Engineering
abvx-agent-skills
Auditable cross-platform coding-agent skillpack for smaller diffs, evidence-led debugging, token control, browser verification, and reviewable `SKILL.md` workflows with static secu…
Security
DashClaw
Approval and policy layer for agents: intercepts risky actions before they run and blocks or escalates them by rule. MIT.
Security
Anthropic-Cybersecurity-Skills
753+ structured cybersecurity skills mapped to MITRE ATT&CK. 31k★.
Security
keelwright
Engine for vibe-coders and loop-coders who ship AI-generated code they can't read line by line. Covers 28 known failure modes: SQL injection, hardcoded secrets, hallucinated packag…
Security
Stranger Recognition Skill | 陌生人识别技能
Identifies strangers appearing in surveillance areas through facial comparison; supports video stream and image detection, suitable for stranger warnings in residential communities…
Security
supply-chain-advisory
Audits dependency supply chains for bad versions, lockfile drift, and artifact integrity
Engineering
tiered-audit
Runs a three-tier codebase audit (git history, targeted scans, full review) with gating
Engineering
rust-review
Audits Rust code for unsafe blocks, ownership issues, and Cargo dependency risks
Engineering
unified-review
Orchestrates multi-domain review (code, arch, tests, security) in a single pass
Security
content-sanitization
Provides sanitization guidelines for external content in skills and hooks
Security
hooks-eval
Evaluate hook security, performance, and SDK compliance. Use for audits
Security
risk-classification
Classifies agent tasks into 4 risk tiers (GREEN/YELLOW/RED/CRITICAL)
Security
code-audit
Perform a structured audit of a codebase covering security, code quality, performance, dependencies, architecture, and testing hygiene, then produce a prioritized findings report. …
Security
misteye-security-check
This is the MistEye security gate skill. It is triggered by pre-installation risk checks (including Skill/MCP dependency manifests), pre-access security checks for domains or URLs,…
Security
defi-onchain-analytics
Use when profiling wallets, analyzing protocols or pools, inspecting token metrics, evaluating DEX liquidity or LP/vault performance, reading smart contract state, resolving proxy …
Design
ui-ergonomics
Use when auditing whether a view/screen is correctly built against usability & ergonomic dimensions. Checks a UI against 18 usability dimensions — prompting, grouping by location/f…
Engineering
frontend-shift-left-audit
Audit frontend code quality - linting, type safety, security, accessibility, testing, and CI/CD coverage. Scans a repo's static analysis tools (ESLint, Biome, TypeScript), test run…
Security
solana-auditor
Audit and research Solana smart contracts for security vulnerabilities and exploits. Use this skill whenever the user asks to audit, review, analyze, or security-test any Solana pr…
General
ecm-qc-disclosure-review
Independent legal review for securities disclosure documents. When given a prospectus, major-asset restructuring report, equity-change report, acquisition report, listing notice, o…
Security
wp-hardened-contact-form
Install a production-hardened contact form into a WordPress / Sage / Acorn theme. Ships a 9-layer defense stack (CSRF nonce, honeypot, timing, interaction count, gibberish heuristi…
Security
fivem-audit
Performs comprehensive FiveM resource security, performance, and compatibility audits. Detects backdoors, RATs, SQL injection, event exploitation, NUI vulnerabilities, supply chain…
Security
wp-malware-remediation
Analizar, detectar y limpiar malware PHP en sitios WordPress alojados en servidores Linux (CWP/cPanel). Cubre el ciclo completo: triage, backup, escaneo heurístico, clasificación d…
Security
global-agent-guardrails
One shared denylist of catastrophic shell commands (rm -rf on / or ~, dd/mkfs, sudo rm, fork bombs, curl|sh, git push --force, gh repo delete) enforced as a PreToolUse/pre-exec gua…
Security
deepsafe-scan
Preflight security scanner for AI coding agents — scans deployment config, skills/MCP servers, memory/sessions, and AI agent config files (hooks injection) for secrets, PII, prompt…
Security
Alepha188838884/context-firewall
Local proxy that collapses N downstream MCP servers into 4 meta-tools with progressive tool discovery (measured: 122 tools → 4, ~28.6K tokens of definitions saved), compresses larg…
Security
1claw-hermes
TypeScript integration bringing [1Claw](https://1claw.xyz) to Hermes — MCP-based secret fetching from an HSM-backed vault, a [Shroud](https://docs.1claw.xyz/docs/guides/shroud) TEE…
Security
truthfinder
Always-active web search safety skill. Classifies every website into SAFE, CAUTION, RISKY, or BLOCKED before reading or citing it. Reads and evaluates real user reviews and feedbac…
Security
qa
Use for paranoid, language-agnostic architectural code review — applies SOLID, DRY/KISS/YAGNI, decoupling, OWASP/NIST security, and quantitative complexity thresholds (cyclomatic >…
Security
symbiont
AI-native agent runtime with typestate-enforced ORGA reasoning loop, Cedar policy authorization, CommunicationPolicyGate for inter-agent governance, ToolClad declarative tool contr…
Security
skill-security-reviewer
Security review and threat analysis for agent skills. Use when reviewing, auditing, or validating skills for security issues including prompt injection, code execution risks, data …
Security
cyber-risk-modeling
Quantify cyber risk using FAIR methodology with Monte Carlo simulation, assess control effectiveness against NIST CSF/CIS/ISO 27001 frameworks, evaluate risk appetite alignment, an…
General
ecm-qc-shareholders-meeting-witness
Reviews shareholder meeting witness opinions against regulatory references from public filings. Pulls meeting notices and board resolutions via open APIs, performs field-level cros…
Security
trafficwatch-ids-review
