Browse the full skills directory.浏览完整技能目录。
Filter by query, category, scenario, platform, and risk signals with server-side catalog results.按关键词、品类、场景、平台和风险信号筛选;URL 参数会直接下推到目录 API。
95 results
Community-indexed skills are not individually editor-curated; review risk signals, source, and maintenance before install.
api-security-testing
API安全测试的专业技能和方法论
aig-scanner
A.I.G Scanner — AI security scanning for infrastructure, AI tools / skills, AI Agents, and LLM jailbreak evaluation via
ctf web
Provides web exploitation techniques for CTF challenges. Use when the target is primarily an HTTP application, API, bro…
ctf pwn
Provides binary exploitation techniques for CTF challenges. Use when you already have a vulnerable native target or ser…
ctf reverse
Provides reverse engineering techniques for CTF challenges. Use when the main job is to understand how a compiled, obfu…
skill vetter
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Ch…
solidity audit
Solidity smart contract security audit assistant following EEA EthTrust V3 specification. Performs structured audit wor…
skill vetting
Vet ClawHub skills for security and utility before installation. Use when considering installing a ClawHub skill, evalu…
skill scanner
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them.…
claw sentinel
Runtime security layer for OpenClaw agents. Intercepts and scans all external input (emails, API responses, web content…
senior secops
Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure de…
runtime sentinel
Runtime security guardian for OpenClaw agents. Use this skill whenever the user mentions security, skill safety, prompt…
phy ssrf audit
Server-Side Request Forgery (SSRF) vulnerability scanner (OWASP A10:2021). Detects URL-fetching sinks in Python/Java/No…
phy path traversal audit
Path traversal and Local File Inclusion (LFI) vulnerability scanner (OWASP A01:2021). Detects user-controlled paths pas…
phy jwt auth audit
phy jwt auth audit: agent skill — from LeoYeAI/openclaw-master-skills.
phy graphql schema audit
GraphQL schema static auditor. Reads any .graphql SDL file or introspection JSON to detect N+1 exposure hotspots (neste…
phy deserialization audit
Unsafe deserialization vulnerability scanner (OWASP A08:2021). Detects Python pickle/yaml/eval, Java ObjectInputStream/…
phy cors audit
CORS (Cross-Origin Resource Sharing) misconfiguration auditor. Probes any API endpoint with crafted Origin headers to d…
skill vetter
Security vetting protocol before installing any AI agent skill. Red flag detection for credential theft, obfuscated cod…
credential manager
MANDATORY security foundation for OpenClaw. Consolidate scattered API keys and credentials into a secure .env file with…
isms audit expert
Information Security Management System (ISMS) audit expert for ISO 27001 compliance verification, security control asse…
agentguard
GoPlus AgentGuard — AI agent security guard. Automatically blocks dangerous commands, prevents data leaks, and protects…
gdpr dsgvo expert
GDPR and German DSGVO compliance automation. Scans codebases for privacy risks, generates DPIA documentation, tracks da…
clawsec feed
Security advisory feed with automated NVD CVE polling for OpenClaw-related vulnerabilities. Updated daily.
