Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
aibot88 Bundle Fortify SecurityExpert in Gravito security and authentication. Trigger this when setting up Auth, configuring CSP, or implementing security middleware.
3 -
aibot88 Bundle Fxa Review QuickFast single-pass FXA-specific commit review covering security, conventions, logic/bugs, tests, and migrations. No subagents — runs directly in the main context.
3 -
aibot88 Bundle Github CommanderStructured workflows for triaging GitHub issues, reviewing PRs, sprinting through milestones, and running security/quality/performance audits — with configurable validation gates, auto-detected security scanning, journal audit trails, and human-in-the-loop checkpoints. Use this skill whenever you are working on a GitHub issue, reviewing or submitting a PR, running any kind of code audit, updating dependencies, or working through a milestone. Also use when the user mentions issue numbers, PR numbers, milestone names, or asks you to "fix", "triage", "audit", "review", or "update deps".
3 -
aibot88 Bundle GRAPHQL ReviewerWHEN: GraphQL schema review, resolver patterns, N+1 detection, query complexity, API security WHAT: Schema design + N+1 detection + Query complexity + Input validation + Error handling + DataLoader patterns WHEN NOT: REST API → api-documenter, Database schema → schema-reviewer, ORM → orm-reviewer
3 -
aibot88 Bundle GRAPHQL SecuritySecure GraphQL APIs - authentication, authorization, rate limiting, and validation
3 -
aibot88 Bundle Harness PlatformHarness Platform administration including delegates, RBAC, connectors, secrets, templates, policy as code (OPA), user management, audit logs, and governance
3 -
aibot88 Bundle Hipaa ComplianceEnsure HIPAA compliance when handling PHI (Protected Health Information). Use when writing code that accesses user health data, check-ins, journal entries, or any sensitive information. Activates for audit logging, data access, security events, and compliance questions.
3 -
aibot88 Bundle Hook DevelopmentUse when creating, modifying, or debugging Claude Code hooks — PreToolUse, PostToolUse, Stop, SubagentStop, SessionStart, SessionEnd, UserPromptSubmit, PreCompact, Notification. Covers the plugin `hooks/hooks.json` wrapper format vs. the user `settings.json` direct format, matchers, security patterns, `$CLAUDE_PLUGIN_ROOT` portability, lifecycle limitations, and debugging. Trigger on "add a hook", "validate tool use", "block dangerous commands", "enforce completion", "hook-based automation".
3 -
aibot88 Bundle Hunt New ProgramInitialize a threat hunting program with an environment map, tool inventory, huntmap, and empty execution directories
3 -
aibot88 Bundle Jquery Ajax JSONBest practices for jQuery AJAX with JSON data handling including sending/receiving JSON, error handling, security (CSRF protection, XSS prevention), promise patterns, caching, and modern alternatives. Use when working with jQuery AJAX requests, implementing JSON APIs, troubleshooting AJAX issues, or migrating from jQuery to Fetch API.
3 -
aibot88 Bundle Laravel SecurityLaravel security best practices for authn/authz, validation, CSRF, mass assignment, file uploads, secrets, rate limiting, and secure deployment.
3 -
aibot88 Bundle Loom Code ReviewRun multi-axis implementation review through Loom critique. Use before merge, after feature or bug-fix implementation, when receiving review feedback, when reviewing AI/human code, or when correctness, readability, architecture, security, performance, tests, or evidence need pressure-testing.
3 -
aibot88 Bundle Mythril SymbolicSymbolic execution analysis using Mythril for deep vulnerability detection in smart contracts. Supports configurable transaction depth, timeout settings, and proof-of-concept exploit generation.
3 -
aibot88 Bundle Odoo Code ReviewReview Odoo addon code for correctness, security, performance, migrations, tests, and official Odoo coding guidelines. Use when reviewing Odoo modules, diffs, pull requests, or changed files involving models, fields, XML views, data, controllers, reports, OWL/assets, manifests, access rules, record rules, or OCA migrations.
3 -
aibot88 Bundle Pentest WirelessWireless network pentest — WPA/WPA2/WPA3, evil twin, 802.1X enterprise, Bluetooth advisory. Triggers on wireless pentest, WiFi, WPA2, WPA3, PMKID, evil twin, deauth, Aircrack, hcxdumptool, 802.1X, Bluetooth, BLE security.
3 -
aibot88 Bundle Persona It AdminThis skill should be used when the user says "IT admin mode", "check for security issues", "review audit logs", "configure Drive permissions", "monitor login activity", "run IT standup", or "manage Workspace settings", or wants to administer IT operations, enforce security policies, and review pending requests in Google Workspace.
3 -
aibot88 Bundle Pr Review ExpertUse when the user asks to review pull requests, analyze code changes, check for security issues in PRs, or assess code quality of diffs.
