Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
johnalbertini14-glitch Bundle BackendBuild reliable backend services with proper error handling, security, and observability.
1 -
johnalbertini14-glitch Bundle BackupImplement reliable backup strategies avoiding data loss, failed restores, and security gaps.
1 -
johnalbertini14-glitch Bundle BitcoinAssist with Bitcoin transactions, wallets, Lightning, and security decisions.
1 -
johnalbertini14-glitch Bundle CamerasConnect to security cameras, capture snapshots, and process video feeds with protocol support.
1 -
johnalbertini14-glitch Bundle FoldersIndex important directories and perform safe folder operations with proper security checks.
1 -
johnalbertini14-glitch Bundle PasskeyImplement WebAuthn passkeys avoiding critical security and compatibility pitfalls.
1 -
johnalbertini14-glitch Bundle WindowsWindows-specific patterns, security practices, and operational traps that cause silent failures.
1 -
johnalbertini14-glitch Bundle Pr Risk AnalyzerAnalyze GitHub pull requests for security risks and determine if a PR is safe to merge.
1 -
johnalbertini14-glitch Bundle Polymarket News MonitorMonitor official Polymarket sources (The Oracle blog, API status) for important updates, security alerts, and breaking news. Automatic importance scoring with instant notifications for critical events.
1 -
johnalbertini14-glitch Bundle Skill Security AuditorCommand-line security analyzer for ClawHub skills. Run analyze-skill.sh to scan SKILL.md files for malicious patterns, credential leaks, and C2 infrastructure before installation. Includes threat intelligence database with 20+ detection patterns.
1 -
johnalbertini14-glitch Bundle Fal Consumption Audit审计 fal 账号消耗与用户扣费的一致性。查询 fal 官方账单,交叉比对 fal_tasks 中的用户消耗,汇总积分/现金明细,检测异常。当用户提到"消耗审计"、"账单核对"、"fal 对账"、"用量异常"时使用此 skill。
1 -
johnalbertini14-glitch Bundle Openclaw Setup GuideStep-by-step 6-part guide to set up OpenClaw AI assistant on VPS with WhatsApp, Google OAuth, backups, security, automation, and verification.
1 -
johnalbertini14-glitch Bundle Openclaw Audit WatchdogAutomated daily security audits for OpenClaw agents with email reporting. Runs deep audits and sends formatted reports.
1 -
johnalbertini14-glitch Bundle Skill Audit GuardianAudit dropped ClawHub skill ZIPs, classify risk (SAFE/CAUTION/REMOVE), auto-sort files, and generate a plain-English security dashboard.
1 -
johnalbertini14-glitch Bundle Compliance CheckerPolicy-based compliance assessment for OpenClaw skills. Define security policies, assess skills against them, track violations, and generate compliance reports. Maps findings to frameworks like CIS Controls and OWASP. Integrates with arc-skill-scanner and arc-trust-verifier.
1 -
johnalbertini14-glitch Bundle Presale Regulation AuditorAudit regulation freshness and update policy-driven controls without hardcoding. Use when checking if sales/process regulations are outdated, inconsistent with operations, or need config-level updates.
1 -
johnalbertini14-glitch Bundle Sys Guard Linux RemediatorHost-based Linux incident response and remediation skill focused on precise threat detection, forensic-safe data collection, firewall control (iptables/nftables), integrity validation, and controlled remediation while preserving system stability.
1 -
johnalbertini14-glitch Bundle Mpc Accept Crypto PaymentsAccept crypto payments on Solana via MoonPay Commerce (formerly Helio). Create Pay Links, generate checkout URLs, check transactions, and list supported currencies. Use when the user wants to accept crypto payments, create payment links, charge for products/services with crypto, or query payment transactions. Requires a MoonPay Commerce account with API key and secret.
1 -
johnalbertini14-glitch Bundle Afrexai Cybersecurity EngineComplete cybersecurity assessment, threat modeling, and hardening system. Use when conducting security audits, threat modeling, penetration testing, incident response, or building security programs from scratch. Works with any stack — zero external dependencies.
1 -
johnalbertini14-glitch Bundle Moltbot SecuritySecurity hardening for AI agents - Moltbot, OpenClaw, Cursor, Claude. Lock down gateway, fix permissions, auth, firewalls. Essential for vibe-coding setups.
1 -
johnalbertini14-glitch Bundle Switchboard Data OperatorAutonomous operator for Switchboard on-demand feeds, Surge streaming, and randomness. Designs jobs, simulates via Crossbar, and deploys/updates/reads feeds across Solana/SVM, EVM, Sui, and other Switchboard-supported chains—with user-controlled security, spend limits, and allow/deny lists.
1 -
johnalbertini14-glitch Bundle ComplianceclawRegulations change 4,000+ times per year. Your clients can't track them all. complianceclaw monitors federal and state regulatory changes, maps them to your clients' obligations, generates compliance checklists, and produces audit-ready reports—before the enforcement action arrives.
