SKILL.md packages that extend Claude Code, Cursor, Copilot, and other AI agents.
Tags

clawmoat
Scans agent inputs and outputs for prompt injection, jailbreaks, credential leaks, PII, and unsafe tool calls; includes scripts for scanning and auditing.

sandbox0
Guidance and templates for integrating Sandbox0 sandboxing into AI agents — CLI/SDK patterns, templates, volumes, network policy, and deployment choices.

application-skills
Membrane-powered integration for Very Good Security (VGS): manage tokenization, vault records, and proxy requests via the Membrane CLI and connector workflow.

aboutsecurity
High-speed, stateless subdomain brute-force and verification using ksubdomain; optimized for large-scale discovery and validation where raw-socket performance a

cc-best
Strategies and checklists for code quality: security reviews, systematic debugging, and code-health assessments to reduce technical debt and improve reliability

shipyard
Automated workflow to detect and fix CVEs in Go dependencies across Submariner repositories; creates one commit per package and a single PR per branch.

antigravity-awesome-skills
Structured workflow for testing REST and GraphQL API security: authentication, authorization, input validation, rate limiting, and common API vulnerabilities.

wildclawbench
Adds full email, SMS, and persistent storage to agents—plus inter-agent messaging, task delegation, outbound security, and spam moderation.

codex_skill
Perform security-focused code reviews aligned to OWASP Top 10 and CWE patterns; produces grouped findings, risk summary, and remediation guidance.

secure-claude-skills
Automated and manual security tests for web apps: CSRF, rate limiting, input validation, security headers and pre-deployment checklist.

awesome-omni-skill
A read-only Kubernetes security audit toolkit for exporting resources, sanitizing metadata, and generating PSS/NSA-compliant reports.

tradeos
Natural-language driven CEX trading and portfolio management for agents: API key vaulting, multi-exchange orders, DCA, arbitrage scanning, alerts and security r

scammer.skill
Detect likely scam messages, identify the scam stage, and predict the scammer's next move to help users defend themselves.

awesome-omni-skill
Run a user request through five specialized agents in parallel, then synthesize their outputs into a consensus recommendation with confidence scoring and dissen

cryptoskill
Natural-language trading skill for Bybit: market data, spot and derivatives trading, account queries, and secure confirmation flows for Mainnet operations.

agent-skills
Comprehensive guidance for building, configuring, troubleshooting, and deploying Microsoft Foundry Classic agents and integrations.

agentic-commerce-skills-plugins
Implementation guidance for UCP identity linking using OAuth2 authorization code flow to link buyer accounts between platforms and merchants for personalized ch

awesome-openclaw-skills
Framework and templates to analyze incentives, tokenomics, MEV, governance attacks, and auction mechanisms in blockchain protocols.

skills
Collection of software development best practices for code quality, testing, security, performance, and observability across stacks.

tech-debt-skill
Run a deliberate, file-cited technical debt and architecture audit that outputs a TECH_DEBT_AUDIT.md with prioritized findings and remediation recommendations.

aboutsecurity
Practical reverse-engineering techniques for CTFs: static & dynamic analysis, anti-debug bypasses, custom VM handling, and multi-platform tooling.

de-anthropocentric-research-engine
Orchestrates a full adversarial assessment: surface enumeration, attack-vector generation, probing, and aggregated findings to score attack resilience.

awesome-skills-cn
Guides and checklists for binary reverse-engineering workflows (IDA, Ghidra, radare2, angr) including static/dynamic analysis phases and best practices.

useful-ai-prompts
Practical guidance and code snippets to harden REST APIs: authentication, rate limiting, input validation, headers, and middleware.

opencode-skills-collection
Guided methodology and best practices for binary reverse engineering, covering static and dynamic analysis workflows and common tooling.

antigravity-awesome-skills
A step-by-step workflow for testing REST and GraphQL APIs, covering authentication, authorization, input validation, rate limiting, GraphQL checks, and error-ha

Auth0 Agent Skills
Guides an agent to add Auth0 authentication to native Android apps (Kotlin/Java), including Web Auth, secure credential storage, biometric protection, and MFA,

api-relay-audit
An 11-step automated security audit for AI API relay/proxy services — detects prompt injection, context truncation, tool-call substitution, stream integrity iss

bountyforge
Orchestrates parallelized bug-bounty audits across smart contracts and web/APIs, producing deduplicated, gate-evaluated, platform-ready vulnerability reports fo

pi_agent_rust
Policy-as-code and linting guardrails for Perplexity integrations: ESLint rules, pre-commit hooks, CI checks, and runtime safeguards to prevent secrets and unsa