3 -
aibot88 Bundle Property TestingProperty-based and generative testing across the polyglot stack. TRIGGER when: user asks about property-based testing, generative testing, QuickCheck, Hypothesis, proptest, StreamData, fast-check, fuzzing test inputs, or finding edge cases that example tests miss. DO NOT TRIGGER when: user asks about TDD workflow (use tdd), mutation testing (use tdd), load testing (use performance-profiler), or security fuzzing (use security-audit).
3 -
aibot88 Bundle Pwntools Exploitation SkillExploit development automation using pwntools framework
3 -
aibot88 Bundle Quality ReviewerDeep code review with web research to verify against latest ecosystem. Use when user says 'double check against latest', 'verify versions', 'check security', 'review against docs', or needs deep analysis beyond automatic quality hook.
3 -
aibot88 Bundle Review Claude MdAudit and fix CLAUDE.md files using a tiered binary checklist based on official Anthropic best practices and community guidelines. Use when the user asks to "review CLAUDE.md", "audit CLAUDE.md", "score CLAUDE.md", "improve CLAUDE.md", or "fix CLAUDE.md".
3 -
aibot88 Bundle Security ArsenalSecurity payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table. Use when you need specific payloads for XSS/SSRF/SQLi/XXE/IDOR/path-traversal, bypass techniques, or to check if a finding is submittable. Also use when asked about what NOT to submit.
3 -
aibot88 Bundle Security ScannerRun security scans including SAST, dependency scanning, and secret detection
3 -
aibot88 Bundle Session TemplateApply task-specific templates to AI session plans using ai-update-plan. Use when starting a new task to load appropriate plan structure (feature, bugfix, refactor, documentation, security).
3 -
aibot88 Bundle Slither AnalysisExpert integration with Slither static analyzer for smart contract vulnerability detection, code quality analysis, and security reporting. Supports all Slither detectors and custom analysis configurations.
3 -
aibot88 Bundle Spring Boot CoreSpring Boot 4.0 + Java 25 development - auto-configuration, starters, Actuator, profiles, externalized config, security, and production patterns. Use when building backend apps, creating endpoints, configuring Spring, or asking "how do I set up X?"
3 -
aibot88 Bundle System ArchitectSystem architecture skill for designing scalable, maintainable software systems. Covers microservices/monolith decisions, API design, DB selection, caching, security, and scalability planning.
3 -
aibot88 Bundle Target ProfilingResearch and build a target system profile via SSH — discovers OS, services, users, network baseline, and security stack
3 -
aibot88 Bundle Validate TriggerAudit an existing Sim webhook trigger against the service's webhook API docs and repository conventions, then report and fix issues across trigger definitions, provider handler, output alignment, registration, and security. Use when validating or repairing a trigger under `apps/sim/triggers/{service}/` or `apps/sim/lib/webhooks/providers/{service}.ts`.
3 -
aibot88 Bundle Wordpress ServerWordPress server optimization — Nginx config, PHP 8.3-FPM tuning, Redis object caching, WP Rocket, security hardening, staging, multisite
3 -
aibot88 Bundle SparkDevOps operations via the SPARK CLI. Use when the user asks about repo status, security auditing, system cleanup, port conflicts, SSL certificates, or managing dev tool updates. Trigger on: "are my repos up to date", "check for secrets", "audit the code", "clean up disk", "what port is running on", "check certs", "update my tools", "which repos need a pull", "find repo", "tag repos". Also trigger before commits (security check) and before deploys (status check).
3 -
aibot88 Bundle 1k Code Review PrComprehensive PR code review for OneKey monorepo. Use when reviewing PRs, code changes, or diffs — covers security (secrets/PII leakage, supply-chain, AuthN/AuthZ), code quality (hooks, race conditions, null safety, concurrent requests), and OneKey-specific patterns (Fabric crashes, MIUI, BigNumber). Triggers on "review PR", "review this PR", "code review", "check this diff", "审查 PR", "代码审查", "review
3 -
aibot88 Bundle 1password SecretsSecure secret management using 1Password CLI. Detect plaintext secrets in files and codebases, convert environment files to 1Password templates, inject secrets securely using op inject, and audit codebases for security compliance.
3 -
aibot88 Bundle Access ManagementRBAC/ABAC implementation patterns, least privilege access, row-level security, column masking, and access review workflows.
3 -
aibot88 Bundle Adding New MetricGuides systematic implementation of new sustainability metrics in OSS Sustain Guard using the plugin-based metric system. Use when adding metric functions to evaluate project health aspects like issue responsiveness, test coverage, or security response time.
3 -
aibot88 Bundle Agentic StructureCollaborative programming framework for production-ready development. Use when starting features, writing code, handling security/errors, adding comments, discussing requirements, or encountering knowledge gaps. Applies to all development tasks for clear, safe, maintainable code.
3
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include fortify-security, fxa-review-quick, github-commander. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.