Marketplace category archive

Security & Verification Skills

Explore live Security & Verification skills across the current marketplace catalog.

133live listings
10frameworks in use
Livetaxonomy archive

Category Skills

Browse the published marketplace skills currently assigned to this category.

Security & Verification Security Reviewed

Grype Container and SBOM Vulnerability Scanner

Scan container images, filesystems, and SBOMs for known vulnerabilities using Anchore Grype. Supports major OS package ecosystems and language-specific packages with EPSS risk scoring and OpenVEX filtering.

⭐ 12k grype
Claude Code Security & Verification
2w ago 👁 3 View skill →
Security & Verification Security Reviewed

Semgrep Supply Chain Rule Pack Runner

Runs Semgrep code and supply-chain checks with `semgrep scan`, registry rule packs, and dependency-aware findings to surface risky patterns early. Useful when agents need to summarize security results in repo terms developers can act on immediately.

⭐ 14.6k semgrep
ChatGPT Agents Security & Verification
2w ago 👁 3 View skill →
Security & Verification Security Reviewed

Sigstore Cosign Container Signature Checker

Checks container trust with `cosign verify`, Rekor transparency log lookups, and OCI image reference inspection. Useful for agents that need to confirm whether an image was actually signed and recorded before it reaches a deployment pipeline.

Claude Code Security & Verification
2w ago 👁 3 View skill →
Security & Verification Security Reviewed

Vault Transit Secrets Envelope Verifier

Verifies encryption workflows with HashiCorp Vault Transit endpoints like `/encrypt`, `/decrypt`, and `/rewrap`, plus key metadata inspection. Useful for agents reviewing whether application secrets handling is actually using envelope encryption correctly instead of assuming the library setup is safe.

⭐ 35.3k vault
Codex Security & Verification
2w ago 👁 2 View skill →
Security & Verification Security Reviewed

OPA Rego Policy Bundle Tester

Tests authorization and policy bundles with the Open Policy Agent `/v1/data` and `/v1/compile` APIs plus `opa test` semantics. Great for agents that need to explain which Rego rules allow or deny a request before policy changes go live.

OpenClaw Security & Verification
2w ago 👁 2 View skill →
Security & Verification Security Reviewed

SSL Certificate Auditor

Audits TLS/SSL configurations using sslyze Python library and SSL Labs API v3. Checks certificate chain validity, HSTS headers, and OCSP stapling status with Certificate Transparency log verification.

OpenClaw Security & Verification
3w ago 👁 3 View skill →
Security & Verification Security Reviewed

Dependency Vulnerability Scanner

Scans project dependencies using OSV.dev API and Snyk CLI for known CVEs across npm, PyPI, Maven, and Go modules. Generates SBOM in CycloneDX format via syft.

MCP Security & Verification
3w ago 👁 3 View skill →
Security & Verification Security Reviewed

OWASP ZAP Active Scanner Agent

Runs OWASP ZAP active security scans via the ZAP API daemon with custom scan policies. Generates SARIF reports compatible with GitHub Advanced Security code scanning alerts.

Codex Security & Verification
3w ago 👁 4 View skill →
Security & Verification Security Reviewed

OWASP ZAP Security Scanner Agent

Automates OWASP ZAP active and passive scanning against web applications, parsing alerts into structured vulnerability reports. Integrates with the ZAP API daemon to manage contexts, spider targets, and export SARIF-formatted findings.

OpenClaw Security & Verification
3w ago 👁 4 View skill →
Security & Verification Security Reviewed

Trivy Container & IaC Vulnerability Scanner

Runs Aqua Security Trivy against container images, filesystem paths, and Terraform/CloudFormation templates. Produces vulnerability matrices with CVSS scoring and fix-version recommendations.

ChatGPT Agents Security & Verification
3w ago 👁 4 View skill →
Security & Verification Security Reviewed

Sigstore Cosign Verification Pipeline

Verifies container image signatures and SBOMs using Sigstore Cosign and Rekor transparency log. Enforces supply chain security policies by validating keyless signatures against Fulcio certificate authorities.

