Reduce risk

Best security and compliance skills for AI agents

Explore skills for vulnerability checks, secret scanning, dependency review, policy validation, and security-aware automation.

Builders choosing skills for scan dependencies and find exposed secrets. Ranked from the OpenAgentSkill index using quality, trust, freshness, adoption, and install readiness.

30
Ranked
333K
Stars
100
Top trust

Workflow

Scan dependencies

Workflow

Find exposed secrets

Workflow

Review security findings

#1

Vuls

26 fitTrust 100Excellent 100

Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices

Excellent quality, 12K stars, and a 26 use-case fit score.

12K starsJun 5, 2026 pushProduction candidateGoSecurity
$ npx skills add future-architect/vuls
#2

Brakeman

25 fitTrust 100Excellent 100

A static analysis security vulnerability scanner for Ruby on Rails applications

Excellent quality, 7.2K stars, and a 25 use-case fit score.

7.2K starsJun 12, 2026 pushProduction candidateRubyStatic Analysis
$ npx skills add presidentbeef/brakeman
#3

Nuclei

24 fitTrust 100Excellent 100

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.

Excellent quality, 29K stars, and a 24 use-case fit score.

29K starsJun 4, 2026 pushProduction candidateGoSecurity
$ npx skills add projectdiscovery/nuclei
#4

Lynis

23 fitTrust 100Excellent 100

Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.

Excellent quality, 16K stars, and a 23 use-case fit score.

16K starsMay 11, 2026 pushProduction candidateShellCompliance
$ npx skills add CISOfy/lynis
#5

Grype

23 fitTrust 100Excellent 100

A vulnerability scanner for container images and filesystems

Excellent quality, 12K stars, and a 23 use-case fit score.

12K starsJun 9, 2026 pushProduction candidateGoStatic Analysis
$ npx skills add anchore/grype
#6

Opa

23 fitTrust 100Excellent 100

Open Policy Agent (OPA) is an open source, general-purpose policy engine.

Excellent quality, 12K stars, and a 23 use-case fit score.

12K starsJun 12, 2026 pushProduction candidateGoCompliance
$ npx skills add open-policy-agent/opa
#7

Kyverno

22 fitTrust 100Excellent 100

Unified Policy as Code

Excellent quality, 7.8K stars, and a 22 use-case fit score.

7.8K starsJun 8, 2026 pushProduction candidateGoCompliance
$ npx skills add kyverno/kyverno
#8

Skills

22 fitTrust 100Excellent 100

Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows

Excellent quality, 5.7K stars, and a 22 use-case fit score.

5.7K starsJun 11, 2026 pushProduction candidatePythonAI Agents
$ npx skills add trailofbits/skills
#9

DeepAudit

22 fitTrust 100Excellent 100

DeepAudit:人人拥有的 AI 黑客战队,让漏洞挖掘触手可及。国内首个开源的代码漏洞挖掘多智能体系统。小白一键部署运行,自主协作审计 + 自动化沙箱 PoC 验证。支持 Ollama 私有部署 ,一键生成报告。支持中转站。​让安全不再昂贵,让审计不再复杂。

Excellent quality, 6.4K stars, and a 22 use-case fit score.

6.4K starsApr 1, 2026 pushProduction candidatePythonSAST
$ npx skills add lintsinghua/DeepAudit
#10

Bearer

21 fitTrust 100Excellent 100

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Excellent quality, 2.7K stars, and a 21 use-case fit score.

2.7K starsJun 8, 2026 pushProduction candidateGoSAST
$ npx skills add Bearer/bearer
#11

Promptfoo

20 fitTrust 100Excellent 100

Test your prompts, agents, and RAGs. Red teaming/pentesting/vulnerability scanning for AI. Compare performance of GPT, Claude, Gemini, DeepSeek, and more. Simple declarative configs with command line and CI/CD integration. Used by OpenAI and Anthropic.

Excellent quality, 22K stars, and a 20 use-case fit score.

22K starsJun 13, 2026 pushProduction candidateTypeScriptRAG
$ npx skills add promptfoo/promptfoo
#12

Claude Skills

20 fitTrust 100Excellent 100

337 Claude Code skills & agent skills & plugins (30+ Agents, 70+ custom commands, 330+ skills, customizable references, scripts)for Claude Code, Codex, Gemini CLI, Cursor, and 8 more coding agents — engineering, marketing, product, compliance, C-level advisory, research, business operations, commercial & finance, and your daily productivity skills.

Excellent quality, 18K stars, and a 20 use-case fit score.

18K starsJun 12, 2026 pushProduction candidatePythonAI Agents
$ npx skills add alirezarezvani/claude-skills
#13

Edict

20 fitTrust 100Excellent 100

🏛️ 三省六部制 · OpenClaw Multi-Agent Orchestration System — 9 specialized AI agents with real-time dashboard, model config, and full audit trails

Excellent quality, 16K stars, and a 20 use-case fit score.

16K starsJun 4, 2026 pushProduction candidatePythonAI Agents
$ npx skills add cft0808/edict
#14

Wazuh

20 fitTrust 100Excellent 100

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

Excellent quality, 16K stars, and a 20 use-case fit score.

16K starsJun 12, 2026 pushProduction candidateC++Compliance
$ npx skills add wazuh/wazuh
#15

Semgrep

20 fitTrust 100Excellent 100

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Excellent quality, 15K stars, and a 20 use-case fit score.

15K starsJun 12, 2026 pushProduction candidateOCamlSAST
$ npx skills add semgrep/semgrep
#16

Zaproxy

20 fitTrust 100Excellent 100

The ZAP by Checkmarx Core project

Excellent quality, 15K stars, and a 20 use-case fit score.

