Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
hashgraph-online-awesome-codex-plugins Bundle Governance SyncAudit or explicitly synchronize Claude and Codex repository governance without overwriting conflicts. Triggers: governance sync, CLAUDE.md, AGENTS.md, instruction mirror.
-
hashgraph-online-awesome-codex-plugins Skill GuardrailsAgentGuards security guardrails — the mandatory input-screening, web-content, and destructive-command checking workflow. Load and apply this at the START of EVERY request, before using any content fetched from the web (curl/wget/HTTP libraries), and before suggesting any destructive command. Covers check_input, authorize_action, and the required block-message format.
-
hashgraph-online-awesome-codex-plugins Skill Configure ReviewUse when configuring or changing a repository's tracked branches, layered review policy, ignored tracked paths, retrieval limits, summary depth, or non-secret task-board metadata.
-
hashgraph-online-awesome-codex-plugins Bundle Staff Engineer ModeUse when engineering decisions span ideation, design, development, testing, release, operations, maintenance; API/reliability/security/data/doc lifecycle before process skills
-
hashgraph-online-awesome-codex-plugins Bundle PpapProduction Part Approval Process (PPAP) — verify PPAP submission level, audit all 18 elements, check completeness for customer approval, prepare PSW. Use when a supplier needs to submit parts for approval, when reviewing a PPAP package, or when determining which PPAP level is required. Covers AIAG PPAP 4th edition with Ford, BMW, VW, and Stellantis OEM-specific requirements.
-
hashgraph-online-awesome-codex-plugins Skill Evaluating Bgs ModsUse when deciding whether a mod belongs in a modpack — judging mod quality, fit, risk, and pack-value BEFORE download/install. Triggers - "should I add this mod", "is this mod good", "评估这个mod", "这个mod值得装吗", "is this mod worth it", "this mod looks too good to be true", "compare these mods", "does this mod fit my pack". NOT for how to install a mod (use interpreting-mod-author-instructions), load order (writing-bgs-load-order), or conflict resolution (xedit-conflict-audit).
-
hashgraph-online-awesome-codex-plugins Skill Curating Bgs ModpackUse when planning or building the whole Bethesda modpack incrementally — batch strategy, rollback point, naming convention, separator discipline, attribution, and declaring 风格 before adding mods. Triggers - "build a modpack", "plan the pack", "batch strategy", "rollback point", "naming convention", "declare 风格", "策展整合包", "整合包规划". NOT for deciding whether one mod belongs (evaluating-bgs-mods), installing one mod from author instructions (interpreting-mod-author-instructions), load order mechanics (writing-bgs-load-order), or record conflicts (xedit-conflict-audit).
-
hashgraph-online-awesome-codex-plugins Skill Xedit Conflict AuditUse when auditing conflicts in a Bethesda plugin set — determining for a record (or a plugin's records) which override wins, what the conflict label is, what references it, and whether the configuration is safe or breaking.
-
hashgraph-online-awesome-codex-plugins Skill Audit GuideInteractive internal audit guide for ISO 9001:2015 and IATF 16949:2016 — walks through key clauses interactively, scores findings as Major NC / Minor NC / OFI, and generates a structured audit report. Use when conducting an internal audit and needing real-time finding documentation and a structured clause-by-clause audit approach.
-
hashgraph-online-awesome-codex-plugins Bundle Vda 6 3 AuditVDA 6.3 Process Audit — conduct or prepare for a process audit using the VDA 6.3 methodology, evaluate process elements P1–P7, calculate degree of fulfillment, classify findings, and generate an audit report. Use when a customer requests a VDA 6.3 audit, when auditing a supplier's manufacturing process, or when preparing for a VDA process audit visit. Covers VDA 6.3 4th edition (2023).
-
hashgraph-online-awesome-codex-plugins Skill Fmea ReviewerPFMEA and DFMEA gap audit against AIAG-VDA FMEA Handbook 2019 — reviews an existing FMEA for missing failure modes, incorrect AP ratings, unaddressed H-AP items, missing special characteristics, and PFMEA-to-Control Plan linkage gaps. Returns a structured gap report with specific findings and required actions before PPAP or audit submission.
