Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
aibot88 Bundle Loi 25 ComplianceBase de connaissances sur la Loi 25 du Québec (protection des renseignements personnels) appliquée au développement logiciel. Ce skill doit être utilisé quand l'utilisateur demande "audit loi 25", "vérifier la conformité", "protection des données personnelles", "PII", "renseignements personnels", "vie privée", "chiffrement des données sensibles", "droit à l'effacement", "portabilité des données", "EFVP", "évaluation des facteurs relatifs à la vie privée", ou toute question sur la conformité d'un projet aux lois québécoises de protection de la vie privée.
3 -
aibot88 Bundle Nora ArchitectuurHelpt bij het ontwerpen van overheidssystemen conform de Nederlandse Overheid Referentie Architectuur (NORA), inclusief basisprincipes, afgeleide principes, informatiebeveiliging (BIO), en de GDI (Generieke Digitale Infrastructuur). Biedt richtlijnen voor architectuurprincipes, standaarden en voorzieningen. Gebruik deze skill wanneer de gebruiker vraagt over 'NORA', 'referentiearchitectuur', 'enterprise architectuur overheid', 'government architecture', 'NORA principes', 'basisprincipes overheid', 'afgeleide principes', 'BIO', 'Baseline Informatiebeveiliging Overheid', 'informatiebeveiliging overheid', 'information security government', 'GDI', 'Generieke Digitale Infrastructuur', 'voorzieningen overheid', 'Diginetwerk', 'Digipoort', 'Digikoppeling', 'Digilevering', 'Stelsel van Basisregistraties', 'basisregistratie', 'FORUM standaardisatie', 'pas toe of leg uit', 'comply or explain', 'open standaarden overheid', 'lijsten open standaarden', 'verplichte standaard', 'architectuurprincipe overheid', 'TOGAF overhe
3 -
aibot88 Bundle Openapi ValidatorValidate OpenAPI specifications for correctness, security, and best practices
3 -
aibot88 Bundle Pattern DetectionDetect patterns, anomalies, and trends in code and data. Use when identifying code smells, finding security vulnerabilities, or discovering recurring patterns. Handles regex patterns, AST analysis, and statistical anomaly detection.
3 -
aibot88 Bundle Pitfalls SecuritySecurity patterns for session keys, caching, logging, and environment variables. Use when implementing authentication, caching sensitive data, or setting up logging. Triggers on: session key, private key, cache, logging, secrets, environment variable.
3 -
aibot88 Bundle Power Bi DesignerConception de dashboards Power BI — DAX, modèle de données, visualisations avancées et Row-Level Security. Se déclenche avec "Power BI", "DAX", "dashboard Power BI", "rapport Power BI", "modèle de données Power BI".
3 -
aibot88 Bundle Query Token AuditQuery token security audit to detect scams, honeypots, and malicious contracts before trading. Returns comprehensive security analysis including contract risks, trading risks, and scam detection. Use when users ask "is this token safe?", "check token security", "audit token", or before any swap.
3 -
aibot88 Bundle Rails Review FlowMulti-pass Rails code review workflow that identifies bugs, security vulnerabilities, and architectural issues; assigns severity levels (Critical, Suggestion, Nice-to-have); and generates actionable review comments with a mandatory re-review loop for Critical findings. Use for full PR review workflows, multi-pass security or architecture audits, or implementing and verifying responses to review feedback. Trigger: review this PR, full code review, multi-pass review, audit security vulnerabilities, review architecture, respond to review feedback, implement review fixes.
3 -
aibot88 Bundle Release ChecklistSequential release gate validating build success, test suite, security checks, type checking, manifest counts consistency, and changelog presence. Each step reports pass/fail with remediation guidance. Manages version bumping, staging, and pre-push confirmation. Use when preparing a release.
3 -
aibot88 Bundle Review DependencyUse for security review of dependency updates — bumps, upgrades, or new dependencies.
3 -
aibot88 Bundle Robotics SecuritySecurity hardening and best practices for robotic systems, covering SROS2 DDS security, network segmentation, secrets management, secure boot, and the physical-cyber safety intersection. Use this skill when securing ROS2 communications, configuring DDS encryption and access control, hardening robot onboard computers, managing certificates and credentials, setting up network segmentation for robot fleets, or addressing the unique security challenges where cyber vulnerabilities become physical safety risks. Trigger whenever the user mentions SROS2, DDS security, robot security, robot hardening, ROS2 encryption, ROS2 access control, robot network security, secure robot deployment, robot certificates, keystore generation, robot firewall, e-stop security, safety controller isolation, or IEC 62443 for robotics.
