Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
jeremylongshore Skill Scanning Database Security 2Process use when you need to work with security and compliance. This skill provides security scanning and vulnerability detection with comprehensive guidance and automation. Trigger with phrases like "scan for vulnerabilities", "implement security controls", or "audit security".
-
jeremylongshore Skill Scanning Container Security 2Execute use when you need to work with security and compliance. This skill provides security scanning and vulnerability detection with comprehensive guidance and automation. Trigger with phrases like "scan for vulnerabilities", "implement security controls", or "audit security".
-
jeremylongshore Skill Checking Infrastructure Compliance 2Execute use when you need to work with compliance checking. This skill provides compliance monitoring and validation with comprehensive guidance and automation. Trigger with phrases like "check compliance", "validate policies", or "audit compliance".
-
jeremylongshore Skill Implementing Database Audit Logging 2Process use when you need to track database changes for compliance and security monitoring. This skill implements audit logging using triggers, application-level logging, CDC, or native logs. Trigger with phrases like "implement database audit logging", "add audit trails", "track database changes", or "monitor database activity for compliance".
-
dvcrn Bundle Erp ClawAI-native ERP system. Full accounting, invoicing, inventory, purchasing, tax, billing, HR, payroll, advanced accounting (ASC 606/842, intercompany, consolidation), and financial reporting in a single install. 365+ actions across 14 domains. Modular expansion via GitHub-hosted modules. Double-entry GL, immutable audit trail, US GAAP.
32 -
dvcrn Bundle Csp Gen 2Generate Content Security Policy headers for your site. Use when you need to add CSP headers without spending hours reading the spec.
32 -
dvcrn Bundle Clawback 2Gmail security proxy with policy enforcement, approval workflows, and audit logging. Use when the user wants to read, search, or send Gmail with guardrails — send actions may require human approval before executing.
32 -
dvcrn Bundle Clawback 3Gmail security proxy with policy enforcement, approval workflows, and audit logging. Use when the user wants to read, search, or send Gmail with guardrails — send actions may require human approval before executing.
32 -
dvcrn Bundle Auto Reply 2Instagram DM auto-reply system. DM monitoring, reading, replying, security check (injection rejection). Use when checking Instagram DMs, reading unread messages, replying to DMs, setting up DM monitoring cron jobs, or handling DM auto-reply workflows. Triggers on: Instagram DM, DM check, DM reply, DM auto-reply, dm-alert.
32 -
dvcrn Bundle Cifer Sdk 2Implement quantum-resistant encryption using the CIFER SDK (cifer-sdk npm package). Covers SDK initialization, wallet setup, secret creation, text encryption/decryption, and file encryption/decryption on any supported chain (Ethereum, Sepolia, Ternoa). Use when the user mentions CIFER, cifer-sdk, quantum-resistant encryption, ML-KEM, secret creation, or encrypted payloads/files with blockchain.
32 -
dvcrn Bundle Clawguard 4Security scanner for OpenClaw/Clawdbot skills - detect malicious patterns before installation
32 -
dvcrn Bundle Clawguard 5Security scanner for ClawHub skills. Analyze before you install.
32 -
dvcrn Bundle API Gateway 2API gateway for calling third-party APIs with managed auth. Use this skill when users want to interact with external services like Slack, HubSpot, Salesforce, Google Workspace, Stripe, and more.
32 -
dvcrn Skill Skill Vetter 2Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.
32 -
dvcrn Bundle Skill Audit 2Audits Claude skills from GitHub repositories for effectiveness, token usage, safety, and best-practice compliance, then automatically generates bilingual social media posts about the findings. Use when the user wants to audit a skill, review a skill from GitHub, analyze a SKILL.md, evaluate skill quality, or check a skill for safety and permission issues.
32 -
dvcrn Bundle Skill Audit 3Runs a deterministic static safety audit for third-party AI skill or plugin repositories before install or execution. Use when asked to scan a skill repo, assess whether a repo is safe to install, run a skill safety assessment, or produce evidence-backed findings for pre-install security screening.
32 -
dvcrn Bundle Code Review 2AI-powered code analysis via LogicArt — find bugs, security issues, and get logic flow visualizations. Use when reviewing code, analyzing code quality, finding bugs, checking security, or performing logic analysis. Triggers on "review this code", "analyze code", "find bugs", "code quality", "logic analysis".
32 -
dvcrn Bundle Openclaw Shield 2Security audit engine for OpenClaw configurations. Detects vulnerabilities, misconfigurations, secret leaks, and over-privileged agents. Use when the user asks about security, hardening, config review, or audit of their OpenClaw setup.
32 -
dvcrn Bundle Skill Scanner 3Scan OpenClaw skills for security vulnerabilities before installing them. Use when evaluating a new skill from ClawHub or any third-party source. Detects credential stealers, data exfiltration, malicious URLs, obfuscated code, and supply chain attacks.
32 -
dvcrn Bundle Skill Shield 2Security audit tool for ClawHub skills. Scans a skill directory with 65 detection patterns, anti-obfuscation analysis, and dual rating system (Security + Compliance). v0.6.1 fixes batch scan performance by skipping venv/node_modules directories. Use when: installing a new skill, reviewing skill safety, or auditing permissions.
