Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
aibot88 Bundle Openclaw Audit WatchdogAutomated daily security audits for OpenClaw agents with DM delivery and optional email reporting. Runs deep audits, creates or updates a recurring cron job, and sends formatted reports to configured recipients.
3 -
aibot88 Bundle Persona Security BasicsSecure Persona API keys, webhook secrets, PII handling in verification data. Use when working with Persona identity verification. Trigger with phrases like "persona security-basics", "persona security-basics".
3 -
aibot88 Bundle Pop Assessment SecurityValidates PopKit security posture using concrete vulnerability patterns, automated secret scanning, and OWASP-aligned checklists
3 -
aibot88 Bundle Posthog Security BasicsSecure PostHog integration: API key management, project key vs personal key separation, secret rotation, scoped keys, and git-leak prevention. Trigger: "posthog security", "posthog secrets", "secure posthog", "posthog API key security", "posthog key rotation".
3 -
aibot88 Bundle Procore Security BasicsProcore security basics — construction management platform integration. Use when working with Procore API for project management, RFIs, or submittals. Trigger with phrases like "procore security basics", "procore-security-basics".
3 -
aibot88 Bundle Production System AuditComprehensive system audit methodology for production web applications. Use when auditing systems before launch, identifying technical debt, troubleshooting systematic issues, preparing for security reviews, or creating improvement roadmaps. Systematically audits database schema, API endpoints, external integrations, performance, security, and monitoring across all layers.
3 -
aibot88 Bundle Recht Sozial BeschwerdeAustrian social security appeals — challenging Bescheide from ÖGK/PVA/AMS/SVS, Klage to Arbeits- und Sozialgericht (ASG), pension disputes, Pflegestufe appeals, and AMS sanctions (Sperren). Kostenfreiheit in Sozialrechtssachen.
3 -
aibot88 Bundle Salesforce ArchitectureUse for org-level Salesforce architecture work — capacity planning, security/sharing review, integration patterns, multi-org strategy, tech-debt assessment.
3 -
aibot88 Bundle Secret Handling RuntimeDecision-aid skill for runtime secret hygiene — fd passing, scratch surface verification, error-path safety, identifier hygiene, and avoiding the SECRETS_ENV aggregation anti-pattern
3 -
aibot88 Bundle Secure Coding PracticesSecure coding practices and defensive programming patterns for building security-first applications. Use when implementing authentication, handling user input, managing sensitive data, or conducting secure code reviews.
3 -
aibot88 Bundle Generating Security Audit ReportsThis skill enables Claude to generate comprehensive security audit reports. It is designed to provide insights into an application or system's security posture, compliance status, and recommended remediation steps. Use this skill when the user requests a "security audit report", wants to "audit security", or needs a "vulnerability assessment report". The skill analyzes security data and produces a detailed report in various formats. It is best used to identify vulnerabilities, track compliance, and create remediation roadmaps. The skill can be activated via the command `/audit-report` or its shortcut `/auditreport`.
3 -
aibot88 Bundle Security Audit StandardSecurity audit methodology and checklist for codebases. Use when performing security reviews, auditing a project for vulnerabilities, or hardening an application before deployment. Covers secret scanning, input validation, authentication/authorization, cryptographic practices, dependency auditing, CSP configuration, rate limiting, OWASP Top 10 checks, and audit report format. Derived from production audit work.
3 -
aibot88 Bundle Serpapi Security BasicsSecure SerpApi API keys and prevent credit abuse. Use when storing API keys, implementing backend proxies, or auditing SerpApi access patterns. Trigger: "serpapi security", "serpapi API key security", "secure serpapi".
3 -
aibot88 Bundle Shopify Security BasicsApply Shopify security best practices for API credentials, webhook HMAC validation, and access scope management. Use when securing API keys, validating webhook signatures, or auditing Shopify security configuration. Trigger with phrases like "shopify security", "shopify secrets", "secure shopify", "shopify HMAC", "shopify webhook verify".
