Best Security & Compliance Skills for Claude Code

    Skills for security audits, static analysis, vulnerability triage, and compliance checks. Ship safer software and meet regulatory requirements faster.

    67 skills

    Bounty Security Pattern Master Library — 399 Vulnerability Patterns

    by Atlas Agent Suite

    $75

    A premium library of 399 vulnerability patterns and DeFi attack vectors for AI-driven bug hunting and security audits.

    7
    125.0(1)

    security audit

    by Roy Yuen

    $10

    Professional security audit skill for web apps and APIs with structured severity-based findings and remediation plans.

    4
    0No reviews

    cybersecurity bridge for all agentic

    by Roy Yuen

    Free

    A high-performance wrapper to route security tasks directly to the Anthropic-Cybersecurity-Skills library.

    3
    21No reviews

    skill security vendor pack

    by Roy Yuen

    Free

    Audit AI agent skills for security risks, packaging errors, and marketplace readiness with professional reports.

    2
    17No reviews

    security first

    by Roy Yuen

    Free

    Prevent vulnerabilities before they happen by forcing early security framing and secure-by-default design patterns.

    2
    20No reviews

    skill install safety gate

    by Roy Yuen

    Free

    Automated security and compatibility firewall for installing AI agent skills and Codex/OpenClaw packages.

    2
    10No reviews

    AI Cleanroom Solutions Tool Cleanroom Design

    by Clean Room Design

    Free

    Expert AI guidance for ISO-compliant cleanroom design, HVAC filtration setup, and controlled environment installation.

    2
    5No reviews

    Accessibility Auditor (WCAG 2.2)

    by rayyer

    $10

    Find accessibility barriers and WCAG 2.2 AA failures in web and mobile UI code — with file:line, the exact criterion, and a fix

    2
    15.0(1)

    truth first enterprise

    by Roy Yuen

    $5

    Transform AI claims into verified, risk-assessed technical reports for production, DevOps, and enterprise governance.

    3
    1No reviews

    dependency auditor

    by Samuel Rose

    $5

    Audit dependencies for security, licenses, and health while generating a phased, low-risk upgrade and migration plan.

    1
    1No reviews

    sast configuration

    by LocoLoboZ

    $10

    Automate the setup and optimization of Semgrep, SonarQube, and CodeQL for high-signal security testing.

    3
    3No reviews

    ai security auditor

    by Timoranjes

    Free

    Comprehensive security auditing for AI agents, covering prompt injection, tool permissions, and data leakage risks.

    2
    8No reviews

    business ai governance mesh

    by Roy Yuen

    $7

    A modular governance framework for AI policy, agent risk assessment, human-in-the-loop approvals, and audit trails.

    2
    0No reviews

    dependency health check

    by Timoranjes

    Free

    Automated security audit and health check for software dependencies across polyglot projects.

    2
    6No reviews

    x402 attack surface gate

    by Tate Lyman

    $19

    Automated launch-readiness auditor for x402 and agent-payment API surfaces.

    2
    0No reviews

    ADA Compliance Checker (Free) Most Common problems only

    by Jochem den Boer

    Free

    A fast, free 3-point accessibility screen (text contrast, image alt text, form labels) to spot the most common ADA/WCAG problems before they cost you.

    2
    4No reviews

    🔒 PII & Data Leak Scanner

    by JustHandled Labs

    $15

    Scan your schemas, seed data, config, and logs for personal data before it leaks. Detects PII-indicating column and key names (email, ssn, phone, address) across SQL, CSV, and JSON, plus PII in the data itself: email addresses, SSN-like numbers, credit-card-like numbers, phone numbers, and PII written into log files. Each finding is flagged with its location and a GDPR-style review note. Heuristic by design: it surfaces what to review, not a compliance guarantee.

    2
    3No reviews

    accessibility auditor

    by Timoranjes

    Free

    Audit frontend code for WCAG 2.2 AA compliance with prioritized remediation steps and deep semantic analysis.

    2
    3No reviews

    Bug Bounty Report Reviewer

    by Atlas Agent Suite

    $15

    Audit and refine vulnerability reports to maximize bounty payouts and reduce N/A or duplicate closures.

