Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
aibot88 Bundle Auth SecurityOAuth 2.1 + JWT authentication security best practices. Use when implementing auth, API authorization, token management. Follows RFC 9700 (2025).
3 -
aibot88 Bundle Auth SupabaseImplements standard Supabase authentication flows including signup, login, password reset, OAuth providers, email verification, and session management with complete security best practices
3 -
aibot88 Bundle Bash ExecutorExecute bash commands and scripts safely with validation, error handling, and security checks. Use for system operations, file management, text processing, and command-line tools.
3 -
aibot88 Bundle Celery ExpertExpert Celery distributed task queue engineer specializing in async task processing, workflow orchestration, broker configuration (Redis/RabbitMQ), Celery Beat scheduling, and production monitoring. Deep expertise in task patterns (chains, groups, chords), retries, rate limiting, Flower monitoring, and security best practices. Use when designing distributed task systems, implementing background job processing, building workflow orchestration, or optimizing task queue performance.
3 -
aibot88 Bundle Ceo StandardsCEO Standards — Security policy, coding standards, performance patterns. Load this when reviewing security, writing code, or enforcing quality gates.
3 -
aibot88 Bundle Changelog Gen트리거: "changelog", "변경 이력", "릴리즈 노트", "release notes", "CHANGELOG 만들어줘" git log 또는 PR/커밋 목록을 분석하여 Keep a Changelog 형식의 CHANGELOG.md를 생성한다. 버전별 Added/Changed/Deprecated/Removed/Fixed/Security 섹션으로 구조화한다. 출력: CHANGELOG.md 형식 마크다운 + 버전 범프 권고
3 -
aibot88 Bundle Check SecretsScan the codebase for potential secret leaks including API keys, tokens, passwords, hardcoded project IDs, and sensitive identifiers. Use when the user says "check for secrets", "scan for leaks", "security check", or before committing sensitive changes.
3 -
aibot88 Bundle Clavix ReviewReview code changes with criteria-driven analysis (Security, Architecture, Standards, Performance). Use when reviewing PRs or code changes.
3 -
aibot88 Bundle Clawsec SuiteClawSec suite manager with embedded advisory-feed monitoring, cryptographic signature verification, approval-gated malicious-skill response, and guided setup for additional security skills.
3 -
aibot88 Bundle Code ReviewerComprehensive code review skill for TypeScript, JavaScript, Python, Swift, Kotlin, Go. Includes automated code analysis, best practice checking, security scanning, and review checklist generation. Use when reviewing pull requests, providing code feedback, identifying issues, or ensuring code quality standards.
3 -
aibot88 Bundle Codeql ExpertExpert-level CodeQL for static analysis, vulnerability detection, and security code scanning
3 -
aibot88 Bundle Compliance OsCompliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across multiple frameworks. Four decisions: (1) Given a company profile, which of the 12 supported frameworks apply (ISO 27001/13485/42001/14971, EU AI Act, MDR 745, GDPR, SOC 2, FDA QSR, NIST CSF 2.0, NIS2, HIPAA)? (2) Across selected frameworks, which controls overlap and how much evidence reuses? (3) For a given framework + scope, what does a realistic mock audit produce — drawing from the 205-scenario library? (4) Across selected frameworks, what's the unified evidence checklist with reuse map? Use when standing up a multi-framework program, planning the annual audit calendar, or preparing for certification stage 1. Does NOT replace per-framework skills (it orchestrates them).
3 -
aibot88 Bundle Core ReviewerCode review and quality assurance specialist for ensuring code quality, security, and maintainability
3 -
aibot88 Bundle Core WorkflowDetailed development workflow patterns, checklists, and standards. Auto-loads for complex tasks, planning, debugging, testing, or when explicit patterns are needed. Contains session protocols, git conventions, security checklists, testing strategy, and communication standards.
3 -
aibot88 Bundle Crack HashcatAdvanced password recovery and hash cracking tool supporting multiple algorithms and attack modes. Use when: (1) Performing authorized password auditing and security assessments, (2) Recovering passwords from captured hashes in forensic investigations, (3) Testing password policy strength and complexity, (4) Validating encryption implementations, (5) Conducting security research on cryptographic hash functions, (6) Demonstrating password weakness in penetration testing reports.
3 -
aibot88 Bundle CybersecurityPerform an advanced offensive security audit and attack simulation on the current features.
3 -
aibot88 Bundle DigikoppelingHelpt bij het implementeren van Digikoppeling voor beveiligde system-to-system communicatie tussen overheidsorganisaties. Begeleidt bij het kiezen en implementeren van het juiste koppelvlakprofiel (REST API, WUS, ebMS2), PKIoverheid-certificaten, OIN-registratie en aansluiting op Diginetwerk. Gebruik deze skill wanneer de gebruiker vraagt over 'Digikoppeling', 'koppelvlak overheid', 'system-to-system', 'REST profiel', 'WUS profiel', 'ebMS2 profiel', 'PKIoverheid certificaat', 'Diginetwerk', 'OIN', 'CPA', 'beveiligde berichtenuitwisseling', 'MSH', 'MSH configuratie', 'MSH koppeling', 'MSH profiel', 'Logius koppelvlak', 'SOAP overheid', 'WS-Security overheid', 'overheid-API beveiliging', 'reliable messaging overheid', of wanneer de gebruiker beveiligde berichtenuitwisseling tussen overheidssystemen wil implementeren.
3 -
aibot88 Bundle Dotnet CodeqlUse the open-source CodeQL ecosystem for .NET security analysis. Use when a repo needs CodeQL query packs, CLI-based analysis on open source codebases, or GitHub Action setup with explicit licensing caveats for private repositories.
