Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
aibot88 Bundle Validating Pci Dss ComplianceValidate PCI-DSS compliance for payment card data security. Use when auditing payment systems. Trigger with 'validate PCI-DSS', 'check payment security', or 'audit card data'.
3 -
aibot88 Bundle Vendor Security QuestionnaireAutomated vendor security assessment through questionnaire generation, response parsing, and risk scoring
3 -
aibot88 Bundle Code Security Audit对代码项目进行全面安全审计,支持 Python、Node.js、Go、Java 四种语言。 包含依赖漏洞扫描(结合原生工具 + Claude 分析)、代码安全模式检查(OWASP Top 10、注入、反序列化、 敏感信息泄露、认证授权、加密问题等)、业务逻辑审计、攻击链构建、配置审计、以及结构化报告输出。 触发场景:(1) 用户要求对项目进行安全审计/安全检查/代码审计 (2) 用户要求检查代码中的安全漏洞 (3) 用户要求进行依赖漏洞扫描 (4) 用户提到 security audit、vulnerability scan、代码审计、安全扫描、渗透测试前的代码审查 (5) 用户要求检查 OWASP Top 10 相关问题
3 -
aibot88 Bundle Pentest CoreUse when the user asks to perform security audits, penetration testing, vulnerability scanning, OWASP Top 10 checks, or offensive security assessments. Covers static analysis, dependency scanning, secret detection, API security testing, and pen test report generation.
3 -
aibot88 Bundle AI Orchestration Feedback LoopMulti-AI engineering loop orchestrating Claude, Codex, and Gemini for comprehensive validation. USE WHEN (1) mission-critical features requiring multi-perspective validation, (2) complex architectural decisions needing diverse AI viewpoints, (3) security-sensitive code requiring deep analysis, (4) user explicitly requests multi-AI review or triple-AI loop. DO NOT USE for simple features or single-file changes. MODES - Triple-AI (full coverage), Dual-AI Codex-Claude (security/logic), Dual-AI Gemini-Claude (UX/creativity).
3 -
aibot88 Bundle Algo Blockchain Smart ContractDesign and implement smart contracts as self-executing programmatic agreements on blockchain. Use this skill when the user needs to build automated on-chain logic, evaluate smart contract security, or design tokenized business rules — even if they say 'smart contract development', 'automated agreement', or 'on-chain logic'.
3 -
aibot88 Bundle API Security And Rate LimitingUse when configuring, auditing, or troubleshooting API rate limits, Connected App OAuth scope restriction, Connected App IP restrictions, API session policies, or API usage monitoring in a Salesforce org. Trigger keywords: 'API rate limit', '429 error', 'OAuth scope restriction', 'Connected App IP restriction', 'API usage monitoring', 'concurrent API limits', 'Bulk API limits'. NOT for OAuth flow implementation, token exchange mechanics, or general Connected App setup — use security/oauth-flows-and-connected-apps for those.
3 -
aibot88 Bundle Citrix Comprehensive KnowledgeComprehensive Citrix domain knowledge covering CVAD, DaaS, Gateway, NetScaler, and Workspace products. Use when needing deep product knowledge, architecture understanding, troubleshooting patterns, administration best practices, security hardening, performance optimization, or operational workflows. Provides foundational Citrix expertise for all engineering tasks.
3 -
aibot88 Bundle Encrypted Field Query PatternsDesign SOQL, filters, reporting, and indexes against Shield Platform Encryption fields. Trigger keywords: Shield Platform Encryption, encrypted field query, probabilistic vs deterministic encryption, encrypted SOQL filter, encrypted field index. Does NOT cover: Classic Encryption (deprecated), field-level security policy, or tenant secret key rotation.
3 -
aibot88 Bundle Fix Selected Security FindingsUse this skill only when the user explicitly selects security finding IDs to fix. Do not use it to fix all findings or perform broad refactors.
3 -
aibot88 Bundle Ifap Aktenanlage BatchregisterLegt für Massenprüfungen ein Batchregister mit Gläubigerstamm, Prüfnummern, Status, Wiedervorlagen und Audit-Trail an.
3 -
aibot88 Bundle Infrastructure VulnerabilitiesOWASP Infrastructure Top 10 vulnerability knowledge base for identifying, assessing, and remediating security risks in internal IT infrastructure environments.