3 -
aibot88 Bundle Sis Memory OrchestratorSubstrate-aware memory orchestration for Starlight Intelligence System. Coordinates a 7-subagent team that proactively manages memory writes, retrieval, knowledge-graph maintenance, privacy redaction, decay, audit, and substrate benchmarking across pluggable backends (mempalace, Letta, Mem0, AgentDB, Qdrant, screenpipe, filesystem). Use when the user asks about SIS memory architecture, wants to add or swap a memory substrate, runs `/sis memory`, asks "where should this capture go", reports memory leaks or staleness, requests benchmarks across substrates, or sets up a new sovereign user adopting SIS. Honors privacy-by-default (everything local; embeddings local; PII redaction before any external call).
3 -
aibot88 Bundle Skill Security AnalyzerComprehensive security risk analysis for Claude skills. Use when asked to analyze security risks, review security stance, audit skills for vulnerabilities, check security before deployment, or evaluate safety of skill files. Triggers include "analyze security," "security risks," "security audit," "security review," "is this skill safe," or "check for vulnerabilities."
3 -
aibot88 Bundle Smart Contract Analysis SkillEthereum and blockchain smart contract security analysis
3 -
aibot88 Bundle Stripe Webhook SecurityThis skill should be used when implementing security for Stripe webhook endpoints, handling "webhook rate limiting", "Stripe secret management", "webhook abuse prevention", "log redaction for billing", "STRIPE_WEBHOOK_SECRET storage", "webhook endpoint protection", "Stripe API key security", "billing security review", "sensitive data in logs", "production webhook hardening", "DDoS protection for webhooks", or when the user asks about securing Stripe webhook endpoints and billing infrastructure in Fastify.
3 -
aibot88 Bundle Threat Surface AnalysisDiscover a codebase's threat surface through systematic investigation — map ecosystem groups, dependency graphs, service connections, authentication mechanisms, and trust boundaries. Use when performing threat modeling, security review, or architectural analysis of any multi-ecosystem repository.
3 -
aibot88 Bundle Webflow Enterprise RbacConfigure Webflow enterprise access control — OAuth 2.0 app authorization, scope-based RBAC, per-site token isolation, workspace member management, and audit logging for compliance. Trigger with phrases like "webflow RBAC", "webflow enterprise", "webflow roles", "webflow permissions", "webflow OAuth scopes", "webflow access control", "webflow workspace members".
3 -
aibot88 Bundle Webflow Security BasicsApply Webflow API security best practices — token management, scope least privilege, OAuth 2.0 secret rotation, webhook signature verification, and audit logging. Use when securing API tokens, implementing least privilege access, or auditing Webflow security configuration. Trigger with phrases like "webflow security", "webflow secrets", "secure webflow", "webflow API key security", "webflow token rotation".
3 -
aibot88 Bundle Well Architected ReviewUse when conducting a formal Salesforce Well-Architected Framework (WAF) review of an org or solution design. Covers all three pillars: Trusted (security, compliance), Easy (user experience, adoption), and Adaptable (scalability, maintainability). Produces a structured assessment with findings and recommendations. Triggers: well-architected review, WAF assessment, org architecture review, architecture health check, trusted easy adaptable. NOT for deep-dives into individual pillars (use security-architecture-review, limits-and-scalability-planning, or technical-debt-assessment) or for implementation guidance.
3 -
aibot88 Bundle Workflow Codebase AuditUse for cold-start, time-boxed, multi-axis audits of unfamiliar codebases — take-home assessments, post-acquisition or due-diligence reviews, inherited-service onboarding, pre-refactor tech-debt sweeps. Dispatches the auditor subagent for the broad sweep, optionally fans out to security-auditor / debugger on top findings (only when --depth=deep), and renders ranked findings with reasoning chains and counter-evidence fields.
3 -
aibot88 Bundle Workflow Security AuditComprehensive security assessment and remediation. Use for security reviews, compliance checks, vulnerability assessments.
3 -
aibot88 Bundle Nuclei Scan살아있는 호스트에 nuclei로 알려진 취약점 패턴을 스캔한다. exposure, misconfig, token, secret 태그 위주. BBP 가용성 침해 방지를 위해 rate limit 필수.
