Search
Prompt injection and agent security
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT. | NVIDIA/ | 20k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 2 | Scan agent skills for security issues. An agent skill from getsentry/skills. | getsentry/ | 1k | 4 repos | ~2.5k | Automated safety check: Warn | Apache-2.0 | yesterday |
| 3 | Query AI Safety HOT news, research papers, incidents, hot topics, and daily/weekly/monthly reports through its public read-only MCP service. | wuyoscar/ | 827 | — | ~1.4k | Automated safety check: Pass | Unknown | today |
| 4 | Probes an AI agent through dialogue for cross-user data access, privilege escalation and login bypass, and reports confirmed findings as structured vulnerability entries. | Tencent/ | 6.8k | — | ~753 | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 5 | Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics. | alexgreensh/ | 190 | — | ~2.5k | Automated safety check: Notes | Unknown | 14 days ago |
| 6 | Run HOL Guard scanner and guard operations via uv run hol-guard. | hashgraph-online/ | 845 | — | ~542 | Automated safety check: Pass | Apache-2.0 | today |
| 7 | Investigate and harden Skylos security behavior. An agent skill from duriantaco/skylos. | duriantaco/ | 846 | — | ~585 | Automated safety check: Pass | Apache-2.0 | today |
| 8 | Run a pre-deployment security compliance checklist based on KISA guidelines. | cdppcorp/ | 360 | — | ~1.3k | Automated safety check: Pass | MIT | 6 mo ago |
| 9 | 9.Setup Install or initialize HOL Guard local runtime protection for Claude Code. | hashgraph-online/ | 845 | — | ~443 | Automated safety check: Pass | Apache-2.0 | today |
| 10 | Comprehensive security review framework for AI agents. An agent skill from slowmist/slowmist-agent-security. | slowmist/ | 508 | — | ~1.4k | Automated safety check: Pass | MIT | 5 mo ago |
| 11 | Applies the AI SAFE2 framework to security reviews, code reviews and compliance mapping for AI agents, RAG pipelines and MCP servers. | CyberStrategyInstitute/ | 147 | — | ~1.2k | Automated safety check: Pass | Unknown | yesterday |
| 12 | 按中国法规(网安法 / PIPL / 等保2.0 / 数据出境 / AI生成内容标识)审计一个 AI 项目的代码仓库,产出每条都带 文件:行 取证、经独立复核、经脚本校验的合规报告。当用户问「这个项目上线合不合规」「调用了 OpenAI/Claude 算不算数据出境」「要不要做 AI 标识」「帮我做合规自查/等保/PIPL 检查」时使用。Audit an AI project's… | jnMetaCode/ | 140 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | 12 days ago |
| 13 | 13.Sail Apply the SAIL (Secure AI Lifecycle) V2 framework by Pillar Security to secure AI applications and agents. | pillar-labs/ | 113 | — | ~5.1k | Automated safety check: Pass | Unknown | 3 mo ago |
| 14 | Installs hooks that check each agent action against security policies before it runs, blocking destructive commands and logging every decision. | pegasi-ai/ | 392 | — | ~1.4k | Automated safety check: Warn | Apache-2.0 | yesterday |
| 15 | Probes an AI agent through dialogue to check whether its file, code-execution or network tools can be misused to run unexpected code or reach outside targets. | Tencent/ | 6.8k | — | ~1.5k | Automated safety check: Notes | Apache-2.0 | 2 days ago |
| 16 | 16.Clawscan CLI A skill your agent uses when running or explaining the ClawScan CLI, including one-off agent-skill scans, benchmark runs, scanner fixtures, judge harness commands, env var validation, and… | openclaw/ | 143 | — | ~3k | Automated safety check: Pass | MIT | 4 days ago |
| 17 | Guide for writing eval conversation JSONs and running them through policy engines | open-bias/ | 143 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 18 | Tells a model how to treat the tagged double-brace placeholders that Maskit's local privacy gateway substitutes for sensitive text, so tokens are copied exactly instead of guessed, split or faked. | xiaYuTian11/ | 297 | — | ~718 | Automated safety check: Pass | AGPL-3.0 | yesterday |
| 19 | 19.Ship Commit and push a finished change the way this repo requires — explicit paths, one commit per logical change, no attribution, the five documentation places answered, the site checks before a push (a… | guardana/ | 259 | — | ~964 | Automated safety check: Notes | Apache-2.0 | today |
| 20 | 20.Gsd Browser Native Rust browser automation CLI for AI agents. An agent skill from gsd-build/gsd-browser. | gsd-build/ | 268 | — | ~7.5k | Automated safety check: Pass | Apache-2.0 | 5 mo ago |
| 21 | 21.Kesekit Fix Auto-fix security vulnerabilities found in CII, AI, robot, space, and supply chain systems. | cdppcorp/ | 360 | — | ~1.1k | Automated safety check: Pass | MIT | 6 mo ago |
| 22 | 22.Status Check HOL Guard local protection status for Claude Code without changing configuration. | hashgraph-online/ | 845 | — | ~231 | Automated safety check: Pass | Apache-2.0 | today |
| 23 | Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings. | trailofbits/ | 7.5k | 6 repos | ~5.4k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 24 | Probes whether an agent with web fetch and stored user memory can be tricked by a malicious page into leaking data through chained URL paths. | Tencent/ | 6.8k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 25 | A skill your agent uses when a researcher, maintainer, or contributor found or suspects a malicious skill on ClawHub and needs a private reporting workflow: opening a GitHub private vulnerability… | openclaw/ | 143 | — | ~1.1k | Automated safety check: Pass | MIT | 4 days ago |
