Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
cwinvestments Skill Memstack Security Git GuardUse when the user says 'git-guard', 'check git protection', 'is this repo protected', 'verify gitleaks', 'set up git hooks', 'install git-guard', or wants to confirm a repo blocks secrets and internal files before commit. This is an installer and verifier, NOT a scanner (gitleaks does the actual scanning). Do NOT use for deep secret audits or RLS work.
-
cwinvestments Skill Memstack Security Csp HeadersUse this skill when the user says 'CSP', 'Content-Security-Policy', 'security headers', 'HSTS', 'X-Frame-Options', 'clickjacking', 'unsafe-inline', 'unsafe-eval', or needs to audit, generate, or fix HTTP security headers for a web application. Do NOT use for API route audits or dependency scanning.
Audited -
cwinvestments Skill Memstack Security Owasp Top10Use this skill when the user says 'OWASP audit', 'OWASP top 10', 'security audit', 'vulnerability assessment', 'full security check', or needs a comprehensive web application security review against OWASP Top 10 categories. Do NOT use for dependency audits or secret scanning alone.
Audited -
cwinvestments Skill Memstack Security Rls CheckerUse this skill when the user says 'check RLS', 'audit RLS', 'RLS policies', 'row level security', 'Supabase security audit', or needs to verify table-level access control. Audits Supabase Row Level Security policies across all tables. Do NOT use for non-Supabase projects or writing RLS policies from scratch.
Audited -
yuniorglez Bundle Convex ProSenior Backend Architect for Convex.dev (2026). Specialized in reactive database design, type-safe full-stack synchronization, and hardened authorization patterns. Expert in building low-latency, real-time applications using Convex v2+ features like RLS (Row Level Security), HTTP Actions, File Storage, and advanced indexing.
-
yuniorglez Bundle Auditor ProSenior Security Engineer & Forensic Analyst. Expert in AI-driven vulnerability scanning, CTEM standards, and agentic security orchestration.
-
yuniorglez Bundle Security Audit ProSenior Data Security Architect & Forensic Auditor for 2026. Specialized in Row Level Security (RLS) enforcement, Zero-Trust database architecture, and automated data access auditing. Expert in neutralizing unauthorized access in Convex, Supabase, and Postgres environments through strict policy validation, JIT (Just-in-Time) access controls, and forensic trace analysis.
-
ynitto Bundle Dependency Auditor依存関係のセキュリティ脆弱性・ライセンス適合性・最新性を監査するスキル。「依存関係を監査して」「パッケージの脆弱性を確認して」「ライセンスを確認して」「古いライブラリを調べて」「npm auditして」「依存関係のセキュリティチェック」「CVEを確認して」「ライセンス違反がないか確認して」「サプライチェーンリスクを調べて」などで発動する。npm/pip/cargo/go/gem/maven/gradle など主要パッケージマネージャーに対応する。
-
hwj123hwj Bundle Writing BeatsWriting, exploit — assemble raw material into a journey of beats, grounding each term before a beat leans on it.
-
scandit Bundle Skill AuditorMaintainer tool for this repo. Use when the user wants to audit the skill catalog — check eval coverage ("which edge cases have no eval on <platform>?", "check eval coverage for <product>"), check cross-platform consistency ("are the sparkscan skills consistent?", "audit skill quality"), verify the routing table ("is the handoff table in sync?"), lint skill structure, refresh a product feature taxonomy, or run a full audit. Also use when a batch of new skills lands and the catalog needs re-validation, or before a release of the skill repo.
-
scandit Skill Audit Common Skill RulesUse when the user wants to verify that the universal trust-and-verification rules are present in every Scandit SDK skill in this repo. Triggered by "audit common skill rules", "check rule consistency across skills", or "audit skills for missing trust rules".
