Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
iblai Skill Iblai Vibe Security Owasp AuditAudit application source code against the OWASP Top 10 vulnerability categories. Use when the user mentions 'OWASP,' 'security audit,' 'code security review,' 'vulnerability audit,' 'find vulnerabilities,' 'secure code review,' 'security review,' or wants to check their codebase for common security weaknesses.
-
iblai Skill Iblai Vibe Security Disk ForensicsAnalyze disk images and file systems for digital evidence recovery in forensic investigations and CTF challenges. Use when the user mentions 'disk forensics,' 'forensic analysis,' 'disk image,' 'file carving,' 'deleted files,' 'evidence recovery,' 'autopsy,' 'sleuthkit,' or needs to examine a forensic image.
-
iblai Skill Iblai Vibe Security Incident TriageGuide rapid triage and initial response to security incidents following NIST SP 800-61 methodology. Use when the user mentions 'incident response,' 'security incident,' 'triage,' 'we've been hacked,' 'breach,' 'compromised,' 'malware detected,' 'suspicious activity,' 'IOC,' 'indicators of compromise,' or needs help handling a security event.
-
iblai Skill Iblai Vibe Security Dependency AuditAudit project dependencies, frameworks, languages, and dev tools for known vulnerabilities, CVEs, and security anti-patterns. Use when the user mentions 'dependency audit,' 'npm audit,' 'CVE,' 'vulnerable packages,' 'supply chain security,' 'outdated dependencies,' 'known vulnerabilities,' 'security advisory,' 'package security,' 'framework vulnerability,' 'is this package safe,' or needs to check whether their stack has known security issues.
-
dirnbauer Bundle Competitor ProfilingWhen the user wants to research, profile, or analyze competitors from their URLs. Also use when the user mentions 'competitor profile,' 'competitor research,' 'competitor analysis,' 'profile this competitor,' 'analyze competitor,' 'competitive intelligence,' 'competitor deep dive,' 'who are my competitors,' 'competitor landscape,' 'competitor dossier,' 'competitive audit,' or 'research these competitors.' Input is a list of competitor URLs. Output is structured competitor profile markdown files. For creating comparison/alternative pages from profiles, see competitors. For sales-specific battle cards, see sales-enablement.
-
junmystery Skill Mobile Application Security Cheat SheetMobile Application Security Cheat Sheet
Audited -
junmystery Skill HTTP Strict Transport Security Cheat SheetHTTP Strict Transport Security Cheat Sheet
-
junmystery Skill Software Supply Chain Security Cheat SheetSoftware Supply Chain Security
-
junmystery Skill Infrastructure As Code Security Cheat SheetInfrastructure as Code Security Cheatsheet
-
junmystery Skill Browser Extension Vulnerabilities Cheat SheetBrowser Extension Security Vulnerabilities Cheat Sheet
-
junmystery Skill Choosing And Using Security Questions Cheat SheetChoosing and Using Security Questions Cheat Sheet
-
junmystery Skill Microservices Based Security Arch Doc Cheat SheetMicroservices based Security Arch Doc Cheat Sheet
-
calesthio Bundle Cartesia SonicUse Cartesia Sonic and related Cartesia voice APIs for production speech: text-to-speech, realtime WebSocket TTS, voice selection, instant and professional voice cloning, pronunciation/language/emotion controls, voice localization, voice changer, pricing/concurrency planning, privacy/security review, and QA for narration, ads, localization, dubbing, avatars, and interactive voice agents.
-
runxhq Bundle LedgerAnswer a cross-run audit question against the receipt ledger, returning matched receipts and a chain-verification result.
-
runxhq Bundle Cve AuditAudit exact npm dependency versions against OSV through Runx native HTTP and emit replay-verified evidence with no unverified findings.
-
runxhq Bundle Audit ReceiptAudit a sealed runx receipt for governance, comparing exercised authority and any declared approval requirement with signed evidence, and flag over-reach, approval inconsistency, unrecorded refusals, or exposed secret material.
-
saeed-vayghan Bundle Wordpress MasterElite WordPress architect specializing in full-stack development, performance optimization, and enterprise solutions. Masters custom theme/plugin development, multisite management, security hardening, and scaling WordPress from small sites to enterprise platforms handling millions of visitors.
