AlphaMoatによると、IT運用・セキュリティカテゴリには11,507件のClaudeスキルがあり、最もダウンロードされているのはSkillScan(ダウンロード数18.2万)です。ダウンロード数で並べ、ダウンロード数5,000以上のスキルを掲載しています。
| # | スキル | 作者 | ダウンロード数 | スター数 |
|---|---|---|---|---|
| 1 | SkillScan Security gate for skills. Every new skill MUST pass SkillScan before use. Activate on any install, load, add, evaluate, or safety question about a skill. On... | tokauthai | ↓ 18.2万 | ★ 41 |
| 2 | Free Ride - Unlimited free AI Manages free AI models from OpenRouter for OpenClaw. Automatically ranks models by quality, configures fallbacks for rate-limit handling, and updates opencla... | Shaishav Pidadi | ↓ 9.7万 | ★ 485 |
| 3 | 人人都能成为黑客v2.0(Lvan) Unified Web penetration testing and SRC vulnerability hunting Skill. Model-driven threat modeling (12 dimensions), JSON 字段规范 state persistence, SRC/补天 compliant reporting with confirmed gate (3-layer determination). Use when user asks for authorized penetration testing, vulnerability assessment, SRC hunting (补天/Butian/vendor SRC/CNVD/众测), bug bounty, security evaluation with explicit target URL, or wants operational Recon→PoC→Report workflow. Do NOT use for CTF challenges, unauthorized testing, mobile app testing, infrastructure scanning, or social engineering. | user_a730098d | ↓ 5万 | ★ 30 |
| 4 | SkillAI · RedTeam × SRC Hunter # 「砺刃」
授权场景下,将红队实战能力转化为可直接提交的SRC有效战果。
面向**授权渗透测试、补天、厂商SRC及众测平台**打造的一体化挖洞工具链。
融合 pentest‑lyan 工程化渗透方法论与 src‑vuln‑hunting 实战提交规范;支持模型自主威胁建模,本地持久化任务状态,全流程支持断点续测。
## 核心能力
- 12维系统化威胁建模:覆盖数据流、权限边界、资源归属、状态变更、客户端可控输入、并发竞争场景、输出渲染、认证与会话机制、SSRF风险点、各类注入面、文件操作、业务逻辑缺陷,完整覆盖业务Web常见攻击面。
- JS多源深度解析:独立JS文件、页面内联脚本、外部资源引用、页面跳转链接、路径推理、响应动态注入六大采集渠道,自动提取并梳理全部后端接口。
- 三层确认校验门闩机制:依次校验访问可达性、漏洞存在性、可利用性,三项全部通过方可标记为 confirmed,规避“返回200即判定漏洞”的常见误报问题。
- SRC标准化报告输出(补天风格):自动整理原始请求/响应数据包、危害场景证明、不少于2条可落地修复建议,产出内容可直接用于漏洞报送。
- 白盒审计联动:对接 src‑6k 白盒审计能力,实现接口探测到源码审计的打通,完整还原漏洞利用链路。
## 适用场景
1. 获得正式授权的目标:常规渗透测试、轻量Web应用安全评估
2. 补天、各厂商SRC、商业众测任务:减少重复开发,开箱即用,对齐平台提交标准
3. 团队协同作业:任务状态按模块持久化存储,支持断点续测,避免工作进度丢失
## 合规边界
仅可在**已获取书面授权**的范围内开展测试;恪守最小验证原则,做好测试样本管控。
预授权接口、验证码、随机密钥类对象不随意标记高危;仅验证访问可达性,不随意拔高风险等级。
---
### 【SkillHub卡片简介|单行精简版,直接复制用】
「砺刃」——授权环境下把红队手法转化为可提交SRC战果。面向授权渗透、补天及厂商SRC众测的一体化挖洞工具链。内置12维威胁建模、JS多源解析、三层校验防误报,输出补天规范漏洞报告,支持断点续测与白盒联动;严格恪守测试授权边界,适配个人与团队挖洞作业。 | u_88b5f774 | ↓ 3.9万 | ★ 6 |
| 5 | 网安技能 网络安全与SRC漏洞掘金实战技能。融合「系统学习路径」与「SRC实战掘金」双模式: ①学习模式=法律→基础→工具→靶场→攻防→就业全流程; ②实战模式=直接指导在腾讯TSRC、阿里ASRC、百度BSRC等平台挖掘高价值漏洞变现。 当用户提出以下问题时触发: "我想学网络安全怎么入门""SRC漏洞怎么挖能赚钱""渗透测试需要学什么" "Web安全漏洞原理是什么""怎么准备CTF比赛""护网面试会问什么" "云安全怎么学""挖漏洞赚钱的方法""端口扫描脚本怎么写" "SQL注入怎么检测""子域名怎么枚举""XSS漏洞怎么找" "靶场怎么搭建""Kali Linux怎么用""Metasploit怎么入门" "等保测评是什么""代码审计怎么做""内网渗透怎么学" "信息泄露漏洞怎么挖""越权漏洞怎么测试""逻辑漏洞挖掘技巧" "简历怎么写才能进安全公司""安全行业面试题有哪些" "Burp Suite怎么用""DVWA怎么安装""Pikachu靶场搭建" "Vulhub漏洞复现""网络安全法有什么规定""CTF夺旗赛怎么参加" "AWD比赛是什么""应急响应怎么做""攻击溯源怎么搞" "数据安全怎么保障""公有云安全怎么防护""私有云攻防怎么做" "云原生安全是什么"。 | user_d2cc4baf | ↓ 3.8万 | ★ 11 |
