Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
humaisali Skill Ethical Hacking MethodologyMaster the complete penetration testing lifecycle from reconnaissance through reporting. This skill covers the five stages of ethical hacking methodology, essential tools, attack techniques, and professional reporting for authorized security assessments.
-
johnalbertini14-glitch Bundle Sec AuditOpenClaw Security Audit Skill
1 -
humaisali Bundle API Endpoint BuilderBuilds production-ready REST API endpoints with validation, error handling, authentication, and documentation. Follows best practices for security and scalability.
-
humaisali Skill API Security TestingAPI security testing workflow for REST and GraphQL APIs covering authentication, authorization, rate limiting, input validation, and security best practices.
-
humaisali Bundle Apple Hig ExpertAudits and designs iOS/macOS/watchOS/visionOS interfaces against the Apple Human Interface Guidelines, including the Liquid Glass design language (announced WWDC25, shipped with iOS 26/macOS Tahoe, Sept 2025). Use when reviewing an Apple-platform mockup or app for HIG compliance, checking contrast or tap-target sizes, or designing native-feeling Apple UI (e.g., 'audit my iOS app against the HIG', 'is this text readable on Liquid Glass?').
-
humaisali Skill Production AuditAudit a shipped repo for production-readiness gaps across RLS, webhooks, secrets, grants, Stripe idempotency, mobile UX, and deployment health.
-
humaisali Bundle Wcag Audit PatternsComprehensive guide to auditing web content against WCAG 2.2 guidelines with actionable remediation strategies.
-
humaisali Bundle Protocol Reverse EngineeringComprehensive techniques for capturing, analyzing, and documenting network protocols for security research, interoperability, and debugging.
-
humaisali Bundle Stride Analysis PatternsApply STRIDE methodology to systematically identify threats. Use when analyzing system security, conducting threat modeling sessions, or creating security documentation.
-
humaisali Skill Nodejs Best PracticesNode.js development principles and decision-making. Framework selection, async patterns, security, and architecture. Teaches thinking, not copying.
-
johnalbertini14-glitch Bundle CrawsecureOffline security scanner for ClawHub skills — detect unsafe patterns before installation.
1 -
johnalbertini14-glitch Bundle ClawdvaultSECURITY NOTICE: The following content is from an EXTERNAL, UNTRUSTED source (e.g., email, webhook).
1 -
johnalbertini14-glitch Bundle Raini Skill AuditSkill Audit 🔍
1 -
johnalbertini14-glitch Bundle Clawguard 2Security scanner for OpenClaw/Clawdbot skills - detect malicious patterns before installation
1 -
johnalbertini14-glitch Bundle Afrexai Energy AuditEnergy Audit — Commercial Building Assessment
1 -
johnalbertini14-glitch Bundle Afrexai Payroll AuditPayroll Compliance Auditor
1 -
johnalbertini14-glitch Bundle Business Process AuditBusiness Process Audit
1 -
johnalbertini14-glitch Bundle Afrexai AI Safety AuditAI Safety Audit
1 -
johnalbertini14-glitch Bundle Afrexai Tech Debt AuditTechnical Debt Audit
1 -
johnalbertini14-glitch Bundle Skill Auditor 2Security audit and quarantine system for third-party OpenClaw skills. Use when evaluating, reviewing, or installing any skill from ClawHub or external sources. Automatically triggered before any skill installation.
1 -
johnalbertini14-glitch Bundle Claw Security ScannerClaw Security Scanner
1 -
johnalbertini14-glitch Bundle Openclaw Skill ScannerSecurity gate for OpenClaw AgentSkills. Scans folder/ClawHub skills with cisco-ai-defense/skill-scanner before installation. Supports manual scans, staged installs, and auto-quarantine of high-risk skills via systemd.
1 -
johnalbertini14-glitch Skill SecuritySecurity Best Practices 🔒
1 -
johnalbertini14-glitch Bundle Security Vuln ScannerSecurity Vulnerability Scanner
1 -
ncdevshiv Skill Idor TestingThis skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or obje...
-
ncdevshiv Skill Code ReviewerElite code review expert specializing in modern AI-powered code analysis, security vulnerabilities, performance optimization, and production reliability. Masters static analysis tools, security scanning, and configuration review with 2024/2025 best practices. Use PROACTIVELY for code quality assurance.
-
ncdevshiv Skill Laravel ExpertSenior Laravel Engineer role for production-grade, maintainable, and idiomatic Laravel solutions. Focuses on clean architecture, security, performance, and modern standards (Laravel 10/11+).
-
ncdevshiv Skill Red Team ToolsThis skill should be used when the user asks to "follow red team methodology", "perform bug bounty hunting", "automate reconnaissance", "hunt for XSS vulnerabilities", "enumerate su...
-
ncdevshiv Skill Scanning ToolsThis skill should be used when the user asks to "perform vulnerability scanning", "scan networks for open ports", "assess web application security", "scan wireless networks", "detec...
-
ncdevshiv Skill Security AuditComprehensive security auditing workflow covering web application testing, API security, penetration testing, vulnerability scanning, and security hardening.
-
ncdevshiv Skill FirebaseFirebase gives you a complete backend in minutes - auth, database, storage, functions, hosting. But the ease of setup hides real complexity. Security rules are your last line of defense, and they'r...
-
ncdevshiv Skill Find BugsFind bugs, security vulnerabilities, and code quality issues in local branch changes. Use when asked to review changes, find bugs, security review, or audit code on the current branch.
-
ncdevshiv Skill WordpressComplete WordPress development workflow covering theme development, plugin creation, WooCommerce integration, performance optimization, and security hardening.
-
ncdevshiv Skill Fix ReviewVerify fix commits address audit findings without new bugs
-
ncdevshiv Skill Linkerd PatternsImplement Linkerd service mesh patterns for lightweight, security-focused service mesh deployments. Use when setting up Linkerd, configuring traffic policies, or implementing zero-trust networking ...
-
ncdevshiv Skill Security AuditorYou are a security auditor specializing in DevSecOps, application security, and comprehensive cybersecurity practices.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include ethical-hacking-methodology, sec-audit, api-endpoint-builder. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.