Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
construct-ai-primary Skill Procurement Approval RoutingRoute procurement orders through value-based approval chains with authority matrix enforcement, HITL gates, and audit trail logging
0 -
construct-ai-primary Skill Gov Compliance Audit ExecutionExecute governance audits and compliance reviews, identify non-compliances, and track corrective actions to closure
0 -
aibot88 Bundle Scitex Auditscitex-audit
3 -
aibot88 Bundle Perl Security中文优先:用于Perl安全相关任务,帮助识别、设计、实现或验证对应工作流。English keywords: Comprehensive Perl security covering taint mode, input validation, safe process execution, DBI parameterized queries, web security (XSS/SQLi/CSRF), and perlcritic security policies.
3 -
aibot88 Bundle Hook FrameworkHook Framework do $100M Leads — 3 tipos de hook (dream outcome, problem, secret). Use para gerar headlines de LP, hooks de ads (especialmente short-form), subject lines de email, primeiras frases de copy.
3 -
aibot88 Bundle Uphold InvariantsLoad relevant code quality reference files (architecture, testing, security, type design, etc.) and apply their invariants to the current task. ALWAYS invoke before designing, writing, or editing ANY code.
3 -
aibot88 Bundle Dependency Fix NPMAction findings from dependency-audit-npm. Detects npm / pnpm / yarn (classic or berry), respects Corepack, uses overrides / resolutions for transitive vulns. Local commits only.
3 -
aibot88 Bundle Git Secret ScannerDetects leaked secrets in Git repositories using pattern-based scanning with Gitleaks rule definitions and the GitHub Secret Scanning API. Identifies exposed API keys, tokens, and credentials across full commit history using git log --all -p analysis.
3 -
aibot88 Bundle Security Assistant引导安全审查和漏洞评估,遵循 OWASP 标准。 使用时机:安全审计、漏洞检查、安全编码审查、威胁建模。 关键字:security, OWASP, vulnerability, authentication, authorization, 安全, 漏洞, 认证。
3 -
aibot88 Bundle Circleci Orb LinterValidates CircleCI configuration files and custom Orbs using the CircleCI CLI (circleci config validate) and Orb Development Kit. Checks for deprecated images, inefficient caching strategies, and security anti-patterns.
3 -
aibot88 Bundle Csp Policy AnalyzerParses and evaluates Content Security Policy headers using csp-parse and csp-evaluator libraries. Identifies overly permissive directives, missing protections, and generates tightened policy recommendations.
3 -
aibot88 Bundle Security Issue SyncSynchronize a security issue in <tracker> with the state of its GitHub discussion, the <security-list> mailing thread, and any <upstream> PRs that fix it. The skill gathers all relevant signals, proposes label, milestone, assignee, field and draft-email updates, and only applies changes the user has explicitly confirmed. Suggests the next step in the handling process and prints the CVE allocation link when a CVE is needed.
3 -
aibot88 Bundle Springboot Security中文优先:用于Spring Boot安全相关任务,帮助识别、设计、实现或验证对应工作流。English keywords: Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.
3 -
aibot88 Bundle Sync Security IssueSynchronize a security issue in <tracker> with the state of its GitHub discussion, the <security-list> mailing thread, and any <upstream> PRs that fix it. The skill gathers all relevant signals, proposes label, milestone, assignee, field and draft-email updates, and only applies changes the user has explicitly confirmed. Suggests the next step in the handling process and prints the CVE allocation link when a CVE is needed.
3 -
aibot88 Bundle Circleci Orb AuditorAudits CircleCI orb versions and configurations using the CircleCI v2 API. Flags deprecated orbs, provides pinning recommendations, and checks security advisories from the orb registry.
3 -
aibot88 Bundle Dependency Audit NPMAudit a JavaScript / TypeScript project (npm, pnpm, or yarn) for outdated versions, vulnerabilities, unused or missing declarations, lockfile drift, and duplicates.
3 -
aibot88 Bundle Legal Total AnalysisLegal Total Analysis — Lean pre-flight audit
3 -
aibot88 Bundle NPM Package AnalyzerDeep analysis of npm packages using npm-registry-fetch and pacote. Evaluates bundle size via bundlephobia API, checks security advisories from npm audit, and maps dependency trees with arborist.
