Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
aibot88 Bundle Asvs RequirementsOWASP ASVS 5.0 requirements database for security audits. Provides chapter structure, control objectives, and verification requirements for all 17 ASVS domains.
3 -
aibot88 Bundle Atft Code QualityEnforce lint, formatting, typing, testing, and security hygiene across the ATFT-GAT-FAN codebase.
3 -
aibot88 Bundle Bmad Testarch NfrAssess NFRs like performance security and reliability. Use when the user says "lets assess NFRs" or "I want to evaluate non-functional requirements"
3 -
aibot88 Bundle Bootstrap ProjectBootstrap a fresh or existing repo with nyann. TRIGGER when the user says "set up this project", "initialize git workflow", "bootstrap this repo", "scaffold this project", "ngyamm this repo", "use my <name> profile" / "apply the nextjs-prototype profile" (profile mode). ALSO trigger on "standard setup" / "usual stack" / "the usual setup" / "install all the standard hooks" / "give this repo the usual setup" / "make this repo standard" / "install nyann" — these read as opinionated bulk setup, not narrow edits, even though they sound small. Also trigger on any phrasing that mentions wiring up git hooks + branching + conventions + docs as a single opinionated setup. DO NOT trigger on narrow requests like "add a lint hook" or "update CLAUDE.md" — those are edits, not bootstraps. DO NOT trigger on "audit this project" / "fix what's drifted" / "bring into compliance" — those are retrofit. DO NOT trigger on "check this project's health" / "is this healthy" — those are doctor. When in doubt, run the detection step and
3 -
aibot88 Bundle Cloudflare ExpertExpert-level Cloudflare Workers, CDN, edge computing, and security services
3 -
aibot88 Bundle Codex AdversarialRun Codex adversarial review — actively tries to break confidence in the change. Use when asked "adversarial review", "적대적 리뷰", or wants thorough security/correctness challenge.
3 -
aibot88 Bundle Codex Claude LoopDual-AI engineering loop orchestrating Claude Code (planning/implementation) and Codex (validation/review). Use when (1) complex feature development requiring validation, (2) high-quality code with security/performance concerns, (3) large-scale refactoring, (4) user requests codex-claude loop or dual-AI review. Do NOT use for simple one-off fixes or prototypes.
3 -
aibot88 Bundle Compliance ReportBuild a compliance bundle — CycloneDX SBOM, SPDX license report, SARIF findings, OpenVEX/CycloneDX VEX, optional cosign signatures, manifest.json with SHA-256 sums, Markdown index. Use when assembling an audit bundle, SOC 2 attestation, supply-chain compliance package, or evidence for a customer security questionnaire.
3 -
aibot88 Bundle Context MaximizerExploit the 1M token context (Opus 4.6 / Sonnet 4.6) for full codebase awareness in SpecKit. Intelligently loads constitution, specs, skills, and codebase files while staying within token limits. Prioritizes critical files and provides context usage reports.
3 -
aibot88 Bundle Contextual ReviewReview pull requests for code quality, security vulnerabilities, best practices, and potential issues. Use when reviewing PRs, examining diffs, or providing code review feedback.
3 -
aibot88 Bundle Controleur FiscalInspecteur des finances publiques IA. Simule un contrôle fiscal DGFIP complet sur les comptes d'une entreprise française (SASU, EURL, SAS, SARL). Analyse le FEC, la liasse fiscale, les charges déduites, le compte courant d'associé, la TVA, l'IS selon 8 axes de vérification. Identifie les chefs de redressement potentiels avec montants, base légale et niveaux de risque. Triggers: contrôle fiscal, redressement, vérification comptabilité, DGFIP, FEC, déductibilité, audit fiscal, tax audit
3 -
aibot88 Bundle Crypto PrimitivesImplementation and secure usage of cryptographic primitives including ECDSA, BLS, Schnorr signatures, key derivation, secret sharing, and constant-time operations. Provides guidance for secure cryptographic implementations in blockchain applications.
3 -
aibot88 Bundle Dependency DoctorDiagnose and heal dependency issues in ANY package manager, ANY language. Use when facing version conflicts, security vulnerabilities, or dependency bloat.