-
hashgraph-online-awesome-codex-plugins Bundle Skill AuditorAudit a SKILL.md or REFERENCE file, score it 0–10, identify major and minor findings, and generate copy-paste improvements. Use when reviewing a new skill before merging, auditing an existing skill for gaps, checking cross-skill consistency, or validating that a skill meets the Quality-Engineering-Skills framework standards. Triggers: audit this skill, score this SKILL.md, review reference file, check skill quality, find gaps in skill, validate skill before PR.
-
hashgraph-online-awesome-codex-plugins Bundle Control PlanControl Plan — build, review, or audit a Prototype, Pre-launch, or Production Control Plan linked to PFMEA failure modes and controls. Use when creating a new control plan, updating after a process change or corrective action, or auditing an existing CP for completeness and PFMEA alignment. Covers AIAG Control Plan reference manual and IATF 16949 §8.5.1.
-
hashgraph-online-awesome-codex-plugins Bundle Oss Maintainer WorkflowUse when maintaining or releasing a public open-source repository, including issue triage, pull request review, dependency or security remediation, release preparation, and source-linked adoption reporting.
-
hashgraph-online-awesome-codex-plugins Bundle Iatf 16949 AuditConduct an IATF audit, check supplemental requirements, or prepare for a manufacturing process audit or IATF 16949:2016 third-party assessment. Covers customer-specific requirements (CSR), all 16 automotive supplemental clauses, and the three required audit types: QMS audit, manufacturing process audit, and product audit. Use for internal IATF audits or supplier quality audits at automotive organisations.
-
hashgraph-online-awesome-codex-plugins Bundle Ncr WritingWrite a non-conformance report, NCR, reject a supplier, or document a defect with objective-evidence language and correct severity grading (Critical/Major/Minor). Covers disposition recommendations and segregation requirements for incoming inspection failures, in-process defects, customer returns, and audit findings.
-
hashgraph-online-awesome-codex-plugins Bundle Iso 9001 Internal AuditConduct an internal audit by clause, answer ISO 9001 internal audit questions, or prepare evidence for §4 §5 §6 §7 §8 §9 §10. Provides key audit questions by clause, finding classification (Major NC / Minor NC / OFI), and audit report writing. Use when planning or conducting an ISO 9001:2015 internal audit or preparing for third-party certification.
-
hashgraph-online-awesome-codex-plugins Skill Interpreting Mod Author InstructionsUse when deciding how to correctly download/install a Bethesda mod per the author's instructions — triggers "how do I install", "FOMOD choices", "which file to download", "author说明", "install instructions", "which variant", "按作者说明安装", "这个mod怎么装". NOT for deciding whether to include the mod (use evaluating-bgs-mods), load order editing (writing-bgs-load-order), record conflicts (xedit-conflict-audit), archive operations (using-bgs-archive), Papyrus work (using-bgs-papyrus), or translation/export tasks (using-bgs-translator).
-
hashgraph-online-awesome-codex-plugins Bundle Car Corrective ActionWrite a corrective action report, CAPA, respond to an NCR or audit finding, or document an 8D D5 root cause action. Covers the full CAR structure: root cause analysis, corrective actions, implementation evidence, and verification of effectiveness (VOE) per ISO 9001 §10.2. Use for any quality escape requiring documented systemic corrective action.
-
lord1egypt Skill Security HeadersImplementing Content Security Policy (CSP), CORS, and essential security headers in web server responses.
2 -
lord1egypt Skill Data Managed Agents Self Hosted SandboxesReference documentation for running Managed Agents tool execution in self-hosted infrastructure, including environment setup, workers, webhook-driven wake, orchestration, monitoring, credentials, and security responsibilities
2 -
leoyeai-openclaw-master-skills Bundle ElytroEthereum EIP-4337 smart contract wallet designed for AI agents. Use this skill whenever the user wants to manage Ethereum accounts, check balances, send ETH/tokens, swap tokens on Uniswap, manage 2FA security hooks, or do anything with their Elytro wallet. Supports gasless transactions via sponsorship. For token swaps, combines with the Uniswap swap-planner skill.
-
leoyeai-openclaw-master-skills Bundle Nexusweb3 SafetyRead-only API reference for NexusWeb3 safety protocols 21-30 on Base mainnet — kill switch status, KYA verification, audit logs, bounties, licensing, milestones, subscriptions, insolvency, referrals, and collectives.
