Marketplace category archive

Security & Verification Skills

Explore live Security & Verification skills across the current marketplace catalog.

132live listings
10frameworks in use
Livetaxonomy archive

Category Skills

Browse the published marketplace skills currently assigned to this category.

Security & Verification Published

Test API authorization flows with Hadrian

<p>Lets an agent exercise REST, GraphQL, and gRPC authorization paths with YAML-defined role tests so BOLA, BFLA, broken authentication, and related API flaws are caught before release.</p>

Multi-Framework Security & Verification
Security & Verification Security Reviewed

Audit Linux host hardening drift before exposing SSH or rolling to production

Uses Lynis to run an on-host security audit and turn the findings into a prioritized hardening checklist for an agent or operator. Invoke it when a machine is about to become internet-facing, after base image changes, or whenever you need a quick read on hardening drift instead of a generic vulnerability scan.

Multi-Framework Security & Verification
Yesterday πŸ‘ 2 View skill →
Security & Verification Security Reviewed

Audit GitHub Actions workflows for insecure permissions and unpinned actions

This ASE skill uses zizmor to audit GitHub Actions workflows and composite actions for security mistakes before they ship. An agent can scan local repos or remote GitHub repositories, flag risky permission scopes and unsafe workflow patterns, and return plain output, GitHub-native findings, or SARIF for follow-up automation.

Multi-Framework Security & Verification
2 days ago πŸ‘ 1 View skill →
Security & Verification Security Reviewed

Generate adversarial API test cases from an OpenAPI or GraphQL schema

Use Schemathesis when an agent needs to turn an API schema into broad negative and edge-case coverage instead of hand-writing examples. The skill exercises live endpoints or app hooks, explores unexpected combinations, and reports failures that ordinary happy-path tests miss.

Multi-Framework Security & Verification
3 days ago πŸ‘ 1 View skill →
Security & Verification Security Reviewed

Audit OpenClaw host security posture and hardening gaps

This skill uses OpenClaw's healthcheck workflow to inspect the host running the assistant, surface risky exposure, and turn the findings into a staged hardening plan. It is for operator-style audits with explicit approval gates, not a generic software listing or a replacement for OS administration.

OpenClaw Security & Verification
3 days ago πŸ‘ 5 View skill →
Security & Verification Security Reviewed

Infisical CLI Secrets Injection and Access Management

Infisical CLI retrieves, injects, and manages secrets across local development, CI/CD, staging, and production environments. It is useful when agent workflows need a structured way to pull environment variables and secret material without hardcoding credentials into scripts.

Multi-Framework Security & Verification
4 days ago πŸ‘ 2 View skill →
Security & Verification Security Reviewed

Trivy Security Scanner for Containers and IaC

Trivy is Aqua Security’s scanner for vulnerabilities, misconfigurations, secrets, SBOMs, and license issues. It fits security review, container hygiene, and infrastructure-as-code checks in one CLI.

Multi-Framework Security & Verification
5 days ago πŸ‘ 6 View skill →
Security & Verification Security Reviewed

SOPS Secret File Encryption and Rotation

SOPS manages encrypted YAML, JSON, ENV, INI, and binary files with KMS, age, and PGP. It is a tight fit for secrets handling, rotation, and encrypted configuration workflows.

Multi-Framework Security & Verification
5 days ago πŸ‘ 3 View skill →
Security & Verification Security Reviewed

Clerk JavaScript Backend SDK for Server-Side Auth Workflows

Clerk’s JavaScript backend SDK gives agents a real server-side interface for auth and user management. It is useful for verifying sessions, fetching users, issuing invitations, and integrating Clerk into custom backend or edge workflows.

Multi-Framework Security & Verification
6 days ago πŸ‘ 2 View skill →
Security & Verification Security Reviewed

WorkOS AuthKit Next.js Authentication Toolkit

WorkOS AuthKit is a real authentication toolkit for Next.js applications. It gives agents a concrete integration target for login, sessions, RBAC, SSO, MFA, and user management backed by WorkOS docs and package releases.