3 -
aibot88 Bundle Genecyber Loadout PromptsSecurity Audit Guide Template
3 -
aibot88 Bundle NPM Registry AnalyzerQueries the npm registry API and npms.io scoring endpoint to evaluate package quality, maintenance scores, and download trends. Uses npm-audit for security vulnerability detection against the GitHub Advisory Database.
3 -
aibot88 Bundle Dependency Audit SwiftAudit a Swift / Xcode project (Swift Package Manager and/or CocoaPods) for outdated versions, vulnerabilities, unused or missing declarations, and duplicates.
3 -
aibot88 Bundle NPM Audit Deep ScannerExtends npm audit with deep transitive dependency analysis using the npm Registry API. Generates fix PRs via GitHub API and cross-checks advisories against the OSV.dev vulnerability database.
3 -
aibot88 Bundle Pypi Package InspectorQueries the PyPI JSON API and the libraries.io API to analyze Python package metadata, dependency trees, and version histories. Uses pip-audit for vulnerability scanning against the OSV database.
3 -
aibot88 Bundle Security Bounty Hunter中文优先:用于安全bountyhunter相关任务,帮助识别、设计、实现或验证对应工作流。English keywords: Hunt for exploitable, bounty-worthy security issues in repositories. Focuses on remotely reachable vulnerabilities that qualify for real reports instead of noisy local-only findings.
3 -
aibot88 Bundle Dependency Audit DotnetAudit a .NET / NuGet project for outdated versions, known vulnerabilities, unused or missing declarations, lockfile drift, and duplicate versions.
3 -
aibot88 Bundle Dependency Audit PythonAudit a Python project (pip, uv, Poetry, or pdm) for outdated versions, vulnerabilities, unused or missing declarations, lockfile drift, and duplicates.
3 -
aibot88 Bundle Security Scan Assistant引导自动化安全扫描、依赖包审计和机密检测。 使用时机:依赖审计、CVE 扫描、机密检测、许可证合规。 关键字:scan, audit, CVE, dependency, secret, SBOM, vulnerability, 扫描, 漏洞。
3 -
aibot88 Bundle Semgrep Pattern ScannerExecutes Semgrep CLI with custom YAML rules and the Semgrep Registry API to detect anti-patterns, vulnerabilities, and taint tracking violations. Outputs SARIF-formatted results for GitHub Security tab integration.
3 -
aibot88 Bundle Springboot Verification中文优先:用于Spring Boot验证相关任务,帮助识别、设计、实现或验证对应工作流。English keywords: Verification loop for Spring Boot projects: build, static analysis, tests with coverage, security scans, and diff review before release or PR.
3 -
aibot88 Bundle Girste Chihuaudit Docs SkillChihuaudit Claude Skill - Complete System Audit
3 -
aibot88 Bundle Photon Osint Web CrawlerPhoton is a blazing-fast Python web crawler purpose-built for OSINT operations. It extracts URLs, emails, social media accounts, files, secret keys, JavaScript endpoints, and subdomains from target websites with multithreaded efficiency.
3 -
aibot88 Bundle Zm2231 Z Audit Skills Z AuditZ-Audit: Security Audit for Vibe-Coded Projects
3 -
aibot88 Bundle Healthcare Phi Compliance中文优先:用于医疗PHI合规相关任务,帮助识别、设计、实现或验证对应工作流。English keywords: Protected Health Information (PHI) and Personally Identifiable Information (PII) compliance patterns for healthcare applications. Covers data classification, access control, audit trails, encryption, and common leak vectors.
3 -
aibot88 Bundle Sonarqube Analysis RunnerRun SonarQube static analysis scans via the SonarQube Web API and sonar-scanner CLI. Detects code smells, bugs, and security vulnerabilities with configurable quality gates and branch analysis support.
3 -
aibot88 Bundle Contabo Security HardeningContabo Security Hardening
3 -
aibot88 Bundle Nginx Config Linter TesterValidates nginx.conf files using the gixy static analyzer and crossplane parser library. Tests configuration for security misconfigs, HTTP header issues, and performs dry-run validation via nginx -t subprocess invocation.
3
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include procurement-approval-routing, gov-compliance-audit-execution, scitex-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.