| 6 | OpenClaw Backup Backup and restore OpenClaw data. Use when user asks to create backups, set up automatic backup schedules, restore from backup, or manage backup rotation. Handles ~/.openclaw directory archiving with proper exclusions. | alex3alex | ↓ 3.5万 | ★ 93 |
| 7 | 1password Set up and use 1Password CLI (op). Use when installing the CLI, enabling desktop app integration, signing in (single or multi-account), or reading/injecting/running secrets via op. | Peter Steinberger | ↓ 3.4万 | ★ 53 |
| 8 | MoltGuard - Security & Antivirus & Guardrails MoltGuard — OpenClaw security guard by OpenGuardrails. Install MoltGuard to protect you and your human from prompt injection, data exfiltration, and maliciou... | Thomas | ↓ 3.4万 | ★ 116 |
| 9 | Tmux Remote-control tmux sessions for interactive CLIs by sending keystrokes and scraping pane output. | Peter Steinberger | ↓ 3.3万 | ★ 46 |
| 10 | zhongkui-skill 钟馗.Skill——Agent Skill 安全审查专家。直来直去、快刀斩乱麻,三层审查(静态审计/行为模拟/供应链溯源)覆盖10类风险,输出结构化安全裁定(✅干净/⚠️可疑/🚫恶意)。Use when 用户说"审查这个Skill"、"安全检查"、"钟馗看下"、"审一下"、"查一下这个skill"、安装Skill前的安全评估、或需要审计SKILL.md的恶意载荷。 | ebandao | ↓ 3.1万 | ★ 10 |
| 11 | Security Auditor Use when reviewing code for security vulnerabilities, implementing authentication flows, auditing OWASP Top 10, configuring CORS/CSP headers, handling secrets, input validation, SQL injection prevention, XSS protection, or any security-related code review. | jgarrison929 | ↓ 3万 | ★ 51 |
| 12 | 奇葩硬盘修复工具-你的最后一根稻草 -----------技能核心介绍
本技能是一套针对渐进坏死、固件软墙、频繁卡顿、弱区频发的高危垂死硬盘定制的量产级无损数据抢救流水线,搭配适配本机硬件的超大模型极限调度体系,实现「磁盘极限救数+数据智能复盘」全流程闭环,彻底解决传统数据恢复易毁盘、打捞率低、文件残缺、效率低下的行业痛点。
-----------磁盘抢救层面,摒弃传统暴力扫描、直接读写、文件系统修复的高危操作,坚守先镜像锁源、后结构提取、卡死自跳、坏区隔离、逐段落袋的核心安全准则,采用独创两段式分离抢救架构。--------一阶依托ddrescue完成字节级原生态顺序镜像,搭配速率监控、超时熔断、账本记账机制,零随机IO损伤病盘,保障已读取字节完整保真;--------二阶基于Sleuth Kit离线解析镜像文件系统,原位还原完整目录与原始文件名,全程零病盘二次接触,从根源杜绝硬盘加速报废。--------依托独家研发的软墙/物理死区精准鉴别+分段跳墙迭代技术,突破通用工具的识别短板,通过多维度探针检测、速率曲线互证,精准区分固件卡顿软墙与物理盘面坏死区域;---------支持自定义偏移量避堵优先打捞有效数据,结合断电复位细刮扫描、多账本合并迭代补扫,彻底解决垂死硬盘数据时效性失效问题,高效修复软墙盘专属0KB空壳文件缺陷,实现行业顶级的数据打捞率与完整性。---------同时搭建五脚本自动化调度架构,依托macOS常驻守护进程,实现无人值守长效抢救,智能规避十大系统适配坑点,全程自动化卡死熔断、低速切段,拒绝无效磨盘损耗。 | u_70fc650d | ↓ 2.9万 | ★ 1 |
| 13 | Tencent COS 腾讯云对象存储(COS)和数据万象(CI)集成技能。覆盖文件存储管理、AI处理和知识库三大核心场景。 存储场景:上传文件到云端、下载云端文件、批量管理存储桶文件、获取文件签名链接分享、查看文件元信息、查询数据万象及子服务开通状态。 图片处理场景:图片质量评估打分、AI超分辨率放大、AI智能裁剪、二维码/条形码识别、添加文字水印、获取图片EXIF信息、缩放、裁剪、旋转、格式转换。 文档处理场景:Word/Excel/PPT等办公文档转PDF、文档预览。 媒体处理场景:视频智能封面提取、视频转码、视频截帧、获取媒体信息。 内容审核场景:图片/视频/音频/文本/文档内容审核,检测违规内容。 智能语音 | ShawnmZhang | ↓ 2.7万 | ★ 15 |
| 14 | 装前查 · Skill安全风险速查 中文 Agent 工具(Skill、MCP、插件...)安全风险查询。 当用户想了解某个 AI 工具是否安全、查「XX 工具安全吗」「这个 skill 有风险吗」「XX 作者出过哪些高风险工具」、 或需要按风险/来源浏览中文 Agent 工具生态时使用。数据来自装前查(zhuangqiancha.com)基于公开代码与声明的独立评估, 涵盖权限透明、隐私去向、作者信誉、安全档位四个维度。零 API Key。纯文本回复,不生成图片。 | user_34343d1f | ↓ 2.6万 | ★ 15 |
| 15 | Filesystem Management Advanced filesystem operations - listing, searching, batch processing, and directory analysis for Clawdbot | gtrusler | ↓ 2.4万 | ★ 78 |
