Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
aibot88 Bundle CoreCore development principles and guidelines covering security, QA, performance, documentation, and coding standards. Used by all agents to ensure consistent quality across the Orchestra system.
3 -
aibot88 Bundle Sast ToolsComprehensive guide to sast tools. Master the concepts, implementation, best practices, and real-world applications of sast tools in professional environments.
3 -
aibot88 Bundle SecSecurity review, vulnerability analysis, threat modeling. Use PROACTIVELY when reviewing authentication, authorization, or data handling.
3 -
aibot88 Bundle Secure Code ReviewLanguage-aware security code review covering CWE/OWASP patterns, SAST integration, and remediation guidance for Python, JS, Go, and Java.
3 -
aibot88 Bundle Sca RunnerRuns Software Composition Analysis (SCA) to detect vulnerable dependencies. Wraps npm audit and Trivy fs. Use when user asks to "scan dependencies", "check npm vulnerabilities", "SCA scan", "dependency audit", "依存関係スキャン", "脆弱性チェック".
3 -
aibot88 Bundle Cybersecurity ComplianceUse when identifying cybersecurity-specific regulations and incident reporting obligations. Covers NIS2, DORA, SEC cyber disclosure rules, CISA incident reporting, state breach notification laws, cyber insurance requirements, and security certification frameworks. USE FOR: NIS2, DORA, SEC cybersecurity rules, CISA, breach notification, incident reporting, SOC 2, ISO 27001, cyber insurance, FedRAMP, StateRAMP, CMMC, data breach response DO NOT USE FOR: implementing security controls (use security skills), security testing tools (use security/security-testing), general data privacy (use privacy-data-protection)
3 -
aibot88 Bundle DependenciesMap, assess, and remediate project dependencies with routing to dependency-mapper and security checks.
3 -
aibot88 Bundle Cybersecurity PartnerCybersecurity partner skill for acting as a practical security collaborator across architecture review, threat modeling, secure design, risk prioritization, defensive planning, vulnerability remediation, incident readiness, security roadmaps, and technical decision support. Use when the user wants an ongoing security advisor, reviewer, or second set of eyes.
3 -
aibot88 Bundle When Setting Network Security Use Network Security SetupConfigure Claude Code sandbox network isolation with trusted domains, custom access policies, and environment variables for secure network communication.
3 -
aibot88 Bundle Remediation AuthSecurity fix patterns for authentication and authorization vulnerabilities (credentials, JWT, deserialization, access control). Provides language-specific secure implementations.
3 -
aibot88 Bundle Security AnalystSecurity analyst persona with deep OWASP expertise, vulnerability classification, risk assessment, and compliance mapping
3 -
aibot88 Bundle Audit Context BuildingEnables ultra-granular, line-by-line code analysis to build deep architectural context before vulnerability or bug finding.
3 -
aibot88 Bundle When Configuring Sandbox Security Use Sandbox ConfiguratorConfigure Claude Code sandbox security with file system and network isolation boundaries. Ensures safe code execution with proper access controls and resource limits.
3 -
aibot88 Bundle Gate ValidationValidate that quality, security, and release gates are correctly defined, implemented, and enforced with evidence.
3 -
aibot88 Bundle Cleanup GithubProgressive audit and cleanup of GitHub accounts - stale forks, orphaned secrets, failing workflows, security configs. Audit-first with user approval before destructive actions. Triggers on 'clean up GitHub', 'audit my repos', 'GitHub hygiene', 'stale forks', 'orphaned secrets'. Requires gh CLI. (user)
3 -
aibot88 Bundle Advanced TopicsExplore advanced CS topics including advanced data structures, parallel computing, security, functional programming, and quantum computing.
3 -
aibot88 Bundle Understanding OcsfUnderstand the OCSF schema. Use when working with OCSF, looking up classes or objects, normalizing security events, or asking about the schema.
3 -
aibot88 Bundle Spec Securityセキュリティ・脆弱性対策の開発・テストを行う際に使用。OAuth/OIDC攻撃対策、認証識別子切り替え攻撃、Session Fixation、マルチテナント分離、セキュリティテスト実装時に役立つ。
3 -
aibot88 Bundle When Reviewing Pull Request Orchestrate Comprehensive Code RUse when conducting comprehensive code review for pull requests across multiple quality dimensions. Orchestrates 12-15 specialized reviewer agents across 4 phases using star topology coordination. Covers automated checks, parallel specialized reviews (quality, security, performance, architecture, documentation), integration analysis, and final merge recommendation in a 4-hour workflow.
3 -
aibot88 Bundle Vibe Security SkillThis skill helps Claude write secure web applications. Use when working on any web application to ensure security best practices are followed.
3 -
lovits Bundle Writing BeatsWriting, exploit; assemble raw material into a journey of beats, grounding each term before a beat leans on it.
0 -
lovits Bundle Writing ShapeWriting, exploit: shape raw material into an article, paragraph by paragraph.
