Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
aibot88 Bundle Fintech APIScaffold a production-ready financial services API -- generate a complete fintech backend with Plaid bank account linking and transaction sync, ACH/wire/card payment processing with payment orchestration, double-entry bookkeeping ledger with immutable entries and balance caching, KYC identity verification workflow with progressive tiers and document upload, idempotent request handling with deduplication windows, HMAC-signed outbound webhooks with retry and exponential backoff, append-only audit logging for compliance, multi-currency support with integer minor-unit arithmetic, and field-level encryption for sensitive data. Supports Fastify 5, NestJS, Express, FastAPI, Django REST, and Gin. Build a fintech API, create payment backend, scaffold banking API, financial services backend, money transfer service, neobank API, lending platform.
3 -
aibot88 Bundle Glba ExpertGLBA expert for financial institutions. Deep knowledge of Gramm-Leach-Bliley Act including Safeguards Rule (16 CFR Part 314), Privacy Rule (16 CFR Part 313), FTC enforcement, information security program requirements, vendor management, and consumer privacy notices.
3 -
aibot88 Bundle Django ReviewerWHEN: Django project review, ORM queries, views/templates, admin customization WHAT: ORM optimization + View patterns + Template security + Admin config + Migration safety WHEN NOT: FastAPI → fastapi-reviewer, Flask → flask-reviewer, DRF API only → consider api-expert
3 -
aibot88 Bundle HealthcheckHost security hardening and risk-tolerance configuration for Otto deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, Otto cron scheduling for periodic checks, or version status checks on a machine running Otto (laptop, workstation, Pi, VPS).
3 -
aibot88 Bundle Irap ExpertAustralian IRAP (Information Security Registered Assessors Program) expert. Provides guidance on ISM controls, Essential Eight maturity levels, ACSC guidelines, and Australian data sovereignty requirements.
3 -
aibot88 Bundle Linux AdminUse this skill when managing Linux servers, writing shell scripts, configuring systemd services, debugging networking, or hardening security. Triggers on bash scripting, systemd units, iptables, firewall, SSH configuration, file permissions, process management, cron jobs, disk management, and any task requiring Linux system administration.
3 -
aibot88 Bundle Manage RefsCross-cutting reference manager for medical manuscripts. Single entry point for citation-key validation, journal-CSL pandoc rendering, manuscript ↔ DOCX cross-reference QC, marker conversion (``[N]`` ↔ ``[@key]``), and native Zotero CWYW field-code injection. Replaces the inline reference-handling that previously lived in ``/write-paper`` Phase 7.6 and is reused by ``/revise``, ``/peer-review``, ``/sync-submission``, and any skill that produces a journal submission. Audit-only verification stays in ``/verify-refs`` — this skill writes (renders, injects, converts); that skill only reads.
3 -
aibot88 Bundle MindfulnessCultivate defensive situational awareness, threat assessment, and mental clarity under pressure. Covers the Cooper color code awareness system, body language reading and intent detection, verbal de-escalation, moving mindfulness in public spaces, combat focus and the OODA loop, rapid grounding techniques for acute stress, context-specific integration, and ongoing review and refinement of awareness skills. Use when entering unfamiliar or potentially hostile environments, needing to assess a situation for safety, de-escalating a verbal confrontation, or integrating awareness practice into daily movement.
3 -
aibot88 Bundle Msf OneshotMetasploit Framework 调用方法论(一行式 + 交互式)。当需要利用操作系统级漏洞(如 EternalBlue/MS17-010)、数据库远程漏洞(如 PostgreSQL/MySQL RCE)、网络服务漏洞(SMB/RDP/FTP)、需要生成 payload、启动反弹 shell handler、或后渗透操作时使用。MSF 拥有 2000+ exploit 模块,覆盖 Windows/Linux 操作系统、数据库、网络设备的远程利用。本技能同时覆盖一行式快速利用和 interactive_session 交互式操作(handler/meterpreter/后渗透)。任何涉及 metasploit、msfconsole、meterpreter、系统级 exploit、远程溢出、payload 生成、handler、后渗透的场景都应使用此技能
3 -
aibot88 Bundle 1passwordRead 1Password secrets via the `op` CLI with a service-account token. Secret values are metadata-only by default.
