Skills · Topic
Security
Every skill in Security — what it does, who published it, and the one command that installs it. Pick a tile below for install details, or follow the original listing to the author's repo.
79 entries.
- reverse-engineering-tools — Guide for reverse engineering tools and techniques used in game security research. Use this skill when working with debu
- payload — Use when working with Payload CMS projects (payload.config.ts, collections, fields, hooks, access control, Payload API).
- skill-vetter — Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Che
- accessibility — Audit and improve web accessibility following WCAG 2.1 guidelines. Use when asked to "improve accessibility", "a11y audi
- computer-use-agents — Build AI agents that interact with computers like humans do - viewing screens, moving cursors, clicking buttons, and typ
- performing-security-audits — This skill allows Claude to conduct comprehensive security audits of code, infrastructure, and configurations.
- google-drive-automation — Automate Google Drive file operations (upload, download, search, share, organize) via Rube MCP (Composio). Upload/downlo
- woocommerce-code-review — Review WooCommerce code changes for coding standards compliance. Use when reviewing code locally, performing automated P
- claude-oauth-refresher — Keep your Claude access token fresh 24/7. Automatically refreshes OAuth tokens before expiry so you never see authentica
- skill-security-auditor — Security audit and vulnerability scanner for AI agent skills before installation.
- openclaw-memory-audit — Scan the agent workspace and memory logs for leaked API keys, tokens, or sensitive credentials.
- security-review — Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or impleme
- security-header-generator — Generates security HTTP headers (CSP, HSTS, CORS, etc.) for web applications to prevent common attacks. Use when user as
- fact-check — Verify technical accuracy of JavaScript concept pages by checking code examples, MDN/ECMAScript compliance, and external
- mcporter — Use the mcporter CLI to list, configure, auth, and call MCP servers/tools directly (HTTP or stdio), including ad-hoc ser
- springboot-security — Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency securi
- fix-security-vulnerability — Analyze and propose fixes for Dependabot security alerts
- find-bugs — Find bugs, security vulnerabilities, and code quality issues in local branch changes. Use when asked to review changes,
- django-drf — Django REST Framework patterns. Trigger: When implementing generic DRF APIs (ViewSets, serializers, routers, permissions
- red-team-tools-and-methodology — This skill should be used when the user asks to "follow red team methodology", "perform bug bounty hunting", "automate r
- attack-tree-construction — Build comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps,
- forensics-data-collector — Forensics Data Collector - Auto-activating skill for Security Advanced. Triggers on: forensics data collector, forensics
- snowflake-connections — Configuring Snowflake connections using connections.toml (for Snowflake CLI, Streamlit, Snowpark) or profiles.yml (for d
- gh — Use the GitHub CLI (gh) to perform core GitHub operations: auth status, repo create/clone/fork, issues, pull requests, r
- amcs-validator — Score composed artifacts against blueprint rubric. Evaluates hook density, singability, rhyme tightness, section complet
- fanvue — Manage content, chats, subscribers, and earnings on the Fanvue creator platform via OAuth 2.0 API.
- static-analysis — Expertise in LLVM-based static analysis including dataflow analysis, pointer analysis, taint tracking, and program verif
- exploit-researcher — Exploit researcher persona specializing in attack surface analysis, exploit scenario generation, and vulnerability chain
- research-grants — Write competitive research proposals for NSF, NIH, DOE, and DARPA.
- stride-analysis-patterns — Apply STRIDE methodology to systematically identify threats. Use when analyzing system security, conducting threat model
- klingai-install-auth — Execute set up Kling AI API authentication and configure API keys.
- security-scanning-security-hardening — Coordinate multi-layer security scanning and hardening across application, infrastructure, and compliance controls.
- linkerd-patterns — Implement Linkerd service mesh patterns for lightweight, security-focused service mesh deployments. Use when setting up
- security-scanner — Scans OpenClaw skills for security vulnerabilities and suspicious patterns before installation
- springboot-verification — Verification loop for Spring Boot projects: build, static analysis, tests with coverage, security scans, and diff review
- dma-attack-techniques — Guide for Direct Memory Access (DMA) attack techniques using FPGA hardware. Use this skill when researching PCIe DMA att
- vulnerability-scanner — Advanced vulnerability analysis principles. OWASP 2025, Supply Chain Security, attack surface mapping, risk prioritizati
- epic-security — Guide on security practices including CSP, rate limiting, and session security for Epic Stack
- cursor-privacy-settings — Configure Cursor privacy and data handling settings. Triggers on "cursor privacy", "cursor data", "cursor security", "pr
- obsidian-enterprise-rbac — Implement team vault access patterns and role-based controls. Use when managing shared vaults, implementing access contr
- wordpress-org-compliance — Ensures WordPress.org compliance for freemium plugins (free vs premium features, license keys, trial limits, upselling).
