Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
aibot88 Bundle Managing Container RegistriesThis skill enables Claude to manage container registries, including ECR, GCR, and Harbor. It should be used when the user needs to create, configure, or manage container image registries. It helps generate production-ready configurations, implement best practices, and ensure a security-first approach. Use this skill when the user mentions terms like "container registry," "ECR," "GCR," "Harbor," "image repository," or requests assistance with managing container images. It's also helpful for generating configuration code for DevOps pipelines related to container registries.
3 -
aibot88 Bundle Cross Layer Contract AuditAudit client, API, database, and docs for contract mismatches. Use for schema drift, auth/session/payment changes, migrations, or integration regressions.
3 -
aibot88 Bundle Customerio Security BasicsApply Customer.io security best practices. Use when implementing secure credential storage, PII handling, webhook signature verification, or GDPR/CCPA compliance. Trigger: "customer.io security", "customer.io pii", "secure customer.io", "customer.io gdpr", "customer.io webhook verify".
3 -
aibot88 Bundle Databricks Security BasicsApply Databricks security best practices for secrets and access control. Use when securing API tokens, implementing least privilege access, or auditing Databricks security configuration. Trigger with phrases like "databricks security", "databricks secrets", "secure databricks", "databricks token security", "databricks scopes".
3 -
aibot88 Bundle Deduplicate Security IssueMerge two <tracker> tracking issues that describe the same root-cause vulnerability (typically discovered independently by two reporters, arriving via different channels), preserving every reporter's credit, every mailing-list thread reference, and every independent attack-vector description. Updates the kept issue's body in place, closes the duplicate with the `duplicate` label, and regenerates the CVE JSON attachment so both finders land in `credits[]`.
3 -
aibot88 Bundle Dependency Audit AssistantReviews package dependencies for security vulnerabilities, outdated versions, and license compliance. Use when user asks about dependencies, security audits, or before releases.
3 -
aibot88 Bundle Dev Smart Contract AuditorAudit de sécurité de smart contracts Solidity et blockchain. Se déclenche avec "smart contract", "Solidity", "audit blockchain", "vulnérabilité smart contract", "reentrancy", "ERC-20", "ERC-721", "Web3 security".
3 -
aibot88 Bundle Dokploy Security HardeningSecurity best practices for Dokploy templates: secrets management, network isolation, least privilege, image security, and hardening recommendations.
3 -
aibot88 Bundle Elevenlabs Security BasicsApply ElevenLabs security best practices for API keys, webhook HMAC validation, and voice data protection. Use when securing API keys, validating webhook signatures, or auditing ElevenLabs security configuration. Trigger: "elevenlabs security", "elevenlabs secrets", "secure elevenlabs", "elevenlabs API key security", "elevenlabs webhook signature", "elevenlabs HMAC".
3 -
aibot88 Bundle Etsy AI Disclosure AuditorScans every listing in an Etsy shop for missing AI Disclosure tags required by Etsy's 2025 generative-AI policy. Use when the user wants to audit AI compliance, check AI Disclosure tags, prepare a shop for the AI policy enforcement, or avoid shop suspension. Categorizes listings by risk level (clear AI / partial AI / human-made), tags accordingly with operator approval, flags ambiguous cases for manual review.
3 -
aibot88 Bundle File Upload Virus ScanningUse when designing malware and content scanning for files uploaded to Salesforce (Files, Attachments, ContentVersion) — external scanning service callouts, quarantine patterns, and user-facing messaging. Triggers: 'virus scan salesforce upload', 'malware scan content version', 'quarantine uploaded file', 'clamav salesforce', 'file upload security'. NOT for field-level data validation.
