Bounty Security Pattern Master Library — 399 Vulnerability Patterns
A premium library of 399 vulnerability patterns and DeFi attack vectors for AI-driven bug hunting and security audits.
Skill of the Month: Award Winning Design by Aman Garg · View skill →
Skills for security audits, static analysis, vulnerability triage, and compliance checks. Ship safer software and meet regulatory requirements faster.
356 live security & compliance skills for Kiro.
A premium library of 399 vulnerability patterns and DeFi attack vectors for AI-driven bug hunting and security audits.
by Roy Yuen
Professional security audit skill for web apps and APIs with structured severity-based findings and remediation plans.
by Roy Yuen
Transform AI claims into verified, risk-assessed technical reports for production, DevOps, and enterprise governance.
by Roy Yuen
Prevent vulnerabilities before they happen by forcing early security framing and secure-by-default design patterns.
by Roy Yuen
Audit AI agent skills for security risks, packaging errors, and marketplace readiness with professional reports.
by Roy Yuen
A high-performance wrapper to route security tasks directly to the Anthropic-Cybersecurity-Skills library.
Expert AI guidance for ISO-compliant cleanroom design, HVAC filtration setup, and controlled environment installation.
by Samuel Rose
Audit dependencies for security, licenses, and health while generating a phased, low-risk upgrade and migration plan.
by Shogun Labs
Pre-commit security hooks: secret detection, destructive command prevention
by Roy Yuen
Automated security and compatibility firewall for installing AI agent skills and Codex/OpenClaw packages.
Scan AI agent skill definitions for malicious instructions, prompt injections, and security risks—locally.
by Roy Yuen
Automated governance and risk audit for AI agent tool permissions and authentication boundaries.
by Roy Yuen
A modular governance framework for AI policy, agent risk assessment, human-in-the-loop approvals, and audit trails.
by Shogun Labs
Project-specific Claude Code agent harness setup
Accelerate your bounty hunting with smart program prioritization and vulnerability report triaging for DeFi protocols.
by LocoLoboZ
Professional CTI analysis skill for structured attribution using ACH, Diamond Model, and confidence scoring.
by Tate Lyman
Automated launch-readiness auditor for x402 and agent-payment API surfaces.
by rayyer
Find accessibility barriers and WCAG 2.2 AA failures in web and mobile UI code — with file:line, the exact criterion, and a fix
by Edric Vale
Safe dependency upgrade plans: changelog-aware risk scoring, test hints, and rollback paths.
Penetration-test your Claude Code agent's guardrails before you deploy. Throws prompt-injection payloads, shell-chaining, and path-traversal attempts at your PreToolUse/PostToolUse hooks and sensitive-file protections, then returns a pass/fail report on 10+ attack vectors with copy-paste remediation for every gap.
by LocoLoboZ
Automate the setup and optimization of Semgrep, SonarQube, and CodeQL for high-signal security testing.
by Rian O'Leary
Full WCAG 2.1 AA accessibility audits with JS rendering, professional client reports, and remediation roadmaps.
Automated security auditing and risk assessment for Model Context Protocol (MCP) servers.
by rayyer
Adaptive GDPR, CCPA, security, and AI compliance audit with severity-graded findings and law citations
Each skill on this page is a SKILL.md file built for security & compliance work and confirmed to run in Kiro. Install one into ~/.kiro/skills/, start a new session, and Kiro follows the workflow the creator encoded instead of improvising from a short prompt.
Listings are ranked by installs, upvotes and reviews, so what surfaces first is what other Kiro users actually keep. Free and paid skills compete on the same page, and every listing shows its security scan result before you download anything.
These are the jobs creators are actually shipping skills for in this category. Each one encodes a full workflow, so Kiro follows the same method every time instead of improvising from a one-line prompt.
Start with the outcome, not the label. Open the listing and read the SKILL.md preview: a good security & compliance skill states exactly what it does, what it needs from you, and what it deliberately refuses to do. Vague descriptions usually mean vague output.
Then check three things: the install count and reviews (other Kiro users voting with their setup), whether the creator ships updates, and whether the skill is universal SKILL.md or agent-specific. Free skills are a fine way to test a creator's style before buying their paid work.
Every paid creator is verified before they can sell, so skills come from practitioners, not scraped prompt packs.
Each version is scanned for prompt injection, credential exfiltration and destructive commands before it goes live.
Some skills are free, but most are paid. Paid skills show the price upfront and include future updates from the creator.
Unzip into ~/.kiro/skills/ and start a new session. No plugin store, no build step.
Have questions about Agensi? Drop us an email and we'll get back to you.
Founder & CEO of Agensi
Email UsBook a Callinfo@agensi.io
We typically respond within a few hours during business hours.