Skill específica para revisar, implementar, probar y documentar TrafficWatch IDS, un sistema académico de detección de intrusos con Python, Flask, Scapy, dashboard web, respuesta a…
Security
salesforce-apex-quality
Apex code quality guardrails for Salesforce development. Enforces bulk-safety rules (no SOQL/DML in loops), sharing model requirements, CRUD/FLS security, SOQL injection prevention…
Security
workflow-security-report
Triage a GitHub code-scanning (CodeQL) finding and generate an immutable Markdown report with an index entry, recommending remediation or dismissal, pinning every code reference to…
Security
cyber-incident-response-72h
Structured immediate response for active cyber incidents — hacker attacks, ransomware, data exfiltration, insider threats. Phase 1: immediate containment, network isolation, forens…
Security
auditclaw-grc
GRC automation suite covering 13 frameworks (SOC 2, ISO 27001, HIPAA, GDPR, NIST CSF, PCI DSS, CMMC, FedRAMP, others). Manages controls, evidence, risks, policies, vendors, inciden…
Security
ovhcloud-live-kms-key-destruction-guard
Gate and audit OVHcloud KMS key version destruction requests by enforcing five mandatory checks: confirmed key ID and KMS service URN, named approving identity, usage audit confirm…
Security
forter-agentic-readiness-audit
Audit a website against the Forter Agentic Readiness Guide. Loads the 25 weighted rubrics in `audit/`, probes the target site (and optional source code), scores each guideline Pass…
AI / ML
uncertainty-imaging
Audits uncertainty quantification, OOD detection, and selective prediction layers in medical-imaging models, validating MC-dropout, ensembles, conformal intervals, and abstention r…
DevOps
ssh-command-screenshot
Run SSH commands in Windows Terminal and capture per-command screenshot evidence into a new folder. Use early whenever a task involves Linux/Unix system inspection, troubleshooting…
Security
hack-review
Performs a scoped, coverage-led review of a working tree, staged diff, commit range, branch diff, PR, or suspicious implementation to identify hack-like risks such as impossible-st…
Business
due-diligence-checklist
Drafts due diligence checklists for U.S. corporate transactions (M&A, asset purchases, investments, JVs, restructurings). Covers corporate structure, financials, tax, contracts, IP…
Security
gcp-live-kms-key-destruction-guard
Gate Cloud KMS key version destruction and key ring deletion against a complete CMEK dependency audit. All Cloud SQL, GCS, BigQuery, Compute Engine disk, and Secret Manager resourc…
Security
cilium-network-policy-review
Use this skill for Cilium network policy review across Kubernetes NetworkPolicy, CiliumNetworkPolicy, and CiliumClusterwideNetworkPolicy formats, including L7 policy via Envoy, Clu…
Security
risk-control
Manages hazard and risk records for regulated projects via a single normalized YAML file (docs/.index/risk-file.yaml) with hazard IDs, risk estimates, controls, verification links,…
Security
hipaa-review
Performs a HIPAA Security Rule compliance review across all Administrative, Physical, and Technical Safeguards in 45 CFR Part 164, Subpart C. Auto-invoked for healthcare data secur…
Business
sap-treasury-cash-risk-review
Reviews SAP Treasury and Risk Management (TRM) and Cash Management setups, covering cash positioning, liquidity forecasting, bank account governance, in-house cash design, hedge co…
Security
security-focused-review
Scoped security review establishing assets, trust boundaries, and attacker prerequisites with evidence-backed findings across auth, authorization, validation, injection, path handl…
Security
dsv-beweissicherung
Structures evidence preservation after a data-protection incident to keep materials admissible in administrative, criminal, or civil proceedings. Covers chain of custody, secure lo…
Engineering
ghayth-skill
End-to-end engineering workflow for Ghayth and similar business systems. Covers planning, building, refactoring, testing, security review, and release across roles, approvals, fina…
Engineering
pg-migration
PostgreSQL schema migration safety reviewer and DDL generator. Use for writing, reviewing, or planning schema changes including ALTER TABLE, index operations, constraint modificati…
General
ki-verordnung-compliance
Performs EU AI Act compliance checks covering scope, risk classification, prohibited practices, high-risk systems, transparency duties, GPAI models, conformity declarations, CE mar…
Engineering
verified-core-discipline
Provides the project's multi-tier correctness model: verified core (facades, lattice algebra, certifiers, reference models, law corpus) plus surrounding checks (types, model-checki…
Security
threat-model
Analyzes systems and applications to produce structured threat model reports using STRIDE, OWASP Top 10, OWASP LLM Top 10, or MITRE ATT&CK frameworks. Use for traditional web appli…
Engineering
suede-ship
Canonical Suede shipping DAG: scout, multi-lens research, gap critic, lane plan with explicit file ownership, disjoint parallel build, dual-lens review, adversarial refute, integra…
Business
event-staffing-compliance
Assess worker-classification and compliance risk for temporary event staffing in the US and Canada. Use when a user asks about W-2 vs 1099 event workers, misclassification penaltie…
Engineering
project-agentification
Assess repository agent-readiness, harden against failure modes, scaffold AGENTS.md / SKILL.md / MCP servers / hooks / specs from observed failures, and diagnose why coding agents …
Security
supabase-security
Use when auditing or hardening a Supabase project's security posture. Triggers: scan/audit Supabase, RLS verification, find leaky tables, check anon grants, review SECURITY DEFINER…
Security
gcp-live-bigquery-dataset-deletion-guard
Gate BigQuery dataset deletion, table truncation, and authorized view changes against a full downstream dependency audit and export confirmation. Dataset deletion is immediate and …
Showing the top 60 of 11,167. See the full list →