Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
aibot88 Bundle Audit Security DependenciesUse when adding packages, bumping versions, or responding to security alerts. Enforces supply chain security and vulnerability remediation.
3 -
aibot88 Bundle Axiom Audit Database SchemaUse when the user mentions database schema review, migration safety, GRDB migration audit, or SQLite schema checking.
3 -
aibot88 Bundle Axiom Scan Security PrivacyUse when the user mentions security review, App Store submission prep, Privacy Manifest requirements, hardcoded credentials, or sensitive data storage.
3 -
aibot88 Bundle Implementing Backup StrategiesThis skill implements backup strategies for databases and applications. It generates configuration files and setup code to ensure data protection and disaster recovery. Use this skill when the user requests to "implement backup strategy", "configure backups", "setup data recovery", or needs help with "backup automation". The skill provides production-ready configurations, best practices, and multi-platform support for database and application backups. It focuses on security and scalability.
3 -
aibot88 Bundle Cloudflare Security CheckerAutomatically validates Cloudflare Workers security patterns during development, ensuring proper secret management, CORS configuration, and input validation
3 -
aibot88 Bundle Workers SecurityCloudflare Workers security with authentication, CORS, rate limiting, input validation. Use for securing APIs, JWT/API keys, or encountering auth failures, CORS errors, XSS/injection vulnerabilities.
3 -
aibot88 Bundle Crewai Task And Tool DesignUse when an approved ai-architecture.md defines CrewAI tasks or callable tools. Produces task decomposition, tool schemas, an auth-enforcing execution adapter, idempotency, audit logging, and failure tests. Not for crew topology, retrieval design, or provider SDK work.
3 -
aibot88 Bundle Cyber Incident Response 72hStrukturierte Sofortmassnahmen bei aktivem Cyber-Vorfall — Hacker-Angriff Ransomware Datenexfiltration Insider-Threat. Phase 1 Sofort-Eindaemmung Netztrennung Forensik-Sicherung. Phase 2 DSGVO-Meldung Art. 33 72 Stunden bei Risiko Betroffenen-Information Art. 34 bei hohem Risiko NIS-2 24-Stunden-Fruehwarnung 72-Stunden-Vorfallsmeldung. Phase 3 Strafanzeige § 202a § 303a § 303b StGB Cybersecurity-Versicherer-Meldung Bestellung Forensik-Dienstleister. Phase 4 Kommunikation Kunden Mitarbeiter Aufsichtsbehoerde. Beweissicherung Chain-of-Custody Mitteilung in Klarsprache fuer Fuehrungsorgan.
3 -
aibot88 Bundle Dependency Security AuditorAudit dependency CVEs across Node, Python, Flutter/Dart, and mixed repos; design OSV/native audit hooks for pre-push and CI.
3 -
aibot88 Bundle Derivatives Trading OptionsBinance Derivatives-trading-options request using the Binance API. Authentication requires API key and secret key. Supports testnet and mainnet.
3 -
aibot88 Bundle Detecting Suspicious AssertDetects suspicious use of assertions for security checks that can be disabled in production builds. Use when analyzing assertion usage, security checks, or investigating assert-related vulnerabilities.
3 -
aibot88 Bundle Dokploy Template ValidationValidate Dokploy templates against conventions: YAML syntax, network structure, health checks, environment variables, security patterns, and quality standards.
3 -
aibot88 Bundle Electron Ipc Security AuditAnalyze Electron IPC implementations for security vulnerabilities including contextIsolation, nodeIntegration, preload scripts, and channel validation
3 -
aibot88 Bundle Eresus Serialization ReviewSerialization and deserialization security review skill for object mappers, parser pipelines, message formats, and state transfer mechanisms. Trigger when the user asks to: "review serialization security", "check deserialization", "audit Jackson/Fastjson/YAML/XML parsing", "look for gadget-chain risk", "review session or message deserialization", or wants a focused audit of parser-driven attack surface. Complements eresus-sast-scanner with a deep dive on serialization abuse paths.
3 -
aibot88 Bundle File Path Traversal TestingThis skill should be used when the user asks to "test for directory traversal", "exploit path traversal vulnerabilities", "read arbitrary files through web applications", "find LFI vulnerabilities", or "access files outside web root". It provides comprehensive file path traversal attack and testing methodologies.
3 -
aibot88 Bundle Firebase Firestore StandardComprehensive guide for Firestore Standard Edition, including provisioning, security rules, and SDK usage. Use this skill when the user needs help setting up Firestore, writing security rules, or using the Firestore SDK in their application.
3 -
aibot88 Bundle Firm Advanced Security PackAdvanced security audit pack covering secrets lifecycle, path canonicalization, exec plan freeze, hook routing, config includes, prototype pollution, safeBins profiles, and group policy defaults. 8 deep security tools.
3 -
aibot88 Bundle Hermes Attestation GuardianHermes-only runtime security attestation and drift detection skill for operator-managed Hermes infrastructure.
3 -
aibot88 Bundle Hubspot Agency Multi PortalManage 10-100 HubSpot portals for agency clients with credential isolation that prevents cross-portal data contamination, per-portal audit trails for billing and GDPR/CCPA attribution, and a scriptable bulk-onboarding workflow that eliminates one-at-a-time credential setup. Use when onboarding new client portals, building a compliant per-client API call log, rotating tokens across a full agency fleet, or generating per-client compliance reports. Trigger with "hubspot agency", "multi-portal management", "hubspot credential isolation", "per-portal audit log", "hubspot compliance report", "bulk portal onboarding", "token rotation cascade", "hubspot client portals".
3 -
aibot88 Bundle Incident Response CommanderGuides teams through IT outages and security incidents, providing structured workflows for detection, containment, eradication, and post-mortem analysis.
