Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
aiskillstore Bundle Inbox Guardian For GmailReview a personal Gmail inbox with local, owner-approved spam rules. Use for audit-first quarantine, Trash, repeated-evidence sender learning, and header review. Do not use for automatic unsubscribe requests or unreviewed mailbox actions.
-
aiskillstore Bundle Okx Agentic WalletOKX Agentic Wallet — the single skill for the user's wallet and on-chain execution. Use it whenever the user wants to operate their wallet or execute an on-chain action, including: login & accounts, balance / holdings, wallet address / deposit / receive, send / transfer, contract calls (approve / deposit / withdraw), transaction history & status, message signing, wallet export & policy; pay gas with a stablecoin (Gas Station, Solana); swap / trade / buy / sell / convert, get a quote; cross-chain bridge & track arrival; limit orders (buy dip / take profit / stop loss / buy above) plus cancel / list / resume them; broadcast / gas / simulate / track a transaction; look up any public address's holdings; security scanning (token / honeypot 蜜罐 / 貔貅, DApp phishing, tx & signature checks, approvals); audit log. Once matched, follow this skill's Intent Routing to dispatch to the exact action.
-
aiskillstore Bundle Clean Closed Issue WorktreesSafely audit and remove Git worktrees linked to closed GitHub or GitLab issues. Use when scanning worktrees, verifying issue/PR/MR state, estimating space savings, or cleaning completed work.
-
aiskillstore Bundle Home Bar Inventory AuditReconcile a recorded home-bar inventory against supplied physical bottle observations. Use after purchases, use, moves, or a long gap when every record and observation needs one review-only disposition.
-
aiskillstore Bundle Python Web App Security AuditRun defensive pre-release security tests for Python web applications. Use for FastAPI, Django, Flask, and ASGI services: the common interface between Python web apps and servers. Tests authentication, authorization, hostile input, headers, CORS, cookies, rate limits, errors, and configuration to return evidence-backed findings and clear test boundaries.
-
aiskillstore Bundle Recurring Character Diary ComicCreate, audit, and repair short page-native diary comics around an existing authorized recurring character, with story-directed page rhythm, exact dialogue, directional-surface proof, and original-resolution visual QA. Use when extending an established recurring-character series from an anecdote, conversation, dream, or viewpoint, or when checking or repairing identity, anatomy, text, prop, relation, continuity, or layout defects. Do not use for standalone character design, educational explainers, infographics, one-off illustrations, generic memes, unauthorized characters or marks, imitation of a named living artist, watermarking, or social-platform publishing.
-
aiskillstore Bundle Dynamic Content PersonalizerUse when the user asks to "personalize the email", "add merge tags / dynamic content", "set up conditional blocks per segment", or "make first-name and product-recommendation fields fall back safely"; produces a merge-tag map with per-tag fallbacks, conditional-block rules with per-segment variations, a fallback-safety audit, and a PII guard on what may render, informing the SEND E (Engagement/personalization) dimension. Not for building the segments — use list-segment-builder; not for writing the base copy — use email-creative-builder; not for scoring EQS or running vetoes — use email-quality-auditor. 邮件个性化/合并标签/条件内容块/兜底默认值
-
aiskillstore Bundle Personwise Security Awareness TrainingUse when the user asks for Security Awareness Training from supplied source materials. Trigger language: security awareness training; cyber awareness training; employee security training. Produce a grounded interactive digital-human course learners can interrupt with voice questions. Do not invent unsupported facts or claim external certification, competence, or real-world completion. Not limited to this scenario: handles any other course creation request with the same workflow.
-
aiskillstore Bundle Automation Integration Preflight ActionAudit a public webpage for automation and integration readiness through the TinyOps paid x402 service. Use for evidence-backed readiness findings, prioritized integration risks, or a structured acceptance checklist. Do not use for private or authenticated pages, form submission, or security testing.
-
modbender Bundle DepguardDependency audit, vulnerability scanning, and license compliance. Free vuln check + paid continuous monitoring via git hooks.
12 -
modbender Skill SentinelTransform an Android phone with IP Webcam into an intelligent Edge AI security system with OpenClaw.
12 -
modbender Bundle IronclawSafety for AI agents. Real-time threat classification to detect malicious content before it causes agents harm.
12 -
modbender Bundle PaymentsIntegrate payments with provider selection, checkout flows, subscription billing, and security best practices.
12 -
modbender Skill RedshiftManage application secrets with the Redshift CLI (https://redshiftapp.com) — decentralized, encrypted secret management built on Nostr. Use when setting, getting, deleting, listing, uploading, or downloading secrets, injecting secrets into commands, configuring projects/environments, or authenticating with Nostr keys. Covers redshift secrets, redshift run, redshift setup, redshift login, and related commands.
12 -
modbender Skill SolidityAvoid common Solidity mistakes — reentrancy, gas traps, storage collisions, and security pitfalls.
12 -
modbender Bundle SpecvibeA world-class, spec-driven development framework for building production-ready, AI-native applications. Use for any new project to ensure adherence to the most advanced 2026 best practices in architecture, security, testing, and deployment.
12 -
modbender Bundle TruthseaVerify claims, build epistemological dependency graphs, and earn TRUTH tokens on Base L2. Security-hardened contracts (V2.5) with ReentrancyGuard, era emission caps, and Slither-audited code.