3 -
aibot88 Bundle Flow Compliance ValidationOrchestrate compliance validation workflow with requirements mapping, audit evidence collection, gap analysis, remediation tracking, and attestation
3 -
aibot88 Bundle Flow Security Review CycleOrchestrate continuous security validation, threat modeling, vulnerability management, and security gate enforcement across SDLC phases
3 -
aibot88 Bundle Grad Disruptive InnovationApply Christensen's Disruptive Innovation theory to assess low-end and new-market threats to incumbents. Use this skill when the user needs to evaluate whether a new entrant poses a disruptive threat, analyze why incumbents fail against inferior-but-cheaper alternatives, or design a disruption strategy targeting overserved customers.
3 -
aibot88 Bundle Hipaa Compliance AutomatorHIPAA security and privacy compliance automation for ePHI protection, safeguards assessment, and audit preparation
3 -
aibot88 Bundle Hipaa Compliance ValidatorHIPAA compliance validation skill for genomic data handling and audit
3 -
aibot88 Bundle Idor Vulnerability TestingThis skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references," or "bypass authorization to access other users' data." It provides comprehensive guidance for detecting, exploiting, and remediating IDOR vulnerabilities in web applications.
3 -
aibot88 Bundle Justfile Security PatternsLevel 2 patterns - vulns, lic, sbom, doctor (security, compliance, environment health)
3 -
aibot88 Bundle Performing Security AuditsAnalyze code, infrastructure, and configurations by conducting comprehensive security audits. It leverages tools within the security-pro-pack plugin, including vulnerability scanning, compliance checking, and cryptography review. Use when assessing security or running audits. Trigger with phrases like 'security scan', 'audit', or 'vulnerability'.
3 -
aibot88 Bundle Perplexity Security BasicsApply Perplexity security best practices for API key management and query safety. Use when securing API keys, implementing query sanitization, or auditing Perplexity security configuration. Trigger with phrases like "perplexity security", "perplexity secrets", "secure perplexity", "perplexity API key security", "perplexity PII".
3 -
aibot88 Bundle Picoclaw Security GuardianPicoclaw security posture skill with advisory awareness, configuration drift detection, and supply-chain verification guidance.
3 -
aibot88 Bundle Ring Production Readiness AuditRing-standards-aligned production readiness audit across Structure, Security, Operations, Quality, and Infrastructure — 43 base dimensions + 1 conditional (multi-tenant) = up to 44 dimensions. Use before production deployment, periodic reviews, onboarding, or major releases. Skip for prototypes, libraries, or single-dimension checks. Runs explorers in batches of 10 and produces a scored report (0-430 base, max 440 with multi-tenant) with severity ratings.
3 -
aibot88 Bundle Salesforce Security BasicsApply Salesforce security best practices for Connected Apps, OAuth, and field-level security. Use when securing API credentials, implementing least privilege access, or auditing Salesforce security configuration. Trigger with phrases like "salesforce security", "salesforce secrets", "secure salesforce", "salesforce connected app security", "salesforce FLS".
3 -
aibot88 Bundle Secret Exposure PreventionPrevent secret leakage across git history, package artifacts, logs, and docs. Use when editing workflows, packaging configuration, environment files, or release automation.
3 -
aibot88 Bundle Security Compliance ReviewPerforms advanced SAST (Static Application Security Testing) and compliance analysis on Pull Request diffs. Identifies real security vulnerabilities, secrets, and regulatory compliance violations (GDPR, HIPAA, SOC2, PCI-DSS) by analyzing only changed code. Multi-language with exploitability assessment and CWE mapping.
3 -
aibot88 Bundle Security Incident ResponseWhen to use: active or suspected Salesforce org compromise, unauthorized access investigation, attacker containment, forensic evidence collection from EventLogFile/LoginHistory, session revocation, OAuth token cleanup, eradication of attacker persistence, and post-incident recovery verification. Trigger keywords: org compromised, suspicious login, attacker access, session revocation, forensic investigation, breach response, event log forensics, login anomaly investigation, incident response runbook. Does NOT cover general security setup, permission set design, field-level security configuration, or proactive security hardening — those are separate skills. NOT for general security setup.
