Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
aibot88 Bundle GreynoiseClassify IP addresses as internet scanners (benign/malicious) or targeted attackers — filters noise from security alerts
3 -
aibot88 Bundle Hora DepsDependency audit and smart update — scan outdated packages, check vulnerabilities, update with automatic testing. Use when user says deps, dependencies, outdated, update packages, npm audit, vulnerabilities, security audit deps, upgrade, bump versions. Do NOT use for security code audit — use hora-security. Do NOT use for installing new packages — just npm install.
3 -
aibot88 Bundle Hunt PlanCreate phase plans for a threat hunt with exact telemetry tasks, receipts, and query outputs
3 -
aibot88 Bundle Inet MailMailstandaarden getest door internet.nl: SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), DMARC (Domain-based Message Authentication), STARTTLS, DANE (DNS-based Authentication of Named Entities). Triggers: mail test, DMARC, DKIM, SPF, STARTTLS, DANE, mailserver beveiliging, email security, e-mailbeveiliging, mailstandaarden, anti-spoofing
3 -
aibot88 Bundle Libsecretlibsecret - Secret generation and environment utilities. generateSecret creates cryptographic random secrets. generateSecretB64 creates base64url secrets. createJwt signs HS256 JSON Web Tokens. getEnvVar and setEnvVar manage .env files. hashValues creates deterministic hashes. Use for credential management, JWT creation, and environment configuration.
3 -
aibot88 Bundle Memstack Business LicensingUse this skill when the user says 'licensing', 'license audit', 'can I use this commercially', 'OSS license check', 'license compatibility', 'GPL', 'MIT', 'AGPL', 'copyleft'. Scans the repository for every dependency and asset license, then produces a per-package verdict table: ready for commercial use, citation/attribution required, more information needed, or commercial use not allowed. Do NOT use for vulnerability scanning (use dependency-audit) or contract drafting (use contract-template).
3 -
aibot88 Bundle OnvifscanONVIF device security scanner for testing authentication and brute-forcing credentials. Use when you need to assess security of IP cameras or ONVIF-enabled devices.
3 -
aibot88 Bundle Palo AltoPAN-OS firewall'unda DNAT (port yönlendirme) ve security policy source kısıtlama işlerini doğal dilden uygular. Müşteri tek cümlede ister ("198.51.100.108'in 80 portu 192.168.1.50:90'a yönlendirilsin" / "RULE_108 sadece şu IP'lere açık olsun"); skill firewall'a doğrudan bağlanır, çakışmaları kontrol eder, idempotent şekilde NAT + security policy + service/address objelerini oluşturur ve commit eder. Credential'lar sadece process içinde tutulur, diske yazılmaz. Her çağrı öncesi auto-update yapar (24h cache).
3 -
aibot88 Bundle PHP RulesPHP coding rules from ai-toolkit: coding-style, frameworks, patterns, security, testing. Triggers: .php, composer.json, Laravel, Symfony, PHPUnit, PSR-12, Composer. Load when writing, reviewing, or editing PHP code.
3 -
aibot88 Bundle QuickscanRun a quick security scan on a target. Consults the Brain first, validates scope, runs passive recon + vuln scan in parallel.
3 -
aibot88 Bundle Reopt CLIBaseline guidance for the reopt CLI — authentication, login, global flags, security rules, and exit codes. Use before other reopt CLI skills or whenever a task involves `reopt login`, `reopt status`, brandapp credentials, or CI automation.
3 -
aibot88 Bundle Sast ScanStatic application security testing (SAST) for changed source files — Vulnetix's built-in rule set plus optional Semgrep augmentation when `.semgrep` config is present. Use when reviewing a PR for code-level vulnerabilities, scanning a feature branch before merge, gating CI on critical findings, or running rule-specific checks for a known weakness class.
3 -
aibot88 Bundle SkillscanSecurity gate for skills. Every new skill MUST pass SkillScan before use. Activate on any install, load, add, evaluate, or safety question about a skill. On first load, run first-run to scan all existing skills. Blocks HIGH/CRITICAL skills. No exceptions.