32 -
dvcrn Skill Audit 2Smart contract audit checklist for HyperEVM — covers Solidity security, HyperEVM-specific risks, API signing security, and bonding curve/AMM patterns. Run before every mainnet deployment.
32 -
dvcrn Bundle Prisma Sase ClawHow to interact with the Palo Alto Networks Prisma SASE API, including Prisma Access, Prisma SD-WAN, and Prisma Access Browser. Use this skill whenever the user wants to query, configure, monitor, or automate anything related to Prisma SASE, Prisma Access, Prisma SD-WAN, Prisma Access Browser, Palo Alto SASE, PANW SASE, or network security policies managed through the SASE platform. Also trigger when the user mentions tenant service groups (TSGs), SASE API tokens, security policy rules, SD-WAN sites, remote networks, GlobalProtect, or aggregate monitoring via the SASE platform.
32 -
dvcrn Bundle Security Audit 2Comprehensive security auditing for Clawdbot deployments. Scans for exposed credentials, open ports, weak configs, and vulnerabilities. Auto-fix mode included.
32 -
dvcrn Bundle Code Review 3Complete code review workflow for GitCode PRs. Combines automated security scanning with manual code review, outputs formatted findings, and posts comments to PR. Use when reviewing GitCode pull requests - follows 5-step process: automated scan, manual review, issue selection, formatted output, and optional PR comment posting.
32 -
dvcrn Bundle Moltguard 2MoltGuard — runtime security plugin for OpenClaw agents by OpenGuardrails. Helps users install, register, activate, and check the status of MoltGuard. Use when the user asks to: install MoltGuard, check MoltGuard status, register or activate MoltGuard, configure the AI Security Gateway, or understand what MoltGuard detects. Provides local-first protection against data exfiltration, credential theft, command injection, and sensitive data leakage. Source: https://github.com/openguardrails/openguardrails/tree/main/moltguard
32 -
dvcrn Bundle Skill Reviewer 3Comprehensive skill review and validation. Use when you need to audit an OpenClaw skill for correctness, completeness, and compliance with OpenClaw specifications. Performs three levels of review: (1) Format validation via package_skill.py, (2) Content quality assessment of SKILL.md structure and writing, (3) Functional verification that generated templates/scripts match actual OpenClaw specifications.
32 -
dvcrn Bundle Nano Banana 2 3Gemini image generation, editing, and search-grounded image creation via gemini-3.1-flash-image-preview (Nano Banana 2). USE FOR: - Generating images from text prompts (text-to-image) - Editing or transforming an existing image with text instructions - Generating images grounded in live web/image search results Requires GEMINI_API_KEY environment variable. See rules/setup.md for configuration and rules/security.md for output handling guidelines.
32 -
dvcrn Skill Healthcheck 2Host security hardening and risk-tolerance configuration for OpenClaw deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, OpenClaw cron scheduling for periodic checks, or version status checks on a machine running OpenClaw (laptop, workstation, Pi, VPS).
32 -
dvcrn Bundle Clawhub Publish 2Create, package, and publish OpenClaw skills to ClawHub. Use when you need to: (1) build a new skill from scratch, (2) package a skill into a .skill file, (3) publish or update a skill on clawhub.com, (4) set up a GitHub repo for a skill, (5) audit a skill before publishing. Covers the full lifecycle from idea to published skill, including frontmatter, scripts, references, validation, versioning, and the clawhub CLI. Complements the skill-creator skill with ClawHub-specific publishing workflow and practical patterns.
32 -
dvcrn Bundle Rey Network ScannerDiscover devices and scan ports on your local network using nmap with security-first defaults.
32 -
dvcrn Bundle Skillguard 3AI-powered security scanner for OpenClaw skills. Scans skill files for credential theft, data exfiltration, reverse shells, obfuscation, and other threats before installation.
32 -
dvcrn Bundle Security Audit 4Security audit for external resources (GitHub repos, downloaded skills, files). Detects malicious code, suspicious executables, and content mismatches. Use when: (1) cloning GitHub projects, (2) downloading skills from web, (3) running external code/scripts. Always run before trusting or executing external code.
32 -
dvcrn Bundle Skill Auditor 5Security audit and quarantine system for third-party OpenClaw skills. Use when evaluating, reviewing, or installing any skill from ClawHub or external sources. Automatically triggered before any skill installation.
32 -
dvcrn Skill Clawhub Skill Creator 2Create ClawhHub-ready OpenClaw skills with correct structure, scanner criteria, security rules & publish checklist. No credentials or binaries required.
32 -
dvcrn Bundle Security Scanner 2Scans OpenClaw skills for security vulnerabilities and suspicious patterns before installation
32 -
dvcrn Bundle Feishu Card Sender 2发送飞书卡片消息(支持纯文本和图片)。使用 message 工具的 card 参数,需要配置飞书应用凭证(App ID + App Secret)。
32
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include scanning-database-security, scanning-container-security, openclaw-shield. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.