Security agents

Best AI agent skills for security review

Ranked OpenAgentSkill shortlist for agents that scan dependencies, review permissions, inspect secrets, summarize vulnerabilities, and prepare safe remediation steps.

Developers and security-minded teams that want agents to inspect repositories before running third-party code or shipping changes. Ranked from the OpenAgentSkill index using quality, trust, freshness, adoption, and install readiness.

best AI agent skills for security reviewAI agents
30
Ranked
720K
Stars
94
Top trust

Search intent

Find AI agent skills for vulnerability scanning, secret review, dependency risk, security audit notes, and safe remediation workflows.

These pages are generated from real registry records. The list below is not a generic article; every row links to a skill profile with install, trust, audit, and risk fields.

#1

Lynis

26 fitTrust 94Excellent 100Audit 93 · Safe to try

Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.

Excellent quality, 16K stars, and a 26 use-case fit score.

Best suited scenario

Inspect risky files

16K starsMay 11, 2026 pushProduction candidateShellSecurity
$ npx skills add CISOfy/lynis
#2

Vuls

26 fitTrust 96Excellent 100Audit 95 · Safe to try

Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices

Excellent quality, 12K stars, and a 26 use-case fit score.

Best suited scenario

Inspect risky files

12K starsJun 12, 2026 pushProduction candidateGoSecurity
$ npx skills add future-architect/vuls
#3

Brakeman

25 fitTrust 90Excellent 100Audit 93 · Safe to try

A static analysis security vulnerability scanner for Ruby on Rails applications

Excellent quality, 7.2K stars, and a 25 use-case fit score.

Best suited scenario

Inspect risky files

7.2K starsJun 15, 2026 pushProduction candidateRubyStatic Analysis
$ npx skills add presidentbeef/brakeman
#4

Nuclei

24 fitTrust 98Excellent 100Audit 96 · Safe to try

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.

Excellent quality, 29K stars, and a 24 use-case fit score.

Best suited scenario

Inspect risky files

29K starsJun 13, 2026 pushProduction candidateGoSecurity
$ npx skills add projectdiscovery/nuclei
#5

Grype

23 fitTrust 94Excellent 100Audit 95 · Safe to try

A vulnerability scanner for container images and filesystems

Excellent quality, 12K stars, and a 23 use-case fit score.

Best suited scenario

Inspect source files

12K starsJun 12, 2026 pushProduction candidateGoStatic Analysis
$ npx skills add anchore/grype
#6

Opa

23 fitTrust 95Excellent 100Audit 95 · Safe to try

Open Policy Agent (OPA) is an open source, general-purpose policy engine.

Excellent quality, 12K stars, and a 23 use-case fit score.

Best suited scenario

Inspect risky files

12K starsJun 12, 2026 pushProduction candidateGoCompliance
$ npx skills add open-policy-agent/opa
#7

Kubescape

23 fitTrust 97Excellent 100Audit 96 · Safe to try

Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, and clusters. It includes risk analysis, security, compliance, and misconfiguration scanning, saving Kubernetes users and administrators precious time, effort, and resources.

Excellent quality, 11K stars, and a 23 use-case fit score.

Best suited scenario

Inspect risky files

11K starsJun 15, 2026 pushProduction candidateGoKubernetes
$ npx skills add kubescape/kubescape
#8

Immudb

22 fitTrust 91Excellent 100Audit 93 · Safe to try

immudb - immutable database based on zero trust, SQL/Key-Value/Document model, tamperproof, data change history

Excellent quality, 9.0K stars, and a 22 use-case fit score.

Best suited scenario

Extract obligations

9.0K starsJun 1, 2026 pushProduction candidateGoGDPR
$ npx skills add codenotary/immudb
#9

Kyverno

22 fitTrust 94Excellent 100Audit 95 · Safe to try

Unified Policy as Code

Excellent quality, 7.8K stars, and a 22 use-case fit score.

Best suited scenario

Inspect risky files

7.8K starsJun 8, 2026 pushProduction candidateGoCompliance
$ npx skills add kyverno/kyverno
#10

Skills

22 fitTrust 96Excellent 100Audit 96 · Safe to try

Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows

Excellent quality, 5.8K stars, and a 22 use-case fit score.

Best suited scenario

Inspect source files

5.8K starsJun 15, 2026 pushProduction candidatePythonAI Agents
$ npx skills add trailofbits/skills
#11

Caddy

22 fitTrust 94Excellent 100Audit 95 · Safe to try

Fast and extensible multi-platform HTTP/1-2-3 web server with automatic HTTPS

Excellent quality, 73K stars, and a 22 use-case fit score.

