Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
elophanto Bundle VulnhunterSecurity vulnerability detection and variant analysis skill. Use when hunting for dangerous APIs, footgun patterns, error-prone configurations, and vulnerability variants across codebases. Combines sharp edges detection with variant hunting methodology.
Audited -
elophanto Skill Security EngineeringExpert application security engineer specializing in threat modeling, vulnerability assessment, secure code review, and security architecture design. Adapted from msitarzewski/agency-agents.
-
elophanto Skill Smart Contract AuditUse when reviewing a Solidity, Vyper, or Rust (Solana/Anchor) smart contract for paid audit work or pre-launch sanity check. Covers reentrancy, oracle manipulation, access control, signature replay, integer/precision, donation/share-inflation, and protocol-specific risks. Outputs a findings report with severity, impact, PoC sketch, and remediation. Includes outreach templates for direct-to-protocol paid engagements.
-
elophanto Skill Autonomous OptimizationIntelligent system governor that continuously shadow-tests APIs for performance while enforcing strict financial and security guardrails against runaway costs. Adapted from msitarzewski/agency-agents.
-
elophanto Skill 12 Principles Of AnimationAudit animation code against Disney's 12 principles adapted for web. Use when reviewing motion, implementing animations, or checking animation quality. Outputs file:line findings.
Audited -
elophanto Skill Runbook Enterprise FeatureEnterprise feature development runbook — adding major features to existing products with compliance, security, and quality gates. Adapted from msitarzewski/agency-agents.
-
mariourquia Bundle Funds Flow CalculatorCalculate and verify funds flow, prorations, wire instructions, and the settlement statement for CRE acquisition closings. Branches by all-cash vs. financed (single tranche vs. multiple), 1031 exchange proceeds, number of funding sources, and proration method (per diem vs. actual/365 vs. 30/360). Triggers on 'funds flow', 'prorations', 'settlement statement', 'wire instructions', 'cash to close', 'net proceeds', 'security deposit transfer', 'closing statement', 'ALTA statement', or when given a closing date, rent roll, tax bill, and purchase price.
-
mariourquia Bundle Lease Compliance AuditorUnified lease administration compliance audit covering CAM reconciliation, percentage rent verification, insurance tracking, escalation audits, and environmental compliance. Quantifies revenue recovery opportunities with probability-weighted waterfall analysis. Triggers on 'audit lease compliance', 'CAM reconciliation', 'percentage rent audit', 'insurance certificates', or property disposition/refinancing prep.
-
mariourquia Bundle Investor Lifecycle ManagerLP lifecycle management: investor meetings, benchmark comparison, cash management, audit coordination, re-up solicitation, GIPS composites, satisfaction tracking. Triggers: investor meeting, LP relations, benchmark, NCREIF, ODCE, audit PBC, re-up, GIPS, capital call, distribution, investor reporting.
-
mariourquia Bundle Cam Reconciliation CalculatorCalculates annual CAM reconciliation for multi-tenant commercial properties. Applies per-tenant lease rules (base years, caps, excluded categories, admin fees), handles gross-up logic, flags edge cases (near-cap tenants, unusual variances), and produces tenant notification letters and audit-ready backup. Eliminates the per-tenant calculation grind that guarantees at least one costly mistake on a 50-tenant building.
-
timsonner Skill SeatbeltUse for Windows host situational awareness and security posture enumeration during authorized pentests. Trigger on approved Windows host review, local configuration inspection, and identifying material privilege or credential exposure on a specific system.
-
timsonner Skill Pentest Attack PatternsReference document containing common attack patterns, payloads, and exploitation techniques for penetration testing including exploit research methodology, web application attacks, command injection, path traversal/LFI, XSS, XXE, SSRF, reverse shells, privilege escalation, password cracking, Windows exploitation, network attacks, database attacks, wireless attacks, and references.
-
timsonner Skill Owasp ZapUse for OWASP-focused web and API testing during authorized pentests. Trigger on proxy-based web review, automated or manual scan support, baseline OWASP Top 10 coverage, and validating application security controls with a lighter-weight interception workflow.
Audited -
timsonner Skill SearchsploitUse for exploit and vulnerability reference research during authorized pentests. Trigger on confirmed product versions, CVE review, exploitability triage, and mapping known issues to observed services without running exploit code.
Audited -
timsonner Skill Tool SelectionSelect pentest tools by methodology phase, target type, and risk tolerance. Use for deciding whether to use amass, subfinder, nmap, owasp-zap, wfuzz, dirb, dnsrecon, netcat, linpeas, winpeas, metasploit-framework, and related tools during authorized assessments.
Audited -
timsonner Skill Metasploit FrameworkUse for controlled auxiliary scanning, exploit research, and narrowly bounded validation during authorized pentests. Trigger on approved module-driven checks, repeatable proof paths, and situations where a framework-managed workflow is safer than ad hoc execution.