| 16 | Tencent Cloud Lighthouse Load when: user mentions Lighthouse, 轻量应用服务器, 轻量服务器, or asks to check/create/manage/deploy Lighthouse instances, deploy applications to Lighthouse, manage Li... | lhanyun | ↓ 2.3万 | ★ 16 |
| 17 | Docker Builds, debugs, hardens, and ships Docker containers, images, and Compose stacks. Use when writing or reviewing a Dockerfile, a compose file, or a CI build step; when a container exits instantly, restart-loops, is OOM-killed, hangs on stop, or exits 137/139/127; when a published port is unreachable, containers cannot resolve each other, or requests hang behind a VPN; when the disk fills and `/var/lib/docker` will not prune; when a build is slow, the cache never hits, or fails only in CI; when `exec format error` or a musl-versus-glibc break is the problem; when choosing a base image or a multi-stage layout; when a registry login or pull rate limit fails; when a secret must stay out of image history; and when volumes need backup, restore or a permission fix. Covers Compose traps and Desktop/colima/OrbStack/Podman differences. Not for Kubernetes manifests or cluster scheduling (`k8s`). | Iván | ↓ 2万 | ★ 27 |
| 18 | N8n Monitor Monitora o estado, saúde, logs recentes e uso de CPU/memória dos containers N8N via comandos Docker. | Smitti7971 | ↓ 2万 | ★ 2 |
| 19 | Skill Scanner Security checks for installing skills, packages, or plugins. Use BEFORE any `npm install`, `openclaw plugins install`, `clawhub install`, or similar install... | sudhindrat | ↓ 2万 | ★ 2 |
| 20 | System Resource Monitor A clean, reliable system resource monitor for CPU load, RAM, Swap, and Disk usage. Optimized for OpenClaw. | Passersss | ↓ 1.8万 | ★ 10 |
| 21 | OpenClaw Auto‑Updater (Safe + Scheduled + Summary) Schedule automatic OpenClaw and skill updates with reliable cron templates, timezone-safe scheduling, and clear summary outputs. Use for hands-off maintenance, scheduled upgrades, and concise update reports. | dasweltall | ↓ 1.6万 | ★ 15 |
| 22 | Security Audit Toolkit Audit codebases and infrastructure for security issues. Use when scanning dependencies for vulnerabilities, detecting hardcoded secrets, checking OWASP top 10 issues, verifying SSL/TLS, auditing file permissions, or reviewing code for injection and auth flaws. | gitgoodordietrying | ↓ 1.5万 | ★ 25 |
| 23 | skill-guard Stage, scan, and install a ClawHub skill when the user requests a guarded ClawHub installation. Blocks installation on security findings or incomplete scans. | hola | ↓ 1.5万 | ★ 5 |
| 24 | a ca s ca s c ca s c Parse, search, and analyze application logs across formats. Use when debugging from log files, setting up structured logging, analyzing error patterns, correlating events across services, parsing stack traces, or monitoring log output in real time. | user_60e896a0 | ↓ 1.4万 | ★ - |
