Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
modbender Skill ShieldapiShieldAPI — x402 Security Intelligence for AI Agents. 7 endpoints: password breach check (900M+ HIBP hashes), email breach lookup, domain reputation (DNS/blacklists/SSL/SPF/DMARC), IP reputation (Tor/blacklists), URL safety (phishing/malware/brand impersonation), and full security scan. Pay-per-request with USDC micropayments ($0.001-$0.01). No account, no API key, no subscription. Demo mode on all endpoints.
12 -
modbender Bundle Agentaudit SkillAutomatic security gate that checks packages against a vulnerability database before installation. Use before any npm install, pip install, yarn add, or package manager operation.
12 -
modbender Bundle Audit CodeSecurity-focused code review for hardcoded secrets, dangerous calls, and common vulnerabilities
12 -
modbender Bundle Auto ReplyInstagram DM auto-reply system. DM monitoring, reading, replying, security check (injection rejection). Use when checking Instagram DMs, reading unread messages, replying to DMs, setting up DM monitoring cron jobs, or handling DM auto-reply workflows. Triggers on: Instagram DM, DM check, DM reply, DM auto-reply, dm-alert.
12 -
modbender Bundle Zeroex Swap Skill⚠️ SECURITY WARNING: This skill involves real funds. Review all parameters before executing swaps.
12 -
modbender Bundle Abm OutboundMulti-channel ABM automation that turns LinkedIn URLs into coordinated outbound campaigns. Scrapes profiles, enriches with Apollo (email + phone), gets mailing addresses via Skip Trace, then orchestrates email sequences, LinkedIn touches, and handwritten letters via Scribeless. The secret weapon for standing out in crowded inboxes.
12 -
modbender Skill Pywayne Aliyun OssAliyun OSS (Object Storage Service) file management toolkit for Python. Use when working with Aliyun OSS to upload files, download files, list objects, delete files, manage directories, read file contents, check file existence, get file metadata, copy and move objects. Supports both authenticated (with API key/secret for write operations) and anonymous access (read-only).
12 -
modbender Skill API Security Best PracticesImplement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilities.
12 -
modbender Bundle Arc SentinelSecurity monitoring and infrastructure health checks for OpenClaw agents. Run breach monitoring (HaveIBeenPwned), SSL certificate expiry checks, GitHub security audits, credential rotation tracking, secret scanning, git hygiene, token watchdog, and permission audits. Use when performing security scans, checking credential rotation status, auditing repos for leaked secrets, or monitoring SSL certificates and infrastructure health.
12 -
modbender Bundle Auth AuditorAudit your authentication implementation for security flaws. Use when you need to verify your auth is actually secure.
12 -
modbender Bundle Clawsec FeedSecurity advisory feed with automated NVD CVE polling for OpenClaw-related vulnerabilities. Updated daily.
12 -
modbender Bundle ClawtributorCommunity incident reporting for AI agents. Contribute to collective security by reporting threats.
12 -
modbender Bundle Crypto ToolsAccess crypto data, monitor portfolios, detect scams, and navigate exchanges with real-time APIs and security tools.
12 -
modbender Bundle Discord Server CtrlComplete A-Z Discord server administration. Channel/role/member management, AutoMod, webhooks, templates, audit logs, scheduled events, threads, and full server control via CLI.
12 -
modbender Skill Dont Hack Me別駭我!基本安全檢測 — Security self-check for Clawdbot/Moltbot. Run a quick audit of your clawdbot.json to catch dangerous misconfigurations — exposed gateway, missing auth, open DM policy, weak tokens, loose file permissions. Auto-fix included. Invoke: "run a security check" or "幫我做安全檢查".
12 -
modbender Skill FrankensteinCombine the best parts of multiple skills into one. Searches ClawHub, GitHub, skills.sh, skillsmp.com and other AI skill repos. Analyzes each safely, compares features, and builds a combined 'Frankenstein' skill with the best of each. Uses skill-auditor for security scanning and sandwrap for safe analysis. Use when: (1) Multiple skills exist for same purpose, (2) Want best-of-breed combination, (3) Building a comprehensive skill from fragments.
12 -
modbender Bundle Hookflo TernUse this skill for requests touching webhooks, event-driven infrastructure, or real-time HTTP callbacks — from beginner setup to advanced security and architecture. Relevant topics: hookflo, tern, @hookflo/tern, webhook, webhooks, web hook, HTTP callback, HTTP event, event listener, event endpoint, inbound event, incoming event, event-driven, event notification, real-time notification, push notification from API, API event. Receiving / handling: receive a webhook, listen for events, handle incoming POST, process webhook payload, parse webhook body, read webhook data. Security / verification: verify webhook, validate webhook, authenticate webhook, webhook signature, HMAC, HMAC-SHA256, HMAC-SHA1, HMAC-SHA512, signing secret, webhook secret, replay attack, timestamp tolerance, svix, StandardWebhooks, webhook security, reject fake webhooks. Alerting / monitoring: webhook alert, notify on event, Slack alert from webhook, email alert from webhook, webhook log, webhook dashboard, monitor webhooks, debug webhook, web
12 -
modbender Bundle Ntopng AdminProfessional network monitoring and device identification using ntopng Redis data. Designed for security auditing and diagnostic environments.