Multi-Framework Security & Verification
6 days ago πŸ‘ 2 View skill →
Security & Verification Security Reviewed

Better Auth Authentication Framework for TypeScript Applications

Better Auth is an open source authentication framework for TypeScript apps. It gives agents a concrete way to wire sign-in, sessions, passkeys, OAuth providers, and plugins into modern web stacks with real package and docs support.

Multi-Framework Security & Verification
6 days ago πŸ‘ 2 View skill →
Security & Verification Security Reviewed

Magika AI File Type Detection and Content Classification

Magika is Google's AI-powered file type detector for fast, content-based identification of binary and text files. It is useful when an agent needs safer routing, validation, triage, or downstream policy decisions based on the real file contents instead of just filenames or MIME headers.

Multi-Framework Security & Verification
1w ago πŸ‘ 2 View skill →
Security & Verification Security Reviewed

Cerbos Open Source Authorization Policy Decision Point

Cerbos is an open-core, language-agnostic, scalable authorization solution that makes implementing and managing user permissions simple. It uses context-aware YAML access control policies managed through Git-ops, providing high-availability APIs for dynamic access decisions across applications.

Multi-Framework Security & Verification
1w ago πŸ‘ 2 View skill →
Security & Verification Security Reviewed

Naabu Fast Port Scanner by ProjectDiscovery

Naabu is a fast and reliable port scanning tool written in Go by ProjectDiscovery. It supports SYN, CONNECT, and UDP scans, integrates with Nmap for service discovery, and handles IPv4/IPv6 targets with automatic deduplication for efficient attack surface enumeration.

Multi-Framework Security & Verification
1w ago πŸ‘ 3 View skill →
Security & Verification Security Reviewed

Cariddi Domain Crawler and Endpoint Secret Scanner

Cariddi is a Go-based security tool that takes a list of domains, crawls their URLs, and scans for endpoints, secrets, API keys, file extensions, tokens, and errors. It supports configurable concurrency, depth limits, proxy routing, and multiple output formats.

Multi-Framework Security & Verification
1w ago πŸ‘ 2 View skill →
Security & Verification Security Reviewed

Tracecat AI-Native Security Automation and SOAR Platform

Tracecat is an open-source, AI-native security automation platform built as a self-hosted alternative to Tines and Splunk SOAR. It combines agents, workflows, case management, and lookup tables in one platform with sandboxed execution powered by Temporal and nsjail.

Multi-Framework Security & Verification
1w ago πŸ‘ 3 View skill →
Security & Verification Security Reviewed

Horcrux Shamir Secret Sharing File Encryption and Splitting Tool

Horcrux splits files into encrypted fragments using Shamir Secret Sharing, so you can distribute pieces across locations and reconstruct the original with a configurable threshold β€” no password required.

Multi-Framework Security & Verification
1w ago πŸ‘ 2 View skill →
Security & Verification Security Reviewed

Unkey Open Source API Key Management and Rate Limiting Platform

Unkey is an open-source developer platform for managing API keys, rate limiting, and usage analytics. It provides a fast, globally distributed key verification system that integrates into any API with minimal code changes.

Custom Agents Security & Verification
1w ago πŸ‘ 2 View skill →
Security & Verification Security Reviewed

Hanko Open Source Passkey Authentication and User Management

Hanko is an open-source authentication and user management platform built on passkeys and WebAuthn. It provides a drop-in authentication solution as an alternative to Auth0, Clerk, and Stytch, with pre-built web components, a REST API, and an admin dashboard.

Custom Agents Security & Verification
1w ago πŸ‘ 3 View skill →
Security & Verification Security Reviewed

Casdoor Open Source Identity and Access Management Platform

Casdoor is an open source AI-first Identity and Access Management (IAM) platform and auth server supporting OAuth 2.1, OIDC, SAML, CAS, LDAP, SCIM, WebAuthn, TOTP, MFA, and MCP gateway integration with a web-based admin UI.

Multi-Framework Security & Verification
1w ago πŸ‘ 3 View skill →