Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
aibot88 Bundle Audit DependenciesRun npm audit and check for outdated/vulnerable dependencies. Returns structured output with vulnerability counts by severity, outdated packages, and recommended updates. Used for security validation and dependency health checks.
3 -
aibot88 Bundle Claude Code ReviewUse when asked to review a PR, or when /review is invoked with a PR number or URL. Performs a focused code review checking for bugs, security, performance, and test gaps, then posts findings as a PR comment and formal GitHub review.
3 -
aibot88 Bundle Clean Code Mastery**CLEAN CODE MASTERY**: '코드 작성', '함수 만들어', '구현해', '개발해', '리팩토링', '개선해', '설계해', '클린코드', '코드품질' 요청 시 자동 발동. *.ts/*.py/*.go/*.java 등 모든 코드 파일 작업 시 자동 적용. SOLID/DRY/KISS + OWASP 보안 패턴. 언어별 선택적 로드.
3 -
aibot88 Bundle Code Review CsharpPerform structured code reviews of C# source code covering naming conventions, performance, security, readability, and .NET best practices. Trigger phrases include "review this C# code", "check my C# for best practices", "analyze this C# class", "find issues in my C# code".
3 -
aibot88 Bundle Coderabbit RequestUse after completing file changes - strongest for source code (AST-aware linting, security, tests), lighter support for markdown/config. Dispatches CodeRabbit reviewer subagent. ALWAYS request review before considering work complete.
3 -
aibot88 Bundle Compliance AuditorAutomated compliance auditing for SOC2, HIPAA, GDPR, and PCI-DSS. Activates for compliance checks, security audits, regulatory requirements, and compliance automation.
3 -
aibot88 Bundle Dag Scope EnforcerRuntime enforcement of file system boundaries and tool access restrictions. Blocks unauthorized operations and logs violations. Activate on 'enforce scope', 'access control', 'boundary enforcement', 'tool restrictions', 'runtime security'. NOT for validation (use dag-permission-validator) or isolation management (use dag-isolation-manager).
3 -
aibot88 Bundle Defender QuickscanTrigger Windows Defender scans, check threat history, update signatures, and query protection status via PowerShell
3 -
aibot88 Bundle Dependency AuditorAutomated security auditing of project dependencies to identify known vulnerabilities.
3 -
aibot88 Bundle Dependency CheckerAudit dependencies — npm audit, govulncheck, pip-audit, cargo-audit, outdated packages, update plan
3 -
aibot88 Bundle Dependency ManagerExpert dependency manager specializing in package management, security auditing, and version conflict resolution across multiple ecosystems. Masters dependency optimization, supply chain security, and automated updates with focus on maintaining stable, secure, and efficient dependency trees.
3 -
aibot88 Bundle Design IntegrationDesign a Uniswap integration architecture. Use when user is building a project that needs to integrate Uniswap and wants recommendations on integration method (Trading API vs SDK vs direct contract), architecture patterns, required dependencies, and security considerations.
3 -
aibot88 Bundle Design Review GateParallel design review by 6 specialist agents (PM, Architect, Designer, Security Design, UX, CTO) with mandatory unanimous approval.
3 -
aibot88 Bundle Detection EngineerCreate detection rules and hunting queries from malware analysis findings. Use when you need to write Sigma rules for SIEM, Suricata rules for network IDS, defang IOCs for safe sharing, or convert analysis findings into actionable detection content for SOC teams and threat hunters.
3 -
aibot88 Bundle Devsecops PatternsDevSecOps patterns — shift-left security, SAST (semgrep/CodeQL), secrets detection (gitleaks/trufflehog), dependency scanning (trivy/grype), DAST, OPA/Falco policy-as-code, container security, and security gates per CI stage.
3 -
aibot88 Bundle Dotnet Aspnet CoreBuild, debug, modernize, or review ASP.NET Core applications with correct hosting, middleware, security, configuration, logging, and deployment patterns on current .NET.
3 -
aibot88 Bundle Eresus Deser AuditDeserialization vulnerability audit skill with gadget chain knowledge for all major languages. Trigger when the user asks to: "audit deserialization", "check for insecure deserialization", "find pickle vulnerabilities", "Marshal.load audit", "gadget chain analysis", "check for unsafe YAML loading", or when reviewing code that processes serialized data (JSON with type info, YAML, XML, binary formats).
3 -
aibot88 Bundle Evidence ValidatorValidates audit evidence artifacts for completeness, timeliness, relevance, and authenticity. Reviews screenshots, logs, configurations, and policies against control requirements.
3 -
aibot88 Bundle Evolve Plan ReviewUse when scout-report.md exists and TDD/Build hasn't started yet. Runs four lenses (CEO, Eng, Design, Security) in parallel on the task list and produces a verdict (PROCEED, REVISE, ABORT) before code is written. Catches misaligned plans before they cost cycles.