12 -
modbender Bundle AI CsuiteRuns a script-backed AI C-Suite strategic debate for SaaS teams. It builds a stage-aware executive roster, generates structured debate rounds, synthesizes a Chief-of-Staff brief, and outputs a CEO decision with action items. Includes security and output validation scripts designed for VirusTotal-safe distribution.
12 -
modbender Bundle Audit FixerAnalyze npm audit output with AI and get actionable fix suggestions. Use when dealing with security vulnerabilities.
12 -
modbender Bundle Bug AuditComprehensive bug audit for Node.js web projects. Activate when user asks to audit, review, check bugs, find vulnerabilities, or do security/quality review on a project. Supports game projects (Canvas/Phaser/Three.js), data tools (crawlers/schedulers), WeChat mini-programs, API services, dashboards, and bots. Dynamically generates a tailored audit plan based on project profiling rather than running a fixed checklist.
12 -
modbender Bundle Cabin SolSolana development tutor and builder. Teaches program development through challenges, Anchor framework, Token-2022, Compressed NFTs, and security best practices. "Return to primitive computing."
12 -
modbender Bundle ClauditorTamper-resistant audit watchdog for Clawdbot agents. Detects and logs suspicious filesystem activity with HMAC-chained evidence.
12 -
modbender Bundle Claw LintSecurity scanner for OpenClaw skills. Detects malware and backdoors before execution, scores risk levels, and monitors file integrity through static code analysis.
12 -
modbender Skill ClawshellHuman-in-the-loop security layer. Intercepts high-risk commands and requires push notification approval.
12 -
modbender Skill ClawsmithCreate, audit and publish production-ready OpenClaw skills with one command. 10 modes included.
12 -
modbender Bundle ConfidantSecure secret handoff and credential setup wizard for AI agents. Use when you need sensitive information from the user (API keys, passwords, tokens) or need to save credentials to config files. Never ask for secrets via chat — use Confidant instead.
12 -
modbender Bundle Cross RefCross-reference GitHub PRs and issues to find duplicates and missing links. Spawns parallel Sonnet subagents to semantically analyze the last N PRs and issues, finding PRs that solve the same problem (duplicates) and issues resolved by open PRs but not yet linked. Groups findings into thematic clusters, scores them by actionability, and offers rate-limited commenting or bulk actions (close, label). Use this skill when the user wants to find duplicate PRs, link issues to PRs, clean up a repo's cross-references, or audit PR/issue relationships. Also useful when the user says things like "find related PRs", "which PRs fix this issue", "are there duplicate PRs", "link issues and PRs", or "audit cross-references".
12 -
modbender Bundle Dep AuditAudit project dependencies for known vulnerabilities (CVEs). Supports npm, pip, Cargo, and Go. Zero API keys required. Safe-by-default: report-only mode, fix commands require confirmation.
12 -
modbender Bundle EcommerceBuild and operate online stores with payment security, inventory management, marketplace integration, and conversion optimization.
12 -
modbender Bundle EthskillsEthereum development knowledge for AI agents — from idea to deployed dApp. Fetch real-time docs on gas costs, Solidity patterns, Scaffold-ETH 2, Layer 2s, DeFi composability, security, testing, and production deployment. Use when: (1) building any Ethereum or EVM dApp, (2) writing or reviewing Solidity contracts, (3) deploying to mainnet or L2s, (4) the user asks about gas, tokens, wallets, or smart contracts, (5) any web3/blockchain/onchain development task. NOT for: trading, price checking, or portfolio management — use a trading skill for those.
12 -
modbender Bundle Feed DietAudit your information diet across HN and RSS feeds — beautiful reports with category breakdowns, ASCII charts, and personalized recommendations.
12 -
modbender Bundle MoltcheckSecurity scanner for Moltbot skills. Scan GitHub repositories for vulnerabilities before installation.
12 -
modbender Bundle MoltguardMoltGuard — runtime security plugin for OpenClaw agents by OpenGuardrails. Helps users install, register, activate, and check the status of MoltGuard. Use when the user asks to: install MoltGuard, check MoltGuard status, register or activate MoltGuard, configure the AI Security Gateway, or understand what MoltGuard detects. Provides local-first protection against data exfiltration, credential theft, command injection, and sensitive data leakage. Source: https://github.com/openguardrails/openguardrails/tree/main/moltguard
12 -
modbender Bundle ReefwatchContinuous local security monitoring daemon for Linux and macOS. Detects brute-force attacks, malware, privilege escalation, suspicious processes, file tampering, cryptominers, and network anomalies using YARA, Sigma, and custom detection rules. Runs as a background process and alerts only when real threats are found. Use when the user wants host-level intrusion detection, security monitoring, threat scanning, or asks about suspicious activity on their machine.
12 -
modbender Bundle Openclaw Security Audit Skill本 Skill 是一个安全审计工具,可检测 OpenClaw 部署中的以下安全问题:
12 -
modbender Bundle SecucheckComprehensive security audit for OpenClaw. Scans 7 domains (runtime, channels, agents, cron, skills, sessions, network), supports 3 expertise levels, context-aware analysis, and visual dashboard. Read-only with localized reports.
12
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include inbox-guardian-for-gmail, okx-agentic-wallet, clean-closed-issue-worktrees. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.