Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
gabrielmoreira Bundle 701 Technologies OpenapiUse when you need framework-agnostic OpenAPI 3.x guidance — spec structure, metadata and versioning, paths and operations, reusable schemas, security schemes, examples, documentation quality, contract validation (e.g. Spectral), breaking-change awareness, and handoffs to codegen — without choosing Spring Boot, Quarkus, or Micronaut. This should trigger for requests such as Review an OpenAPI; Improve an OpenAPI; Improve API contract; Improve API schema design. Part of Plinth Toolkit
17 -
gabrielmoreira Skill Wow API CombatComplete reference for WoW Retail Combat, Damage Meter, Threat, Loss of Control, Combat Text, Combat Audio Alert, Secret Values, and Spectator APIs. Covers the 12.0.0 combat log removal (CLEU no longer available to addons), C_DamageMeter built-in damage meter, C_Secrets secret predicates, C_CurveUtil/C_DurationUtil for secret value visualization, C_LossOfControl, C_CombatText, C_CombatAudioAlert, ENCOUNTER_STATE_CHANGED, threat functions, and the new COMBAT_LOG_MESSAGE event. Use when working with combat data, damage meters, threat, loss of control, combat text, encounter events, or any combat-related addon functionality.
17 -
gabrielmoreira Bundle Escalation PackPrepare support escalation handoffs. Use when Codex is asked to escalate a customer issue, summarize severity and impact, package reproduction evidence, create an engineering handoff, prepare a billing/security/legal escalation, or request an internal decision.
17 -
gabrielmoreira Bundle AI Assist Tech Debt22-dimension, 5-tier technical debt audit covering code quality, architecture, infrastructure, quality processes, and operational readiness. Produces severity-ranked findings with weighted health score. Use when assessing codebase health, prioritizing tech debt remediation, or auditing code quality across all layers.
17 -
gabrielmoreira Skill Flutter InternationalizationAdd, fix, audit, and maintain Flutter internationalization with gen-l10n, ARB files, AppLocalizations, flutter_localizations, intl formatting, plural/select messages, RTL support, locale-specific number/date formatting, and localization build errors. Use when asked to add l10n or i18n, translate Flutter UI text, configure l10n.yaml, manage ARB translations, migrate away from package:flutter_gen imports, or troubleshoot generated localization code.
17 -
gabrielmoreira Skill 53 Tracking SetupDung khi phai setup do luong TRUOC khi tieu bat ky dong nao — pixel va CAPI, GA4, UTM convention, event mapping, offline conversion, dong y du lieu, va checklist verify xanh. Kich hoat khi user nhac 'setup tracking', 'cai pixel', 'UTM', 'CAPI', 'do luong chuyen doi', 'so lieu khong khop'. Quy tac cung: khong chay ads khi tracking chua xanh. Khong dung cho — doc data da co ra insight thi dung skill 13-phan-tich-du-lieu; ra soat cau hinh ads thi dung skill 21-audit-ads-performance.
17 -
gabrielmoreira Skill Openclaw Ghsa MaintainerInspect, patch, validate, publish, or confirm OpenClaw GHSA security advisories and private-fork state.
17 -
gabrielmoreira Skill Rust ReviewPerforms comprehensive Rust security review for safe/unsafe boundary issues, memory safety in unsafe blocks, concurrency hazards, panic-induced DoS, FFI safety, and async runtime mistakes. Use when auditing Rust crates, services, or libraries — particularly those with `unsafe`, FFI, or concurrent code.
17 -
gabrielmoreira Skill SemgrepRuns a Semgrep security scan over a codebase: detects languages, selects rulesets, presents the plan for explicit approval, then runs every approved ruleset through scripts/run-scans.sh, which batches the semgrep processes and writes scans.json, and merges the output to SARIF. Supports two scan modes, "run all" for full ruleset coverage and "important only" for security findings at medium-to-high confidence and impact. Uses Semgrep Pro for cross-file taint analysis when it is available. Use when asked to scan code for vulnerabilities, run a security audit with Semgrep, find bugs, or perform static analysis. For the same scan without the approval gate, use the /static-analysis:semgrep-scan workflow.
17 -
gabrielmoreira Skill Config HardenerAudit and harden your OpenClaw configuration. Checks AGENTS.md, gateway settings, sandbox config, and permission policies for security weaknesses.
17 -
gabrielmoreira Skill Network WatcherAudit and monitor network requests made by OpenClaw skills. Detects data exfiltration, unauthorized API calls, and suspicious outbound connections.
17 -
gabrielmoreira Skill Pyats RoutingCCIE-level routing protocol analysis - OSPF, BGP, EIGRP, IS-IS, static routes, RIB/FIB verification, redistribution audit, and convergence validation. Use when analyzing routing tables, debugging OSPF neighbors, checking BGP peering, verifying route redistribution, or validating convergence after changes.