15K starsJun 4, 2026 pushProduction candidateJavaSecurity
$ npx skills add zaproxy/zaproxy
#17

Clair

20 fitTrust 100Excellent 100

Vulnerability Static Analysis for Containers

Excellent quality, 11K stars, and a 20 use-case fit score.

11K starsJun 4, 2026 pushProduction candidateGoStatic Analysis
$ npx skills add quay/clair
#18

Bbot

19 fitTrust 100Excellent 100

The recursive internet scanner for hackers. 🧡

Excellent quality, 9.9K stars, and a 19 use-case fit score.

9.9K starsJun 12, 2026 pushProduction candidatePythonOSINT
$ npx skills add blacklanternsecurity/bbot
#19

Wpscan

19 fitTrust 100Excellent 100

WPScan WordPress security scanner. Written for security professionals and blog maintainers to test the security of their WordPress websites. Contact us via contact@wpscan.com

Excellent quality, 9.6K stars, and a 19 use-case fit score.

9.6K starsJun 4, 2026 pushProduction candidateRubySecurity
$ npx skills add wpscanteam/wpscan
#20

Sealed Secrets

19 fitTrust 100Excellent 100

A Kubernetes controller and tool for one-way encrypted Secrets

Excellent quality, 9.1K stars, and a 19 use-case fit score.

9.1K starsJun 2, 2026 pushProduction candidateGoKubernetes
$ npx skills add bitnami-labs/sealed-secrets
#21

Scanners Box

19 fitTrust 100Excellent 100

A powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑

Excellent quality, 8.9K stars, and a 19 use-case fit score.

8.9K starsJun 10, 2026 pushProduction candidateStatic AnalysisClaude Code
$ npx skills add We5ter/Scanners-Box
#22

Cloudnative Pg

19 fitTrust 100Excellent 100

CloudNativePG is a comprehensive platform designed to seamlessly manage PostgreSQL databases within Kubernetes environments, covering the entire operational lifecycle from initial deployment to ongoing maintenance

Excellent quality, 8.8K stars, and a 19 use-case fit score.

8.8K starsJun 12, 2026 pushProduction candidateGoKubernetes
$ npx skills add cloudnative-pg/cloudnative-pg
#23

Checkov

19 fitTrust 100Excellent 100

Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.

Excellent quality, 8.8K stars, and a 19 use-case fit score.

8.8K starsJun 11, 2026 pushProduction candidatePythonKubernetes
$ npx skills add bridgecrewio/checkov
#24

OneForAll

19 fitTrust 100Excellent 100

OneForAll是一款功能强大的子域收集工具

Excellent quality, 9.8K stars, and a 19 use-case fit score.

9.8K starsMay 11, 2026 pushProduction candidatePythonOSINT
$ npx skills add shmilylty/OneForAll
#25

Bandit

19 fitTrust 100Excellent 100

Bandit is a tool designed to find common security issues in Python code.

Excellent quality, 8.1K stars, and a 19 use-case fit score.

8.1K starsMay 25, 2026 pushProduction candidatePythonSecurity
$ npx skills add PyCQA/bandit
#26

Visual Explainer

19 fitTrust 100Excellent 100

Agent skill that generates rich HTML pages or slide decks for diagrams, diff reviews, plan audits, data tables, and project recaps

Excellent quality, 8.7K stars, and a 19 use-case fit score.

8.7K starsApr 27, 2026 pushProduction candidateHTMLAI Agents
$ npx skills add nicobailon/visual-explainer
#27

Dependency Cruiser

19 fitTrust 100Excellent 100

Validate and visualize dependencies. Your rules. JavaScript, TypeScript, CoffeeScript. ES6, CommonJS, AMD.

Excellent quality, 6.8K stars, and a 19 use-case fit score.

6.8K starsJun 11, 2026 pushProduction candidateJavaScriptStatic Analysis
$ npx skills add sverweij/dependency-cruiser
#28

Cloudquery

19 fitTrust 100Excellent 100

Data pipelines for cloud config and security data. Build cloud asset inventory, CSPM, FinOps, and vulnerability management solutions. Extract from AWS, Azure, GCP, and 70+ cloud and SaaS sources.

Excellent quality, 6.4K stars, and a 19 use-case fit score.

6.4K starsJun 11, 2026 pushProduction candidateGoData Analysis
$ npx skills add cloudquery/cloudquery
#29

Tfsec

19 fitTrust 100Excellent 100

Tfsec is now part of Trivy

Excellent quality, 7.0K stars, and a 19 use-case fit score.

7.0K starsMar 25, 2026 pushProduction candidateGoStatic Analysis
$ npx skills add aquasecurity/tfsec
#30

Cloud Custodian

19 fitTrust 100Excellent 100

Rules engine for cloud security, cost optimization, and governance, DSL in yaml for policies to query, filter, and take actions on resources

Excellent quality, 6.0K stars, and a 19 use-case fit score.

6.0K starsJun 10, 2026 pushProduction candidatePythonCompliance
$ npx skills add cloud-custodian/cloud-custodian

Selection method

How this list is ranked

OpenAgentSkill scores each candidate against the workflow keywords, then balances fit with GitHub stars, quality signals, trust profile, maintenance freshness, and whether there is a clear install path.

How does OpenAgentSkill rank security and compliance?

The ranking combines workflow fit, quality score, trust profile, GitHub adoption, maintenance freshness, and whether a clear install path exists.

Should I install the top skill immediately?

No. Treat the list as a shortlist, open the skill detail page, inspect the repository and license, then test the install command in a sandbox workflow.

Can my agent consume this ranking through an API?

Yes. Use /api/skills/search with the related task or /api/agent/rankings?slug=best-security-compliance-skills to fetch ranked skill data.