Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
agents-store Bundle Security AuditUse when the security posture of an OpenClaw instance or of the whole fleet is in question — a gateway port that may be reachable from outside the host, firewall rules that read correctly but may not apply to published ports, an operator bearer token that may be shared between instances or sitting in a plaintext file, permissions on state, credential or identity trees, a metrics or admin endpoint answering without authentication, a secret found in a backup or an identity copy, a question about who can reach an instance and what that access grants, before exposing an instance to a new network or new people, and after any suspected compromise.
-
agents-store Bundle Encrypted StorageThis skill should be used when encrypting or decrypting financial data files, rotating the storage passphrase, understanding where data is stored, or troubleshooting encryption errors. Relevant for queries like "encrypt my transaction data", "change my storage passphrase", "where are my bank files stored", or "decrypt accounts file". Use this skill whenever the user asks about data security, encryption, storing financial data, passphrase management, or where their data is saved.
-
agents-store Skill Backlink AuditThis skill should be used when the user asks about "backlink audit", "backlink analysis", "link profile", "toxic links", "referring domains", "link building", "backlink prospecting", "disavow list", "spam score", or needs to analyze backlink profiles using DataForSEO.
-
agents-store Skill Secret ScanningThis skill should be used when the user asks to "scan for secrets", "Infisical scan", "find leaked secrets in git", "set up a pre-commit secret scan", "infisical scan git-changes", "scan repo for API keys", "add a secret-scanning baseline", or "ignore a false-positive secret" — using the Infisical CLI to detect and prevent committed secrets.
-
agents-store Bundle Access ControlThis skill should be used when the user asks about "Payload access control", "RBAC in Payload", "row-level security", "isAdmin function", "field access control", "global access control", "overrideAccess", "multi-tenant Payload", "filter by user role", "Payload Access function", or needs to decide who can create/read/update/delete documents.
-
agents-store Bundle Fleet DiagnosticsUse when an OpenClaw instance is misbehaving or suspected of it — health green but nothing is happening, a container restarting or unhealthy, an empty or ignored config, models returning unauthorized or reporting logged out, tokens that are present but empty, schedules failing or firing twice or stalling, memory search dead or paused or a state database growing without limit, keys missing inside the container, shared skills that look installed and do nothing, a version that does not match its siblings, or a port published where it should not be. Also use when a report, audit or repair needs a stable finding id.
-
agents-store Bundle Secrets InfisicalUse when secrets reach an OpenClaw instance through an injection wrapper and something about that is in question — a feature silently off while the config looks right, an instance receiving far fewer keys than its siblings, a plaintext env file inside the state tree, a token or client id sitting in a backup or identity copy, a key that has to be added, rotated, or proven delivered, a machine identity or its project binding, a secret reference in the config, or a restart whose safety depends on every referenced key still resolving.
-
agents-store Skill Workflow AnalysisAnalyze an n8n workflow JSON before importing — node inventory, connection topology, credential requirements, security flags, complexity scoring, and compatibility checks. Use when asked to "analyze n8n workflow", "check workflow before import", "workflow compatibility check", "review n8n template", "assess workflow complexity", or before importing any template or community workflow.
-
agents-store Skill Instance ReadinessAssess n8n instance readiness before provisioning. Runs health checks, inventories workflows and credentials, detects conflicts, verifies community nodes, and produces a readiness report with pass/warn/fail ratings. Use when: "check n8n instance", "is n8n ready for provisioning", "n8n health check", "verify n8n instance", "pre-provisioning check", "audit n8n before import", "instance readiness report"
Audited -
agents-store Bundle Labels States PropertiesDesign taxonomies for Plane projects — labels, workflow states, work item types, and custom properties. Use when the user asks how to organize labels, design a state machine, set up custom fields, configure work item types, decide between label/property/type, or audit a noisy taxonomy. Covers naming conventions, recommended sets, and the difference between the four metadata mechanisms.
-
agents-store Bundle Audit StackUse when the user asks to "audit project stack", "analyze technologies", "scan dependencies", "generate stack.json", "what template level is this project", "map project to layers", or wants to discover all technologies in a codebase and get template and stack.json recommendations.
-
xalgord Skill Performing Arp Spoofing Attack SimulationSimulates ARP spoofing attacks in authorized lab or pentest environments using arpspoof, Ettercap, and Scapy to demonstrate man-in-the-middle risks, test network detection capabilities, and validate ARP inspection countermeasures.
-
xalgord Skill Detecting Modbus Command Injection AttacksDetect command injection attacks against Modbus TCP/RTU protocol in ICS environments by monitoring for unauthorized write operations, anomalous function codes, malformed frames, and deviations from established communication baselines using ICS-aware IDS and protocol deep packet inspection.
Audited -
xalgord Skill Implementing Ot Incident Response PlaybookDevelop and implement OT-specific incident response playbooks aligned with SANS PICERL framework, IEC 62443, and NIST SP 800-82 that address unique ICS challenges including safety-critical systems, limited downtime tolerance, and coordination between IT SOC, OT engineering, and plant operations teams.
Audited -
xalgord Skill Performing Ransomware Tabletop ExercisePlans and facilitates tabletop exercises simulating ransomware incidents to test organizational readiness, decision-making, and communication procedures. Designs realistic scenarios based on current ransomware threat actors (LockBit, ALPHV/BlackCat, Cl0p), injects covering double extortion, backup destruction, and regulatory notification requirements. Evaluates participant responses against NIST CSF and CISA guidelines. Activates for requests involving ransomware tabletop, incident response exercise, or ransomware readiness drill.