17 -
gabrielmoreira Bundle Evolve SkillsAnalyze recent project artifacts and Session Audit Reports (SA1, SA2, SA3...) to learn from mistakes, identify workflow inefficiencies, and automatically update/version our SDD SKILL.md files. Handles multiple session audits and TEMP milestones.
17 -
gabrielmoreira Bundle Session AuditCapture any session (milestone, hotfix, manual edits, external reports) into Session Audit Reports (M{X}SA{Y}.md) that drive documentation updates, skill evolution, and quality monitoring. Use when the user says "session-audit", "document this session", "capture this session".
17 -
gabrielmoreira Skill AurakitSonnet Amplified fullstack engine. 34 modes, SEC-01~15 OWASP security, 13 runtime hooks, 75% token reduction. Install: npx @smorky85/aurakit
17 -
gabrielmoreira Skill Hunt Race ConditionHunting skill for race condition vulnerabilities. Built from 12 public bug bounty reports including modern HTTP/2 single-packet attack cases (James Kettle DEF CON 2023 "Smashing the State Machine"; RyotaK / Flatt Security 10,000-request first-sequence-sync expansion 2024). Covers coupon double-redemption, gift-card double-spend, MFA-OTP-validate race, account-create race, faucet/crypto token double-mint, email-activation race, vote/upvote inflation, password-reset token race, rate-limit bypass via concurrent requests. Use when hunting race conditions, TOCTOU bugs, MFA-bypass-via-timing.
17 -
gabrielmoreira Skill Conventions ImproverAudit and improve project conventions files (AGENTS.md, CLAUDE.md, GEMINI.md). Scans for all conventions files, evaluates quality against a scoring rubric, outputs a quality report, then makes targeted improvements with user approval. Use when asked to check, audit, update, or improve AGENTS.md or similar files.
17 -
gabrielmoreira Skill Currency AuditComprehensive brain file review — external freshness, internal consistency, semantic accuracy — stamp only after full assessment
17 -
gabrielmoreira Bundle QA Test StrategyDesign, audit, and improve QA and test strategy for software, games, websites, products, and launches. Use when Codex is asked about test plans, acceptance tests, regression, smoke testing, exploratory testing, automation scope, risk-based coverage, test data, release gates, defect triage, QA checklists, or verification strategy.
17 -
gabrielmoreira Skill Deps MgmtDeep dependency management workflow—inventory, upgrade policy, security patches, licensing, lockfiles, and supply-chain hygiene. Use when upgrading frameworks, resolving CVEs, or standardizing how teams pin dependencies.
17 -
gabrielmoreira Bundle Content Quality AuditorPublish-readiness gate: 80-item CORE-EEAT audit with weighted scoring, veto checks, and fix plan. 内容质量/EEAT评分
17 -
gabrielmoreira Skill Dpa ReviewRead a Data Processing Agreement before you sign it — sub-processors, transfer mechanism, breach-notice window, deletion, audit rights — in plain language with 🔴🟡🟢 risk. Use when asked to review a DPA, check a data processing agreement, is this DPA safe to sign, or what am I agreeing to on data. Produces the plain-English summary, the risk-ranked findings, the missing-clause checklist, and the questions to send back before signature.
17 -
gabrielmoreira Skill Rfc WriterWrite an engineering RFC (Request for Comments) for a technical decision, architectural change, or significant implementation approach. Use when asked to write an RFC, document a technical proposal, create a design doc, write an architecture decision for review, or produce a technical specification for team feedback. Produces a complete RFC document covering problem statement, motivation, proposed solution, alternatives rejected, implementation plan, migration plan, security and performance implications, observability changes, rollout plan, and open questions.
17 -
gabrielmoreira Skill Compliance ChecklistGenerate a prioritised compliance checklist for GDPR, SOC 2, ISO 27001, FCA, HIPAA, or other frameworks with a gap analysis. Use when asked for a compliance checklist, gap analysis, readiness assessment, or audit preparation for any regulatory framework. Produces a structured checklist with prioritised gaps, quick wins, and evidence requirements. Optimised for Opus 4.7 and newer models. Not a substitute for legal or compliance professional advice.
17 -
gabrielmoreira Skill Dental Clinical NoteWrite a dental chart note that survives an insurance audit, a recall years later, and a colleague picking up the case cold — the finding, the justification, the consent conversation, and the materials, in the order a reviewer looks for them. Use when asked to write a chart note, document a procedure, improve clinical documentation, or when a claim was denied for insufficient documentation. Produces a structured note with subjective, objective, assessment and plan, the medical necessity justification, consent documented, materials and lot numbers, and the next-visit plan. Documentation support only; the clinical content is the treating clinician's.