3 -
aibot88 Bundle Owasp CheckOWASP Top 10 vulnerability scanning and remediation
3 -
aibot88 Bundle Memstack Security Owasp Top10Use this skill when the user says 'OWASP audit', 'OWASP top 10', 'security audit', 'vulnerability assessment', 'full security check', or needs a comprehensive web application security review against OWASP Top 10 categories. Do NOT use for dependency audits or secret scanning alone.
3 -
aibot88 Bundle Paper AuditAudit paper drafts for logical consistency, compliance, and academic integrity (Triangulation Matrix).
3 -
aibot88 Bundle Pentest APIAPI security testing — REST/GraphQL/WebSocket, OWASP API Top 10, JWT/OAuth analiz, mass assignment, broken object-level authorization advisory. Triggers on API pentest, OWASP API, REST security, GraphQL test, WebSocket, JWT analysis, OAuth flow, BOLA, BFLA, mass assignment.
3 -
aibot88 Bundle Podium AuthAuthenticate production Podium integrations and survive the auth-side failures — OAuth2 access-token expiry storms, refresh-token decay after 90 days of non-use, scope drift on re-grant, secret rotation without downtime, multi-tenant token routing, leakage in commits. Use when hardening token caching, building a refresh-token decay monitor, rotating Podium client credentials, or recovering from 401/403 auth cascades. Trigger with "podium auth", "podium oauth", "podium token refresh", "podium scope drift", "podium credential rotation", "podium multi-location auth".
3 -
aibot88 Bundle QA SecurityPerform a security audit based on OWASP. Use when the user wants to verify security, look for vulnerabilities, or before a production deployment.
3 -
aibot88 Bundle Review AuthProduction-readiness audit for authentication. Use when auth code changes or when auth feels fragile, unclear, or unsafe. Covers OIDC, sessions, tokens, route protection, and secret management.
3 -
aibot88 Bundle Review MoodSets the reviewer persona for all code review, security review, and /simplify agents. Default mood: strict. Persists for the session until changed. Invoke /review-mood [mood] to switch. Invoke /review-mood to see current mood.
3 -
aibot88 Bundle Review MoveRun an in-house P0-P3 security review on a Sui Move package. Use when the user wants a Move security review or self-audit.
3 -
aibot88 Bundle Memstack Security Rls CheckerUse this skill when the user says 'check RLS', 'audit RLS', 'RLS policies', 'row level security', 'Supabase security audit', or needs to verify table-level access control. Audits Supabase Row Level Security policies across all tables. Do NOT use for non-Supabase projects or writing RLS policies from scratch.
3 -
aibot88 Bundle Roll ReviewSelf code review step in the TCR workflow. Runs after each micro-step is completed and before commit, checking code quality, security, and design issues.
3 -
aibot88 Bundle Rust ReviewRust code audit: unsafe blocks, ownership patterns, and Cargo dependency security scanning
3 -
aibot88 Bundle Rust StrictRust security, strictness, and vulnerability prevention rules. Use when writing, reviewing, or auditing Rust code. Complements rust-skills (179 general rules) with security-focused rules: unsafe audit, unwrap/expect bans, error handling hierarchy, secret handling, concurrency safety, input validation for Tauri commands, and release profile hardening. Derived from production Rust projects.
