Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
aibot88 Bundle Spring Boot Security JWTProvides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based access control using Spring Security 6.x. Use when implementing authentication or authorization in Spring Boot applications.
3 -
aibot88 Bundle Supabase Security BasicsApply Supabase security best practices: anon vs service_role key separation, RLS enforcement, policy patterns, JWT verification, and API hardening. Use when securing a Supabase project, auditing API key usage, implementing Row Level Security, or running a production security checklist. Trigger with phrases like "supabase security", "supabase RLS", "secure supabase", "supabase API key", "supabase hardening", "row level security", "service role key".
3 -
aibot88 Bundle Typescript Anti PatternsThis skill should be used when reviewing TypeScript code for anti-patterns, when code contains unsafe practices, when identifying common TypeScript mistakes, when auditing AI-generated TypeScript code, or when enforcing production-grade TypeScript standards. Trigger on: "review TypeScript code", "TypeScript anti-patterns", "unsafe TypeScript", "type assertion smell", "any type misuse", "non-null assertion", "TypeScript code review", "AI generated TypeScript", "TypeScript best practices audit", "code smells TypeScript", "silent catch", "type widening", "generic soup", "mutable exports", "enum pitfalls", "numeric enum", "TypeScript security review", "unsafe cast".
3 -
aibot88 Bundle Validating Cors PoliciesValidate CORS policies for security issues and misconfigurations. Use when reviewing cross-origin resource sharing. Trigger with 'validate CORS', 'check CORS policy', or 'review cross-origin'.
3 -
aibot88 Bundle Vercel Policy GuardrailsImplement lint rules, CI policy checks, and automated guardrails for Vercel projects. Use when setting up code quality rules, preventing secret exposure, or enforcing deployment policies for Vercel applications. Trigger with phrases like "vercel policy", "vercel lint", "vercel guardrails", "vercel best practices check", "vercel secret scan".
3 -
aibot88 Bundle Visualforce FundamentalsDesigning and debugging Visualforce pages: standard/custom controllers, view state management, CSRF and SOQL injection security, PDF rendering, Visualforce email templates. Use when building custom UI pages or PDF outputs on the Salesforce platform. NOT for LWC development (use lwc/* skills). NOT for Visualforce email template syntax (use email-services).
3 -
aibot88 Bundle Whistleblower ComplianceAudit whistleblower systems and draft compliant reporting policies. Use when assessing or building whistleblower programs.
3 -
aibot88 Bundle Windsurf Security BasicsApply Windsurf security best practices for workspace isolation, data privacy, and secret protection. Use when securing sensitive code from AI indexing, configuring telemetry, or auditing Windsurf security posture. Trigger with phrases like "windsurf security", "windsurf secrets", "windsurf privacy", "windsurf data protection", "codeiumignore".
3 -
aibot88 Bundle Secure Engineering SkillExpert Secure Developer, Optimizer, & Cyber Analyst. Use this skill when the user wants to build a static website, assess web application vulnerabilities (OWASP Top 10), or optimize code for performance and readability. Trigger whenever terms like "build website," "static site," "OWASP," "security audit," "refactor," or "optimize" are mentioned.
3 -
aibot88 Bundle Smart Contract YAML Pattern AuditAudits smart contract source against vulnerability patterns supplied as YAML. Use when the user provides contract code and a YAML pattern list (e.g. id, name, severity, description, false_positives) and expects a structured JSON report of matches and rationale.
3 -
aibot88 Bundle Ascii Motd Profile BannerGenerate ASCII-only MOTD / SSH login banner / shell profile welcome messages (short/long variants, quiet mode guidance, security notices).
3 -
aibot88 Bundle Authentication Flow RulesOAuth 2.1 compliant authentication flows (MANDATORY Q2 2026). PKCE required for ALL clients, Implicit Flow removed, modern token security.