clawsec
You are now acting as the ClawSec Monitor assistant. The user has invoked /clawsec to manage, operate, or interpret the…
ciso advisor
Security leadership for growth-stage companies. Risk quantification in dollars, compliance roadmap (SOC 2/ISO 27001/HIP…
ciso advisor
Security leadership for growth-stage companies. Risk quantification in dollars, compliance roadmap (SOC 2/ISO 27001/HIP…
trustlayer sybil scanner
Feedback forensics for ERC-8004 agents. Detects Sybil rings, fake reviews, rating manipulation, and reputation launderi…
blueagent x402
Security OS for autonomous agents and builders on Base. 31 pay-per-use tools across Quantum Security, Agent Safety, Res…
cvss score extraction
Extract CVSS (Common Vulnerability Scoring System) scores from vulnerability data sources with proper fallback handling…
ka88 agent shield
Professional security audit for AI agents. Checks URLs for SSRF, analyzes content for prompt injection, validates comma…
Agent Compliance & Security Assessment
Comprehensive compliance and security self-assessment for AI agents. 14-check framework producing a structured threat m…
two factor authentication best practices
Configure TOTP authenticator apps, send OTP codes via email/SMS, manage backup codes, handle trusted devices, and imple…
email and password best practices
Configure email verification, implement password reset flows, set password policies, and customise hashing algorithms f…
prompt guard
Meta's 86M prompt injection and jailbreak detector. Filters malicious prompts and third-party data for LLM apps. 99%+ T…
ssh penetration testing
This skill should be used when the user asks to "pentest SSH services", "enumerate SSH configurations", "brute force SS…
eicar test
Test skill containing EICAR test file for malware detection
yidun skill sec
Intelligent code security scanner with hybrid local-cloud detection. Fingerprints packages, runs static behavioral anal…
openguardrails
Runtime security plugin for AI agents. Provides local-first protection against data exfiltration, credential theft, com…
ai prompt engineering safety review
Comprehensive AI prompt engineering safety review and improvement prompt. Analyzes prompts for safety, bias, security v…
Domain Skill Template
Use this template for domain-specific security testing (cryptographic testing, web security methodologies, etc.).
constant time testing
Constant-time testing detects timing side channels in cryptographic code. Use when auditing crypto implementations for…
c review
Performs comprehensive C/C++ security review for memory corruption, integer overflows, race conditions, and platform-sp…
threat detection
Use when hunting for threats in an environment, analyzing IOCs, or detecting behavioral anomalies in telemetry. Covers…
senior secops
../../../engineering-team/skills/senior-secops/SKILL.md
senior secops
Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure de…
isms audit expert
Information Security Management System (ISMS) audit expert for ISO 27001 compliance verification, security control asse…
incident response
Use when a security incident has been detected or declared and needs classification, triage, escalation path determinat…
gdpr dsgvo expert
GDPR and German DSGVO compliance automation. Scans codebases for privacy risks, generates DPIA documentation, tracks da…
ciso advisor
Security leadership for growth-stage companies. Risk quantification in dollars, compliance roadmap (SOC 2/ISO 27001/HIP…
variant analysis
Find similar vulnerabilities and bugs across codebases using pattern-based analysis. Use when hunting bug variants, bui…
firebase apk scanner
Scans Android APKs for Firebase security misconfigurations including open databases, storage buckets, authentication is…
yara rule authoring
Guides authoring of high-quality YARA-X detection rules for malware identification. Use when writing, reviewing, or opt…
trailmark
Builds and queries multi-language source code graphs for security analysis. Includes pre-analysis passes for blast radi…
semgrep rule creator
Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. Use when writing…
mermaid to proverif
Translates Mermaid sequenceDiagrams describing cryptographic protocols into ProVerif formal verification models (.pv fi…
semgrep
Run Semgrep static analysis scan on a codebase using parallel subagents. Supports two scan modes — "run all" (full rule…
sharp edges
Identifies error-prone APIs, dangerous configurations, and footgun designs that enable security mistakes. Use when revi…
insecure defaults
