Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
dvcrn Bundle Botlearn Healthcheck 2botlearn-healthcheck — BotLearn autonomous health inspector for OpenClaw instances across 5 domains (hardware, config, security, skills, autonomy); triggers on system check, health report, diagnostics, or scheduled heartbeat inspection.
32 -
dvcrn Skill Requesting Code Review 2Review diffs with structured checklist — spec compliance, security, tests, breaking changes, code quality
32 -
dvcrn Skill Install Vt Sentinel 2Install or upgrade VT Sentinel security plugin. Use when the user asks to install, set up, enable, update, or upgrade VT Sentinel, VirusTotal scanning, malware protection, or file security scanning. Handles fresh installs and upgrades from any previous version.
32 -
dvcrn Skill API Gateway 3Gateway universal para APIs. Conecta cualquier API REST/GraphQL con configuración simple. Gestiona autenticación, rate limiting y caching.
32 -
dvcrn Skill Security Audit 7Comprehensive OpenClaw security audit — checks gateway binding, credential exposure, channel policies, tool sandboxing, network/IP leaks, and macOS system security (SIP, FileVault, TCC).
32 -
dvcrn Bundle Credential Manager 2MANDATORY security foundation for OpenClaw. Consolidate scattered API keys and credentials into a secure .env file with proper permissions. Includes GPG encryption for high-value secrets, credential rotation tracking, deep scanning, and backup hardening. Use when setting up OpenClaw, migrating credentials, auditing security, or enforcing the .env standard. This is not optional — centralized credential management is a core requirement for secure OpenClaw deployments.
32 -
dvcrn Bundle Tech Stack EvaluatorTechnology stack evaluation and comparison with TCO analysis, security assessment, and ecosystem health scoring. Use when comparing frameworks, evaluating technology stacks, calculating total cost of ownership, assessing migration paths, or analyzing ecosystem viability.
32 -
dvcrn Skill Security Audit 8Audit codebases and infrastructure for security issues. Use when scanning dependencies for vulnerabilities, detecting hardcoded secrets, checking OWASP top 10 issues, verifying SSL/TLS, auditing file permissions, or reviewing code for injection and auth flaws.
32 -
dvcrn Bundle Google Workspace CLI 2Google Workspace administration via the gws CLI. Install, authenticate, and automate Gmail, Drive, Sheets, Calendar, Docs, Chat, and Tasks. Run security audits, execute 43 built-in recipes, and use 10 persona bundles. Use for Google Workspace admin, gws CLI setup, Gmail automation, Drive management, or Calendar scheduling.
32 -
dvcrn Bundle Social Media Manager 3When the user wants to develop social media strategy, plan content calendars, manage community engagement, or grow their social presence across platforms. Also use when the user mentions 'social media strategy,' 'social calendar,' 'community management,' 'social media plan,' 'grow followers,' 'engagement rate,' 'social media audit,' or 'which platforms should I use.' For writing individual social posts, see social-content. For analyzing social performance data, see social-media-analyzer.
32 -
dvcrn Bundle Security Check 2🔒 Pre-installation security verification for external code and dependencies. Automated risk analysis for GitHub repos, npm packages, PyPI libraries, and shell scripts. Integrates CVE databases (Snyk, Safety DB) to detect vulnerabilities before you install. Shows risk level (✅ safe / ⚠️ review / ❌ dangerous) with actionable recommendations. First comprehensive security skill for OpenClaw — protect your system before downloading untrusted code.
32 -
dvcrn Bundle Openclaw Skill Scanner 2Security gate for OpenClaw AgentSkills. Scans folder/ClawHub skills with cisco-ai-defense/skill-scanner before installation. Supports manual scans, staged installs, and auto-quarantine of high-risk skills via systemd.
32 -
dvcrn Skill Security 4Advanced security validation for Clawdbot - pattern detection, command sanitization, and threat monitoring
32 -
dvcrn Bundle Skill Security Scanner 2Security scanner for OpenClaw skills. Use when installing, updating, or auditing skills to detect malicious backdoors, suspicious code patterns, data exfiltration risks, and security vulnerabilities. Automatically analyzes Python/JavaScript/Shell code for dangerous functions (eval, exec, system calls), network requests, file operations, environment variable access, obfuscation patterns, and known attack signatures. Provides security score and installation recommendations.
32 -
dvcrn Bundle Security Audit 9Security audit helper for your codebase.
32 -
dvcrn Bundle Information Security Manager Iso27001ISO 27001 ISMS implementation and cybersecurity governance for HealthTech and MedTech companies. Use for ISMS design, security risk assessment, control implementation, ISO 27001 certification, security audits, incident response, and compliance verification. Covers ISO 27001, ISO 27002, healthcare security, and medical device cybersecurity.