3 -
aibot88 Bundle Nodejs Observability ReadinessUse when making a scaffolded Node.js service production-observable — replacing the no-op telemetry seam with OpenTelemetry tracing, prom-client RED metrics, and trace-correlated structured logs, then defining SLIs/SLOs and multi-burn-rate alert rules — after the service scaffold exists and reliability SLO targets are approved or intentionally deferred. Do not use for the service shell, config, or error tiers, auth or security review, queue or event integration, or performance and resilience gating; use the other Node.js archetype skills instead.
3 -
aibot88 Bundle Oci Certificates Issuer ReviewUse this skill when reviewing OCI Certificates Service issuer configurations for cert-manager on OKE. Trigger on any request to audit OCI CA hierarchy, issuance rules, OKE Workload Identity vs Instance Principal auth, IAM policy scope, OCSP reachability, or certificate version management.
3 -
aibot88 Bundle Openai Security Best PracticesPerform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks. Originally from OpenAI's curated skills catalog.
3 -
aibot88 Bundle Red Team Tools And MethodologyThis skill should be used when the user asks to "follow red team methodology", "perform bug bounty hunting", "automate reconnaissance", "hunt for XSS vulnerabilities", "enumerate subdomains", or needs security researcher techniques and tool configurations from top bug bounty hunters.
3 -
aibot88 Bundle Rpa Workflow Resilience ReviewUse this skill when reviewing exported RPA workflow definitions for resilience and security defects that cause unattended bots to fail silently in production. Trigger when a user provides UiPath XAML files, Automation Anywhere bot exports, Power Automate Desktop flow definitions, Blue Prism process XML, or project dependency manifests, or asks why an unattended bot crashes silently, double-processes transactions, or times out under load. This skill reviews workflow definitions statically; it never connects to a live orchestrator, never runs a bot, and never requests runner credentials or orchestrator URLs.
3 -
aibot88 Bundle Security API Security HardenerDurcissement de la sécurité des APIs — rate limiting, validation d'entrée, headers de sécurité, CORS, protection contre les attaques courantes. À utiliser quand l'utilisateur sécurise une API, configure des headers de sécurité ou implémente du rate limiting. Se déclenche aussi avec "sécurité API", "rate limiting", "headers sécurité", "CORS", "API hardening", "protection API", "OWASP API".
3 -
aibot88 Bundle Spring Boot REST API StandardsProvides REST API design standards and best practices for Spring Boot projects. Use when creating or reviewing REST endpoints, DTOs, error handling, pagination, security headers, HATEOAS and architecture patterns.
3 -
aibot88 Bundle Windsurf Dependency ManagementAnalyze and update dependencies with vulnerability scanning. Activate when users mention "update dependencies", "security audit", "npm audit", "vulnerability scan", or "dependency updates". Handles dependency analysis and updates. Use when working with windsurf dependency management functionality. Trigger with phrases like "windsurf dependency management", "windsurf management", "windsurf".
3 -
aibot88 Bundle RadarUse radar for multi-framework smart contract AST generation and security analysis. Supports Rust (Anchor, native, Stylus) and Solidity (standard, Foundry). Triggers include generating AST, finding vulnerabilities, debugging via AST output, writing security templates, contributing detection rules, or working with radar's template DSL. Use when users mention radar, AST generation for Rust/Solidity/Anchor/Stylus/Foundry, smart contract parsing, vulnerability detection, template development, or security scanning.
3 -
aibot88 Bundle Grove Security AuditUse when performing security audits on a codebase. Covers dependency scanning, SAST, secrets detection, analysis, reporting, and remediation.
3 -
aibot88 Bundle 302 Frameworks Spring Boot RESTUse when you need to design, review, or improve REST APIs with Spring Boot — including HTTP methods, resource URIs, status codes, DTOs, versioning, deprecation and sunset headers, content negotiation (JSON and vendor media types), ISO-8601 instants in DTOs, pagination/sorting/filtering, Bean Validation at the boundary, idempotency, ETag concurrency, HTTP caching, error handling, security, contract-first OpenAPI (OpenAPI Generator), controller advice, and problem details for errors. This should trigger for requests such as Review Java code for Spring Boot REST API; Apply best practices for Spring Boot REST API in Java code. Part of cursor-rules-java project
3 -
aibot88 Bundle 404 Frameworks Quarkus SecurityUse when you need to design, review, or improve security in Quarkus applications — including Quarkus Security with JWT/OIDC, basic auth, @RolesAllowed / @Authenticated / @PermitAll, SecurityIdentity, permission checks, path-based authorization in configuration, exception mapping for auth failures, and sensitive-data-safe logging. This should trigger for requests such as Add Quarkus security support; Review Quarkus security configuration; Improve API authorization in Quarkus; Add JWT/OIDC security in Quarkus; Harden Quarkus authorization rules. Part of cursor-rules-java project
3 -
aibot88 Bundle Agentprivacy Threat AdversarialThreat modelling and adversarial analysis for 0xagentprivacy. Activates when discussing R(d) adversarial bounds, attack surface analysis, red team methodologies, trusted setup attacks, side-channel vulnerabilities, or systematic approaches to finding privacy architecture weaknesses.
