Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
rudironsoni Skill Dotnet API Security 2Secures ASP.NET Core APIs. Identity, OAuth/OIDC, JWT bearer, passkeys, CORS, rate limiting.
-
rudironsoni Skill Dotnet Security Owasp 2Hardens .NET apps per OWASP Top 10 -- injection, auth, XSS, deprecated security APIs.
-
rudironsoni Skill Dotnet API Security 3Secures ASP.NET Core APIs. Identity, OAuth/OIDC, JWT bearer, passkeys, CORS, rate limiting.
-
rudironsoni Skill Dotnet Security Owasp 3Hardens .NET apps per OWASP Top 10 -- injection, auth, XSS, deprecated security APIs.
-
mturac Skill Quarkus VerificationVerification loop for Quarkus projects: build, static analysis, tests with coverage, security scans, native compilation, and diff review before release or PR.
-
mturac Skill Security Review 2Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
-
mturac Skill Quality NonconformanceCodified expertise for quality control, non-conformance investigation, root cause analysis, corrective action, and supplier quality management in regulated manufacturing. Informed by quality engineers with 15+ years experience across FDA, IATF 16949, and AS9100 environments. Includes NCR lifecycle management, CAPA systems, SPC interpretation, and audit methodology. Use when investigating non-conformances, performing root cause analysis, managing CAPAs, interpreting SPC data, or handling supplier quality issues.
Audited -
mturac Skill Security Bounty HunterHunt for exploitable, bounty-worthy security issues in repositories. Focuses on remotely reachable vulnerabilities that qualify for real reports instead of noisy local-only findings.
-
mturac Skill Postgres Patterns 2PostgreSQL database patterns for query optimization, schema design, indexing, and security. Quick reference for common patterns, index types, data types, and anti-pattern detection. Based on Supabase best practices.
-
mturac Skill Security Review 3Kimlik doğrulama eklerken, kullanıcı girdisi işlerken, secret'larla çalışırken, API endpoint'leri oluştururken veya ödeme/hassas özellikler uygularken bu skill'i kullanın. Kapsamlı güvenlik kontrol listesi ve kalıplar sağlar.
-
mturac Skill Springboot VerificationVerification loop for Spring Boot projects: build, static analysis, tests with coverage, security scans, and diff review before release or PR.
-
mturac Skill Perl Security 2テイントモード、入力バリデーション、安全なプロセス実行、DBIパラメータ化クエリ、Webセキュリティ(XSS/SQLi/CSRF)、perlcriticセキュリティポリシーを網羅する包括的なPerlセキュリティ。
-
mturac Skill Laravel Security 2Laravel security best practices for authn/authz, validation, CSRF, mass assignment, file uploads, secrets, rate limiting, and secure deployment.
-
mturac Skill Quarkus Security 2Quarkus Security best practices for authentication, authorization, JWT/OIDC, RBAC, input validation, CSRF, secrets management, and dependency security.
-
mturac Skill Perl Security 3Perl Security
-
mturac Bundle Security Review 4인증 추가, 사용자 입력 처리, 시크릿 관리, API 엔드포인트 생성, 결제/민감한 기능 구현 시 이 스킬을 사용하세요. 포괄적인 보안 체크리스트와 패턴을 제공합니다.
-
mturac Bundle Security Review 5Security Review
-
mturac Skill Laravel Security 3Laravel セキュリティベストプラクティス:認証・認可、バリデーション、CSRF、一括割当、ファイルアップロード、シークレット管理、レート制限、安全なデプロイメント
-
wenjunduan Skill Security Review 2安全审查清单 — T 阶段 (Path C+)
-
wenjunduan Skill Security Review 3Security Review
-
wenjunduan Skill Security Review 4安全审查清单 (源自 ECC security-review)
-
wenjunduan Skill Security Review 5安全审查。Path C+ 自动触发或显式调用。检查认证/授权、输入验证、密钥管理、依赖漏洞。
-
wenjunduan Skill Security Review 6安全审查
-
wenjunduan Skill Security Review 7安全审查 — Path C+ 或显式触发
-
ultroncore Skill Security Scanner 2Route security scanning tasks to the right tool — containers, secrets, SAST, SBOM, web apps
-
ffsshhttiikk Skill Mobile Security 2Securing mobile applications on iOS and Android platforms against reverse engineering, data leakage, and runtime attacks
-
ffsshhttiikk Skill Application Security 2Securing applications through design, development, and deployment practices to prevent vulnerabilities and protect against attacks
-
yejiming Bundle Crypto Com ExchangeCrypto.com Exchange Spot request using the Crypto.com Exchange API. Authentication requires API key and secret key. Supports production and UAT sandbox.
-
yejiming Bundle SpotBinance Spot request using the Binance API. Authentication requires API key and secret key. Supports testnet and mainnet.
-
mittuled Bundle Compliance AuditorThis skill conducts comprehensive compliance audits across 7 regulatory frameworks using a 57-item checklist with quantitative scoring and remediation guidance. Use when preparing for certification audits (SOC 2, ISO 27001) or regulatory reviews. Also consider when onboarding enterprise customers with compliance requirements. Suggest when annual compliance review cycle begins.
-
xalgord Skill Configuring Tls 1 3 For Secure CommunicationsTLS 1.3 (RFC 8446) is the latest version of the Transport Layer Security protocol, providing significant improvements over TLS 1.2 in both security and performance. It reduces handshake latency to 1-R
Audited -
xalgord Skill Analyzing Apt Group With Mitre NavigatorAnalyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps of adversary TTPs for detection gap analysis and threat-informed defense.
Audited -
xalgord Skill Implementing Siem Correlation Rules For AptWrite multi-event correlation rules that detect APT lateral movement by chaining Windows authentication events, process execution telemetry, and network connection logs across hosts. Uses Splunk SPL and Sigma rule format to correlate Event IDs 4624, 4648, 4688, and Sysmon Events 1/3 within sliding time windows to surface attack sequences invisible to single-event detections.
-
xalgord Skill Analyzing Threat Actor Ttps With Mitre AttackMITRE ATT&CK is a globally-accessible knowledge base of adversary tactics, techniques, and procedures (TTPs) based on real-world observations. This skill covers systematically mapping threat actor beh
Audited -
xalgord Skill Analyzing Threat Actor Ttps With Mitre NavigatorMap advanced persistent threat (APT) group tactics, techniques, and procedures (TTPs) to the MITRE ATT&CK framework using the ATT&CK Navigator and attackcti Python library. The analyst queries STIX/TAXII data for group-technique associations, generates Navigator layer files for visualization, and compares defensive coverage against adversary profiles. Activates for requests involving APT TTP mapping, ATT&CK Navigator layers, threat actor profiling, or MITRE technique coverage analysis.
Audited -
dingxingdi Bundle Security Vulnerability Repair 2Use this skill when the user wants software-fix data focused on security bugs such as injections, missing checks, unsafe parsing, broken access control, cryptographic mistakes, or information leaks. Trigger it for requests like 'make security repair tasks', 'generate vulnerability-fixing data', 'give me code issues with CWE-style fixes', or 'create patching tasks for insecure code'. Do not use it for ordinary non-security defects or for security exploitation tasks where the objective is to attack rather than repair.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include quarkus-verification, security-review, dotnet-api-security. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.