3 -
aibot88 Bundle Snyk CodeExecute Snyk Code SAST (Static Application Security Testing) scans on source code files or projects, interpret vulnerability findings, generate structured security reports, and suggest remediations. Use this skill whenever the user mentions: "snyk", "snyk code", "SAST scan", "scan de segurança", "verificar vulnerabilidades no código", "análise estática de segurança", "snyk scan", "rodar snyk", "vulnerabilidade no código-fonte", or wants to audit code for security issues with Snyk. Also trigger when the user uploads code and asks for a security scan or wants a Snyk-style report.
3 -
aibot88 Bundle Swift CspExpert SWIFT Customer Security Programme (CSP) advisor covering the Customer Security Controls Framework (CSCF v2025). Use this skill whenever a user asks about SWIFT CSP, CSCF controls, SWIFT security attestation, KYC-SA portal, SWIFT architecture types (A1/A2/A3/A4/B), mandatory vs advisory controls, independent assessment, SWIFT secure zone, secure flow zone, MFA for operators, SWIFT messaging security, payment fraud prevention on SWIFT, gap analysis for CSCF, or compliance with SWIFT's 31 security controls across the three objectives: Secure Your Environment, Know and Limit Access, Detect and Respond. Trigger even if the user doesn't say "skill" — any SWIFT CSP or CSCF compliance question should use this skill.
3 -
aibot88 Bundle TrailmarkBuilds and queries multi-language source code graphs for security analysis. Includes pre-analysis passes for blast radius, taint propagation, privilege boundaries, and entry point enumeration. Use when analyzing call paths, mapping attack surface, finding complexity hotspots, enumerating entry points, tracing taint propagation, measuring blast radius, or building a code graph for audit prioritization. Supports 16 languages including Solidity, Cairo, Circom, Rust, Go, Python, C/C++, TypeScript.
3 -
aibot88 Bundle Two Factor Authentication Best PracticesConfigure TOTP authenticator apps, send OTP codes via email/SMS, manage backup codes, handle trusted devices, and implement 2FA sign-in flows using Better Auth's twoFactor plugin. Use when users need MFA, multi-factor authentication, authenticator setup, or login security with Better Auth.
3 -
aibot88 Bundle Txt AuditReview Apple text code for correctness, performance, and modernization risk in a single pass with severity-ranked findings. Covers TextKit 1 fallback triggers, NSTextStorage subclass correctness (edited / changeInLength / batched edits), didProcessEditing character-mutation bugs, deprecated glyph APIs, full-document ensureLayout, missing allowsNonContiguousLayout, NSLinguisticTagger / UIMenuController deprecations, missing performEditingTransaction wrappers on TextKit 2, Writing Tools coordinator gaps (writingToolsIgnoredRangesIn, isWritingToolsActive), String-vs-NSString length confusion in range arithmetic, and main-thread storage rules. Use when a user asks to audit, scan, or review a text editor codebase, when preparing an editor for shipping, when triaging a post-release regression in TextKit code, or when a pull request needs a structured pass focused on text-specific risks.
3 -
aibot88 Bundle Wa ReviewThis skill should be used when the user asks to "review architecture", "Well-Architected review", "check bestpractices", "security assessment",or "cost optimization analysis".
3 -
aibot88 Bundle Wp ReviewWordPress theme and plugin review skill. Detects whether a target path is a theme or plugin, runs security and standards checks, scores the findings, and writes a markdown report. Use when the user wants to review a WordPress theme or plugin directory, generate a code review report, inspect WordPress security posture, or compare review strictness with selectable security levels.
3 -
aibot88 Bundle Xray Scan使用 xray 进行 Web 漏洞自动化扫描。当需要对 Web 应用进行全面漏洞扫描(XSS/SQLi/命令注入/SSRF/XXE/路径穿越/文件上传/弱口令等)时使用。xray 是长亭科技出品的综合性 Web 安全评估工具,支持主动扫描、被动代理扫描、基础爬虫扫描三种模式,内置丰富的检测插件和社区 POC。任何涉及 xray 漏洞扫描、Web 安全评估、被动代理扫描的场景都应使用此技能
3 -
aibot88 Bundle ResearchTechnical research methodology with YAGNI/KISS/DRY principles. Phases: scope definition, information gathering, analysis, synthesis, recommendation. Capabilities: technology evaluation, architecture analysis, best practices research, trade-off assessment, solution design. Actions: research, analyze, evaluate, compare, recommend technical solutions. Keywords: research, technology evaluation, best practices, architecture analysis, trade-offs, scalability, security, maintainability, YAGNI, KISS, DRY, technical analysis, solution design, competitive analysis, feasibility study. Use when: researching technologies, evaluating architectures, analyzing best practices, comparing solutions, assessing technical trade-offs, planning scalable/secure systems.