3 -
aibot88 Bundle Configuring Auto Scaling PoliciesThis skill configures auto-scaling policies for applications and infrastructure. It generates production-ready configurations based on user requirements, implementing best practices for scalability and security. Use this skill when the user requests help with auto-scaling setup, high availability, or dynamic resource allocation, specifically mentioning terms like "auto-scaling," "HPA," "scaling policies," or "dynamic scaling." This skill provides complete configuration code for various platforms.
3 -
aibot88 Bundle Axiom File Protection RefUse when asking about 'FileProtectionType', 'file encryption iOS', 'NSFileProtection', 'data protection', 'secure file storage', 'encrypt files at rest', 'complete protection', 'file security' - comprehensive reference for iOS file encryption and data protection APIs
3 -
aibot88 Bundle Building Stories With TddExpert for building user stories using Test-Driven Development (TDD) with NestJS and @lenne.tech/nest-server. Implements new features by creating story tests first in tests/stories/, then uses generating-nest-servers skill to develop code until all tests pass. Ensures high code quality and security compliance. Use in projects with @lenne.tech/nest-server in package.json dependencies (supports monorepos with projects/*, packages/*, apps/* structure).
3 -
aibot88 Bundle Checking Hipaa ComplianceCheck HIPAA compliance for healthcare data security requirements. Use when auditing healthcare applications. Trigger with 'check HIPAA compliance', 'validate health data security', or 'audit PHI protection'.
3 -
aibot88 Bundle Checking Owasp ComplianceCheck compliance with OWASP Top 10 security risks and best practices. Use when performing comprehensive security audits. Trigger with 'check OWASP compliance', 'audit web security', or 'validate OWASP'.
3 -
aibot88 Bundle Checking Session SecurityAnalyze session management implementations to identify security vulnerabilities in web applications. Use when you need to audit session handling, check for session fixation risks, review session timeout configurations, or validate session ID generation security. Trigger with phrases like "check session security", "audit session management", "review session handling", or "session fixation vulnerability".
3 -
aibot88 Bundle Claude Code Bash PatternsClaude Code Bash tool patterns with hooks, automation, git workflows. Use for PreToolUse hooks, command chaining, CLI orchestration, custom commands, or encountering bash permissions, command failures, security guards, hook configurations.
3 -
aibot88 Bundle Claude Native Code ReviewAdversarial code review — find what will break in production, not what looks wrong in theory. Covers correctness, security, failure modes, performance, and maintainability. Use when reviewing PRs, auditing code quality, or before merging. Triggers on: 'review this code', 'code review', 'check this PR', 'is this code good', 'review before merge', 'look over this code'.
3 -
aibot88 Bundle Context Security ResolverAuthentication, authorization, Clerk integration, RLS policies, and security patterns. Use when working with security-resolver code, files, or integration. Invoke when navigating security-resolver codebase, searching for security-resolver files, debugging security-resolver errors, or discussing security-resolver patterns. Keywords: security-resolver, {{KEYWORDS}}
3 -
aibot88 Bundle Scanning Database SecurityThis skill enables Claude to perform comprehensive database security scans using the database-security-scanner plugin. It is triggered when the user requests a security assessment of a database, including identifying vulnerabilities like weak passwords, SQL injection risks, and insecure configurations. The skill leverages OWASP guidelines to ensure thorough coverage and provides remediation suggestions. Use this skill when the user asks to "scan database security", "check database for vulnerabilities", "perform OWASP compliance check on database", or "assess database security posture". The plugin supports PostgreSQL and MySQL.
3 -
aibot88 Bundle Dev Dependency ManagementPackage and dependency management patterns across ecosystems (npm, pip, cargo, maven). Covers lockfiles, semantic versioning, dependency security scanning, update strategies, monorepo workspaces, transitive dependencies, and avoiding dependency hell.
3 -
aibot88 Bundle Documenso Security BasicsImplement security best practices for Documenso document signing integrations. Use when securing API keys, configuring webhooks securely, or implementing document security measures. Trigger with phrases like "documenso security", "secure documenso", "documenso API key security", "documenso webhook security".