Audited -
vinayaklatthe Skill Defender TvmGuidance for Microsoft Defender Threat Intelligence (Defender TI) and Microsoft Defender Vulnerability Management (MDVM) — the threat-and-vulnerability layer of Defender XDR. Covers MDVM exposure score, CVE prioritization with threat insights and active campaigns, security baselines (CIS/STIG), browser-extension and certificate inventory, network share assessment, hardware/firmware inventory, security recommendations and remediation tasks (Intune integration), and Defender TI for adversary-tracked indicators, intel profiles, infrastructure pivoting, and MDTI APIs. WHEN: Defender Vulnerability Management, MDVM, MDVM add-on, exposure score, threat-aware vulnerability prioritization, CIS benchmark CVEs, security baselines assessment, browser extension inventory, firmware vuln, Microsoft Defender Threat Intelligence, MDTI, intel profiles, threat actor tracking, IOC pivoting, MDTI API, threat hunting with intel. DO NOT USE for endpoint EDR config (use defender-for-endpoint), Sentinel detections (use sentinel-detec
-
vinayaklatthe Skill Purview AuditGuidance for Microsoft Purview Audit (Standard and Premium) - logging and searching user/admin activity across Microsoft 365 for investigations and compliance. Covers tier differences, default and extended retention, high-value events, audit search UX, Office 365 Management Activity API / Microsoft Graph audit API, and Sentinel/SIEM integration. WHEN: Purview Audit, audit log search, Microsoft 365 audit, Audit Premium, investigate user activity, audit log retention, Microsoft Graph audit API, forensic logging, crucial audit events, MailItemsAccessed.
Audited -
vinayaklatthe Skill Passkeys Fido2Guidance for rolling out passkeys (device-bound and synced) and FIDO2 security keys in Microsoft Entra ID as the primary phishing-resistant authentication method. Covers passkey types (device-bound in Microsoft Authenticator, synced passkeys via platform providers, hardware security keys), Conditional Access authentication strength, registration campaigns, Temporary Access Pass (TAP) bootstrapping, lifecycle (lost device, attestation), Conditional Access requiring phishing-resistant MFA, decommissioning legacy methods (SMS, voice, weaker app push), and integration with Windows Hello for Business. WHEN: passkey rollout, FIDO2 keys, phishing-resistant MFA, Microsoft Authenticator passkey, device-bound passkey, synced passkey, Temporary Access Pass, TAP, Conditional Access authentication strength, kill SMS MFA, retire voice MFA, passwordless rollout, FIDO2 attestation, security key registration. DO NOT USE for general CA policy authoring (use conditional-access-mfa), Windows desktop sign-in design end-to-end (us
-
vinayaklatthe Skill Purview Dspm AIGuidance for Microsoft Purview Data Security Posture Management for AI (DSPM for AI) - discovering, monitoring, and protecting sensitive data interactions with generative AI apps like Microsoft 365 Copilot, Security Copilot, Copilot Studio agents, and third-party AI (ChatGPT, Gemini). Covers AI usage visibility, one-click recommendations, oversharing risk surfaced to AI, and DLP for AI. WHEN: DSPM for AI, AI data security posture, Copilot data risk, monitor AI prompts, sensitive data in AI, generative AI data protection, third-party AI usage visibility, secure Copilot data, what sensitive data is being sent to AI, monitor what users are putting into Copilot prompts, detect sensitive data in AI responses, ChatGPT data leakage risk. DO NOT USE when the goal is remediating overshared SharePoint content before Copilot rollout (use purview-copilot-oversharing) or building IRM policies for departing users (use insider-risk-baseline).
Audited -
vinayaklatthe Skill Purview For M365Guidance for applying Microsoft Purview data security and compliance across Microsoft 365 workloads (Exchange, SharePoint, OneDrive, Teams) - coordinating labels, DLP, retention, and Copilot data protection per workload with each workload's distinct behaviour. WHEN: Purview for Microsoft 365, protect SharePoint and Teams data, M365 compliance, labels and DLP across Office, retention for Exchange, Teams data security, OneDrive governance, Microsoft 365 data protection, per-workload Purview.
