Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
diegosouzapw Bundle Find Bugs 2Find Bugs workflow skill. Use this skill when the user needs Find bugs, security vulnerabilities, and code quality issues in local branch changes. Use when asked to review changes, find bugs, security review, or audit code on the current branch and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Fix Review 2Fix Review workflow skill. Use this skill when the user needs Verify fix commits address audit findings without new bugs and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Burp Suite Testing 2Burp Suite Web Application Testing workflow skill. Use this skill when the user needs to perform authorized web application security testing with Burp Suite, including proxy interception, authenticated request analysis, manual verification, evidence capture, and tightly scoped active scanning.
54 -
diegosouzapw Bundle Django Perf Review 2Django Performance Review workflow skill. Use this skill when the user needs Django performance code review. Use when asked to "review Django performance", "find N+1 queries", "optimize Django", "check queryset performance", "database performance", "Django ORM issues", or audit Django code for performance problems and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Differential Review 2Differential Security Review workflow skill. Use this skill when the user needs Security-focused code review for PRs, commits, and diffs and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle File Path Traversal 2File Path Traversal Testing workflow skill. Use this skill when the user needs Identify and exploit file path traversal (directory traversal) vulnerabilities that allow attackers to read arbitrary files on the server, potentially including sensitive configuration files, credentials, and source code and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle API Endpoint Builder 2API Endpoint Builder workflow skill. Use this skill when the user needs Builds production-ready REST API endpoints with validation, error handling, authentication, and documentation. Follows best practices for security and scalability and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle API Security Testing 2API Security Testing Workflow workflow skill. Use this skill when the user needs API security testing workflow for REST and GraphQL APIs covering authentication, authorization, rate limiting, input validation, and security best practices and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Broken Authentication 2Broken Authentication Testing workflow skill. Use this skill when the user needs Identify and exploit authentication and session management vulnerabilities in web applications. Broken authentication consistently ranks in the OWASP Top 10 and can lead to account takeover, identity theft, and unauthorized access to sensitive systems and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Burp Suite Testing V2 2Burp Suite Web Application Testing workflow skill. Use this skill when the user needs execute authorized web application security testing with Burp Suite across interception, replay, authenticated assessment, targeted scanning, and manual verification while preserving scope control, evidence quality, and provenance.
54 -
diegosouzapw Bundle Code Review Checklist 2Code Review Checklist workflow skill. Use this skill when the user needs Comprehensive checklist for conducting thorough code reviews covering functionality, security, performance, and maintainability and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle API Security Best Practices V2 2API Security Best Practices workflow skill. Use this skill when the user needs Implement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilities and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Dependency Management Deps Audit 2Dependency Audit and Security Analysis workflow skill. Use this skill when the user needs You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
thomasmoreai Skill Deposition IpSupplements general deposition preparation with IP-specific examination frameworks for patent, trademark, copyright, and trade secret cases. Covers witness strategies for inventors, accused infringers, licensing witnesses, and experts. Use alongside @deposition-preparation and @deposition-expert-witness when planning IP depositions, drafting outlines, or analyzing witness strategy.
Audited -
thomasmoreai Skill IsmExpert Australian Information Security Manual (ISM) advisor for government entities and their supply chains. Use for ISM control selection, gap analysis, system authorisation, IRAP assessment preparation, security documentation, and ASD compliance. Triggers on: ISM controls, ASD compliance, IRAP assessment, PROTECTED system scoping, Essential Eight vs ISM, system authorisation, NC/OS/ PROTECTED/SECRET/TOP SECRET classification markings, security objectives, ISM guidelines or chapters, control applicability markings, cybersecurity documentation for Australian government, and any question about the ASD Information Security Manual framework or Australian government cybersecurity obligations.
Audited -
thomasmoreai Skill DoraExpert DORA (Regulation (EU) 2022/2554 — Digital Operational Resilience Act) compliance advisor for EU financial entities. Use this skill whenever a user asks about DORA compliance, ICT risk management frameworks, ICT incident classification or reporting, threat-led penetration testing (TLPT), ICT third-party risk management, Register of Information, contractual provisions with ICT providers, ICT concentration risk, oversight of critical ICT third-party service providers (CTPPs), or any DORA RTS/ITS obligation. Also trigger for: "DORA gap analysis", "DORA readiness", "Art. 6 ICT risk framework", "Art. 17 incident reporting", "Art. 26 TLPT", "Art. 28 third-party policy", "Art. 30 contractual provisions", "Register of Information CIR 2024/2956", "critical TPSP designation", "DORA vs NIS2", "DORA simplified framework", or EBA/ESMA/EIOPA digital resilience guidance.
Audited -
thomasmoreai Skill WispDrafts a Written Information Security Program compliant with Massachusetts 201 CMR 17.00 and supplementary frameworks (GDPR, CCPA, HIPAA, GLBA, PCI-DSS). Produces a board-ready regulatory document covering coordinator designation, risk assessment, safeguards, training, incident response with breach notification, and vendor oversight. Use when an organization handles personal information of MA residents and needs a standalone WISP for regulatory examination or executive approval.
