Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
aibot88 Bundle Github Code ReviewerReview GitHub PRs with surgical precision. Flag only high-severity issues (bugs, security, performance, breaking changes) via succinct inline comments on specific lines. Skip style, nits, and minor improvements. High signal, low noise.
3 -
aibot88 Bundle Groq Security BasicsApply Groq security best practices for API key management and data protection. Use when securing API keys, implementing least privilege access, or auditing Groq security configuration. Trigger with phrases like "groq security", "groq secrets", "secure groq", "groq API key security".
3 -
aibot88 Bundle Liveview Code ReviewReviews Phoenix LiveView code for lifecycle patterns, assigns/streams usage, components, and security. Use when reviewing LiveView modules, .heex templates, or LiveComponents.
3 -
aibot88 Bundle Logging API RequestsMonitor and log API requests with correlation IDs, performance metrics, and security audit trails. Use when auditing API requests and responses. Trigger with phrases like "log API requests", "add API logging", or "track API calls".
3 -
aibot88 Bundle Maintain Project APIMaintain canonical API.md files through deterministic audit and bounded apply modes. Use when a project API reference needs auditing, normalization, or bounded fixes for API surface, authentication, request and response schemas, errors, versioning, compatibility, local verification, or support guidance. This is the default baseline API.md workflow for most repos unless a narrower plugin owns that repo shape.
3 -
aibot88 Bundle Medical Chart ReviewExpert-level review and analysis of medical charts, EMRs, and EHRs by clinicians, coders, and CDI/quality auditors. Use when asked to "review a chart", "chart review", "chart abstraction", "clinical documentation review", "audit medical records", "extract from EHR", "summarize patient history", "check documentation", "validate ICD-10/HCC/CPT coding", "DRG validation", "perform CDI review", "risk adjustment audit", "HEDIS gap analysis", "medication reconciliation", "identify red flags in chart", "abstract clinical data", or any task involving SOAP notes, progress notes, discharge summaries, problem lists, H&P, consult notes, lab/imaging interpretation, or Epic/Cerner/Athena/Meditech data. DO NOT USE FOR providing direct patient care, making diagnoses for live patients, prescribing, or anything requiring a licensed clinician's judgment of record. DO NOT USE FOR building HEDIS or HCC NLP extraction pipelines (use the hedis-nlp or hcc-nlp skills in the same repo). DO NOT USE FOR HIPAA compliance program work like
3 -
aibot88 Bundle Medical Coding AuditReview clinical documentation and assigned codes for accuracy, compliance, and optimization, identifying documentation improvement opportunities and coding errors
3 -
aibot88 Bundle Miro Multi Env SetupConfigure Miro REST API v2 across development, staging, and production with separate OAuth apps, isolated test boards, and secret management. Trigger with phrases like "miro environments", "miro staging", "miro dev prod", "miro environment setup", "miro multi env".
3 -
aibot88 Bundle Miro Security BasicsApply Miro REST API v2 security best practices — OAuth scope minimization, token storage, webhook signature validation, and secret rotation. Trigger with phrases like "miro security", "miro secrets", "secure miro", "miro token security", "miro webhook signature".
3 -
aibot88 Bundle Navan Prod ChecklistUse when validating production readiness for a Navan API integration — credential rotation, alerting, rate limits, SSO, SCIM, and compliance audit trails. Trigger with "navan prod checklist" or "navan production readiness".
3 -
aibot88 Bundle OAUTH Flow ArchitectImplements OAuth 2.0 and OpenID Connect authentication flows with proper security, token management, and common provider integrations.
3 -
aibot88 Bundle OAUTH ImplementationGuidelines for implementing OAuth 2.0 and OAuth 2.1 authentication flows with security best practices and PKCE
3 -
aibot88 Bundle Owasp Security AuditProvides comprehensive security standards and checklists based on OWASP Top 10:2025. Includes language-specific secure coding patterns for 20+ languages, guidance on Agentic AI security, and ASVS 5.0 requirements to ensure robust defense-in-depth across the development lifecycle.
3 -
aibot88 Bundle Parallel Code ReviewParallel 3-reviewer code review: Security, Business-Logic, Architecture.
3 -
aibot88 Bundle Postgres Rls PatternUse when writing or reviewing Postgres queries in a multi-tenant SaaS where every table row must be scoped to a single organization. Enforces the FORCE ROW LEVEL SECURITY + USING + WITH CHECK triple on every tenant-bound table, and wraps application queries in an `orgQuery(orgId)` helper that sets `app.current_org_id` before each statement. Do NOT use for cross-org system queries such as billing cron jobs or admin panels (those bypass RLS intentionally via the service role); use a service-role query wrapper instead.
3 -
aibot88 Bundle Projekt ArbeitsweiseStrukturierte Projekt- und Ordnerarbeit fuer immobilienrechtliche Rechtsabteilungen statt freihaendigem Prompting. Pro Mandat oder Objekt entsteht ein Projekt-Ordner mit fixierten Vorgaben — Playbook Mustervertraege Klauselkatalog AVV-Anforderungen Zitierregeln. Skill prueft eingehende Dokumente automatisch gegen die Projekt-Vorgaben einschliesslich AVV-Pruefung nach Art. 28 DSGVO und interner Compliance-Vorgaben. Erzeugt Projekt-Skelett mit Unterordnern Vertraege Korrespondenz Schriftsaetze Recherche Mandantenkontakt und Ablage. Dokumentiert pro Projekt welche Skills mit welchen Eingaben genutzt wurden — fuer Nachvollziehbarkeit und Audit. Unterstuetzt Agenten-Workflows die auf Datei-Eingang reagieren.
