Engineering
abvx-agent-skills
Auditable cross-platform coding-agent skillpack for smaller diffs, evidence-led debugging, token control, browser verification, and reviewable `SKILL.md` workflows with static secu…
Security
Anthropic-Cybersecurity-Skills
753+ structured cybersecurity skills mapped to MITRE ATT&CK. 4k+ stars.
Security
agent-bom discover aws
Discover AWS-hosted AI agent and MCP-relevant assets from the operator's environment, emit canonical agent-bom inventory JSON, and scan it without giving age...
Security
agent-bom discover azure
Discover Azure-hosted AI agent and MCP-relevant assets from the operator's environment, emit canonical agent-bom inventory JSON, and scan it without giving a...
Security
agent-bom discover gcp
Discover GCP-hosted AI agent and MCP-relevant assets from the operator's environment, emit canonical agent-bom inventory JSON, and scan it without giving age...
Security
agent-bom discover snowflake
Discover Snowflake Cortex, Snowpark, notebook, Streamlit, MCP, and AI-observability assets from the operator's environment, emit canonical agent-bom inventor...
Security
agent-bom ingest
Validate and ingest operator-pushed agent-bom inventory JSON from AWS, Azure, GCP, Snowflake, CMDB, or endpoint collectors. Use when a user has canonical inv...
Security
agent-bom runtime
AI runtime security monitoring — context graph analysis, runtime audit log correlation with CVE findings, and vulnerability analytics queries. Use when the u...
Security
agent-bom vulnerability intel
Use agent-bom to check package, SBOM, inventory, and agent dependency exposure against OSV, GitHub Security Advisories, NVD, EPSS, and CISA KEV with explicit...
Security
ClawSecCheck — OpenClaw Security Self-Audit
Free, local security self-audit for your own OpenClaw agent. Reads your OpenClaw config, bootstrap files, log files, agent session logs, and installed skills...
Security
Vmware Harden
Use this skill whenever the user needs to perform VMware compliance auditing, baseline checking, or drift detection on vSphere/ESXi/NSX environments. Directl...
Security
Vmware Policy
Unified audit logging, policy enforcement, and input sanitization for the entire VMware MCP skill family. Use when querying audit logs, managing policy rules...
Security
agent-bom compliance
AI compliance and policy engine — evaluate scan results against OWASP, NIST, SOC 2, ISO 27001, CMMC, EU AI Act, AISVS v1.0, and related frameworks. Generate...
Security
agent-bom registry
MCP server security registry and trust assessment — look up servers in the 1013-entry server security metadata registry, run pre-install marketplace checks,...
Security
agent-bom scan
Open security scanner for agentic infrastructure — agents, MCP, packages, blast radius, runtime, and trust for package CVEs (OSV, NVD, EPSS, KEV), container...
Security
Vmware Nsx Security
Use this skill whenever the user needs to manage VMware NSX security — distributed firewall (DFW) policies, security groups, microsegmentation, and IDS/IPS....
