Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
aibot88 Bundle Connecting Vpcs With PeeringEstablishes VPC peering connections between two VPCs for direct private network connectivity. Always use this skill when creating or managing VPC peering — it validates CIDR overlap, updates all route tables in both VPCs, configures DNS resolution, and provides security group guidance that are critical for correct connectivity.
3 -
aibot88 Bundle Dependency Conflict ResolverDetect and resolve package dependency conflicts before installation across npm/yarn/pnpm, pip/poetry, cargo, and composer. Auto-trigger when installing/upgrading packages. Validates peer dependencies, version compatibility, security vulnerabilities. Auto-resolves safe conflicts (patches, dev deps), suggests manual review for breaking changes. Prevents conflicting versions, security vulnerabilities, broken builds.
3 -
aibot88 Bundle Rails ConventionsRails 8.x application architecture, implementation, and review guidance for production codebases. Use when building or reviewing Ruby on Rails 8 features across models, controllers, routes, Hotwire, jobs, APIs, performance, security, and testing. Trigger for requests mentioning Rails 8, Active Record, Active Job, GoodJob, Solid Queue, Turbo/Stimulus, REST resources, migrations, code quality, naming, and production readiness.
3 -
aibot88 Bundle Governance Compliance ShieldCorporate governance and regulatory compliance operating system covering board management, board meeting protocols, corporate governance best practices, audit readiness, SOC 2/ISO 27001/ISO 9001 certification, ESG framework, data governance, internal controls, risk management framework, whistleblower policy, anti-bribery/FCPA, related party transactions, and regulatory compliance by industry. Includes India governance stack covering Companies Act 2013 governance requirements, MCA/ROC compliance, Board composition rules, CSR obligations (Section 135), related party transactions (Section 188), annual compliance calendar, statutory audit requirements, secretarial audit, SEBI LODR for listed companies, and NCLT proceedings. Use when user mentions board, governance, compliance, audit, SOC 2, ISO, ESG, internal controls, risk management, whistleblower, anti-bribery, FCPA, board meeting, board minutes, independent director, audit committee, CSR, Companies Act, MCA, ROC, SEBI LODR, statutory audit, secretarial audit,
3 -
aibot88 Bundle Ln 620 Codebase AuditorCoordinates 9 specialized audit workers (security, build, architecture, code quality, dependencies, dead code, observability, concurrency, lifecycle). Researches best practices, delegates parallel audits, aggregates results into single Linear task in Epic 0.
3 -
aibot88 Bundle Ln 762 Dependency AuditAudits project dependencies for vulnerabilities. Multi-ecosystem support (npm, .NET, Python, Go). CVSS-based severity classification.
3 -
aibot88 Bundle Ln 634 Test Coverage AuditorIdentifies missing tests for critical paths (money, security, data integrity, core flows). Use when auditing test coverage gaps.
3 -
aibot88 Bundle Loom Code Review And QualityUse when a code diff, branch, PR, worker output, or implementation-complete ticket needs a code-focused quality review across correctness, tests, architecture, security, performance, scope, and evidence before audit or closure.
3 -
aibot88 Bundle Mission Control Release PrepPrepare a project for release through Mission Control. Use when validation, docs, versioning, changelog, limitations, evidence, deployment readiness, and security concerns need one coordinated release-prep review.
3 -
aibot88 Bundle Repo Modernize Upgrade AuditRepo/monorepo—dep modernize, vuln fix, framework-aware upgrade, hard-cut, dep-native refactors.
3 -
aibot88 Bundle Scanning For VulnerabilitiesExecute this skill enables comprehensive vulnerability scanning using the vulnerability-scanner plugin. it identifies security vulnerabilities in code, dependencies, and configurations, including cve detection. use this skill when the user asks to scan fo... Use when appropriate context detected. Trigger with relevant phrases based on skill purpose.
3 -
aibot88 Bundle Secure Coding Training SkillDeveloper security training and assessment for secure coding practices and vulnerability prevention
3 -
aibot88 Bundle Xss And Injection PreventionUse when writing or reviewing Visualforce pages, Apex controllers, or LWC components that output user-supplied data, build dynamic queries, or construct HTTP responses. Triggers: 'XSS in Visualforce', 'SOQL injection vulnerability', 'how to encode output in Apex', 'JSENCODE Visualforce', 'open redirect prevention'. NOT for Apex CRUD/FLS enforcement (use soql-security or apex-crud-and-fls), NOT for Shield encryption (use shield-encryption-key-management), NOT for AppExchange security review process (use secure-coding-review-checklist).
