Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
aibot88 Bundle Web VulnerabilitiesOWASP Top 10 for Web Applications (2025) vulnerability knowledge base for identifying, assessing, and remediating security risks in web application environments.
3 -
aibot88 Bundle Webhook IntegrationUse when implementing or reviewing an inbound webhook handler for any third-party provider - verifying signatures, deduplicating retries, choosing the right HTTP status code for retry vs no-retry, persisting raw payloads before canonical mapping, and quarantining unverifiable events. Covers signature schemes, idempotency patterns, provider retry contracts, raw-then-canonical pipelines, quarantine, secret rotation, and PII-capture timing. Do NOT use for outbound webhook publishing (use `event-contract-design`), general background-job orchestration, or chasing a webhook handler that has already failed in production (use `debugging`).
3 -
aibot88 Bundle Apache Nifi RegistryExpert guidance for Apache NiFi Registry including flow versioning, buckets, Git integration, security, and registry client configuration. Use this when working with flow version control and registry management.
3 -
aibot88 Bundle API Design ArchitectRESTful and GraphQL API design expert covering best practices, security, and scalability
3 -
aibot88 Bundle Application SecuritySecure applications against common vulnerabilities. Use when reviewing code for security, implementing security controls, or hardening applications. Covers OWASP Top 10.
3 -
aibot88 Bundle Arch Security ReviewUse when reviewing code for security vulnerabilities, implementing authorization, or ensuring data protection.
3 -
aibot88 Bundle Audit Trail VerifierVerifies financial data against source documents, bank statements, contracts
3 -
aibot88 Bundle Auth Security ExpertOAuth 2.1, JWT (RFC 8725), encryption, and authentication security expert. Enforces 2026 security standards.
3 -
aibot88 Bundle Auth0 AuthenticationGuidelines for implementing Auth0 authentication with best practices for security, rules, actions, and SDK integration
3 -
aibot88 Bundle Authentication SetupDesign and implement authentication and authorization systems. Use when setting up user login, JWT tokens, OAuth, session management, or role-based access control. Handles password security, token management, SSO integration.
3 -
aibot88 Bundle Automated Code FixerAutomated IT helper for detecting and fixing code issues. Use when code fails tests, linting, type-checking, or has security vulnerabilities. Enforces strict quality gates before accepting fixes.
3 -
aibot88 Bundle Automation ValidatorValidates automation workflow JSON before deployment for Power Automate, n8n, Make, Zapier and other platforms. Checks syntax, structure, best practices, and potential issues. Analyzes workflow JSON files for platform compliance, missing error handling, performance issues, and security concerns. Use when user wants to validate, review, or check a workflow before deployment/import.
3 -
aibot88 Bundle Backend API PatternsBackend and API implementation patterns for scalability, security, and maintainability. Use when building APIs, services, and backend infrastructure.
3 -
aibot88 Bundle Calculating AlimentyUse when determining the amount of alimony under Polish KRO — calculating justified needs of the entitled person vs. earning/property capacity of the obligor (art. 135 KRO), applying equal-standard-of-living principle, setting up documentary evidence, drafting interim security motions under art. 754¹ KPC, or coordinating with the Fundusz Alimentacyjny when enforcement fails
3 -
aibot88 Bundle Ciso Product ManagerCISO & Product Manager skill providing security-focused product vision, risk assessment, and strategic guidance for caro development
3 -
aibot88 Bundle Clade Prod ChecklistProduction readiness checklist for Claude-powered applications — Use when working with prod-checklist patterns. error handling, monitoring, fallbacks, cost controls, and security. Trigger with "anthropic production", "claude production ready", "anthropic launch checklist", "go live with claude".
3 -
aibot88 Bundle Clay Security BasicsApply Clay security best practices for API keys, webhook secrets, and data access control. Use when securing Clay integrations, rotating API keys, auditing access, or implementing webhook authentication. Trigger with phrases like "clay security", "clay secrets", "secure clay", "clay API key security", "clay webhook security".
3 -
aibot88 Bundle Code Review AnalysisPerform comprehensive code reviews with best practices, security checks, and constructive feedback. Use when reviewing pull requests, analyzing code quality, checking for security vulnerabilities, or providing code improvement suggestions.
3 -
aibot88 Bundle Code Review PatternsMulti-dimensional code assessment across security, quality, performance, and maintainability with confidence-gated reporting (>=80%) and Router Contract generation.
3 -
aibot88 Bundle Code Review SimplifyUse when reviewing code changes for quality, security, performance, or maintainability issues and identifying simplification opportunities in a single token-efficient pass
3 -
aibot88 Bundle Code Security ReviewConducts comprehensive security code reviews including vulnerability detection (OWASP Top 10, CWE), authentication/authorization flaws, injection attacks, cryptography issues, sensitive data exposure, API security, dependency vulnerabilities, security misconfigurations, and compliance validation (PCI-DSS, GDPR, HIPAA). Produces detailed security assessment reports with CVE references, CVSS scores, exploit scenarios, and remediation guidance. Use when reviewing code security, performing security audits, checking for vulnerabilities, validating security controls, assessing security risks, or when users mention "security review", "vulnerability scan", "security audit", "penetration test", "OWASP", "security assessment", "secure coding", or "security compliance".