-
saeed-vayghan Bundle Backend DeveloperSenior backend engineer specializing in scalable API development and microservices architecture. Builds robust server-side solutions with focus on performance, security, and maintainability.
-
saeed-vayghan Bundle Compliance AuditorExpert compliance auditor specializing in regulatory frameworks, data privacy laws, and security standards. Masters GDPR, HIPAA, PCI DSS, SOC 2, and ISO certifications with focus on automated compliance validation and continuous monitoring.
-
saeed-vayghan Bundle Dependency ManagerExpert dependency manager specializing in package management, security auditing, and version conflict resolution across multiple ecosystems. Masters dependency optimization, supply chain security, and automated updates with focus on maintaining stable, secure, and efficient dependency trees.
-
saeed-vayghan Bundle Incident ResponderExpert incident responder specializing in security and operational incident management. Masters evidence collection, forensic analysis, and coordinated response with focus on minimizing impact and preventing future incidents.
-
saeed-vayghan Bundle Penetration TesterExpert penetration tester specializing in ethical hacking, vulnerability assessment, and security testing. Masters offensive security techniques, exploit development, and comprehensive security assessments with focus on identifying and validating security weaknesses.
-
saeed-vayghan Skill Ad Security ReviewerActive Directory security specialist analyzing identity configuration, privileged group design, delegation, authentication policies, legacy protocols, and attack-surface exposure across enterprise domains.
-
saeed-vayghan Bundle Blockchain DeveloperExpert blockchain developer specializing in smart contract development, DApp architecture, and DeFi protocols. Masters Solidity, Web3 integration, and blockchain security with focus on building secure, gas-efficient, and innovative decentralized applications.
-
saeed-vayghan Skill Powershell Security HardeningSecurity-focused PowerShell specialist skilled in hardening Windows systems, securing automation, enforcing least privilege, and aligning scripts with enterprise security baselines and compliance frameworks.
-
ever-just Skill UI UX AuditUI/UX Audit for app.customagents.io Dashboard
-
ever-just Skill Verification AuditVerification Audit
-
ever-just Skill Mongodb Schema AuditMongoDB Schema Auditing & Migration
-
ever-just Skill Ad Transparency AuditAd Transparency Audit
-
nirholas Skill Restaking ExplainedGuide to restaking and liquid restaking tokens (LRTs) — EigenLayer, restaking mechanics, operator selection, risk analysis, and the restaking ecosystem. Use when explaining restaking concepts, evaluating LRT protocols, or helping users understand EigenLayer and AVS security.
Audited -
nirholas Skill Yield Farming AnalysisAnalyze DeFi yield farming opportunities including APY breakdown, risk assessment, smart contract security, and impermanent loss estimation.
Audited -
nirholas Skill Rug Pull DetectionIdentify potential rug pull and scam indicators in crypto projects by analyzing contract code, team behavior, liquidity locks, and tokenomics red flags before investing.
Audited -
nirholas Skill Binance Token AuditQuery token security audit via Binance Web3 API to detect scams, honeypots, and malicious contracts before trading. Returns comprehensive security analysis including contract risks, trading risks, and scam detection across BSC, Base, Solana, and Ethereum.
Audited -
nirholas Skill Cross Chain Bridge GuideGuide to cross-chain bridges — bridge architectures, trust assumptions, security risks, major bridges comparison, and bridging best practices. Covers Stargate, Across, Hop, Wormhole, and official L2 bridges. Use when helping users move assets between chains safely.
Audited -
nirholas Skill Stablecoin Risk AnalysisEvaluate stablecoin safety by analyzing peg mechanisms, reserve composition, audit transparency, regulatory exposure, and depegging history to assess holding and usage risk.
Audited -
nirholas Skill Mev Protection GuideGuide to MEV (Maximal Extractable Value) — sandwich attacks, frontrunning, backrunning, and how to protect transactions. Use when explaining MEV to users, recommending swap protection, or analyzing suspicious transaction patterns.
Audited
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include iblai-vibe-security-owasp-audit, iblai-vibe-security-disk-forensics, iblai-vibe-security-incident-triage. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.