3 -
aibot88 Bundle Alibabacloud Waf Quick ShowcaseSolution skill for using WAF to protect web applications on ECS. Used for quickly deploying network environments including VPC, security groups, and ECS instances, and integrating WAF for web application protection. Trigger words: "WAF protection", "ECS web protection", "Web Application Firewall", "website security"
3 -
aibot88 Bundle Android Owasp Security ReviewerAndroidアプリのセキュリティレビューをOWASP Mobile Top 10 2024およびMASVS (Mobile Application Security Verification Standard) の観点で実施し、Markdownレポートを生成する。 Use when: (1) Androidアプリのセキュリティ監査/レビュー依頼時 (2) 「セキュリティチェック」「脆弱性診断」「OWASP」「MASVS」キーワード時 (3) Androidプロジェクトのコードレビューでセキュリティ観点が必要な時 (4) 金融・医療アプリのセキュリティ評価時
3 -
aibot88 Bundle Apex User And Permission ChecksUse when Apex needs to check what the running user is, can see, or can do — via UserInfo, FeatureManagement, FeatureManagement.checkPermission, or FeatureManagement.checkPermissionType. Covers custom permissions, permission sets, user licenses, and profile checks. NOT for FLS/CRUD (use Security.stripInaccessible or `with user_mode`), sharing rules, or external user license logic.
3 -
aibot88 Bundle Cometchat Android V5 ProductionProduction readiness for CometChat Android — server-side token auth, user management CRUD, ProGuard rules, and security checklist.
3 -
aibot88 Bundle Cometchat Android V6 ProductionCometChat Android UIKit v6 production readiness — token auth, ProGuard/R8, security checklist, release configuration
3 -
aibot88 Bundle Cometchat Flutter V5 ProductionUse when preparing a CometChat Flutter UIKit v5 app for production. Covers auth tokens, ProGuard, environment config, security hardening.
3 -
aibot88 Bundle Cometchat Flutter V6 ProductionProduction readiness for CometChat Flutter UIKit v6 — server-side auth tokens, user management, Android ProGuard/R8, iOS Info.plist, minSdk, release build checklist, environment configuration, and security hardening. Use when preparing a CometChat Flutter app for production deployment.
3 -
aibot88 Bundle Connected App Security PoliciesManaging OAuth policies, IP relaxation, session security, PKCE, and credential rotation for Salesforce Connected Apps. Use when hardening Connected App security, rotating client secrets, configuring IP restrictions, or requiring high-assurance sessions. NOT for basic Connected App setup or creation. NOT for OAuth flow implementation (use oauth-flows-and-connected-apps).
3 -
aibot88 Bundle Dependency Vulnerability TriageTurns npm audit/Snyk results into prioritized patch plans with severity assessment, safe upgrade paths, breaking change analysis, and rollback strategies. Use for "dependency security", "vulnerability patching", "npm audit", or "security updates".
3 -
aibot88 Bundle Digitalocean Droplet DeploymentGeneric DigitalOcean droplet deployment using doctl CLI for any application type (APIs, web servers, background workers). Includes validation, deployment scripts, systemd service management, secret handling, health checks, and deployment tracking. Use when deploying Python/Node.js/any apps to droplets, managing systemd services, handling secrets securely, or when user mentions droplet deployment, doctl, systemd, or server deployment.
3 -
aibot88 Bundle Electron Main Preload GeneratorGenerate secure main process and preload script boilerplate with proper context isolation, IPC patterns, and security best practices for Electron applications
3
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include validating-pci-dss-compliance, vendor-security-questionnaire, code-security-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.