Security
hush
Use whenever an agent needs to STORE, GENERATE, or USE a secret (API token, key, signing value, password) without ever exposing the plaintext. Replaces the "go set this env var / p…
Security
misteye-security-check
This is the MistEye security gate skill. It is triggered by pre-installation risk checks (including Skill/MCP dependency manifests), pre-access security checks for domains or URLs,…
Security
defi-onchain-analytics
Use when profiling wallets, analyzing protocols or pools, inspecting token metrics, evaluating DEX liquidity or LP/vault performance, reading smart contract state, resolving proxy …
Design
ui-ergonomics
Use when auditing whether a view/screen is correctly built against usability & ergonomic dimensions. Checks a UI against 18 usability dimensions — prompting, grouping by location/f…
Engineering
frontend-shift-left-audit
Audit frontend code quality - linting, type safety, security, accessibility, testing, and CI/CD coverage. Scans a repo's static analysis tools (ESLint, Biome, TypeScript), test run…
Security
solana-auditor
Audit and research Solana smart contracts for security vulnerabilities and exploits. Use this skill whenever the user asks to audit, review, analyze, or security-test any Solana pr…
Security
wp-hardened-contact-form
Install a production-hardened contact form into a WordPress / Sage / Acorn theme. Ships a 9-layer defense stack (CSRF nonce, honeypot, timing, interaction count, gibberish heuristi…
Security
fivem-audit
Performs comprehensive FiveM resource security, performance, and compatibility audits. Detects backdoors, RATs, SQL injection, event exploitation, NUI vulnerabilities, supply chain…
Security
wp-malware-remediation
Analizar, detectar y limpiar malware PHP en sitios WordPress alojados en servidores Linux (CWP/cPanel). Cubre el ciclo completo: triage, backup, escaneo heurístico, clasificación d…
Security
deepsafe-scan
Preflight security scanner for AI coding agents — scans deployment config, skills/MCP servers, memory/sessions, and AI agent config files (hooks injection) for secrets, PII, prompt…
Security
1claw-hermes
TypeScript integration bringing [1Claw](https://1claw.xyz) to Hermes — MCP-based secret fetching from an HSM-backed vault, a [Shroud](https://docs.1claw.xyz/docs/guides/shroud) TEE…
Security
truthfinder
Always-active web search safety skill. Classifies every website into SAFE, CAUTION, RISKY, or BLOCKED before reading or citing it. Reads and evaluates real user reviews and feedbac…
Security
qa
Use for paranoid, language-agnostic architectural code review — applies SOLID, DRY/KISS/YAGNI, decoupling, OWASP/NIST security, and quantitative complexity thresholds (cyclomatic >…
Security
symbiont
AI-native agent runtime with typestate-enforced ORGA reasoning loop, Cedar policy authorization, CommunicationPolicyGate for inter-agent governance, ToolClad declarative tool contr…
Security
skill-security-reviewer
Security review and threat analysis for agent skills. Use when reviewing, auditing, or validating skills for security issues including prompt injection, code execution risks, data …
Security
cyber-risk-modeling
Quantify cyber risk using FAIR methodology with Monte Carlo simulation, assess control effectiveness against NIST CSF/CIS/ISO 27001 frameworks, evaluate risk appetite alignment, an…
Security
salesforce-apex-quality
Apex code quality guardrails for Salesforce development. Enforces bulk-safety rules (no SOQL/DML in loops), sharing model requirements, CRUD/FLS security, SOQL injection prevention…
Security
cyber-incident-response-72h
Structured immediate response for active cyber incidents — hacker attacks, ransomware, data exfiltration, insider threats. Phase 1: immediate containment, network isolation, forens…
Security
ovhcloud-live-kms-key-destruction-guard
Gate and audit OVHcloud KMS key version destruction requests by enforcing five mandatory checks: confirmed key ID and KMS service URN, named approving identity, usage audit confirm…
Security
forter-agentic-readiness-audit
Audit a website against the Forter Agentic Readiness Guide. Loads the 25 weighted rubrics in `audit/`, probes the target site (and optional source code), scores each guideline Pass…
DevOps
ssh-command-screenshot
Run SSH commands in Windows Terminal and capture per-command screenshot evidence into a new folder. Use early whenever a task involves Linux/Unix system inspection, troubleshooting…
Security
hack-review
Performs a scoped, coverage-led review of a working tree, staged diff, commit range, branch diff, PR, or suspicious implementation to identify hack-like risks such as impossible-st…
Business
due-diligence-checklist