Audited -
vinayaklatthe Skill Intune Device MgmtGuidance for Microsoft Intune device management — enrollment, configuration, compliance, and security baselines across Windows, macOS, iOS/iPadOS, and Android. Covers Autopilot vs corporate-vs-BYOD enrollment, compliance policies that feed Conditional Access, Intune security baselines, update rings / Autopatch, and using filters and ring-based rollouts to avoid lockouts. WHEN: Microsoft Intune, MDM, device enrollment, Autopilot, Apple ABM, Android Enterprise, compliance policy, security baseline, configuration profile, settings catalog, manage devices, device compliance for Conditional Access, endpoint management, Windows Autopatch, update rings. DO NOT USE for app-only protection on BYOD (use intune-app-protection), endpoint detection / EDR (use defender-for-endpoint), or disk encryption only (use bitlocker-design).
Audited -
vinayaklatthe Skill Compromise RecoveryGuidance for responding to and recovering from a significant identity/tenant compromise - regaining administrative control, evicting the adversary in a single coordinated action, and hardening to prevent reentry. Covers trusted foundation (PAW), containment, eviction, identity recovery (krbtgt, federation), and post-eviction hardening. WHEN: compromise recovery, incident response, regain control after breach, evict attacker, tenant compromise, rebuild trust, ransomware recovery, post-breach hardening, kick out adversary, emergency response, attacker is in our tenant right now, ransomware hit our organisation, regain admin access after a breach, adversary has domain admin or Global Admin. DO NOT USE for routine SOC investigation (use defender-xdr / sentinel) or for preventive hardening with no active compromise (use security-architecture / entra-id).
-
vinayaklatthe Skill Insider Risk BaselineGuidance for establishing a Microsoft Purview Insider Risk Management (IRM) baseline - detecting and managing risky insider activity (data theft, leaks, policy violations) with privacy-by-design. Covers prerequisites, HR connector, policy templates, indicators, pseudonymisation, triage workflow, and Adaptive Protection integration. WHEN: Insider Risk Management, IRM, detect data theft by departing employee, insider threat, risky user activity, IRM policy templates, pseudonymization, Adaptive Protection, insider risk indicators, HR connector, departing user, separation of duties.
Audited -
vinayaklatthe Skill Defender For Office 365Guidance for Microsoft Defender for Office 365 (MDO) — protection for email and collaboration (Teams, SharePoint, OneDrive) against phishing, malware, spoofing, and business email compromise. Covers Plan 1 vs Plan 2 selection, preset security policies (Standard/Strict), Safe Links, Safe Attachments, anti-phishing impersonation protection, configuration analyzer drift detection, Submissions portal triage, Threat Explorer hunting, AIR, and attack simulation training. WHEN: Defender for Office 365, MDO, email security policy, Safe Links, Safe Attachments, anti-phishing, anti-spoofing, impersonation protection, preset security policies, Standard preset, Strict preset, configuration analyzer, phishing protection, attack simulation training, Threat Explorer, Submissions portal, tenant allow block list, BEC, business email compromise, DMARC, MDO Plan 1 vs Plan 2. DO NOT USE for endpoint protection (use defender-for-endpoint) or M365 oversharing (use purview-copilot-oversharing).
Audited -
vinayaklatthe Skill Purview Records ManagementGuidance for Microsoft Purview Records Management — declaring, managing, and disposing records across SharePoint, OneDrive, Exchange, and Teams. Covers retention labels with record / regulatory record options, file plan import, event-based retention (employee leaves, contract expires), disposition review (single- and multi-stage), proof of deletion / records of disposition, retention label policies vs auto-apply policies (KQL/sensitive info types/trainable classifiers), label-aware DLP, integration with Information Governance vs Records Management licensing, and role separation between records managers and admins. WHEN: records management Purview, file plan, retention label record, regulatory record, event-based retention, disposition review, record declaration SharePoint, immutable records, audit-proof deletion, file plan import. DO NOT USE for non-records data lifecycle (use purview-data-lifecycle), DLP policies (use purview-dlp-policy), or eDiscovery (use purview-ediscovery).
