Topic · Security
Best prompt injection and agent security skills for Claude Code, Codex and other agents.
- skills
- 157
- official
- 5
Prompt injection and agent security skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT. | NVIDIA/ | 20k | 1 repo | ~1.8k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 2 | Scan agent skills for security issues. An agent skill from getsentry/skills. | getsentry/ | 1k | 4 repos | ~2.5k | Automated safety check: Warn | Apache-2.0 | 5 days ago |
| 3 | Probes an AI agent through dialogue for cross-user data access, privilege escalation and login bypass, and reports confirmed findings as structured vulnerability entries. | Tencent/ | 6.8k | — | ~753 | Automated safety check: Pass | Apache-2.0 | today |
| 4 | Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics. | alexgreensh/ | 188 | — | ~2.5k | Automated safety check: Notes | Unknown | 11 days ago |
| 5 | Run HOL Guard scanner and guard operations via uv run hol-guard. | hashgraph-online/ | 815 | — | ~542 | Automated safety check: Pass | Apache-2.0 | today |
| 6 | Investigate and harden Skylos security behavior. An agent skill from duriantaco/skylos. | duriantaco/ | 843 | — | ~545 | Automated safety check: Pass | Apache-2.0 | today |
| 7 | Run a pre-deployment security compliance checklist based on KISA guidelines. | cdppcorp/ | 361 | — | ~1.3k | Automated safety check: Pass | MIT | 6 mo ago |
| 8 | 8.Setup Install or initialize HOL Guard local runtime protection for Claude Code. | hashgraph-online/ | 815 | — | ~443 | Automated safety check: Pass | Apache-2.0 | today |
| 9 | Comprehensive security review framework for AI agents. An agent skill from slowmist/slowmist-agent-security. | slowmist/ | 508 | — | ~1.4k | Automated safety check: Pass | MIT | 5 mo ago |
| 10 | Applies the AI SAFE2 framework to security reviews, code reviews and compliance mapping for AI agents, RAG pipelines and MCP servers. | CyberStrategyInstitute/ | 146 | — | ~1.2k | Automated safety check: Pass | Unknown | today |
| 11 | 按中国法规(网安法 / PIPL / 等保2.0 / 数据出境 / AI生成内容标识)审计一个 AI 项目的代码仓库,产出每条都带 文件:行 取证、经独立复核、经脚本校验的合规报告。当用户问「这个项目上线合不合规」「调用了 OpenAI/Claude 算不算数据出境」「要不要做 AI 标识」「帮我做合规自查/等保/PIPL 检查」时使用。Audit an AI project's… | jnMetaCode/ | 140 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | 9 days ago |
| 12 | 12.Sail Apply the SAIL (Secure AI Lifecycle) V2 framework by Pillar Security to secure AI applications and agents. | pillar-labs/ | 113 | — | ~5.1k | Automated safety check: Pass | Unknown | 3 mo ago |
| 13 | Installs hooks that check each agent action against security policies before it runs, blocking destructive commands and logging every decision. | pegasi-ai/ | 392 | — | ~1.4k | Automated safety check: Warn | Apache-2.0 | 4 mo ago |
| 14 | Probes an AI agent through dialogue to check whether its file, code-execution or network tools can be misused to run unexpected code or reach outside targets. | Tencent/ | 6.8k | — | ~1.5k | Automated safety check: Notes | Apache-2.0 | today |
| 15 | 15.Clawscan CLI A skill your agent uses when running or explaining the ClawScan CLI, including one-off agent-skill scans, benchmark runs, scanner fixtures, judge harness commands, env var validation, and… | openclaw/ | 142 | — | ~3k | Automated safety check: Pass | MIT | yesterday |
| 16 | Guide for writing eval conversation JSONs and running them through policy engines | open-bias/ | 143 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 17 | Tells a model how to treat the tagged double-brace placeholders that Maskit's local privacy gateway substitutes for sensitive text, so tokens are copied exactly instead of guessed, split or faked. | xiaYuTian11/ | 295 | — | ~718 | Automated safety check: Pass | AGPL-3.0 | 3 days ago |
| 18 | 18.Gsd Browser Native Rust browser automation CLI for AI agents. An agent skill from gsd-build/gsd-browser. | gsd-build/ | 268 | — | ~7.5k | Automated safety check: Pass | Apache-2.0 | 5 mo ago |