    2
    0No reviews

    Jamf Self Service Credential Helper

    by LB Creations

    $12.99

    Secure, battle-tested patterns for user detection and credential prompting in Jamf and Kandji scripts

    2
    0No reviews

    Cert Watch — SSL Certificate Expiry Monitor + Telegram Alerts

    by Forge Executive

    $6

    Monitors SSL cert expiry dates and sends Telegram alerts before they expire. Critical at <7d, warning at <30d.

    2
    0No reviews

    Mac Admin Log Redactor

    by LB Creations

    Free

    Sanitize Mac admin logs and MDM evidence before sharing.

    2
    1No reviews

    Security Vulnerability Triage Agent for Small Teams

    by Shandra

    $50

    Turns dependency scan reports and security alerts into prioritized remediation plans with severity, exploitability, affected area, safe fix strategy, and verification checklists.

    2
    0No reviews

    ics anomaly detection

    by LocoLoboZ

    $15

    Design and analyze industrial control system anomaly detection logic for safe, protocol-aware OT security monitoring.

    2
    0No reviews

    cyber attack chain analysis

    by LocoLoboZ

    $12

    Transform incident timelines into structured Cyber Kill Chain mappings and high-impact defensive roadmaps.

    2
    0No reviews

    vulnerability remediation tracker

    by LocoLoboZ

    $12

    Transform raw vulnerability data into compliant remediation reports, ageing registers, and executive dashboards.

    2
    0No reviews

    regex pattern validator

    by Timoranjes

    $5

    Expert regex architect for building, auditing, and optimizing high-performance, ReDoS-safe patterns.

    2
    0No reviews

    Gitleaks Auto Scan — Secret Detection & Zero Finding Achievement Workflow

    by Shogun Labs

    $5

    Automate secret scanning with gitleaks — detect API keys, passwords, tokens before incidents.

    2
    0No reviews

    ot incident response playbook builder

    by LocoLoboZ

    $15

    Build safety-first, framework-aligned incident response playbooks for ICS, SCADA, and OT environments.

    2
    0No reviews

    prompt injection auditor

    by Timoranjes

    Free

    The security auditor for AI agents. Detect prompt injection, secret leaks, and unsafe tool access in SKILL.md files.

    1
    3No reviews

    Prompt Injection & Agent Security Gate

    by PubsProToolkit

    $14

    An adversarial security gate that audits untrusted content — web pages, tool outputs, documents, emails — for embedded instructions, exfiltration, and authority spoofing, then returns a SAFE/REVIEW/BLOCK verdict.

    2
    0No reviews

    nex multitenant saas fastapi

    by Nex AI

    $9

    Prevent data leaks with auto-injected SQLAlchemy tenant scoping and Cloudflare Access auth for FastAPI SaaS apps.

    2
    0No reviews

    anti phishing training program

    by LocoLoboZ

    $10

    Design, govern, and report on enterprise-grade anti-phishing training programs and simulation metrics.

    1
    0No reviews

    GDPR Compliance Scanner for Marketing and Code

    by Martin Gunderman

    $15

    Automatically detect GDPR compliance risks in websites, codebases, marketing assets, and AI workflows.

    1
    1No reviews

    🛡️ Supabase RLS Doctor

    by JustHandled Labs

    $19

    Audit your Supabase project for the row-level-security mistakes that quietly expose data: tables without RLS, policies that resolve to true, leaked service-role keys, missing auth.uid() checks, open storage buckets, overbroad grants, and migration drift. A local, read-only scan plus a full review checklist, each finding with severity, evidence, and a fix. No database changes without confirmation.

    1
    0No reviews

    kubernetes manifest reviewer

    by Timoranjes

    Free

    Professional-grade Kubernetes YAML auditor for security, API deprecations, and deployment best practices.

    1
    1No reviews

    prompt injection auditor v2

    by Kaymue

    Free

    Audit prompts and MCP tools for prompt injection. 47 attack patterns, OWASP LLM Top 10, generates adversarial tests. CVSS-scored.

    2
    2No reviews

    code repair spine

    by Corey Jacobs

    Free

    Generate source-safe repository audits and repair handoff bundles without mutating your code.