3 -
aibot88 Bundle Cometchat ProductionProduction readiness for CometChat — server-side token auth, user management CRUD, environment hardening, and security checklist. Replaces dev-mode authKey with server-side tokens.
3 -
aibot88 Bundle Compliance And AuditUse when a project requires a compliance framework mapping, when risks need formal documentation, when audit evidence must be collected, or when producing a compliance attestation before release. Applies to SOC 2, ISO 27001, GDPR, PCI DSS, NIST CSF, and DORA.
3 -
aibot88 Bundle Compliance ChecklistProvides a checklist framework for surfacing potentially applicable application-compliance obligations across declared jurisdictions (Japan / EU / US-CA / platform stores). The Skill is invoked by product-manager, security-reviewer, and technical-writer when a capability that may have legal exposure is added (chat / payments / PII collection / data export). It emits a checklist with primary-source citations and a mandatory disclaimer block; it never marks items as "complied with" — only the human reviewer can. Skill contents (Progressive Disclosure): SKILL.md — overview, six invariant rules, output contract, navigation disclaimers.md — the mandatory disclaimer block, in EN and JA triggers.md — capability-detection rules and PII-path refusal globs jurisdictions/JP.md — Japan: 電気通信事業法 / 特定商取引法 / 改正個人情報保護法 / 資金決済法 jurisdictions/EU.md — GDPR (with Art. 3 extraterritorial scope) jurisdictions/US-CA.md — CCPA / CPRA jurisdictions/platform.md — Apple App Store / Google Play This Skill is bilingual where its output r
3 -
aibot88 Bundle Compliance ValidatorValidate compliance during migration with rule checking, audit trails, and security control validation
3 -
aibot88 Bundle Create Associate NsgCreates a new Network Security Group and associates it with the specified subnets and/or NICs of a Virtual Network.
3 -
aibot88 Bundle Csp And Trusted UrlsConfigure Content Security Policy via Trusted URLs and CSP Trusted Sites so Lightning, LWR, and LWC can call third-party scripts, APIs, and frame sources. NOT for clickjack configuration.
3 -
aibot88 Bundle Cybersecurity BasicsFoundational cybersecurity literacy covering threat landscape (malware, phishing, social engineering, network attacks), defensive practices (encryption, authentication, access control, patching), privacy fundamentals (data collection, tracking, regulatory frameworks), and security reasoning (threat modeling, risk assessment, defense in depth). Use when explaining security concepts, evaluating system security, teaching safe technology practices, or reasoning about digital privacy. Distinct from professional penetration testing -- this skill covers what every technology user and designer should understand.
3 -
aibot88 Bundle Scanning For Data Privacy IssuesThis skill enables Claude to automatically scan code and configuration files for potential data privacy vulnerabilities using the data-privacy-scanner plugin. It identifies sensitive data exposure, compliance violations, and other privacy-related risks. Use this skill when the user requests to "scan for data privacy issues", "check privacy compliance", "find PII leaks", "identify GDPR violations", or needs a "privacy audit" of their codebase. The skill is most effective when used on projects involving personal data, financial information, or health records.
3 -
aibot88 Bundle Dependency EvaluatorEvaluates whether a programming language dependency should be used by analyzing maintenance activity, security posture, community health, documentation quality, dependency footprint, production adoption, license compatibility, API stability, and funding sustainability. Use when users ask "should I use X or Y?", "are there better options for [feature]?", "what's a good library for [task]?", "how do we feel about [dependency]?", or when considering adding a new dependency, evaluating an existing dependency, or comparing/evaluating package alternatives.
3 -
aibot88 Bundle Dev Security AuditorAudit de sécurité complet d'une application ou d'un code source. À utiliser quand l'utilisateur veut vérifier la sécurité de son projet. Se déclenche avec "audit sécurité", "security audit", "vérifier la sécurité", "est-ce que mon code est sécurisé", "analyse de sécurité".
3 -
aibot88 Bundle Doncheli Audit TrailRecord and query the decision log for a project. Activate when user mentions "audit", "trail", "log decisions", "decision history", "why was this decided", "ADR", "architecture decision".
3 -
aibot88 Bundle Doncheli Data PolicyAudit and document what personal or sensitive data the project collects, processes, and stores. Activate when user mentions "privacy", "data policy", "what data", "GDPR", "personal data", "data retention", "PII".
3 -
aibot88 Bundle Ethics Safety ImpactUse when decisions could affect groups differently and need to anticipate harms/benefits, assess fairness and safety concerns, identify vulnerable populations, propose risk mitigations, define monitoring metrics, or when user mentions ethical review, impact assessment, differential harm, safety analysis, vulnerable groups, bias audit, or responsible AI/tech.
3 -
aibot88 Bundle Eval Injection TestSkill with injected eval patterns for security testing
3 -
aibot88 Bundle Fastapi VerificationVerification loop for FastAPI projects: type checking, linting, tests with coverage, security scans, and API schema validation before release or PR.
3
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include web-vulnerabilities, webhook-integration, apache-nifi-registry. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.