3 -
aibot88 Bundle Ramp Security BasicsRamp security basics — corporate card and expense management API integration. Use when working with Ramp for card management, expenses, or accounting sync. Trigger with phrases like "ramp security basics", "ramp-security-basics", "corporate card API".
3 -
aibot88 Bundle Release OrchestratorUse when running pre-release validation, generating changelogs, bumping semantic versions, scoring deployment readiness, or orchestrating end-to-end release pipelines. Provides pre-flight checks, secret scanning, conventional commit parsing, and GO/CONDITIONAL/NO-GO gating.
3 -
aibot88 Bundle Replit Data HandlingImplement secure data handling on Replit: PostgreSQL, KV Database, Object Storage, and data security patterns. Use when handling sensitive data, connecting databases, implementing data access patterns, or ensuring secure data flow in Replit-hosted applications. Trigger with phrases like "replit data", "replit database", "replit PostgreSQL", "replit storage", "replit data security", "replit GDPR".
3 -
aibot88 Bundle Repo Security ReviewSecurity audit for GitHub repositories before installation. Use when user wants to check if a repo/app is safe to install, review install scripts for malicious code, verify an open source project isn't collecting data, or audit dependencies for suspicious packages. Triggers on phrases like "is this safe to install", "check this repo", "review this script", "audit this code", "is this sketchy".
3 -
aibot88 Bundle Researchers SecurityResearches malware analysis, CVEs, attribution reports, and hacker community sources. Use when the album subject involves cybersecurity incidents or threat actors.
3 -
aibot88 Bundle Sandbox ConfiguratorConfigure Claude Code sandbox security with file system and network isolation boundaries
3 -
aibot88 Bundle Scanning For SecretsDetect exposed secrets, API keys, and credentials in code. Use when auditing for secret leaks. Trigger with 'scan for secrets', 'find exposed keys', or 'check credentials'.
3 -
aibot88 Bundle Sdd Uc System DesignProduit les documents de conception technique SDD (ARCHITECTURE.md, DEPLOYMENT.md, SECURITY.md, COMPLIANCE_MATRIX.md) à partir d'un SPEC-racine-*.md (+ extensions). En CLI écrit dans docs/, sur claude.ai livre des artefacts Markdown. S'active pour concevoir l'architecture technique d'un projet SDD.
3 -
aibot88 Bundle Security EngineeringSecurity architecture and implementation patterns. Use when designing security controls, implementing authentication/authorization, conducting threat modeling, or ensuring compliance with security frameworks.
3 -
aibot88 Bundle Security Review Web3Security patterns for Web3 and blockchain applications — Solana wallet signature verification, transaction validation, smart contract interaction security, and checklist for DeFi/NFT features.
3 -
aibot88 Bundle Sentry Data HandlingConfigure GDPR-compliant data handling, PII scrubbing, and data retention policies in Sentry. Use when implementing beforeSend filters, server-side data scrubbing rules, IP anonymization, data subject deletion requests, or SOC 2 audit controls. Trigger with phrases like "sentry pii scrubbing", "sentry gdpr", "sentry data privacy", "scrub sensitive data sentry", "sentry data retention", "sentry compliance".
3 -
aibot88 Bundle V3 Security OverhaulComplete security architecture overhaul for claude-flow v3. Addresses critical CVEs (CVE-1, CVE-2, CVE-3) and implements secure-by-default patterns. Use for security-first v3 implementation.
3 -
aibot88 Bundle V8 Security TriagingGuides the initial analysis and impact assessment of a V8 security report, strictly excluding implementation or fixing.
3 -
aibot88 Bundle Validate IntegrationAudit an existing Sim integration against the service API docs and repository conventions, then report and fix issues across tools, blocks, outputs, OAuth scopes, triggers, and registry entries. Use when validating or repairing a service integration under `apps/sim/tools`, `apps/sim/blocks`, or `apps/sim/triggers`.
3 -
aibot88 Bundle Test FuzzFeed random/invalid inputs to find unexpected crashes. Use when testing input handling, security, or finding edge case bugs.
3 -
aibot88 Bundle Web3 Smart ContractsUse this skill when writing, reviewing, auditing, or deploying Solidity smart contracts. Triggers on Solidity development, smart contract security auditing, DeFi protocol patterns, gas optimization, ERC token standards, reentrancy prevention, flash loan attack mitigation, Foundry/Hardhat testing, and blockchain deployment. Covers Solidity, OpenZeppelin, EVM internals, and common vulnerability patterns.
3 -
aibot88 Bundle Wish Ssh Code ReviewReviews Wish SSH server code for proper middleware, session handling, and security patterns. Use when reviewing SSH server code using charmbracelet/wish.
3 -
aibot88 Bundle Adobe Multi Env SetupConfigure Adobe OAuth credentials and API access across development, staging, and production environments with separate Developer Console projects, secret managers, and environment-specific scoping. Trigger with phrases like "adobe environments", "adobe staging", "adobe dev prod", "adobe environment setup", "adobe config by env".
3 -
aibot88 Bundle Adobe Security BasicsApply Adobe security best practices for OAuth credentials, secret rotation, I/O Events webhook signature verification, and least-privilege scoping. Use when securing API credentials, implementing webhook validation, or auditing Adobe security configuration. Trigger with phrases like "adobe security", "adobe secrets", "secure adobe", "adobe credential rotation", "adobe webhook signature".
3 -
aibot88 Bundle AI Sdk Best PracticesProduction best practices for building AI agents with Vercel AI SDK v5. Covers security, performance, error handling, testing, deployment patterns, and real-world implementation guidelines.
3
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include ai-sdk-best-practices, github-code-reviewer, groq-security-basics. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.