Security

Security scanning and vulnerability detection

Showing 673-696 of 2236 skills
rand

discover-cloud

by rand

Automatically discover cloud computing and serverless skills when working with cloud. Activates for cloud development tasks.

API Dev 117 5mo ago
markus41

IaC Architecture - Cross-Cutting Concerns Skill

by markus41

Audit trails are complete and immutable

CI/CD 18 6mo ago
blacklanternsecurity

network-recon

by blacklanternsecurity

Network reconnaissance, host discovery, port scanning, and service enumeration.

Auth 236 4mo ago
0xAxiom

Social Intel Hub

by 0xAxiom

Edit config/skills-inventory.json when you ship new tools. The context matcher uses this to identify threads where your tools are directly relevant.

Processing 18 5mo ago
CTCT-CT2

ctct-security-patrol

by CTCT-CT2

OpenClaw 安全巡检工具,一键执行系统安全扫描并生成通俗易懂的报告。 使用场景:用户说"安全巡检"、"安全检查"、"安全审计"、"巡检"、"security audit"、"检查安全"、"系统安全"等。 触发条件:任何与 OpenClaw 安全检测、审计、巡检相关的请求。

Agents 355 3mo ago
AgentSecOps

container-grype

by AgentSecOps

Container vulnerability scanning and dependency risk assessment using Grype with CVSS severity ratings, EPSS exploit probability, and CISA KEV indicators. Use when: (1) Scanning container images and filesystems for known vulnerabilities, (2) Integrating vulnerability scanning into CI/CD pipelines with severity thresholds, (3) Analyzing SBOMs (Syft, SPDX, CycloneDX) for security risks, (4) Prioritizing remediation based on threat metrics (CVSS, EPSS, KEV), (5) Generating vulnerability reports in multiple formats (JSON, SARIF, CycloneDX) for security toolchain integration.

Processing 179 8mo ago
dgalarza

parallel-code-review

by dgalarza

This skill should be used when performing comprehensive code reviews using multiple specialized review agents in parallel. It provides patterns for concurrent execution, decision tracking to prevent redundancy, and consolidated reporting. Use when needing thorough review coverage from multiple perspectives (security, architecture, performance) or when reviewing large changesets.

Agents 58 6mo ago
ghostsecurity

ghost-report

by ghostsecurity

"Ghost Security — combined security report. Aggregates findings from all scan skills (scan-deps, scan-secrets, scan-code) into a single prioritized report focused on the highest risk, highest confidence issues. Use when the user requests a security overview, vulnerability summary, full security audit, or combined scan results."

Analytics 399 5mo ago
lijigang

ljg-xray-book

by lijigang

Deep structure extraction from books using the Epiplexity principle - maximizing computational investment to extract maximum learnable structure from any book.

CLI Tools 449 5mo ago
NickCrew

code-quality-workflow

by NickCrew

Use when assessing or improving code quality, maintainability, performance, or security hygiene - provides workflows for analysis, code review, and systematic improvements with validation steps.

Automation 22 6mo ago
anthonylee991

superpowers-workflow

by anthonylee991

Enforces a disciplined workflow for coding, debugging, refactoring, and automation: brainstorm -> plan -> implement with verification (prefer TDD) -> review -> finish. Use for almost any non-trivial change.

Agents 811 6mo ago
CommandCodeAI

aws-cost-operations

by CommandCodeAI

This skill provides AWS cost optimization, monitoring, and operational best practices with integrated MCP servers for billing analysis, cost estimation, observability, and security assessment.

Cloud 94 7mo ago
HermeticOrmus

solidity-security

by HermeticOrmus

Master smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns. Use when writing smart contracts, auditing existing contracts, or implementing security measures for blockchain applications.

Legal 82 8mo ago
launchdarkly

launchdarkly-flag-discovery

by launchdarkly

"Audit your LaunchDarkly feature flags to understand the landscape, find stale or launched flags, and assess removal readiness. Use when the user asks about flag debt, stale flags, cleanup candidates, flag health, or wants to understand their flag inventory."

Code Review 20 5mo ago
kroegha

kali-docker-pentesting

by kroegha

Comprehensive pentesting toolkit using Kali Linux Docker container. Provides direct access to 200+ security tools without MCP overhead. Use when conducting security assessments, penetration testing, vulnerability scanning, or security research. Works via direct docker exec commands for maximum efficiency.

CLI Tools 20 8mo ago
BagelHole

audit-logging

by BagelHole

Implement centralized audit logging and SIEM integration. Configure log retention and security monitoring. Use when implementing audit trail requirements.

Auth 42 5mo ago
BagelHole

gcp-audit-logs

by BagelHole

Configure GCP Cloud Audit Logs for compliance. Set up log routing and BigQuery analysis. Use when auditing GCP activity.

Code Review 42 5mo ago
ahmedasmar

ci-cd

by ahmedasmar

CI/CD pipeline design, optimization, DevSecOps security scanning, and troubleshooting. Use for creating workflows, debugging pipeline failures, implementing SAST/DAST/SCA, optimizing build performance, implementing caching strategies, setting up deployments, securing pipelines with OIDC/secrets management, and troubleshooting common issues across GitHub Actions, GitLab CI, and other platforms.

CI/CD 189 8mo ago
smallnest

healthcheck

by smallnest

Host security hardening and risk-tolerance configuration for OpenClaw deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, OpenClaw cron scheduling for periodic checks, or version status checks on a machine running OpenClaw (laptop, workstation, Pi, VPS).

Automation 600 5mo ago
Geeksfino

code-review

by Geeksfino

Reviews code for quality, best practices, and potential issues. Use when asked to review, audit, or check code for problems.

Code Review 64 6mo ago
ScientiaCapital

gtm-pricing

by ScientiaCapital

"B2B go-to-market strategy, pricing models, ICP development, positioning, and competitive intelligence. Use when planning GTM strategy, setting pricing, defining ICP, or evaluating opportunities."

Math 26 5mo ago
ScientiaCapital

security

by ScientiaCapital

"Application security patterns - authentication, secrets management, input validation, OWASP Top 10. Use when: auth, JWT, secrets, API keys, SQL injection, XSS, CSRF, RLS, security audit, pen testing basics."

Auth 26 5mo ago
JosiahSiegel

docker-security-guide

by JosiahSiegel

Comprehensive Docker security guidelines and threat mitigation strategies

Processing 48 6mo ago
ghostsecurity

ghost-scan-secrets

by ghostsecurity

Ghost Security - Secrets and credentials scanner. Scans codebase for leaked API keys, tokens, passwords, and sensitive data. Detects hardcoded secrets and generates findings with severity and remediation guidance. Use when the user asks to check for leaked secrets, scan for credentials, find hardcoded API keys or passwords, detect exposed .env values, or audit code for sensitive data exposure.

Agents 399 5mo ago