Tools
AI-Agent Skills for Snyk Tasks
55 agent skills that handle jobs people use Snyk for — for Claude Code, Codex, and Cursor.
This collection provides modular AI-agent skills for developers automating application security and dependency management tasks. If you use tools like Snyk to manage vulnerabilities, these skills allow your AI agents to execute similar workflows directly within your development environment. You will find specialized agents for scanning codebases for hardcoded secrets with Gitleaks, conducting security audits on backend infrastructure, and checking for specific compliance patterns in frameworks like Next.js 16. These skills act as task-specific modules for tools like Claude Code, Cursor, and Codex, letting you delegate routine security checks to an agent. By integrating these into your workflow, you can automate vulnerability discovery, credential leak detection, and architecture audits during the development phase. This registry is designed for engineers who want to bring security verification closer to the editor, ensuring that your code, configurations, and API integrations are checked for common risks before you commit.
Top Snyk skills
senior-security
davila7
Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing. Includes security assessment tools, threat modeling, crypto implementation, and security automation. Use when designing security architecture, conducting penetration tests, implementing cryptography, or performing security audits.
reviewing-nextjs-16-patterns
djankies
Review code for Next.js 16 compliance - security patterns, caching, breaking changes. Use when reviewing Next.js code, preparing for migration, or auditing for violations.
backend-security-coder
sickn33
Expert in secure backend coding practices specializing in input validation, authentication, and API security. Use PROACTIVELY for backend security implementations or security code reviews.
security
parcadei
Security audit workflow - vulnerability scan → verification
fix-security-vulnerability
getsentry
Analyze and propose fixes for Dependabot security alerts
skill-security-auditor
alirezarezvani
Security audit and vulnerability scanner for AI agent skills before installation. Use when: (1) evaluating a skill from an untrusted source, (2) auditing a skill directory or git repo URL for malicious code, (3) pre-install security gate for Claude Code plugins, OpenClaw skills, or Codex skills, (4) scanning Python scripts for dangerous patterns like os.system, eval, subprocess, network exfiltration, (5) detecting prompt injection in SKILL.md files, (6) checking dependency supply chain risks, (7) verifying file system access stays within skill boundaries. Triggers: "audit this skill", "is this skill safe", "scan skill for security", "check skill before install", "skill security check", "skill vulnerability scan".
codebase-cleanup-deps-audit
sickn33
You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.
dependency-auditor
alirezarezvani
Check dependencies for known vulnerabilities using npm audit, pip-audit, etc. Use when package.json or requirements.txt changes, or before deployments. Alerts on vulnerable dependencies. Triggers on dependency file changes, deployment prep, security mentions.
k8s-security
rohitg00
Audit Kubernetes RBAC, enforce policies, and manage secrets. Use for security reviews, permission audits, policy enforcement with Kyverno/Gatekeeper, and secret management.
contrib-pr-review
homeassistant-ai
Review a contribution PR for safety, quality, and readiness. Checks for security concerns, test coverage, size appropriateness, and intent alignment. Use when reviewing external contributions.
production-code-audit
davila7
Autonomously deep-scan entire codebase line-by-line, understand architecture and patterns, then systematically transform it to production-grade, corporate-level professional quality with optimizations
security-scanning-security-dependencies
sickn33
You are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security. Scan project dependencies across ecosystems to identify vulnerabilities, assess risks, and recommend remediation.
trivy-offline-vulnerability-scanning
benchflow-ai
Use Trivy vulnerability scanner in offline mode to discover security vulnerabilities in dependency files. This skill covers setting up offline scanning, executing Trivy against package lock files, and generating JSON vulnerability reports without requiring internet access.
k8s-policy
rohitg00
Kubernetes policy management with Kyverno and Gatekeeper. Use when enforcing security policies, validating resources, or auditing policy compliance.
tech-debt
vm0-ai
Technical debt management - scan codebase for bad smells and create tracking issues
security-automation
Ed1s0nZ
安全自动化的专业技能和方法论
substrate-vulnerability-scanner
trailofbits
Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin checks. Use when auditing Substrate runtimes or FRAME pallets.
windsurf-dependency-management
jeremylongshore
Analyze and update dependencies with vulnerability scanning. Activate when users mention "update dependencies", "security audit", "npm audit", "vulnerability scan", or "dependency updates". Handles dependency analysis and updates. Use when working with windsurf dependency management functionality. Trigger with phrases like "windsurf dependency management", "windsurf management", "windsurf".
dependency-management-deps-audit
sickn33
You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.
security-scan
LowyShin
Performs a rapid security sweep for secrets, API keys, and common vulnerabilities using cross-platform platform tools.
security-hardening
Doumajnik
Full security audit and hardening workflow covering OWASP Top 10, dependency scanning, secrets management, and infrastructure security. Use when auditing security, hardening an application, or responding to vulnerability reports. Triggers on: security, harden, vulnerability, OWASP, audit, CVE, penet
oss-vulnerabilities
JasonTheDeveloper
OWASP Open Source Software Top 10 vulnerability knowledge base for identifying, assessing, and remediating security risks in open source software dependencies.
audit-project
agent-sh
Use when user asks to 'review my code', 'audit the codebase', 'run code review', 'check for issues', 'find bugs', 'security review', 'performance review', or wants multi-agent iterative review. Spawns role-based reviewers (code-quality-reviewer, security-expert, performance-engineer, test-quality-gu
rank-audit
Houseofmvps
Full SEO/GEO/AEO/Citability/Content/Performance/Vertical/Security audit with auto-fix. Scans, reports, fixes, and verifies.
How to choose a Snyk skill
When selecting a skill, evaluate its specific scope and technical focus. Look at whether the agent is designed for broad security audits or targeted tasks like credential scanning. Review the documentation to understand what tools the skill calls, such as Gitleaks for secrets or custom audit scripts for infrastructure. Check for clear instructions on when to trigger the agent, as some are built for proactive coding while others are meant for post-development reviews. Prioritize well-maintained repositories that outline clear workflows for vulnerability detection and verification.