Security audit and hardening for AI agents — credential hygiene, secret scanning, prompt injection defense, data leakage prevention, and privacy zones.
Scan code and dependencies for CVEs, OWASP issues, and hardcoded secrets.
716 skills found
Page 1 of 30
Security audit and hardening for AI agents — credential hygiene, secret scanning, prompt injection defense, data leakage prevention, and privacy zones.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Performs static analysis for OWASP 2025 risks, supply chain threats, secrets detection, code patterns, and prioritizes vulnerabilities by exploitability and...
Automated authorized penetration testing skill with multi-layer detection, PoC/exploit generation, comprehensive vulnerability reporting, and scope safety co...
오픈소스 취약점 분석 스킬. 사용자가 오픈소스 패키지 이름과 사용 중인 버전을 입력하면, NVD(NIST), OSV.dev(Google), GitHub Advisory 3개 데이터 소스에서 CVE 취약점을 조회하여 최신 버전 정보와 함께 보안 리포트를 생성한다. 마크다운, Exce...
技能生态的「安全策展 → 安装闸门 → 生态治理」全能工具,find-skills 的社区超级增强版(能力已超越原版与 skill-vetter 等同类)。 当用户用自然语言描述需求("我想做个海报""帮我分析股票""有没有能做 X 的技能"),或明确说 "找个 skill / 找技能 / 安装技能 / find skills / 技能推荐 / 技能管理 / 卸载技能 / 技能安全审查 / 技能装太多太乱了"时触发。 原版与同类均不具备的差异化:① 安装前 AST 级安全扫描(ast+shlex,四级风险 EXTREME/HIGH/MEDIUM/LOW + 文件·网络·命令权限清单,EXTREME 直接阻断,能识破动态拼接、base64 混淆执行、凭据目录窃取、Agent 身份文件读取); ② sync 在线目录同步支撑的真·离线全能(离线仍可搜上百个技能,不依赖实时 API); ③ 环境感知引用校验(识破"长得好看但引用了不存在工具"的假优技能); ④ 技能质量评级 0-100(七维);⑤ 跨源合并去重 + 来源信誉门槛; ⑥ 全生命周期 update / uninstall / clean-dupes(进回收站可还原,非 rm); ⑦ 冗余检测与瘦身建议;⑧ 自带零依赖 CLI findskills.py(20 子命令,140 项测试全绿 + 端到端冒烟自证); ⑨ 内置 promote 自我营销引擎与 demo 可录屏演示。 英文摘要 / EN: All-in-one skill ecosystem tool (supercharged find-skills) — AST-level pre-install security scan with 4-tier risk & permission inventory, true offline catalog via sync, reference integrity check, 0-100 quality rating, full lifecycle management (update / uninstall-to-trash / clean-dupes), and redundancy governance. 20 zero-dependency subcommands, 140 passing tests, MIT.
授权 Web 渗透测试 Skill。模型自主威胁建模,JSON Schema 校验状态文件结构,输出按功能列出测了哪些威胁。 Use when user asks to perform authorized web penetration testing, vulnerability assessment on a web application, security testing with an explicit target URL, or asks to evaluate web application security posture. Do NOT use for unauthori
Securely store, search, and use secrets (API keys, tokens, passwords, SSH keys) with hal-vault, an SSH-key encrypted local secret store. Use when the user shares a credential that should be saved, asks what secrets are stored or where a key is, or when a command/workflow needs a secret injected. Core discipline - never print raw secret values into chat, logs, or files; reference secrets only by their masked form, and use --reveal exclusively inside command substitution.
Play ClawVille, a persistent AI life simulation where agents work jobs, earn coins, level up, build homes, trade, and compete on leaderboards.
Comprehensive audit of all construction data sources and systems. Map data flows, identify silos, assess quality, and create integration roadmap.
Analyze competitor GEO (Generative Engine Optimization) strategies by examining their content structure, Schema markup, llms.txt, and AI citation signals. Be...
Detect anomalies and outliers in construction data: unusual costs, schedule variances, productivity spikes. Statistical and ML-based detection methods.
Fast OSINT and reconnaissance presets using bbot and nmap. One-command subdomain enumeration, port scanning, and web fingerprinting for bug bounty recon.
Security audit tool for OpenClaw skills. Scans for credential harvesting, code injection, network exfiltration, obfuscation. ALWAYS run before installing any...
Audit and harden OpenClaw configuration for security. Scans openclaw.json for vulnerabilities, exposed credentials, insecure gateway settings, overly permiss...
Security scanner for OpenClaw skills. Detects prompt injection, credential leaks, unsafe code execution, MCP misconfigurations, privilege escalation, obfusca...
ShieldAPI — x402 Security Intelligence for AI Agents. 11 endpoints: password range check (k-anonymity), password check (deprecated), email breach lookup, dom...
The first security skill to install after setting up OpenClaw — powered by Tencent Zhuque Lab. Works like an antivirus for your AI environment: audits instal...
Persona-weighted merge governance for AI-assisted engineering. Evaluates PR risk (tests, security markers, reliability signals), returns MERGE/BLOCK/REVISE d...
Agents can sign plugins, rotate credentials without losing identity, and publicly attest to behavior.
Deep-scan a codebase, understand its architecture and patterns, then produce a comprehensive audit report with prioritized fixes. Optionally apply changes on...
Use when a task adds, upgrades, removes, or reviews software dependencies and the agent should apply a Socket-based supply-chain guardrail before changing ma...
Preflight-check Render service environment variables before deploys; catches missing keys and placeholder/template values that commonly break production roll...
审计和扫描技能的安全性。当用户希望对工作区中的其他技能进行安全扫描时使用。