Audited -
thomasmoreai Skill Hipaa BaaDrafts HIPAA/HITECH-compliant Business Associate Agreements governing PHI/ePHI handling between covered entities and business associates. Covers Privacy Rule and Security Rule obligations, breach notification, subcontractor flow-downs, individual-rights support, and state-law overlays. Use when drafting or updating a BAA, negotiating vendor PHI access, or attaching HIPAA terms to a services agreement. Trigger keywords: BAA, business associate agreement, HIPAA contract, PHI vendor agreement, HITECH breach notice.
Audited -
thomasmoreai Skill Ecp ManualDrafts an audit-ready Export Compliance Program manual covering EAR, ITAR, and OFAC requirements. Use when creating or updating an export compliance policy, international trade compliance program, or preparing enforcement defense documentation for regulatory review.
Audited -
thomasmoreai Skill Employee NdaDrafts U.S. employee non-disclosure/confidentiality agreements that protect employer trade secrets and proprietary information while preserving employee mobility. Triggers on: employee NDA, confidentiality agreement, non-disclosure agreement, trade secret protection, proprietary information, onboarding confidentiality clause, pre-employment NDA.
Audited -
thomasmoreai Skill Audit SummaryProduces structured U.S. legal audit summaries that distill compliance findings into executive-ready risk prioritization and remediation plans, covering likelihood/impact scoring, consequence analysis, and corrective actions with timelines and owners. Use for legal audits, compliance audits, regulatory audits, compliance gap analyses, risk assessments, audit report summaries, or remediation roadmaps. Trigger keywords: audit summary, compliance findings, audit report, risk prioritization, remediation plan, regulatory exposure, corrective action plan.
Audited -
thomasmoreai Skill Deed Of TrustDrafts combined Deed of Trust and Security Agreement instruments creating real property and UCC Article 9 personal property security interests for commercial financing. Use when drafting trust deeds, security agreements, commercial real estate financing documents, or combined real/personal property security instruments.
Audited -
thomasmoreai Skill China PiplGuides compliance with China's Personal Information Protection Law (PIPL, effective 1 November 2021). Covers consent requirements, cross-border transfer mechanisms (CAC security assessment, standard contracts, certification), separate consent triggers, and critical information infrastructure obligations. Keywords: PIPL, China data protection, CAC security assessment, cross-border transfer, separate consent, CIIO.
Audited -
thomasmoreai Skill Pos LicenseDrafts Software and POS System License Agreements for proprietary software use between licensor and licensee. Covers license grants, financial terms, IP, PCI-DSS data security, SLAs, and termination. Use when drafting POS software licenses, SaaS subscriptions, franchise technology licenses, or software distribution agreements.
Audited -
thomasmoreai Skill Byod PolicyDrafts a Bring Your Own Device (BYOD) policy for U.S. employers governing personal device access to company systems. Covers MDM enrollment, encryption, remote wipe authority, privacy expectations, data classification, and regulatory overlays (HIPAA, GLBA, SOX, GDPR). Use when creating or updating BYOD policies, mobile device security policies, or personal device programs.
Audited -
diegosouzapw Bundle Firebase V2 2Use this skill when designing, reviewing, or operating Firebase systems across Auth, Firestore, Realtime Database, Storage, Functions, Hosting, App Check, and related security boundaries.
54 -
diegosouzapw Bundle Expo API Routes 2Create a secret workflow skill. Use this skill when the user needs Guidelines for creating API routes in Expo Router with EAS Hosting and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Avoid AI Writing 2Avoid AI Writing \u2014 Audit & Rewrite workflow skill. Use this skill when the user needs Audit and rewrite content to remove 21 categories of AI writing patterns with a 43-entry replacement table and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Firmware Analyst 2Download from vendor workflow skill. Use this skill when the user needs Expert firmware analyst specializing in embedded systems, IoT security, and hardware reverse engineering and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
vamseeachanta Skill Enforcement Audit And Upgrade 2Audit existing enforcement infrastructure, identify gaps between advisory and strict modes, create hard-gate scripts, and incrementally roll out enforcement. Pattern from
-
vamseeachanta Skill Gsd Operational Audit 2Audit a repo's live GSD/get-shit-done workflow state against docs, issues, and runtime outputs to find stale issues, automation reliability gaps, parser drift, migration residue, and policy contradictions.
Audited -
vamseeachanta Skill Hidden Folder Audit Pre Audit 2Sub-skill of hidden-folder-audit: Pre-Audit (+6).
-
vamseeachanta Bundle Provider Session Ecosystem Audit 2Audit Claude/Codex/Hermes/Gemini session logs, normalize provider-specific quirks, and wire recurring exports/reporting for ongoing ecosystem health checks.
-
vamseeachanta Skill Multi Tool Architecture Assessment 2Systematic comparison of competing tools/approaches before committing to a multi-account, multi-tool architecture. Uses parallel subagents for research, system-state audit, and data quality analysis. Produces a decision matrix with explicit trade-offs.
-
vamseeachanta Bundle Plan Exit Governance Drift Handoff 2When ending a session on an iterated plan draft, audit and document approval-state drift across GitHub labels, local approval markers, README status, and latest review verdicts.
-
vamseeachanta Bundle Provider Session Learning Transfer 2Refresh provider session audit, identify post-audit/unassessed sessions, extract actionable learnings, and transfer them into repo notes and GitHub issues before a follow-up implementation session.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include ecp-manual, hipaa-baa, deposition-ip. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.