3 -
aibot88 Bundle Doppler Secret ValidationValidate and test Doppler secrets. TRIGGERS - add to Doppler, store secret, validate token, test credentials.
3 -
aibot88 Bundle Dotnet Meziantou AnalyzerUse the open-source free `Meziantou.Analyzer` package for design, usage, security, performance, and style rules in .NET. Use when a repo wants broader analyzer coverage with a single NuGet package.
3 -
aibot88 Bundle Eresus Pr Security ReviewSecurity-focused pull request and diff review skill for finding newly introduced vulnerabilities, risky regressions, and missing security tests in changed code. Trigger when the user asks to: "review this PR for security", "check this diff for vulns", "do a security code review", "audit changed files", or wants findings on a patch instead of a full-repo scan. Best used alongside eresus-sast-scanner.
3 -
aibot88 Bundle Evaluation Coverage AuditUse when completed work needs evaluation coverage audited across correctness, security, performance, and quality dimensions
3 -
aibot88 Bundle Firecrawl Security BasicsApply Firecrawl security best practices for API key management and webhook verification. Use when securing API keys, implementing webhook signature validation, or auditing Firecrawl security configuration. Trigger with phrases like "firecrawl security", "firecrawl secrets", "secure firecrawl", "firecrawl API key security", "firecrawl webhook signature".
3 -
aibot88 Bundle Fireflies Security BasicsApply Fireflies.ai security best practices for API keys and webhook verification. Use when securing API keys, verifying webhook signatures, or auditing Fireflies.ai security configuration. Trigger with phrases like "fireflies security", "fireflies secrets", "secure fireflies", "fireflies webhook signature", "fireflies HMAC".
3 -
aibot88 Bundle Grammarly Security BasicsSecurity fundamentals for Grammarly API credential management. Use when setting up secure authentication and token handling for Grammarly integrations.
3 -
aibot88 Bundle Guidewire Enterprise RbacImplement Guidewire RBAC: API roles, user permissions, and security policies. Trigger: "guidewire enterprise rbac", "enterprise-rbac".
3 -
aibot88 Bundle Guidewire Security BasicsImplement Guidewire security: OAuth2 JWT, API roles, Gosu secure coding, and data protection. Trigger: "guidewire security basics", "security-basics".
3 -
aibot88 Bundle Guimkt Consent Mode AuditAudita implementação de Consent Mode v2, LGPD compliance, CMP e disparos indevidos de tags sem consentimento. Deep dive pós-implementação que complementa a seção "Consent & Privacy Architecture" do measurement-plan. Valida default/update states, CMP integration, comportamento de cada tag por estado de consent, certificação Google CMP Partner, data retention settings, e gera relatório com score, itens críticos e checklist de correção. Use quando precisar auditar consent mode, validar LGPD compliance, verificar CMP, checar se tags disparam sem consentimento, auditar privacidade, consent mode v2 audit, verificar cookie policy, auditoria de CMP, compliance de dados, LGPD audit, ou qualquer variação de "meu consent está funcionando?", "tags sem consentimento", "auditoria LGPD", "consent mode audit", "CMP review", "privacidade do site".
3 -
aibot88 Bundle Hootsuite Security BasicsApply Hootsuite security best practices for secrets and access control. Use when securing API keys, implementing least privilege access, or auditing Hootsuite security configuration. Trigger with phrases like "hootsuite security", "hootsuite secrets", "secure hootsuite", "hootsuite API key security".
3 -
aibot88 Bundle Hubspot Policy GuardrailsImplement HubSpot lint rules, secret scanning, and CI policy checks. Use when setting up code quality rules for HubSpot integrations, preventing token leaks, or configuring CI guardrails. Trigger with phrases like "hubspot policy", "hubspot lint", "hubspot guardrails", "hubspot security check", "hubspot eslint rules".
3
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include spring-boot-security-jwt, supabase-security-basics, typescript-anti-patterns. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.