1 -
auth0 Bundle Auth0Use when adding, fixing, or improving how an app authenticates users or protects an API, or when using or configuring any Auth0 feature — signing users in and out, sessions and tokens, guarding routes and endpoints, MFA, SSO, Organizations, RBAC, custom domains, Universal Portals for hosted account and organization self-service, or Universal Login branding. Also use to audit a tenant's health, security, and plan fit (CheckMate), to debug why an auth flow fails, to migrate from another auth provider, or to set up the Vercel native integration. Covers any web, mobile, or backend framework and every Auth0 SDK, tool, and API. Use even if the user never mentions Auth0.
-
behisecc Bundle Vibesec SkillThis skill helps Claude write secure web applications. Use this when working on any web application or when a user requests a scan or audit to ensure security best practices are followed.
9.7k -
hustcer Bundle Nushell ProComprehensive Nushell scripting best practices, idioms, security, and evidence-driven code review. Use when writing, reviewing, auditing, debugging, or refactoring Nushell (.nu) scripts, modules, custom commands, pipelines, config, and tests. Also use for Bash/POSIX-to-Nushell conversion and Nu 0.114/0.115 migration issues such as stricter types, YAML 1.2, `external_arg`, `run`, SemVer, optional `nothing`, subprocess diagnostics, and explicit submodule imports.
-
ivan-magda Bundle Swift Security ExpertUse when working with iOS/macOS Keychain Services (SecItem queries, kSecClass, OSStatus errors), biometric authentication (LAContext, Face ID, Touch ID), CryptoKit (AES-GCM, ChaChaPoly, ECDSA, ECDH, HPKE, ML-KEM), Secure Enclave, secure credential storage (OAuth tokens, API keys), certificate pinning (SecTrust, SPKI), keychain sharing across apps/extensions, migrating secrets from UserDefaults or plists, or OWASP MASVS/MASTG mobile compliance on Apple platforms.
-
jazzychad Bundle IOS Code AuditRun a thorough audit of an iOS / macOS Swift codebase — bugs, dead code, duplication, Swift concurrency issues, deprecated APIs, security, performance, and SwiftUI quality — and produce a single navigable CODE_AUDIT.md report with file:line-cited findings. Use when the user asks for a "code audit", "comprehensive review", "find tech debt", "what should I clean up", or similar broad-scope assessment of a Swift project.
-
kunchenguid-chrome-devtools-axi Skill Chrome Devtools AxiControl a Chrome browser session through the chrome-devtools-axi CLI - navigate, snapshot, click, fill forms, run JavaScript, inspect console and network, take screenshots, audit performance. Use whenever a task needs a real browser: opening or testing a web page, clicking through a flow, extracting page content, or debugging a website.
-
devanshudesai Bundle Design AuditUI/UX design audit with Steve Jobs and Jony Ive design philosophy
-
skymavis Bundle Decision RecordsDraft, promote, archive, and supersede ADR-style decision records (types are open: architecture, product, security, policy, legal, …) and keep INDEX.md and cross-links generated, via the bundled scripts/decisions.py tool. Use when creating or promoting decision drafts, superseding or archiving a decision, fixing a promotion breach, flattening the old per-type accepted/ layout, or running build, check, promote, rename-draft-id, migrate-layout, or install.
-
dmmulroy-better-result Bundle Adopt Better ResultAdopt better-result in an existing TypeScript codebase. Use for a repository-wide error-handling audit and proposal, or for implementing a named vertical slice with TaggedError and Result.
-
dmmulroy-better-result Bundle Audit Better Result DependentsAudit better-result changes or PRs against known Prisma and Better T Stack downstream dependents. Use when working on better-result API/type/runtime changes and the user asks whether a change breaks Prisma dependents, Better T Stack dependents, npm dependents, or PR compatibility.
-
dosu-ai Bundle DosuUse the Dosu CLI to authenticate and configure coding agents; manage Libraries, Agents, sources, Monitor, documents, reviews, threads, topics, members, integrations, and deployments; query knowledge; or audit a repository for Dosu-generated docs. Use for Dosu platform work that should be done from a terminal instead of the web app.
-
hosmelq Bundle Durable Workflow ControlDurable repo-local workflow control for explicit loop/queue workflows, long-running implementation or review passes, durable source-backed investigations, and goal/control handoffs that need a persistent cursor, evidence surface, verifier, and stop state. Use when the user asks to create, run, resume, reset, audit, or improve a durable loop/queue; asks for a goal with verified control links; references existing control artifacts; or grants durable continuation. Do not trigger for ordinary one-turn research, generic docs, notes, goals, or handoffs that do not need durable tracking.
-
spatie-guidelines-skills Bundle Spatie SecurityApply Spatie's security guidelines when configuring applications, databases, servers, credentials, or signed Git commits, or when reviewing code for security concerns; use for SSL setup, CSRF protection, password hashing, database permissions, and server hardening.
-
webshare-proxy Skill Spend AuditAudits a Webshare account for wasted proxy spend and recommends plan adjustments based on the account's own historical usage, using the webshare CLI. Use periodically (e.g. monthly) or whenever asked to review proxy costs, find savings, cut spend, or right-size plans. Strictly read-only — it recommends, it never changes the account.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include afrexai-cybersecurity-engine, moltbot-security, switchboard-data-operator. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.