3 -
aibot88 Bundle Sales LiznrLiznr platform help — AI meeting assistant with real-time transcription, contextual intelligence, and task sync to Jira/Slack/Notion. Use when setting up Liznr Chrome extension or Teams app for meeting recording, Liznr transcription not capturing speakers correctly, Liznr action items not syncing to Jira or Slack, choosing Liznr vs Fathom or Fireflies or tl;dv for budget meeting notes, evaluating Liznr for recruiting interviews or legal meetings, Liznr multilingual transcription accuracy, or Liznr privacy and data security questions. Do NOT use for comparing note-takers broadly without mentioning Liznr (use /sales-note-taker) or reviewing a specific call for coaching (use /sales-call-review).
3 -
aibot88 Bundle Sapcc AuditFull-repo SAP CC Go compliance audit against review standards.
3 -
aibot88 Bundle Sast ReportConsolidate all SAST vulnerability results from the sast/ folder into a single final report ranked by severity and confidentiality impact. Reads all *-results.md files and produces sast/final-report.md. Run after all vulnerability detection skills complete. Use when asked to generate a final report, consolidate findings, or summarize security results.
3 -
aibot88 Bundle Sc VerifierFalse positive elimination and confidence scoring for all security findings
3 -
aibot88 Bundle Sfra ReviewSFRA (Storefront Reference Architecture) code review skill using Swarm pattern. Analyzes controllers, models, ISML, services, jobs for best practices, security, and performance. Triggers on "SFRA review", "SFCC code review", "cartridge review"
3 -
aibot88 Bundle Simple EarnBinance Simple-earn request using the Binance API. Authentication requires API key and secret key.
3 -
aibot88 Bundle Skills KeysManage API keys for the runner's --execute layer. CRUD on ~/.skills.env (chmod 600): list / add / update / remove / enable / disable gate flags / verify (ping vendor APIs) / export (eval-ready). Single source of truth for OPENAI_API_KEY, GEMINI_API_KEY, BFL_API_KEY, FAL_KEY, REPLICATE_API_TOKEN, RUNWAY_API_KEY, KLING_ACCESS_KEY_ID/SECRET, SUNO_API_KEY, ELEVENLABS_API_KEY, IDEOGRAM_API_KEY, ANTHROPIC_API_KEY, S3_* + gate flags (LYRIA_API_ENABLED, SUNO_API_ENABLED, OPENAI_SORA_API_ENABLED). Explicit shell exports always win over file entries. Use when the user says 'add my OpenAI key', 'rotate the Suno key', 'check which keys are set', 'verify my Gemini key works', 'where do I put my keys'.
3 -
aibot88 Bundle Snap ReviewReview a GitHub pull request in read-only mode for material bugs, regressions, missing tests, architecture drift, security/privacy risk, performance risk, and merge blockers. Use when the user wants a PR reviewed before merge or before posting feedback.
3 -
aibot88 Bundle Specdd RiskUse when Claude Code needs to classify risk before SpecDD work starts, especially around write authority, public contracts, security, data, migrations, dependencies, verification gaps, rollback, or destructive operations.
3 -
aibot88 Bundle Spring BootExpert guidance for Spring Boot application development with best practices for RESTful APIs, testing, security, and deployment
3 -
aibot88 Bundle Sub AccountBinance Sub-account request using the Binance API. Authentication requires API key and secret key.
3 -
aibot88 Bundle Swift RulesSwift coding rules from ai-toolkit: coding-style, frameworks, patterns, security, testing. Triggers: .swift, Package.swift, .xcodeproj, SwiftUI, Combine, async/await, XCTest. Load when writing, reviewing, or editing Swift code.
3 -
aibot88 Bundle Test MasterGenerates test files, creates mocking strategies, analyzes code coverage, designs test architectures, and produces test plans and defect reports across functional, performance, and security testing disciplines. Use when writing unit tests, integration tests, or E2E tests; creating test strategies or automation frameworks; analyzing coverage gaps; performance testing with k6 or Artillery; security testing with OWASP methods; debugging flaky tests; or working on QA, regression, test automation, quality gates, shift-left testing, or test maintenance.
3
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include fintech-api, glba-expert, django-reviewer. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.