Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
modbender Bundle Skill Security Scanner 2Security scanner for OpenClaw skills. Use when installing, updating, or auditing skills to detect malicious backdoors, suspicious code patterns, data exfiltration risks, and security vulnerabilities. Automatically analyzes Python/JavaScript/Shell code for dangerous functions (eval, exec, system calls), network requests, file operations, environment variable access, obfuscation patterns, and known attack signatures. Provides security score and installation recommendations.
12 -
modbender Skill Weather Checker 2Get current weather information for any city
12 -
modbender Bundle Owasp Asi03 IdentityIdentity Abuse Skill (OWASP ASI03)
12 -
modbender Bundle Skill Hunter 2Find, evaluate, and install ClawHub skills. Semantic search across 10,000+ skills, security vetting before install, side-by-side comparison. The skill that makes skills useful.
12 -
modbender Skill Owasp Asi02 Tool MisuseTool Misuse Skill (OWASP ASI02)
12 -
modbender Skill Cio Intelligence 2Chief Intelligence Officer analytical framework for AI startups. Use for competitive analysis, technology trend assessment, signal classification, opportunity scoring, threat identification, and strategic intelligence briefings.
12 -
modbender Skill Email Reporter 2Generates email reports and statistics using gog CLI. Creates daily/weekly summaries, spam stats, sender analysis, pending tasks, audit history, and exports data to Google Sheets or text files using gog sheets/docs. Use when the user wants a report, summary, statistics, or export of email activity.
12 -
teng-bio Bundle Bio Reviewer ResponseDraft, audit, or revise point-by-point reviewer responses for bioinformatics manuscripts. Use for 生信审稿回复, 逐点回复, 大修回复, reviewer质疑batch effect/FDR/外部验证/数据泄露/样本量/方法可复现. Do not claim analyses, revisions, citations, line numbers, figures, or validations were completed unless supplied by the author.
-
teng-bio Bundle Project Version CuratorPost-hoc audit, cleanup planning, and release/staging preparation for already messy project directories where many dated, v1/v2/v3, final/current, intermediate, figure, table, and script files are mixed together. Use when Codex is asked to audit existing version clutter, generate an inventory, detect duplicate/conflicting historical files, map files to accepted/candidate/legacy status using project indexes, or create a dry-run cleanup/release plan after the fact. For active development-time guardrails, new runs, promotion, baselines, or branching, use project-flow-guard instead.
-
teng-bio Bundle Bio Data Code AvailabilityPrepare or audit Data Availability and Code Availability statements for bioinformatics manuscripts. Use for 生信数据可用性, 代码可用性, GEO/SRA/ENA/BioProject/BioSample/PRIDE/Zenodo/GitHub accession, FAIR清单, source data. Do not invent repository records, accessions, DOIs, licences, embargo dates, or access restrictions.
-
finchipaiorg Skill Draft Corrective Action MemorandumI-9 compliance corrective action memorandum following an internal audit, where the remediation plan must distinguish between paperwork corrections, anti-discrimination concerns requiring separate treatment, and ongoing work-authorization obligations for nonimmigrant employees.
-
syntavell Bundle Syntavell Git CommitUse this skill only when the user asks Codex to inspect Git state, stage paths, create or amend a commit, prepare a commit message, update a Syntavell submodule pointer, or publish an already authorized branch. Do not use it for ordinary code review, implementation, documentation editing, or security review when no Git operation was requested.
-
syntavell Bundle Syntavell Security ReviewUse this skill to review Syntavell changes, designs, dependencies, or releases for security, privacy, integrity, and supply-chain risk. Do not use it for ordinary implementation, documentation editing, Git commits, or public vulnerability disclosure text unless the user explicitly asks for security review or disclosure handling.
-
finchipaiorg Skill Compare I9 Roster AuditCross-audit comparing an employee roster against employment eligibility verification records to identify compliance gaps at the individual employee level, with employee-specific documentation, timing, and reverification analysis.
-
finchipaiorg Skill Draft Mortgage And Security AgreementGuides drafting of a commercial mortgage and security agreement by reconciling the deal terms, title materials, appraisal, operating documents, and renovation materials into a complete security instrument with a companion issues memorandum.
-
finchipaiorg Skill Review Enterprise Saas AgreementGuides preparation of a risk-tiered issues memo for an enterprise SaaS agreement review in a regulated-data context where privacy compliance, security controls, service levels, and contractual terms must be assessed against the vendor's representations.
-
finchipaiorg Skill Draft Complaint Trade Secret MisappropriationFederal complaint for trade secret misappropriation and related claims, plus a strategic memo flagging anticipated defenses and litigation concerns, based on forensic and employment documentation.
-
finchipaiorg Skill Draft Vendor Due Diligence MemorandumGuides preparation of a vendor due diligence memorandum for a procurement committee where contractual, security, compliance, and reference findings must be synthesized into a structured recommendation.
