Skip to content

Marketplace

Everything your AI needs, in one place.

Ready-made agents, skills, personas, prompts, templates and tools. Each one is checked before it goes live, works with any model, and installs in a click. Rate what you use so the best rises to the top.

146.7K
listings
1
installs
0
reviews
40.4K
publishers
612 results
Skill

polygraph

Behavioral trust grades (A–F) for MCP servers. Use when an agent needs to check whether an MCP server is safe before using it, verify an onchain attestation before trusting or paying a server, look up

by bankrbotskills.sh
Not rated yet
Free
Skill

trustlayer-sybil-scanner

Feedback forensics for ERC-8004 agents. Detects Sybil rings, fake reviews, rating manipulation, and reputation laundering across 20 chains. No API key needed.

by bankrbotskills.sh
Not rated yet
Free
Skill

api-testing

API security testing and validation for REST/GraphQL/gRPC endpoints, contract testing, load testing, fuzzing, and Postman/Bruno/Hurl workflows

by oimiragieoskills.sh
Not rated yet
Free
Skill

content-security-scan

Automated security scanner for external skill/agent content fetched from GitHub or web sources. Runs a 7-step PASS/FAIL security gate against fetched markdown/text content.

by oimiragieoskills.sh
Not rated yet
Free
Skill

fiber-routing-and-csrf-protection

Focuses on routing, CSRF protection, context handling, and template usage within the internal handlers directory.

by oimiragieoskills.sh
Not rated yet
Free
Skill

fix-review

Verify fix commits address security findings without introducing new bugs or regressions. Analyzes diffs for anti-patterns like removed validation, weakened access control, reduced error handling, reo

by oimiragieoskills.sh
Not rated yet
Free
Skill

medusa-security

AI-first security scanning with Medusa. 3,000+ detection patterns covering AI/ML, agents, MCP, RAG, prompt injection, and traditional SAST vulnerabilities. Wraps Medusa CLI with SARIF/JSON parsing, st

by oimiragieoskills.sh
Not rated yet
Free
Skill

commit-security-scan

Analyze code changes for security vulnerabilities using LLM reasoning and threat model patterns. Use for PR reviews, pre-commit checks, or branch comparisons.

by factory-aiskills.sh
Not rated yet
Free
Skill

security-review

Scan code changes for security vulnerabilities using STRIDE threat modeling, validate findings for exploitability, and output structured results for downstream patch generation. Supports PR review, sc

by factory-aiskills.sh
Not rated yet
Free
Skill

threat-model-generation

Generate a STRIDE-based security threat model for a repository. Use when setting up security monitoring, after architecture changes, or for security audits.

by factory-aiskills.sh
Not rated yet
Free
Skill

vulnerability-validation

Validate security findings from commit-security-scan by assessing exploitability, filtering false positives, and generating proof-of-concept exploits. Use after running commit-security-scan to confirm

by factory-aiskills.sh
Not rated yet
Free
Skill

geo-technical

Technical SEO audit with GEO-specific checks — crawlability, indexability, security, performance, SSR, and AI crawler access

by zubair-trabzadaskills.sh
Not rated yet
Free
Skill

security-practices

OWASP Top 10, authentication, and secure coding practices

by miles990skills.sh
Not rated yet
Free
Skill

analyze-repo

Enterprise-grade repository analysis with arc42/C4 architecture documentation, technical debt quantification, security assessment, and multi-stakeholder reporting

by miles990skills.sh
Not rated yet
Free
Skill

detecting-container-escape-attempts

Detects container escape at runtime across tooling - namespace manipulation, capability abuse, kernel exploits, sensitive host mounts, and anomalous syscalls - and explains which signals matter regard

by mukul975skills.sh
Not rated yet
Free
Skill

hardening-docker-containers-for-production

Hardens Dockerfiles, images, and per-container runtime settings against the CIS Docker Benchmark v1.8.0: non-root users, dropped capabilities, read-only root filesystem, seccomp and AppArmor profiles,

by mukul975skills.sh
Not rated yet
Free
Skill

implementing-kubernetes-pod-security-standards

Chooses and applies the correct Kubernetes Pod Security Standard (Privileged, Baseline, Restricted) for a workload: what each profile forbids, how to map existing workloads to a profile, which securit

by mukul975skills.sh
Not rated yet
Free
Skill

implementing-network-policies-for-kubernetes

Writes portable upstream Kubernetes NetworkPolicy YAML - default-deny-all, DNS egress, namespace and pod selector rules - that works on any conformant CNI such as Calico or Cilium. Use when segmentati

by mukul975skills.sh
Not rated yet
Free
Skill

performing-docker-bench-security-assessment

Runs Docker Bench for Security, the open-source CIS Docker Benchmark audit script, across host configuration, daemon settings, images, and runtime configuration, then interprets pass/fail/warn output

by mukul975skills.sh
Not rated yet
Free
Skill

performing-kubernetes-penetration-testing

Evaluates Kubernetes cluster security by actively simulating attacker techniques against the API server, kubelet, etcd, pods, RBAC, network policy, and secrets, using kube-hunter, Kubescape, peirates,

by mukul975skills.sh
Not rated yet
Free
Skill

scanning-docker-images-with-trivy

Scans a Docker image with Trivy for vulnerabilities in OS packages and language dependencies, misconfiguration, exposed secrets, and licence violations, emitting SARIF, CycloneDX, or SPDX output. Use

by mukul975skills.sh
Not rated yet
Free
Skill

securing-container-registry-with-harbor

Configures the security features of the Harbor open-source container registry - integrated Trivy scanning, Cosign and Notary content trust policies, project-level RBAC, immutable tag and retention rul

by mukul975skills.sh
Not rated yet
Free
Skill

api-jwt-authenticator

A conceptual skill for securing FastAPI REST APIs with JWT authentication

by aiskillstoreskills.sh
Not rated yet
Free
Skill

skill-name

[REQUIRED] Comprehensive description of what this skill does and when to use it. Include: (1) Primary functionality, (2) Specific use cases, (3) Security operations context. Must include specific "Use

by aiskillstoreskills.sh
Not rated yet
Free
1

Find

Search or browse by kind. Every card shows who made it, how many people installed it and what they think.

2

Install

One click. You get a manifest the router understands, plus copy-paste snippets for the CLI, Python and YAML.

3

Rate and publish

Leave a star rating after you have used it. Made something useful? Publish it - free listings go live immediately.

Prefer the terminal? osr stack apply registry://starter installs the starter template.