Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
brucesongs Bundle Satellite Leo SecuritySatellite and LEO communication security — Starlink, Kuiper, OneWeb, Iridium, Inmarsat, Viasat KA-SAT, HughesNet, DVB-S/S2, VSAT (iDirect/Hughes), GNSS receiver attacks, AcidRain wiper (Viasat 2022)
-
brucesongs Bundle Security Bounty HunterHunt for exploitable, bounty-worthy security issues in target systems. Focuses on remotely reachable vulnerabilities that qualify for real reports and responsible disclosure, not broad best-practices reviews or theoretical findings.
-
brucesongs Bundle Vulnerability AssessmentVulnerability assessment is the process of systematically identifying and quantifying security weaknesses in information systems through automated scanning, CVE analysis, and risk scoring.
-
brucesongs Bundle Physical Security TestingPhysical penetration testing covering mechanical lock bypass (pin-tubular/wafer), RFID/NFC badge cloning (Proxmark3/ESP-RFID-Tool/Walrus), HID iCLASS/Mifare duplication, drop box deployment (LAN Turtle/Packet Squirrel), USB weapons (Rubber Ducky/Bash Bunny), hidden camera placement, and on-site engagement operations including tailgating pretext preparation and physical-docs legal templates.
-
brucesongs Bundle Security MisconfigurationSecurity misconfiguration detection (OWASP A02:2025) covering default credentials, unnecessary services, verbose errors, missing security headers, and directory listing exposures across deployed systems.
-
brucesongs Bundle Automotive Vehicle SecurityCAN/CAN-FD bus analysis, UDS diagnostics, IVI pentest, OBD-II exploitation, key fob replay/relay attacks, GNSS spoofing, EV charging station (ISO 15118), and connected vehicle red team operations.
-
brucesongs Bundle Eu AI Act Compliance RedteamEU AI Act (Regulation (EU) 2024/1689) compliance-focused red team testing for high-risk AI systems — Article 9 adversarial testing, Annex III classification, Annex IV technical documentation, conformity assessment, and Notified Body audit preparation. Enforceable since 2 August 2026 with fines up to €35M or 7% global turnover.
-
brucesongs Bundle Threat Intel Platform AttackAttacking threat intelligence platforms (MISP, OpenCTI, Anomali ThreatStream, ThreatQuotient, ThreatConnect, IBM Threat Intel, Palo Alto AutoFocus, Mandiant Advantage). Covers platform CVEs (MISP CVE-2022-29527, OpenCTI vulnerabilities), API abuse, sharing-group trust abuse, false-positive IOC injection, STIX/TAXII feed manipulation, and supply-chain attacks via poisoned TI feeds. Use when testing threat-intel platform security, validating IOC sharing trust models, or simulating APT feed-poisoning campaigns.
-
brucesongs Bundle Post Quantum Migration AttackAttacks against cryptographic systems during the PQC migration period. Covers Harvest-Now-Decrypt-Later (SNDL/HNDL), hybrid PQC downgrade abuse, KEM combiner flaws, mixed-protocol failures, NIST PQC standard implementations (ML-KEM/Kyber, ML-DSA/Dilithium, SLH-DSA/SPHINCS+), and QKD infrastructure attacks. Use when reviewing cryptographic agility, hybrid deployments, or preparing for quantum threat readiness.
-
nexscope-ai Bundle Ecommerce Ozon Seller ProductsMPSTATS Ozon Russia seller drill-down product list by seller ID. Returns all SKUs under a seller with complete metrics: sales, revenue, price, rating, stock, turnover, lost revenue, supporting multi-dimensional numeric filters, sorting, and currency conversion. Use for store structure analysis, seller bestseller analysis, competitor store benchmarking. Trigger when the user mentions Ozon seller products, Ozon store analysis, Ozon seller drill-down, Ozon seller SKUs, Ozon store bestsellers, Ozon competitor store, MPSTATS seller, Ozon seller drill-down, Ozon shop audit, Russian marketplace seller SKUs, Ozon store structure. Also trigger when the intent is to view all products and their sales performance under an Ozon seller ID, even without explicitly mentioning MPSTATS.
-
nexscope-ai Bundle Ecommerce Ruiguan Gun Parts SearchCheck product images against a database of policy-violating items using visual similarity matching. Triggered when users mention policy compliance check, product image compliance review, violation detection, prohibited product screening, image-based compliance audit, pre-listing risk screening, or product image risk check. Even if the user does not explicitly say "compliance," this skill should be triggered whenever the need involves comparing product images against a violation database.
-
nimadorostkar Skill ContainersUse when building or debugging container images. Covers multi-stage builds, layer caching, image size, non-root users, signal handling, and the security defaults most Dockerfiles get wrong.
-
nimadorostkar Skill Secure CodingUse when writing code that handles untrusted input, authentication, or sensitive data. Covers injection prevention, authentication and session handling, authorization, cryptography, and the defaults that make code safe by construction.
-
nimadorostkar Skill Code ReviewUse when reviewing a pull request, diff, or branch. Produces severity-ranked findings covering correctness, security, performance, and maintainability, with concrete fixes rather than opinions.
