Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
aibot88 Bundle Secrets ScannerDétecte les secrets, clés API et credentials exposés dans le code. À utiliser pour vérifier qu'aucun secret n'est dans le code. Se déclenche avec "secrets", "clé API exposée", "credential leak", "mot de passe dans le code", "token exposé", ".env", "secret scanner".
3 -
aibot88 Bundle Security ChecksPrzegląd bezpieczeństwa zmian w kodzie i konfiguracji.
3 -
aibot88 Bundle Security ReportGenerate security assessment reports in docx format with findings, risk ratings, and remediation recommendations. Use when: User asks for security audit report, vulnerability assessment document, penetration test report, or compliance gap analysis document. Keywords: security report, audit findings, vulnerability report, pentest report
3 -
aibot88 Bundle Security ReviewSecurity vulnerability assessment identifying OWASP risks, injection vectors, authentication issues, and data exposure with severity classification.
3 -
aibot88 Bundle SecurityheadersAudit HTTP security headers for any URL and receive a grade (A+ to F) with specific recommendations for missing headers
3 -
aibot88 Bundle Solana SecurityAudit Solana programs (Anchor or native Rust) for security vulnerabilities. Use when reviewing smart contract security, finding exploits, analyzing attack vectors, performing security assessments, or when explicitly asked to audit, review security, check for bugs, or find vulnerabilities in Solana programs.
3 -
aibot88 Bundle Specstory GuardInstall a pre-commit hook that scans .specstory/history for secrets before commits. Run when user says "set up secret scanning", "install specstory guard", "protect my history", or "check for secrets".
3 -
aibot88 Bundle Strategy ReviewUse when reviewing, critiquing, or stress-testing an existing strategy document. Evaluates seven dimensions — diagnosis quality, guiding policy strength, action coherence, assumption exposure, falsifiability — with optional 7S, Five Forces, Balanced Scorecard, and Hoshin Kanri lenses. Triggers on: review my strategy, poke holes in this plan, what's weak here, strategy audit, red team this. Does NOT build strategy (use strategy-interview) or brainstorm project ideas (use brainstorm-beagle).
3 -
aibot88 Bundle Threat AdvisoryGenerate a personalized threat advisory based on your tech stack — what CVEs, breaches, and supply chain attacks matter to YOU.
3 -
aibot88 Bundle Vendor AssessorConducts comprehensive vendor security assessments. Evaluates vendor security posture, identifies risks, and generates assessment reports with recommendations.
3 -
aibot88 Bundle Academic ReviserSelf-review, audit, or verify CS/AI/ML paper drafts as a critical peer reviewer. Three-round review (evidence→argument→style) with Verification Status and debt tracking. Use when: reviewing a paper draft before submission, checking evidence compliance of claims, simulating peer reviewer feedback, verifying citation closure and evidence debts, performing cross-section consistency checks. Triggers on: 审修, self review, 自查, verification, revise, 修订, check draft, 审稿, evidence compliance, peer review, 论文审查, draft audit, 验证论文, 检查引用, cross-section review.
3 -
aibot88 Bundle Account TakeoverHow to identify and test for account takeover vulnerabilities in web applications. Use this skill whenever the user mentions account takeover, authentication bypass, password reset attacks, email verification bypass, session hijacking, or any technique to compromise user accounts. This includes testing authorization issues, unicode normalization attacks, reset token reuse, CORS/CSRF/XSS exploitation, cookie manipulation, and OAuth vulnerabilities.
3 -
aibot88 Bundle Activity LoggingFollow these patterns when implementing activity emission and audit logging in OptAIC. Use for emitting ActivityEnvelopes on mutations (create, update, delete, execute), designing payloads, and ensuring audit compliance.
3 -
aibot88 Bundle Add Health CheckTech health check: documentation, security, architecture, data analysis. Use when user requests project audit, tech debt review, or health check.
3 -
aibot88 Bundle Aico Code ReviewRequest structured code review to catch correctness, security, performance, and readability issues. Reviews should happen early and often. Use this skill when: - Completing a task and need quality check - After major feature implementation - Before merging to main branch - When stuck and need fresh perspective on code - User asks for "code review", "review my code", "check my code" - Subagent-driven workflow needs spec compliance or quality review Review categories: Correctness, Tests, Security, Performance, Readability, Error Handling Severity levels: Critical (fix now), Important (fix before proceeding), Minor (note for later)
3 -
aibot88 Bundle Andm Sd ReviewerAdversarial System Design auditor that reviews SD deliverables (requirements, architecture, deep-dive, data flow, security, tradeoffs, evolution, product breakdown) plus ADRs and API specs against an attack-vector checklist. Use to audit SD artifacts and produce a Claim Review file. Read-only - never modifies SD docs.
3 -
aibot88 Bundle Android SecurityAndroid security fundamentals: encrypted storage (EncryptedSharedPreferences, EncryptedFile), biometric authentication (BiometricPrompt, Credential Manager), network certificate pinning, SafetyNet/Play Integrity API, KeyStore-backed key generation, and secure data handling patterns. Use this when: storing sensitive data locally, implementing biometric login, pinning TLS certificates, protecting API keys, integrating Play Integrity attestation, generating cryptographic keys in Android KeyStore, or hardening an app against reverse engineering.
3 -
aibot88 Bundle Binary HardeningBinary hardening skill for security-hardened C/C++ builds. Use when enabling RELRO, PIE, stack canaries, FORTIFY_SOURCE, CFI sanitizers, shadow stack, or seccomp-bpf syscall filtering. Covers checksec analysis, compiler and linker flags for hardened builds, and NSA/CISA-recommended mitigations. Activates on queries about binary hardening, checksec, RELRO, PIE, stack canaries, FORTIFY_SOURCE, CFI, shadow stack, or seccomp.