Drafts due diligence checklists for U.S. corporate transactions (M&A, asset purchases, investments, JVs, restructurings). Covers corporate structure, financials, tax, contracts, IP…
Security
gcp-live-kms-key-destruction-guard
Gate Cloud KMS key version destruction and key ring deletion against a complete CMEK dependency audit. All Cloud SQL, GCS, BigQuery, Compute Engine disk, and Secret Manager resourc…
Security
cilium-network-policy-review
Use this skill for Cilium network policy review across Kubernetes NetworkPolicy, CiliumNetworkPolicy, and CiliumClusterwideNetworkPolicy formats, including L7 policy via Envoy, Clu…
Security
prism-scanner
Security scanner for AI Agent skills, plugins, and MCP servers. Use when: user asks to scan a skill, check if a plugin is safe, vet an MCP server, review skill security, detect mal…
Security
hipaa-review
Performs a HIPAA Security Rule compliance review across all Administrative, Physical, and Technical Safeguards in 45 CFR Part 164, Subpart C. Auto-invoked for healthcare data secur…
Business
sap-treasury-cash-risk-review
Reviews SAP Treasury and Risk Management (TRM) and Cash Management setups, covering cash positioning, liquidity forecasting, bank account governance, in-house cash design, hedge co…
Security
security-focused-review
Scoped security review establishing assets, trust boundaries, and attacker prerequisites with evidence-backed findings across auth, authorization, validation, injection, path handl…
Security
dsv-beweissicherung
Structures evidence preservation after a data-protection incident to keep materials admissible in administrative, criminal, or civil proceedings. Covers chain of custody, secure lo…
Engineering
pg-migration
PostgreSQL schema migration safety reviewer and DDL generator. Use for writing, reviewing, or planning schema changes including ALTER TABLE, index operations, constraint modificati…
General
ki-verordnung-compliance
Performs EU AI Act compliance checks covering scope, risk classification, prohibited practices, high-risk systems, transparency duties, GPAI models, conformity declarations, CE mar…
Security
threat-model
Analyzes systems and applications to produce structured threat model reports using STRIDE, OWASP Top 10, OWASP LLM Top 10, or MITRE ATT&CK frameworks. Use for traditional web appli…
Business
event-staffing-compliance
Assess worker-classification and compliance risk for temporary event staffing in the US and Canada. Use when a user asks about W-2 vs 1099 event workers, misclassification penaltie…
Engineering
project-agentification
Assess repository agent-readiness, harden against failure modes, scaffold AGENTS.md / SKILL.md / MCP servers / hooks / specs from observed failures, and diagnose why coding agents …
Security
supabase-security
Use when auditing or hardening a Supabase project's security posture. Triggers: scan/audit Supabase, RLS verification, find leaky tables, check anon grants, review SECURITY DEFINER…
Security
gcp-live-bigquery-dataset-deletion-guard
Gate BigQuery dataset deletion, table truncation, and authorized view changes against a full downstream dependency audit and export confirmation. Dataset deletion is immediate and …
Business
sap-manufacturing-execution-risk-review
Reviews SAP manufacturing execution risks in PP, S/4HANA, and DM/MES—covering production order governance, capacity controls, MRP exceptions, shop-floor integration, quality manage…
DevOps
vercel-incident-toolkit
Vercel account hardening and incident response. Use when the user mentions a Vercel breach/incident, asks to audit or rotate Vercel environment variables, mark env vars sensitive, …
Security
data-flow-review
Expert review pass examining data-flow, state ownership, lifetime, and boundary topology across every non-trivial entity—flagging ownership mismatches, incorrect dependency directi…
Business
gcp-live-cost-budget-action-guard
Gate Cloud Billing budget threshold changes, committed-use discount (CUD) purchases, and quota increase requests with explicit financial-authority approval. CUD contracts are 1-3 y…
Business
coi-compliance-review
Reviews CRE insurance certificates (ACORD 25) and endorsements against Access Agreement insurance requirements, producing a pass/fail compliance determination with broker-ready def…
Security
auditing-skills
Scans AI agent skill directories for dangerous bash patterns, prompt injection, supply chain risks, and SKILL.md structure violations. Use when reviewing, validating, or security-a…
Security
dependa-audit
Supply-chain audit of a Dependabot PR. For every dependency the PR bumps, diff the current vs target version (install hooks, new deps, publisher/provenance, network endpoints, code…
Showing the top 60 of 9,378. See the full list →