3 -
aibot88 Bundle 701 Technologies OpenapiUse when you need framework-agnostic OpenAPI 3.x guidance — spec structure, metadata and versioning, paths and operations, reusable schemas, security schemes, examples, documentation quality, contract validation (e.g. Spectral), breaking-change awareness, and handoffs to codegen — without choosing Spring Boot, Quarkus, or Micronaut. This should trigger for requests such as Review an OpenAPI; Improve an OpenAPI; Improve API contract; Improve API schema design. Part of cursor-rules-java project
3 -
aibot88 Bundle Agentprivacy DragonwakerQuantum threat response persona. Activates when discussing post-quantum security, the 1200-qubit threshold, secp256k1 vulnerability, dragon flight conditions, or the transition from stored secrets to behavioral manifold proofs.
3 -
aibot88 Bundle Apex Encoding And CryptoUse when Apex must sign, verify, encrypt, hash, encode, or decode payloads — including HMAC for webhook signatures, RSA/ECDSA signing for JWT bearer flows, AES for stored secrets, base64/hex/URL encoding, and digest comparisons for integration integrity. Triggers: 'Crypto.sign', 'Crypto.generateMac', 'EncodingUtil.base64Encode', 'JWT signing in Apex', 'verify webhook signature'. NOT for setting up Named Credentials or OAuth flows end-to-end — use apex-named-credentials-patterns; NOT for SOQL injection defense — use soql-security.
3 -
aibot88 Bundle Appfolio Security BasicsSecure AppFolio API credentials and tenant data. Trigger: "appfolio security".
3 -
aibot88 Bundle Arc42 Write S08 ConceptsSchreibt arc42 Sektion 8 (Querschnittliche Konzepte): Übergreifende Lösungsansätze, Muster, Regeln, Domänenmodelle, technische Konzepte. Use when: Sektion 8 schreiben, Konzepte, Crosscutting Concepts, Querschnitt, Muster, Domänenmodell, Logging, Security, Fehlerbehandlung dokumentieren.
3 -
aibot88 Bundle Architecture Doc AuditorSystematic completeness audit of Architecture Documentation using 188-item viewpoint-based checklist, severity-classified gap detection, technical debt indicators, and architecture anti-pattern scanning. Supports TOGAF, C4, arc42, and IEEE 42010 frameworks. PROACTIVELY activate for: (1) Architecture review gates, (2) ADR validation before implementation, (3) C4 diagram completeness check, (4) Technical debt assessment, (5) Pre-implementation validation, (6) Governance compliance audit, (7) Design doc handoff review. Triggers: "audit architecture", "review ADR", "check architecture doc", "validate design doc", "architecture review", "audit C4 diagrams", "check system context", "technical debt assessment", "architecture health check", "governance review", "architecture completeness"
3 -
aibot88 Bundle Auditing Wallet SecurityAudit wallet security by analyzing token approvals, permissions, and transaction patterns. Use when checking wallet security, reviewing approvals, or assessing risk exposure. Trigger with phrases like "audit wallet", "check approvals", "security scan", or "revoke tokens".
3 -
aibot88 Bundle Bamboohr Security BasicsApply BambooHR security best practices for API keys, webhook verification, and PII data handling compliance. Use when securing API keys, implementing webhook signature validation, or handling sensitive employee data from BambooHR. Trigger with phrases like "bamboohr security", "bamboohr secrets", "secure bamboohr", "bamboohr PII", "bamboohr data protection".
3 -
aibot88 Bundle Cc Conversation AnalyzerComprehensive Claude Code conversation analysis skill for deep-diving into CC session logs. Use when analyzing exported Claude Code conversations to understand: project patterns, error rates, command failures, security risks, session duration, tool usage, and workflow efficiency. Triggers: "analyze conversation", "CC analysis", "conversation analysis", "session review", "Claude Code logs", "analyze my sessions", "review CC usage", "conversation insights", "what went wrong in my session", "session forensics", "CC forensics"
3 -
aibot88 Bundle Cometchat IOS ProductionProduction-ready CometChat iOS setup — server-side auth tokens, security best practices, and deployment checklist.
3 -
aibot88 Bundle Dag Permission ValidatorValidates permission inheritance between parent and child agents. Ensures child permissions are equal to or more restrictive than parent. Activate on 'validate permissions', 'permission check', 'inheritance validation', 'permission matrix', 'security validation'. NOT for runtime enforcement (use dag-scope-enforcer) or isolation management (use dag-isolation-manager).
3
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include openclaw-audit-watchdog, persona-security-basics, pop-assessment-security. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.