3 -
aibot88 Bundle Web3 Security AnalysisAnalyze Web3 security risks with SpoonOS agents. Use when checking token safety (honeypots, rugs), simulating transactions, detecting MEV, or auditing contracts.
3 -
aibot88 Bundle Security BaselineEstablish a security baseline for a website or web app. Use this skill when configuring HTTPS and TLS, setting security headers, planning secrets management, evaluating CSP policies, doing a basic security audit, or hardening a site before launch. Triggers on security headers, HTTPS, TLS, CSP, content security policy, HSTS, secrets management, vulnerability scan, security audit, harden, OWASP, security baseline. Also triggers when a security review is required for compliance or before going live.
3 -
aibot88 Bundle Security EngineerSEOcrawler security vulnerability scanner and hardening specialist for comprehensive security audits.
3 -
aibot88 Bundle Security GuardianExpert en sécurité applicative pour détecter les vulnérabilités, auditer le code, et guider les bonnes pratiques de sécurité. OWASP Top 10, authentification, autorisation, cryptographie, gestion de secrets. Utiliser pour audits sécurité, reviews de code sensible, conception de features sécurisées, ou résolution de failles.
3 -
aibot88 Bundle Security ScanningAgentShield security audit with 5 scanning categories, 102 static analysis rules, and optional red-team simulation.
3 -
aibot88 Bundle Security SentinelUse when working with authentication, API routes, user input, or sensitive data. Audits code for security vulnerabilities based on OWASP Top 10. Critical for payment processing, auth systems, and data handling.
3 -
aibot88 Bundle Security SnapshotGenerate a client-ready security hygiene snapshot for a prospect domain. Free lead magnet for consulting practices. Outputs a markdown report covering SSL/TLS grade, HTTP security headers, email authentication (SPF/DMARC), and server fingerprint leaks. Use when the user says /security-snapshot, /snapshot [domain], "run a security check on X", or "generate a security report for [company]". Do NOT use for penetration testing, internal infrastructure audits, or application-layer vulnerability assessment. This is a passive, unauthenticated scan for conversation-starter value, not a full audit.
3 -
aibot88 Bundle Skill Usage AuditScan all artefacts (epics, stories, PRDs) for Base Rule
3 -
aibot88 Bundle Social PsychologyHow individuals think about, influence, and relate to one another. Covers conformity (Asch line experiments, informational vs. normative influence), obedience (Milgram experiments, situational factors), attitudes (formation, change, cognitive dissonance, persuasion), group dynamics (groupthink, social facilitation, social loafing, deindividuation), and prejudice (stereotyping, implicit bias, stereotype threat, intergroup conflict, contact hypothesis). Use when analyzing social influence, group behavior, attitude formation, prejudice, or interpersonal processes.
3 -
aibot88 Bundle Staff Code ReviewStaff-engineer-level code review that goes beyond correctness to evaluate architectural alignment, system-level implications, failure modes, performance, scalability, backward compatibility, observability, security, and cross-team impact. Use when reviewing a PR (URL or diff), analyzing code changes for architectural fitness, or when the user asks for a thorough/staff-level/senior review of code changes. Triggers on "review this PR", "review these changes", "staff review", "thorough code review", sharing a GitHub PR URL for review, or asking about the architectural impact of changes.
3 -
aibot88 Bundle Statutory Auditorनेपाली नियमित लेखा परीक्षण (statutory audit under NCA Act 2053)। NFRS अनुपालन, ब्यालेन्स शीट / P&L सत्यापन, लेखा परीक्षण मत। Statutory audit under NCA Act 2053. NFRS compliance, balance sheet/P&L verification, audit opinion. Use for audit planning, NFRS compliance checks, or audit report generation.
3 -
aibot88 Bundle Structured Code ReviewPerforms a structured five-stage code review covering requirements compliance, correctness, code quality, testing, and security/performance. Each stage uses targeted checklists and categorized feedback (Blocker/Major/Minor/Nit) with actionable suggestions and rationale. Use when the user asks for code review, PR feedback, pull request review, or wants their code checked for bugs, style issues, or vulnerabilities — triggered by phrases like "review my code", "check this PR", "review my changes", "pull request review", or "code feedback".