Codex Security & Verification
3w ago 👁 2 View skill →
Security & Verification Security Reviewed

AWS CloudTrail Log Normalizer

Normalizes and enriches AWS CloudTrail JSON logs into OCSF (Open Cybersecurity Schema Framework) format. Maps eventSource/eventName pairs to MITRE ATT&CK technique IDs using the MITRE ATT&CK STIX API.

Custom Agents Security & Verification
3w ago 👁 2 View skill →
Security & Verification Security Reviewed

TLS Certificate Chain Analyzer

Analyzes TLS certificate chains using OpenSSL s_client and the crt.sh Certificate Transparency API. Detects weak algorithms, expiring intermediates, and CT log compliance issues.

MCP Security & Verification
3w ago 👁 3 View skill →
Security & Verification Security Reviewed

SAST Rule Compiler for Semgrep

Compiles and validates custom Semgrep SAST rules using the semgrep-core engine. Tests pattern matching against sample codebases and generates rule performance benchmarks with p/ci rulesets.

Codex Security & Verification
3w ago 👁 3 View skill →
Security & Verification Security Reviewed

SBOM Generator with CycloneDX

Generates Software Bill of Materials in CycloneDX 1.5 format using cdxgen and syft. Enriches component data with license detection from clearlydefined.io and vulnerability cross-referencing via OSV.dev.

Gemini Security & Verification
3w ago 👁 3 View skill →
Security & Verification Security Reviewed

Trivy Container Vulnerability Scanner

Automates Aqua Security Trivy scans against Docker images and OCI artifacts to detect CVEs, misconfigurations, and license violations. Integrates with Trivy's JSON/SARIF output for CI-gate decisions and generates remediation reports.

Claude Code Security & Verification
3w ago 👁 2 View skill →
Security & Verification Security Reviewed

Cosign Artifact Signature Verifier

Validates container image and artifact signatures using Sigstore Cosign with keyless verification via Fulcio and Rekor transparency logs. Enforces supply chain integrity policies with OPA/Rego.

Codex Security & Verification
3w ago 👁 2 View skill →
Security & Verification Security Reviewed

OWASP ZAP API Security Auditor

Orchestrates OWASP ZAP active and passive scans against REST and GraphQL endpoints using ZAP's Python API client. Generates DAST reports with CWE mappings and suggests WAF rule configurations.

OpenClaw Security & Verification
3w ago 👁 3 View skill →
Security & Verification Security Reviewed

Snyk License Compliance Checker

Uses the Snyk CLI and REST API to audit open-source dependencies for license compliance across npm, PyPI, Maven, and Go modules. Generates SPDX license reports and flags copyleft violations.

Cursor Security & Verification
3w ago 👁 6 View skill →
Security & Verification Security Reviewed

Vault Secrets Rotator

Manages secret lifecycle through the HashiCorp Vault HTTP API v1. Rotates database credentials via Vault dynamic secrets engine and syncs to Kubernetes via External Secrets Operator CRDs.

MCP Security & Verification
3w ago 👁 10 View skill →
Security & Verification Security Reviewed

Trivy Container Scanner

Wraps the Trivy CLI for comprehensive container image vulnerability scanning. Outputs results in SARIF format for GitHub Code Scanning API integration and generates OCI artifact attestations.

OpenClaw Security & Verification
3w ago 👁 3 View skill →
Security & Verification Security Reviewed

NPM Audit Deep Scanner

Extends npm audit with deep transitive dependency analysis using the npm Registry API. Generates fix PRs via GitHub API and cross-checks advisories against the OSV.dev vulnerability database.

Custom Agents Security & Verification
3w ago 👁 3 View skill →
Security & Verification Security Reviewed

Sigstore Cosign Verifier

Automates container image signature verification using Cosign CLI and the Rekor transparency log API. Validates SLSA provenance attestations and checks Fulcio certificate chains for keyless signing.

Cursor Security & Verification
3w ago 👁 4 View skill →
Security & Verification Security Reviewed

Snyk Dependency Audit Skill

Uses the Snyk CLI and REST API v1 to scan package manifests for known CVEs. Cross-references findings with the GitHub Advisory Database and produces SBOM documents in CycloneDX format.

Claude Code Security & Verification
3w ago 👁 3 View skill →