32 -
dvcrn Skill Email Reporter 2Email reports/stats via gog CLI (preferred) or Python scripts (fallback). Daily/weekly summaries, spam stats, export to Sheets/Docs, audit log, undo.
32 -
dvcrn Skill Email Reporter 3Generates email reports and statistics using gog CLI. Creates daily/weekly summaries, spam stats, sender analysis, pending tasks, audit history, and exports data to Google Sheets or text files using gog sheets/docs. Use when the user wants a report, summary, statistics, or export of email activity.
32 -
kbarbel640-del Bundle Qms Audit ExpertISO 13485 internal audit expertise for medical device QMS. Covers audit planning, execution, nonconformity classification, and CAPA verification. Use for internal audit planning, audit execution, finding classification, external audit preparation, or audit program management.
1 -
mhassan0000 Skill Wireshark AnalysisExecute comprehensive network traffic analysis using Wireshark to capture, filter, and examine network packets for security investigations, performance optimization, and troubleshooting.
1 -
mhassan0000 Skill Linux Shell ScriptingProvide production-ready shell script templates for common Linux system administration tasks including backups, monitoring, user management, log analysis, and automation. These scripts serve as building blocks for security operations and penetration testing environments.
1 -
mhassan0000 Skill Constant Time AnalysisAnalyze cryptographic code to detect operations that leak secret data through execution timing variations.
1 -
diegosouzapw Bundle Performance 2Optimize web performance for faster loading and better user experience. Use when asked to "speed up my site", "optimize performance", "reduce load time", "fix slow loading", "improve page speed", or "performance audit".
54 -
diegosouzapw Bundle Analyze 2Invoke IMMEDIATELY via python script when user requests codebase analysis, architecture review, security assessment, or quality evaluation. Do NOT explore first - the script orchestrates exploration.
54 -
diegosouzapw Bundle Fastapi 2FastAPI Python framework. Covers REST APIs, validation, dependencies, security. Keywords: Pydantic, async, OAuth2, JWT.
54 -
diegosouzapw Bundle Red Team ToolsThis skill should be used when the user asks to "follow red team methodology", "perform bug bounty hunting", "automate reconnaissance", "hunt for XSS vulnerabilities", "enumerate su...
54 -
diegosouzapw Bundle Memory 2This skill should be used when the user asks to "/gobby memory", "remember", "recall", "forget memory". Manage persistent memories across sessions - store, search, delete, update, and list memories.
54 -
diegosouzapw Bundle 1password 2Plan, validate, and use 1Password CLI setup for secret injection and auth. Use when tasks need 1Password CLI usage, secret references, op run/read/inject, or provisioning secrets via env vars/.env files and scripts.
54 -
diegosouzapw Bundle Code Reviewer 2Use when reviewing pull requests, conducting code quality audits, or identifying security vulnerabilities. Invoke for PR reviews, code quality checks, refactoring suggestions.
54 -
diegosouzapw Bundle Pr Review 3Perform automated code review on pull requests using Devin Review with regulatory compliance checks. Use this skill when reviewing migration PRs for correctness, when enforcing CIS Benchmark security compliance on code changes, when running automated bug detection and code quality analysis, or when triaging and auto-fixing review findings across enterprise modernization PRs.
54 -
diegosouzapw Bundle Payload 2Use when working with Payload CMS projects (payload.config.ts, collections, fields, hooks, access control, Payload API). Use when debugging validation errors, security issues, relationship queries, transactions, or hook behavior.
54 -
diegosouzapw Bundle Code Review 5Systematic code review checklist covering correctness, security, performance, and maintainability. Use when reviewing pull requests, auditing changes, or checking code quality across any language.
54 -
diegosouzapw Bundle GRAPHQL Architect 2Master modern GraphQL with federation, performance optimization, and enterprise security. Build scalable schemas, implement advanced caching, and design real-time systems. Use PROACTIVELY for GraphQL architecture or performance optimization.
54 -
diegosouzapw Bundle Browser Test 2Run comprehensive Playwright browser tests across desktop, tablet, and mobile viewports. Auto-discovers pages and tests navigation, forms, auth, CRUD, responsive behavior, interactive elements, error states, user flows, and performance metrics.
54 -
diegosouzapw Bundle Idor TestingThis skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or obje...
54 -
diegosouzapw Bundle Tdd Workflow 2Use when implementing any feature or bugfix, before writing implementation code - write the test first, watch it fail, write minimal code to pass; ensures tests actually verify behavior by requiring failure first. Enforces RED-GREEN-REFACTOR cycle with iron-law compliance.
54
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include tech-stack-evaluator, google-workspace-cli, social-media-manager. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.