    1
    2No reviews

    🛡️ Skill Injection Scanner

    by JustHandled Labs

    $15

    Scan a SKILL.md package for prompt injection and secret exfiltration before you install or publish an agent skill. Flags env-variable-to-URL exfiltration wording, conditional triggers with hidden side effects, imperative instructions buried in HTML comments, zero-width characters, base64 and long-token blobs, remote content treated as instructions, pipe-to-shell and recursive force-delete references, and overbroad tool requests (network plus browser plus file-write with no scope).

    1
    0No reviews

    agent supply chain auditor

    by Timoranjes

    Free

    Structured security auditing for AI agent skills to detect prompt injection, data exfiltration, and malicious commands.

    2
    1No reviews

    🛡️ GitHub Actions Permission Hardener

    by JustHandled Labs

    $19

    Audit and harden GitHub Actions workflows against overbroad permissions, secrets exposure, and supply-chain risks.

    1
    0No reviews

    🚦 Pre Launch Safety Check

    by JustHandled Labs

    $13

    Check your app for the security mistakes that leak data before you launch, explained in plain English. Flags API keys and secrets sitting in your code, a committed .env file, data with no login protecting it, database tables anyone can read, debug mode left on, wide-open sharing (CORS), hardcoded admin passwords, and public storage buckets. Built for non-technical founders shipping AI-built apps: every finding tells you what is wrong, why it matters, and how to fix it.

    2
    0No reviews

    dockerfile hardener

    by Timoranjes

    Free

    A security auditor that identifies Docker vulnerabilities, scores configurations, and generates hardened replacements.

    1
    1No reviews

    🛡️ Helm Chart Security Doctor

    by JustHandled Labs

    $13

    Audit a Helm chart for insecure defaults before you deploy to Kubernetes. Flags privileged containers, allowPrivilegeEscalation, missing CPU/memory limits and requests, hostPath volumes, hostNetwork/hostPID/hostIPC sharing, readOnlyRootFilesystem not set, runAsNonRoot not enforced (or runAsUser 0), plaintext secrets in values.yaml, missing NetworkPolicy, and NodePort/LoadBalancer services exposed without restriction.

    1
    0No reviews

    linux audit

    by SkillBill

    $9

    Complete security audit for Linux systems and WSL2. Checks kernel CVEs, SSH, firewall, users, and more hardening in one shot.

    2
    0No reviews

    AI Prompt Injection Defense Shield & LLM Jailbreak Security Auditor Code Review Agent

    by Brandon DeVries

    Free

    Stop leaving your AI startup exposed to malicious users trying to steal your proprietary system prompts or bypass your paywalls. The AI Prompt Injection Defense Shield is an automated code review agent that deeply analyzes your Next.js or Python backend, instantly detecting insecure LLM input fields, un-sanitized API data streams, and weak prompt boundaries. By automatically generating the exact copy-paste code patches required to harden your AI wrapper against the latest OWASP top 10 LLM vulnerabilities, this skill allows solo developers and indie hackers to confidently launch their SaaS without the fear of massive, unexpected API billing spikes or catastrophic data leaks.

    1
    2No reviews

    ai act transparency pack

    by Nex AI

    $9/mo

    Automate EU AI Act transparency audits, Article 50 disclosures, and AI literacy documentation for your apps.

    1
    0No reviews

    WordPress Accessibility Auditor

    by Arnstein Larsen

    $13.99

    A structured WCAG 2.1 AA audit and fix agent for WordPress themes, organized by block theme, Gutenberg, forms, and navigation context, with scored findings and complete before-to-after code patches.

    1
    0No reviews

    toegankelijkheid audit

    by Nex AI

    $7

    Professional accessibility auditing for architects, balancing legal regulations with real-world usability.

    1
    0No reviews

    Api Security Scanner

    by Echo Rose

    $5

    Api Security Scanner - A Premium AI Agent Skill

    2
    1No reviews

    Manuscript Disclosure & Submission Readiness Gate

    by PubsProToolkit

    Free

    A pre-submission gate for medical and scientific manuscripts. It audits your near-final draft, abstract, poster, or congress submission for the disclosures journals now screen on intake — AI/LLM-use disclosure (ICMJE-aligned), authorship against the four ICMJE criteria, conflict-of-interest and funding statements, and data availability — then returns a PASS/REVISE verdict naming every gap, plus a ready-to-paste AI-use disclosure statement. Built by a CMPP-certified medical writer.

