SecuritySkills
Framework-grounded security reviews, compliance audits, and incident response
All Skills in This Repository (50)
Pure Emerald Level Indicatorssecurity-engineer
Orchestrate security engineering workflows for code review, pipeline hardening, and CVE triage.
appsec-engineer
Guide application security engineers through threat modeling and secure code review.
vciso
Assess security program maturity and plan compliance readiness for organizations without a full-time CISO.
cloud-security-engineer
Orchestrate AWS, Azure, and GCP security posture assessments with remediation plans.
soc-analyst
Guide SOC analysts through structured alert triage and incident investigation workflows.
agent-security
Review AI agent architectures for security risks across permissions and oversight.
llm-top-10
Review LLM applications for OWASP Top 10 security weaknesses.
model-supply-chain
Review AI/ML model supply chains for provenance, lineage, and backdoor indicators.
agentic-top-10
Audits agentic AI systems for OWASP Top 10 security risks across architectures.
ai-data-privacy
Review AI/ML systems for data privacy and governance risks.
prompt-injection
Detect prompt injection vulnerabilities in LLM-integrated applications and classify findings by OWASP LLM01.
forensics-checklist
Guide digital forensic evidence collection with chain-of-custody and hash integrity.
Frequently Asked Questions
FAQPage SchemaHow to install SecuritySkills?▼
Run `npx skills add UnitOneAI/SecuritySkills --all -g -y` in your terminal to install all 45 security skills globally.
What security frameworks do these skills cover?▼
Skills map findings to real published frameworks including OWASP Top 10, OWASP LLM Top 10, NIST CSF 2.0, NIST SP 800-53/800-61/800-207, MITRE ATT&CK, CIS Controls v8, SOC 2, ISO 27001, PCI DSS v4.0, and HIPAA.
Can it review AI and LLM application security?▼
Yes. Dedicated skills cover the OWASP LLM Top 10, agentic AI risks, prompt injection testing, model supply chain integrity, and AI data privacy.
Does SecuritySkills work with Claude Code and Cursor?▼
Yes. Every skill follows the open SKILL.md standard and works in Claude Code, Cursor, Gemini CLI, Codex, OpenClaw, and Kiro.
Can non-engineers use it for compliance audits?▼
Yes. Role bundles like the virtual CISO guide compliance gap analyses, board reporting, and risk assessments using plain-language requests, with no coding required.
Related Repositories in Software Engineering
View All in Software Engineering→openclaw
Run a personal AI assistant across your devices and chat apps
superpowers
Gives coding agents a disciplined workflow from idea to merged code
react
AI agent skills for building, testing, and porting React core