Tools

AI-Agent Skills for Snyk Tasks

55 agent skills that handle jobs people use Snyk for — for Claude Code, Codex, and Cursor.

This collection provides modular AI-agent skills for developers automating application security and dependency management tasks. If you use tools like Snyk to manage vulnerabilities, these skills allow your AI agents to execute similar workflows directly within your development environment. You will find specialized agents for scanning codebases for hardcoded secrets with Gitleaks, conducting security audits on backend infrastructure, and checking for specific compliance patterns in frameworks like Next.js 16. These skills act as task-specific modules for tools like Claude Code, Cursor, and Codex, letting you delegate routine security checks to an agent. By integrating these into your workflow, you can automate vulnerability discovery, credential leak detection, and architecture audits during the development phase. This registry is designed for engineers who want to bring security verification closer to the editor, ensuring that your code, configurations, and API integrations are checked for common risks before you commit.

Top Snyk skills

senior-security

davila7

Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing. Includes security assessment tools, threat modeling, crypto implementation, and security automation. Use when designing security architecture, conducting penetration tests, implementing cryptography, or performing security audits.

3191

reviewing-nextjs-16-patterns

djankies

Review code for Next.js 16 compliance - security patterns, caching, breaking changes. Use when reviewing Next.js code, preparing for migration, or auditing for violations.

11106

backend-security-coder

sickn33

Expert in secure backend coding practices specializing in input validation, authentication, and API security. Use PROACTIVELY for backend security implementations or security code reviews.

2446

security

parcadei

Security audit workflow - vulnerability scan → verification

533

fix-security-vulnerability

getsentry

Analyze and propose fixes for Dependabot security alerts

716

skill-security-auditor

alirezarezvani

Security audit and vulnerability scanner for AI agent skills before installation. Use when: (1) evaluating a skill from an untrusted source, (2) auditing a skill directory or git repo URL for malicious code, (3) pre-install security gate for Claude Code plugins, OpenClaw skills, or Codex skills, (4) scanning Python scripts for dangerous patterns like os.system, eval, subprocess, network exfiltration, (5) detecting prompt injection in SKILL.md files, (6) checking dependency supply chain risks, (7) verifying file system access stays within skill boundaries. Triggers: "audit this skill", "is this skill safe", "scan skill for security", "check skill before install", "skill security check", "skill vulnerability scan".

510

codebase-cleanup-deps-audit

sickn33

You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.

26

dependency-auditor

alirezarezvani

Check dependencies for known vulnerabilities using npm audit, pip-audit, etc. Use when package.json or requirements.txt changes, or before deployments. Alerts on vulnerable dependencies. Triggers on dependency file changes, deployment prep, security mentions.

16

k8s-security

rohitg00

Audit Kubernetes RBAC, enforce policies, and manage secrets. Use for security reviews, permission audits, policy enforcement with Kyverno/Gatekeeper, and secret management.

15

contrib-pr-review

homeassistant-ai

Review a contribution PR for safety, quality, and readiness. Checks for security concerns, test coverage, size appropriateness, and intent alignment. Use when reviewing external contributions.

14

production-code-audit

davila7

Autonomously deep-scan entire codebase line-by-line, understand architecture and patterns, then systematically transform it to production-grade, corporate-level professional quality with optimizations

14

security-scanning-security-dependencies

sickn33

You are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security. Scan project dependencies across ecosystems to identify vulnerabilities, assess risks, and recommend remediation.

14

trivy-offline-vulnerability-scanning

benchflow-ai

Use Trivy vulnerability scanner in offline mode to discover security vulnerabilities in dependency files. This skill covers setting up offline scanning, executing Trivy against package lock files, and generating JSON vulnerability reports without requiring internet access.

14

k8s-policy

rohitg00

Kubernetes policy management with Kyverno and Gatekeeper. Use when enforcing security policies, validating resources, or auditing policy compliance.

13

tech-debt

vm0-ai

Technical debt management - scan codebase for bad smells and create tracking issues

13

security-automation

Ed1s0nZ

安全自动化的专业技能和方法论

12

substrate-vulnerability-scanner

trailofbits

Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin checks. Use when auditing Substrate runtimes or FRAME pallets.

12

windsurf-dependency-management

jeremylongshore

Analyze and update dependencies with vulnerability scanning. Activate when users mention "update dependencies", "security audit", "npm audit", "vulnerability scan", or "dependency updates". Handles dependency analysis and updates. Use when working with windsurf dependency management functionality. Trigger with phrases like "windsurf dependency management", "windsurf management", "windsurf".

12

dependency-management-deps-audit

sickn33

You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.

11

security-scan

LowyShin

Performs a rapid security sweep for secrets, API keys, and common vulnerabilities using cross-platform platform tools.

00

security-hardening

Doumajnik

Full security audit and hardening workflow covering OWASP Top 10, dependency scanning, secrets management, and infrastructure security. Use when auditing security, hardening an application, or responding to vulnerability reports. Triggers on: security, harden, vulnerability, OWASP, audit, CVE, penet

00

oss-vulnerabilities

JasonTheDeveloper

OWASP Open Source Software Top 10 vulnerability knowledge base for identifying, assessing, and remediating security risks in open source software dependencies.

00

audit-project

agent-sh

Use when user asks to 'review my code', 'audit the codebase', 'run code review', 'check for issues', 'find bugs', 'security review', 'performance review', or wants multi-agent iterative review. Spawns role-based reviewers (code-quality-reviewer, security-expert, performance-engineer, test-quality-gu

00

rank-audit

Houseofmvps

Full SEO/GEO/AEO/Citability/Content/Performance/Vertical/Security audit with auto-fix. Scans, reports, fixes, and verifies.

00

How to choose a Snyk skill

When selecting a skill, evaluate its specific scope and technical focus. Look at whether the agent is designed for broad security audits or targeted tasks like credential scanning. Review the documentation to understand what tools the skill calls, such as Gitleaks for secrets or custom audit scripts for infrastructure. Check for clear instructions on when to trigger the agent, as some are built for proactive coding while others are meant for post-development reviews. Prioritize well-maintained repositories that outline clear workflows for vulnerability detection and verification.

More Snyk skills

Frequently asked

Are these skills a replacement for Snyk?
No. These are independent agent skills designed to perform security-related tasks within your development environment. While they cover activities like dependency auditing or secret detection, they operate as standalone tools for your AI assistant. They do not provide the managed vulnerability databases or enterprise-grade reporting features typically associated with platforms like Snyk.
How do I know which skill fits my workflow?
Select a skill based on the specific security gap you are addressing. Use specialized tools like secrets-gitleaks for credential protection or backend-security-coder for input validation. If you need a broad overview, choose skills focused on comprehensive security audits. Always verify that the skill's technical approach matches your project's architecture and the framework version you are currently utilizing.

Skills for other tools

Search skills

Search the agent skills registry