3 -
aibot88 Bundle Cve FixFix CVEs in project dependencies end-to-end. Use when the user wants to fix a security vulnerability, mentions a CVE ID, runs a security audit and finds vulnerabilities, or asks why their build is failing due to a security check. Surface the CVE, trace the affected dependency to its version source, research the fix online, upgrade if a patched version exists, suppress only as a last resort. Works across Maven, npm, Go, Python, Rust, and Ruby projects.
3 -
aibot88 Bundle Smart Contract Security AuditDeep security analysis for Solidity smart contracts with DeFi context
3 -
aibot88 Bundle 502 Frameworks Micronaut RESTUse when you need to design, review, or improve REST APIs with Micronaut — including @Controller routes, HTTP status codes, DTOs, Bean Validation, exception handlers, pagination, idempotency, ETag/If-Match, caching headers, versioning, contract-first OpenAPI (OpenAPI Generator), optional runtime OpenAPI via micronaut-openapi, and security annotations. This should trigger for requests such as Review or improve Micronaut @Controller REST APIs; Add validation, error handling, or align controllers with the OpenAPI contract on Micronaut HTTP layer. Part of cursor-rules-java project
3 -
aibot88 Bundle Agentprivacy Amnesia ProtocolFoundational skill for amnesia-as-ZK-primitive patterns. Applies when designing systems where forgetting is the proof, separation creates trust, and the inability to reconstruct origin is the security guarantee. Core to Act XXXI cosmological closure.
3 -
aibot88 Bundle Agentprivacy Forensic DefenseIncident response, breach containment, damage assessment, and evidence preservation for 0xagentprivacy swordsman operations. Activates when a privacy breach is detected or suspected, when designing post-compromise recovery procedures, when building forensic audit capabilities, or when the swordsman must shift from prevention to damage control. Triggers: "breach", "incident response", "compromise", "forensic", "damage assessment", "evidence preservation", "post-compromise", "breach containment", "data exposure", "leak detection".
3 -
aibot88 Bundle Apex Custom Permissions CheckCustom Permissions in Apex: FeatureManagement.checkPermission, $Permission global variable, permission-set gating of feature code, Custom Permission metadata. NOT for CRUD/FLS enforcement (use security-apex-crud-fls). NOT for standard Salesforce permissions (use permission-set-architecture).
3 -
aibot88 Bundle Broken Authentication TestingThis skill should be used when the user asks to "test for broken authentication vulnerabilities", "assess session management security", "perform credential stuffing tests", "evaluate password policies", "test for session fixation", or "identify authentication bypass flaws". It provides comprehensive techniques for identifying authentication and session management weaknesses in web applications.
3 -
aibot88 Bundle Custom Logging And MonitoringUse when designing or implementing a custom logging framework in Apex: log sObject schema, log level gating, retention policies, batch purge jobs, and forwarding logs to external monitoring systems (Splunk, Datadog, etc.). NOT for built-in debug logs or Developer Console (use debug-logs-and-developer-console), NOT for exception capture and error propagation (use error-handling-framework), NOT for Event Monitoring (use security skills).
3 -
aibot88 Bundle Generating Compliance ReportsGenerate comprehensive compliance reports for security standards. Use when creating compliance documentation. Trigger with 'generate compliance report', 'compliance status', or 'audit compliance'.
3 -
aibot88 Bundle Import Security Issue From MdOpen one or more `<tracker>` tracking issues from a markdown file containing a batch of security findings (typically the output of an AI security review or a third-party scanner). Each finding in the file becomes one tracker, landing in the `Needs triage` board column with the standard issue-template body fields populated from the markdown sections. Unlike `import-security-issue` (Gmail) and `import-security-issue-from-pr` (public PR), there is no inbound reporter to reply to and no PR to inspect — the file itself is the full report.
3 -
aibot88 Bundle Import Security Issue From PrOpen a tracking issue in <tracker> for a security-relevant fix that has already been opened (or merged) as a public PR in <upstream>, in the case where there is no inbound `<security-list>` report. The tracker lands in the `Assessed` board column (the team-deliberate import implies the security assessment has already happened) with the scope label applied, `pr created` / `pr merged` reflecting the PR's state, and `Remediation developer` / `PR with the fix` body fields populated from the PR — ready for `allocate-cve` to take over.