Audited -
vinayaklatthe Skill Windows 11 Security BaselineGuidance for the Windows 11 enterprise security baseline — Microsoft's recommended security settings deployed via Intune (Settings catalog / security baselines) or GPO. Covers core hardware-rooted controls (TPM 2.0, Secure Boot, virtualization-based security / VBS, Hypervisor-Protected Code Integrity / HVCI, Memory Integrity, Credential Guard, Local Security Authority protection), Windows LAPS (Microsoft's modern local admin password solution, replacement for legacy LAPS), Smart App Control, Personal Data Encryption (PDE), Windows Hello for Business deployment, controlled folder access, exploit protection, BitLocker baseline, app control with WDAC, removable storage controls, and integration with Intune compliance and Defender for Endpoint. WHEN: Windows 11 baseline, Windows security baseline, VBS HVCI Memory Integrity, Credential Guard, LSA protection, Windows LAPS, replace legacy LAPS, Smart App Control, WDAC, exploit protection, PDE Windows 11, Intune security baseline. DO NOT USE for endpoint EDR config (
-
vinayaklatthe Skill Purview Insider Risk ManagementGuidance for Microsoft Purview Insider Risk Management (IRM) — detect, investigate, and act on risky user activity (data theft by departing employees, intellectual property leaks, security policy violations) using signals from M365, Entra, Defender, Windows endpoints, HR systems, and Adaptive Protection. Covers policy templates (data theft by departing users, data leaks, security policy violations), HRIS connector setup, indicator selection, sequence detection, anomaly detection, alerts triage, case investigation with content explorer, integration with eDiscovery and Communication Compliance, Adaptive Protection's automatic DLP policy adjustment, privacy controls (pseudonymization), role separation, and tenant-allow-list. WHEN: insider risk management, IRM policy, data theft departing user, IP leak detection, HRIS connector Purview, Adaptive Protection, insider risk indicators, sequence detection Purview, IRM case investigation, IRM privacy controls, IRM pseudonymization, insider risk Sentinel. DO NOT USE for
-
chengyi818 Skill Trailofbits SecurityUse when CodeQL/Semgrep 静态分析,漏洞检测 - 驱动安全审计、内核模块漏洞扫描。
Audited -
chengyi818 Skill Security Best PracticesUse when 安全编码最佳实践,CodeQL/Semgrep 集成 - 驱动代码安全审计、内核模块漏洞扫描。
Audited -
cleanexpo Skill Audit TrailAudit Trail
-
cleanexpo Skill Finished Audit>
-
cleanexpo Skill Secret ManagementSecret Management
-
cleanexpo Bundle System Supervisor>-
-
cleanexpo Bundle Execution Guardian>-
-
cleanexpo Skill Audit Mode ClassifierSkill: audit-mode-classifier
-
frankxai Bundle Pair ProgrammingAI-assisted pair programming with multiple modes (driver/navigator/switch), real-time verification, quality monitoring, and comprehensive testing. Supports TDD, debugging, refactoring, and learning sessions. Features automatic role switching, continuous code review, security scanning, and performance optimization with truth-score verification. Use when pairing on code with driver/navigator roles, doing TDD, or wanting real-time review while building.
-
frankxai Bundle Starlight ChronicleThe reflective layer of the FrankX OS. A four-cadence practice — weekly Palace Review, monthly Survey, quarterly Constellation Census, annual Legacy Audit — that witnesses what's been built, blesses what is whole, and orients the next move from a sovereign vantage. Couples to /changelog as its factual underlayer. Use when invoking /palace, /chronicle, /bless, or when a Sunday reflection is requested.
-
aaronjmars Skill ShiplogRecap of everything shipped since the last run - cross-repo PRs, security fixes, star deltas, and X traction, synthesized into a digest article and a ready-to-post shiplog in your voice.
-
aaronjmars Skill Send EmailCompose and send a one-off email to a named recipient via Resend - written in the operator's voice, then sent in-run through the shared send caps with an operator audit copy
-
aaronjmars Skill Inbox TriageDaily GitHub notification inbox triage - surfaces aging vuln PR replies, security advisories, review requests, and mentions that need action
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include memstack-security-git-guard, memstack-security-csp-headers, memstack-security-owasp-top10. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.