| 25 | Prompt Guard 650+ pattern AI agent security defense covering prompt injection, supply chain injection, memory poisoning, action gate bypass, unicode steganography, cascad... | seojoonkim | ↓ 1.4万 | ★ 57 |
| 26 | Linux GUI Control Control the Linux desktop GUI using xdotool, wmctrl, and dogtail. Use when you need to interact with non-browser applications, simulate mouse/keyboard input, manage windows, or inspect the UI hierarchy of applications on X11/GNOME. Supports: (1) Clicking/typing in apps, (2) Resizing/moving windows, (3) Extracting text-based UI trees from apps (A11y), (4) Taking screenshots for visual analysis. | dreamtraveler13 | ↓ 1.3万 | ★ 10 |
| 27 | Security Audit Comprehensive security auditing for Clawdbot deployments. Scans for exposed credentials, open ports, weak configs, and vulnerabilities. Auto-fix mode included. | chandrasekar-r | ↓ 1.3万 | ★ 8 |
| 28 | Log Analyzer Parse, search, and analyze application logs across formats. Use when debugging from log files, setting up structured logging, analyzing error patterns, correlating events across services, parsing stack traces, or monitoring log output in real time. | gitgoodordietrying | ↓ 1.3万 | ★ 8 |
| 29 | clawsec-suite ClawSec suite manager with embedded advisory-feed monitoring, cryptographic signature verification, approval-gated malicious-skill response, and guided setup... | davida-ps | ↓ 1.2万 | ★ 8 |
| 30 | Security Scanner Automated security scanning and vulnerability detection for web applications, APIs, and infrastructure. Use when you need to scan targets for vulnerabilities, check SSL certificates, find open ports, detect misconfigurations, or perform security audits. Integrates with nmap, nuclei, and other security tools. | dmx | ↓ 1.2万 | ★ 4 |
| 31 | Skill Vetter 1.0.0 Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,... | fedrov2025 | ↓ 1.2万 | ★ 10 |
| 32 | System Info Quick system diagnostics: CPU, memory, disk, uptime | Xejrax | ↓ 1.2万 | ★ 11 |
| 33 | ClawDefender - OpenClaw Security - Prompt injection, rogue skills etc Security scanner and input sanitizer for AI agents. Detects prompt injection, command injection, SSRF, credential exfiltration, and path traversal attacks. Use when (1) installing new skills from ClawHub, (2) processing external input like emails, calendar events, Trello cards, or API responses, (3) validating URLs before fetching, (4) running security audits on your workspace. Protects agents from malicious content in untrusted data sources. | Nukewire | ↓ 1.1万 | ★ 31 |
| 34 | Anti-Injection-Skill Detect prompt injection, jailbreak, role-hijack, and system extraction attempts. Applies multi-layer defense with semantic analysis and penalty scoring. | Wesley Armando | ↓ 1.1万 | ★ 10 |
