Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
aibot88 Bundle NPM Package Audit AnalyzerAnalyzes npm package security advisories using npm audit, the npm Registry API, and the GitHub Advisory Database GraphQL API. Produces prioritized vulnerability reports with upgrade path recommendations.
3 -
aibot88 Bundle Post Milestone Audit SwiftAudit a Swift / Xcode codebase after a milestone tag is cut — drift, regressions, extraction signals, and convention compliance against documented rules.
3 -
aibot88 Bundle Semgrep Sast Scanner SkillRuns Semgrep static analysis with custom rule packs targeting OWASP Top 10 patterns. Uses semgrep CLI with --config=auto and --sarif output for GitHub Advanced Security integration and CWE-tagged finding reports.
3 -
aibot88 Bundle Semgrep Security Scanner 2Scan codebases for security vulnerabilities and anti-patterns using Semgrep OSS rules and the Semgrep CLI. Supports custom YAML rule authoring and SARIF output for CI integration.
3 -
aibot88 Bundle Dill Lk Claude Skillls SecuritySkill: Security
3 -
aibot88 Bundle Betterleaks Secrets ScannerA fast, configurable secrets scanner built by the creator of Gitleaks and backed by Aikido Security. Betterleaks detects leaked passwords, API keys, and tokens in git repositories, directories, and stdin with CEL-based validation and parallelized scanning.
3 -
aibot88 Bundle NPM Package Audit ReferenceProvides deep dependency analysis using npm audit, socket.dev API for supply chain risk scoring, and bundlephobia API for bundle size impact assessment. Generates license compliance reports via license-checker.
3 -
aibot88 Bundle Owasp Zap Scan OrchestratorOrchestrates OWASP ZAP active and passive scans via the ZAP API, automating spider crawls, AJAX spidering with Selenium, and generating SARIF-format vulnerability reports.
3 -
aibot88 Bundle Post Milestone Audit DotnetAudit a .NET / C# codebase after a milestone tag is cut — drift, regressions, extraction signals, and convention compliance against documented rules.
3 -
aibot88 Bundle Post Milestone Audit NestjsAudit a NestJS (TypeScript) codebase after a milestone tag is cut — drift, regressions, extraction signals, and convention compliance against documented rules.
3 -
aibot88 Bundle Post Milestone Audit PythonAudit a Python codebase after a milestone tag is cut — drift, regressions, extraction signals, and convention compliance against documented rules.
3 -
aibot88 Bundle Snyk Dependency Audit SkillUses the Snyk CLI and REST API v1 to scan package manifests for known CVEs. Cross-references findings with the GitHub Advisory Database and produces SBOM documents in CycloneDX format.
3 -
aibot88 Bundle NPM Dependency Audit ScannerScans Node.js projects for vulnerable dependencies using npm audit and the OSV.dev REST API. Cross-references CVE databases via the National Vulnerability Database API v2.0 and generates SBOM documents in CycloneDX format.
3 -
aibot88 Bundle Scan Python Code For Risky Security Patterns With Bandit BefCatch insecure Python calls, weak crypto usage, shell injection risks, and similar patterns before merge or release.
3 -
aibot88 Bundle Audit Github Actions For Privilege And Supply Chain Risks WiRun a focused security pass on GitHub Actions workflows before merge so token misuse, dangerous permissions, and unpinned actions are caught early.
3 -
aibot88 Bundle Audit Python Dependency Sets For Known Vulnerabilities BeforScan Python requirements and environments for known vulnerable or malicious packages before they move further through delivery or promotion workflows.
3 -
aibot88 Bundle Audit Python Environments And Requirements Files For Known VCheck Python environments and requirements files for published vulnerabilities before shipping, upgrading, or approving dependency changes.
3 -
aibot88 Bundle Baseline And Review Repository Secret Findings With Detect SScan a repository for secrets, keep an auditable baseline, and review only newly introduced findings during commits or CI checks.
3 -
aibot88 Bundle Capture Linux Runtime Security Events And Suspicious BehavioWatch live Linux and container activity through eBPF so you can triage suspicious runtime behavior before it disappears into guesswork.
3 -
aibot88 Bundle Gate Pull Requests With Targeted Diff Aware AI Security ReviRun a Claude Code powered security review pass on trusted pull requests so suspicious auth, secret, injection, and unsafe logic changes surface before merge.
3 -
aibot88 Bundle Inspect Binary Hardening Flags And Exploit Mitigations WithCheck ELF or PE binaries for hardening gaps like NX, PIE, RELRO, stack canaries, and Fortify before release or incident review.
3 -
aibot88 Bundle Lint Dotenv Files For Duplicated Keys And Unsafe FormattingCheck dotenv files for duplicated keys, malformed values, and formatting mistakes before they break local runs or secret handoffs.
3 -
aibot88 Bundle Run Security Audits And Variant Analysis Workflows In ClaudeUse curated Trail of Bits security skills inside Claude Code when the job is auditing, variant hunting, or fix verification rather than generic coding assistance.
3 -
aibot88 Bundle Score Open Source Repositories For Supply Chain Risk SignalsCheck a repository against OpenSSF security heuristics before you trust it as a dependency, approve it for use, or ship from it.
3 -
aibot88 Bundle Triage Pull Request Security Risks With Staged Threat ModeliAnalyze a GitHub pull request for security impact, run targeted vulnerability-investigation skills when Stage 1 finds credible threats, and return a structured verdict instead of doing an ad hoc manual review.
3 -
aibot88 Bundle Turn Windows Event Logs Into Sigma Backed Threat Hunting TimParse Windows event logs into fast timelines and detection-rich outputs so agents can triage suspicious host activity, search for known patterns, and hand investigators reviewable artifacts.
3 -
frank-luongt Bundle Owasp Top10 3<!-- AUTO-GENERATED by export-skills.py — DO NOT EDIT -->
-
frank-luongt Bundle Iam Security 3<!-- AUTO-GENERATED by export-skills.py — DO NOT EDIT -->
-
frank-luongt Bundle Owasp API Top10 3<!-- AUTO-GENERATED by export-skills.py — DO NOT EDIT -->
-
frank-luongt Bundle Security Auditor 3<!-- AUTO-GENERATED by export-skills.py — DO NOT EDIT -->
-
frank-luongt Bundle Hipaa Security Rule 3<!-- AUTO-GENERATED by export-skills.py — DO NOT EDIT -->
-
frank-luongt Bundle API Security Patterns 5<!-- AUTO-GENERATED by export-skills.py — DO NOT EDIT -->
-
frank-luongt Bundle API Security Best Practices 3<!-- AUTO-GENERATED by export-skills.py — DO NOT EDIT -->
-
frank-luongt Skill Hipaa Security Rule 4<!-- AUTO-GENERATED by export-plugins.py — DO NOT EDIT -->
-
frank-luongt Bundle Security Scanning Security Sast 3<!-- AUTO-GENERATED by export-skills.py — DO NOT EDIT -->
-
frank-luongt Skill Owasp Top10 4<!-- AUTO-GENERATED by export-plugins.py — DO NOT EDIT -->
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include npm-package-audit-analyzer, post-milestone-audit-swift, semgrep-sast-scanner-skill. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.