    1
    0No reviews

    SAST Configuration Kit

    by Arnstein Larsen

    $7

    A DevSecOps engineer that stands up and tunes static analysis (Semgrep, SonarQube, CodeQL) for high-signal findings — picks the right tool for the stack, writes the config and rulesets, wires a sane CI gate, and tunes out the false positives that get scanners muted.

    1
    0No reviews

    Security Sweep

    by Ryan O'Donnell

    $5

    An automated security auditor that scans code for OWASP vulnerabilities, secrets, and injection flaws before deployment.

    2
    0No reviews

    🛡️ OpenClaw Guardrail Linter

    by JustHandled Labs

    $12

    Scan your OpenClaw config for the settings that quietly hand your agent too much power: unrestricted exec, open inbound DMs, secrets committed in config, the deny-write bypass, sandbox turned off, dangerous Docker binds, and elevated tools. Read-only, plain-English findings, grounded in the OpenClaw docs.

    1
    0No reviews

    company due diligence

    by Julian GM

    $29

    Public-source due diligence and risk assessment for companies, vendors, and business counterparties — every finding labeled verified, reported, or unverified.Automated OSINT due diligence and risk assessment for companies, vendors, and business counterparties.

    2
    0No reviews

    GDPR Compliance Cockpit — German & EU Websites

    by adrian-structure

    $49

    Local-first GDPR/TDDDG compliance cockpit that actually executes — scan a live site locally, check uploads fully offline, or build a compliant site, all with an evidence-backed report.

    2
    0No reviews

    AI Data Exposure and Vendor Risk Assessor

    by PubsProToolkit

    $14

    Before you send proprietary or sensitive data to an AI vendor, assess the risk. Classifies what's actually your moat versus regulated, contractual, or harmless data, maps the real exposure vectors by vendor tier, lists the questions to get in writing, and gives a send / send-with-controls / keep-in-house recommendation per data type.

    1
    0No reviews

    Prompt Injection Red Team Kit

    by PubsProToolkit

    $14

    Red-team your own AI agent for prompt-injection and tool-misuse vulnerabilities before it ships — then fix them. Maps your attack surface, generates a defensive test plan with the safe behavior expected for each case, and gives a prioritized mitigations list. Defensive use only.

    1
    0No reviews

    Payment Fraud Triage — BEC & Vendor Fraud Verdict (CLEAR/VERIFY/HOLD)

    by Julian GM

    $29

    Triage a vendor email, invoice, or bank-detail change request for BEC/fraud signals before you pay — mechanical CLEAR / VERIFY / HOLD verdict, honest about what it can't check.

    2
    0No reviews

    App Firewall

    by Echo Rose

    $5

    App Firewall - A Premium AI Agent Skill

    1
    0No reviews

    Skill Security Review

    by Scar Tissue Systems

    $14

    A third-party skill is instructions your agent will trust. Review it before you install it. Structured security auditing for third-party skills to detect injection, exfiltration, and hidden malicious logic.

    2
    0No reviews

    AgentForge DeFi Safety Toolkit (Solana + EVM, x402)

    by acarchidi

    Free

    DeFi safety layer for agents providing rug checks, transaction decoding, and contract audits on EVM and Solana.

    1
    0No reviews

    Ai Robustness Tester

    by Echo Rose

    $5

    Ai Robustness Tester - A Premium AI Agent Skill

    1
    0No reviews

    hipaa readiness audit

    by Elyas Shukri Elmi

    $48

    Audits codebases for HIPAA Security Rule gaps, identifies PHI leaks, and maps BAA requirements.

    1
    0No reviews

    money agent safety harness

    by Elyas Shukri Elmi

    $39

    A 6-layer engineering containment gate for agents that move real money.

    1
    0No reviews

    eaa accessibility remediation

    by Elyas Shukri Elmi

    $39

    Audit and remediate Shopify and WooCommerce stores for EAA, WCAG 2.1 AA, and ADA Title II compliance.

    1
    0No reviews

    revenueguard

    by Roy Yuen

    $7

    Local-first revenue assurance tool to identify billing leakage, unbilled usage, and expired discounts.

    1
    0No reviews