| 19 | 19.Kesekit Fix Auto-fix security vulnerabilities found in CII, AI, robot, space, and supply chain systems. | cdppcorp/ | 361 | — | ~1.1k | Automated safety check: Pass | MIT | 6 mo ago |
| 20 | 20.Status Check HOL Guard local protection status for Claude Code without changing configuration. | hashgraph-online/ | 815 | — | ~231 | Automated safety check: Pass | Apache-2.0 | today |
| 21 | Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings. | trailofbits/ | 7.4k | 6 repos | ~5.4k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 22 | Probes whether an agent with web fetch and stored user memory can be tricked by a malicious page into leaking data through chained URL paths. | Tencent/ | 6.8k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | today |
| 23 | A skill your agent uses when a researcher, maintainer, or contributor found or suspects a malicious skill on ClawHub and needs a private reporting workflow: opening a GitHub private vulnerability… | openclaw/ | 142 | — | ~1.1k | Automated safety check: Pass | MIT | yesterday |
| 24 | 24.Secureclaw Security hardening toolkit for OpenClaw. An agent skill from adversa-ai/secureclaw. | adversa-ai/ | 348 | 1 repo | ~193 | Automated safety check: Pass | MIT | 5 mo ago |
| 25 | Probes whether an agent can be hijacked by instructions hidden in documents, retrieved chunks or fetched web pages, using test prompts that embed a hidden instruction. | Tencent/ | 6.8k | — | ~1.1k | Automated safety check: Warn | Apache-2.0 | today |
| 26 | Route wording work to GPT (codex CLI) or Gemini (agy CLI) instead of writing it with Claude — landing-page copy, a readability rewrite of a README or docs page, attack and judge prompts for a rule… | guardana/ | 129 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 27 | A skill your agent uses when an OpenClaw maintainer or owner is reviewing a ClawHub malicious-skill profile proposal PR: checking proposals/<GHSA-ID/clawscan.yml, reading the private vulnerability… | openclaw/ | 142 | — | ~1.9k | Automated safety check: Pass | MIT | yesterday |
| 28 | Plan, execute, document, and retest authorized security assessments of AI agents and multi-agent workflows using safe adversarial cases, synthetic identities, canaries, and evidence-based findings. | seb1n/ | 206 | — | ~2.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 29 | Generate secure coding prompts and guides for AI tools (Claude, ChatGPT, Cursor, Copilot). | cdppcorp/ | 361 | — | ~1.4k | Automated safety check: Pass | MIT | 6 mo ago |
| 30 | 30.Ship Commit and push a finished change the way this repo requires — explicit paths, one commit per logical change, no attribution, the five documentation places answered, the site checks before a push (a… | guardana/ | 129 | — | ~836 | Automated safety check: Notes | Apache-2.0 | yesterday |
| 31 | Use HOL Guard to preview and protect AI-agent package installs, Cursor surfaces, CI, and automation workflows. | hashgraph-online/ | 815 | — | ~605 | Automated safety check: Pass | Apache-2.0 | today |
| 32 | Static safety audit of a SKILL.md that scores five dimensions and acts as a gate: skills below the pass line do not ship, whatever else they score. | openJiuwen-ai/ | 442 | — | ~3.5k | Automated safety check: Warn | Apache-2.0 | today |
| 33 | Finds security threats in a design with a STRIDE pass per component, rates severity and records fixes, with extra checks for AI agent and tool risks. | dralgorhythm/ | 125 | — | ~581 | Automated safety check: Pass | No licence | 2 mo ago |
| 34 | Applies the AI SAFE2 v3.1 governance framework to designing, building, auditing and testing AI agents, RAG pipelines, MCP and tool integrations and AI infrastructure. | CyberStrategyInstitute/ | 146 | — | ~2.7k | Automated safety check: Pass | Unknown | today |
| 35 | Refreshes the guide's coding-agent and MCP security threat data through AgentSec Triage: research advisories, add tested records and synchronize the public feed. | FlorianBruniaux/ | 6.1k | — | ~680 | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 36 | Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them. | iflytek/ | 5.2k | 2 repos | ~1.1k | Automated safety check: Notes | Apache-2.0 | today |
