Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
aibot88 Bundle Better Auth V2Production-ready authentication system using Better Auth v2 with latest features. Includes OAuth providers, advanced RBAC, multi-tenant support, and security best practices.
3 -
aibot88 Bundle Bitcoin WalletUse when implementing Bitcoin wallet features - provides complete architecture for on-chain Bitcoin transactions, UTXO management, address derivation from Nostr keys, and transaction handling with proper security patterns
3 -
aibot88 Bundle Ccs DelegationAuto-activate CCS CLI delegation for deterministic tasks. Parses user input, auto-selects optimal profile (glm/kimi/custom) from ~/.ccs/config.json, enhances prompts with context, executes via `ccs {profile} -p "task"` or `ccs {profile}:continue`, and reports results. Triggers on "use ccs [task]" patterns, typo/test/refactor keywords. Excludes complex architecture, security-critical code, performance optimization, breaking changes.
3 -
aibot88 Bundle Check Security코드 보안 취약점을 탐지한다. bandit을 사용하여 일반적인 보안 이슈를 검사한다.
3 -
aibot88 Bundle Code ChecklistTeam code quality checklist - use for checking Python code quality, bugs, security issues, and best practices
3 -
aibot88 Bundle Comfort SafetyUse when creating animations that reassure users, reduce anxiety, or communicate protection and security.
3 -
aibot88 Bundle Contract CheckAudit health of contract tests across services — staleness, sync gaps, uncommitted pacts, missing tests.
3 -
aibot88 Bundle CryptotokenkitAccess security tokens and smart cards using CryptoTokenKit. Use when building token driver extensions with TKTokenDriver and TKToken, communicating with smart cards via TKSmartCard, implementing certificate-based authentication, managing token sessions, or integrating hardware security tokens with the system keychain.
3 -
aibot88 Bundle Custom WorkersCreate and run custom background analysis workers with composable phases. Use when you need automated code analysis, security scanning, pattern learning, or API documentation generation.
3 -
aibot88 Bundle Direnv PatternImplements the b00t environment management pattern: direnv → .envrc → dotenv → .env where datums specify WHICH environment variables are required and .env contains the actual secret VALUES. Ensures automatic environment loading per-project.
3 -
aibot88 Bundle Eks NetworkingEKS networking configuration including VPC CNI, load balancers, and network policies. Use when setting up cluster networking, configuring ingress/load balancing, implementing network security, troubleshooting connectivity, or optimizing network costs.
3 -
aibot88 Bundle Expo Eas BuildEAS Build ile iOS ve Android build profilleri, credentials yonetimi, build cache, secrets ve monorepo destegi. Triggers on eas build, eas.json, build profile, credentials, provisioning profile, keystore, push certificate, service account, build cache, eas secret, monorepo, development build, preview build, production build.
3 -
aibot88 Bundle Fight Repo RotFinds what's rotting in a repo and returns a prioritized diagnosis — dead code first, then god files / hotspots / hardcoded paths / stale TODOs / lopsided import graphs. Dead-code candidates are tagged HIGH / MEDIUM / LOW confidence so the operator can delete with calibrated risk. Pure diagnosis — never edits code, never plans fixes, never runs verification. Hand off to refactor-verify for deletions and restructures, to project-conventions for config issues, to audit-security for CVE dependency rot. Language-agnostic.
3 -
aibot88 Bundle Firebase RulesBest practices for interacting with Firebase services, including security and optimization.
3 -
aibot88 Bundle Github ArchiveInvestigate GitHub security incidents using tamper-proof GitHub Archive data via BigQuery. Use when verifying repository activity claims, recovering deleted PRs/branches/tags/repos, attributing actions to actors, or reconstructing attack timelines. Provides immutable forensic evidence of all public GitHub events since 2011.
3 -
aibot88 Bundle Go Code ReviewComprehensive code review checklist for Go projects. Evaluates code quality, idiomatic patterns, error handling, naming, package structure, and test coverage. Use when reviewing Go code, PRs, or before merging changes. Trigger examples: "review this code", "check this PR", "code review", "review Go file". Do NOT use for security-specific audits (use go-security-audit) or performance-specific analysis (use go-performance-review).
3 -
aibot88 Bundle Golang SwaggerGolang OpenAPI/Swagger documentation with swaggo/swag — annotation comments (@Summary, @Param, @Success, @Router, @Security), swag init code generation, framework integrations (gin, echo, fiber, chi, net/http), security definitions (Bearer/JWT, OAuth2, API key), and struct tags (swaggertype, enums, example, swaggerignore). Apply when adding or maintaining Swagger/OpenAPI docs in a Go project, or when the codebase imports github.com/swaggo/swag, github.com/swaggo/gin-swagger, github.com/swaggo/echo-swagger, github.com/swaggo/http-swagger, or github.com/swaggo/files.
3 -
aibot88 Bundle Harness ReviewMulti-perspective review supporting code, plan, and scope analysis. Auto-detects review type from context. Use when user mentions reviews, code review, plan review, scope analysis, security, performance, quality checks, PRs, diffs, or change review. Do NOT load for: implementation work, new feature development, bug fixes, or setup.
