Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
gabrielmoreira Skill Oversharing AuditAudit what your public online presence quietly reveals — and tighten it — before a stranger, employer, or scammer uses it. Use when asked what does my online presence reveal, audit my privacy, what can people find out about me, or clean up my social media. Produces a review of what's exposed across profiles and posts (location, routines, identifiers, security-question answers), the specific risks each creates, prioritized fixes (settings + what to remove/stop posting), and habits to prevent future leaks — without demanding you delete everything.
17 -
openclaw Skill Convex Launch ReadinessRun every Convex audit (authz, reviewer, advisor, insights) into one scored, deduped readiness report with an ordered fix plan — Lighthouse for your backend.
9.1k -
rlaope Skill Omh Provider Profile Posture[omh] Prepare provider-profile metadata without reading secrets or calling providers. Use when the user says: provider-profile-posture, provider profile posture, provider profile readiness, secret presence confirmation, connector profile posture, 공급자 프로필 상태, 시크릿 존재 확인, 커넥터 준비 상태.
-
gabrielmoreira Bundle Linkedin Post WriterDraft a new LinkedIn post from scratch using one of 20 2026 hook formulas (anaphora, R.I.P., time-anchor, curiosity-gap, contrarian, controlled A/B, false-binary, and more) plus a founders-edition angle library, picked by engagement goal (comments, reposts, likes, saves). Runs the humanizer pass and schedules via Publora on approval. Use to write a post, find a hook or proven format, or get founder-specific angles. Not for reviewing existing drafts (use linkedin-humanizer --mode audit).
17 -
suyoumo Skill Parallel Pr ReviewUse when asked to "review the open PRs", review a batch or stack of pull requests, or run a recurring PR-review pass on a repo — especially with many PRs, stacked branches, conflicts, or security-sensitive changes. Covers grouping, fan-out to review subagents, verdict synthesis, and posting.
-
tophant-ai Bundle Tophant Clawvault InstallerInstall, configure, test, and uninstall ClawVault AI security proxy
-
gabrielmoreira Skill Modern CppGuides C++ code toward modern idioms (C++20/23/26). Use when writing new C++ code, modernizing legacy patterns, or working on security-critical C++. Replaces raw pointers with smart pointers, SFINAE with concepts, printf with std::print, error codes with std::expected.
17 -
useai-pro Skill Setup AuditorAudit your OpenClaw environment for credential leaks, unsafe defaults, and missing sandbox configuration. Wizard-style: answers questions about your setup and produces a fix checklist.
-
worldbank Skill Wbg Oss ReviewAudits and prepares a GitHub repository for World Bank Group (WBG) open source publication. Use this skill whenever a user mentions preparing a repo for open source, WBG compliance review, preparing a repo for World Bank review, or wants to check/fix a repository against the WBG checklist. Also trigger when a user says their repo needs the WB license (MIT or Apache 2.0 with the matching IGO rider), citation file, code of conduct, contributing guide, or any combination of World Bank open source requirements. Even if they just say "prepare my repo for open source", "review my repo", or "audit my repo for WBG", use this skill.
-
zebbern Skill API Fuzzing Bug BountyThis skill should be used when the user asks to "test API security", "fuzz APIs", "find IDOR vulnerabilities", "test REST API", "test GraphQL", "API penetration testing", "bug bounty API testing", or needs guidance on API security assessment techniques.
-
automateyournetwork Skill Markmap VizCreate interactive mind map visualizations from markdown - network inventory, OSPF areas, BGP topology, security audit results. Use when visualizing network topology as a mind map, creating audit result diagrams, or generating hierarchical views of OSPF areas, BGP peers, or VLAN structures
-
automateyournetwork Skill Zscaler ZiaManage Zscaler Internet Access firewall rules, URL filtering, DLP, and security policies.
-
daymade Skill Github Sensitive Data CleanupScan and remove sensitive data (secrets, API keys, private domains/IPs, PII) from GitHub repository history. Use this skill whenever the user says "scan sensitive data", "clean git history", "remove secrets from repo", "sanitize GitHub history", "清理敏感数据", "历史重写", "force push", "泄露", or needs to repair a public repo after accidental secret/private context leakage. Also use before any force push to a public repository to verify visibility, backup, and scan results.
-
gabrielmoreira Skill HotfixEmergency fix workflow that bypasses normal sprint processes with a full audit trail. Creates hotfix branch, tracks approvals, and ensures the fix is backported correctly.