| 37 | Run a security vulnerability assessment based on KISA guidelines. | cdppcorp/ | 361 | — | ~2.3k | Automated safety check: Pass | MIT | 6 mo ago |
| 38 | 38.Agent Wallet Give the AI agent its own EVM wallet with admin-controlled policies the agent CANNOT bypass even under prompt injection. | internet-court/ | 6.4k | 2 repos | ~4.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 39 | Report/investigate RUNTIME ACTIVITY of AI agents (Agent 365 / Copilot Studio / M365 Copilot / Work IQ) — agents used, tools/connectors, channels, tokens, prompt/reply content, and Prompt Shield… | SCStelz/ | 249 | — | ~17k | Automated safety check: Pass | MIT | 2 days ago |
| 40 | 40.Add A Rule Add security coverage to Guardana the way this repository requires — as a rule, evaluator or target, never by patching the engine — with the fixtures, the framework mapping and the documentation… | guardana/ | 129 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 41 | OpenClaw 安全部署指南 / Security deployment guide — help users secure their OpenClaw installation | jnMetaCode/ | 140 | — | ~644 | Automated safety check: Warn | Apache-2.0 | 9 days ago |
| 42 | AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents | Hack23/ | 239 | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 43 | Detect error propagation, chain failures, and single-point breakdowns that cascade across agent workflows. | Tencent/ | 6.8k | — | ~593 | Automated safety check: Pass | Apache-2.0 | today |
| 44 | Audit AI agent configurations for security risks — excessive permissions, prompt injection surfaces, data exfiltration paths, and missing guardrails. | OWASP/ | 187 | — | ~542 | Automated safety check: Pass | CC-BY-4.0 | 13 days ago |
| 45 | A skill your agent uses when reviewing an agent Skill before sharing, installing, or executing it and when checking a Skill bundle for credentials, dangerous commands, suspicious network behavior… | zrt-ai-lab/ | 287 | — | ~317 | Automated safety check: Pass | No licence | 2 mo ago |
| 46 | Audit or report on AI agent security posture across Copilot Studio, Microsoft 365 Copilot, Microsoft Foundry, and third-party agents. | SCStelz/ | 249 | — | ~21k | Automated safety check: Pass | MIT | 2 days ago |
| 47 | 47.Auto Autonomous, non-interactive run of the whole lifecycle for one development task — size, plan, build, gate, review, fix, commit — without stopping for questions. | guardana/ | 129 | — | ~792 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 48 | Audit agent skills, plugins, prompts, manifests, scripts, dependencies, and bundled assets for provenance, prompt-injection, permission, execution, exfiltration, persistence, and update risk. | seb1n/ | 206 | — | ~2.4k | Automated safety check: Pass | MIT | 1 mo ago |
Questions, answered from the data.
What is the best prompt injection and agent security skill?
Skill Inspector (official) from NVIDIA/SkillSpector ranks first of the 157 prompt injection and agent security skills listed here, with the highest score: its repository has 20k GitHub stars, 1 other GitHub owner carry a copy, its SKILL.md loads about 1.8k tokens and it passes the automated safety check with no findings. Next come Skill Scanner and Authorization Bypass Detection.
Which prompt injection and agent security skills are official?
5 of the 157 prompt injection and agent security skills are official, published by the vendor's own GitHub organization: Skill Inspector, Skill Scanner, Agentic GitHub Actions Auditor, Agent Owasp Compliance and Remediating With AWS Security Agent.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.
Explore related skills
Category
More topics in Security
- Security review636
- Web application vulnerabilities467
- Vulnerability scanning304
- Static analysis and SAST283
- Security operations246
- Supply chain security233
- Threat modeling228
- Penetration testing182
- Cryptography159
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38