3 -
aibot88 Bundle Supabase PatternsGeneric Supabase best practices for Row Level Security, realtime subscriptions, storage, and edge functions. Framework-agnostic.
3 -
aibot88 Bundle Supabase ProjectsThis skill should be used when managing Supabase projects or organizations, creating new projects, listing projects, checking project status, retrieving API keys, pausing or restoring projects, or working with project costs and billing. Trigger when: "create Supabase project", "list Supabase projects", "Supabase API keys", "pause project", "restore project", "Supabase organization", "project cost", "get project URL", "publishable key", "secret key", "anon key", "service role key", "asymmetric JWT", "JWT signing keys", "key rotation", "supabase link", "project settings", or managing Supabase project lifecycle.
3 -
aibot88 Bundle Supabase SecurityAudit de sécurité complet pour les projets Supabase. Lance un pentest automatisé qui vérifie RLS, buckets, auth, keys exposées, et génère un rapport avec remediation. Utiliser quand l'utilisateur dit "audit supabase", "sécurité supabase", "vérifier mon supabase", ou veut s'assurer que son backend Supabase est sécurisé.
3 -
aibot88 Bundle Thinking Red TeamDeliberately attack your own plans, systems, and assumptions to find weaknesses before adversaries or reality does. Use for security review, architecture validation, plan stress-testing, and pre-launch preparation.
3 -
aibot88 Bundle Us Hipaa SecurityHIPAA Security Rule expert for US healthcare compliance. Deep knowledge of 45 CFR Part 164 Subpart C, Administrative/Physical/Technical Safeguards, Required vs Addressable specifications, Risk Analysis, Business Associate Agreements, and HHS OCR enforcement.
3 -
aibot88 Bundle Ring Using Lib CommonsDual-mode skill for github.com/LerianStudio/lib-commons v5, Lerian's shared Go library — the non-observability surface. Sweep Mode dispatches parallel explorers to detect DIY implementations that should use lib-commons, with file:line replacement precision. Reference Mode catalogs lib-commons packages for lifecycle (Launcher), outbox repository, circuit breakers, tenant management, idempotency, security/TLS, database, messaging, HTTP toolkit. Observability (log, metrics, tracing, assertions, panic recovery, redaction) moved out of lib-commons into lib-observability v1.0.0 — see [[using-lib-observability]] and its sub-skills [[using-tracing]], [[using-runtime]], [[using-assert]]. Skip for non-Go code or Ring itself.
3 -
aibot88 Bundle Vbs Scan SecurityUse when scanning code for security vulnerabilities. Use when user says "scan security", "kiểm tra bảo mật", "security audit", "review security", or invokes `/vbs-scan-security`. For large scans (>20 main-language files OR >30 total OR >14 days) processes chunks sequentially. Outputs bilingual reports (vi/en).
3 -
aibot88 Bundle Watch MarketplacePoll the Anthropic plugin marketplace manifest until "channelhub" appears, then notify the user. Use when waiting for the security review to land — the submission portal shows "Published" before the public manifest is updated.
3 -
aibot88 Bundle Add Security AuditSecurity audit: OWASP Top 10, multi-tenancy, injection, auth, XSS, dependencies.
3 -
aibot88 Bundle AI Risk AssessmentIdentifying, assessing, and mitigating risks in AI systems including bias, safety, privacy, security, and ethical concerns.
3 -
aibot88 Bundle API AuthenticationSecure API authentication with JWT, OAuth 2.0, API keys. Use for authentication systems, third-party integrations, service-to-service communication, or encountering token management, security headers, auth flow errors.
3 -
aibot88 Bundle API Best PracticesREST API design patterns, OpenAPI specifications, versioning strategies, authentication, error handling, and security best practices. Use when designing APIs, creating endpoints, documenting APIs, or implementing backend services that expose HTTP APIs.
3 -
aibot88 Bundle Audit DeliverablesThe "Structural Critic" that audits specialist output and issues a binary PASS or BLOCKED verdict. No track is complete until the Quality Gate approves. Read-only — never fixes, only judges.
3
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include loi-25-compliance, nora-architectuur, openapi-validator. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.