Security
Anthropic-Cybersecurity-Skills
753+ structured cybersecurity skills mapped to MITRE ATT&CK. 4k+ stars.
Security
agent-bom discover aws
Discover AWS-hosted AI agent and MCP-relevant assets from the operator's environment, emit canonical agent-bom inventory JSON, and scan it without giving age...
Security
agent-bom discover azure
Discover Azure-hosted AI agent and MCP-relevant assets from the operator's environment, emit canonical agent-bom inventory JSON, and scan it without giving a...
Security
agent-bom discover gcp
Discover GCP-hosted AI agent and MCP-relevant assets from the operator's environment, emit canonical agent-bom inventory JSON, and scan it without giving age...
Security
agent-bom discover snowflake
Discover Snowflake Cortex, Snowpark, notebook, Streamlit, MCP, and AI-observability assets from the operator's environment, emit canonical agent-bom inventor...
Security
agent-bom ingest
Validate and ingest operator-pushed agent-bom inventory JSON from AWS, Azure, GCP, Snowflake, CMDB, or endpoint collectors. Use when a user has canonical inv...
Security
agent-bom runtime
AI runtime security monitoring — context graph analysis, runtime audit log correlation with CVE findings, and vulnerability analytics queries. Use when the u...
Security
agent-bom vulnerability intel
Use agent-bom to check package, SBOM, inventory, and agent dependency exposure against OSV, GitHub Security Advisories, NVD, EPSS, and CISA KEV with explicit...
Security
ClawSecCheck — OpenClaw Security Self-Audit
Free, local security self-audit for your own OpenClaw agent. Reads your OpenClaw config, bootstrap files, log files, agent session logs, and installed skills...
Security
eKYC Suite
eKYC Suite is the ClawHub KYC identity verification Skill, KYC onboarding Skill, and remote KYC onboarding Skill for AI agents that need face liveness detect...
Security
Vmware Harden
Use this skill whenever the user needs to perform VMware compliance auditing, baseline checking, or drift detection on vSphere/ESXi/NSX environments. Directl...
Security
Vmware Policy
Unified audit logging, policy enforcement, and input sanitization for the entire VMware MCP skill family. Use when querying audit logs, managing policy rules...
Security
agent-bom compliance
AI compliance and policy engine — evaluate scan results against OWASP, NIST, SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks. Generate...
Security
agent-bom registry
MCP server security registry and trust assessment — look up servers in the 1013-entry server security metadata registry, run pre-install marketplace checks,...
Security
agent-bom scan
Open security scanner for agentic infrastructure — agents, MCP, packages, blast radius, runtime, and trust for package CVEs (OSV, NVD, EPSS, KEV), container...
Security
Vmware Nsx Security
Use this skill whenever the user needs to manage VMware NSX security — distributed firewall (DFW) policies, security groups, microsegmentation, and IDS/IPS....