Best suited scenario

Move data between tools

73K starsJun 15, 2026 pushProduction candidateGoPrivacy
$ npx skills add caddyserver/caddy
#12

Win11Debloat

21 fitTrust 95Excellent 100Audit 95 · Safe to try

A simple, lightweight PowerShell script that allows you to remove pre-installed apps, disable telemetry, as well as perform various other changes to declutter and customize your Windows experience. Win11Debloat works for both Windows 10 and Windows 11.

Excellent quality, 48K stars, and a 21 use-case fit score.

Best suited scenario

Extract obligations

48K starsJun 14, 2026 pushProduction candidatePowerShellPrivacy
$ npx skills add Raphire/Win11Debloat
#13

Trivy

21 fitTrust 96Excellent 100Audit 95 · Safe to try

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Excellent quality, 36K stars, and a 21 use-case fit score.

Best suited scenario

Inspect source files

36K starsJun 15, 2026 pushProduction candidateGoKubernetes
$ npx skills add aquasecurity/trivy
#14

AdGuardHome

21 fitTrust 95Excellent 100Audit 95 · Safe to try

Network-wide ads & trackers blocking DNS server

Excellent quality, 35K stars, and a 21 use-case fit score.

Best suited scenario

Load football datasets

35K starsJun 16, 2026 pushProduction candidateGoPrivacy
$ npx skills add AdguardTeam/AdGuardHome
#15

Web Check

21 fitTrust 95Excellent 100Audit 95 · Safe to try

🕵️‍♂️ All-in-one OSINT tool for analysing any website

Excellent quality, 34K stars, and a 21 use-case fit score.

Best suited scenario

Extract obligations

34K starsJun 15, 2026 pushProduction candidateTypeScriptPrivacy
$ npx skills add lissy93/web-check
#16

Hosts

21 fitTrust 98Excellent 100Audit 96 · Safe to try

🔒 Consolidating and extending hosts files from several well-curated sources. Optionally pick extensions for porn, social media, and other categories.

Excellent quality, 31K stars, and a 21 use-case fit score.

Best suited scenario

Move data between tools

31K starsJun 11, 2026 pushProduction candidatePythonPrivacy
$ npx skills add StevenBlack/hosts
#17

Lighthouse

21 fitTrust 96Excellent 100Audit 96 · Safe to try

Automated auditing, performance metrics, and best practices for the web.

Excellent quality, 30K stars, and a 21 use-case fit score.

Best suited scenario

Inspect source files

30K starsJun 18, 2026 pushProduction candidateJavaScriptDeveloper Tools
$ npx skills add GoogleChrome/lighthouse
#18

Setup Ipsec Vpn

21 fitTrust 92Excellent 100Audit 93 · Safe to try

Set up your own IPsec VPN server in just a few minutes, with IPsec/L2TP, Cisco IPsec and IKEv2. Supports Ubuntu, Debian, CentOS/RHEL, Amazon Linux, Alpine and Raspberry Pi. Includes client config and management scripts.

Excellent quality, 28K stars, and a 21 use-case fit score.

Best suited scenario

Inspect repository metadata

28K starsJun 16, 2026 pushProduction candidateShellPrivacy
$ npx skills add hwdsl2/setup-ipsec-vpn
#19

Gitleaks

21 fitTrust 92Excellent 100Audit 94 · Safe to try

Find secrets with Gitleaks 🔑

Excellent quality, 28K stars, and a 21 use-case fit score.

Best suited scenario

Inspect source files

28K starsJun 13, 2026 pushProduction candidateGoCI/CD
$ npx skills add gitleaks/gitleaks
#20

Keepassxc

21 fitTrust 92Excellent 100Audit 93 · Needs review

KeePassXC is a cross-platform community-driven port of the Windows application “KeePass Password Safe”.

Excellent quality, 28K stars, and a 21 use-case fit score.

Best suited scenario

Extract obligations

28K starsJun 4, 2026 pushProduction candidateC++Privacy
$ npx skills add keepassxreboot/keepassxc
#21

Ente

21 fitTrust 95Excellent 100Audit 95 · Safe to try

💚 End-to-end encrypted cloud for everything.

Excellent quality, 27K stars, and a 21 use-case fit score.

Best suited scenario

Extract obligations

27K starsJun 16, 2026 pushProduction candidateDartPrivacy
$ npx skills add ente-io/ente
#22

Ungoogled Chromium

21 fitTrust 95Excellent 100Audit 95 · Safe to try

Google Chromium, sans integration with Google

Excellent quality, 27K stars, and a 21 use-case fit score.