Detects fail-open insecure defaults (hardcoded secrets, weak auth, permissive security) that allow apps to run insecure…
graph evolution
Compares Trailmark code graphs at two source code snapshots (git commits, tags, or directories) to surface security-rel…
audit prep assistant
Prepares codebases for security review using Trail of Bits' checklist. Helps set review goals, runs static analysis too…
fp check
Systematically verifies suspected security bugs to eliminate false positives. Produces TRUE POSITIVE or FALSE POSITIVE…
dimensional analysis
Annotates codebases with dimensional analysis comments documenting units, dimensions, and decimal scaling. Use when som…
entry point analyzer
Analyzes smart contract codebases to identify state-changing entry points for security auditing. Detects externally cal…
constant time analysis
Detects timing side-channel vulnerabilities in cryptographic code. Use when implementing or reviewing crypto code, enco…
agentic actions auditor
Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations including Claude Code Action, Gem…
codeql
Scans a codebase for security vulnerabilities using CodeQL's interprocedural data flow and taint tracking analysis. Tri…
iam
AWS Identity and Access Management for users, roles, policies, and permissions. Use when creating IAM policies, configu…
secrets manager
AWS Secrets Manager for secure secret storage and rotation. Use when storing credentials, configuring automatic rotatio…
google cloud recipe auth
Provides expert guidance on authenticating and authorizing to Google Cloud services and APIs, covering human users, ser…
osint methodology
Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments. Covers the…
Offensive OSINT — External Red Team Arsenal
Operational arsenal for external red-team and bug-bounty reconnaissance. Concrete wordlists (28 Swagger paths, 13 Graph…
threat detection
Exact detection thresholds for identifying malicious network patterns including port scans, DoS attacks, and beaconing…
ctf malware
Provides malware analysis and network traffic techniques for CTF challenges. Use when analyzing obfuscated scripts, mal…
mcp atlassian hint inject
Demonstrates mcp-atlassian credential leak via hint parameter.
ctf forensics
Provides digital forensics and signal analysis techniques for CTF challenges. Use when analyzing disk images, memory du…
flowise chatflow api
Exposes Flowise chatflow API with overrideConfig support.
mcpwn retry exploit
Demonstrates MCPwn runaway invocation pattern.
spec to code compliance
Verifies code implements exactly what documentation specifies for blockchain audits. Use when comparing code against wh…
tsa risk
腾讯云智能顾问架构风险巡检分析报告生成工具。用于分析用户在腾讯云智能顾问产品下的架构图风险巡检情况,从API拉取数据并生成移动端友好的HTML可视化报告,最终将HTML转换为PNG图片输出。当用户提到智能顾问架构巡检、风险分析、巡检报告、…
tsa risk
腾讯云智能顾问架构风险巡检分析报告生成工具。用于分析用户在腾讯云智能顾问产品下的架构图风险巡检情况,从API拉取数据并生成移动端友好的HTML可视化报告,最终将HTML转换为PNG图片输出。当用户提到智能顾问架构巡检、风险分析、巡检报告、…
supply chain risk auditor
Identifies dependencies at heightened risk of exploitation or takeover. Use when assessing supply chain attack surface,…
azure compliance
Run Azure compliance and security audits with azqr plus Key Vault expiration checks. Covers best-practice assessment, r…
soc2 compliance
../../../ra-qm-team/skills/soc2-compliance/SKILL.md
threat detection
../../../engineering-team/skills/threat-detection/SKILL.md
soc2 compliance
Use when the user asks to prepare for SOC 2 audits, map Trust Service Criteria, build control matrices, collect audit e…
risk management specialist
../../../ra-qm-team/skills/risk-management-specialist/SKILL.md
incident response
../../../engineering-team/skills/incident-response/SKILL.md
burpsuite project parser
Searches and explores Burp Suite project files (.burp) from the command line. Use when searching response headers or bo…
secure workflow guide
Guides through Trail of Bits' 5-step secure development workflow. Runs Slither scans, checks special features (upgradea…
acquiring-disk-image-with-dd-and-dcfldd
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through hash v
android-reverse-engineering
Decompile Android APK, XAPK, JAR, and AAR files using jadx or Fernflower/Vineflower. Reverse engineer Android apps, extr
Active Directory Attacks
This skill should be used when the user asks to "attack Active Directory", "exploit AD", "Kerberoasting", "DCSync", "pas
offensive-iot
IoT and embedded device security testing methodology. Covers hardware reconnaissance (UART, JTAG, SWD, SPI flash, I2C EE
offensive-active-directory
Active Directory attack methodology for internal network red team engagements. Covers reconnaissance (BloodHound, PowerV