Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
the-nam-shub Skill Website Performance OptimizationHelps marketers audit and improve website technical performance, including page load speed and core web vitals, to reduce bounce rate and improve conversion.
-
openlabor Skill SecurityApplication security
-
zhouyinlong-lab Bundle Dog Project Evaluate三通道独立评估研究项目:课程作业完成度评分、论文投稿水平判定、开源项目成熟度审计。 输出含结论总表、分项评分、证据引用、决定性阻断项和升级路线图。 Trigger: 评估项目, 完成度, 大作业评分, 论文投稿, 开源成熟度, 能投什么会议, 仓库水平, 这个项目什么水平, evaluate project, course assignment, capstone, paper readiness, OSS maturity, repository audit, venue recommendation, acceptance probability, 毕业论文评估, 研究原型评估.
-
brucesongs Bundle CouncilCouncil provides a structured framework for analyzing security questions from multiple adversarial and defensive perspectives simultaneously.
-
brucesongs Bundle Web XssXSS (Cross-Site Scripting) is an attack that injects malicious scripts into trusted websites.
Audited -
brucesongs Bundle Repo ScanCross-stack source code asset audit that classifies every file, detects embedded third-party libraries, and delivers actionable verdicts per module.
-
brucesongs Bundle Browser QAAutomated browser-based security testing using Playwright and browser devtools. Interact with web applications as a user would — click, type, navigate — while monitoring network traffic, JavaScript execution, and DOM changes for security issues.
-
brucesongs Bundle Cps AttackCyber-Physical Systems (CPS) attacks — PLCs (Siemens S7, Rockwell ControlLogix, Schneider Modicon, Mitsubishi MELSEC), ICS protocols (Modbus, DNP3, Profinet, EtherNet/IP, IEC 61850, OPC UA), HMIs, SCADA historians, OT-to-IT pivot, SIS bypass. Distinct from scada-ics-security (broader ICS overview) — this skill goes deep on protocol-level PLC exploitation, packet replay/injection, and field-device firmware attacks. Covers 2024-2025 incidents (Unitronics PLC attack, Pipedream/Incontroller, multi-vendor PLC CVEs).
-
brucesongs Bundle Exa SearchSemantic search using Exa API for security research queries. Unlike keyword-based search, Exa understands context and retrieves high-quality, relevant results for technical research.
-
brucesongs Bundle Dns AttacksDNS Attacks exploit the Domain Name System protocol for reconnaissance, spoofing, tunneling, and data exfiltration. DNS is a foundational infrastructure service that is frequently misconfigured, poorly monitored, and trusted by default -- making it an ideal attack vector.
-
brucesongs Bundle API SecurityAPI Security Testing covers security assessment across three major API architectures: REST, GraphQL, and gRPC, focusing on the OWASP API Security Top 10 core risks: Broken Authentication, Broken Object Level Authorization (BOLA), Excessive Data Exposure, Rate Limiting Bypass.
-
brucesongs Bundle Terminal OpsEvidence-first execution workflow for running security commands, inspecting system state, debugging tool failures, and making verified changes. This skill enforces a disciplined approach: inspect before acting, keep changes narrow, and report exact execution state.
-
brucesongs Bundle Tool MasteryVerification and assessment of practical proficiency with Kali Linux security tools. Covers tool classification, proficiency levels, verification methods, and combination strategies across the 518-tool Kali arsenal.
Audited -
brucesongs Bundle Wifi PentestWiFi security assessment skills: covering wireless network reconnaissance, WPA/WPA2 handshake capture and offline cracking, WPS PIN brute forcing, Evil Twin attacks, wireless sniffing, and deauthentication attacks.
-
brucesongs Bundle Darkweb IntelDark web intelligence gathering — Tor/onion service reconnaissance, marketplace monitoring, breach data markets, threat actor profiling, with strict OPSEC for investigators.
-
brucesongs Bundle SteganographySteganography is the practice of concealing data within non-secret carrier files such as images, audio, video, and documents. Unlike encryption, which makes data unreadable but visibly present, steganography hides the very existence of the hidden data.
-
brucesongs Bundle Crypto AttacksCryptographic Attacks target implementation flaws and algorithm weaknesses in encryption systems, covering OWASP A04: Cryptographic Failures.
-
brucesongs Bundle Macos SecuritymacOS red team and security assessment — SIP/TCC bypass, Endpoint Security framework, Apple Silicon/T2/M-series attacks, Mach-O analysis, Keychain extraction, MDM bypass, LaunchAgents/Daemons persistence, and macOS-native malware analysis.
