Security
DashClaw
Approval and policy layer for agents: intercepts risky actions before they run and blocks or escalates them by rule. MIT.
Security
Anthropic-Cybersecurity-Skills
753+ structured cybersecurity skills mapped to MITRE ATT&CK. 31k★.
Security
keelwright
Engine for vibe-coders and loop-coders who ship AI-generated code they can't read line by line. Covers 28 known failure modes: SQL injection, hardcoded secrets, hallucinated packag…
Security
Stranger Recognition Skill | 陌生人识别技能
Identifies strangers appearing in surveillance areas through facial comparison; supports video stream and image detection, suitable for stranger warnings in residential communities…
Security
x0x
Secure computer-to-computer networking for AI agents — gossip broadcast, direct messaging, CRDTs, group encryption. Post-quantum encrypted, NAT-traversing. Everything you need to b…
Security
supply-chain-advisory
Audits dependency supply chains for bad versions, lockfile drift, and artifact integrity
Security
writing-rules
Creates behavioral rules in markdown to block dangerous commands or restrict AI behavior
Security
content-sanitization
Provides sanitization guidelines for external content in skills and hooks
Security
hooks-eval
Evaluate hook security, performance, and SDK compliance. Use for audits
Security
risk-classification
Classifies agent tasks into 4 risk tiers (GREEN/YELLOW/RED/CRITICAL)
Security
authentication-patterns
Provides auth patterns for API keys, OAuth, and token management
Security
osint-investigator
OSINT Investigator v2.1 — comprehensive open-source intelligence skill. Triggers on: OSINT, recon, digital footprint, dorking, social media investigation, username lookups, email t…
Security
code-audit
Perform a structured audit of a codebase covering security, code quality, performance, dependencies, architecture, and testing hygiene, then produce a prioritized findings report. …
Security
misteye-security-check
This is the MistEye security gate skill. It is triggered by pre-installation risk checks (including Skill/MCP dependency manifests), pre-access security checks for domains or URLs,…
Security
defi-onchain-analytics
Use when profiling wallets, analyzing protocols or pools, inspecting token metrics, evaluating DEX liquidity or LP/vault performance, reading smart contract state, resolving proxy …
Security
solana-auditor
Audit and research Solana smart contracts for security vulnerabilities and exploits. Use this skill whenever the user asks to audit, review, analyze, or security-test any Solana pr…
Security
wp-hardened-contact-form
Install a production-hardened contact form into a WordPress / Sage / Acorn theme. Ships a 9-layer defense stack (CSRF nonce, honeypot, timing, interaction count, gibberish heuristi…
Security
fivem-audit
Performs comprehensive FiveM resource security, performance, and compatibility audits. Detects backdoors, RATs, SQL injection, event exploitation, NUI vulnerabilities, supply chain…
Security
wp-malware-remediation
Analizar, detectar y limpiar malware PHP en sitios WordPress alojados en servidores Linux (CWP/cPanel). Cubre el ciclo completo: triage, backup, escaneo heurístico, clasificación d…
Security
global-agent-guardrails
One shared denylist of catastrophic shell commands (rm -rf on / or ~, dd/mkfs, sudo rm, fork bombs, curl|sh, git push --force, gh repo delete) enforced as a PreToolUse/pre-exec gua…
Security
skills-keys
Manage API keys for the runner's --execute layer. CRUD on ~/.skills.env (chmod 600): list / add / update / remove / enable / disable gate flags / verify (ping vendor APIs) / export…
Security
ctfd-api
Work with any CTFd-platform CTF via its REST API (api/v1) as a player — list and read challenges, download attached files, submit flags (with correct handling of every attempt stat…
Security
amlclaw
AI-powered crypto AML compliance toolkit. Screens blockchain addresses against 40+ international regulations, generates compliance policies, and creates machine-readable detection …
Security
deepsafe-scan
Preflight security scanner for AI coding agents — scans deployment config, skills/MCP servers, memory/sessions, and AI agent config files (hooks injection) for secrets, PII, prompt…
Security
Alepha188838884/context-firewall
Local proxy that collapses N downstream MCP servers into 4 meta-tools with progressive tool discovery (measured: 122 tools → 4, ~28.6K tokens of definitions saved), compresses larg…
Security
1claw-hermes
TypeScript integration bringing [1Claw](https://1claw.xyz) to Hermes — MCP-based secret fetching from an HSM-backed vault, a [Shroud](https://docs.1claw.xyz/docs/guides/shroud) TEE…
Security
dsv-forensische-erstsicherung
Coordinates forensic first-response after a data protection incident among client, internal IT, external forensic expert, and law firm. Covers forensic selection and engagement, ma…
Security
truthfinder
Always-active web search safety skill. Classifies every website into SAFE, CAUTION, RISKY, or BLOCKED before reading or citing it. Reads and evaluates real user reviews and feedbac…
Security
qa
Use for paranoid, language-agnostic architectural code review — applies SOLID, DRY/KISS/YAGNI, decoupling, OWASP/NIST security, and quantitative complexity thresholds (cyclomatic >…
Security
symbiont
AI-native agent runtime with typestate-enforced ORGA reasoning loop, Cedar policy authorization, CommunicationPolicyGate for inter-agent governance, ToolClad declarative tool contr…
Security
skill-security-reviewer
Security review and threat analysis for agent skills. Use when reviewing, auditing, or validating skills for security issues including prompt injection, code execution risks, data …
Security
cyber-risk-modeling
Quantify cyber risk using FAIR methodology with Monte Carlo simulation, assess control effectiveness against NIST CSF/CIS/ISO 27001 frameworks, evaluate risk appetite alignment, an…
Security
trafficwatch-ids-review
