Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
johnalbertini14-glitch Bundle Pls Audit WebsiteWebsite Audit
1 -
johnalbertini14-glitch Bundle Afrexai AI Spend AuditAI Spend Audit
1 -
johnalbertini14-glitch Bundle Skill ShieldSecurity audit tool for ClawHub skills. Scans a skill directory with 65 detection patterns, anti-obfuscation analysis, and dual rating system (Security + Compliance). v0.6.1 fixes batch scan performance by skipping venv/node_modules directories. Use when: installing a new skill, reviewing skill safety, or auditing permissions.
1 -
johnalbertini14-glitch Bundle Skill Security Reviewer<!-- Skill Security Reviewer | Version 3.0.0 | Author: chris@zast.ai -->
1 -
johnalbertini14-glitch Bundle Shieldcortex SkillShieldCortex — Persistent Memory & Security for AI Agents
1 -
johnalbertini14-glitch Bundle Tech Security AuditTech Security Audit Skill
1 -
johnalbertini14-glitch Bundle Clawhub Publish DoctorDiagnose and mitigate ClawHub/ClawDHUB publish failures (auth, browser-login, missing dependencies, pending security-scan visibility errors, and wrong profile/skill URLs). Use when publishing skills to ClawHub fails, inspect reports temporary errors, or you need a safer publish+verify workflow with retries.
1 -
johnalbertini14-glitch Bundle Openapi Deep AuditOpenAPI Deep Audit & Test Architect
1 -
johnalbertini14-glitch Bundle Skillguard 2AI-powered security scanner for OpenClaw skills. Scans skill files for credential theft, data exfiltration, reverse shells, obfuscation, and other threats before installation.
1 -
johnalbertini14-glitch Bundle Aiclude Security ScanAiclude Security Scan
1 -
johnalbertini14-glitch Bundle Aoi Openclaw Security Toolkit CoreAOI OpenClaw Security Toolkit (Core)
1 -
boomsystel-code Bundle Data Lineage TrackerTrack data origin, transformations, and flow through construction systems. Essential for audit trails, compliance, and debugging data issues.
-
majiayu000 Bundle GuardrailsSecurity techniques and quality control for prompts and agents
567 -
majiayu000 Bundle SecupdatesSecurity news aggregation from tldrsec, no.security, and other sources. USE WHEN security news, security updates, what's new in security, breaches, security research, sec updates. SkillSearch('secupdates') for docs.
567 -
majiayu000 Bundle Owasp CheckOWASP Top 10 vulnerability scanning and remediation
567 -
majiayu000 Bundle UX UI AuditUX 감사 에이전트. 사용자 경험을 분석하고 개선점을 도출합니다.
567 -
majiayu000 Bundle AI AuditabilityImplementing comprehensive logging, tracking, and audit trails for AI systems to ensure compliance and enable debugging.
567 -
majiayu000 Bundle Check StripeAudit Stripe integration: configuration, webhooks, subscription logic, security. Outputs structured findings. Use log-stripe-issues to create issues. Invoke for: Stripe audit, payment review, subscription analysis.
567 -
majiayu000 Bundle Crypto AuditAudit cryptographic implementations for weak algorithms, insecure defaults, predictable randomness, key management issues, and timing attacks. Use when reviewing security-critical crypto code.
567 -
majiayu000 Bundle Dast ScannerDynamic Application Security Testing execution and management. Configure and execute OWASP ZAP and Nuclei scans, run authenticated scanning, manage scan policies and scope, correlate findings with SAST results, and generate comprehensive vulnerability reports.
567 -
majiayu000 Bundle Eks SecurityEKS security hardening and best practices. Use when configuring cluster security, implementing pod security, managing secrets, preparing for compliance audits, hardening infrastructure, scanning containers, or responding to security incidents.
567 -
majiayu000 Bundle Kompliance XPerforms intelligent compliance audits for software projects. Automatically detects which regulatory frameworks (GDPR, HIPAA, PCI-DSS, CCPA, SOC 2) apply based on project analysis and user context. Provides tiered reports with executive summaries and detailed technical findings. Use when the user asks about compliance, regulatory requirements, security standards, data protection, or wants to audit their codebase for legal/regulatory adherence.
567 -
majiayu000 Bundle Tls SecurityExpert skill for TLS/SSL implementation and certificate management. Generate and validate TLS configurations, create and manage X.509 certificates, analyze cipher suite security, debug TLS handshake failures, and implement certificate pinning.
567 -
majiayu000 Bundle Sapcc AuditFull-repo SAP CC Go compliance audit against review standards.
567 -
majiayu000 Bundle SeverityData-driven severity classification for smart contract audit findings with statistical breakdowns and 30 representative examples per level from top audit firms. Use when assigning severity to findings, justifying classifications with historical data, or calibrating severity judgment against Code4rena, Sherlock, and Cyfrin benchmarks.
567 -
majiayu000 Bundle SelfauditPause and do a first-principles audit of recent work
567 -
majiayu000 Bundle AuditcodexSend recent work to OpenAI Codex CLI for an independent audit/review
567 -
majiayu000 Bundle Typo3 SecuritySecurity hardening checklist and best practices for TYPO3 v13/v14 installations, covering configuration, file permissions, and common vulnerabilities.
567 -
majiayu000 Bundle Review BugsAudit code for logical bugs, race conditions, edge cases, and error handling issues.
567 -
majiayu000 Bundle Gdpr CheckVerify GDPR/CNIL compliance on entities
567 -
majiayu000 Bundle Secure AuthSecure authentication implementation patterns. Use when implementing user login, registration, password reset, session management, JWT authentication, or OAuth integration. Provides production-ready patterns that avoid common tutorial pitfalls like insecure token storage, weak password hashing, and session fixation.
567 -
majiayu000 Bundle Ssl Checker查询域名的SSL证书信息,包括到期时间、颁发者等详情
567 -
majiayu000 Bundle Attack FlowGenerate SITF-compliant attack flow JSON files from attack descriptions or incident reports. Use when analyzing supply chain attacks, breaches, or security incidents.
567 -
majiayu000 Bundle Auth HelperBetter Auth integration specialist for user authentication, sessions, and security management
567 -
majiayu000 Bundle Auth ShieldSecurity-first authentication, authorization, and session management architect for modern web + mobile apps using Supabase Auth. Use when: - Designing or reviewing authentication flows (signup, login, logout, password reset, magic link) - Implementing or auditing passkeys/WebAuthn/FIDO2 support - Configuring MFA (TOTP, WebAuthn second factor, recovery codes) - Setting up or reviewing OAuth2/OIDC flows (Google, Apple, SAML SSO) - Reviewing session management (token TTLs, rotation, storage, revocation) - Hardening mobile auth (Keychain/Keystore, deep-link safety, app attestation) - Performing auth threat modeling for new features - Reviewing auth-related PRs for security pitfalls - Adding step-up authentication for sensitive operations - Fixing auth bugs, token leaks, or session issues Triggers: "auth", "login", "signup", "passkey", "WebAuthn", "MFA", "2FA", "TOTP", "OAuth", "SSO", "magic link", "password reset", "CSRF", "refresh token", "session fixation", "PKCE", "biometric"
567 -
majiayu000 Bundle Security SymfonySicherheit & DSGVO - Atoll Tourisme. Use when reviewing security, implementing auth, or hardening code.
567
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include auth-shield, pls-audit-website, afrexai-ai-spend-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.