0 -
lovits Bundle Nature WritingDraft, restructure, or plan Nature-style manuscript sections and initial-submission materials from author-provided claims, results, figures, notes, or Chinese drafts. Use for abstracts, introductions, related work, methods, Results or experiments, discussions, conclusions, titles, full manuscript arguments, and first-submission packages such as cover letters, title pages, highlights, author contributions, availability or declaration text, and reviewer suggestions. Also use to classify Results evidence, decide what belongs in main text, captions, Methods or source data, or Supplementary Information, compress Results to the shortest sufficient evidence chain, prevent revision accretion, and audit paragraph necessity or claim repetition. Trigger on drafting a paper or section, structuring a manuscript, academic writing, first submission, 投稿材料、首次投稿、投稿信、标题页、亮点、作者贡献、数据可用性声明、推荐审稿人.
0 -
lovits Bundle Stop That ShitKeep coding agents focused on requested and necessary work. Use when a request sets a read-only, answer-only, file, action, or stopping boundary; when evidence shows scope creep, speculative hardening, unnecessary hashing or dependencies, repeated audit loops, or valueless delegation; or when the user invokes Stop That Shit. Do not invoke for an ordinary focused fix without a boundary or scope-creep signal.
0 -
lovits Bundle Nature ResponseDraft, audit, or revise Nature-style revision correspondence packages: point-by-point reviewer-separated response letters, rebuttal letters, revision cover letters, LaTeX cover/response templates, and red-marked revised-manuscript excerpts. Keep mutually blind reviewers isolated so no reviewer-facing response reveals another reviewer's comments, numbering, recommendation, or author response. Prevent reviewer-driven manuscript accretion by preferring replacement, compression, or SI relocation over appending non-central defense prose. Use for reviewer comments, editor decision letters, pasted editorial emails, response drafts, cover letters, response to reviewers, rebuttal, 修回信, 返修邮件, 编辑邮件, 返修 cover letter, 审稿意见回复, 逐点回复, 大修回复, 小修回复, 回复审稿人, 修改稿回复, 写rebuttal, 回应审稿意见, 标红修改, or LaTeX 模板.
0 -
lovits Bundle Nature Paper CardBuild a source-grounded deep-reading Paper Card for one scientific paper, preprint, PDF, DOI, arXiv page, publisher article, or pasted paper text. Use when the user asks for a Paper Card, deep-reading literature card, single-paper deep analysis, module-by-module analysis, experiment-to-claim evidence chain, conclusion-boundary audit, critical analysis, knowledge connections, or candidate research ideas. Produce the fixed Sections 01-16 covering bibliographic position, research question, background route, pain point, core insight, method and module logic, essential formulas, experiment-to-claim evidence, conclusion boundaries, author-stated limitations, critical analysis, learned knowledge, knowledge connections, and testable research ideas. Do not use for full-paper bilingual translation, formal peer-review reports, batch literature monitoring, academic-English collection, comprehension quizzes, or public-article writing.
0 -
lovits Bundle Claude Md ImproverAudit and improve CLAUDE.md files in repositories. Use when user asks to check, audit, update, improve, or fix CLAUDE.md files. Scans for all CLAUDE.md files, evaluates quality against templates, outputs quality report, then makes targeted updates. Also use when the user mentions "CLAUDE.md maintenance" or "project memory optimization".
0 -
lovits Skill Security And HardeningHardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services. Use when auditing dependencies for known vulnerabilities, triaging package-manager audit findings, or assessing supply-chain risk in a new package. Use when personal data or privacy compliance (GDPR, CCPA) is involved.
0 -
lovits Skill Doubt Driven DevelopmentSubjects every non-trivial decision to a fresh-context adversarial review before it stands. Use when correctness matters more than speed, when working in unfamiliar code, when stakes are high (production, security-sensitive logic, irreversible operations), or any time a confident output would be cheaper to verify now than to debug later.
0 -
seaworld008 Skill Skill VetterUse before installing or trusting an external skill to inspect instructions, scripts, permissions, dependencies, provenance, and suspicious behavior for security and reliability risks.
65 -
seaworld008 Skill GRAPHQL ExpertUse when designing GraphQL APIs, reviewing schemas and resolvers, optimizing queries, managing federation, or checking GraphQL security and performance best practices.
65 -
seaworld008 Bundle Security AuditAudit codebases for exploitable security vulnerabilities with concrete attack paths, impact, and source evidence.
65 -
seaworld008 Skill Security ReviewReview code changes for injection, XSS, authentication, authorization, cryptography, and other security defects with evidence-based severity.
65 -
seaworld008 Skill Pr Review ExpertReview GitHub PRs or GitLab MRs for correctness, security, compatibility, and affected test coverage, with actionable evidence tied to the diff.
65 -
seaworld008 Skill Security AuditorSecurity audit workflow for AI-generated application code, APIs, infrastructure changes, dependencies, secrets, auth flows, and pull requests before they ship.
65 -
seaworld008 Bundle API Design ReviewerUse when reviewing API designs for consistency, usability, versioning, error semantics, security, backward compatibility, and developer experience before implementation or release.
65
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include writing-beats, stop-that-shit, security-and-hardening. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.