Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
brucevanfdm Bundle Env Var Safe ShellRule matrix negative fixture - safe environment variable usage without piping; not intended for production deployment.
-
brucevanfdm Bundle Path Safe RealpathRule matrix negative fixture - uses realpath to validate file paths; not intended for production deployment.
-
brucevanfdm Bundle Network DeclaredRule matrix security fixture for network_declared used by security rule matrix integration tests; not intended for production deployment.
-
brucevanfdm Bundle Path Traversal OpenRule matrix security fixture for path_traversal_open used by security rule matrix integration tests; not intended for production deployment.
-
brucevanfdm Bundle Undeclared NetworkRule matrix security fixture for undeclared_network used by security rule matrix integration tests; not intended for production deployment.
-
brucevanfdm Bundle Subprocess Test ExampleRule matrix negative fixture - subprocess usage in test helper; not intended for production deployment.
-
demerzels-lab Bundle Csp GenGenerate Content Security Policy headers for your site. Use when you need to add CSP headers without spending hours reading the spec.
10 -
demerzels-lab Bundle Zugashield7-layer AI security scanner for OpenClaw.
10 -
demerzels-lab Bundle SecretcodexGenerate creative code names and encode/decode secret messages using classic and sophisticated ciphers.
10 -
demerzels-lab Bundle Secret PortalSpin up a one-time web UI for securely entering secret keys and env vars.
10 -
demerzels-lab Bundle Sui CoverageAnalyze Sui Move test coverage, identify untested code, write missing tests, and perform security audits.
10 -
demerzels-lab Bundle Solo ReviewFinal code review and quality gate — run tests, check coverage, audit security, verify acceptance criteria.
10 -
demerzels-lab Bundle Safe SkillsSafeSkills - Secure Secret Management for AI Agents
10 -
demerzels-lab Bundle Skill Safety CheckerRuns VirusTotal-style security checks on OpenClaw/Cursor skills before install, including remote code execution (RCE)
10 -
demerzels-lab Bundle Efka API IntegrationGreek social security (EFKA) integration — employee records, contribution calculations, APD declarations.
10 -
demerzels-lab Bundle Cyber Security EngineerSecurity engineering workflow for OpenClaw privilege governance and hardening.
10 -
demerzels-lab Bundle Brw AI Discoverability AuditAudit how a brand appears in AI-powered search (ChatGPT, Perplexity, Claude, Gemini)
10 -
demerzels-lab Bundle Guardrailsguardrails - Interactive Security Guardrails Configuration
10 -
demerzels-lab Bundle Security ScannerAutomated security scanning and vulnerability detection for web applications, APIs, and infrastructure.
10 -
demerzels-lab Bundle Sui Auto TestAnalyze Sui Move test coverage, identify untested code, write missing tests, and perform security audits.
10 -
demerzels-lab Bundle AbaddonRed team security mode for OpenClaw.
10 -
demerzels-lab Bundle Secret ManagerManage API keys securely via GNOME Keyring and inject them into OpenClaw config.
10 -
demerzels-lab Bundle AgentguardAgentGuard - Security Monitoring Skill
10 -
demerzels-lab Bundle AgentauditAutomatic security gate that checks packages against a vulnerability database before installation.
10 -
wpacademy Bundle Wp Plugin DevDevelop WordPress plugins following official WordPress coding standards, security best practices, and WordPress.org directory guidelines. Use this skill whenever the user wants to create, scaffold, or develop a WordPress plugin — including standard plugins (settings pages, CPTs, shortcodes), WooCommerce extensions, Gutenberg block plugins, or REST API / headless plugins. Also trigger when the user mentions "WordPress plugin", "WP plugin", asks to build a feature as a plugin, wants to add admin pages, register custom post types, create blocks, build WooCommerce add-ons, or extend WordPress in any way via plugin architecture. Even if the user just says "build me a plugin for X", use this skill.
-
coreyhaines31 Skill Owasp AuditAudit application source code against the OWASP Top 10 vulnerability categories. Use when the user mentions 'OWASP,' 'security audit,' 'code security review,' 'vulnerability audit,' 'find vulnerabilities,' 'secure code review,' 'security review,' or wants to check their codebase for common security weaknesses.
36.3k -
coreyhaines31 Skill Incident TriageGuide rapid triage and initial response to security incidents following NIST SP 800-61 methodology. Use when the user mentions 'incident response,' 'security incident,' 'triage,' 'we've been hacked,' 'breach,' 'compromised,' 'malware detected,' 'suspicious activity,' 'IOC,' 'indicators of compromise,' or needs help handling a security event.
36.3k -
coreyhaines31 Skill Dependency AuditAudit project dependencies, frameworks, languages, and dev tools for known vulnerabilities, CVEs, and security anti-patterns. Use when the user mentions 'dependency audit,' 'npm audit,' 'CVE,' 'vulnerable packages,' 'supply chain security,' 'outdated dependencies,' 'known vulnerabilities,' 'security advisory,' 'package security,' 'framework vulnerability,' 'is this package safe,' or needs to check whether their stack has known security issues.
36.3k -
omas-odoo Bundle Odoo XML ConventionsUse when writing, reviewing, or migrating any .xml file in an Odoo module — views, actions, menus, security records, data files, QWeb templates. Holds Odoo's naming, formatting, inheritance, and cross-version syntax conventions. Invoke before adding records to views/, security/, data/, or report/ directories.
-
btn101 Skill Find BugsFind bugs, security vulnerabilities, and code quality issues in local branch changes. Use when asked to review changes, find bugs, security review, or audit code on the current branch.
-
btn101 Bundle Gha Security ReviewGitHub Actions security review for workflow exploitation vulnerabilities. Use when asked to "review GitHub Actions", "audit workflows", "check CI security", "GHA security", "workflow security review", or review .github/workflows/ for pwn requests, expression injection, credential theft, and supply chain attacks. Exploitation-focused with concrete PoC scenarios.
-
caarles00 Bundle Security ReviewSecurity code review for vulnerabilities. Use when asked to "security review", "find vulnerabilities", "check for security issues", "audit security", "OWASP review", or review code for injection, XSS, authentication, authorization, cryptography issues. Provides systematic review with confidence-based reporting.
-
cartridge-gg Bundle Account AbstractionStarknet account abstraction correctness and security guidance for validate/execute paths, nonces, signatures, and session policies.
-
jahidulislamseo Skill Semrush ToolWhen the user wants keyword research with search volume, competitive keyword analysis, site audit data, position tracking, or competitor organic analysis. Trigger on "keyword research," "search volume," "keyword difficulty," "what keywords do they rank for," "site audit," "Semrush," or "competitive analysis." Use Semrush for keyword data and competitive intelligence — use Ahrefs for backlink-focused analysis.
-
jahidulislamseo Skill Local Competitor AnalysisWhen the user wants to analyze local search competitors, benchmark against map pack rivals, or understand why competitors outrank them. Also use when the user mentions "competitor analysis," "who's outranking me," "competitor GBP," "local competition," or "competitive audit." For geogrid-specific ranking data, see geogrid-analysis. For general map pack strategy, see map-pack-optimization.
-
codealive-ai Bundle Anti Pattern AuditMonthly self-deception audit — 25 anti-patterns from CEO Bible Section M
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include wp-plugin-dev, csp-gen, guardrails. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.