Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
aibot88 Bundle Improve C6 1Improve readiness criterion C6.1 (Static Analysis) in the current project by adding linting, type checking, or security scanning. Raises the fulfillment level by one step.
3 -
aibot88 Bundle Kompliance XPerforms intelligent compliance audits for software projects. Automatically detects which regulatory frameworks (GDPR, HIPAA, PCI-DSS, CCPA, SOC 2) apply based on project analysis and user context. Provides tiered reports with executive summaries and detailed technical findings. Use when the user asks about compliance, regulatory requirements, security standards, data protection, or wants to audit their codebase for legal/regulatory adherence.
3 -
aibot88 Bundle Kotlin RulesKotlin coding rules from ai-toolkit: coding-style, frameworks, patterns, security, testing. Triggers: .kt, .kts, build.gradle.kts, Ktor, Jetpack Compose, coroutines, kotlinx. Load when writing, reviewing, or editing Kotlin code.
3 -
aibot88 Bundle Log AnalysisAnalyze application logs to identify errors, performance issues, and security anomalies. Use when debugging issues, monitoring system health, or investigating incidents. Handles various log formats including Apache, Nginx, application logs, and JSON logs.
3 -
aibot88 Bundle Logic HealthSweep a directory, module, or full codebase for logic correctness and produce a scored health dashboard with systemic patterns. Trigger when the scope is multi-file — "audit the whole codebase", "health check", "audit src/", "audit auth and payments modules", "where should I focus testing", "onboarding review", "logic overview before we ship". SCOPE HARD RULE: multi-file or directory scope. One file or one function uses logic-review; a concrete failure uses logic-locate; two versions uses logic-diff; explaining a path uses logic-explain; "fix everything" (no scope named) uses logic-fix-all. Do NOT trigger for: single function/file, style/architecture-only audits, security-only scans, performance-only audits.
3 -
aibot88 Bundle Logic ReviewFind logic bugs in a single file or function via semi-formal execution tracing (Premises → Trace → Divergence → Remedy). Trigger when a user shares code and suspects something is wrong without naming a concrete failure — phrases like "review this", "does this look right", "check this function", "audit this code", "tests pass but prod fails". SCOPE HARD RULE: one file or one function only. For a directory or whole module use logic-health; for a confirmed failure (stack trace, failing test, specific wrong value) use logic-locate; for two versions use logic-diff; for repo-wide autonomous fixing use logic-fix-all. Do NOT trigger for: style/formatting, security scanning, performance, test generation, architecture or design questions.
3 -
aibot88 Bundle Lwc SecurityUse when designing or reviewing Lightning Web Components for DOM safety, Lightning Web Security boundaries, third-party library handling, and secure server-side data access from LWC. Triggers: 'innerHTML in lwc', 'Lightning Web Security', 'document.querySelector', 'light DOM security', 'secure apex class for lwc'. NOT for org-wide sharing architecture or Apex-only security reviews when no LWC surface is involved.
3 -
aibot88 Bundle Mac SentinelmacOS security hardening for Claude Code — pre-execution validation, malicious config detection, credential hygiene, endpoint protection
3 -
aibot88 Bundle OpenzeppelinExpert usage of OpenZeppelin Contracts library for secure smart contract development. Covers access control, token standards, governance, upgrades, and security utilities.
3 -
aibot88 Bundle Oscal ExpertExpertise on OSCAL (Open Security Controls Assessment Language) — what document types exist, when to use each, schema versioning, FedRAMP/eMASS/CSPM integration, round-trip workflows.
3 -
aibot88 Bundle Owasp Top 10Revisa código contra as 10 falhas mais comuns antes de merge
3 -
aibot88 Bundle Pentest StigDISA STIG (Security Technical Implementation Guide) audit + GPO remediation + keep-open justification advisory. Triggers on STIG, DISA, SCAP, OpenSCAP, Compliance Master, GPO, group policy hardening, keep-open justification, CKL.
3 -
aibot88 Bundle Postgres RlsGuides agents implementing or auditing PostgreSQL Row Level Security in a multi-tenant SaaS codebase. Covers ENABLE+FORCE pairing, USING+WITH CHECK policies, view bypass via security_invoker, SET LOCAL for connection pool safety, superuser/owner bypass detection, and materialized view risks. Do NOT use for application-level authorization logic (use nextauth-patterns), non-PostgreSQL databases, or application query tier questions (use multi-tenancy-rls for orgQuery() usage).
3 -
aibot88 Bundle ProductionosProductionOS — dual-target AI engineering operating system for repo-wide audits, upgrade plans, code reviews, strategic product reviews, security sweeps, UX audits, and recursive quality improvement.
3 -
aibot88 Bundle Python RulesPython coding rules from ai-toolkit: coding-style, frameworks, patterns, security, testing. Triggers: .py, .pyi, pyproject.toml, requirements.txt, Pipfile, FastAPI, Django, Flask, pytest, SQLAlchemy, ruff, mypy. Load when writing, reviewing, or editing Python code.
3 -
aibot88 Bundle Recht SozialAustrian social security law analysis — health insurance (ASVG/GSVG/BSVG), pension (Pensionsrecht), unemployment benefits (AlVG), care allowance (BPGG), accident insurance, and Mindestsicherung. Analyzes entitlements, contribution obligations, and benefit calculations.
3 -
aibot88 Bundle Safety Check**WORKFLOW SKILL** — Risk awareness before action. USE FOR: assessing risks (security, data integrity, compatibility, operational, reversibility) of any task at variable depth. Accepts weight: Light (quick scan), Standard (dimensional analysis), Deep (full Risk Radar with evidence). Can be invoked multiple times in the same flow with increasing weight. DO NOT USE FOR: penetration testing, compliance audits, static security analysis tools.
