Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
uitbreidenos Skill Compensation ModelerCommission accrual simulation, payout forecasts, plan design validation, dispute audit trails, and what-if modeling for compensation changes. Tracks all changes for compliance.
-
uitbreidenos Skill Audit Report WriterAudit Report Writer
-
uitbreidenos Skill Incident ClassifierClassifies security incident by severity, scope (affected users/systems), timeline (how long was it happening?), and activates response plan.
-
uitbreidenos Skill Security ComplianceSecurity & Compliance Audit
-
uitbreidenos Skill Hipaa Compliance CheckerEvaluates systems, workflows, and data handling practices against HIPAA Privacy and Security Rules. Outputs a compliance gap analysis with risk-rated findings, remediation steps, and required documentation checklist.
-
uitbreidenos Skill Medical Coding ValidatorValidates medical coding accuracy for ICD-10-CM/PCS, CPT, and HCPCS codes against clinical documentation. Outputs a coding audit with accuracy scores, common error patterns, and correction recommendations.
-
rushikeshsakharleofficial Skill Security ExpertUse when performing security audits, vulnerability scanning, or implementing secure coding practices.
-
deedeeharris Skill BhUse when asked to hunt bugs, find and fix bugs, audit code quality, or run /bh. Launches the generic/bug-hunter babysitter process on the current repo. Supports yolo (auto-fix) and interactive (breakpoints) modes.
-
deedeeharris Skill Bh AuditUse when asked to audit code for bugs without fixing them. Scans the repo with 3 independent expert judges (weighted scoring + expert veto), proves root causes, and generates a report. NEVER modifies code — read-only audit.
-
deedeeharris Skill Coding StandardsUniversal coding standards for any language or stack. Run BEFORE writing code (to set intent) and AFTER writing code (to verify quality). Covers naming, structure, security, tests, and commits.
-
ai-agent-lead Skill Pr ReviewDiscipline for reviewing someone else's pull request — the inverse of `prod-ready` (which is the author's pre-merge gate). Use when the user asks to "review this PR", "look over the diff", "check this change", "give feedback on", or invokes a code-review slash command. Reviews against the linked feature doc / ADRs / domain vocabulary, classifies findings by severity (blocker / suggestion / nit), and returns a structured report. Skip for trivial PRs (typo, dep bump, lint-only) — approve directly. Pairs with `prod-ready` (the author's checklist; the reviewer verifies it landed honestly), `security-review` (escalation when the diff is surface-changing), and the `code-hygiene` lens (`formats/CODE-HYGIENE.md`, applied line-level during the read).
-
tomz Skill Sf DataSOQL, SOSL, Data Loader, sf data CLI, Bulk API 2.0, Record Types, sharing rules, field-level security, and data management patterns
-
aa920044 Bundle Code ReviewerReview changed files, pull requests, diffs, branches, or pasted code for correctness bugs, security vulnerabilities, performance problems, maintainability risks, and architectural issues. Use when the user asks for a code review, PR review, diff review, merge readiness assessment, or actionable feedback on code quality and best practices.
-
vc999999999 Bundle Springboot Code ReviewerReviews Java 25 and Spring Boot 4 codebases, pull requests, files, and modules for migration risks, architecture boundary violations, JSpecify null-safety issues, security flaws, performance regressions, and Spring Data pitfalls. Use when the task is a concrete Java or Spring code review with code context. Do not use for Kotlin-only code, non-Spring frameworks, or generic review advice without files or diffs.
-
tomz Skill Cloudflare WafCloudflare WAF and security — Custom Rules, Managed Rules, rate limiting, bot management, Turnstile CAPTCHA, and incident response workflow.
-
miramocha Skill Audit Uitk Uss Class TogglesAudits Grid Dungeon UI Toolkit C# for unnecessary VisualElement.style writes that should be BEM USS class toggles instead. Auto-enables caveman mode (full) for audit output. Use when the user asks to audit inline styles, USS vs C# styling, style.display/opacity in views, UITK class toggle compliance, or before/after UITK refactors.
-
tomz Skill Oci NetworkingOCI networking — VCN, subnets, security, load balancers, gateways, DRG, VPN, DNS, and peering
-
modbender Skill ClawauditOfficial repo for clawaudit, coming soon as an automated security checker for repositories.