17 -
elementalsouls Bundle Email Domain SecurityRigorous, defensible email-spoofability verdict and SPF supply-chain risk analysis computed from published DNS alone. Deepens the record-level SPF/DMARC/DKIM/BIMI/MTA-STS/DNSSEC fetch recipes in the offensive-osint arsenal (§16.14) with the reasoning that section doesn't do: a priority-ordered composite verdict for whether an attacker can actually land header-From-spoofed mail in an inbox, and by which vector (exact-domain vs subdomain) — grounded in the single most-misunderstood distinction in email security: the envelope MAIL FROM that SPF authenticates vs the visible header From: that only DMARC governs. Explains precisely why SPF -all/~all alone is NOT spoof-proof without DMARC enforcement, and why SPF +all bypasses DMARC even under p=reject pct=100. Covers RFC 7208 §4.6.4's 10-DNS-lookup / 2-void-lookup PermError fail-open condition with a runnable stdlib-only lookup-counter script, plus the SPF-include-takeover supply-chain vector (an attacker re-registering a dead include inherits SPF-pass authority ov
-
elizaos Skill Contribute To ElizaFinish and prove a scoped elizaOS GitHub issue, or independently review and repair an open elizaOS pull request. Use when contributing compute to elizaOS by selecting unclaimed work, implementing or reviewing changes, adding real tests and evidence, validating artifacts, or preparing a contribution for maintainer review.
-
fabioc-aloha Skill Brain AuditPerform a local brain audit for ACT Edition (and Supervisor) using deterministic QA plus targeted file review, then produce severity-ranked fixes. Pairs with extension-audit on the sibling surface side; the Marketplace surface routes there, not here.
-
fengshao1227 Skill Verify Security安全校验关卡。自动扫描代码安全漏洞,检测危险模式,确保安全决策有文档记录。当用户提到安全扫描、漏洞检测、安全审计、代码安全、OWASP、注入检测、敏感信息泄露时使用。在新建模块、安全相关变更、攻防任务、重构完成时自动触发。
-
gabrielmoreira Skill 57 Next Ads PlanDung khi ket thuc mot ky va can lap plan quang cao ky sau tu data that — giu winner, thay loser, gia thuyet test moi, va ngan sach theo 3 kich ban. Kich hoat khi user nhac 'next ads plan', 'plan ads thang sau', 'ky toi chay gi', 'dua vao ket qua lap ke hoach ads', 'ads thang toi'. Khong dung cho — lap media plan lan dau khi chua co data thi dung skill 54-media-plan; chan doan tai sao ky vua roi kem thi dung skill 21-audit-ads-performance.
17 -
gabrielmoreira Skill Bennett Time AuditAudit a week the way Arnold Bennett's 'How to Live on 24 Hours a Day' (1908) prescribes — time as the one income that cannot be increased, the day-within-the-day, and starting with 90 minutes, not a life overhaul. Use when someone says 'I have no time', 'work eats everything', 'I want to learn X but can't fit it', or asks for a time audit or evening routine. Produces a time ledger, one reclaimed 'inner day' block, and Bennett's own warnings about overreach.
17 -
gabrielmoreira Skill PPTX Slide AuditorAudit a PowerPoint presentation for layout issues, text overflow, visual hierarchy problems, and consistency gaps. Use when asked to review a slide deck, check a presentation before a meeting, audit slides for layout problems, or QA a deck before sharing. Produces a slide-by-slide report with issues ranked by severity and specific fixes. Best used with Claude Opus 4.7 or newer for reliable slide-level vision analysis.
17 -
gabrielmoreira Skill Social Media AuditAudit an existing social media presence across all active platforms. Use when asked to review social media performance, analyse a brand's social presence, benchmark against competitors, or identify what's working and what isn't. Produces a scored audit with platform-by-platform analysis, content performance review, competitive benchmarking, and a prioritised action plan.
17 -
gabrielmoreira Bundle Subscription AuditFind and rank the recurring-payment leak — every subscription annualized, sorted by real yearly cost, with the keep/cancel/downgrade pass and the where-they-hide checklist. Use when asked audit my subscriptions, how much am I spending on subscriptions, help me cancel stuff, or what recurring charges am I forgetting. Produces the annualized ranking from the script, the hidden-subscription hunt list, the keep/cancel/downgrade decisions with the cancellation friction notes, and the re-audit cadence.
17 -
gabrielmoreira Skill Task Triage MatrixTriage an overwhelming task list into what actually gets done — the urgent/important sort applied honestly (with the two corrections the classic matrix needs), the do/schedule/delegate/drop verbs, and the list hygiene that keeps triage from becoming a weekly archaeology dig. Use when asked my task list is overwhelming, triage my todos, everything feels urgent, or what should I actually work on. Produces the sorted list with verbs, the urgency audit (what's fake-urgent), the drop list with permission, and the intake rule.