- awesome-game-security-overview — Guide for understanding and contributing to the awesome-game-security curated resource list. Use this skill when adding
- unbrowse — Analyze any website's network traffic and turn it into reusable API skills backed by a shared marketplace.
- hubspot-integration — Expert patterns for HubSpot CRM integration including OAuth authentication, CRM objects, associations, batch operations,
- threat-mitigation-mapping — Map identified threats to appropriate security controls and mitigations. Use when prioritizing security investments, cre
- django-verification — Verification loop for Django projects: migrations, linting, tests with coverage, security scans, and deployment readines
- api-integration-specialist — Expert in integrating third-party APIs with proper authentication, error handling, rate limiting, and retry logic.
- clickup-mcp — Manage ClickUp tasks, docs, time tracking, comments, chat, and search via official MCP. OAuth authentication required.
- nodejs-best-practices — Node.js development principles and decision-making. Framework selection, async patterns, security, and architecture. Tea
- reverse-engineer — Expert reverse engineer specializing in binary analysis, disassembly, decompilation, and software analysis.
- backend-security-coder — Expert in secure backend coding practices specializing in input validation, authentication, and API security. Use PROACT
- google-drive — Manage Google Drive files and folders with full CRUD operations via Ruby scripts.
- security-compliance — Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industr
- typescript-code-review — Perform comprehensive code reviews for TypeScript projects, analyzing type safety, best practices, performance, security
- reviewing-code — Systematically evaluate code changes for security, correctness, performance, and spec alignment. Use when reviewing PRs,
- software-security — A software security skill that integrates with Project CodeGuard to help AI coding agents write secure code and prevent
- better-auth-best-practices — Skill for integrating Better Auth - the comprehensive TypeScript authentication framework.
- confidence-check — Pre-implementation confidence assessment (≥90% required). Use before starting any implementation to verify readiness wit
- tailscale — Manage Tailscale tailnet via CLI and API. Use when the user asks to "check tailscale status", "list tailscale devices",
- solidity-security — Master smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns.
- windows-kernel-security — Guide for Windows kernel security research including driver development, system callbacks, security features, and kernel
- legal-advisor — Draft privacy policies, terms of service, disclaimers, and legal notices. Creates GDPR-compliant texts, cookie policies,
- google-workspace-cli — Google Workspace administration via the gws CLI. Install, authenticate, and automate Gmail, Drive, Sheets, Calendar, Doc
- moai-baas-auth0-ext — Enterprise Auth0 Identity Platform with AI-powered authentication architecture, Context7 integration, and intelligent id
- ai-boss-assistant — Transform any AI into a professional executive assistant with battle-tested personas and workflows. Complete templates f
- amcs-lyrics-generator — Generate song lyrics with citations from pinned sources. Enforces rhyme scheme, meter, syllable counts, hook strategy, a
- skill-hub — OpenClaw skill discovery, security vetting & install. Searches 3000+ curated skills from ClawHub registry and awesome-op
- healthcheck — Host security hardening and risk-tolerance configuration for OpenClaw deployments.
- web-scraper — Configurable web scraping service. Extract structured data from any public website with built-in security controls.
- gdpr-dsgvo-expert — Senior GDPR/DSGVO expert and internal/external auditor for data protection compliance.
- security — Security audit workflow - vulnerability scan → verification
- lark-shared — Use for lark-cli setup/auth tasks: auth login/status/logout, user vs bot identity, business-domain permissions (--domain
- lark-mail — 飞书邮箱:Use when user mentions 起草邮件、写邮件、草稿、发送/回复/转发邮件、查阅邮件、看邮件、搜索邮件、邮件文件夹、邮件标签、邮件联系人、监听新邮件、邮件收信规则等;use for mail/email inten
- ai-research-explore — Rigor Explore compatible skill slug for meaningful and potentially novel deep learning research candidates.
- explore-run — Rigor Improve / Rigor Explore run leaf skill for bounded exploratory evidence in deep learning research repositories.
- sentry-cli — Guide for using the Sentry CLI to interact with Sentry from the command line. Use when the user asks about viewing issue
- browser-act — Browser automation CLI for AI agents. NEVER run browser-act commands directly via Bash — always invoke this skill first.
- convex-performance-audit — Audits Convex performance for reads, subscriptions, write contention, and function limits. Use for slow features, insigh
- firebase-security-rules-auditor — A skill to evaluate how secure Firestore security rules are. Use this when Firestore security rules are updated to ensur