Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
vamseeachanta Bundle Multi Provider Adversarial Review 2Dispatch parallel adversarial reviews to Codex and Gemini CLIs for plans or code artifacts. Use when the AI Review Routing Policy requires two- or three-provider review — architecture-heavy, security-affecting, cross-module, or high-stakes changes.
-
vamseeachanta Skill Periodic Skill Ecosystem Housekeeping Audit 2Maintain a deterministic recurring skill ecosystem housekeeping audit covering skill content quality, grouping/taxonomy drift, size, waivers, baselines, and local-only GitHub payloads.
-
vamseeachanta Bundle Tier1 Indexing Scorecard And Freshness Audit 2Audit tier-1 repos for code-placement/retrieval readiness, write scorecard/freshness reports, create follow-up GitHub issues when requested, and handle daily freshness checks without reinforcing legacy product-doc reference patterns.
-
vamseeachanta Skill Provider Session Ecosystem Audit And Exporters 2Build and maintain cross-provider session-log audits for Claude, Codex, Hermes, and Gemini, including exporter design, normalization, and behavioral verification.
-
vamseeachanta Skill Hidden Folder Audit Verify Hidden Folder State 2Sub-skill of hidden-folder-audit: Verify Hidden Folder State (+3).
-
vamseeachanta Skill Hidden Folder Audit Common Hidden Folders Reference 2Sub-skill of hidden-folder-audit: Common Hidden Folders Reference.
-
vamseeachanta Skill Hidden Folder Audit Step 1 Inventory All Hidden Folders 2Sub-skill of hidden-folder-audit: Step 1: Inventory All Hidden Folders (+4).
-
vamseeachanta Skill Provider Audit Bootstrap And Path Classification 2Fix provider-session ecosystem audit failures caused by source-checkout imports and over-aggressive symbolic-path classification.
-
thomasmoreai Skill Iso27701Expert ISO 27701 Privacy Information Management System (PIMS) compliance advisor. Use this skill whenever a user asks about ISO/IEC 27701:2025, ISO/IEC 27701:2019, privacy information management, PIMS certification, PII controller or processor obligations, privacy risk assessment, Statement of Applicability for privacy, privacy by design, data subject rights, DPIA, records of processing activities, transitioning from ISO 27701:2019, GDPR alignment with ISO 27701, or any privacy management system topic. Also trigger for questions about Annex A.1 (controller controls), A.2 (processor controls), A.3 (shared security controls), or implementing a standalone PIMS without ISO 27001. When in doubt, use this skill — it covers the full ISO 27701 lifecycle from gap assessment through certification.
Audited -
thomasmoreai Skill Hitech Act PrivacyImplements HITECH Act privacy and security requirements including breach notification expansion, four-tier penalty structure, state attorney general enforcement authority, EHR meaningful use privacy conditions, and business associate direct liability. Keywords: HITECH Act, breach notification, penalty tiers, state AG enforcement, meaningful use, EHR privacy.
Audited -
thomasmoreai Skill Telehealth PrivacyImplements telehealth privacy compliance covering HIPAA requirements for virtual care, state licensing and recording consent laws, platform security with BAA requirements for telehealth vendors, cross-state prescribing rules, and OCR enforcement discretion during public health emergencies. Keywords: telehealth privacy, virtual care, HIPAA, recording consent, platform BAA, cross-state licensing, OCR enforcement.
Audited -
thomasmoreai Skill Hipaa Security RuleImplements HIPAA Security Rule technical safeguards under 45 CFR §164.312 for electronic protected health information. Covers access controls with unique user identification, emergency access procedures, automatic logoff, encryption, audit controls, integrity controls, and transmission security. Keywords: HIPAA Security Rule, ePHI, access controls, encryption, audit controls, technical safeguards.
Audited -
thomasmoreai Skill Dd Form 254Drafts DD Form 254 Contract Security Classification Specifications for classified government contracts. Use when preparing security classification specs for prime contractors, subcontractors, SAP/SCI access, or facility clearance documentation per NISPOM (32 CFR Part 117) and DCSA regulations.
Audited -
thomasmoreai Skill Soc2 Privacy AuditGuides SOC 2 Type II Privacy Trust Services Criteria preparation and audit execution. Covers AICPA TSP Section 100 Privacy criteria P1-P8 including notice, choice/consent, collection, use/retention/disposal, access, disclosure, security, and quality. Includes evidence collection, control testing, and report review. Keywords: SOC 2, privacy criteria, TSP, AICPA, Type II, trust services.
Audited -
thomasmoreai Skill Dpia Risk ScoringProvides a structured risk scoring methodology for Data Protection Impact Assessments aligned with ENISA threat taxonomy and ISO 29134. Covers likelihood and severity assessment, risk matrix construction, inherent vs residual risk calculation, and risk appetite thresholds per EDPB WP248rev.01 guidance. Keywords: risk scoring, DPIA risk matrix, likelihood, severity, ENISA, ISO 29134, residual risk, risk appetite.
