Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
johnalbertini14-glitch Bundle CorsConfigure Cross-Origin Resource Sharing correctly to avoid security issues and debugging pain.
1 -
johnalbertini14-glitch Bundle MqttImplement MQTT messaging avoiding security, QoS, and connection management pitfalls.
1 -
johnalbertini14-glitch Bundle RedshiftManage application secrets with the Redshift CLI (https://redshiftapp.com) — decentralized, encrypted secret management built on Nostr. Use when setting, getting, deleting, listing, uploading, or downloading secrets, injecting secrets into commands, configuring projects/environments, or authenticating with Nostr keys. Covers redshift secrets, redshift run, redshift setup, redshift login, and related commands.
1 -
johnalbertini14-glitch Bundle SentinelTransform an Android phone with IP Webcam into an intelligent Edge AI security system with OpenClaw.
1 -
johnalbertini14-glitch Bundle Tarkov APISecurity-focused Tarkov.dev + optional EFT Wiki operations for hardcore Escape from Tarkov players. Use when users want reliable EFT data lookups (items, prices, ammo comparison, tasks, map bosses, service status), stash valuation snapshots, trader flip detection, and map-risk/raid-kit recommendations. Use wiki lookups conditionally for validation or patch-sensitive context, with safe endpoint and query controls.
1 -
johnalbertini14-glitch Bundle ClawbackMirror congressional stock trades with automated broker execution and risk management. Use when you want to track and automatically trade based on congressional disclosures from House Clerk and Senate eFD sources.
1 -
johnalbertini14-glitch Bundle Auth PatternsAuthentication and authorization patterns — JWT, OAuth 2.0, sessions, RBAC/ABAC, password security, MFA, and vulnerability prevention. Use when implementing login flows, protecting routes, managing tokens, or auditing auth security.
1 -
johnalbertini14-glitch Bundle Skill VettingVet ClawHub skills for security and utility before installation. Use when considering installing a ClawHub skill, evaluating third-party code, or assessing whether a skill adds value over existing tools.
1 -
johnalbertini14-glitch Bundle ConfidantSecure secret handoff and credential setup wizard for AI agents. Use when you need sensitive information from the user (API keys, passwords, tokens) or need to save credentials to config files. Never ask for secrets via chat — use Confidant instead.
1 -
johnalbertini14-glitch Bundle Cross RefCross-reference GitHub PRs and issues to find duplicates and missing links. Spawns parallel Sonnet subagents to semantically analyze the last N PRs and issues, finding PRs that solve the same problem (duplicates) and issues resolved by open PRs but not yet linked. Groups findings into thematic clusters, scores them by actionability, and offers rate-limited commenting or bulk actions (close, label). Use this skill when the user wants to find duplicate PRs, link issues to PRs, clean up a repo's cross-references, or audit PR/issue relationships. Also useful when the user says things like "find related PRs", "which PRs fix this issue", "are there duplicate PRs", "link issues and PRs", or "audit cross-references".
1 -
johnalbertini14-glitch Bundle PaymentsIntegrate payments with provider selection, checkout flows, subscription billing, and security best practices.
1 -
johnalbertini14-glitch Bundle SolidityAvoid common Solidity mistakes — reentrancy, gas traps, storage collisions, and security pitfalls.
1 -
johnalbertini14-glitch Bundle SecretcodexGenerate creative code names and encode/decode secret messages using classic and sophisticated ciphers. Blends nostalgic decoder ring fun with modern cryptographic techniques. Includes Caesar, Vigenère, Polybius, Rail Fence, and hybrid methods. Provides keys for secure message sharing between trusted parties.
1 -
johnalbertini14-glitch Bundle Slither AuditRun slither static analysis on Solidity contracts. Fast, lightweight security scanner for EVM smart contracts.
1 -
johnalbertini14-glitch Bundle Secret PortalSpin up a one-time web UI for securely entering secret keys and env vars. Supports guided instructions, single-key mode, and cloudflared tunneling.
1 -
johnalbertini14-glitch Bundle Sui CoverageAnalyze Sui Move test coverage, identify untested code, write missing tests, and perform security audits. Includes Python tools for parsing coverage output and generating reports.
1 -
johnalbertini14-glitch Bundle EcommerceBuild and operate online stores with payment security, inventory management, marketplace integration, and conversion optimization.
1 -
johnalbertini14-glitch Bundle Guava SuitePremium security suite for AI agents. Adds $GUAVA token-gated strict mode protection on top of guard-scanner. Features: 2-layer defense (static + runtime), Soul Lock, Memory Guard, on-chain identity verification via SoulRegistry V2. Requires $GUAVA token on Polygon Mainnet.
1 -
johnalbertini14-glitch Bundle Skill ReviewScrape ClawHub skill pages for Security Scan (VirusTotal/OpenClaw) + Runtime Requirements + Comments for all of Oliver's local skills, and write a markdown report.