-
handsomeboy990 Bundle Security AuditSecurity Audit
-
handsomeboy990 Bundle Security CoreSecurity Core
-
handsomeboy990 Bundle Security TestingSecurity Testing
-
handsomeboy990 Bundle Threat ModelingThreat Modeling
-
handsomeboy990 Bundle Security HeadersSecurity Headers
-
handsomeboy990 Bundle Session SecuritySession Security
-
handsomeboy990 Bundle Dependency SecurityDependency Security
-
handsomeboy990 Bundle Authorization DesignAuthorization Design
-
handsomeboy990 Bundle Authorized PentestingAuthorized Pentesting
-
handsomeboy990 Bundle Security ArchitectureSecurity Architecture
-
handsomeboy990 Bundle Authentication SecurityAuthentication Security
-
handsomeboy990 Bundle Vulnerability AssessmentVulnerability Assessment
-
robomotionio Bundle Fp CheckSystematically verifies suspected security bugs to eliminate false positives. Produces TRUE POSITIVE or FALSE POSITIVE verdicts with documented evidence for each bug.
-
robomotionio Bundle Yara Rule AuthoringGuides authoring of high-quality YARA-X detection rules for malware identification. Use when writing, reviewing, or optimizing YARA rules. Covers naming conventions, string selection, performance optimization, migration from legacy YARA, and false positive reduction. Triggers on: YARA, YARA-X, malware detection, threat hunting, IOC, signature, crx module, dex module.
-
minimax-ai Bundle Due Diligence当用户需要对目标公司做法律尽职调查时使用——同义场景词包括「尽调」「法律尽调」 「尽职调查」「投资前帮我查查这家公司」「收购前尽调」「尽调问题清单」 「帮我看看这家公司有什么法律风险」「出一份尽调报告」。本技能是法律尽调全流程 编排器:matter-workspace 建档 → 按尽调目的裁剪问题清单(references/ diligence-checklist.md,确认门)→ 资料清单请求并标注缺失 → 调 tabular-review 执行 N 文档 × M 问题网格 → Flags 双轴分级汇总(红线三段式 blocks/work-but-ships/FYI)→ 尽调报告骨架成稿 → citation-audit 清零后才可 发出。不下投资结论,不做财务/税务尽调,不替代律师现场核查。
12.9k -
minimax-ai Skill Citation Audit当任何产物(备忘录、清单、报告、合同修改建议、brief)即将对外发出——发送给 相对方、提交法院/仲裁/监管机关、或用于签署——时触发执行引用审计门禁。本技能 是库技能,通常由其他技能在交付前调用而非使用者直接发起:扫描 [CITE:__] 残留、 核全部法条与案例引用已过 statute-verify/case-verify、检查来源标注符合词汇表、 确认法域声明与保密标头档位匹配,输出 PASS/FAIL 与问题清单,FAIL 时给出逐项 修复路径。
12.9k -
minimax-ai Skill Session HandoffAt session end, write a structured handoff file so next session can pick up in 30 seconds. USE WHEN: user says "今天先到这" / "done for today" / "see you tomorrow" / "we'll continue later" / "下次再继续" / "end session" / "收尾", context about to compact, long task in progress, natural pause approaching (end of work day, end of milestone), sub-task in flight that outlives this session. TRIGGER PHRASES: "今天先到这", "done for today", "see you tomorrow", "we'll continue later", "下次再继续", "先到这", "end session", "session 结束", "收尾", "写到 handoff file", "wrap up", "session handoff", "session 接力". SKIP WHEN: session just started (no in-progress work to hand off), work is fully complete and verified (completion-audit passed), user said "throw it all away, start fresh next time" / "全部扔掉".
Audited 12.9k -
minimax-ai Skill Completion AuditBefore saying "done", derive requirements, find authoritative evidence, verify each is ✅. USE WHEN: about to say "done" / "complete" / "ship it" / "I finished" / "做完了" on non-trivial task, about to mark `todowrite` step done, about to update goal to `complete`, user has been waiting for "done" for several turns, "looks good" / "should be fine" / "应该好了" / "我试过没报错" / "我跑了测试都过了" / "I tested it" / "trust me" / "should work". TRIGGER PHRASES: "做完了", "done", "complete", "ship it", "好了", "完成", "搞定", "I think we're done", "应该好了", "looks good", "我试过没报错", "我跑了测试都过了", "I tested it", "trust me", "should work". SKIP WHEN: one-line edit, user can see result in chat immediately, user explicitly said "ship it" / "no more review" in this turn.
Audited 12.9k -
poorvith-mp Bundle Code ReviewReview a change for correctness, performance, security, readability, coverage and architectural fit. Use when reviewing pull requests, diffs, or commits before merging.
-
poorvith-mp Bundle Audit ReadinessPrepare for SOC 2, ISO 27001, HIPAA or PCI-DSS: control mapping, gap analysis and evidence. Use when preparing evidence and technical controls for SOC 2 or ISO 27001.
-
poorvith-mp Bundle Appsec ArchitectMoved to security-review in skills-developer. Removed in v4.1.
-
poorvith-mp Bundle Dependency AuditCheck dependencies for CVEs, license conflicts and breaking-change risk before upgrading. Use when scanning dependencies for CVEs, license conflicts, or supply-chain risks.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include session-handoff, appsec-architect, satellite-leo-security. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.