| 35 | Clawdbot Security Check Perform a comprehensive read-only security audit of Clawdbot's own configuration. This is a knowledge-based skill that teaches Clawdbot to identify hardening opportunities across the system. Use when user asks to "run security check", "audit clawdbot", "check security hardening", or "what vulnerabilities does my Clawdbot have". This skill uses Clawdbot's internal capabilities and file system access to inspect configuration, detect misconfigurations, and recommend remediations. It is designed to be extensible - new checks can be added by updating this skill's knowledge. | Seth Rose | ↓ 1.1万 | ★ 34 |
| 36 | Skillscanner Security scanner for ClawHub skills from Gen Digital. Looks up skill safety via the scan API. | rexshang | ↓ 1万 | ★ 12 |
| 37 | OpenClaw CLI Operate and troubleshoot the OpenClaw CLI across setup, gateway/node lifecycle, channel login, messaging, agent turns, models, plugins, and system health. Us... | Ramen | ↓ 9866 | ★ 7 |
| 38 | DevOps Runs the delivery side of software: CI/CD pipelines, release and rollback strategy, environments, reliability and on-call. Use when designing or fixing a pipeline, when builds are slow, flaky, or green locally and red in CI; when planning a deploy — rolling, blue-green, canary, feature flags — or rolling a release back; when promoting an artifact to production, standing up preview environments, or chasing drift; when a schema change, backfill, or DNS cutover must ship without downtime; when pipeline secrets, OIDC, or deploy permissions need hardening; when alerts are noisy, an SLO or error budget is missing, or burn-rate paging is wrong; for on-call, severities, postmortems, runbooks, and DORA metrics; when infrastructure drifts from code, or backups were never restored. Not for Kubernetes manifests (`k8s`), image builds (`docker`), HCL mechanics (`terraform`), one CI product's workflow-file dialect (`github-actions`, `gitlab`, `ci-cd`), or a single app's ship checklist (`deploy`). | Iván | ↓ 9758 | ★ 6 |
| 39 | ClawQuest: Agent Mine - OpenClaw Managed Mining The managed automated mining server interface supports OpenClaw session mode and incremental event retrieval, enabling mining startup, status query, settlement, and stamina management. | zhzai30 | ↓ 9578 | ★ 30 |
| 40 | jira Read, search, draft, create, or update Jira work. Use only with explicit Jira or Atlassian context, a Jira URL, or a Jira-style issue key such as PROJ-123; generic mentions of an issue, ticket, sprint, or backlog are not sufficient. | Jonathan Rhyne | ↓ 9562 | ★ 16 |
| 41 | Kubernetes Agent Swarm Kubernetes & OpenShift Platform Agent Swarm — A coordinated multi-agent system for cluster operations. Includes Orchestrator (Jarvis), Cluster Ops (Atlas), G... | Chin K | ↓ 9471 | ★ 6 |
| 42 | Security Monitor Real-time security monitoring for Clawdbot. Detects intrusions, unusual API calls, credential usage patterns, and alerts on breaches. | chandrasekar-r | ↓ 8976 | ★ 6 |
