audit skills

523 tagged audit, measured the same way as everything else here.

Browse within: compliance 79accessibility 64enterprise 39core-web-vitals 35crawler 35cmmc 30fedramp 30code-quality 29owasp 27gateway 19hardening 19matrix 19pentest 19threat-modeling 17

edgeone-clawscan

01

Tencent/AI-Infra-Guard

Skill Claude CodeCodex

The first security skill to install after setting up OpenClaw — powered by Tencent Zhuque Lab. Works like an antivirus for your AI environment: audits installed skills, scans skills before installation, and performs a full OpenClaw security health check to prevent data leaks and privacy risks. Backed by Tencent Zhuque…

6.1k 4d ago A 236 tokens original Apache-2.0

Tencent/AI-Infra-Guard

Skill Claude CodeCodex

Scan any agent skill for security risks before you install or use it. Powered by Tencent Zhuque Lab A.I.G (AI-Infra-Guard). 100% local static analysis — no file contents or credentials leave your device. Compatible with CodeBuddy, Cursor, Windsurf, Claude Code, OpenClaw and more. Triggers on: 这个 skill 安全吗, skill 安全扫描…

6.1k 4d ago A 148 tokens original Apache-2.0

intuitem/ciso-assistant-community

Skill Claude CodeCodex

Guide users through a basic risk assessment workflow in CISO Assistant, from asset identification to scenario creation. Use when: (1) User wants to start a risk assessment from scratch (2) User mentions "risk assessment", "identify risks", "threat scenarios", or "risk register" (3) User asks about qualitative vs…

4.4k 2d ago A 138 tokens

mapping-builder

04

intuitem/ciso-assistant-community

Skill Claude CodeCodex

Build a reviewed crosswalk (RequirementMappingSet YAML library + review xlsx/csv) between two CISO Assistant framework YAML files using Claude itself as the reasoning engine. Zero infrastructure — stdlib + pyyaml only, no embedders, no LM Studio, no Qdrant. Use when the user asks to map / crosswalk / generate a…

4.4k 2d ago A 164 tokens

intuitem/ciso-assistant-community

Skill Claude CodeCodex

Enrich a CISO Assistant framework YAML by linking each assessable requirement to reference control URNs from the central doc-pol library (CISO Assistant Key Reference Controls). Produces a reviewable xlsx and patches the framework YAML in place. Use when the user asks to "add reference controls to framework X", "link…

4.4k 2d ago A 102 tokens

AgentEra/Agently

Skill Claude CodeCodex

Audit a vendor agreement or contract: extract key clauses, check that required clause categories are present, flag compliance gaps and risks, and emit a structured audit summary. Use for compliance, contract review, audit, and vendor agreement requests.

1.6k 3d ago A 50 tokens original Apache-2.0

waynesutton/convexskills

Skill Claude CodeCodex

Deep security review patterns for authorization logic, data access boundaries, action isolation, rate limiting, and protecting sensitive operations.

405 6mo ago A 28 tokens original Apache-2.0

flounder

09

adshao/flounder

Skill Claude CodeCodex

Operates Flounder, an autonomous white-hat security auditor. Use when a user asks for a security audit, bug-bounty review, vulnerability investigation, or exploit proof for a public-source or authorized repository, source tree, package, smart contract, Solidity/EVM project, ZK or proof-system code, deployed address…

329 4d ago A 202 tokens AGPL-3.0

docs-audit

10

ChanningLua/prax-agent

Skill Claude CodeCodex

A scheduled review that looks for documentation that may no longer match recently changed source code. It examines Git history and searches documentation for references to changed files or names.

272 1mo ago A 30 tokens original MIT

audit-website

11

squirrelscan/squirrelscan

Skill Claude CodeCodex

Audit a website with the squirrelscan CLI and fix the findings in code. Runs SEO, performance, security, technical, content, accessibility, and 15 other rule categories (260+ rules), returns an LLM-optimized report, then drives an iterative fix loop, mapping issues to source files, applying fixes, and re-auditing…

264 4d ago A 94 tokens original MIT

squirrelscan

12

squirrelscan/squirrelscan

Skill Claude CodeCodex

Skill "squirrelscan" from squirrelscan/squirrelscan, covering squirrelscan cli, links, install, command overview and quickstart.

