100,000+ Skills from Skills.sh — Security Audited

Compliance & Risk AI Agent Skills

Browse Compliance & Risk AI agent skills, compare security audits, and install with one command.

14.4KSkills
150MInstalls
12Categories
Category:
Source:
Target site:

Total 599 skills · 2.8M installs (updates with filters).

azure-compliance
3/3

Azure compliance scanning, Key Vault expiration auditing, and resource configuration validation. Runs azqr (Azure Quick Review) for comprehensive compliance assessment against best practices across subscriptions and resource groups Monitors Key Vault keys, secrets, and certificates for expiration dates and identifies items without expiration policies Detects orphaned, misconfigured, and non-compliant resources using Resource Graph queries Classifies findings by priority (Critical, High, Medium, Low) with remediation guidance for each issue

Verified authormicrosoft
SKILLS.SH
532K1.4K
2026-08-20
apple-appstore-reviewer
3/3

Codebase auditor identifying Apple App Store rejection risks and compliance gaps. Systematically reviews Info.plist, entitlements, privacy manifests, permissions, IAP flows, account handling, and content moderation against App Store Review Guidelines Produces prioritized risk register with severity levels, evidence citations, and concrete remediation steps Includes reviewer experience checklist and draft App Review Notes to streamline submission and reduce re-review cycles Focuses on rejection prevention first, then optimization opportunities for faster approval

Verified authorgithub
SKILLS.SH
10.5K38K
2026-08-20
google-cloud-waf-security
3/3

Generates security-focused guidance for Google Cloud workloads based on the design principles and recommendations in the Google Cloud Well-Architected…

Verified authorgoogle
SKILLS.SH
9.9K18.5K
2026-08-20
agent-governance
3/3

Declarative policies, intent classification, and audit trails for controlling AI agent tool access and behavior. Composable governance policies define allowed/blocked tools, content filters, rate limits, and approval requirements — stored as configuration, not code Semantic intent classification detects dangerous prompts (data exfiltration, privilege escalation, prompt injection) before tool execution using pattern-based signals Tool-level governance decorator enforces policies at function call time with rate limiting, content checking, and audit logging Trust scoring with temporal decay tracks agent reliability in multi-agent systems, gating sensitive operations based on historical success rates Append-only audit trails capture all governance events (allowed, denied, errors) for compliance and security review Works with any agent framework: PydanticAI, CrewAI, OpenAI Agents, LangChain, AutoGen

Verified authorgithub
SKILLS.SH
9.5K38K
2026-08-20
convex-authz
3/3

Audit and harden Convex authorization: identity-from-arg impersonation, missing per-document ownership checks, PII-leaking public queries, and writes into…

Verified authorget-convex
SKILLS.SH
8.9K46
2026-08-20
secure-workflow-guide
3/3

Guides through Trail of Bits' 5-step secure development workflow. Runs Slither scans, checks special features (upgradeability/ERC conformance/token…

Verified authortrailofbits
SKILLS.SH
6.1K6.7K
2026-08-20
code-maturity-assessor
3/3

Systematic code maturity assessment using Trail of Bits' 9-category framework. Analyzes codebase for arithmetic safety, auditing practices, access controls,…

Verified authortrailofbits
SKILLS.SH
5.8K6.7K
2026-08-20
fp-check
3/3

Systematically verifies suspected security bugs to eliminate false positives, producing a TRUE POSITIVE or FALSE POSITIVE verdict with documented evidence for…

Verified authortrailofbits
SKILLS.SH
5.5K6.7K
2026-08-20
google-cloud-waf-sustainability
3/3

Generates sustainability-focused guidance for Google Cloud workloads based on the design principles and recommendations in the Google Cloud Well-Architected…

Verified authorgoogle
SKILLS.SH
5.1K18.5K
2026-08-20
solana-vulnerability-scanner
3/3

Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing.…

Verified authortrailofbits
SKILLS.SH
4.5K6.7K
2026-08-20
semgrep-rule-creator
3/3

Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. Use when writing Semgrep rules or building custom static…

Verified authortrailofbits
SKILLS.SH
4.4K6.7K
2026-08-20
audit-prep-assistant
3/3

Prepares codebases for security review using Trail of Bits' checklist. Helps set review goals, runs static analysis tools, increases test coverage, removes…

Verified authortrailofbits
SKILLS.SH
4.4K6.7K
2026-08-20
security-threat-model
3/3

Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a concise…

Verified authoropenai
SKILLS.SH
4.4K25K
2026-08-20
entry-point-analyzer
3/3

Analyzes smart contract codebases to identify state-changing entry points for security auditing. Detects externally callable functions that modify state,…

Verified authortrailofbits
SKILLS.SH
4.4K6.7K
2026-08-20
secret-scanning
3/3

Guide for configuring and managing GitHub secret scanning, push protection, custom patterns, and secret alert remediation. For pre-commit secret scanning in AI…

Verified authorgithub
SKILLS.SH
4.3K38K
2026-08-20

Stop writing automation&scrapers

Install the CLI. Run your first Skill in 30 seconds. Scale when you're ready.

Start free
free · no credit card