Best suited scenario

Move data between tools

27K starsJun 12, 2026 pushProduction candidatePythonPrivacy
$ npx skills add ungoogled-software/ungoogled-chromium
#23

Fhevm

21 fitTrust 94Excellent 100Audit 94 · Safe to try

FHEVM, a full-stack framework for integrating Fully Homomorphic Encryption (FHE) with blockchain applications

Excellent quality, 25K stars, and a 21 use-case fit score.

Best suited scenario

Extract obligations

25K starsJun 16, 2026 pushProduction candidateRustPrivacy
$ npx skills add zama-ai/fhevm
#24

Dns Blocklists

20 fitTrust 95Excellent 100Audit 95 · Safe to try

DNS-Blocklists: For a better internet - keep the internet clean!

Excellent quality, 24K stars, and a 20 use-case fit score.

Best suited scenario

Extract obligations

24K starsJun 16, 2026 pushProduction candidateTextPrivacy
$ npx skills add hagezi/dns-blocklists
#25

Promptfoo

20 fitTrust 96Excellent 100Audit 95 · Safe to try

Test your prompts, agents, and RAGs. Red teaming/pentesting/vulnerability scanning for AI. Compare performance of GPT, Claude, Gemini, DeepSeek, and more. Simple declarative configs with command line and CI/CD integration. Used by OpenAI and Anthropic.

Excellent quality, 22K stars, and a 20 use-case fit score.

Best suited scenario

Inspect source files

22K starsJun 15, 2026 pushProduction candidateTypeScriptRAG
$ npx skills add promptfoo/promptfoo
#26

FreeTube

20 fitTrust 95Excellent 100Audit 95 · Safe to try

An Open Source YouTube app for privacy

Excellent quality, 21K stars, and a 20 use-case fit score.

Best suited scenario

Extract obligations

21K starsJun 16, 2026 pushProduction candidateVuePrivacy
$ npx skills add FreeTubeApp/FreeTube
#27

Atlas

20 fitTrust 97Excellent 100Audit 96 · Safe to try

🚀 An open and lightweight modification to Windows, designed to optimize performance, privacy and usability.

Excellent quality, 21K stars, and a 20 use-case fit score.

Best suited scenario

Move data between tools

21K starsJun 12, 2026 pushProduction candidateBatchfilePrivacy
$ npx skills add Atlas-OS/Atlas
#28

Teleport

20 fitTrust 96Excellent 100Audit 95 · Safe to try

The easiest, and most secure way to access and protect all of your infrastructure.

Excellent quality, 20K stars, and a 20 use-case fit score.

Best suited scenario

Inspect source files

20K starsJun 16, 2026 pushProduction candidateGoKubernetes
$ npx skills add gravitational/teleport
#29

Super Productivity

20 fitTrust 98Excellent 100Audit 96 · Safe to try

Super Productivity is an advanced todo list app with integrated Timeboxing and time tracking capabilities. It also comes with integrations for Jira, GitLab, GitHub and Open Project.

Excellent quality, 20K stars, and a 20 use-case fit score.

Best suited scenario

Move data between tools

20K starsJun 16, 2026 pushProduction candidateTypeScriptPrivacy
$ npx skills add super-productivity/super-productivity
#30

Claude Skills

20 fitTrust 94Excellent 100Audit 94 · Safe to try

337 Claude Code skills & agent skills & plugins (30+ Agents, 70+ custom commands, 330+ skills, customizable references, scripts)for Claude Code, Codex, Gemini CLI, Cursor, and 8 more coding agents — engineering, marketing, product, compliance, C-level advisory, research, business operations, commercial & finance, and your daily productivity skills.

Excellent quality, 18K stars, and a 20 use-case fit score.

Best suited scenario

Inspect source files

18K starsJun 12, 2026 pushProduction candidatePythonAI Agents
$ npx skills add alirezarezvani/claude-skills

Selection method

How this list is ranked

OpenAgentSkill scores each candidate against the workflow keywords, then balances fit with GitHub stars, quality signals, trust profile, maintenance freshness, and whether there is a clear install path.

How does OpenAgentSkill rank security review?

The ranking combines workflow fit, quality score, trust profile, GitHub adoption, maintenance freshness, and whether a clear install path exists.

Should I install the top skill immediately?

No. Treat the list as a shortlist, open the skill detail page, inspect the repository and license, then test the install command in a sandbox workflow.

Can my agent consume this ranking through an API?

Yes. Use /api/skills/search with the related task or /api/agent/rankings?slug=best-security-review-skills to fetch ranked skill data.