3 -
aibot88 Bundle Dependency HealthSecurity-first dependency management methodology with batch remediation, policy-driven compliance, and automated enforcement. Use when security vulnerabilities exist in dependencies, dependency freshness low (outdated packages), license compliance needed, or systematic dependency management lacking. Provides security-first prioritization (critical vulnerabilities immediately, high within week, medium within month), batch remediation strategy (group compatible updates, test together, single PR), policy-driven compliance framework (security policies, freshness policies, license policies), and automation tools for vulnerability scanning, update detection, and compliance checking. Validated in meta-cc with 6x speedup (9 hours manual to 1.5 hours systematic), 3 iterations, 88% transferability across package managers (concepts universal, tools vary by ecosystem).
3 -
aibot88 Bundle Dev Owasp CheckerVérifie un projet contre le OWASP Top 10 et propose des remédiations. À utiliser pour vérifier la conformité OWASP. Se déclenche avec "OWASP", "top 10", "failles web", "sécurité web", "A01 broken access", "injection", "vérifier OWASP".
3 -
aibot88 Bundle Discover SecurityAutomatically discover security skills when working with authentication, authorization, input validation, security headers, vulnerability assessment, or secrets management. Activates for application security, OWASP, and security hardening tasks.
3 -
aibot88 Bundle Dockerfile ReviewReview Dockerfiles for best practices, security, and optimization. Use when the user says "review Dockerfile", "optimize image", "Dockerfile best practices", "reduce image size", or asks to audit a container build.
3 -
aibot88 Bundle Doncheli SecurityPerform OWASP Top 10 static security audit identifying vulnerabilities in access control, cryptography, injection, configuration, and logging. Activate when user mentions "security audit", "OWASP", "security scan", "vulnerabilities", "auditar seguridad".
3 -
aibot88 Bundle Electron SecurityUse when working on Electron applications — detected by `electron` in package.json dependencies, presence of `main.ts`/`main.js` entry, or `BrowserWindow` usage in source. Enforces contextIsolation true, nodeIntegration false, CSP, and draggable region discipline. Do NOT use for regular web apps, Node.js CLI tools, or non-Electron desktop frameworks (Tauri, Neutralino, NW.js).
3 -
aibot88 Bundle Eresus RemediatorSecurity remediation skill for fixing confirmed or likely SAST findings in source code. Trigger when the user asks to: "fix a vulnerability", "patch this security bug", "remediate SAST findings", "harden this endpoint", "make this auth flow safe", or wants code changes that remove a confirmed security issue while preserving intended behavior. Best used alongside eresus-sast-scanner.
3 -
aibot88 Bundle Essential8 ExpertEssential 8 expert for Australian cyber security. Deep knowledge of ACSC Essential Eight mitigation strategies including 8 strategies, 3 maturity levels, implementation guidance, and Australian government requirements.
3 -
aibot88 Bundle Field Audit TrailSalesforce Shield Field Audit Trail: configuration, retention policies, querying archived field data, compliance requirements. NOT for field history tracking (use field-history-tracking).
3 -
aibot88 Bundle Firefox ExtensionComprehensive guide for developing WebExtensions (browser extensions) for Mozilla Firefox, including Manifest V2/V3 configuration, all WebExtension APIs, security practices, web-ext CLI, and AMO submission.
3 -
aibot88 Bundle Fireworks FlutterUse when building Flutter/Dart apps, debugging Flutter issues, reviewing Flutter PRs, choosing state management, testing widgets/providers, optimizing Flutter performance, or auditing mobile security. Covers Flutter 3.38, Dart 3.10, Riverpod 3.0, BLoC 9.x, GoRouter, clean architecture, Impeller, OWASP Mobile Top 10.
3 -
aibot88 Bundle Food Systems DataUse this Skill to analyze food systems data from FAOSTAT: production/trade/food balance sheets, food security indicators, dietary diversity, and trade flow Sankey diagrams.
3 -
aibot88 Bundle Generate Cve JSONGenerate a CVE 5.x JSON document from an <tracker> tracking issue, ready to paste into the Vulnogram `#source` tab of the ASF CVE tool at https://cveprocess.apache.org/cve5/<CVE-ID>#source. The conversion is deterministic: same issue in, same JSON bytes out. Handles multiple credits (one per line) and multiple references (URLs extracted from the issue's "Public advisory URL" and "PR with the fix" fields; the "Security mailing list thread" field is treated as internal-only and never exported).