Audited -
timsonner Skill Linux Exploit SuggesterUse for Linux kernel and local-exposure suggestion review during authorized pentests. Trigger on approved Linux host analysis, kernel-version triage, and identifying which local privilege-escalation vectors may merit manual validation.
-
mahmoud20138 Skill Code ReviewReviews code changes using CodeRabbit AI. Use when user asks for code review, PR feedback, code quality checks, security issues, or wants autonomous fix-review cycles.
-
matteotitta Skill Content AuditContent audit
-
matteotitta Skill Metadata Lint<!-- Sourced from ibelick/ui-skills (MIT). https://github.com/ibelick/ui-skills/blob/main/skills/fixing-metadata/SKILL.md. See../../../meta/catalog/design-reviewer/NOTICE.md for the MIT attribution block. -->
-
matteotitta Skill Website ScoreWebsite PM Score
-
matteotitta Skill Linkedin Algo AuditLinkedIn Algo Audit
-
matteotitta Skill Signup Onboarding AuditSignup Onboarding Audit
-
matteotitta Skill Product PulseProduct pulse — single-page metrics report
-
matteotitta Skill Linkedin Content AuditLinkedIn Content Audit
-
dasexperten Bundle UX AuditUX Audit
-
dreamlab-ai Bundle Verification QualityVerify an installed artifact against the signed witness manifest via `ruflo verify`, and read the real in-CI regression-guard stack (smoke tests, discoverability audit, cryptographic witness, temporal history). Use when you need to check that documented fixes are still present in the tree, or to understand what's actually enforced in CI vs. designed-but-unshipped. Not for per-file truth scoring, confidence thresholds, or auto-rollback — that surface is design only, see references/design-aspirational.md.
-
tuanductran Bundle Hr AuditHelp HR and compliance teams plan and conduct HR audits, including policy compliance reviews, I-9/documentation audits, pay equity checks, and process audits. Use when asked to conduct an HR audit, audit HR compliance, review personnel files for compliance, build an HR audit checklist, or similar HR audit tasks.
-
tuanductran Bundle Hr PayrollHelp HR operations specialists, payroll administrators, and compensation teams understand, design, and run payroll processing, compliance, and payroll-related HR operations. Use when asked to set up a payroll process, run a payroll compliance audit, design a payroll calendar, handle a payroll discrepancy, build a payroll onboarding checklist, calculate overtime and statutory deductions, design a multi-country payroll process, or any payroll administration, compliance, and operations task.
-
tuanductran Bundle Hr AI EthicsHelp HR and compliance teams govern the ethical use of AI in HR processes, including algorithmic fairness in hiring, bias auditing, AI transparency, accountability frameworks, and ethical AI policy design. Use when asked to audit AI bias in hiring, design ethical AI guidelines for HR, assess algorithmic fairness, build an AI ethics policy, govern AI use in performance management, or address bias in our AI tools.
-
tuanductran Bundle Hr AI PrivacyHelp HR and compliance teams protect employee data privacy in AI-driven HR systems, including GDPR compliance, data minimization, employee consent design, and privacy risk assessment for HR AI tools. Use when asked to protect employee data in AI systems, design HR AI privacy policies, assess privacy risks of AI tools, build employee consent for AI, comply with GDPR for HR AI, or audit HR data privacy.
-
tuanductran Bundle Hr ComplianceHelp HR managers with HR compliance and workplace policies. Use when asked to write an employee handbook, develop OSHA compliance, manage EEO compliance, handle FMLA, conduct a compliance audit, create background check policies, develop immigration compliance strategies, or any HR compliance task.
-
tuanductran Bundle Hr Job AnalysisHelp HR teams, job analysis for compensation analysts, and job design specialists conduct job analysis, define job requirements, and document job content for job evaluation, classification, and workforce planning purposes. Use when asked to conduct a job analysis, define job requirements, write job content, classify a role, evaluate job complexity, run a task analysis, or audit our job structures.
-
tuanductran Bundle Hr AI GovernanceHelp HR and compliance teams govern the responsible use of AI in HR processes, including hiring algorithms, monitoring tools, and policy design. Use when asked to design an AI governance policy for HR, assess bias risk in a hiring algorithm, write an AI use policy for HR, audit an HR AI tool, or similar HR AI governance tasks.
-
tuanductran Bundle Hr Time AttendanceHelp HR and payroll teams design, audit, and communicate time and attendance policies, including clock-in rules, overtime, leave tracking, and time-tracking system configuration. Use when asked to set up a time tracking policy, calculate overtime, design a shift attendance policy, write a lateness policy, or similar time and attendance tasks.
-
tuanductran Bundle Hr Job ArchitectureHelp HR business partners, compensation specialists, and total rewards leaders understand, design, and implement job architecture frameworks including job families, career levels, leveling criteria, and career pathing structures. Use when asked to build a job leveling framework, design a career ladder, create job families, define leveling criteria, audit our job titles, build a career path, standardize roles across teams, design a grade structure, benchmark roles against the market, or any job architecture, career leveling, and role standardization task.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include vulnhunter, security-engineering, smart-contract-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.