3 -
aibot88 Bundle Change ReviewingDiff-basierter Review von Code-Aenderungen. Identifiziert Risiken, Regressionen, Testluecken, Security-Nebenwirkungen und offene Folgearbeiten. Verwende diesen Skill wenn der User sagt: "Review", "Code Review", "Aenderungen pruefen", "Was habe ich kaputt gemacht", "Diff Review", "change-reviewing", "/review".
3 -
aibot88 Bundle Check No SecretsScans codebase for accidentally committed secrets, credentials, API keys, and sensitive data to prevent security breaches
3 -
aibot88 Bundle Claude FrameworkCLAUDE Framework coding standards for code quality, naming conventions, error handling, security, testing, database, and logging
3 -
aibot88 Bundle Clawsec NanoclawUse when checking for security vulnerabilities in NanoClaw skills, before installing new skills, or when asked about security advisories affecting the bot
3 -
aibot88 Bundle Cm Security GatePre-production security audit and vulnerability scanning. Run Snyk + Aikido dependency scans, OWASP analysis, and set up automated GitHub security checks with Jules. Use when asked to 'run security check', 'security audit', 'kiểm tra bảo mật', 'vulnerability scan', 'Snyk', 'OWASP', or before open-sourcing / commercializing a project.
3 -
aibot88 Bundle Code ConventionsUniversal coding principles: DRY, security by default, null guards, and YAGNI. Trigger: When writing or reviewing code in any language or technology.
3 -
aibot88 Bundle Code FoundationsClassify code tasks and execute task-specific checklists with quality gates. Route to WRITE, DEBUG, REVIEW, OPTIMIZE, REFACTOR, SIMPLIFY, or SECURE workflows, each invoking relevant CC and APOSD skills. Produce classification statement plus DONE/NOT DONE verdict with mandatory pre-commit verification. Use when writing, debugging, reviewing, fixing, implementing, optimizing, refactoring, simplifying, or securing code. Triggers on: implement, build, create, debug, fix bug, broken, error, review, audit, optimize, slow, performance, refactor, clean up, simplify, confusing, too complex, secure, vulnerability.
3 -
aibot88 Bundle Csharp ValidatorComprehensive C# code validation, static analysis, and best practices verification for .NET applications. Use when validating C# code, checking SOLID principles, reviewing async/await patterns, verifying nullable reference types usage, checking Entity Framework queries, ensuring security best practices, or reviewing .NET code quality and architecture.
3 -
aibot88 Bundle D365fo DebuggingComplete D365 Finance & Operations debugging framework. Routes symptoms to correct playbook (Finance, SCM, WMS, Batch, Security, Integration, Performance, Reporting). Activates for D365, Dynamics, AX, voucher, posting, batch job, SSRS, DMF, work order, wave, security, can't post, missing, wrong amount, slow, stuck.
3 -
aibot88 Bundle Dependency AuditProvides dependency management and supply chain security practices for auditing vulnerabilities, checking licenses, assessing dependency health, and managing upgrades safely. Use when auditing packages, reviewing security, managing dependencies, or when user mentions 'audit', 'vulnerability', 'dependency', 'supply chain', 'npm audit', 'license', 'bundle size'.
3 -
aibot88 Bundle Devtools SecretsKnowledge and guardrails for the mise + fnox + infisical secrets toolchain. Use when the user asks to "configure secrets", "set up fnox", "infisical", "mise env", "secrets management", "environment variables for secrets", or mentions secret injection, secret providers, or env var hygiene.
3 -
aibot88 Bundle Django DeveloperExpert Django developer mastering Django 4+ with modern Python practices. Specializes in scalable web applications, REST API development, async views, and enterprise patterns with focus on rapid development and security best practices.
3 -
aibot88 Bundle Docs Starter KitGenerates comprehensive documentation templates for open-source and internal projects including README, CONTRIBUTING, SECURITY, CODE_OF_CONDUCT, LICENSE, and other standard docs with suggested sections and best practices. Use when users request "create project docs", "add OSS documentation", "setup standard docs", or "make it open-source ready".
3 -
aibot88 Bundle Docstring FormatAutomatically applies when writing function docstrings. Uses Google-style format with Args, Returns, Raises, Examples, and Security Note sections for proper documentation.
3 -
aibot88 Bundle Email And Password Best PracticesConfigure email verification, implement password reset flows, set password policies, and customise hashing algorithms for Better Auth email/password authentication. Use when users need to set up login, sign-in, sign-up, credential authentication, or password security with Better Auth.
3 -
aibot88 Bundle Event MonitoringShield Event Monitoring: event log types, downloading logs via REST API and SOQL, real-time event monitoring with streaming API, and threat detection policies. NOT for debug logs (use debug-logs-and-developer-console). NOT for custom platform event publishing/subscribing (use platform-events-apex).
3 -
aibot88 Bundle Fastapi ReviewerWHEN: FastAPI project review, Pydantic models, async endpoints, dependency injection WHAT: Pydantic validation + Dependency injection + Async patterns + OpenAPI docs + Security WHEN NOT: Django → django-reviewer, Flask → flask-reviewer, General Python → python-reviewer
3 -
aibot88 Bundle Federation AuditQuery federation audit logs with compliance filtering
3
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include secrets-scanner, security-checks, security-report. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.