Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
aibot88 Bundle JWT Attack SurfaceAudit JWT implementation for algorithm confusion, secret weakness, claim validation issues, and token handling vulnerabilities. Use when reviewing authentication systems using JWT.
3 -
aibot88 Bundle Lindy Install AuthSet up Lindy AI account, API access, and webhook authentication. Use when onboarding to Lindy, configuring API keys for webhook triggers, or connecting Lindy agents to your application. Trigger with phrases like "install lindy", "setup lindy", "lindy auth", "configure lindy API key", "lindy webhook secret".
3 -
aibot88 Bundle Loom Security ScanQuick routine security checks for secrets, dependencies, container images, and common vulnerabilities. Use for lightweight pre-commit and CI scans with tools like Semgrep, Trivy, gitleaks, cargo audit, npm audit, and pip-audit. Not a substitute for deep audits (use loom-security-audit).
3 -
aibot88 Bundle Manage Secrets EnvOpinionated defaults and full lifecycle playbook for secrets and environment variables. Decides where a secret or env-specific value lives (constant, .env, CI secret, env var), scaffolds .env.example and .gitignore, and manages the lifecycle end to end — add, update, rotate, remove, migrate between buckets, audit cross-environment drift, provision new environments. High-stakes companion to project-conventions. Language-agnostic.
3 -
aibot88 Bundle Ml VulnerabilitiesOWASP Machine Learning Top 10 vulnerability knowledge base for identifying, assessing, and remediating security risks in machine learning systems.
3 -
aibot88 Bundle Moai Platform AuthAuthentication and authorization specialist covering Auth0, Clerk, and Firebase Auth. Use when implementing authentication, MFA, SSO, passkeys, WebAuthn, social login, or security features.
3 -
aibot88 Bundle Moai Tool Ast GrepAST-based structural code search, security scanning, and refactoring using ast-grep (sg CLI) with pattern matching and code transformation across 40+ languages. Use for structural search or codemod operations.
3 -
aibot88 Bundle Naming ConventionsUse when performing a full naming audit across a codebase, stack profile, or API surface for convention compliance
3 -
aibot88 Bundle Nginx ConfiguratorConfiguration Nginx — reverse proxy, SSL/TLS, load balancing, caching et security headers. Se déclenche avec "Nginx", "nginx.conf", "reverse proxy", "SSL Nginx", "load balancer Nginx".
3 -
aibot88 Bundle Offensive Security SkillOffensive security tools and techniques integration
3 -
aibot88 Bundle Op Secret TemplateGenerate `op://` secret references for every field on a 1Password item. Output is ready to paste into a `.env` template.
3 -
aibot88 Bundle Orchestrate ReviewUse when user asks to "deep review the code", "thorough code review", "multi-pass review", or when orchestrating the Phase 9 review loop. Provides review pass definitions (code quality, security, performance, test coverage), signal detection patterns, and iteration algorithms.
3 -
aibot88 Bundle Owasp API SecurityOWASP API Security Top 10 testing patterns, injection payloads, auth bypass vectors, and security test generation for REST APIs. Use when writing security tests, reviewing API endpoints for vulnerabilities, or auditing input validation.
3 -
aibot88 Bundle Pci Dss SpecialistPCI DSS v4.0 payment card industry data security standard compliance, assessment, and implementation. Use for PCI DSS, payment card security, cardholder data, PCI compliance, payment security, PCI assessment, SAQ, ROC, QSA, credit card security, payment processing security, PCI scoping, tokenization, payment terminal security, CDE security, and merchant compliance.
3 -
aibot88 Bundle Performing Penetration TestingThis skill enables automated penetration testing of web applications. It uses the penetration-tester plugin to identify vulnerabilities, including OWASP Top 10 threats, and suggests exploitation techniques. Use this skill when the user requests a "penetration test", "pentest", "vulnerability assessment", or asks to "exploit" a web application. It provides comprehensive reporting on identified security flaws.
3 -
aibot88 Bundle Pentest MetasploitPenetration testing framework for exploit development, vulnerability validation, and authorized security assessments using Metasploit Framework. Use when: (1) Validating vulnerabilities in authorized security assessments, (2) Demonstrating exploit impact for security research, (3) Testing defensive controls in controlled environments, (4) Conducting authorized penetration tests with proper scoping and authorization, (5) Developing post-exploitation workflows for red team operations.
3 -
aibot88 Bundle Dartai Post Task ReviewerForked-context deep post-task reviewer — preloads verdict schema + OWASP security + deep code analysis + PM/docs accuracy + replan lens. 對抗深度後任務審查(fork上下文)。 Use when: dispatch post-task-reviewer subagent, deep review after fast gates, OWASP audit, PM/docs accuracy check, replan recommendation
3 -
aibot88 Bundle Pr Security ReviewUse this skill to review a PR or diff for security regressions. Do not use it for full-repository audits or legal contract review.
3 -
aibot88 Bundle Principle SecuritySecurity design principles — trust boundaries and input validation, authentication vs authorization, secrets handling, secure defaults and defense in depth, lightweight threat modeling, cryptography hygiene, attack-surface minimization. Auto-load when designing auth, discussing authn or authz, handling secrets, defining trust boundaries, validating untrusted input, considering SSRF or CSRF, choosing session or JWT mechanics, configuring TLS, picking an encryption primitive, or weighing least-privilege trade-offs.
3 -
aibot88 Bundle Privacy API DesignDesign privacy API patterns including data subject API for DSAR endpoints, consent API for preference management, deletion API with cascading delete orchestration, and audit API for compliance reporting. Provides OpenAPI specifications, error handling, rate limiting, and authentication patterns.