| 26 | Probes whether an agent can be hijacked by instructions hidden in documents, retrieved chunks or fetched web pages, using test prompts that embed a hidden instruction. | Tencent/ | 6.8k | — | ~1.1k | Automated safety check: Warn | Apache-2.0 | 2 days ago |
| 27 | 27.Secureclaw Security hardening toolkit for OpenClaw. An agent skill from adversa-ai/secureclaw. | adversa-ai/ | 347 | 1 repo | ~193 | Automated safety check: Pass | MIT | 6 mo ago |
| 28 | A skill your agent uses when an OpenClaw maintainer or owner is reviewing a ClawHub malicious-skill profile proposal PR: checking proposals/<GHSA-ID/clawscan.yml, reading the private vulnerability… | openclaw/ | 143 | — | ~1.9k | Automated safety check: Pass | MIT | 4 days ago |
| 29 | Plan, execute, document, and retest authorized security assessments of AI agents and multi-agent workflows using safe adversarial cases, synthetic identities, canaries, and evidence-based findings. | seb1n/ | 206 | — | ~2.8k | Automated safety check: Pass | MIT | 2 mo ago |
| 30 | 30.Add A Rule Add security coverage to Guardana the way this repository requires — as a rule, evaluator or target, never by patching the engine — with the fixtures, the framework mapping and the documentation… | guardana/ | 259 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
| 31 | Generate secure coding prompts and guides for AI tools (Claude, ChatGPT, Cursor, Copilot). | cdppcorp/ | 360 | — | ~1.4k | Automated safety check: Pass | MIT | 6 mo ago |
| 32 | Use HOL Guard to preview and protect AI-agent package installs, Cursor surfaces, CI, and automation workflows. | hashgraph-online/ | 845 | — | ~605 | Automated safety check: Pass | Apache-2.0 | today |
| 33 | Static safety audit of a SKILL.md that scores five dimensions and acts as a gate: skills below the pass line do not ship, whatever else they score. | openJiuwen-ai/ | 446 | — | ~3.5k | Automated safety check: Warn | Apache-2.0 | today |
| 34 | Finds security threats in a design with a STRIDE pass per component, rates severity and records fixes, with extra checks for AI agent and tool risks. | dralgorhythm/ | 125 | — | ~581 | Automated safety check: Pass | No licence | 2 mo ago |
| 35 | Applies the AI SAFE2 v3.1 governance framework to designing, building, auditing and testing AI agents, RAG pipelines, MCP and tool integrations and AI infrastructure. | CyberStrategyInstitute/ | 147 | — | ~2.7k | Automated safety check: Pass | Unknown | yesterday |
| 36 | 36.Auto Autonomous, non-interactive run of the whole lifecycle for one development task — size, plan, build, gate, review, fix, commit — without stopping for questions. | guardana/ | 259 | — | ~945 | Automated safety check: Pass | Apache-2.0 | today |
| 37 | Refreshes the guide's coding-agent and MCP security threat data through AgentSec Triage: research advisories, add tested records and synchronize the public feed. | FlorianBruniaux/ | 6.1k | — | ~680 | Automated safety check: Pass | CC-BY-SA-4.0 | today |
| 38 | Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them. | iflytek/ | 5.2k | 2 repos | ~1.1k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 39 | 39.Docs Documentation work in this repo — the five places a user-visible change must answer, the page conventions the site build enforces, the tests that pin prose to the registry, and a simplification pass… | guardana/ | 259 | — | ~967 | Automated safety check: Pass | Apache-2.0 | today |
| 40 | Run a security vulnerability assessment based on KISA guidelines. | cdppcorp/ | 360 | — | ~2.3k | Automated safety check: Pass | MIT | 6 mo ago |
| 41 | Report/investigate RUNTIME ACTIVITY of AI agents (Agent 365 / Copilot Studio / M365 Copilot / Work IQ) — agents used, tools/connectors, channels, tokens, prompt/reply content, and Prompt Shield… | SCStelz/ | 249 | — | ~17k | Automated safety check: Pass | MIT | 2 days ago |
| 42 | OpenClaw 安全部署指南 / Security deployment guide — help users secure their OpenClaw installation | jnMetaCode/ | 140 | — | ~644 | Automated safety check: Warn | Apache-2.0 | 12 days ago |
| 43 | Detect error propagation, chain failures, and single-point breakdowns that cascade across agent workflows. | Tencent/ | 6.8k | — | ~593 | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 44 | AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents | Hack23/ | 239 | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | today |
| 45 | Audit AI agent configurations for security risks — excessive permissions, prompt injection surfaces, data exfiltration paths, and missing guardrails. | OWASP/ | 188 | — | ~542 | Automated safety check: Pass | CC-BY-4.0 | 15 days ago |
| 46 | A skill your agent uses when reviewing an agent Skill before sharing, installing, or executing it and when checking a Skill bundle for credentials, dangerous commands, suspicious network behavior… | zrt-ai-lab/ | 287 | — | ~317 | Automated safety check: Pass | No licence | 2 mo ago |
| 47 | Hunt for the failure this project exists to prevent — code that compiles, types, tests green, and quietly reports "all clear" about something it never examined. | guardana/ | 259 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
| 48 | Audit or report on AI agent security posture across Copilot Studio, Microsoft 365 Copilot, Microsoft Foundry, and third-party agents. | SCStelz/ | 249 | — | ~21k | Automated safety check: Pass | MIT | 2 days ago |