3 -
aibot88 Bundle Sc WebsocketWebSocket security flaw detection — missing origin validation, authentication bypass, and message injection
3 -
aibot88 Bundle Secret SetupFocused micro-skill for secret management setup. Explains options, guides through Bitwarden installation/login/unlock, configures backend. Exits when done.
3 -
aibot88 Bundle Security FixSecurity remediation en vulnerability fix skill. Past fixes toe voor kwetsbaarheden uit security check-rapporten. Automatische dependency updates, configuratie-patches, code fixes via Edit tool, en PR-creatie. Gebruik na een security audit/scan om kritieke en hoge severity issues op te lossen.
3 -
aibot88 Bundle Skill VetterSecurity-first vetting for OpenClaw skills. Use before installing any skill from ClawHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.
3 -
aibot88 Bundle SkillbuilderBuild flawless Claude Code skills. Studies existing skills as reference, ensures correct format, and pushes for genuine intelligence — skills that exploit something specific about how Claude works. SKIP for one-off scripts, prompts, or task helpers.
3 -
aibot88 Bundle Solidity DevDeep expertise in Solidity language features, patterns, and best practices for secure smart contract development. Covers ERC standards, gas optimization, upgradeable contracts, and security patterns.
3 -
aibot88 Bundle Staff ReviewSenior Staff Engineer code review with SOLID principles, security analysis, and architecture critique. Use for significant changes, new systems, or when you want ruthless technical feedback.
3 -
aibot88 Bundle Strict AuditЖёсткий No-Go аудит для safety-critical архитектуры, кода и PR: выдаёт PASS/FAIL, блокирующие замечания и обязательные доказательства по таймингам, измерениям и fault-injection. Использовать перед включением силовой части и для спорных safety/timing-изменений; не использовать как обычное обзорное ревью по умолчанию.
3 -
aibot88 Bundle Swift StrictSwift/SwiftUI strictness, clean code, and security rules. Use when writing, reviewing, or refactoring Swift code in iOS/macOS projects. Covers force unwrap prevention, @Observable vs ObservableObject patterns, access control, concurrency safety (@MainActor, actors, Sendable), error handling with typed enums, memory leak prevention, guard-first style, and naming conventions. Derived from production iOS apps.
3 -
aibot88 Bundle Tls SecurityExpert skill for TLS/SSL implementation and certificate management. Generate and validate TLS configurations, create and manage X.509 certificates, analyze cipher suite security, debug TLS handshake failures, and implement certificate pinning.
3 -
aibot88 Bundle Vuln Scanner脆弱性スキャンスキル。CVE/依存関係脆弱性を検出し、npm audit/pip-audit/trivy等の結果を解析。セキュリティリスクの優先順位付けと修正提案を提供。
3 -
aibot88 Bundle Warden AuditFull security audit — secrets, dependencies, IAM, auth, injection, XSS, HTTPS, rate limiting, public storage. Use when asked for "security audit", "check for vulnerabilities", "security review", or "are we secure".
3 -
aibot88 Bundle Warden ReconSecurity reconnaissance — full inventory of secrets management, IAM, dependencies, auth, encryption, audit logging, and compliance gaps. Use when asked about "security posture", "how secure is this", or "security assessment".
3 -
aibot88 Bundle Web SecurityOWASP Top 10, security headers, CSP, XSS prevention, and vulnerability prevention.
3 -
aibot88 Bundle Webapp NiktoWeb server vulnerability scanner for identifying security issues, misconfigurations, and outdated software versions. Use when: (1) Conducting authorized web server security assessments, (2) Identifying common web vulnerabilities and misconfigurations, (3) Detecting outdated server software and known vulnerabilities, (4) Performing compliance scans for web server hardening, (5) Enumerating web server information and enabled features, (6) Validating security controls and patch levels.
3 -
aibot88 Bundle What AntibotDetect antibot vendors on one or more URLs without opening a browser session. Use when the user asks what antibot, bot protection, WAF, captcha, or challenge provider a site uses, or asks to check sites for Cloudflare, Akamai, DataDome, PerimeterX, Imperva/Incapsula, Kasada, reCAPTCHA, hCaptcha, Anubis, or Shape Security markers.
3 -
aibot88 Bundle Wise ScraperStructured web scraping for AI coders: explore, then exploit with shipped templates, runner, and hooks.
3 -
aibot88 Bundle 1password CLIEntry-point router skill for the 1Password CLI. Use this skill when the user mentions the 1Password CLI (`op`) or 1Password generically, references the secret-reference URI scheme `op://`, asks about `OP_ACCOUNT` or `OP_SERVICE_ACCOUNT_TOKEN`, asks about biometric unlock for a CLI, or is choosing how to load secrets into an app and 1Password is a candidate. Provides general orientation, the auth-mode picker, the full command map, and routing to deeper sub-skills (`op-secrets-injection`, `op-item-management`, `op-provisioning`, `op-ssh-keys`, `op-shell-plugins`, `op-service-accounts`). Defer to those sub-skills for specific commands.
3 -
personamanagmentlayer Bundle Security ExpertExpert-level application security, OWASP Top 10, penetration testing, and security best practices. Use when the user mentions OWASP, pentesting, appsec, vulnerability, encryption, or authentication, or when the task involves Security Principles, OWASP Top 10, Security Domains, or Broken Access Control.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include warden-audit, improve-c6-1, kompliance-x. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.