3 -
aibot88 Bundle Health CheckerProject health dashboard — compilation, tests, TODOs, API spec drift, migration pairs, deps, security, docs, bundle
3 -
aibot88 Bundle Healthcare APIScaffolds a FHIR R4-compliant healthcare API with clinical resource models, SMART on FHIR auth, HIPAA audit logging, PHI-safe error handling, and interoperability endpoints. Triggers on: "healthcare api", "FHIR api", "medical api", "health api", "build a FHIR server", "clinical data api", "patient api", "EHR integration", "SMART on FHIR", "HIPAA compliant api", "healthcare backend", "HL7 api", "build a health platform", "medical records api", "telehealth backend".
3 -
aibot88 Bundle Hipaa ValidateValidate code against HIPAA policy: PHI exposure, missing audit logging, unencrypted transmission/storage, access control gaps, temp file exposure, and missing BAA references
3 -
aibot88 Bundle Hitrust ExpertHITRUST CSF expert for healthcare security. Implementation guidance, assessment workflow, and mapping to HIPAA/NIST/ISO/PCI frameworks. References control IDs only — not a replacement for a licensed CSF copy.
3 -
aibot88 Bundle Jaw Drop AuditBrutaal eerlijke code/repo-audit vanuit het perspectief van een onafhankelijke Champions League webdev, plus een niet-lui transformatieplan naar 10/10 craft. Geen compliance-checklist maar craft-oordeel - zou een top dev zeggen "jaw-dropping shit"?
3 -
aibot88 Bundle Language AuditUse when the user wants to audit multilingual content consistency — check hreflang tags, content parity across languages, regional compliance, translation quality, and localization completeness.
3 -
aibot88 Bundle Margin TradingBinance Margin-trading request using the Binance API. Authentication requires API key and secret key.
3 -
aibot88 Bundle Migrate WizardUse when migrating an AI Studio project to production in one pass. Orchestrates all migration steps (analyze, export, repo setup, graduation, monitoring, security) with upfront configuration and automatic step detection. Trigger examples - "AI Studioから本番に移行して", "migrate to production", "ワンパスでマイグレーション", "production migration wizard"
3 -
aibot88 Bundle Nodejs BackendNode.js backend patterns: layered architecture, TypeScript, validation, error handling, security, deployment. Use when building REST APIs, REST endpoints, middleware, Express/Fastify/Hono/NestJS/Koa servers, tRPC procedures, Bun servers, or server-side TypeScript.
3 -
aibot88 Bundle Offensive WifiWireless / 802.11 attack methodology for red team engagements and wireless security assessments. Covers monitor-mode setup, WPA/WPA2-PSK handshake capture and PMKID attacks, WPA3 SAE downgrade and Dragonblood, WPA-Enterprise (EAP) attacks (MSCHAPv2 cracking, EAP-TLS cert theft, evil-twin RADIUS), Karma / Known Beacons / Mana evil twin attacks, captive-portal phishing, KRACK and FragAttacks, WPS Pixie Dust, deauthentication and disassociation attacks, rogue AP construction (hostapd-mana), 802.1X bypass, MAC randomization defeat, BLE/Zigbee/IEEE 802.15.4 sidebands, and Wi-Fi 6/6E/7 considerations. Use when scoping wireless pentest, war-driving an estate, or testing corporate wireless segmentation.
3 -
aibot88 Bundle Owasp SecurityUse when reviewing code for security vulnerabilities, implementing authentication/authorization, handling user input, or discussing web application security. Covers OWASP Top 10:2025, ASVS 5.0, and Agentic AI security (2026).
3 -
aibot88 Bundle Package SearchSearch for packages and assess security risk before adding as dependencies
3 -
aibot88 Bundle Pci Dss ExpertPCI DSS v4.0.1 compliance expert. Provides guidance on payment card industry security, ROC completion, SAQ selection, requirement interpretation, and the new March 2025 mandatory requirements.
3 -
aibot88 Bundle Plain LanguageUse when asked to review project text for plain language compliance. Produces structured findings with rewrites. Triggers: plain language review, readability check, copy audit, make this clearer.
3 -
aibot88 Bundle Plugin AuditorAutomatically audits Claude Code plugins for security vulnerabilities, best practices, CLAUDE.md compliance, and quality standards when user mentions audit plugin, security review, or best practices check. Specific to claude-code-plugins repository standards.
3 -
aibot88 Bundle Pre Exec CheckSafety check before executing destructive or irreversible commands. Catches dangerous shell commands, risky git operations, secret exposure, and high-blast-radius actions before they run. Activates automatically when Claude is about to execute shell commands that match known risk patterns. Trigger phrases: "check before running", "is this command safe", "safety check", "pre-execution review".
3 -
aibot88 Bundle Primr StrategyGenerate strategy documents from completed Primr research. Use when the user wants AI, CX, security, or data strategy deliverables from an existing report.
3 -
aibot88 Bundle Quality BanditBandit 보안 검사 설정 및 관리 스킬. pyproject.toml에 Bandit 설정을 구성하고 보안 취약점을 탐지한다. OWASP, CWE 기반의 보안 검사 환경을 구축한다.
3
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include bitcoin-wallet, ccs-delegation, check-security. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.