3 -
aibot88 Bundle Security Issue DeduplicateMerge two <tracker> tracking issues that describe the same root-cause vulnerability (typically discovered independently by two reporters, arriving via different channels), preserving every reporter's credit, every mailing-list thread reference, and every independent attack-vector description. Updates the kept issue's body in place, closes the duplicate with the `duplicate` label, and regenerates the CVE JSON attachment so both finders land in `credits[]`.
3 -
aibot88 Bundle Security Soc Analyst GuideGuide pour analyste SOC — triage d'alertes, investigation, SIEM, indicateurs de compromission et playbooks de réponse. Se déclenche avec "SOC", "analyste SOC", "SIEM", "IoC", "incident de sécurité", "triage sécurité".
3 -
aibot88 Bundle Stackblitz Security BasicsSecure WebContainer deployments: CSP headers, sandbox isolation, input validation. Use when working with WebContainers or StackBlitz SDK. Trigger: "stackblitz security".
3 -
aibot88 Bundle Supabase Policy GuardrailsEnforce organizational governance for Supabase projects: shared RLS policy library with reusable templates, table and column naming conventions, migration review process with CI checks, cost alert thresholds, and security audit scripts scanning for common misconfigurations. Use when establishing Supabase standards across teams, creating RLS policy templates, setting up migration review workflows, or auditing existing projects for security and cost issues. Trigger with phrases like "supabase governance", "supabase policy library", "supabase naming convention", "supabase migration review", "supabase cost alert", "supabase security audit", "supabase RLS template".
3 -
aibot88 Bundle Syncfusion Blazor SecurityConfigure Content Security Policy (CSP) for Syncfusion Blazor components across Blazor Server, WebAssembly, and Auto render modes � self-hosted and CDN scenarios
3 -
aibot88 Bundle Threat Modeling TechniquesThreat modeling methodologies using STRIDE, attack trees, and risk assessment for proactive security analysis. Use when designing secure systems, conducting security reviews, or identifying potential attack vectors in applications.
3 -
aibot88 Bundle Validating Csrf ProtectionValidate CSRF protection implementations for security gaps. Use when reviewing form security or state-changing operations. Trigger with 'validate CSRF', 'check CSRF protection', or 'review token security'.
3 -
aibot88 Bundle 402 Frameworks Quarkus RESTUse when you need to design, review, or improve REST APIs with Quarkus REST (Jakarta REST) — including resource classes, HTTP methods, status codes, request/response DTOs, Bean Validation, exception mappers, optional runtime OpenAPI exposure (SmallRye), contract-first generation from OpenAPI, content negotiation, pagination, sorting and filtering, API versioning, idempotency (Idempotency-Key), optimistic concurrency (ETag / If-Match), HTTP caching (Cache-Control), API deprecation (Sunset / Deprecation headers), RFC 7807 Problem Details, ISO-8601 for time in contracts, and security-aware boundaries. This should trigger for requests such as Review or improve JAX-RS resources in a Quarkus project; Design HTTP APIs with validation and error handling on Quarkus; Add API versioning, idempotency, ETag concurrency, or deprecation headers; Implement pagination, sorting, or RFC 7807 Problem Details error responses. Part of cursor-rules-java project
3 -
aibot88 Bundle Aposd Verifying CorrectnessVerify code correctness before claiming done or committing. Run 6-dimension checklist: requirements coverage, concurrency safety, error handling, resource management, boundary conditions, and security. Output PASS/FAIL per dimension with final DONE/NOT DONE verdict. Use after implementation as pre-commit gate. Triggers on: is it done, ready to commit, verify correctness, did I miss anything, pre-commit check.
3 -
aibot88 Bundle Apple Notes Security BasicsApply security best practices for Apple Notes automation scripts. Trigger: "apple notes security".
3
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include managing-container-registries, cross-layer-contract-audit, databricks-security-basics. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.