264 4d ago A 101 tokens original MIT

contribute-spec-fix

13

jentic/jentic-one

Skill Claude CodeCodex

Fix a broken OpenAPI spec in jentic-public-apis with an OpenAPI Overlay, validate it (spectral lint + idempotency check), and contribute it back via a PR to the community catalog. Falls back to applying the same overlay to the local Jentic registry if the user can't wait for maintainer approval, and closes the loop by…

173 3d ago A 138 tokens original Apache-2.0

init-design

14

jentic/jentic-one

Skill Claude CodeCodex

Set up and carry out a new design in docs/design/designs/ /. Follows the conventions established in platform-actors — a brief README index, problem statement, scope, architecture decisions, open questions, and per-concern sub-documents. Ends with scaffolded stubs for each planned document.

173 3d ago A 0 tokens original Apache-2.0

jentic

15

jentic/jentic-one

Skill Claude CodeCodex

Use this skill whenever the user wants to work with a third-party or external API/tool through the Jentic platform — e.g. asks to "find the vessel-tracking API and add it", "get rows from this Google Sheet", connect Slack, import/search/discover an API, integrate or automate a SaaS, pull data from a service, or call…

173 3d ago A 144 tokens original Apache-2.0

librarian

16

gebruder/wirken

Skill Claude CodeCodex

Read-only retrieval over the daily-digest kept set. Slash-invoke with /librarian ; returns items verbatim with citations.

169 2d ago A 34 tokens original MIT

lyrik

17

gebruder/wirken

Skill Claude CodeCodex

Security assessment of a codebase — minimal mode for runner validation.

169 2d ago A 15 tokens original MIT

notes

18

gebruder/wirken

Skill Claude CodeCodex

Create and manage text notes in the workspace.

169 2d ago A 10 tokens original MIT

hig-foundations

19

raintree-technology/hig-doctor

Skill Claude CodeCodex

Apple Human Interface Guidelines design foundations. Use this skill when the user asks about "HIG color", "Apple typography", "SF Symbols", "dark mode guidelines", "accessible design", "Apple design foundations", "app icon", "layout guidelines", "materials", "motion", "privacy", "right to left", "RTL", "inclusive…

121 +1 yesterday A 182 tokens original MIT

hig-patterns

20

raintree-technology/hig-doctor

Skill Claude CodeCodex

Apple Human Interface Guidelines interaction and UX patterns. Use this skill when the user asks about "onboarding flow", "user onboarding", "app launch", "loading state", "drag and drop", "search pattern", "settings design", "notifications", "modality", "multitasking", "feedback pattern", "haptics", "undo redo", "file…

121 +1 yesterday A 205 tokens original MIT

hig-project-context

21

raintree-technology/hig-doctor

Skill Claude CodeCodex

Create or update a shared Apple design context document that other HIG skills use to tailor guidance. Use when the user says "set up my project context," "what platforms am I targeting," "configure HIG settings," or when starting a new Apple platform project. Also activates when other HIG skills need project context…

121 +1 yesterday A 113 tokens original MIT

anti-lie

22

lc198707/anti-lie

Skill Claude CodeCodex

Use when audited OpenClaw conversations or outgoing Feishu/Slack/channel messages contain concrete business numbers such as revenue, percentages, stock prices, contract values, costs, market share, or funding and need evidence checks plus red/yellow/green audit stamps after sends.

89 3mo ago A 57 tokens

dependency-audit

23

BARMPlus/locklens

Skill Claude CodeCodex

A security review of project dependencies managed by npm, Yarn, or pnpm. It can inspect a local project directory or a remote Git repository for known dependency risks.

84 3mo ago A 56 tokens original MIT

cairo-auditor

24

keep-starknet-strange/starknet-agentic

Skill Claude CodeCodex

Security audit of Cairo/Starknet code. Trigger on "audit", "check this contract", "review for security". Modes - default (full repo), deep (+ adversarial reasoning), or specific filenames.

80 3d ago A 47 tokens original MIT