3 -
aibot88 Bundle Python ConventionsApply Python project conventions — uv for deps and builds, Ruff strict (E, F, I, UP, B, SIM, PTH, PIE, RUF, T201, PLC0415), mypy strict, pytest with pytest-cov and pytest-asyncio, vulture for dead code, pip-audit for dependency security, and a gitignored test.py for scratch experiments. Use when starting a Python project, writing or reviewing Python code, configuring Python tooling, or evaluating compliance with these defaults. Co-activates with running-tdd-cycles, reviewing-changes, and engineering-philosophy.
3 -
aibot88 Bundle Releasing VersionsManages release preparation including validation, version bumping, documentation verification, and security checks.
3 -
aibot88 Bundle Sast BusinesslogicDetect business logic vulnerabilities in a codebase using a three-phase approach: threat modeling (domain analysis and attack scenarios), batched verify (check exploitable gaps in parallel subagents, 3 scenarios each), and merge (consolidate batch results). Covers price manipulation, workflow bypass, limit violations, race conditions, reward abuse, etc. Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/businesslogic-results.md. Use when asked to find business logic, logic flaws, or abuse-of-function bugs.
3 -
aibot88 Bundle Security AwarenessTeaches agents to recognize and avoid security threats during normal activity. Covers phishing detection, credential protection, domain verification, and social engineering defense. Use when building or operating agents that access email, credential vaults, web browsers, or sensitive data.
3 -
aibot88 Bundle Security DashboardGitHub security alerts command center -- triage Dependabot, code scanning, and secret scanning alerts entirely from the editor. Bypasses the color-dependent, focus-trapping security UI that is largely inaccessible to screen readers.
3 -
aibot88 Bundle Security Issue FixAttempt to fix a security issue tracked in <tracker> by implementing the change in a public <upstream> PR. Runs the security-issue-sync skill first to reconcile the issue's state, then analyses the discussion to decide whether the issue is easily fixable (clear consensus, small scope, known location). If it is, proposes an implementation plan, waits for explicit user confirmation, writes the change in the user's local <upstream> clone, runs the local checks and tests, opens a PR from the user's fork via `gh pr create --web`, and updates the <tracker> tracking issue with the new PR link and any relevant labels. Public PR content is checked to make sure it does **not** reveal the CVE, the security nature of the change, or any link back to <tracker>.
3 -
aibot88 Bundle Soc Cognitive BiasIdentify and analyze cognitive biases including confirmation bias, anchoring, availability heuristic, and sunk cost fallacy in decision-making contexts. Use this skill when the user needs to audit a decision for bias, understand why a team keeps making the same mistakes, design debiasing interventions, or evaluate whether a conclusion is based on evidence or cognitive shortcuts — even if they say 'are we fooling ourselves', 'why do we keep getting this wrong', or 'is this analysis biased'.
3 -
aibot88 Bundle Sonar Quality GateSonarQube-style quality gate analyzer + auto-fix. Inspects code for Bugs · Vulnerabilities · Security Hotspots · Code Smells · Duplication · Coverage with severity (BLOCKER/CRITICAL/MAJOR/MINOR/INFO) and Reliability/Security/Maintainability ratings A-E. Follows 'Clean as You Code' — focus changes on new code, leave legacy. Use when running quality gate, fixing sonar issues, pre-commit lint, before PR merge, or any code-smell/coverage/duplication/vulnerability check.
3 -
aibot88 Bundle Supply Chain AuditAnalyze project dependencies for supply chain risks. Checks maintainer count, commit frequency, CVE history, abandonment signals, bus factor, and security policy presence for each direct dependency. Supports npm, pip, cargo, go mod, and composer. Use when: "supply chain audit", "dependency risk", "check dependencies", "maintainer risk", "abandoned packages", "dependency health", "package security", "supply chain risk".
3 -
aibot88 Bundle Tech Stack ScannerAutomated technical architecture review, security assessment, scalability analysis
3 -
aibot88 Bundle Technical AnalysisTechnical analysis capabilities for APIs, data models, integrations, and security requirements. Use when analyzing technical aspects of systems or documenting technical requirements.
3 -
aibot88 Bundle Template GeneratorGenerate standardized document templates (DOCUMENT, TECHNICAL, PROPOSAL, RESEARCH, SECURITY-QA, INDEX) with YAML frontmatter, Quick Reference sections, and consistent structure for professional documentation.
3 -
aibot88 Bundle Transparency AuditPrüft die Transparenz-Compliance des Menschlichkeit Österreich Projekts — ZVR-Nummer 1182213083, Vereinsstatuten, Datenschutzerklärung und Impressum auf Vollständigkeit und Korrektheit. Wird aufgerufen bei `/transparency-audit`.
3 -
aibot88 Bundle Validate ConnectorAudit an existing Sim knowledge base connector against the service API docs and repository conventions, then report and fix issues in auth, config fields, pagination, document mapping, tags, and registry entries. Use when validating or repairing code in `apps/sim/connectors/{service}/`.
3 -
aibot88 Bundle Verification GatesCreates explicit validation checkpoints (verification gates) between project phases to catch errors early and ensure quality before proceeding. Use when the user asks about quality gates, milestone checks, phase transitions, approval steps, go/no-go decision points, or preventing cascading errors across a multi-step workflow. Produces acceptance criteria checklists, automated CI gate configurations, manual sign-off requirements, and conditional review rules for scenarios such as security changes, API changes, or database migrations.
3 -
aibot88 Bundle Web Security AuditExpert guidance on identifying and mitigating common web vulnerabilities from a bug hunter's perspective. Covers access control, XSS, CSRF, SSRF, insecure file uploads, and JWT security with detailed protection strategies, implementation patterns, and verification checklists.
3
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include jwt-attack-surface, lindy-install-auth, loom-security-scan. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.