OpenAgentSkill guide

Best security and compliance skills for AI agents

Explore skills for vulnerability checks, secret scanning, dependency review, policy validation, and security-aware automation.

When to use this guide

Start from the job, then shortlist the tools.

Scan dependencies

Use quality and freshness signals to decide whether a skill belongs in this workflow.

Find exposed secrets

Use quality and freshness signals to decide whether a skill belongs in this workflow.

Review security findings

Use quality and freshness signals to decide whether a skill belongs in this workflow.

Prepare audit notes

Use quality and freshness signals to decide whether a skill belongs in this workflow.

Shortlist

Top skills to evaluate

Compare top 4
#1VulsExcellent · 10012K stars

Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices

Best fit: High-confidence pick with strong adoption and healthy maintenance signals.

#2Osv ScannerExcellent · 10011K stars

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Best fit: High-confidence pick with strong adoption and healthy maintenance signals.

#3NucleiExcellent · 10029K stars

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.

Best fit: High-confidence pick with strong adoption and healthy maintenance signals.

#4OpaExcellent · 10012K stars

Open Policy Agent (OPA) is an open source, general-purpose policy engine.

Best fit: High-confidence pick with strong adoption and healthy maintenance signals.

#5KubescapeExcellent · 10011K stars

Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, and clusters. It includes risk analysis, security, compliance, and misconfiguration scanning, saving Kubernetes users and administrators precious time, effort, and resources.

Best fit: High-confidence pick with strong adoption and healthy maintenance signals.

#6KyvernoExcellent · 987.8K stars

Unified Policy as Code

Best fit: High-confidence pick with strong adoption and healthy maintenance signals.

#7SkillsExcellent · 1006.6K stars

Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows

Best fit: High-confidence pick with strong adoption and healthy maintenance signals.

#8TrivyExcellent · 10036K stars

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Best fit: High-confidence pick with strong adoption and healthy maintenance signals.

#9Web CheckExcellent · 10034K stars

🕵️‍♂️ All-in-one OSINT tool for analysing any website

Best fit: High-confidence pick with strong adoption and healthy maintenance signals.

#10InfisicalExcellent · 10027K stars

Infisical is the open-source platform for secrets, certificates, and privileged access management.

Best fit: High-confidence pick with strong adoption and healthy maintenance signals.