3 -
aibot88 Bundle Loom Security And HardeningUse when the work touches security-sensitive boundaries: untrusted input, authn/authz, secrets, sensitive data, uploads, webhooks, command/database execution, external integrations, dependencies, or hardening review.
3 -
aibot88 Bundle Lwc Locker To Lws MigrationMigrating LWCs from Lightning Locker Service to Lightning Web Security (LWS) — flipping the org switch safely, identifying components likely to break, removing Locker workarounds that are now insecure, and validating third-party libraries that previously failed under SecureWindow/SecureElement proxies. NOT for Aura → LWC migration — see lwc/aura-to-lwc-migration. NOT for general LWC security review (XSS, public-API hardening) — see lwc/lwc-security and lwc/lwc-public-api-hardening.
3 -
aibot88 Bundle Markdown Sanitization ChainMarkdown sanitization order matters — marked.js then DOMPurify then Mermaid to prevent XSS
3 -
aibot88 Bundle Oraclecloud Core Workflow BBuild OCI networking from scratch — VCN, subnets, gateways, and security rules. Use when creating a new VCN, debugging connectivity issues, or setting up security lists and NSGs. Trigger with "oci networking", "vcn setup", "security list", "nsg rules", "oci subnet".
3 -
aibot88 Bundle Oraclecloud Security BasicsMaster OCI IAM policy syntax, common policy patterns, and API key management. Use when writing IAM policies, granting access to compartments, or managing API keys. Trigger with "oraclecloud security basics", "oci iam policy", "oci policy syntax", "oci api key setup".
3 -
aibot88 Bundle Scanning Container SecurityExecute use when you need to work with security and compliance. This skill provides security scanning and vulnerability detection with comprehensive guidance and automation. Trigger with phrases like "scan for vulnerabilities", "implement security controls", or "audit security".
3 -
aibot88 Bundle Security Compliance CheckerVérification de conformité sécurité incluant ISO 27001, SOC 2, HIPAA, NIST et audit trail. Se déclenche avec "ISO 27001", "SOC 2", "HIPAA", "NIST", "conformité sécurité", "audit sécurité", "compliance"
3 -
aibot88 Bundle Responding To Security IncidentsAssists with security incident response, investigation, and remediation. This skill is triggered when the user requests help with incident response, mentions specific incident types (e.g., data breach, ransomware, DDoS), or uses terms like "incident response plan", "containment", "eradication", or "post-incident activity". It guides the user through the incident response lifecycle, from preparation to post-incident analysis. It is useful for classifying incidents, creating response playbooks, collecting evidence, constructing timelines, and generating remediation steps. Use this skill when needing to respond to a "security incident".
3 -
aibot88 Bundle Snowflake Policy GuardrailsImplement Snowflake governance guardrails with network rules, session policies, authentication policies, and automated compliance checks. Use when enforcing security policies, implementing data governance, or configuring automated compliance for Snowflake. Trigger with phrases like "snowflake policy", "snowflake guardrails", "snowflake governance", "snowflake compliance", "snowflake enforce".
3 -
aibot88 Bundle Solana Bot Sdk OrchestratorUse this skill when building Solana trading bots or automation that combines solana-streamer, sol-parser-sdk, sol-trade-sdk, and sol-safekey, including multi-language SDK variants for Rust, Node.js/TypeScript, Python, and Go. It helps agents choose the right SDK boundary, wire event streams into trades, handle wallet security, and produce runnable bot code for Codex, Claude Code, Cursor, or similar coding agents.
3 -
aibot88 Bundle Spring Security Auth ReviewUse when reviewing or hardening authentication and authorization in a Spring Boot service that uses Spring Security, JWT, OAuth2, sessions, refresh tokens, or service-to-service auth. Produces an actionable auth review, findings by severity, trust-boundary analysis, secure Spring Security configuration guidance, and remediation priorities. Do not use for general application security review, non-Spring services, or domain authorization policy design outside the framework layer. Pairs with spring-boot-service-scaffold (actuator and security baseline), backend-architecture (trust boundaries, authorization touchpoints, CSRF/CORS posture, and rate-limit behavior), spring-boot-observability-readiness (auth event logging and redaction), and quality-engineering (security test coverage).
3 -
aibot88 Bundle Analyzing Session ManagementDetects session management vulnerabilities including session fixation, session hijacking, and insecure cookie handling. Use when analyzing authentication sessions, cookie security, or investigating session-related vulnerabilities.
3 -
aibot88 Bundle Aoa Invariant Coverage AuditAudit whether existing tests and checks actually constrain the stable invariants that matter. Use when you need to judge if current coverage proves a rule or only repeats examples, and you want the smallest bounded follow-up gaps. Do not use when the invariant itself is still undefined or when the real task is to author new invariants rather than audit coverage.
3 -
aibot88 Bundle Bosskuai Laravel DevelopmentUse this for expert Laravel backend development, audits, queues, Eloquent, migrations, validation, service boundaries, testing, security, performance, and production readiness.
3 -
aibot88 Bundle Brazilian Fintech ComplianceComprehensive Brazilian financial regulatory compliance guide. Use when implementing LGPD data protection, BCB regulations, PIX/Boleto standards, or financial security patterns for Brazilian market applications.
3 -
aibot88 Bundle Citrix Storefront DeploymentStoreFront deployment planning, configuration, and security hardening. Use when planning StoreFront infrastructure, configuring stores and authentication, setting up server groups, implementing SSL/TLS, or troubleshooting StoreFront connectivity issues. Covers architecture patterns, high availability, and operational procedures.
3
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include audit-security-dependencies, axiom-audit-database-schema, axiom-scan-security-privacy. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.