Skill específica para revisar, implementar, probar y documentar TrafficWatch IDS, un sistema académico de detección de intrusos con Python, Flask, Scapy, dashboard web, respuesta a…
Security
salesforce-apex-quality
Apex code quality guardrails for Salesforce development. Enforces bulk-safety rules (no SOQL/DML in loops), sharing model requirements, CRUD/FLS security, SOQL injection prevention…
Security
audit-trail-protokoll
Maintains an immutable audit trail logging every review run, prompt change, reviewer sign-off, cache hit, and hash verification. Records timestamp, action, responsible party, cube …
Security
workflow-security-report
Triage a GitHub code-scanning (CodeQL) finding and generate an immutable Markdown report with an index entry, recommending remediation or dismissal, pinning every code reference to…
Security
cyber-incident-response-72h
Structured immediate response for active cyber incidents — hacker attacks, ransomware, data exfiltration, insider threats. Phase 1: immediate containment, network isolation, forens…
Security
auditclaw-grc
GRC automation suite covering 13 frameworks (SOC 2, ISO 27001, HIPAA, GDPR, NIST CSF, PCI DSS, CMMC, FedRAMP, others). Manages controls, evidence, risks, policies, vendors, inciden…
Security
ovhcloud-live-kms-key-destruction-guard
Gate and audit OVHcloud KMS key version destruction requests by enforcing five mandatory checks: confirmed key ID and KMS service URN, named approving identity, usage audit confirm…
Security
forter-agentic-readiness-audit
Audit a website against the Forter Agentic Readiness Guide. Loads the 25 weighted rubrics in `audit/`, probes the target site (and optional source code), scores each guideline Pass…
Security
hack-review
Performs a scoped, coverage-led review of a working tree, staged diff, commit range, branch diff, PR, or suspicious implementation to identify hack-like risks such as impossible-st…
Security
integration-auth0
Connect Auth0 (identity + access management — users, roles, apps, actions, logs, org management) to a self-hosted Hermes Agent over SSH via the official auth0/auth0-mcp-server stdi…
Security
gcp-live-kms-key-destruction-guard
Gate Cloud KMS key version destruction and key ring deletion against a complete CMEK dependency audit. All Cloud SQL, GCS, BigQuery, Compute Engine disk, and Secret Manager resourc…
Security
cilium-network-policy-review
Use this skill for Cilium network policy review across Kubernetes NetworkPolicy, CiliumNetworkPolicy, and CiliumClusterwideNetworkPolicy formats, including L7 policy via Envoy, Clu…
Security
risk-control
Manages hazard and risk records for regulated projects via a single normalized YAML file (docs/.index/risk-file.yaml) with hazard IDs, risk estimates, controls, verification links,…
Security
hipaa-review
Performs a HIPAA Security Rule compliance review across all Administrative, Physical, and Technical Safeguards in 45 CFR Part 164, Subpart C. Auto-invoked for healthcare data secur…
Security
ciphertext-recovery
ARM64 trace ciphertext recovery methodology. Use when given an ARM64 execution trace file and asked to reverse-engineer encryption, signature, or encoding algorithms from ciphertex…
Security
pre-exec-check
Safety check before executing destructive or irreversible commands. Catches dangerous shell commands, risky git operations, secret exposure, and high-blast-radius actions before th…
Security
security-focused-review
Scoped security review establishing assets, trust boundaries, and attacker prerequisites with evidence-backed findings across auth, authorization, validation, injection, path handl…
Security
incident-materiality
Records cybersecurity incident materiality determinations across six factors—financial, operational, data, regulatory, reputational, and series assessment—capturing rationale, deci…
Security
iota-agent-mcp
IOTA blockchain MCP server providing wallet management with human-in-the-loop signing, Move smart contract build/test/publish, and on-chain queries via JSON-RPC and GraphQL. Use wh…
Security
dsv-beweissicherung
Structures evidence preservation after a data-protection incident to keep materials admissible in administrative, criminal, or civil proceedings. Covers chain of custody, secure lo…
Security
threat-model
Analyzes systems and applications to produce structured threat model reports using STRIDE, OWASP Top 10, OWASP LLM Top 10, or MITRE ATT&CK frameworks. Use for traditional web appli…
Security
supabase-security
Use when auditing or hardening a Supabase project's security posture. Triggers: scan/audit Supabase, RLS verification, find leaky tables, check anon grants, review SECURITY DEFINER…
Security
gcp-live-bigquery-dataset-deletion-guard
Gate BigQuery dataset deletion, table truncation, and authorized view changes against a full downstream dependency audit and export confirmation. Dataset deletion is immediate and …
Security
Invisible Unicode Injection Scan 不可視 Unicode コード注入検出
Detects invisible Unicode characters (tag characters, variation selectors, zero-width marks, bidi controls, anomalous whitespace) injected into source code diffs. Uses deterministi…
Security
data-flow-review
Expert review pass examining data-flow, state ownership, lifetime, and boundary topology across every non-trivial entity—flagging ownership mismatches, incorrect dependency directi…
Security
auditing-skills
Scans AI agent skill directories for dangerous bash patterns, prompt injection, supply chain risks, and SKILL.md structure violations. Use when reviewing, validating, or security-a…
Security
dependa-audit
Supply-chain audit of a Dependabot PR. For every dependency the PR bumps, diff the current vs target version (install hooks, new deps, publisher/provenance, network endpoints, code…
Security
mcp-server-vet
Read-only safety inspection of a third-party MCP server before it is added to a config or trusted. Analyzes declared tools, schemas, scopes, transport, and secret surface, compares…
Showing the top 60 of 10,889. See the full list →