Audited -
xalgord Skill Performing False Positive Reduction In SiemPerform systematic SIEM false positive reduction through rule tuning, threshold adjustment, correlation refinement, and threat intelligence enrichment to combat alert fatigue.
Audited -
xalgord Skill Detecting Living Off The Land With LolbasDetect Living Off the Land Binaries (LOLBins/LOLBAS) abuse including certutil, regsvr32, mshta, and rundll32 via process telemetry, Sigma rules, and parent-child process analysis
Audited -
xalgord Skill Detecting Dcsync Attack In Active DirectoryDetect DCSync attacks where adversaries abuse Active Directory replication privileges to extract password hashes by monitoring for non-domain-controller accounts requesting directory replication via DsGetNCChanges.
Audited -
xalgord Skill Detecting Ntlm Relay With Event CorrelationDetect NTLM relay attacks through Windows Security Event correlation by analyzing Event 4624 LogonType 3 for IP-to-hostname mismatches, identifying Responder/LLMNR poisoning artifacts, auditing SMB and LDAP signing enforcement across the domain, and detecting NTLM downgrade attacks from NTLMv2 to NTLMv1 using event log analysis.
Audited -
xalgord Skill Detecting T1003 Credential Dumping With EdrDetect OS credential dumping techniques targeting LSASS memory, SAM database, NTDS.dit, and cached credentials using EDR telemetry, Sysmon process access monitoring, and Windows security event correlation.
Audited -
xalgord Skill Hunting For Registry Persistence MechanismsHunt for registry-based persistence mechanisms including Run keys, Winlogon modifications, IFEO injection, and COM hijacking in Windows environments.
Audited -
xalgord Skill Exploiting HTTP Request SmugglingDetecting and exploiting HTTP request smuggling vulnerabilities caused by Content-Length and Transfer-Encoding parsing discrepancies between front-end and back-end servers.
Audited -
xalgord Skill Testing For Broken Access ControlSystematically testing web applications for broken access control vulnerabilities including privilege escalation, missing function-level checks, and insecure direct object references.
Audited -
xalgord Skill Performing Bluetooth Security AssessmentAssess Bluetooth Low Energy device security by scanning, enumerating GATT services, and detecting vulnerabilities
Audited -
xalgord Skill Exploiting Broken Function Level AuthorizationTests APIs for Broken Function Level Authorization (BFLA) vulnerabilities where regular users can invoke administrative functions or access privileged API endpoints by directly calling them. The tester identifies admin and privileged endpoints, then attempts to access them with regular user credentials by manipulating HTTP methods, URL paths, and request parameters. Maps to OWASP API5:2023 Broken Function Level Authorization. Activates for requests involving BFLA testing, admin endpoint bypass, function-level access control testing, or API privilege escalation.
-
xalgord Skill Implementing API Threat Protection With ApigeeImplement API threat protection using Google Apigee policies including JSON/XML threat protection, OAuth 2.0, SpikeArrest, and Advanced API Security for OWASP Top 10 defense.
-
xalgord Skill Detecting Arp Poisoning In Network TrafficDetect and prevent ARP spoofing attacks using ARPWatch, Dynamic ARP Inspection, Wireshark analysis, and custom monitoring scripts to protect against man-in-the-middle interception.
Audited -
xalgord Skill Detecting Spearphishing With Email GatewaySpearphishing targets specific individuals using personalized, researched content that bypasses generic spam filters. Email security gateways (SEGs) like Microsoft Defender for Office 365, Proofpoint,
Audited -
xalgord Skill Implementing Dmarc Dkim Spf Email SecuritySPF, DKIM, and DMARC form the three pillars of email authentication. Together they prevent domain spoofing, validate message integrity, and define policies for handling unauthenticated mail. Proper im
Audited -
xalgord Skill Performing Active Directory Forest Trust AttackEnumerate and audit Active Directory forest trust relationships using impacket for SID filtering analysis, trust key extraction, cross-forest SID history abuse detection, and inter-realm Kerberos ticket assessment.
Audited -
xalgord Skill Implementing Soar Playbook For PhishingAutomate phishing incident response using Splunk SOAR REST API to create containers, add artifacts, and trigger playbooks
Audited -
xalgord Skill Hunting For Data Staging Before ExfiltrationDetect data staging activity before exfiltration by monitoring for archive creation with 7-Zip/RAR, unusual temp folder access, large file consolidation, and staging directory patterns via EDR and process telemetry
Audited -
xalgord Skill Testing For Email Header InjectionTest web application email functionality for SMTP header injection vulnerabilities that allow attackers to inject additional email headers, modify recipients, and abuse contact forms for spam relay.
Audited -
xalgord Skill Implementing API Security Testing With 42crunchImplement comprehensive API security testing using the 42Crunch platform to perform static audit and dynamic conformance scanning of OpenAPI specifications.
Audited -
xalgord Skill Analyzing Command And Control CommunicationAnalyzes malware command-and-control (C2) communication protocols to understand beacon patterns, command structures, data encoding, and infrastructure. Covers HTTP, HTTPS, DNS, and custom protocol C2 analysis for detection development and threat intelligence. Activates for requests involving C2 analysis, beacon detection, C2 protocol reverse engineering, or command-and-control infrastructure mapping.
Audited -
xalgord Skill Configuring Network Segmentation With VlansDesigns and implements VLAN-based network segmentation on managed switches to isolate network zones, enforce access control between segments, and reduce the attack surface by limiting lateral movement paths in enterprise network environments.
Audited
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include security-audit, encrypted-storage, backlink-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.