabilities in NanoClaw skills, before installing new skills, or when asked about security advisories affecting the bot
-
mk-organization-1 Bundle Agency Infrastructure MaintainerExpert infrastructure specialist focused on system reliability, performance optimization, and technical operations management. Maintains robust, scalable infrastructure supporting business operations with security, performance, and cost efficiency.
-
mk-organization-1 Bundle Agency Autonomous Optimization ArchitectIntelligent system governor that continuously shadow-tests APIs for performance while enforcing strict financial and security guardrails against runaway costs.
-
mk-organization-1 Skill Springboot SecuritySpring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.
-
mk-organization-1 Skill Postgres PatternsPostgreSQL database patterns for query optimization, schema design, indexing, and security. Based on Supabase best practices.
-
mk-organization-1 Skill Springboot VerificationVerification loop for Spring Boot projects: build, static analysis, tests with coverage, security scans, and diff review before release or PR.
-
lobbi-docs Skill M365 AuditorDesign Microsoft 365 audit log query specifications and compliance reporting for FINRA, state insurance examiner, and internal audit requirements in financial services tenants.
-
lobbi-docs Skill Audit TrailDesign audit log specifications for regulated business processes. Use when a workflow requires a defensible audit trail for FINRA examinations, state insurance audits, SOX controls testing, or internal compliance reviews.
-
lobbi-docs Skill Workflow AuditGenerate audit trail specifications for regulatory compliance in insurance and financial services. Use when designing audit logging for FINRA, state insurance department, SOX, or internal compliance requirements.
-
lobbi-docs Skill Compliance CheckAudit a workflow or business process against insurance, mortgage, or financial services regulatory requirements. Use when a client workflow needs regulatory sign-off or when validating that a proposed automation meets compliance requirements before build.
-
lobbi-docs Skill Onedrive OrganizerDesign OneDrive for Business folder structure and governance policy specifications to ensure consistent file organization, security, and compliance for financial services firms.
-
lobbi-docs Skill Channels BootstrapProduction-ready channel server implementations — CI webhook receiver, mobile approval relay, Discord/Telegram bridge, and local fakechat dev profile. Copy-paste starter code with sender allowlists, permission relay, and security hardening.
-
lobbi-docs Skill Cc Security ComplianceSecurity & Compliance
-
lobbi-docs Skill Hook Script LibrarySecurity-hardened hook script implementations — ready-to-paste templates for security-guard, auto-format, inject-context, session-init, on-stop, and lessons-learned-capture
-
lobbi-docs Skill Permissions SecurityClaude Code Permissions & Security
-
lobbi-docs Skill Supply Chain SecurityThis skill should be used when triaging dependency advisories, code-scanning alerts, or committed secrets — reachability analysis, revoke-first remediation, provenance, and maintenance risk signals.
-
timsonner Skill EnterpriseEnterprise features and configuration for OpenCode - team deployment, security, and administration
Audited -
timsonner Skill DalfoxUse for tightly scoped XSS validation during authorized web assessments. Trigger on reflected or stored XSS candidate triage, payload verification, and repeatable retest of confirmed cross-site scripting weaknesses.
Audited -
elophanto Skill Report DistributionAutomates distribution of consolidated sales reports to representatives based on territorial parameters with audit trailing. Adapted from msitarzewski/agency-agents.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include powershell-security-hardening, meccha-chameleon-game-trainer-detection, minecraft-vape-client-security-analysis. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.