Discover and install skills, docs, and rules to enhance your AI agent's capabilities.
Top Performing in Security & Compliance
Data-driven rankings. Real results from real agents.
| Name | Contains | Score |
|---|---|---|
rmyndharis/antigravity-skills You are a compliance expert specializing in regulatory requirements for software systems including GDPR, HIPAA, SOC2, PCI-DSS, and other industry standards. Perform compliance audits and provide implementation guidance. | Skills | — |
PostHog/posthog Focused security audit of code, calibrated to surface real exploitable bugs and suppress theoretical findings. Use when the user asks to "audit", "security-audit", "find vulnerabilities", "check for IDOR/SSRF/XSS/injection", or wants a security review of a file, directory, branch diff, or PR. Covers access control, injection, auth/secrets, sensitive data, business logic, web boundary, and AI agent/LLM trifecta risks. Produces calibrated findings with data flow, exploit request, fix, and confidence — no theoretical or defense-in-depth nits. | Skills | |
cloudflare/security-audit-skill Security audit of a codebase — web apps, APIs, services, CLI tools, libraries, daemons, and more. Use when asked to find security bugs, do a security review, audit for vulnerabilities, or pen-test the code. Focuses on exploitable issues with real impact, not theoretical concerns or industry-standard behavior. | Skills | — |
RightNow-AI/openfang Security audit expert for OWASP Top 10, CVE analysis, code review, and penetration testing methodology | Skills | |
aave/aptos-aave-v3 Audits Move contracts for security vulnerabilities before deployment using 7-category checklist. Triggers on: 'audit contract', 'security check', 'review security', 'check for vulnerabilities', 'security audit', 'is this secure', 'find security issues'. | Skills | |
waynesutton/convexskills Deep security review patterns for authorization logic, data access boundaries, action isolation, rate limiting, and protecting sensitive operations | Skills | |
rmyndharis/antigravity-skills Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks. Masters vulnerability assessment, threat modeling, secure authentication (OAuth2/OIDC), OWASP standards, cloud security, and security automation. Handles DevSecOps integration, compliance (GDPR/HIPAA/SOC2), and incident response. Use PROACTIVELY for security audits, DevSecOps, or compliance implementation. | Skills | — |
eigent-ai/eigent Security auditing for code, configs, and infrastructure. Use when the user wants to audit or improve security: scan for vulnerabilities (SQL injection, XSS, command injection, path traversal), detect hardcoded secrets and credentials, review auth and authorization, check dependencies for known CVEs, audit config files for insecure defaults, or generate security reports. Trigger on "security audit", "vulnerability scan", "code review for security", "find secrets", "check for vulnerabilities", "OWASP", "CVE", or questions about code security. | Skills | |
nyldn/claude-octopus OWASP compliance, vulnerability scanning, and adversarial red team testing — use for security reviews | Skills | |
RightNow-AI/openfang Compliance expert for SOC 2, GDPR, HIPAA, PCI-DSS, and security frameworks | Skills | |
jeremylongshore/claude-code-plugins-plus-skills Analyze code, infrastructure, and configurations by conducting comprehensive security audits. It leverages tools within the security-pro-pack plugin, including vulnerability scanning, compliance checking, and cryptography review. Use when assessing security or running audits. Trigger with phrases like 'security scan', 'audit', or 'vulnerability'. | Skills | |
boisenoise/skills-collections Automated compliance checking against CIS, PCI-DSS, HIPAA, and SOC 2 benchmarks | Skills | |
v7.0.17 Curated library of 28 atomic skills and 9 personas for Ruby on Rails development. Organized by category: testing, code-quality, engines, infrastructure, api, context, and personas. Covers code review, architecture, security, testing (RSpec), engines, Hotwire, and TDD automation. Shared Ruby skills (YARD docs, DDD, service objects) have moved to ruby-core-skills. | Skills | |
x-cmd/x-cmd Security audit for code changes. Triggered by "/security-review" when reviewing auth, crypto, input handling, or when user explicitly requests a security audit. | Skills | |
briiirussell/cybersecurity-skills Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps. Use when the user mentions 'cloud security,' 'cloud audit,' 'AWS security,' 'GCP security,' 'Azure security,' 'IAM audit,' 'S3 bucket,' 'cloud misconfiguration,' 'cloud hardening,' or needs to review cloud infrastructure security. | Skills | |
nearai/ironclaw Security audit for code changes and PRs — OWASP top 10, auth flows, data handling, secrets exposure, supply chain risks. Writes findings as actionable items. | Skills | |
TurnaboutHero/oh-my-antigravity Security specialist - finds vulnerabilities and ensures best practices | Skills | |
waynesutton/convexskills Quick security audit checklist covering authentication, function exposure, argument validation, row-level access control, and environment variable handling | Skills | |
shawnpang/startup-founder-skills When the user needs a security assessment — threat modeling, vulnerability review, auth flow audit, dependency scanning, or says "is this secure", "review for vulnerabilities", "threat model", "security audit", "pen test prep". | Skills | |
rohitg00/awesome-claude-code-toolkit Application security covering input validation, auth, headers, secrets management, and dependency auditing | Skills |
Can't find what you're looking for? Evaluate a missing skill.