agent security skills

412 tagged agent security, measured the same way as everything else here.

Browse within: ai-security 145llm-security 77static-analysis 65supply-chain-security 62formal-verification 60ai-agent-security 55agent-security-scanner 47AI Safety 32Multi-Agent 30ai-governance 30vulnerability 30agent-orchestration 29self-hosted 29agent-tools 25

skill-inspector

01

NVIDIA/SkillSpector

Skill Claude CodeCodex

Review AI agent skills before installation using NVIDIA SkillSpector and source-aware semantic review. Use when asked whether a skill or downloaded skill folder is safe, trustworthy, installable, over-permissioned, or malicious.

15k yesterday A 47 tokens original Apache-2.0

chef-assistant

02

NVIDIA/SkillSpector

Skill Claude CodeCodex

Use when cooking or planning meals, troubleshooting recipes, learning culinary techniques.

15k yesterday A 17 tokens original Apache-2.0

aig-agent-redteam

04

Tencent/AI-Infra-Guard

Skill Claude CodeCodex

A guide for authorized security testing of AI products, agents, connectors, skills, plugins, code repositories, and related infrastructure. It uses harmless checks and collected evidence to identify and describe security risks.

6.1k 4d ago A 164 tokens original Apache-2.0

Tencent/AI-Infra-Guard

Skill Claude CodeCodex

Scan any agent skill for security risks before you install or use it. Powered by Tencent Zhuque Lab A.I.G (AI-Infra-Guard). 100% local static analysis — no file contents or credentials leave your device. Compatible with CodeBuddy, Cursor, Windsurf, Claude Code, OpenClaw and more. Triggers on: 这个 skill 安全吗, skill 安全扫描…

6.1k 4d ago A 148 tokens original Apache-2.0

arcjet/arcjet-js

Skill Claude CodeCodex

Integrate Arcjet security into a Vercel Eve agent using @arcjet/guard — add guard gates to tools and connections, screen inbound messages, and record agent lifecycle events correlated to the session. Use when asked to add Arcjet to an Eve agent, rate limit its tools, guard connection access, or screen inbound messages.

681 yesterday A 77 tokens original Apache-2.0

arcjet/arcjet-js

Skill Claude CodeCodex

Integrate Arcjet security into a Genkit JS agent using @arcjet/guard — wrap ai.defineTool, put guardMiddleware on generate({ use }) for unwrapped / MCP / filesystem tools, and read a caller-owned id from generate({ context }). Use when asked to add Arcjet to genkit, rate limit its tools, screen inbound messages, or…

681 yesterday A 89 tokens original Apache-2.0

arcjet/arcjet-js

Skill Claude CodeCodex

Integrate Arcjet security into a LangChain JS createAgent using @arcjet/guard — wrap tool() / StructuredTool, put guardMiddleware on createAgent({ middleware }) for MCP / unwrapped tools, and read configurable.threadid for correlation. Use when asked to add Arcjet to langchain createAgent, rate limit its tools, screen…

681 yesterday A 101 tokens original Apache-2.0

emiliaprotocol/emilia-protocol

Skill Claude CodeCodex

Verify the authenticity of AI-agent authorization receipts and human-device signoffs. Use this whenever a user shares a "trust receipt", an "authorization receipt", a "signoff", or WebAuthn/passkey approval evidence and asks whether it is valid, genuine, or tampered with. Pairs with the public EMILIA Protocol MCP…

653 yesterday A 94 tokens original Apache-2.0

hol-guard

10

hashgraph-online/hol-guard

Skill Claude CodeCodex

Run HOL Guard scanner and guard operations via uv run hol-guard. Use when the user asks to scan plugins/MCP/skills for security, quality, or ecosystem compliance, or when they ask to run guard detect/install/protect workflows for local AI harnesses.

504 yesterday A 58 tokens original Apache-2.0

setup

11

hashgraph-online/hol-guard

Skill Claude CodeCodex

Install or initialize HOL Guard local runtime protection for Claude Code. Use when the user explicitly asks to install, enable, set up, or repair HOL Guard.

504 yesterday A 33 tokens original Apache-2.0

status

12

hashgraph-online/hol-guard

Skill Claude CodeCodex

Check HOL Guard local protection status for Claude Code without changing configuration. Use when the user asks whether Guard is installed, active, healthy, or protecting Claude Code.