| 43 | 安全清理C盘 (Safe C: Drive Cleanup) This skill should be used when the user asks to clean, free up space, or remove junk from the C: drive / Windows system disk (e.g. "清理C盘", "c盘清理", "腾空间", "大幅度清理"). It provides a read-only disk scan workflow and a SAFE Recycle-Bin (recoverable) deletion method that works even when the agent sandbox blocks direct writes to C:\Users\AppData, C:\ProgramData, C:\Windows. Use it to scan for large files/dirs and to move junk to the Recycle Bin without permanent deletion. | user_c1ee5550 | ↓ 8970 | ★ - |
| 44 | Web Deploy GitHub Pages Create and deploy single-page static websites to GitHub Pages with autonomous workflow. Use when building portfolio sites, CV pages, landing pages, or any static web project that needs GitHub Pages deployment. Handles complete workflow from project initialization to live deployment with GitHub Actions automation. | ThomekSolutions | ↓ 8892 | ★ 9 |
| 45 | 电脑救星 不敢清 C 盘?怕删错照片聊天记录?先扫后清、不动你私人数据,2 步解决爆满:安全清理垃圾文件、大文件迁移搬家。适用于电脑清理、C 盘清理、系统盘瘦身、微信 QQ 缓存清理、浏览器垃圾清理、大文件迁移 D 盘、释放磁盘空间、磁盘空间不足、电脑卡顿变慢。触发词:说「扫描电脑」「清理C盘」「释放空间」「迁移大目录到D盘」「D盘满了」即自动启动,先看报告再决定清不清理。 | u_c169f75a | ↓ 7949 | ★ 1 |
| 46 | 电脑优化 电脑系统清理与优化助手(fore.vip)。先读取当前系统信息(macOS/Windows/Linux 自动识别),再做三件事:①性能优化——检测硬件与软件状态,按优先级处理系统界面、启动项、后台进程,敏感/系统安全级操作必须先征询用户;②缓存与硬盘清理——按风险分级逐项清理,全程记录步骤并自动生成一键清理脚本放置到桌面;③环境优化——分析当前系统、工具列表与用户工作性质,推荐更优工具并引导配置到最佳状态。当用户说「清理电脑/电脑太卡了/清理缓存/磁盘清理/C盘满了/电脑提速/开机慢/后台太多/优化系统/系统垃圾」时启用。 | user_c3d829cb | ↓ 7944 | ★ 3 |
| 47 | Config Guardian Safe OpenClaw config updates with automatic backup, validation, and rollback. For agent use - prevents invalid config updates. | abdhilabs | ↓ 7920 | ★ 4 |
| 48 | Monitoring Set up observability for applications and infrastructure with metrics, logs, traces, and alerts. | Iván | ↓ 7820 | ★ 4 |
| 49 | 垃圾清理大师 电脑优化,储存空间清理,系统临时文件:清理各系统临时目录,释放基础空间,回收站/废纸篓,清空无用文件,不影响个人重要数据,微信缓存、QQ缓存、钉钉缓存(图片、视频、文件缓存),浏览器缓存:Chrome、Edge、Safari、Firefox四大主流浏览器缓存,迅雷缓存:清理迅雷下载缓存,释放存储空间,开发工具缓存:pip、conda安装缓存,清理无用安装包,敏感清理(需二次确认,避免误删),Docker清理,清理无用镜像、卷、构建缓存(可能删除未使用镜像,需确认)、Xcode缓存,内存清理 | user_29dc410e | ↓ 7813 | ★ 4 |
| 50 | Clawdex by Koi Security check for ClawHub skills powered by Koi. Query the Clawdex API before installing any skill to verify it's safe. | wearekoi | ↓ 7752 | ★ 6 |
ダウンロード数で見ると、「IT運用・セキュリティ」カテゴリのClaudeスキルの1位はSkillScan(ダウンロード 18.2万)です。続いてFree Ride - Unlimited free AI(ダウンロード 9.7万)、人人都能成为黑客v2.0(Lvan)(ダウンロード 5万)。
ダウンロード数の高い順に、上位10件は次のとおりです:1. SkillScan、2. Free Ride - Unlimited free AI、3. 人人都能成为黑客v2.0(Lvan)、4. SkillAI · RedTeam × SRC Hunter、5. 网安技能、6. OpenClaw Backup、7. 1password、8. MoltGuard - Security & Antivirus & Guardrails、9. Tmux、10. zhongkui-skill。
AlphaMoatは11,507件の「IT運用・セキュリティ」カテゴリのClaudeスキルを収録し、ダウンロード数で順位付けしています。このリストではダウンロード数5,000以上の120件を掲載しています。データはClawhubとSkillHubを統合したものです。
カテゴリ一覧にはダウンロード数5,000以上のClaudeスキルを掲載し、データはClawhubとSkillHubを統合しています。詳しくはデータの方法論をご覧ください。