Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
zakirkun Skill Blue TeamBlue team defense using Deep Eye outputs for detection engineering, IR content, and hardening. Use for blue team, SOC, SIEM, detection engineering, threat hunting, IR triage, hardening, /blue-team.
-
zotonic Bundle Zotonic SecurityUse when reviewing or implementing security-sensitive Zotonic code in templates, JavaScript, Erlang, models, controllers, cookies, HTTP headers, embeds, client-stored state, access control, CSP, or client/server communication.
-
google Bundle Unsafe RustAuthor, document, review, audit, or redesign unsafe Rust with proof-grade rigor. Use for unsafe blocks and functions, unsafe traits and impls, raw pointers, FFI, inline assembly, intrinsics, layout or validity reasoning, concurrency and atomics, SIMD and target features, allocators, invariant-bearing fields, safety comments or `# Safety` documentation, soundness reviews, TCB audits, generated unsafe code, changes to safety or behavioral contracts, and proof-oriented redesign of unsafe abstractions.
14.4k -
hapelee Bundle Legado Compose ReviewReview existing Legado Jetpack Compose code for architecture, behavior, maintainability, and project convention issues. Use when Codex is asked to audit, review, inspect, evaluate, or find problems in Legado Compose screens, routes, ViewModels, contracts, dialogs, sheets, navigation, or early Compose implementations, especially for MVI/UDF, StateFlow/SharedFlow, Clean Architecture, MainActivity navigation, legacy Activity compatibility, and View-era mixed-pattern drift.
-
milanhorvatovic Bundle Toolchain DoctorExamines a repository's per-language tooling and prescribes what is missing. scan inventories the lint, format, type-check, and version-pin declarations and whether CI runs them; audit grades the distance to each language's tooling floor, advisory only; scaffold proposes minimal pinned configs and CI steps, one confirmation each. Covers python (ruff, mypy or pyright), typescript (strict tsc, biome or eslint plus prettier), rust (cargo fmt, clippy at deny-warnings), and bash (shellcheck, shfmt). Never installs anything, never writes unconfirmed. Triggers on "set up linting for this repo", "what tooling is this project missing", "is our formatter setup right", "add a type checker", "why doesn't CI run the linter", "pin our tool versions", or /toolchain-doctor.
-
milanhorvatovic Bundle Oss Repository ConventionsStewards an open-source repo toward and along a top-notch standard. Triggers on audit / set up / harden / level up an OSS repo, "what is this repo missing", "score its health", "add a SECURITY policy / license / CONTRIBUTING", "set up auto-merge", "auto-approve bot PRs", "make CI composable", first-touch onboarding; invoked on /oss-repository-conventions. Covers licensing; security and governance; contribution, conduct, and community health; repo infrastructure and dev setup; code style and testing; CI automation, dependency supply chain, and PR autonomy; releases and documentation. Modes: scan (what's declared), audit (gaps scored by severity), scaffold (drafts missing files, one confirmation each). Reports and proposes; not for commit/PR/branch/release-notes prose (change-narration).
-
pbi-agent Bundle Powerbi AuditUse when auditing a local Power BI PBIP or TMDL project and producing or resuming an evidence-based `AUDIT-REPORT.md` with matching `AUDIT-TODO.md` progress tracking.
-
vigolium Bundle AuditUse when performing repository security analysis that combines application/attack-surface modeling and, depending on mode, advisory intelligence, static analysis, manual exploit-path review, false-positive elimination, PoC construction, and reporting. Applies to knowledge-base, lite, balanced, deep, revisit, and focused audit roles; the active command definition and engine remain the orchestration authority.
-
vigolium Bundle Vuln ReportDraft a single-vulnerability report in GitHub advisory style from an audit finding, bug note, patch diff, PoC, or code review evidence. Use when Codex needs to turn one confirmed security issue into a clean disclosure-ready report with the fixed section set — Summary; Severity, Confidence, Vulnerability Type; Impact; Affected Component; Source to Sink Flow; Vulnerable Code; Proof of concept & Evidence; Preconditions; Remediation — with embedded code snippets, explanatory prose that points to the vulnerable code, and inline GitHub markdown links to source evidence.
-
vigolium Bundle Zeroize AuditDetects missing zeroization of sensitive data in source code and identifies zeroization removed by compiler optimizations, with assembly-level analysis, and control-flow verification. Use for auditing C/C++/Rust code handling secrets, keys, passwords, or other sensitive data.