17 -
snailsploit Skill Offensive API SecurityComprehensive API security testing methodology covering REST, gRPC, and WebSocket attack surfaces. Addresses the full OWASP API Security Top 10 2023 including BOLA/IDOR, broken authentication, excessive data exposure, rate limiting bypass, BFLA, mass assignment, SSRF, and security misconfiguration. Includes REST-specific attacks such as HTTP verb tampering, content-type switching, and parameter pollution. Covers gRPC exploitation through protobuf interception, reflection API enumeration, and metadata injection. Addresses WebSocket vulnerabilities including origin bypass, message injection, and cross-site WebSocket hijacking. Provides tooling guidance for Burp Suite, Postman, grpcurl, websocat, and mitmproxy. Each technique includes detection signatures and defensive indicators so you understand what artifacts your testing leaves behind. Designed for authorized penetration testing engagements against API-driven architectures.
-
gabrielmoreira Skill CodeqlScans a codebase for security vulnerabilities using CodeQL's interprocedural data flow and taint tracking analysis. Triggers on "run codeql", "codeql scan", "build codeql database", "SAST scan", "taint analysis", "dataflow analysis", or "find vulnerabilities in this repo". Covers Python, JavaScript/TypeScript, Go, Java/Kotlin, C/C++, C#, Ruby, and Swift. Supports "run all" (security-and-quality + security-experimental) and "important only" (high-precision) scan modes, and creates data extension models for project-specific sources and sinks. For fast single-file pattern matching, or when no build is available for a compiled language, use the semgrep skill; to parse SARIF that already exists rather than produce it, use the sarif-parsing skill.
17 -
gabrielmoreira Skill Top Web VulnerabilitiesThis skill should be used when the user asks to "identify web application vulnerabilities", "explain common security flaws", "understand vulnerability categories", "learn about injection attacks", "review access control weaknesses", "analyze API security issues", "assess security misconfigurations", "understand client-side vulnerabilities", "examine mobile and IoT security flaws", or "reference the OWASP-aligned vulnerability taxonomy". Use this skill to provide comprehensive vulnerability definitions, root causes, impacts, and mitigation strategies across all major web security categories.
17 -
gabrielmoreira Bundle Build Audit LogsBuild or review audit trails in TypeScript/JavaScript apps using evlog (pipelines, typed actions, denials, retention, compliance-style reviews). For application code, not for extending the evlog package.
17 -
gabrielmoreira Skill Secrets ManagementUse this skill when handling API keys, passwords, tokens, private keys, or any sensitive credential. Never hardcode secrets in source code — apply this whenever the word "key", "token", "password", or "secret" appears in the task.
17 -
gabrielmoreira Skill Vault MountsDiscover and manage HashiCorp Vault secret engine mounts.
17 -
gabrielmoreira Bundle Repo Profile GovernanceAudit and harden repository profile, community health, discoverability metadata, and contribution surfaces across repos using bounded, evidence-based checks.
17 -
gabrielmoreira Bundle AI Writing DetectorUse when the user asks to detect, scan, audit, score, or flag AI-writing patterns without rewriting the text, including requests for a deterministic local detector result when the host can execute Node.
17 -
gabrielmoreira Skill Diff Security ReviewFlag only new security issues introduced by this diff. Gates Warden security clearance.
17 -
gabrielmoreira Skill Skill VetterSecurity-first skill vetting protocol for AI agents. Use before installing any skill from the platform skill market, skillhub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns to determine whether a skill is safe to install.
17 -
gabrielmoreira Bundle Dt Sec Semantic MappingSuggest and validate semantic dictionary (SD) mappings for new security integrations using vendor API samples or live events. Use when: mapping a new security vendor data to Dynatrace SD; checking required fields; validating namespaces; highlighting discrepancies vs the semantic dictionary; proposing mapping improvements; running runtime validation against live tenant data.
17 -
gabrielmoreira Skill Hunt API MisconfigHunt API security misconfiguration — mass assignment, prototype pollution, HTTP verb tampering. Mass assignment: send {is_admin:true, role:admin, verified:true} on profile/account/reset endpoints — server blindly applies. JWT signature/crypto forging (alg:none, key confusion, kid/jku) is owned by hunt-jwt-crypto; this skill covers only non-crypto JWT handling. Prototype pollution: __proto__ injection in JSON merge / Object.assign / lodash _.merge → polluted prototype reaches sink (RCE in Node, XSS in browser). HTTP verb: GET-bypass-CSRF, X-HTTP-Method-Override, TRACE enabled. Detection: API responses with extra fields, JWTs in headers (decode at jwt.io). CORS misconfiguration (reflect-any-origin, null origin, subdomain-regex bypass, postMessage) is owned by hunt-cors. Use when hunting API misconfigs, mass-assignment, prototype pollution (JWT crypto → hunt-jwt-crypto).
17
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include zscaler-zia, markmap-viz, oversharing-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.