3 -
aibot88 Bundle Git Security 2025Git security best practices for 2025 including signed commits, zero-trust workflows, secret scanning, and verification
3 -
aibot88 Bundle Global ValidationImplement server-side validation with allowlists, specific error messages, type checking, and sanitization to prevent security vulnerabilities and ensure data integrity. Use this skill when creating or editing form request classes, when validating API inputs, when implementing validation rules in controllers or services, when writing client-side validation for user experience, when sanitizing user input to prevent injection attacks, when validating business rules, when implementing error message display, or when ensuring consistent validation across all application entry points.
3 -
aibot88 Bundle Golang CLI ReviewComprehensive code review for Golang CLI applications. Produces an actionable checklist covering error handling, CLI framework patterns (Cobra/urfave), testing, performance, security, and Go idioms. TRIGGERS: Review Go CLI, review golang command-line, code review .go CLI, audit CLI application, check golang tool, review cobra app
3 -
aibot88 Bundle Hardware SecurityHardware and embedded security research capabilities. Interface with JTAG debuggers, analyze SPI/I2C communications, dump and analyze firmware, support fault injection, side-channel analysis, and hardware exploitation research.
3 -
aibot88 Bundle Hashing PasswordsCRITICAL security skill teaching proper credential and password handling. NEVER store passwords, use bcrypt/argon2, NEVER accept third-party credentials. Use when handling authentication, passwords, API keys, or any sensitive credentials.
3 -
aibot88 Bundle HTTP InterceptorsAngular 21+ functional HTTP interceptors for auth, error handling, loading states, retry logic, caching, and security best practices
3 -
aibot88 Bundle Iso27001 ControlsЭксперт ISO 27001. Используй для ISMS, security controls и compliance implementation.
3 -
aibot88 Bundle Javascript StrictJavaScript (Node.js) strictness, clean code, and security rules. Use when writing, reviewing, or refactoring plain JavaScript (non-TypeScript) Node.js code. Covers const-first variable declarations, async/await patterns, class vs function patterns, JSDoc documentation, error handling, hot-path performance, CommonJS module patterns, and vulnerability prevention. Derived from production Node.js services.
3 -
aibot88 Bundle Legal Ip FortressStartup legal and IP protection operating system covering entity formation, co-founder agreements, IP strategy (patents, trademarks, trade secrets, copyright), employment law, contract management, regulatory compliance by industry, data privacy (GDPR/CCPA/DPDP), open-source license compliance, litigation prevention, IP valuation, M&A legal readiness, and investor-side legal requirements. Includes comprehensive India legal stack covering Companies Act 2013, FEMA, RBI regulations, SEBI compliance, Patent Act 1970, Trademark Act 1999, IT Act 2000, DPDP Act 2023, Labour Codes 2020, Shop & Establishment Acts, GST compliance, transfer pricing, and regulatory sandbox frameworks. Use when user mentions legal, lawyer, attorney, IP, patent, trademark, copyright, trade secret, contract, NDA, employment agreement, ESOP agreement, shareholder agreement, term sheet legal, regulatory, compliance, GDPR, CCPA, data privacy, open source license, litigation, lawsuit, cease and desist, incorporation, entity structure, or any leg
3 -
aibot88 Bundle Legal Ip SoftwareProprietà intellettuale su software — diritto italiano ed europeo. MODO A interna: OSS compliance policy, SBOM process (SPDX/CycloneDX), IP register aziendale, invention assignment, clean room procedure, trade secret protection protocol (artt. 98-99 CPI + D.Lgs. 63/2018), AI usage policy. MODO B contrattuale: IP Assignment clausole complete, license agreement proprietaria, SaaS subscription con IP, OSS disclosure annex, AI-generated output ownership clause + training data clause, trademark license, trade secret in NDA, patent RAND/FRAND, CLA contributor. Copre LDA 633/1941 artt. 64-bis/ter/quater + art. 12-bis (dipendenti) + art. 110 (cessione), brevetti CII art. 45 CPI + EPO G 1/19 (10/3/2021), OSS SPDX/GPL/MIT/Apache2/BSL, AI-generated (Cass. 1107/2023 Biancheri + L. 132/2025 art. 25), TDM opt-out art. 70-septies LDA. Giurisprudenza chiave: Kadrey v Meta, Getty v Stability UK 4/11/2025, Bartz v Anthropic. Attivati su LDA, art. 64-bis, art. 12-bis, SIAE, CII brevetto, art. 45 CPI, SPDX, GPL, SBOM, trade secr
3
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include asvs-requirements, atft-code-quality, bmad-testarch-nfr. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.