Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
aibot88 Bundle Database Schema AnalyzerAnalyze PostgreSQL/Supabase database schemas for design quality, security, performance, and best practices. Use when reviewing schemas, migrations, RLS policies, or when user mentions database design, indexing, or security issues.
3 -
aibot88 Bundle Deepgram Security BasicsApply Deepgram security best practices for API key management and data protection. Use when securing Deepgram integrations, implementing key rotation, or auditing security configurations. Trigger: "deepgram security", "deepgram API key security", "secure deepgram", "deepgram key rotation", "deepgram data protection", "deepgram PII redaction".
3 -
aibot88 Bundle Detect Hardcoded SecretsDetect hardcoded secrets, API keys, passwords, and credentials in source code. Security audit for leaked secrets. Works across all languages. Use when user asks about security issues or secret detection.
3 -
aibot88 Bundle Django Security AdvancedAdvanced Django security — file upload validation (extension/size/storage), DRF API security (rate limiting throttles, JWT), Content Security Policy middleware, django-environ secrets management, security event logging, and production deployment checklist.
3 -
aibot88 Bundle Doubt Driven DevelopmentSubject every non-trivial decision to a fresh-context adversarial review before it stands. Use when correctness matters more than speed, when working in unfamiliar code, when stakes are high (production, security-sensitive logic, irreversible operations), or any time a confident output would be cheaper to verify now than to debug later. Don't use for mechanical operations (renames, formatting), one-line changes with obvious correctness, or when the user has explicitly asked for speed over verification.
3 -
aibot88 Bundle Enterprise Code AnalyzerThree-tier enterprise code analysis system. Tier 1 analyzes individual repositories (structure, patterns, dependencies, memory). Tier 2 maps cross-repository relationships (API contracts, shared libraries, service coupling). Tier 3 provides enterprise governance (technology portfolio, technical debt, security audit, strategic recommendations). Generates local .memory folders, .cursorrules files, and governance reports.
3 -
aibot88 Bundle Eresus Codeql HeuristicsLanguage-specific vulnerability hotspot reference for manual code audit. Trigger when the user asks to: "what sinks should I look for in Java?", "Python security hotspots", "dangerous functions in Go", "JavaScript injection patterns", or when starting a manual audit of a specific language and needing a sink/source checklist.
3 -
aibot88 Bundle Evernote Security BasicsImplement security best practices for Evernote integrations. Use when securing API credentials, implementing OAuth securely, or hardening Evernote integrations. Trigger with phrases like "evernote security", "secure evernote", "evernote credentials", "evernote oauth security".
3 -
aibot88 Bundle Expense Bot ArchitectureProduction-ready LINE bot with AI-powered expense tracking using TypeScript, Prisma, and Google Gemini. Comprehensive guide covering backend development, database design, AI integration, security, testing, and deployment.
3 -
aibot88 Bundle Flexport Security BasicsApply Flexport API security best practices including webhook signature verification, API key rotation, and least-privilege access patterns. Trigger: "flexport security", "flexport webhook signature", "secure flexport API key".
3 -
aibot88 Bundle Gemini Config ManagementExpert guide for configuring Google Gemini CLI. Covers global vs project settings.json, Trusted Folders, Policy Engine, and environment variables. Use when configuring Gemini settings, managing trusted folders, setting up security policies, or troubleshooting configuration precedence. Delegates to gemini-cli-docs for official references.
3 -
aibot88 Bundle Gemini Research SubagentDelegates large-context code analysis to Gemini CLI. Use when analyzing codebases, tracing bugs across files, reviewing architecture, or performing security audits. Gemini reads, Claude implements.
3 -
aibot88 Bundle Gesellschafts ComplianceGesellschafts-Compliance-Tracker – Initialisierung, Fälligkeitsbericht, Status-Update, Gesundheits-Audit, Export. Pflegt eine compliance-tracker.yaml aus der Gesellschaftstabelle, berechnet Einreichungsfristen nach Rechtsträger und Rechtsordnung und zeigt auf, was in den nächsten 30/60/90 Tagen fällig ist. Trigger: „Gesellschafts-Compliance", „Einreichungsfristen", „Bilanzpublizität", „Transparenzregister", „Jahresabschluss einreichen", „was ist fällig".
3 -
aibot88 Bundle Ideogram Security BasicsApply Ideogram security best practices for API key management and access control. Use when securing API keys, implementing key rotation, or auditing Ideogram security configuration. Trigger with phrases like "ideogram security", "ideogram secrets", "secure ideogram", "ideogram API key security", "ideogram key rotation".
3 -
aibot88 Bundle Infrastructure ReportingGenerate comprehensive network infrastructure reports including health status, performance analysis, security audits, and capacity planning recommendations.
3 -
aibot88 Bundle Insforge Schema PatternsDatabase schema patterns for InsForge including social graphs, e-commerce, content publishing, and multi-tenancy with RLS policies. Use when designing data models with relationships, foreign keys, or Row Level Security.
3 -
aibot88 Bundle Intercom Security BasicsApply Intercom security best practices for tokens, webhook verification, and scopes. Use when securing access tokens, implementing webhook signature validation, or configuring least-privilege OAuth scopes. Trigger with phrases like "intercom security", "intercom secrets", "secure intercom", "intercom webhook signature", "intercom token rotation".
3 -
aibot88 Bundle Juicebox Security BasicsApply Juicebox security best practices. Trigger: "juicebox security", "juicebox api key security".