1 -
johnalbertini14-glitch Bundle Human SecurityMulti-layer security for human interactions on SNS platforms (Coconala, Fiverr, Upwork, X, Threads, LinkedIn). Protects against scams, phishing, and maintains professional boundaries. Always active alongside moltbook-security.
1 -
johnalbertini14-glitch Bundle SpecvibeA world-class, spec-driven development framework for building production-ready, AI-native applications. Use for any new project to ensure adherence to the most advanced 2026 best practices in architecture, security, testing, and deployment.
1 -
johnalbertini14-glitch Bundle Security ScannerAutomated security scanning and vulnerability detection for web applications, APIs, and infrastructure. Use when you need to scan targets for vulnerabilities, check SSL certificates, find open ports, detect misconfigurations, or perform security audits. Integrates with nmap, nuclei, and other security tools.
1 -
johnalbertini14-glitch Bundle Repo AnalyzerGitHub repository trust scoring and due diligence. Use when asked to analyze, audit, score, or evaluate any GitHub repo — especially for crypto/DeFi project DD, checking if a repo is legit, evaluating code quality, verifying team credibility, or comparing multiple repos. Also handles X/Twitter URLs containing GitHub links — auto-extracts and analyzes repos from tweets. Triggers on "analyze this repo", "is this legit", "check this GitHub", "trust score", "audit this project", "repo quality", "batch scan repos", "analyze this tweet". ALSO auto-triggers when the user pastes an X/Twitter URL that contains a GitHub link — no explicit "analyze" command needed. When triggered by a tweet, ALWAYS include the tweet text/context above the analysis. Do NOT use for general GitHub browsing, reading READMEs, or cloning repos without analysis.
1 -
johnalbertini14-glitch Bundle EncryptionEncrypt files, secure passwords, manage keys, and audit code for cryptographic best practices.
1 -
johnalbertini14-glitch Bundle Auditclaw IdpIdentity provider compliance checks for auditclaw-grc. 8 read-only checks across Google Workspace (MFA, admin audit, inactive users, passwords) and Okta (MFA, password policy, inactive users, session policy).
1 -
johnalbertini14-glitch Bundle ClawsmithCreate, audit and publish production-ready OpenClaw skills with one command. 10 modes included.
1 -
johnalbertini14-glitch Bundle Browser SecureSecure browser automation with Chrome profile support, vault integration, approval gates, and comprehensive audit logging. Use for authenticated sites, sensitive operations, or compliance requirements.
1 -
johnalbertini14-glitch Bundle Rey Code ReviewComprehensive code review for quality, security, and best practices. Quick review for small changes, full review for large changes.
1 -
johnalbertini14-glitch Bundle Agentaudit SkillAutomatic security gate that checks packages against a vulnerability database before installation. Use before any npm install, pip install, yarn add, or package manager operation.
1 -
johnalbertini14-glitch Bundle Skill SecuritySecurity audit tool for OpenClaw skills. Scans for credential harvesting, code injection, network exfiltration, obfuscation. ALWAYS run before installing any new skill from external sources. Triggers on: new skill installation, skill audit, security scan, skill review, before loading external skill.
1 -
johnalbertini14-glitch Bundle Pywayne Aliyun OssAliyun OSS (Object Storage Service) file management toolkit for Python. Use when working with Aliyun OSS to upload files, download files, list objects, delete files, manage directories, read file contents, check file existence, get file metadata, copy and move objects. Supports both authenticated (with API key/secret for write operations) and anonymous access (read-only).
1 -
johnalbertini14-glitch Bundle Tor BrowserHeadless browser automation with Tor SOCKS5 proxy support for accessing .onion sites and anonymous browsing. Use when navigating dark web resources, scraping Tor hidden services, conducting security research on dark web forums, or when anonymity is required. Supports navigation, element interaction, screenshots, and data extraction through Tor network.
1 -
johnalbertini14-glitch Bundle Solidity LspSolidity language server providing smart contract development support including compilation, linting, security analysis, and code intelligence for .sol files. Use when working with Ethereum smart contracts, Substrate pallets, or any Solidity code that needs compilation, security checks, gas optimization, or code navigation. Essential for ClawChain pallet development.
1 -
johnalbertini14-glitch Bundle Mfa WordChallenges the user for a secret word before allowing access to sensitive files or system commands.
1 -
johnalbertini14-glitch Bundle Gog RestrictedGoogle Workspace CLI for Gmail, Calendar, and Auth (restricted via security wrapper).
1 -
johnalbertini14-glitch Bundle Dependency AuditSmart dependency health check — security audit, outdated detection, unused deps, and prioritized update plan
1
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include CORS, MQTT, redshift. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.