Audited -
thomasmoreai Skill Breach DocumentationMaintains the GDPR Article 33(5) breach register documenting all personal data breaches regardless of whether supervisory authority notification was required. Covers mandatory register fields including facts, effects, and remedial actions, retention periods, audit readiness, and integration with the accountability framework. Keywords: breach register, Article 33(5), breach documentation, accountability, audit readiness, remedial actions.
Audited -
vamseeachanta Bundle Session Corpus Audit 2Analyze session quality trends — identify high-churn patterns, report waste, flag sessions exceeding 500 tool calls
-
vamseeachanta Bundle Provider Session Quota Operations 2Class-level provider/session operations for Claude, Codex, Gemini, Hermes, quotas, audit exporters, readiness dispatch, and utilization scorecards.
-
vamseeachanta Skill Workflow Compliance Audit 2Systematic audit of whether agents are following established workflows — cross-review, plan approval, TDD compliance, and document intelligence status.
-
diegosouzapw Bundle Audit Context Building 2Deep Context Builder Skill (Ultra-Granular Pure Context Mode) workflow skill. Use this skill when the user needs Enables ultra-granular, line-by-line code analysis to build deep architectural context before vulnerability or bug finding and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Backend Security Coder 2backend-security-coder workflow skill. Use this skill when the user needs Expert in secure backend coding practices specializing in input validation, authentication, and API security. Use PROACTIVELY for backend security implementations or security code reviews and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle API Endpoint Builder V2 2API Endpoint Builder workflow skill. Use this skill when the user needs Builds production-ready REST API endpoints with validation, error handling, authentication, and documentation. Follows best practices for security and scalability and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle API Security Testing V2 2API Security Testing Workflow workflow skill. Use this skill when the user needs API security testing workflow for REST and GraphQL APIs covering authentication, authorization, rate limiting, input validation, and security best practices and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Codebase Audit Pre Push 2Pre-Push Codebase Audit workflow skill. Use this skill when the user needs Deep audit before GitHub push: removes junk files, dead code, security holes, and optimization issues. Checks every file line-by-line for production readiness and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Attack Tree Construction 2Attack Tree Construction workflow skill. Use this skill when the user needs Build comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Burpsuite Project Parser 2Burp Project Parser workflow skill. Use this skill when the user needs Searches and explores Burp Suite project files (.burp) from the command line. Use when searching response headers or bodies with regex patterns, extracting security audit findings, dumping proxy history or site map data, or analyzing HTTP traffic captured in a Burp project and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Cc Skill Security Review 2Security Review Skill workflow skill. Use this skill when the user needs This skill ensures all code follows security best practices and identifies potential vulnerabilities. Use when implementing authentication or authorization, handling user input or file uploads, or creating new API endpoints and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Event Sourcing Architect 2Event Sourcing Architect workflow skill. Use this skill when the user needs Expert in event sourcing, CQRS, and event-driven architecture patterns. Masters event store design, projection building, saga orchestration, and eventual consistency patterns. Use PROACTIVELY for event-sourced systems, audit trail requirements, or complex domain modeling with temporal queries and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Nodejs Best Practices V3 2Node.js Best Practices workflow skill. Use this skill when the user needs Node.js development principles and decision-making. Framework selection, async patterns, security, and architecture. Teaches thinking, not copying and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Audit Context Building V2 2Deep Context Builder Skill (Ultra-Granular Pure Context Mode) workflow skill. Use this skill when the user needs Enables ultra-granular, line-by-line code analysis to build deep architectural context before vulnerability or bug finding and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle API Security Best Practices 2API Security Best Practices workflow skill. Use this skill when the user needs Implement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilities and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Cc Skill Security Review V2 2Security Review Skill workflow skill. Use this skill when the user needs This skill ensures all code follows security best practices and identifies potential vulnerabilities. Use when implementing authentication or authorization, handling user input or file uploads, or creating new API endpoints and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Cc Skill Security Review V3 2Security Review Skill workflow skill. Use this skill when the user needs This skill ensures all code follows security best practices and identifies potential vulnerabilities. Use when implementing authentication or authorization, handling user input or file uploads, or creating new API endpoints and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Codebase Cleanup Deps Audit 2Dependency Audit and Security Analysis workflow skill. Use this skill when the user needs You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Anti Reversing Techniques V2 2anti-reversing-techniques workflow skill. Use this skill when the user needs AUTHORIZED USE ONLY: This skill contains dual-use security techniques. Before proceeding with any bypass or analysis: > 1 and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Protocol Reverse Engineering 2Protocol Reverse Engineering workflow skill. Use this skill when the user needs comprehensive techniques for capturing, analyzing, and documenting network protocols for authorized security research, interoperability work, and debugging, with emphasis on evidence preservation, safe capture practice, and source-backed analysis.
54
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include dpia-risk-scoring, soc2-privacy-audit, hitech-act-privacy. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.