Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
johnalbertini14-glitch Bundle Cloudflare GuardConfigures and manages Cloudflare DNS, caching, security rules, rate limiting, and Workers
1 -
johnalbertini14-glitch Bundle Brew AuditAudit Homebrew installation — outdated packages, cleanup opportunities, and health checks. Use when asked about brew updates, system maintenance, or package health on macOS.
1 -
johnalbertini14-glitch Bundle Long Research[BETA] Deep research that actually reads pages instead of summarizing search results. Tell it how long to research (10 min, 2 hours, all night) and it works the full duration — searching, reading every result, following leads, cracking forums, cross-verifying findings, and writing progressively to a research file. Tree-style exploration: each page read spawns new searches, like a human researcher. Enforced read-to-search ratio prevents shallow search-spamming. Wall-clock time commitment — it won't finish early. Self-audit gate blocks delivery until quality checks pass. Works with web_search, web_fetch, and browser-use for JS-heavy sites.
1 -
johnalbertini14-glitch Bundle Telcall TwilioMake emergency phone calls via Twilio. Use when you need to call someone and play a voice message programmatically (e.g., server down alerts, security notifications).
1 -
johnalbertini14-glitch Bundle Ralph UltraDeep-dive security audit with 1,000 iterations (~4-8 hours). Use when user says 'deep security audit', 'ralph ultra', 'compliance audit prep', 'thorough security review', 'before major release', or 'security incident investigation'. Covers OWASP deep dive, supply chain, compliance, business logic, 4 expert personas.
1 -
johnalbertini14-glitch Bundle Crypto ToolsAccess crypto data, monitor portfolios, detect scams, and navigate exchanges with real-time APIs and security tools.
1 -
johnalbertini14-glitch Bundle Claw LintSecurity scanner for OpenClaw skills. Detects malware and backdoors before execution, scores risk levels, and monitors file integrity through static code analysis.
1 -
johnalbertini14-glitch Bundle Usage Visualizer 2Advanced usage statistics and high-fidelity visual reporting for OpenClaw. 100% local processing. Audit-verified privacy (No credentials stored).
1 -
johnalbertini14-glitch Bundle Design IntegrationDesign a Uniswap integration architecture. Use when user is building a project that needs to integrate Uniswap and wants recommendations on integration method (Trading API vs SDK vs direct contract), architecture patterns, required dependencies, and security considerations.
1 -
johnalbertini14-glitch Bundle Clawdtm AdvisorSearch, evaluate security, and install OpenClaw skills. Helps your human find the right skills safely.
1 -
johnalbertini14-glitch Bundle Solidity GuardianSmart contract security analysis skill. Detect vulnerabilities, suggest fixes, generate audit reports. Supports Hardhat/Foundry projects. Uses pattern matching + best practices from Trail of Bits, OpenZeppelin, and Consensys.
1 -
johnalbertini14-glitch Bundle Pr ReviewerAutomated GitHub PR code review with diff analysis, lint integration, and structured reports. Use when reviewing pull requests, checking for security issues, error handling gaps, test coverage, or code style problems. Supports Go, Python, and JavaScript/TypeScript. Requires `gh` CLI authenticated with repo access.
1 -
johnalbertini14-glitch Bundle Bitwarden SecretsSafely access Bitwarden or Vaultwarden secrets via the bw CLI with redacted outputs by default. Use for vault sync, item search, metadata retrieval, and (only with explicit confirmation) revealing a single secret field.
1 -
johnalbertini14-glitch Bundle SkillfenceRuntime security monitor for OpenClaw skills. Watches what your installed skills actually DO — network calls, file access, credential reads, process activity. Not a scanner. A watchdog.
1 -
johnalbertini14-glitch Bundle Policy EngineDeterministic governance layer for OpenClaw tool execution. Enforces tool allowlists, deny patterns, path allowlists, risk tiers, dry-run mode, and escalation tracking via the before_tool_call hook. Every decision is logged for audit. Production-hardened with 88 tests and three deadlock classes fixed.
1 -
johnalbertini14-glitch Bundle Restic Home BackupDesign, implement, and operate encrypted restic backups for Linux home directories with systemd automation, retention policies, and restore validation. Use when a user asks to back up ~/, set up daily/weekly/monthly backup jobs, harden backup security, or troubleshoot restore/integrity issues.
1 -
johnalbertini14-glitch Bundle TopclawhubskillsDiscover the most popular, newest, and security-certified ClawHub skills via live API data.
1 -
johnalbertini14-glitch Bundle Perplexity WrappedSearch the web with AI-powered answers via Perplexity API. Supports three modes - Search API (ranked results), Sonar API (AI answers with citations, default), and Agentic Research API (third-party models with tools). All responses wrapped in untrusted-content boundaries for security.