Security
hush
Use whenever an agent needs to STORE, GENERATE, or USE a secret (API token, key, signing value, password) without ever exposing the plaintext. Replaces the "go set this env var / p…
Security
osint-investigator
OSINT Investigator v2.1 — comprehensive open-source intelligence skill. Triggers on: OSINT, recon, digital footprint, dorking, social media investigation, username lookups, email t…
Security
misteye-security-check
This is the MistEye security gate skill. It is triggered by pre-installation risk checks (including Skill/MCP dependency manifests), pre-access security checks for domains or URLs,…
Security
defi-onchain-analytics
Use when profiling wallets, analyzing protocols or pools, inspecting token metrics, evaluating DEX liquidity or LP/vault performance, reading smart contract state, resolving proxy …
Security
solana-auditor
Audit and research Solana smart contracts for security vulnerabilities and exploits. Use this skill whenever the user asks to audit, review, analyze, or security-test any Solana pr…
Security
wp-hardened-contact-form
Install a production-hardened contact form into a WordPress / Sage / Acorn theme. Ships a 9-layer defense stack (CSRF nonce, honeypot, timing, interaction count, gibberish heuristi…
Security
fivem-audit
Performs comprehensive FiveM resource security, performance, and compatibility audits. Detects backdoors, RATs, SQL injection, event exploitation, NUI vulnerabilities, supply chain…
Security
wp-malware-remediation
Analizar, detectar y limpiar malware PHP en sitios WordPress alojados en servidores Linux (CWP/cPanel). Cubre el ciclo completo: triage, backup, escaneo heurístico, clasificación d…
Security
skills-keys
Manage API keys for the runner's --execute layer. CRUD on ~/.skills.env (chmod 600): list / add / update / remove / enable / disable gate flags / verify (ping vendor APIs) / export…
Security
ctfd-api
Work with any CTFd-platform CTF via its REST API (api/v1) as a player — list and read challenges, download attached files, submit flags (with correct handling of every attempt stat…
Security
amlclaw
AI-powered crypto AML compliance toolkit. Screens blockchain addresses against 40+ international regulations, generates compliance policies, and creates machine-readable detection …
Security
deepsafe-scan
Preflight security scanner for AI coding agents — scans deployment config, skills/MCP servers, memory/sessions, and AI agent config files (hooks injection) for secrets, PII, prompt…
Security
1claw-hermes
TypeScript integration bringing [1Claw](https://1claw.xyz) to Hermes — MCP-based secret fetching from an HSM-backed vault, a [Shroud](https://docs.1claw.xyz/docs/guides/shroud) TEE…
Security
dsv-forensische-erstsicherung
Coordinates forensic first-response after a data protection incident among client, internal IT, external forensic expert, and law firm. Covers forensic selection and engagement, ma…
Security
truthfinder
Always-active web search safety skill. Classifies every website into SAFE, CAUTION, RISKY, or BLOCKED before reading or citing it. Reads and evaluates real user reviews and feedbac…
Security
qa
Use for paranoid, language-agnostic architectural code review — applies SOLID, DRY/KISS/YAGNI, decoupling, OWASP/NIST security, and quantitative complexity thresholds (cyclomatic >…
Security
symbiont
AI-native agent runtime with typestate-enforced ORGA reasoning loop, Cedar policy authorization, CommunicationPolicyGate for inter-agent governance, ToolClad declarative tool contr…
Security
skill-security-reviewer
Security review and threat analysis for agent skills. Use when reviewing, auditing, or validating skills for security issues including prompt injection, code execution risks, data …
Security
cyber-risk-modeling
Quantify cyber risk using FAIR methodology with Monte Carlo simulation, assess control effectiveness against NIST CSF/CIS/ISO 27001 frameworks, evaluate risk appetite alignment, an…
Security
salesforce-apex-quality
Apex code quality guardrails for Salesforce development. Enforces bulk-safety rules (no SOQL/DML in loops), sharing model requirements, CRUD/FLS security, SOQL injection prevention…
Security
audit-trail-protokoll
Maintains an immutable audit trail logging every review run, prompt change, reviewer sign-off, cache hit, and hash verification. Records timestamp, action, responsible party, cube …
Security
cyber-incident-response-72h
Structured immediate response for active cyber incidents — hacker attacks, ransomware, data exfiltration, insider threats. Phase 1: immediate containment, network isolation, forens…
Security
ovhcloud-live-kms-key-destruction-guard
