Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
ihabkhaled Bundle Evidence FloorUse when mandatory behavior, integration, security, migration, or data requirements lack the appropriate kind of proof.
-
ihabkhaled Bundle Loophole HunterUse when rules appear satisfied while their intent is bypassed, counters reset, classifications change conveniently, or an AI-Psychiatry audit is requested.
-
ihabkhaled Skill Task BootstrapUse when beginning any plan, audit, investigation, modification, review, test, or expensive tool action before the primary objective and completion conditions are explicit.
-
ihabkhaled Bundle Decision ReadinessUse when an important implementation, architecture, security, data, or delivery decision rests on unresolved critical unknowns.
-
ihabkhaled Bundle Executive OverrideUse when an AI-Psychiatry budget expires while new evidence shows a narrow extension is required for correctness, security, or completion.
-
ihabkhaled Skill Critic ControllerUse when reviewers or judges repeat rounds, invent requirements, block on style, expand scope, or continue after correctness, security, regression, and explicit requirements are satisfied.
-
promovaweb Bundle Specsfy Specialist SupabaseProjetar, implementar e revisar soluções Supabase — Postgres, Auth, Row Level Security, Storage, Realtime, Edge Functions e ambiente local. Use quando houver `supabase/config.toml`, migrations Supabase ou clientes `@supabase/*`; não use como substituto de análise Postgres profunda de schema/índice/plano — combine com `specsfy-specialist-postgres` para isso.
-
thegoat395 Bundle Performance Audit WebsitesDiagnose measured runtime and Core Web Vitals.
-
x-cmd Skill Security ReviewSecurity audit for code changes. Triggered by "/security-review" when reviewing auth, crypto, input handling, or when user explicitly requests a security audit.
-
shuwanito Bundle Nexus Cyber BlueBlue team defense and threat detection specialist. Use when you need SIEM analysis, anomaly detection, incident response planning, or zero-day defense strategies. Focuses on reducing detection time and minimizing false positives in security monitoring.
-
shuwanito Bundle Nexus Cyber ThreatThreat intelligence and predictive cybersecurity specialist. Use when you need threat modeling, adversarial ML analysis, predictive security assessments, or dark web monitoring insights. Proactively identifies unmodeled threats and emerging attack vectors before they materialize.
-
shuwanito Bundle Nexus Browser FleetHeadless browser fleet orchestration and management. Use when you need to coordinate multiple headless browser instances for automated web auditing, scraping, or testing at scale using tools like Pinchtab. Detects and corrects unstable fleets that fail audit coverage.
-
shuwanito Bundle Nexus Edu AssessmentAssessment & Evaluation Architect specializing in educational assessment design, rubrics, formative and summative evaluation, and portfolios. Use when you need to design evaluations that measure competencies, create rubrics, or audit existing assessments for alignment and clarity.
-
jordangaston Bundle Imagineering PyramidApply the Imagineering Pyramid — Lou Prosperi's framework derived from Walt Disney Imagineering's theme-park design principles — to develop, refine, audit, or "plus" any creative idea, product, feature, experience, or piece of communication. Use this skill whenever the user wants to design an experience, shape a user journey or onboarding flow, make something more engaging, memorable, or intuitive, pressure-test a creative concept, sharpen a pitch or landing page, or turn a rough idea into a coherent designed experience. Also trigger on explicit mentions of Imagineering, the Imagineering Pyramid, "the Art of the Show," theming, wienies, forced perspective, plussing, or "designing it like Disney would." Especially useful for founders and builders treating a product as an experience rather than a feature list.
-
jordangaston Skill Wsh ReferenceReference guide for Wave Terminal's wsh CLI commands. Use when the user asks about wsh commands, Wave Terminal CLI usage, or needs help with wsh syntax, flags, and examples. Covers: view, edit, editor, getmeta, setmeta, ai, editconfig, setbg, badge, run, deleteblock, ssh, wsl, web, notify, conn, setconfig, file, launch, getvar/setvar, termscrollback, wavepath, blocks, and secret.