Audited -
zacharyzhang-ny Skill Code ReviewComprehensive code review with security, performance, and style analysis
-
millionco Skill Security ReviewReview code for security issues in self-hosted and managed Vercel deployments of this Slack bot. Covers secrets, tokens, permissions, logs, user data handling, SSRF, and data minimization. Use when reviewing code for security, auditing data handling, checking for leaked secrets, or verifying privacy compliance.
-
btn101 Bundle Security LayerSecurity Layer
-
stacklok Skill Security Vuln RemediationRemediate security vulnerabilities found by Grype or pnpm audit. Use when a security scan fails, a CVE needs fixing, or you need to analyze, upgrade, override, or ignore a vulnerable dependency.
-
vijpatel7 Bundle Continuous Claudemd UpdatesMaintains CLAUDE.md in sync with codebase changes after commits. Use when (1) A commit has been made and CLAUDE.md needs updating, (2) User explicitly requests CLAUDE.md update or audit, (3) Major refactoring or architectural changes occur, (4) New conventions or patterns are established, (5) Files referenced in CLAUDE.md are deleted/moved. Keeps documentation concise by moving verbose content to docs/ folder with links, removes outdated information, and ensures CLAUDE.md reflects current codebase state.
-
kesslernity Bundle Controls Gap PackReads a requirement, regulation, or policy and the organisation's control descriptions, then produces a DRAFT controls-and-gap pack — the requirement broken into obligations, mapped controls, apparent coverage, gaps, and actions to assess. Never concludes compliance or that a control is effective; control owners and audit assess. Use when the user asks to map a requirement to controls or run a controls gap analysis.
-
m4d3bug Bundle Skill ScannerScan OpenClaw skills for security vulnerabilities before installing them. Use when evaluating a new skill from ClawHub or any third-party source. Detects credential stealers, data exfiltration, malicious URLs, obfuscated code, and supply chain attacks.
-
hector-ha Bundle Skill CleanerCodex/OpenClaw skill audit: live budget, usage, duplicates, compact descriptions.
-
jfrog Skill Jfrog Package Safety And DownloadCheck JFrog Public Catalog and stored packages for a version, interpret catalog security signals, and download through Artifactory (JFrog Platform locations, remote cache, curation-aware package managers, or repo proxy). Use when the user asks whether a package is safe, allowed, curated, or wants to download npm, Maven, PyPI, Go, or similar packages via JFrog. Do NOT use for pure CVE or vulnerability lookups (e.g. "details on CVE-2021-23337") — those are handled by the jfrog skill's Public security domain queries without this workflow.
-
jhd3197 Skill Audit SubprocessScan backend services for subprocess bugs — missing sudo, missing exception handling on distro-specific commands, raw subprocess calls bypassing system utilities, and container/environment assumptions that break in LXC or restricted environments. Reports issues with file, line, and fix.
Audited -
jimmyhoran Skill Funnel TeardownTear down a competitor's (or your own) complete offer — funnel, landing page, lead magnet, upsell path, pricing strategy, emails, and CTAs — then connect the dots into four answers, why people buy, where people drop off, what's missing, and where money is being left on the table. Use when the user wants to analyze a competitor's funnel or offer, shares a competitor's landing page, pricing page, or email sequence and asks what's working, or says things like 'tear down this funnel', 'funnel audit', 'offer teardown', 'why do people buy from them', 'where are they leaving money on the table', 'what can I steal from their funnel', or 'find the gaps in this offer'.
Audited -
justin Bundle
Jww Codex MaintenanceAudit and reduce Codex desktop and CLI local-state bloat without deleting history or editing private app state. Use when Codex feels slow, logs or sessions consume substantial disk space, stale task worktrees accumulate, configuration contains dead project paths, or the user wants a repeatable maintenance report. Default to a read-only audit; perform archival or rotation only when the user explicitly requests cleanup.
-
kasimmj Skill Security AuditRun an OWASP-style security audit on the current diff, the working tree, or a specified path. Flags injection, auth flaws, secrets, insecure deserialization, and misconfigurations.
-
0xelitesystem Skill Code ReviewerRun a structured five-stage code review on a diff, file, or pull request. Use whenever the user wants code reviewed, audited, or checked before merge. Triggers on "review this code", "audit this PR", "code review", "check this diff", "review my changes", or any time the user pastes code and wants quality, performance, or security feedback. Always use this skill rather than ad-hoc commentary when the user asks for a code review, even if they describe the request in their own words.