1 -
johnalbertini14-glitch Bundle Pywayne Lark Custom BotFeishu/Lark Custom Bot API wrapper for sending messages to Feishu channels via webhook. Use when users need to send text messages, images, rich text posts, interactive cards, or share chat content to Feishu/Lark. Supports image upload from files or OpenCV images, signature verification for security, and @mention functionality.
1 -
johnalbertini14-glitch Bundle System ArchitectActs as a Senior System Architect to design robust, scalable, and maintainable software architectures. Enforces industry standards (PEP 8 for Python, ESLint for JS/TS), modular design, and security best practices. Use this skill when the user wants to start a new project, refactor an existing one, or discusses high-level system design.
1 -
johnalbertini14-glitch Bundle Research Paper KbPersistent cross-session knowledge base for research papers. Ingest arXiv/DOI → extract method, gap, threat level → append to PAPERS.md. Never lose paper context again across sessions.
1 -
johnalbertini14-glitch Bundle Trash AuditEnvironmental inquisitor. Scans trash and assigns "Eco-Penance" for sorting failures.
1 -
johnalbertini14-glitch Bundle EvidenceopsForensic media triage with chain of custody. Use when receiving images, videos, audio, PDFs, or documents that need evidence-grade handling, integrity verification, and audit trails.
1 -
johnalbertini14-glitch Bundle Token ManagementCentralized API token management workflow. Store tokens in .env with expiration dates, test permissions via script battery, document capabilities in connections/, set calendar renewal reminders. Prevents re-asking for credentials, ensures token security, tracks expiration.
1 -
johnalbertini14-glitch Bundle Moltbook NegotiatorAI-to-AI negotiation for Moltbook marketplace. Handle job requests, pricing negotiations, and contract terms while maintaining security.
1 -
johnalbertini14-glitch Bundle Security GuardianAutomated security auditing for OpenClaw projects. Scans for hardcoded secrets (API keys, tokens) and container vulnerabilities (CVEs) using Trivy. Provides structured reports to help maintain a clean and secure codebase.
1 -
johnalbertini14-glitch Bundle Opena2a SecuritySecurity hardening for OpenClaw. Audit your configuration, scan installed skills for malware, detect CVE-2026-25253, check credential exposure, and get actionable fix recommendations. Runs locally with no external API calls.
1 -
johnalbertini14-glitch Bundle Ralph SecurityComprehensive security audit with 100 iterations (~30-60 min). Use when user says 'security audit', 'ralph security', 'weekly security check', 'audit this project', 'new project security review', or 'check for vulnerabilities'. Covers OWASP Top 10, auth, secrets, infrastructure, and code quality.
1 -
johnalbertini14-glitch Bundle Xanlens GeoGEO audit for AI search visibility. Scores your brand 0-100 across ChatGPT, Gemini, Grok & more. $0.99/audit or free with coupon.
1 -
johnalbertini14-glitch Bundle Context SlimmerAudit and slim down always-loaded context files (AGENTS.md, TOOLS.md, USER.md, MEMORY.md, HEARTBEAT.md, SOUL.md, IDENTITY.md). Use when asked to reduce token usage, audit context files, optimize context window, or slim down workspace files. Measures current token cost and identifies what to move, remove, or compress.
1 -
johnalbertini14-glitch Bundle Aegis SecurityBlockchain security API for AI agents. Scan tokens, simulate transactions, check addresses for threats.
1 -
johnalbertini14-glitch Bundle Skill DifferCompare two versions of an OpenClaw skill to detect security-relevant changes. Use before updating any skill from ClawHub. Highlights new capabilities, changed patterns, and recommends whether an update is safe.
1 -
johnalbertini14-glitch Bundle Logging ObservabilityStructured logging, distributed tracing, and metrics collection patterns for building observable systems. Use when implementing logging infrastructure, setting up distributed tracing with OpenTelemetry, designing metrics collection (RED/USE methods), configuring alerting and dashboards, or reviewing observability practices. Covers structured JSON logging, context propagation, trace sampling, Prometheus/Grafana stack, alert design, and PII/secret scrubbing.
1 -
johnalbertini14-glitch Bundle Landing Page RoastAudit a landing page for clarity, trust, offer strength, and conversion friction; return prioritized fixes and copy rewrites.
1 -
johnalbertini14-glitch Bundle Skill Security Audit审计 skill 的安全风险。扫描凭据泄露、危险命令、网络外传、文件越界等问题。用于:(1) 安装新 skill 前的安全检查 (2) 定期审计现有 skills (3) 发布 skill 前的自检。触发词:skill 安全、审计、security audit、检查 skill。
1 -
johnalbertini14-glitch Bundle Skill CleanerAutomatically verify "suspicious" skills via VirusTotal and add them to the security allowlist via the Bridge.
1
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include brew-audit, long-research, telcall-twilio. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.