12 -
modbender Skill Backup 3Implement reliable backup strategies avoiding data loss, failed restores, and security gaps.
12 -
modbender Bundle Csp Gen 2Generate Content Security Policy headers for your site. Use when you need to add CSP headers without spending hours reading the spec.
12 -
modbender Bundle API Gateway 3Connect to 100+ APIs (Google Workspace, Microsoft 365, Notion, Slack, Airtable, HubSpot, etc.) with managed OAuth. Use this skill when users want to interact with external services. Security: The MATON_API_KEY authenticates with Maton.ai but grants NO access to third-party services by itself. Each service requires explicit OAuth authorization by the user through Maton's connect flow. Access is strictly scoped to connections the user has authorized. Provided by Maton (https://maton.ai).
12 -
modbender Bundle Code Review 2AI-powered code analysis via LogicArt — find bugs, security issues, and get logic flow visualizations. Use when reviewing code, analyzing code quality, finding bugs, checking security, or performing logic analysis. Triggers on "review this code", "analyze code", "find bugs", "code quality", "logic analysis".
12 -
modbender Bundle Openclaw Shield 2Enterprise security scanner for AI agents. Detects credential theft, data exfiltration, and malicious code with static analysis + runtime guards + ClamAV integration. Audit logging and tamper-evide...
12 -
modbender Skill Healthcheck 2Host security hardening and risk-tolerance configuration for OpenClaw deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, OpenClaw cron scheduling for periodic checks, or version status checks on a machine running OpenClaw (laptop, workstation, Pi, VPS).
12 -
modbender Skill Audit Badge DemoDemo skill showcasing the audit badge workflow; still experimental.
12 -
modbender Bundle Healthcheck Readiness Starter SkillDescription: Performs a quick risk posture check on the host and reports basic security/posture status.
12 -
modbender Skill Test Audit BadgeTest skill to demonstrate the audit badge; do not use it for real workflows.
12 -
modbender Bundle Skill Reviewer 2Comprehensive skill review and validation. Use when you need to audit an OpenClaw skill for correctness, completeness, and compliance with OpenClaw specifications. Performs three levels of review: (1) Format validation via package_skill.py, (2) Content quality assessment of SKILL.md structure and writing, (3) Functional verification that generated templates/scripts match actual OpenClaw specifications.
12 -
modbender Skill Host Hardening 2Harden an OpenClaw Linux server with SSH key-only auth, UFW firewall, fail2ban brute-force protection, and credential permissions. Use when setting up a new OpenClaw instance, auditing server security, or after a security incident.
12 -
modbender Skill Install Vt Sentinel 2Install or upgrade VT Sentinel security plugin. Use when the user asks to install, set up, enable, update, or upgrade VT Sentinel, VirusTotal scanning, malware protection, or file security scanning. Handles fresh installs and upgrades from any previous version.
12 -
modbender Skill Security 3Security Best Practices 🔒
12 -
modbender Bundle Security Scanner 4Scans OpenClaw skills for security vulnerabilities and suspicious patterns before installation
12 -
modbender Bundle Skill Install Guardian 2Security and due diligence layer for installing external skills from ClawHub. Performs DEEP content scanning for malicious patterns, security checks, integration analysis, and requires owner confirmation before installation.
12 -
modbender Skill Vendor Risk Assessment 2Assess third-party vendor risk for AI and SaaS products. Evaluates security posture, data handling, compliance, financial stability, and operational resilience. Use when onboarding new vendors, conducting annual reviews, or building a vendor management program. Generates a scored risk report with mitigation recommendations. Built by AfrexAI.
12 -
modbender Bundle Glab Attestation 2Work with GitLab attestations for software supply chain security including artifact verification and provenance. Use when verifying software artifacts, managing attestations, or working with supply chain security. Triggers on attestation, verify artifact, provenance, supply chain security.
12 -
modbender Bundle Credential Manager 2MANDATORY security foundation for OpenClaw. Consolidate scattered API keys and credentials into a secure .env file with proper permissions. Includes GPG encryption for high-value secrets, credential rotation tracking, deep scanning, and backup hardening. Use when setting up OpenClaw, migrating credentials, auditing security, or enforcing the .env standard. This is not optional — centralized credential management is a core requirement for secure OpenClaw deployments.
12
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include compensation-modeler, audit-report-writer, incident-classifier. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.