-
leoyeai-openclaw-master-skills Bundle ErpclawAI-native ERP system. Full accounting, invoicing, inventory, purchasing, tax, billing, HR, payroll, advanced accounting (ASC 606/842, intercompany, consolidation), and financial reporting in a single install. 365+ actions across 14 domains. Modular expansion via GitHub-hosted modules. Double-entry GL, immutable audit trail, US GAAP.
-
leoyeai-openclaw-master-skills Skill Onchain AuditOn-chain data and contract security analysis. Includes Binance API and Bitget API for audit, token info, wallet, and contract analysis. CLAWBOT decides which to use based on context.
-
leoyeai-openclaw-master-skills Bundle 360guard360-degree comprehensive security review Skill. Use before installing any Skill from ClawHub, GitHub, or other sources. Performs full security scans including all Skill Vetter checks plus extended system/privacy/behavior checks and automated scanning scripts. Supports static analysis, behavior detection, dependency auditing.
-
leoyeai-openclaw-master-skills Bundle Derivatives Trading Usds FuturesBinance Derivatives-trading-usds-futures request using the Binance API. Authentication requires API key and secret key. Supports testnet and mainnet.
-
leoyeai-openclaw-master-skills Bundle Cis Benchmark AuditCIS benchmark compliance assessment for network infrastructure devices. Maps device configuration against CIS benchmark controls organized by Management Plane, Control Plane, and Data Plane categories across Cisco IOS, PAN-OS, JunOS, and Check Point platforms. References control IDs for traceability without reproducing copyrighted benchmark content.
-
leoyeai-openclaw-master-skills Bundle Clawhub Skill CreatorCreate ClawhHub-ready OpenClaw skills with correct structure, scanner criteria, security rules & publish checklist. No credentials or binaries required.
-
leoyeai-openclaw-master-skills Bundle Derivatives Trading Portfolio MarginBinance Derivatives-trading-portfolio-margin request using the Binance API. Authentication requires API key and secret key. Supports testnet and mainnet.
-
pjt222 Skill AwarenessAI situational awareness — internal threat detection for hallucination risk, scope creep, and context degradation. Maps Cooper color codes to reasoning states and OODA loop to real-time decisions. Use during any task where reasoning quality matters, when operating in unfamiliar territory, after detecting early warning signs such as an uncertain fact or suspicious tool result, or before high-stakes output like irreversible changes or architectural decisions.
-
pjt222 Skill MindfulnessCultivate defensive situational awareness, threat assessment, and mental clarity under pressure. Covers the Cooper color code awareness system, body language reading and intent detection, verbal de-escalation, moving mindfulness in public spaces, combat focus and the OODA loop, rapid grounding techniques for acute stress, context-specific integration, and ongoing review and refinement of awareness skills. Use when entering unfamiliar or potentially hostile environments, needing to assess a situation for safety, de-escalating a verbal confrontation, or integrating awareness practice into daily movement.
-
leoyeai-openclaw-master-skills Bundle Cisco Firewall AuditDual-platform Cisco ASA and Firepower Threat Defense (FTD) firewall audit with ACL analysis, NAT policy validation, Modular Policy Framework / Access Control Policy evaluation, Snort IPS assessment, VPN configuration review, and logging completeness verification.
-
pjt222 Skill Defend ColonyImplement layered collective defense using alarm signaling, role mobilization, and proportional response. Covers threat detection, alert propagation, immune response patterns, escalation tiers, and post-incident recovery for distributed systems and organizations. Use when designing defense-in-depth where no single guardian covers all threats, building incident response that scales with severity, or when current defense is over-reactive to every alert or under-reactive to genuine threats.
-
pjt222 Skill Configure NginxConfigure Nginx as a web server and reverse proxy. Covers static file serving, reverse proxy to upstream services, SSL/TLS termination with Let's Encrypt, location blocks, load balancing, rate limiting, and security headers. Use when serving static files in production, reverse proxying to backend services (Node.js, Python, R/Shiny), terminating SSL/TLS, load balancing across instances, or adding rate limiting and security headers to harden an endpoint.
-
pjt222 Skill Manage ChangelogMaintain a changelog following Keep a Changelog format. Covers entry categorization (Added, Changed, Deprecated, Removed, Fixed, Security), version section management, and unreleased tracking. Use when starting a new project that needs a changelog, adding entries after completing features or fixes, preparing a release by promoting Unreleased entries to a versioned section, or converting a free-form changelog to Keep a Changelog format.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include governance-sync, guardrails, configure-review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.