3 -
aibot88 Bundle Linux Linux Security HardenerDurcissement sécurité Linux — SSH, fail2ban, SELinux, audit, gestion des utilisateurs et mises à jour. Se déclenche avec "sécurité Linux", "hardening Linux", "SSH sécurisé", "fail2ban", "SELinux", "audit Linux".
3 -
aibot88 Bundle Nfr Definition For SalesforceDefining measurable non-functional requirements for Salesforce implementations: performance SLIs, scalability targets, availability SLAs, security and compliance requirements, usability benchmarks. Use when starting architecture design or preparing for go-live sign-off. NOT for technical implementation of those requirements. NOT for HA/DR planning (use ha-dr-architecture). NOT for individual governor limit investigation (use limits-and-scalability-planning). NOT for security controls implementation (use security-architecture-review).
3 -
aibot88 Bundle Prestashop Module DevelopmentComplete PrestaShop module development workflow using modern architecture and best practices. Use when: creating new PrestaShop modules, updating legacy modules to modern code, implementing hooks and actions, setting up module configuration pages, adding front office features, handling database operations, implementing security measures, managing translations, or modernizing existing PrestaShop modules from legacy patterns to current standards.
3 -
aibot88 Bundle Project Analysis Node ExpressUse for deep Node.js / Express project analysis: boot flow, middleware order, async behavior, data layer, auth/security, and Node-specific runtime failure patterns.
3 -
aibot88 Bundle Python Logging Best PracticesPython logging with loguru, structlog, and orjson. TRIGGERS - loguru, structlog, structured logging, JSONL logs, log rotation, secret redaction, OTel logging, lightweight logging, print logging, systemd logging.
3 -
aibot88 Bundle Record Access TroubleshootingDiagnose why a user can or cannot see/edit a record: UserRecordAccess SOQL, Why Can a User Access This Record debug log, OWD, role hierarchy, sharing rules, manual/team/apex shares, implicit parent share. NOT for field-level security (use field-level-security-audit). NOT for designing sharing (use sharing-selection decision tree).
3 -
aibot88 Bundle Secrets Logging Privacy AuditUse this skill to audit secrets, PII, logs, traces, metrics, debug endpoints, and error responses. Do not use it for general performance review.
3 -
aibot88 Bundle Security Implementation GuideComprehensive security patterns for authentication, authorization, input validation, and common vulnerability prevention
3 -
aibot88 Bundle Security Issue Import From MdOpen one or more `<tracker>` tracking issues from a markdown file containing a batch of security findings (typically the output of an AI security review or a third-party scanner). Each finding in the file becomes one tracker, landing in the `Needs triage` board column with the standard issue-template body fields populated from the markdown sections. Unlike `security-issue-import` (Gmail) and `security-issue-import-from-pr` (public PR), there is no inbound reporter to reply to and no PR to inspect — the file itself is the full report.
3 -
aibot88 Bundle Security Issue Import From PrOpen a tracking issue in <tracker> for a security-relevant fix that has already been opened (or merged) as a public PR in <upstream>, in the case where there is no inbound `<security-list>` report. The tracker lands in the `Assessed` board column (the team-deliberate import implies the security assessment has already happened) with the scope label applied, `pr created` / `pr merged` reflecting the PR's state, and `Remediation developer` / `PR with the fix` body fields populated from the PR — ready for `security-cve-allocate` to take over.
3 -
aibot88 Bundle Security Zero Trust ArchitectArchitecture Zero Trust — never trust always verify, micro-segmentation réseau, approche identity-centric et accès conditionnel. Se déclenche avec "Zero Trust", "zero trust architecture", "never trust", "micro-segmentation", "BeyondCorp".
3 -
aibot88 Bundle Transaction Security PoliciesTransaction Security policy creation and configuration: condition builder, enhanced policies, enforcement actions (block, MFA, notification, end session), real-time monitoring mode, and policy troubleshooting. NOT for Event Monitoring log analysis or Shield Event Monitoring setup (use event-monitoring). NOT for Apex testing or debug-log analysis.
3
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include rails-conventions, connecting-vpcs-with-peering, dependency-conflict-resolver. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.