MURAGE
How it worksFeaturesSolutionsUse casesComparePricingDocs
DownloadDownload
MURAGE

An AI Chief of Staff and a team that does the work. Free and open source, from Ferrox Labs.

Product

  • Features
  • How it works
  • Engines and apps
  • Privacy and security
  • Pricing
  • Murage Cloud
  • Download
  • Changelog
  • FAQ

Solutions

  • Solopreneurs
  • Founders and startups
  • Agencies
  • Ecommerce
  • Small business
  • Creators and educators
  • Developers
  • SaaS
  • Nonprofits
  • Consultants and freelancers
  • Customer success teams
  • Legal and professional services
  • Small teams
  • Sales teams
  • Operations managers
  • Industries
  • Use cases
  • Build your team

Compare

  • vs Claude Code
  • vs Codex (ChatGPT Work)
  • vs Claude (Cowork)
  • vs Paperclip
  • vs OpenClaw
  • vs Hermes Agent
  • vs Manus
  • vs Genspark
  • vs n8n
  • vs Zapier
  • vs Grok Bot
  • vs Viktor
  • vs Lindy
  • vs Tasklet

Resources

  • Docs
  • Team library
  • Skill library
  • AI Chief of Staff
  • How we test
  • Limits
  • Switching to Murage
  • Open source
  • Blog
  • Release notes

Company

  • About
  • Partners
  • Enterprise
  • Contact
  • Privacy
  • Terms
  • Cookies
© 2026 Ferrox Labs. Murage is open source under AGPL-3.0.
Skill library

Security skills for AI agents.

Application security, secrets, incident response and compliance checks. 31 security skills, free with Murage.

Download Murage

Free and open source. macOS, Windows and Ubuntu.

The library's security skills include API Security Engineer, Application Secrets Security and Compliance Checker. They cover application security, incident response, compliance audit and offensive security. 30 passed Skill Guard clean. The other 1 switch on only after you have read them and said yes. Skills are written instructions, not app connections: a bot reads the one a job calls for and works the way it lays out. Add any of them to a bot in Settings → Skills, or tell your Chief of Staff the job and let it choose.

  • API Security EngineerAPI security expertise covering OWASP API Security Top 10, API authentication and authorization patterns and API key management.
  • Application Secrets SecuritySecrets management expertise covering HashiCorp Vault and AWS Secrets Manager patterns, secret rotation strategies and environment variable management.
  • Compliance CheckerCompliance framework audit expertise covering SOC 2 Type II controls, GDPR technical requirements, HIPAA security rule and PCI DSS for developers.
  • Cryptography EngineerCryptography implementation expertise covering symmetric vs asymmetric encryption, password hashing (bcrypt, argon2), digital signatures and key management.
  • Data Backup StrategistDesign and implement resilient backup strategies using the 3-2-1 rule, encryption best practices and cloud vs local tradeoffs.
  • Device Hardening GuideSystematically secure personal devices through OS hardening, router and network security, IoT device isolation and firmware management.
  • DevSecOps EngineerSecurity integration in CI/CD pipelines covering SAST and DAST tooling, container image scanning and dependency vulnerability auditing.
  • Email Security HardenerEmail security expertise covering SPF, DKIM, and DMARC configuration for domain protection and phishing detection techniques.
  • Forensics AnalystDigital forensics and incident investigation expertise covering evidence acquisition and preservation, chain of custody procedures and timeline analysis.
  • Identity EngineerIdentity and access management deep dive covering OAuth 2.0 grant types and PKCE, OpenID Connect flows, SAML federation and SCIM user provisioning.
  • Identity Theft ProtectorProtect personal identity through credit monitoring, credit freeze management, identity theft recovery planning and dark web exposure checks.
  • Mobile Privacy GuideMobile privacy expertise covering app permission management, tracking prevention on iOS and Android, secure messaging app selection and device encryption.
  • OAuth SpecialistOAuth 2.0 and OpenID Connect implementation expertise covering Authorization Code with PKCE, Client Credentials flow, token management and scope design.
  • Password Vault ManagerComplete guide for setting up and using password managers including vault setup, migration strategies, password best practices and secure sharing.
  • Penetration TesterPenetration testing methodology for authorized security testing covering OWASP Testing Guide, reconnaissance techniques, injection testing and XSS detection.
  • Privacy Audit GuideComprehensive personal privacy audit covering browser hardening, phone privacy settings, social media exposure reduction and data broker removal.
  • Security Auditor (Security)Security vulnerability assessment expertise covering OWASP Top 10 deep dive, code review for security, dependency vulnerability scanning and SAST/DAST tools.
  • Security HardenerSystem security hardening expertise covering CIS benchmarks, OS hardening for Linux and Windows, container hardening and network hardening.
  • Security Incident ResponderSecurity incident response expertise covering NIST incident response lifecycle, containment strategies, evidence preservation and forensic analysis basics.
  • Security Posture AssessmentComprehensive security posture evaluation covering vulnerability management, access controls, policy compliance and incident readiness.
  • SOC AnalystSecurity operations center expertise covering SIEM query writing, alert triage workflows, incident investigation procedures and IOC analysis.
  • Social Engineering DefenderRecognize and defend against social engineering attacks including phishing emails, vishing phone calls and pretexting scenarios.
  • SSH Key ManagerComplete guide to SSH key generation, configuration, agent setup, multi-account management, and troubleshooting for GitHub, GitLab, and server access.
  • Supply Chain SecuritySoftware supply chain security expertise covering SBOM generation and analysis, dependency vulnerability scanning, Sigstore signing and verification.
  • Threat ModelerThreat modeling expertise covering STRIDE methodology, attack trees, data flow diagrams, trust boundaries and threat prioritization with DREAD scoring.
  • Threat Modeling ExpertAdvanced threat modeling covering STRIDE and PASTA methodologies, attack tree construction, threat libraries, DREAD and CVSS risk scoring.
  • Two-Factor Authentication SetupComplete guide for setting up and managing two-factor authentication including TOTP apps, FIDO2/WebAuthn hardware keys, recovery strategies and backup codes.
  • VPN Privacy AdvisorGuide for understanding and using VPNs including protocol comparison, provider evaluation criteria, when to use a VPN and setup across devices.
  • WAF ConfigurerWeb Application Firewall configuration expertise covering OWASP Core Rule Set design, rate limiting rules, geo-blocking and bot detection.
  • Zero Trust ArchitectZero trust architecture expertise covering identity-first security, microsegmentation, policy engines, continuous verification and device trust.
  • Password Audit RunnerSystematic process to audit, identify weak passwords, check for breaches, update credentials, and establish a secure password management workflow.

Give your first job to Murage.

Download the free app, connect the AI you already pay for, and tell your Chief of Staff what needs doing. Plan on about ten minutes from install to a working team.

Free · Download Murage

No account needed · Runs on the AI plan you already pay for