3 -
aibot88 Bundle Lease Compliance AuditorExpert in lease compliance monitoring and obligation tracking. Use when auditing insurance requirements, verifying environmental compliance, checking use clause adherence, or monitoring covenant compliance. Key terms include insurance audit, CGL requirements, environmental compliance, use clause violations, covenant breach, notice requirements, cure periods
3 -
aibot88 Bundle Legal Compliance AuditorAudit existing legal documents for compliance gaps, outdated clauses, missing disclosures, and cross-document consistency.
3 -
aibot88 Bundle Lokalise Security BasicsApply Lokalise security best practices for API tokens and access control. Use when securing API tokens, implementing least privilege access, or auditing Lokalise security configuration. Trigger with phrases like "lokalise security", "lokalise secrets", "secure lokalise", "lokalise API token security".
3 -
aibot88 Bundle Mfa Enforcement PatternsDesign MFA enforcement: auto-enablement, Salesforce Authenticator rollout, exceptions, service accounts, API-only users, SSO interop, and audit. Trigger keywords: MFA, multi-factor, two-factor, Salesforce Authenticator, MFA exception, MFA SSO, api-only MFA. Does NOT cover: end-user password policies, device-trust posture, or non-Salesforce IdP configuration.
3 -
aibot88 Bundle Mfa Enforcement StrategyPlan and operate Salesforce org-wide multi-factor authentication (MFA) enforcement: verification methods, phased rollout, SSO and API-only considerations, exemptions, and operational readiness. NOT for designing Login Flow post-authentication logic, IP allowlists, or conditional step-up policies—use ip-range-and-login-flow-strategy, network-security-and-trusted-ips, or transaction-security-policies instead.
3 -
aibot88 Bundle Observability ComplianceUse when performing a deep observability audit or remediating missing structured logging, metrics, traces, or alerting rules
3 -
aibot88 Bundle Obsidian Security BasicsImplement secure Obsidian plugin development practices. Covers credential storage, input validation, XSS prevention, network security, URI handler safety, and Electron security. Use when handling user data, storing API keys, making network requests, or preparing for community plugin submission. Trigger with phrases like "obsidian security", "secure obsidian plugin", "obsidian data protection", "obsidian privacy", "obsidian api key storage".
3 -
aibot88 Bundle Offensive Business LogicBusiness logic vulnerability testing for web/mobile/API engagements. Covers workflow bypass, state machine violations, multi-step process abuse, price/quantity/discount manipulation, currency confusion, coupon stacking, refund/chargeback abuse, race conditions on logic boundaries, parameter tampering for hidden flows, role/tenant boundary violations, time-of-check vs use, anti-automation defeat, fraud-detection evasion, and subscription/quota abuse. Use when scoping an application after surface-level OWASP Top 10 has been covered, or when the asset is a transactional/marketplace/fintech/e-commerce/SaaS app where logic flaws produce direct financial impact.
3 -
aibot88 Bundle Openclaw Ghsa MaintainerMaintainer workflow for OpenClaw GitHub Security Advisories (GHSA). Use when Codex needs to inspect, patch, validate, or publish a repo advisory, verify private-fork state, prepare advisory Markdown or JSON payloads safely, handle GHSA API-specific publish constraints, or confirm advisory publish success.
3 -
aibot88 Bundle Palantir Security BasicsApply Palantir Foundry security best practices for credentials, scopes, and access control. Use when securing API tokens, implementing least privilege access, or auditing Foundry security configuration. Trigger with phrases like "palantir security", "foundry secrets", "secure palantir", "palantir API key security", "foundry scopes".
3 -
aibot88 Bundle Physical Threat ModelingThreat library for physical-access threats that STRIDE and OWASP Top 10 don't cover — evil-maid, DMA, hostile peripheral, travel-host, coercion, cold-boot, supply-chain implant, side-channel
3 -
aibot88 Bundle Project Analysis SymfonyUse for deep Symfony project analysis: kernel/bootstrap, container wiring, routing/request flow, Doctrine, security, Messenger, and Symfony-specific failure patterns.
3 -
aibot88 Bundle Replit Policy GuardrailsEnforce security and resource policies for Replit-hosted apps: secrets exposure prevention, resource limits, deployment visibility, and database access controls. Use when hardening a Replit app for production, auditing security posture, or setting up guardrails for team development. Trigger with phrases like "replit policy", "replit guardrails", "replit security audit", "replit hardening", "replit best practices check".
3 -
aibot88 Bundle Risk Mitigation PlanningDevelop comprehensive risk management plans for collections and cultural venues including disaster preparedness, security protocols, and insurance coordination
3 -
aibot88 Bundle Security Essentials PackCurated bundle of essential security skills for building secure applications. Includes threat modeling, hardening guides, audit checklists, compliance frameworks, and contract analysis. Use when establishing security practices for a project.
3 -
aibot88 Bundle Security Pentest PlannerPlans security penetration tests for web applications. Analyzes codebase, API routes, auth implementation, and infrastructure config to generate comprehensive pentest plans. For authorized testing only.
3 -
aibot88 Bundle Security Review AdvancedSecurity anti-patterns — localStorage token storage (XSS risk), trusting client-side authorization checks, reflecting full error details to clients, blacklist vs whitelist input validation, using npm install instead of npm ci in CI pipelines.
3 -
aibot88 Bundle Security Threat ModelingModélisation des menaces pour applications et systèmes — identification des surfaces d'attaque, classification STRIDE, arbres d'attaque et stratégies de mitigation. À utiliser quand l'utilisateur veut sécuriser une architecture, identifier des vulnérabilités potentielles ou réaliser une analyse de risques. Se déclenche aussi avec "threat modeling", "modélisation des menaces", "surface d'attaque", "STRIDE", "risques de sécurité", "analyse de menaces", "DREAD".
3
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include Database Schema Analyzer, detect-hardcoded-secrets, django-security-advanced. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.