Audited -
adityavasireddy Bundle DeslopifyEdit, draft, or audit nonfiction prose for named writing patterns while preserving factual meaning and the writer's voice. Use for requests to sharpen, tighten, remove generic phrasing, or make nonfiction sound less AI-written. Do not use for fiction, poetry, screenwriting, code, translation, or internal summaries.
Audited -
editorialos Skill Content StrategistApply strategic content judgment — pillar health assessment, gap identification, opportunity prioritization, and recommendation sequencing. Frame findings in terms of business goals, not content metrics. Content metrics are inputs. Business outcomes are the output. Used by /audit and /calendar.
-
fab2295 Bundle Sap Cap TestTest-only skill for SAP CAP Node.js projects. Its sole purpose is to scaffold and run automated tests using `cds test` (Node.js test runner wrapper) and, when (and only when) explicitly requested by the user, produce coverage with `c8`. The skill writes test files under `test/` (or the project's existing test folder), executes them, and emits two possible report files at the project root: - `CAP-TEST-REPORT.md` — successful run summary (always) - `CAP-TEST-FAILURE.md` — failure report (only if a test fails) Use when the user asks to: - "cria testes", "gera teste para X", "scaffold tests" - "roda os testes", "executa cds test", "run tests" - "testa o serviço X", "cobertura c8" (coverage mode — must be explicit) Strict negatives — this skill NEVER: - edits production code (`srv/**`, `db/**`, `app/**`, `package.json`, `.cdsrc.json`, `mta.yaml`, `xs-security.json`) — it only writes inside the test folder - implements features, refactors, fixes bugs, changes business logic - runs `git add`, `git commit`, `git push
-
faizee-asad Skill Resume OptimizerTailor a resume or CV to a specific job description with ATS keyword audit, truthful bullet rewrites, summary rewrite, and gap notes.
-
scalefreecom Skill Auditing SkillsUse when checking this repository's skills for security or quality issues before sharing them, or remediating findings across skills.
-
xuzhougeng Bundle Inspect Computer ConfigUse when the user asks to inspect, summarize, audit, compare, or troubleshoot this computer's hardware, operating system, CPU, memory, GPU, disk, or local runtime configuration.
-
englandtong Bundle Project Lifecycle NavigatorAudit a project you are unsure about and get a go, narrow, pivot, archive or stop recommendation, without writing code or changing governance state. Use when a non-technical user needs structured project guidance, a project is drifting, existing code needs a read-only audit, a recent delivery needs comparison with its current target, or new requirements may change scope. Typical triggers include 项目做了一半要不要继续, 我是不是该重开一个, 范围蔓延, 想加个新功能, I have too many projects, should I kill this one, 帮我看看这个仓库还能不能救, audit my codebase, is this project over-engineered, 定义一下 MVP, 怎样算做完, 止损, 归档, 这个项目还有价值吗, define MVP scope, scope creep, project drift, startup checklist, go or no-go, portfolio cleanup, and repository health audit. Also use for duplicate-copy detection, missing version control, hardcoded secrets in shipped artifacts, god-module and entrypoint-sprawl findings, and pre-commitment stop-loss rules. Produces bounded recommendations and handoffs without coding, self-authorizing work, changing governance state, or claiming Q
-
flowerf19 Skill Code ReviewerIndependent review of a code change - verify requested behavior, correctness, security, compatibility, minimal scope, and test coverage.
-
djangopeng Skill Github Secret Auditor当用户希望让 OpenClaw 通过 ACP 调度 Claude Code,对 GitHub 仓库进行 API Key、Token、密码、私钥、Webhook URL 等敏感信息泄露巡检、自动修复、验收、推送修复 commit,并通过飞书发送巡检报告时使用。
-
ironlint Bundle Adapter Drift AuditUse when checking whether an IronLint adapter still matches its coding harness's current contract — auditing adapter/harness drift, verifying hook payload shapes, plugin manifest schemas, lifecycle events, or tool names are up to date, or doing periodic adapter maintenance. Takes a harness name (claude-code, codex, pi, opencode) as argument.
-
ironlint Skill Ironlint ReviewReviews ironlint check health from the telemetry log. Use when the user says "review my ironlint checks", "check health", "which ironlint checks are noisy", "find dead ironlint checks", "ironlint review", or asks for an audit of .ironlint.yml.
-
jppuche Skill CalibratePeriodic system calibration - research official sources, audit rules/docs against current best practices, update documentation system, verify changes. Use when: "calibrate", "audit the system", "check our rules", "are we up to date", or every 10-15 sessions proactively.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include unsafe-rust, legado-compose-review, security-layer. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.