-
finchipaiorg Skill Draft Ice Noi Response PackageDraft a multi-document response package to an employment verification notice of inspection, keeping the external response, privileged internal audit materials, and remediation planning separate and handling each according to its audience and privilege posture.
-
finchipaiorg Skill Draft ComplaintDrafting a federal complaint for trade secret misappropriation and breach of an employment agreement requires pleading each claim element with supporting factual specificity, satisfying the applicable trade secret statute's definitional requirements, and pairing the complaint with a separate strategic concerns memo.
-
finchipaiorg Skill Draft Internal Audit Work PlanAgents produce a work plan that lists audit topics without a structured audit universe with risk ratings and cycle frequencies, fail to reconcile available hours against the co-sourcing cap, omit engagement-specific rationales for each planned area, and miss supervisory guidance thresholds that justify concentration-area audit priorities.
-
finchipaiorg Skill Draft Compliance Audit MemorandumGuides drafting of a pre-acquisition environmental compliance audit memorandum by organizing findings facility-by-facility and medium-by-medium, with assessment of open regulatory matters and their implications for the transaction, using only generic categories and procedural analysis.
-
finchipaiorg Skill Draft InterrogatoriesDrafting interrogatories in a trade secret misappropriation case requires structuring questions to establish the factual basis for alleged misappropriation, the scope of any competitive use, and the identities and roles of relevant individuals, while respecting the applicable limit on interrogatory count including subparts.
-
finchipaiorg Skill Hls Analyze Compliance Program GapsIdentifies structural and documentary gaps in a healthcare data privacy compliance program using incident records, vendor tracking, audit findings, and governance minutes to produce a remediation-focused memorandum.
-
finchipaiorg Skill Hls Compare Policies Hipaa Security RuleCompares security and privacy policies against the HIPAA Security Rule on a policy-by-policy basis, organizing gaps by applicable safeguard category and tailoring remediation sequencing to external compliance deadlines.
-
finchipaiorg Skill Hipaa Security Rule Policy Gap AnalysisHIPAA Security Rule gap analysis comparing each security policy against the applicable regulatory requirements, organized by safeguard category, with remediation recommendations aligned to an upcoming regulatory audit.
-
finchipaiorg Skill Hipaa Compliance Program Gap AnalysisGap analysis of a healthcare organization’s privacy and security compliance program, identifying deficiencies in administrative safeguards, breach notification procedures, and vendor oversight against applicable healthcare privacy and security requirements.
-
finchipaiorg Skill Sec Examination Audit Findings MemoPrivileged audit findings memorandum for the board summarizing examination deficiency findings, analyzing their severity and legal basis, identifying evidence of intent where relevant, and recommending a response strategy.
-
finchipaiorg Skill Extract Penalty Calculations From Fine NoticeStructured audit of a civil penalty notice where the analysis must reconstruct the penalty calculation arithmetic from the notice's components, verify each step against the underlying findings, and identify contestable errors in violation count, rate application, or adjustment factor direction.
-
finchipaiorg Skill Draft Open Source Compliance PolicyBoard-ready open source software compliance policy for a technology company, incorporating audit findings, customer contract obligations, engineering practices, and a pending relicensing development.
-
finchipaiorg Skill Identify Compliance Issues In Employee I9Audit employee I-9 forms against the applicable completion, document, and consistency requirements, using roster or intake data as needed to verify timing and form-level accuracy at the individual employee level.
-
finchipaiorg Skill Identify Issues In Security Agreement Term LoanGuides issue identification in a security agreement for a senior secured lender by systematically checking perfection requirements, cross-document consistency on collateral package terms, and remedies provisions.
-
finchipaiorg Skill Hls Identify Government Subpoena IssuesReviews a government healthcare subpoena and supporting materials to identify potential temporal scope objections, relator indicators, audit privilege risks, retaliation exposure, successor-liability issues, parallel-state-investigation coordination needs, and spoliation concerns.
-
finchipaiorg Skill Draft Security Agreement Whole BusinessDrafting a security agreement for a whole business securitization where the collateral includes operating contracts, intellectual property, deposit accounts, and equipment, requiring layered cash management mechanics, perfection steps for each collateral type, and identification of pre-existing lien and consent issues before closing.
-
finchipaiorg Skill Extract Deficiencies From Internal Audit ReportStructured deficiency matrix extracted from a structured immigration compliance audit report, where the analysis must classify each deficiency by regulatory type and severity and separately flag any potential anti-discrimination exposure for further review.
-
finchipaiorg Skill Ecvc Draft Subordination AgreementDrafting a subordination agreement requires distinguishing lien subordination from debt subordination, addressing purchase money security interest carve-outs, considering bankruptcy-related consent provisions, specifying subrogation rights, and aligning governing law with the senior loan agreement.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include skill-security-scanner, weather-checker, owasp-asi03-identity. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.