504 yesterday A 34 tokens original Apache-2.0

configure

13

SponsioLabs/Sponsio

Skill Claude CodeCodex

Use after /plugin install sponsio-claude-code to wire the runtime end-to-end. The plugin install only registers hooks + skills; the contract library and per-environment overrides are configured here. Bootstraps the per-plugin contract library tree at /.sponsio/plugins/, installs bundled starter libraries for popular…

438 3d ago E 263 tokens original Apache-2.0

sponsio

14

SponsioLabs/Sponsio

Skill Claude CodeCodex

Install, observe, tune, and enforce Sponsio: a runtime contract layer for LLM agents that blocks unsafe tool calls and scores output quality against declared rules. Use when the user wants to set up / add / install Sponsio, add guardrails or runtime safety to an LLM agent, generate or refine a sponsio.yaml, audit tool…

438 3d ago A 203 tokens original Apache-2.0

sponsio

15

SponsioLabs/Sponsio

Skill Claude CodeCodex

Install, observe, tune, and enforce Sponsio: a runtime contract layer for LLM agents that blocks unsafe tool calls and scores output quality against declared rules. Use when the user wants to set up / add / install Sponsio, add guardrails or runtime safety to an LLM agent, generate or refine a sponsio.yaml, audit tool…

438 3d ago A 203 tokens original Apache-2.0

reins

16

pegasi-ai/reins

Skill Claude CodeCodex

Use whenever security, policies, governance, guardrails, compliance, or safety are relevant — including blocked commands, audit trails, dangerous operations, deletions, file modifications, shell commands, MCP access, API calls, network requests, credentials, or any action that could be irreversible or destructive.

408 3mo ago C 58 tokens original Apache-2.0

reins

17

pegasi-ai/reins

Skill Claude CodeCodex

Use this skill whenever security, policies, governance, guardrails, compliance, or safety are relevant — including blocked commands, audit trails, dangerous operations, deletions, file modifications, shell commands, MCP access, API calls, network requests, credentials, or any action that could be irreversible or…

408 3mo ago C 90 tokens original Apache-2.0

api-caller

18

NVIDIA/SkillEvaluator

Skill Claude CodeCodex

Call any REST API dynamically. Make GET, POST, PUT, DELETE requests to any endpoint with custom headers and JSON body.

357 2d ago A 29 tokens original Apache-2.0

calculator

19

NVIDIA/SkillEvaluator

Skill Claude CodeCodex

Evaluate mathematical expressions and unit conversions. Handles arithmetic, percentages, exponents, and common unit conversions (temperature, distance, weight). No external dependencies.

357 2d ago A 32 tokens original Apache-2.0

NVIDIA/SkillEvaluator

Skill Claude CodeCodex

Use when converting an existing benchmark, rubric, verifier, task YAML/JSON, or domain check into SkillEvaluator BYOG/BYOT custom evaluation.

357 2d ago A 35 tokens original Apache-2.0

prismor

21

PrismorSec/prismor

Skill Claude CodeCodex

Runtime security for AI coding agents. Use when about to install a package, paste a secret, run a destructive command, reach an unfamiliar host, govern MCP servers, set up a new workspace, or recover from a Prismor block.

336 yesterday D 51 tokens original Apache-2.0

Asymptote-Labs/agent-beacon

Skill Claude CodeCodex

Verify a Beacon change end to end by running a real Claude Code session inside a disposable Linux cloud sandbox and checking that Beacon captured what the agent actually did. Use when asked to verify, validate, test, or prove that a Beacon change works for real rather than just compiling; when asked whether telemetry…

319 yesterday A 114 tokens original MIT

behavior-verifier

23

open-agent-ai-security/praxen

Skill Claude CodeCodex

Run a Praxen behavior analysis against an AI agent — or author the Worker Remit that drives one. Praxen verifies intended vs observed behavior by comparing an agent's declared policy (Worker Remit) against available evidence — source code, live deployment state (memory files, logs, configs), governance docs, or…

59 2d ago C 184 tokens original Apache-2.0

clawseccheck

24

gl0di/clawseccheck

Skill Claude CodeCodex

Free, local security self-audit for your own OpenClaw agent. Reads your OpenClaw config, bootstrap files, log files, agent session logs, and installed skills — read-only against your OpenClaw setup, plus a bounded host-security scan; writes only its own local report/history (removable with --purge). Scores your setup…

58 24d ago A 203 tokens original MIT