Gate and audit OVHcloud KMS key version destruction requests by enforcing five mandatory checks: confirmed key ID and KMS service URN, named approving identity, usage audit confirm…
Security
forter-agentic-readiness-audit
Audit a website against the Forter Agentic Readiness Guide. Loads the 25 weighted rubrics in `audit/`, probes the target site (and optional source code), scores each guideline Pass…
Security
hack-review
Performs a scoped, coverage-led review of a working tree, staged diff, commit range, branch diff, PR, or suspicious implementation to identify hack-like risks such as impossible-st…
Security
integration-auth0
Connect Auth0 (identity + access management — users, roles, apps, actions, logs, org management) to a self-hosted Hermes Agent over SSH via the official auth0/auth0-mcp-server stdi…
Security
gcp-live-kms-key-destruction-guard
Gate Cloud KMS key version destruction and key ring deletion against a complete CMEK dependency audit. All Cloud SQL, GCS, BigQuery, Compute Engine disk, and Secret Manager resourc…
Security
cilium-network-policy-review
Use this skill for Cilium network policy review across Kubernetes NetworkPolicy, CiliumNetworkPolicy, and CiliumClusterwideNetworkPolicy formats, including L7 policy via Envoy, Clu…
Security
prism-scanner
Security scanner for AI Agent skills, plugins, and MCP servers. Use when: user asks to scan a skill, check if a plugin is safe, vet an MCP server, review skill security, detect mal…
Security
hipaa-review
Performs a HIPAA Security Rule compliance review across all Administrative, Physical, and Technical Safeguards in 45 CFR Part 164, Subpart C. Auto-invoked for healthcare data secur…
Security
ciphertext-recovery
ARM64 trace ciphertext recovery methodology. Use when given an ARM64 execution trace file and asked to reverse-engineer encryption, signature, or encoding algorithms from ciphertex…
Security
pre-exec-check
Safety check before executing destructive or irreversible commands. Catches dangerous shell commands, risky git operations, secret exposure, and high-blast-radius actions before th…
Security
security-focused-review
Scoped security review establishing assets, trust boundaries, and attacker prerequisites with evidence-backed findings across auth, authorization, validation, injection, path handl…
Security
iota-agent-mcp
IOTA blockchain MCP server providing wallet management with human-in-the-loop signing, Move smart contract build/test/publish, and on-chain queries via JSON-RPC and GraphQL. Use wh…
Security
dsv-beweissicherung
Structures evidence preservation after a data-protection incident to keep materials admissible in administrative, criminal, or civil proceedings. Covers chain of custody, secure lo…
Security
threat-model
Analyzes systems and applications to produce structured threat model reports using STRIDE, OWASP Top 10, OWASP LLM Top 10, or MITRE ATT&CK frameworks. Use for traditional web appli…
Security
supabase-security
Use when auditing or hardening a Supabase project's security posture. Triggers: scan/audit Supabase, RLS verification, find leaky tables, check anon grants, review SECURITY DEFINER…
Security
gcp-live-bigquery-dataset-deletion-guard
Gate BigQuery dataset deletion, table truncation, and authorized view changes against a full downstream dependency audit and export confirmation. Dataset deletion is immediate and …
Security
data-flow-review
Expert review pass examining data-flow, state ownership, lifetime, and boundary topology across every non-trivial entity—flagging ownership mismatches, incorrect dependency directi…
Security
auditing-skills
Scans AI agent skill directories for dangerous bash patterns, prompt injection, supply chain risks, and SKILL.md structure violations. Use when reviewing, validating, or security-a…
Security
dependa-audit
Supply-chain audit of a Dependabot PR. For every dependency the PR bumps, diff the current vs target version (install hooks, new deps, publisher/provenance, network endpoints, code…
Security
defi-risk-analysis
Analyze a DeFi protocol's risk profile across smart contract, off-chain, and track-record dimensions. Use when the user wants a risk analysis of a DeFi project, to check protocol s…
Security
permission-set-groups-and-muting
Use when designing or reviewing permission-set-group architecture, including profile minimization, group composition, muting strategy, and migration from profile-heavy models. Trig…
Security
sg-deceptive-reachability-auditor
Audits AWS security-group fleets for hidden multi-hop lateral-movement paths by building a directed reachability graph from SG references, internet edges, and transitive closure. R…
Showing the top 60 of 9,239. See the full list →