3 -
aibot88 Bundle Exploit ResearcherExploit researcher persona specializing in attack surface analysis, exploit scenario generation, and vulnerability chaining
3 -
aibot88 Bundle Express TypescriptGuidelines for building robust APIs with Express.js and TypeScript, covering middleware patterns, routing, and security best practices
3 -
aibot88 Bundle Fedramp 20x ExpertFedRAMP 20X modernization expert. Provides guidance on Key Security Indicators (KSIs), continuous monitoring automation, machine-readable policies, and the new automated authorization approach. Auto-syncs with official FedRAMP docs.
3 -
aibot88 Bundle Firebase FirestoreBuild with Firestore NoSQL database - real-time sync, offline support, and scalable document storage. Use when: creating collections, querying documents, setting up security rules, handling real-time listeners, or troubleshooting permission-denied, quota exceeded, invalid query, or offline persistence errors. Prevents 10 documented errors.
3 -
aibot88 Bundle Fireworks SecuritySecurity hardening superbrain — CWE Top 25, STRIDE threat modeling, Electron hardening, encryption, dependency audits, OWASP compliance
3 -
aibot88 Bundle Fix Security IssueAttempt to fix a security issue tracked in <tracker> by implementing the change in a public <upstream> PR. Runs the sync-security-issue skill first to reconcile the issue's state, then analyses the discussion to decide whether the issue is easily fixable (clear consensus, small scope, known location). If it is, proposes an implementation plan, waits for explicit user confirmation, writes the change in the user's local <upstream> clone, runs the local checks and tests, opens a PR from the user's fork via `gh pr create --web`, and updates the <tracker> tracking issue with the new PR link and any relevant labels. Public PR content is checked to make sure it does **not** reveal the CVE, the security nature of the change, or any link back to <tracker>.
3 -
aibot88 Bundle Gathering SecurityThe drum sounds. Spider and Raccoon gather for complete security work. Use when implementing auth or auditing security end-to-end.
3 -
aibot88 Bundle Gemini Claude LoopDual-AI engineering loop orchestrating Claude Code (planning/implementation) and Gemini (validation/review). Use when (1) complex feature development requiring validation, (2) high-quality code with security/performance concerns, (3) large-scale refactoring, (4) user requests gemini-claude loop or dual-AI review. Do NOT use for simple one-off fixes or prototypes.
3 -
aibot88 Bundle Generational AuditAudite un projet tech (code source + expérience rendue) et évalue son adéquation à 5 cohortes générationnelles (Boomers, Gen X, Millennials, Gen Z, Gen Alpha). Produit un rapport markdown et un JSON exploitable. Utiliser quand l'utilisateur demande un audit générationnel, une analyse d'audience, une évaluation cross-génération, ou veut savoir quelle génération un produit cible réellement.
3 -
aibot88 Bundle Ghsa Skill BuilderUse when building or updating vulnerability pattern Skills from multiple sources: GitHub Security Advisories (GHSA), HackerOne Hacktivity, or NVD. Triggers on keywords: GHSA, CVE, vulnerability skill, vuln pattern, update skills, security advisory, HackerOne, H1, hacktivity, pentest skill, bug bounty, check for updates.
3 -
aibot88 Bundle Github Pr ReviewerPre-merge functional reviewer skill. Invoke for GitHub PR quality, contract validation, and release readiness. Do not invoke for deep security audit of auth/secrets/permissions.
3 -
aibot88 Bundle Gitlab Code ReviewPerforms comprehensive code reviews of GitLab merge requests, analyzing code quality, security, performance, and best practices. Use when the user says "review" or "code review" or asks to review merge requests or analyze branch changes before merging.
3 -
aibot88 Bundle Go API DevelopmentGo API development guidelines using the standard library (1.22+) with best practices for RESTful API design, error handling, and security
3 -
aibot88 Bundle Golang Code ReviewComprehensive Go code review skill for PR reviews, architecture assessment, and test quality analysis. Use when reviewing Go code to ensure adherence to Go best practices, security standards, and project-specific patterns. Applies to full PR reviews, single file/function reviews, architecture evaluation, and test code quality checks.
3 -
aibot88 Bundle Goth Echo SecurityThis skill should be used when the user asks to "integrate goth with echo", "oauth echo framework", "echo authentication", "goth session management", "oauth security", "secure oauth", "gorilla sessions", or needs help with session storage, security patterns, or Echo framework integration for Goth.
3 -
aibot88 Bundle Ha Dr ArchitectureDesigning high availability and disaster recovery strategies for Salesforce: Trust site monitoring, backup strategies, cross-region considerations, business continuity planning, RTO/RPO target definition, and failover patterns for integrations. Use when designing org resilience architecture, planning for outages, or defining recovery objectives. NOT for data backup mechanics (use salesforce-backup-and-restore). NOT for general security architecture (use security-architecture-review).
3 -
aibot88 Bundle Input SanitizationЭксперт по санитизации ввода. Используй для XSS prevention, encoding, validation и security headers.
3
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include audit-dependencies, claude-code-review, clean-code-mastery. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.