3 -
aibot88 Bundle Aif ReviewPerform code review on staged changes or a pull request. Checks for bugs, security issues, performance problems, and best practices. Use when user says "review code", "check my code", "review PR", or "is this code okay".
3 -
aibot88 Bundle Atlas FullFull 9-phase workflow for complex features, epics, and security-critical changes (2-4 hours)
3 -
aibot88 Bundle Audit FullSingle-pass codebase analysis leveraging Opus 4.6 1M context for comprehensive security scanning, architecture review, and dependency auditing. Loads entire codebases for cross-file pattern detection and generates structured audit reports with severity-ranked findings. Use when you need whole-project analysis before releases or security reviews.
3 -
aibot88 Bundle Audit PrepPrepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project documentation checks. Generates a scored Audit Readiness Report and optionally runs static analysis. Trigger on: "prepare for audit", "audit readiness", "pre-audit check", "audit prep", "NatSpec check", or any request to review a Solidity codebase before a security review.
3 -
aibot88 Bundle Audit Sink阶段 2 Sink-driven 审计。从危险 API 往上追踪数据流,判断用户输入是否可达 Sink,发现注入/反序列化/SSRF/文件操作等漏洞。
3 -
aibot88 Bundle Auth AuditAudit authentication and authorization patterns. Checks JWT, sessions, OAuth2, PKCE implementations for security best practices and common vulnerabilities.
3 -
aibot88 Bundle Bib VerifyVerify a BibTeX file for hallucinated or fabricated references by cross-checking every entry against CrossRef, arXiv, and DBLP. Reports each reference as verified, suspect, or not found, with field-level mismatch details (title, authors, year, DOI). Use when the user wants to check a .bib file for fake citations, validate references in a paper, or audit bibliography entries for accuracy.
3 -
aibot88 Bundle Bug BountyBug bounty program management and security disclosure expertise for smart contracts. Covers program setup on Immunefi, vulnerability triage, responsible disclosure coordination, bounty payments, and post-disclosure analysis.
3 -
aibot88 Bundle AnnualreportsAnnual security report aggregation and analysis. USE WHEN annual reports, security reports, threat reports, industry reports, update reports, analyze reports, vendor reports, threat landscape.
3 -
aibot88 Bundle API MitmproxyInteractive HTTPS proxy for API security testing with traffic interception, modification, and replay capabilities. Supports HTTP/1, HTTP/2, HTTP/3, WebSockets, and TLS-protected protocols. Includes Python scripting API for automation and multiple interfaces (console, web, CLI). Use when: (1) Intercepting and analyzing API traffic for security testing, (2) Modifying HTTP/HTTPS requests and responses to test API behavior, (3) Recording and replaying API traffic for testing, (4) Debugging mobile app or thick client API communications, (5) Automating API security tests with Python scripts, (6) Exporting traffic in HAR format for analysis.
3 -
aibot88 Bundle Appsec ExpertElite Application Security engineer specializing in secure SDLC, OWASP Top 10 2025, SAST/DAST/SCA integration, threat modeling (STRIDE), and vulnerability remediation. Expert in security testing, cryptography, authentication patterns, and DevSecOps automation. Use when securing applications, implementing security controls, or conducting security assessments.
3 -
aibot88 Bundle Audit And FixComposite: security audit -> production upgrade -> self-evaluation. Use when user says 'audit', 'check the codebase', 'find and fix issues', or 'is this production-ready'.
3 -
aibot88 Bundle Audit LoggingComprehensive audit logging for compliance and security. Track user actions, data changes, and system events with tamper-proof storage.
3 -
aibot88 Bundle Auth AnalyzerReview and analyze authentication and authorization patterns for security vulnerabilities.
3
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include bug-bounty, greynoise, hora-deps. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.