-
x-cmd Skill CveLook up CVE records via x cve — cached, zero-API-key, daily xz TSV. Load for cve, vulnerability id, kev, epss, nvd, cvelist, or security advisory.
-
andresnator Skill Tooling AuditTrigger: tooling audit, test tooling gaps. Detect build/test/coverage/mutation tooling for refactor safety plans.
Audited -
andresnator Bundle Dependency Security AuditTrigger: dependency audit, CVE scan, vulnerable libraries, runtime support. Audit dependency and runtime risk with read-only evidence.
-
blacklanternsecurity Skill CsrfExploit Cross-Site Request Forgery (CSRF) vulnerabilities during authorized penetration testing.
-
blacklanternsecurity Skill IdorExploit Insecure Direct Object Reference (IDOR) and broken access control vulnerabilities during authorized penetration testing.
-
blacklanternsecurity Skill Xss DomGuide DOM-based XSS exploitation during authorized penetration testing.
-
blacklanternsecurity Skill Xss StoredGuide stored (persistent) and blind XSS exploitation during authorized penetration testing.
-
blacklanternsecurity Skill JWT AttacksExploit JWT (JSON Web Token) vulnerabilities during authorized penetration testing.
-
blacklanternsecurity Skill Ajp GhostcatExploit Apache JServ Protocol (AJP) misconfigurations and Ghostcat (CVE-2020-1938) for file read and remote code execution on Apache Tomcat. Use when port 8009 is open or AJP connector is exposed.
-
blacklanternsecurity Skill OAUTH AttacksExploit OAuth 2.0 and OpenID Connect vulnerabilities during authorized penetration testing.
-
blacklanternsecurity Skill Xss ReflectedGuide reflected XSS exploitation during authorized penetration testing.
-
blacklanternsecurity Skill Ldap InjectionExploit LDAP injection vulnerabilities during authorized penetration testing.
-
blacklanternsecurity Skill Race ConditionExploit race conditions and TOCTOU vulnerabilities in web applications during authorized penetration testing.
-
blacklanternsecurity Skill Adcs PersistenceEstablishes persistence and exploits weak certificate mapping in AD CS. Covers ESC9 (no security extension), ESC10 (weak certificate mapping), ESC12-15 (YubiHSM, issuance policy, altSecIdentities, application policies), Golden Certificate (forge with stolen CA key), certificate theft (DPAPI/CAPI/CNG), and account persistence via certificate mapping.
-
blacklanternsecurity Skill PHP Code InjectionExploit PHP code evaluation injection via eval(), assert(), preg_replace /e, create_function(), call_user_func(), usort() callbacks, and runtime function creation (runkit, uopz). Distinct from OS command injection (shell operators) and SSTI (template engines) — this targets direct PHP code evaluation of user input.
-
blacklanternsecurity Skill Source Code ReviewSecurity-focused source code review. Identifies hardcoded credentials, injection sinks, authentication weaknesses, and framework-specific vulnerabilities. Use when application source code is available for review.
-
blacklanternsecurity Skill Deserialization PHPExploit PHP deserialization vulnerabilities during authorized penetration testing.
-
blacklanternsecurity Skill Smb ExploitationExploit remote SMB vulnerabilities for unauthenticated code execution on Windows hosts.
-
blacklanternsecurity Skill Browser ExploitationExploit browser-based attack surfaces: malicious extension crafting for bot interaction scenarios, Chrome DevTools Protocol abuse on exposed debug ports, and browser profile/cache data extraction from compromised hosts.
-
blacklanternsecurity Skill Deserialization JavaExploit Java deserialization vulnerabilities during authorized penetration testing.
-
blacklanternsecurity Skill Cors MisconfigurationExploit CORS (Cross-Origin Resource Sharing) misconfigurations during authorized penetration testing.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include evidence-floor, loophole-hunter, task-bootstrap. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.