12 -
modbender Bundle Password GenSecure password generator with multiple character sets and strength analysis. Use when: (1) generating strong passwords, (2) creating memorable passphrases, (3) analyzing password strength, or (4) any password-related security needs. Supports random passwords, passphrases, and detailed strength analysis.
12 -
modbender Bundle Perf AuditorRun a Lighthouse performance audit with AI fix suggestions. Use when your site is slow and you need actionable fixes.
12 -
2oaj Bundle Swiftlys2 ToolkitPlan, implement, audit, and review C#/.NET SwiftlyS2 plugins. Use when working with Commands, Core Events, Game Events, GameHooks Pre/Post, raw native hooks, Modules, Workers, Services, high-frequency runtime loops, NetMessages, Schema access, entity handling, thread safety, performance, or IPlayer lifecycle behavior.
-
gabrielmoreira Skill Devex ReviewLive developer experience audit. (gstack)
17 -
conorbronsdon Bundle Avoid AI WritingAudit and rewrite content to remove AI writing patterns ("AI-isms"). Use this skill when asked to "remove AI-isms," "clean up AI writing," "edit writing for AI patterns," "audit writing for AI tells," or "make this sound less like AI." Supports a detect-only mode, an edit-in-place mode for files, an optional voice profile (casual / professional / technical / warm / blunt), and an iterate-to-convergence pass.
-
gabrielmoreira Bundle HallmarkAnti-AI-slop design skill for greenfield pages, audits, redesigns, and design extraction from URLs or screenshots. Use when the user asks to build a new app or landing page, wants to redesign something, invokes Hallmark by name, or uses audit/redesign/study.
17 -
taracodlabs Bundle SsllabsTLS/SSL audit via Qualys SSL Labs — grade ciphers, chains, vulns
-
gabrielmoreira Bundle Reverse Skill RouterRoutes reverse engineering, exploitation, penetration testing, malware, mobile, firmware, browser automation, documentation, and security tasks to the appropriate specialist skill. Use when a task spans modules or the correct reverse-skill entrypoint is unclear.
17 -
bitjaru Skill Ss AuditAudit screens for UX issues using Nielsen's heuristics and modern mobile UX best practices
-
openlair Bundle Ds ReviewUse when a draft, paper, or paper-like report is substantial enough for an independent skeptical audit before finalization, rebuttal, or revision routing.
-
ryo-ebata Skill Code Review HelperA safe skill that helps with code review tasks
-
lennney Bundle StssReduce defensive disclaimers, stacked hedging, and self-protective narration in proposals and decision-facing writing. Use when the user asks to rewrite or audit a proposal, plan, research contribution, executive summary, or similar text for directness. Do not use for ordinary code work or unrelated prose.
-
yaoapp Skill Yao SecretSecret management expert. ALWAYS invoke this skill when you need to read API keys, tokens, or other secrets configured by the user. Never hardcode credentials — use this skill to retrieve them securely.
-
nexu-io Bundle Sync SpecsUse when code changes may have made documentation outdated, when reviewing docs for consistency, or when the user asks to sync or audit documentation.
-
nowork-studio Skill Google Ads AssetsPlan, validate, and safely publish Google Ads assets, including sitelinks, callouts, structured snippets, image assets, and Performance Max asset briefs. Use when asked for Google Ads assets, ad extensions, sitelinks, callouts, snippets, image assets, Performance Max assets, PMax creative, or an asset audit.
-
nyldn Bundle Skill AuditAudit codebases for quality, consistency, and broken patterns — use for pre-release or tech debt review
-
odradekai Bundle AuditingUse when reviewing a bundle-plugin for structural issues, version drift, skill quality, workflow integration, or security risks — before releasing, after changes, or after adding skills. Auto-detects scope (full project vs skill vs workflow)
-
openakita Bundle Openakita Skills Dingtalk CLIDingTalk Workspace CLI (dws) - officially open-sourced cross-platform CLI tool from DingTalk. Provides 86 commands across 12 products: Contact, Chat, Bot, Calendar, Todo, Approval, Attendance, Ding, Report, AITable, Workbench, DevDoc. Built in Go with zero-trust security architecture. Use when user wants to operate DingTalk resources.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include swiftlys2-toolkit, devex-review, reverse-skill-router. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.