100,000+ Skills from Skills.sh — Security Audited

Compliance & Risk AI Agent Skills

Browse Compliance & Risk AI agent skills, compare security audits, and install with one command.

16.1KSkills
210MInstalls
12Categories
Category:
Source:
Target site:

Total 654 skills · 3.5M installs (updates with filters).

azure-compliance
3/3

Azure compliance scanning, Key Vault expiration auditing, and resource configuration validation. Runs azqr (Azure Quick Review) for comprehensive compliance assessment against best practices across subscriptions and resource groups Monitors Key Vault keys, secrets, and certificates for expiration dates and identifies items without expiration policies Detects orphaned, misconfigured, and non-compliant resources using Resource Graph queries Classifies findings by priority (Critical, High, Medium, Low) with remediation guidance for each issue

Verified authormicrosoft
SKILLS.SH
617K1.5K
2026-10-04
convex-authz
3/3

Audit and harden a Convex app's authorization: identity-from-arg impersonation, missing per-document ownership checks, public queries leaking data by a…

Verified authorget-convex
SKILLS.SH
28.3K63
2026-10-04
google-cloud-waf-security
3/3

Generates security-focused guidance for Google Cloud workloads based on the design principles and recommendations in the Google Cloud Well-Architected…

Verified authorgoogle
SKILLS.SH
13.4K20.8K
2026-10-04
apple-appstore-reviewer
3/3

Codebase auditor identifying Apple App Store rejection risks and compliance gaps. Systematically reviews Info.plist, entitlements, privacy manifests, permissions, IAP flows, account handling, and content moderation against App Store Review Guidelines Produces prioritized risk register with severity levels, evidence citations, and concrete remediation steps Includes reviewer experience checklist and draft App Review Notes to streamline submission and reduce re-review cycles Focuses on rejection prevention first, then optimization opportunities for faster approval

Verified authorgithub
SKILLS.SH
11.2K39.7K
2026-10-04
security-best-practices
3/3

Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best…

Verified authoropenai
SKILLS.SH
9.9K27.9K
2026-10-04
agent-governance
3/3

Declarative policies, intent classification, and audit trails for controlling AI agent tool access and behavior. Composable governance policies define allowed/blocked tools, content filters, rate limits, and approval requirements — stored as configuration, not code Semantic intent classification detects dangerous prompts (data exfiltration, privilege escalation, prompt injection) before tool execution using pattern-based signals Tool-level governance decorator enforces policies at function call time with rate limiting, content checking, and audit logging Trust scoring with temporal decay tracks agent reliability in multi-agent systems, gating sensitive operations based on historical success rates Append-only audit trails capture all governance events (allowed, denied, errors) for compliance and security review Works with any agent framework: PydanticAI, CrewAI, OpenAI Agents, LangChain, AutoGen

Verified authorgithub
SKILLS.SH
9.7K39.7K
2026-10-04
google-cloud-waf-sustainability
3/3

Provides recommendations for environmental sustainability, carbon footprint reduction, and energy efficiency based on the Sustainability pillar of the Google…

Verified authorgoogle
SKILLS.SH
8.2K20.8K
2026-10-04
supply-chain-risk-auditor
3/3

Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived…

Verified authortrailofbits
SKILLS.SH
7.3K7.3K
2026-10-04
security-threat-model
3/3

Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a concise…

Verified authoropenai
SKILLS.SH
7K27.9K
2026-10-04
secure-workflow-guide
3/3

Guides through Trail of Bits' 5-step secure development workflow. Runs Slither scans, checks special features (upgradeability/ERC conformance/token…

Verified authortrailofbits
SKILLS.SH
6.9K7.3K
2026-10-04
code-maturity-assessor
3/3

Systematic code maturity assessment using Trail of Bits' 9-category framework. Analyzes codebase for arithmetic safety, auditing practices, access controls,…

Verified authortrailofbits
SKILLS.SH
6.7K7.3K
2026-10-04
fp-check
3/3

Systematically verifies suspected security bugs to eliminate false positives, producing a TRUE POSITIVE or FALSE POSITIVE verdict with documented evidence for…

Verified authortrailofbits
SKILLS.SH
6.4K7.3K
2026-10-04
workload-manager-basics
3/3

Use this skill to manage Google Cloud Workload Manager evaluations, rules, scanned resources, and validation results by using public client libraries and the…

Verified authorgoogle
SKILLS.SH
6K20.8K
2026-10-04
spec-to-code-compliance
3/3

Check code against the documentation that specifies it - which requirements hold, which the code contradicts, which are absent, and what the code does that no…

Verified authortrailofbits
SKILLS.SH
5.4K7.3K
2026-10-04
security-review
3/3

AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and…

Verified authorgithub
SKILLS.SH
5.4K39.7K
2026-10-04

Stop writing automation&scrapers

Install the CLI. Run your first Skill in 30 seconds. Scale when you're ready.

Start free
free · no credit card