-
brucesongs Bundle Threat HuntingProactive threat hunting — MITRE ATT&CK-mapped hunt hypotheses, Sigma detection engineering, SIEM query authoring (Splunk SPL, KQL, Lucene), and SOC workflow integration.
-
brucesongs Bundle Article WritingTransform technical findings into clear, structured written content: penetration test reports, vulnerability disclosures, security blog posts, and technical documentation.
-
brucesongs Bundle Blockchain Web3Blockchain & Web3 security — Solidity/Vyper smart contract auditing, DeFi attack vectors (flash loans, MEV, oracle manipulation), bridge attacks, wallet security, with tooling from Slither/Mythril/Foundry.
-
brucesongs Bundle Gitops SecurityAttacks against GitOps control planes (Argo CD, FluxCD, Jenkins X, Tekton, Fleet, Rancher) — repo impersonation, manifest tampering, RBAC bypass, sync-wave abuse, secret management compromise (Sealed Secrets / SOPS / External Secrets / Vault), cluster privilege escalation via Application/CRDs, and post-exploitation persistence through CRD backdoors. Covers 2024-2025 Argo CD CVEs (CVE-2022-24348, CVE-2024-21626, CVE-2024-32564), FluxCD CVE-2024-37286, and the Akuukam/Code Catalyst supply chain incidents.
-
brucesongs Bundle Insecure DesignInsecure Design (OWASP A06:2025) focuses on security flaws in system architecture and design phases, rather than code implementation-level bugs.
-
brucesongs Bundle Mobile SecurityMobile security covers the complete attack/defense chain of Android/iOS application security testing, APK/IPA reverse engineering, runtime manipulation, certificate pinning bypass, and mobile data protection.
Audited -
brucesongs Bundle Security ReviewComprehensive security checklist and review patterns for analyzing applications, configurations, and infrastructure. This skill provides structured review methodology to identify vulnerabilities across OWASP Top 10 categories during penetration testing.
-
brucesongs Bundle Payment SecurityPayment systems security — PCI-DSS compliance testing, payment API security (Stripe/Adyen/PayPal), EMV chip/PIN, 3-D Secure, mobile wallets (Apple Pay/Google Pay), and fraud system assessment.
-
brucesongs Bundle 5g Telecom Attack5G core (AMF/SMF/UPF), RAN, signaling (PFCP/GTP/Diameter/SS7), IMSI catchers, O-RAN security, roaming abuse, SMS interception, and telecom infrastructure red team operations.
-
brucesongs Bundle Hardware SecurityHardware and embedded system security testing covering physical interface exploitation, firmware extraction and analysis, side-channel attacks, RFID/NFC cloning, and fault injection.
-
brucesongs Bundle Verification LoopAfter discovering a potential vulnerability or exploit - Before submitting any finding to a report or bounty platform - When verifying that a remediation or patch is effective - When cross-checking automated scanner results - User says "verify", "confirm", "validate.
Audited -
brucesongs Bundle Logging MonitoringSecurity logging and monitoring deficiencies (OWASP A09:2021) refer to applications failing to properly record security events or lacking effective monitoring, resulting in attacks going undetected, malicious activities being untraceable.
-
brucesongs Bundle Scada Ics SecuritySCADA/ICS security assessment covering industrial control system protocols including Modbus TCP, S7comm (Siemens), DNP3, EtherNet/IP (CIP), OPC UA, BACnet, and GOOSE.
-
brucesongs Bundle Uav Drone SecurityUAV/drone security testing — PX4/ArduPilot autopilot attacks, MAVLink protocol fuzzing, RF link hijacking (2.4GHz control / 5.8GHz video), GPS spoofing/jamming, DroneSploit framework, DJI hardware reversing, and counter-UAS methodologies.
-
brucesongs Bundle Web Access ControlBroken Access Control (OWASP Top 10 2025 - A01) attacks and defense — covering core attack surfaces including IDOR (Insecure Direct Object Reference), vertical/horizontal privilege escalation, path traversal, and permission bypass.
-
brucesongs Bundle Cms Framework AttackTargeted security assessment of Content Management Systems (WordPress, Joomla, Drupal) using specialized scanners and exploit techniques.
-
brucesongs Bundle Game Anticheat BypassSecurity research on game anti-cheat systems (EAC/BattlEye/Vanguard/Ricochet) — kernel-mode driver architecture, BYOVD attacks, memory access interception, integrity check evasion, and defense-side anti-cheat engineering.
-
brucesongs Bundle Supply Chain SecuritySoftware supply chain security covering the entire lifecycle from code development to deployment: dependency vulnerabilities (known-vulnerable third-party packages), malicious packages (injection and typosquatting.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include website-performance-optimization, Security, Dog-Project-Evaluate. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.