Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
opencue Bundle Vc RepomixUse when you need to pack a local or remote repository into an AI-friendly reference artifact for research, audits, feature-porting prep, context review, or security-oriented repo analysis.
-
opencue Bundle Vc Repomix 2Use when you need to pack a local or remote repository into an AI-friendly reference artifact for research, audits, feature-porting prep, context review, or security-oriented repo analysis.
-
opencue Bundle Vc SecuritySTRIDE + OWASP-based security audit with optional auto-fix. Scans code for vulnerabilities, categorizes by severity, and can iteratively fix findings using vc:autoresearch pattern.
-
opencue Bundle Clawsec FeedSecurity advisory feed package for OpenClaw-related threats and vulnerabilities. The upstream feed is updated daily; local automation is handled by clawsec-suite or the operator.
-
opencue Bundle ClawtributorCommunity incident reporting for AI agents. Contribute to collective security by reporting threats.
-
opencue Bundle Clawsec SuiteClawSec suite manager with embedded advisory-feed monitoring, cryptographic signature verification, approval-gated malicious-skill response, and guided setup for additional security skills.
-
opencue Bundle Vc Audit PlansAudit active Flowser plan files for staleness, completion, and routing truth. Use when cleaning up plans, reconciling active work, or archiving completed artifacts.
-
opencue Bundle Vc Audit Plans 2Audit active Flowser plan files for staleness, completion, and routing truth. Use when cleaning up plans, reconciling active work, or archiving completed artifacts.
-
opencue Bundle AI Slop DetectorUse when the user asks to audit, score, humanize, or fix prose for AI-writing signals or readability. Produces separate AI-slop and comprehension findings with actionable edits.
-
opencue Bundle Clawsec NanoclawUse when checking for security vulnerabilities in NanoClaw skills, before installing new skills, or when asked about security advisories affecting the bot
-
opencue Bundle Vc Audit ContextAudit Flowser context routing, shared-skill discoverability, and Codex/Codex wiring. Use when context docs or skill surfaces move, split, or drift.
-
opencue Bundle Clawsec Nanoclaw 2Use when checking for security vulnerabilities in NanoClaw skills, before installing new skills, or when asked about security advisories affecting the bot
-
opencue Bundle Vc Audit Context 2Audit Flowser context routing, shared-skill discoverability, and Claude/Codex wiring. Use when context docs or skill surfaces move, split, or drift.
-
dvcrn Bundle Owasp Asi03 IdentityIdentity Abuse Skill (OWASP ASI03)
32 -
dvcrn Skill Owasp Asi02 Tool MisuseTool Misuse Skill (OWASP ASI02)
32 -
gabrielmoreira Skill Test WriterWrite, extend, or review tests in any codebase. Use this skill whenever the user asks to write tests, add test coverage, test a new feature, fix failing tests, or audit existing test files — regardless of language, framework, or project. Also trigger for "add tests for", "write tests for", "cover this with tests", "test this file", "update the tests", "improve coverage", or "this needs tests". This skill enforces universal testing rules (no .skip, no lowering thresholds, full-path coverage) and adapts its mock patterns and tooling to whatever stack the repo uses.
17 -
fabioc-aloha Skill Memory Curation 4Monitor, audit, and curate VS Code user memory (/memories/) for token efficiency, scope correctness, and value density
-
fabioc-aloha Skill Security Review 3Defend before attackers find the gaps - OWASP, STRIDE, and Microsoft SFI
-
fabioc-aloha Skill Fleet Management 2Keep heir projects synchronized with Master Alex brain updates — audit drift, upgrade brains, verify deployments
-
fabioc-aloha Skill Architecture Audit 3Comprehensive **project** consistency review across code, documentation, diagrams, and configuration
-
fabioc-aloha Skill Secrets Management 3Secure token storage, VS Code SecretStorage API, credential management, environment variable migration
-
gabrielmoreira Skill Recipe ReviewReviews completed implementation for governing-source compliance, scope economy, repository quality, and security, then applies user-approved corrections.
17 -
fabioc-aloha Skill Distribution Security 3Defense-in-depth, PII protection, secrets scanning, and secure packaging for distributed software
-
fabioc-aloha Skill Test Quality Analysis 3Analyze test code quality to detect coverage-only tests, test smells, and low-value assertions. Use when asked to "analyze test quality", "find coverage-only tests", "audit our tests", "are these tests valuable", "find test smells", or "which tests should we delete". Scores tests 1-5 on real value and produces prioritized improvement reports.
-
fabioc-aloha Skill Token Waste Elimination 4Audit and eliminate token waste from cognitive architecture memory files -- instructions, prompts, skills, and agents
-
fabioc-aloha Skill Documentation Quality Assurance 3Systematic documentation audit, drift detection, preflight validation, and multi-pass quality pipelines
-
bilal140202 Skill Springboot SecuritySpring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.
-
bilal140202 Bundle I18N AuditScan for hardcoded UI strings, missing translation keys, RTL layout breakages, untested locales, and date/number/currency hardcoding. Use when localizing a UI, adding a locale, or auditing internationalization readiness.
-
bilal140202 Skill Red Team AdversarialAdversarial security and resilience analysis — auto-triggered during /review and /test based on task classification. Provides attack surface analysis, boundary testing, auth bypass attempts, dependency chain attacks, and Beast Mode stress testing.
-
gabrielmoreira Skill Aem Security Access ControlAEM Security & Access Control
17 -
modbender Skill Clawguard 2Security scanner for OpenClaw/Clawdbot skills - detect malicious patterns before installation
12 -
gabrielmoreira Skill Tighten PolicyAnalyze and tighten ClawdStrike security policies
17 -
modbender Bundle Localstorage PocSecurity research - localStorage access via SVG XSS
12 -
modbender Skill Skill Auditor 3Analyze OpenClaw skill files for security risks, quality issues, and best-practice violations. Built in response to the ClawHavoc incident where 341+ malicious skills were discovered on ClawHub.
12 -
modbender Bundle Skillguard 2AI-powered security scanner for OpenClaw skills. Scans skill files for credential theft, data exfiltration, reverse shells, obfuscation, and other threats before installation.
12 -
modbender Bundle Rey Network ScannerDiscover devices and scan ports on your local network using nmap with security-first defaults.
12
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include vc:repomix, vc:repomix, vc:security. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.