Security agent skills

Security and compliance skills for AI agents.

Compare skills for vulnerability scanning, secret detection, dependency review, policy checks, audit notes, and security-aware workflows.

Built for teams looking for AI agent skills that can help scan projects, summarize risks, and prepare reviewable remediation steps.

Matched

16

Stars

284K

Workflow

Scan

Output

Risk notes

Agent jobs

Start from a real workflow, not a keyword.

These pages are built for high-intent search and for agents that need a structured shortlist with install commands, trust signals, audit links, and real outcome evidence before installing third-party code.

01

Scan repositories for common risky patterns

02

Summarize dependency and secret scanning results

03

Prepare remediation steps for maintainers

04

Add policy-aware checks before installing third-party skills

Ranked shortlist

High-signal skills to inspect first.

Open best list

#01

Vuls

12K stars

Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices

100

Quality

88

Trust

โ€”

Proven

securityJun 12, 2026 pushGPL-3.0Needs first agent run
$ npx skills add future-architect/vuls
11K stars

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

100

Quality

90

Trust

โ€”

Proven

securityJun 20, 2026 pushApache-2.0Needs first agent run
$ npx skills add google/osv-scanner
29K stars

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.

100

Quality

90

Trust

โ€”

Proven

securityJun 13, 2026 pushMITNeeds first agent run
$ npx skills add projectdiscovery/nuclei

#04

Opa

12K stars

Open Policy Agent (OPA) is an open source, general-purpose policy engine.

100

Quality

88

Trust

โ€”

Proven

securityJun 12, 2026 pushApache-2.0Needs first agent run
$ npx skills add open-policy-agent/opa
11K stars

Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, and clusters. It includes risk analysis, security, compliance, and misconfiguration scanning, saving Kubernetes users and administrators precious time, effort, and resources.

100

Quality

90

Trust

โ€”

Proven

devopsJun 15, 2026 pushApache-2.0Needs first agent run
$ npx skills add kubescape/kubescape
7.8K stars

Unified Policy as Code

98

Quality

87

Trust

โ€”

Proven

securityJun 8, 2026 pushApache-2.0Needs first agent run
$ npx skills add kyverno/kyverno

Evaluation

How to choose the right skill.

Distinguishes confirmed issues from warnings

Documents scanner scope and false-positive behavior

Does not expose secrets in output

Encourages review before high-stakes compliance decisions

Questions

Can these replace a formal security audit?

No. They help agents collect signals and summarize risks, but formal audits need qualified human review and organization-specific controls.

How should agents report security findings?

They should prioritize confirmed risks, avoid leaking sensitive data, and include clear remediation steps with confidence levels.