17 -
gabrielmoreira Skill Esg Disclosure DraftDraft an honest, audit-ready ESG disclosure section in a CSRD/ESRS-flavored structure, adaptable to other frameworks. Use when asked to write a sustainability report section, draft an ESRS or CSRD disclosure, prepare an ESG section for an annual report, or turn raw sustainability data into disclosure text. Produces a disclosure draft with double-materiality framing, metric-methodology-limitation triplets, based forward statements, and explicit data-gap handling.
17 -
gabrielmoreira Skill Grocery Budget AuditFind where the food money actually goes — a no-shame ledger built from real receipts/statements, the four leak categories (waste, convenience markup, brand autopilot, the takeaway blur), a per-leak fix with realistic savings ranges, and a target budget that survives real life. Use when someone says 'we spend how much on food?!', 'audit my grocery spending', 'cut our food bill', or takeaway guilt is the household argument. Produces the ledger, the leak report, and a keep-the-joy budget.
17 -
gabrielmoreira Skill Shared Drive CleanupClean up a shared drive nobody owns — the ownership-first move, the top-down audit that finds the 80% (stale projects, duplicates, ex-employee folders), the archive-don't-delete discipline for shared property, and the norms that prevent regrowth. Use when asked our shared drive is a disaster, clean up the team drive, who owns all these folders, or people are scared to delete anything. Produces the audit map, the archive plan with the fear-killing rule, the ownership assignments, and the going-forward norms.
17 -
gabrielmoreira Skill Establishing Code OwnershipDetermine which PostHog team owns a file, directory, or code path, or enumerate all code a team owns (via distributed `owners.yaml`, `products/*/product.yaml`, and `.github/CODEOWNERS`). Use when assigning a reviewer, attributing a bug or slow query to a team, routing work, scoping a team-wide audit, or answering "who owns X" / "what does team Y own".
17 -
gabrielmoreira Skill Webiny API Security CatalogAPI — Security & Auth — 53 abstractions. Authentication, API keys, roles, users, teams event handlers and use cases.
17 -
gabrielmoreira Skill Egocentric View To Structured LogConverts first-person XR headset video into a structured experiment timeline log. Extracts timestamped events (action, object, location, result) via VLM or action recognition, outputs Markdown or JSON for downstream analysis, reporting, protocol compliance audit, or ELN attachment.
17 -
gabrielmoreira Skill Eval ReportUse when the user has run multiple evaluation skills and wants a comprehensive analysis — maturity assessment, cross-skill signals, trends, prioritized actions, and an executive summary. Also use when the user mentions eval health check, evaluation audit, ship readiness, evaluation maturity, or "how good is my evaluation system itself." This is a read-only analysis skill.
17 -
gabrielmoreira Bundle Readme GeneratorGenerate, audit, or improve a project README following a 15-section structure (Title, Table of Contents, About, Features, Tech Stack, Architecture, Project Structure, Getting Started, Configuration, Security, How to Contribute, What's Next, License, Acknowledgements, Author) with Mermaid diagrams for architecture and flows. Use this skill whenever the user asks to "write a README", "create a README", "draft a README", "generate README.md", "scaffold project docs", "document this repo", "improve my README", "audit my README", "what should go in my README", or starts a new repository and needs documentation. Also trigger on phrases like "the README is bare", "this project has no docs", "fill in my README sections", or any request that produces or reviews a top-level repository README. The skill defaults to Mermaid for diagrams because it renders natively on GitHub, GitLab, Bitbucket, and most modern Markdown viewers — no external image hosting required.
17 -
gabrielmoreira Skill Percepxion OobManage Lantronix out-of-band (OOB) infrastructure via Percepxion central management platform: device inventory, serial port inspection via SLC CLI, firmware compliance, config management, security auditing, and closed-loop incident remediation. Use during outages, maintenance windows, compliance cycles, and AI-assisted automation workflows.
17 -
gabrielmoreira Skill Pyats SecurityNetwork security audit - ACLs, AAA, control plane policing, management plane hardening, encryption, port security, and CIS benchmark checks. Use when auditing device security posture, checking compliance, hardening a router or switch, reviewing access lists, or investigating unauthorized access.
17 -
gabrielmoreira Skill Tech Debt AuditThorough, file-cited technical debt audit across 9 dimensions using AST-grep (tree-sitter), grep, LSP, and language-native tooling. Produces TECH_DEBT_AUDIT.md with severity, effort estimates, and prioritized fixes. Use when asked for codebase health check, tech debt audit, architecture review, code quality assessment, or cleanup planning. Triggers: 'tech debt', 'technical debt', 'debt audit', 'code health', 'technical debt audit', 'codebase health check', 'find tech debt', 'debt analysis', 'audit code quality'.
17
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include 701-technologies-openapi, wow-api-combat, escalation-pack. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.