3 -
aibot88 Bundle Faro SecurityAudit sicurezza OWASP avanzato per pre-lancio. Checklist completa. Trigger: "audit sicurezza", "OWASP", "penetration test", "security review"
3 -
aibot88 Bundle Form SecuritySecurity patterns for web forms including autocomplete attributes for password managers, CSRF protection, XSS prevention, and input sanitization. Use when implementing authentication forms, payment forms, or any form handling sensitive data.
3 -
aibot88 Bundle Gh CoderabbitPython向け統合コードレビュー。Quality/Security/Performance/Architecture/Anti-Fallback + CodeRabbitパターンを全検出
3 -
aibot88 Bundle Github Kernelfoundational definitions for GitHub skills, safety rules, tool escalation, and security boundaries
3 -
aibot88 Bundle Harbor ExpertExpert Harbor container registry administrator specializing in registry operations, vulnerability scanning with Trivy, artifact signing with Notary, RBAC, and multi-region replication. Use when managing container registries, implementing security policies, configuring image scanning, or setting up disaster recovery.
3 -
aibot88 Bundle Hooks BuilderCreate event-driven hooks for Claude Code automation. Use when the user wants to create hooks, automate tool validation, add pre/post processing, enforce security policies, or configure settings.json hooks. Triggers: create hook, build hook, PreToolUse, PostToolUse, event automation, tool validation, security hook
3 -
aibot88 Bundle Hooman CodingRequired coding playbook for this workspace—load via filesystem before writing source, adding deps, or running package/build commands. Applies to every programming task, regardless of simplicity or complexity, even one-file scripts or spikes. Covers research, security, tests, lint/format/build verification, and RCA for bugs.
3 -
aibot88 Bundle Hunt New CaseInitialize a threat hunting case from a signal, detection, intel lead, or analyst suspicion
3 -
aibot88 Bundle Log ForensicsAnalyze system, application, and security logs for forensic investigation. Use when investigating security incidents, insider threats, system compromises, or any scenario requiring analysis of log data. Supports Windows Event Logs, Syslog, web server logs, and application-specific log formats.
3 -
aibot88 Bundle Loom CritiqueRun adversarial review. Use for PR/diff/code/security/UX/API/performance/design review, or when behavior, records, evidence, risks, or acceptance claims need pressure-testing before acceptance.
3 -
aibot88 Bundle Loom ResearchPreserve reusable investigations. Use when compatibility, framework/library behavior, tradeoffs, rejected options, null results, performance/security/migration evidence, or external-source synthesis should remain citable.
3 -
aibot88 Bundle Loom SecurityRoute security-sensitive work before implementation. Use when authentication, authorization, user input, secrets, sensitive data, uploads, webhooks, external integrations, dependency vulnerabilities, trust boundaries, or hardening need threat-aware evidence and critique.
3 -
aibot88 Bundle Medplum RulesMedplum (FHIR healthcare) coding rules from ai-toolkit: coding-style, frameworks, patterns, security, testing. Triggers: medplum.config.mts, medplum.config.ts, FHIR, Medplum, Bot, Subscription, Questionnaire. Load when writing, reviewing, or editing Medplum (FHIR healthcare) code.
3 -
aibot88 Bundle MisardefenderManage and interact with MisarDefender — the local macOS security daemon. Use when: checking security daemon status, viewing security events, starting/stopping defender, scanning for threats, checking file integrity, reviewing network activity logs. Triggers: 'defender', 'misardefender', 'security daemon', 'check threats', 'file integrity', 'security events', 'defender status'.
3 -
aibot88 Bundle Nfr ChecklistSystematische Erhebung, Dokumentation und Priorisierung von Non-Functional Requirements (NFRs) nach ISO 25010 und TOGAF-Qualitätsattributen. Interaktiver Dialog zur Erfassung, Ableitung konkreter Architekturmaßnahmen und Ausgabe als strukturierter NFR-Katalog mit Messkriterien. Verwende diesen Skill bei: NFR erheben, Non-Functional Requirements erstellen, Qualitätsanforderungen dokumentieren, Nicht-funktionale Anforderungen erfassen, Performance-Anforderungen definieren, Skalierbarkeitsanforderungen, Verfügbarkeits-SLA, Sicherheitsanforderungen spezifizieren, Wartbarkeitsanforderungen, NFR-Katalog erstellen. Löst auch aus bei: NFR, Qualitätsattribute, Quality Attributes, Non-Functional Requirements, Nicht-funktionale Anforderungen, Performance Requirements, Availability SLA, Scalability Requirements, Security Requirements, Maintainability, Portability, Compliance Requirements, ISO 25010, TOGAF Quality, Architektur-treibende Anforderungen, Architecture Significant Requirements, ASR, Systemqualität, Quality of
3 -
aibot88 Bundle Offensive JWTJWT attack methodology for penetration testers. Covers algorithm confusion (alg:none, RS256→HS256), weak HMAC secret brute force, kid parameter injection (SQLi, path traversal), jku/x5u/jwk header injection, JWKS cache poisoning, JWS/JWE confusion, timing attacks, and mobile JWT storage extraction. Use when testing JWT-based authentication, hunting auth bypass via token manipulation, or evaluating JWT implementation security in web or mobile apps.
3 -
aibot88 Bundle Ottersec PrepPrep a Sui Move package for an OtterSec security audit. Use when the user mentions OtterSec or wants audit prep.
3 -
aibot88 Bundle Owasp CheckerVérifie un projet contre le OWASP Top 10 et propose des remédiations. À utiliser pour vérifier la conformité OWASP. Se déclenche avec "OWASP", "top 10", "failles web", "sécurité web", "A01 broken access", "injection", "vérifier OWASP".
3
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include auth-security, auth-supabase, bash-executor. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.