Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
aibot88 Bundle Python RulesPython coding rules from ai-toolkit: coding-style, frameworks, patterns, security, testing. Triggers: .py, .pyi, pyproject.toml, requirements.txt, Pipfile, FastAPI, Django, Flask, pytest, SQLAlchemy, ruff, mypy. Load when writing, reviewing, or editing Python code.
3 -
aibot88 Bundle Recht SozialAustrian social security law analysis — health insurance (ASVG/GSVG/BSVG), pension (Pensionsrecht), unemployment benefits (AlVG), care allowance (BPGG), accident insurance, and Mindestsicherung. Analyzes entitlements, contribution obligations, and benefit calculations.
3 -
aibot88 Bundle Safety Check**WORKFLOW SKILL** — Risk awareness before action. USE FOR: assessing risks (security, data integrity, compatibility, operational, reversibility) of any task at variable depth. Accepts weight: Light (quick scan), Standard (dimensional analysis), Deep (full Risk Radar with evidence). Can be invoked multiple times in the same flow with increasing weight. DO NOT USE FOR: penetration testing, compliance audits, static security analysis tools.
3 -
aibot88 Bundle Sc WebsocketWebSocket security flaw detection — missing origin validation, authentication bypass, and message injection
3 -
aibot88 Bundle Secret SetupFocused micro-skill for secret management setup. Explains options, guides through Bitwarden installation/login/unlock, configures backend. Exits when done.
3 -
aibot88 Bundle Security FixSecurity remediation en vulnerability fix skill. Past fixes toe voor kwetsbaarheden uit security check-rapporten. Automatische dependency updates, configuratie-patches, code fixes via Edit tool, en PR-creatie. Gebruik na een security audit/scan om kritieke en hoge severity issues op te lossen.
3 -
aibot88 Bundle Skill VetterSecurity-first vetting for OpenClaw skills. Use before installing any skill from ClawHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.
3 -
aibot88 Bundle SkillbuilderBuild flawless Claude Code skills. Studies existing skills as reference, ensures correct format, and pushes for genuine intelligence — skills that exploit something specific about how Claude works. SKIP for one-off scripts, prompts, or task helpers.
3 -
aibot88 Bundle Solidity DevDeep expertise in Solidity language features, patterns, and best practices for secure smart contract development. Covers ERC standards, gas optimization, upgradeable contracts, and security patterns.
3 -
aibot88 Bundle Staff ReviewSenior Staff Engineer code review with SOLID principles, security analysis, and architecture critique. Use for significant changes, new systems, or when you want ruthless technical feedback.
3 -
aibot88 Bundle Strict AuditЖёсткий No-Go аудит для safety-critical архитектуры, кода и PR: выдаёт PASS/FAIL, блокирующие замечания и обязательные доказательства по таймингам, измерениям и fault-injection. Использовать перед включением силовой части и для спорных safety/timing-изменений; не использовать как обычное обзорное ревью по умолчанию.
3 -
aibot88 Bundle Swift StrictSwift/SwiftUI strictness, clean code, and security rules. Use when writing, reviewing, or refactoring Swift code in iOS/macOS projects. Covers force unwrap prevention, @Observable vs ObservableObject patterns, access control, concurrency safety (@MainActor, actors, Sendable), error handling with typed enums, memory leak prevention, guard-first style, and naming conventions. Derived from production iOS apps.
3 -
aibot88 Bundle Tls SecurityExpert skill for TLS/SSL implementation and certificate management. Generate and validate TLS configurations, create and manage X.509 certificates, analyze cipher suite security, debug TLS handshake failures, and implement certificate pinning.
3 -
aibot88 Bundle Vuln Scanner脆弱性スキャンスキル。CVE/依存関係脆弱性を検出し、npm audit/pip-audit/trivy等の結果を解析。セキュリティリスクの優先順位付けと修正提案を提供。
3 -
aibot88 Bundle Warden AuditFull security audit — secrets, dependencies, IAM, auth, injection, XSS, HTTPS, rate limiting, public storage. Use when asked for "security audit", "check for vulnerabilities", "security review", or "are we secure".
3 -
aibot88 Bundle Warden ReconSecurity reconnaissance — full inventory of secrets management, IAM, dependencies, auth, encryption, audit logging, and compliance gaps. Use when asked about "security posture", "how secure is this", or "security assessment".
3 -
aibot88 Bundle Web SecurityOWASP Top 10, security headers, CSP, XSS prevention, and vulnerability prevention.
3 -
aibot88 Bundle Webapp NiktoWeb server vulnerability scanner for identifying security issues, misconfigurations, and outdated software versions. Use when: (1) Conducting authorized web server security assessments, (2) Identifying common web vulnerabilities and misconfigurations, (3) Detecting outdated server software and known vulnerabilities, (4) Performing compliance scans for web server hardening, (5) Enumerating web server information and enabled features, (6) Validating security controls and patch levels.
3 -
aibot88 Bundle What AntibotDetect antibot vendors on one or more URLs without opening a browser session. Use when the user asks what antibot, bot protection, WAF, captcha, or challenge provider a site uses, or asks to check sites for Cloudflare, Akamai, DataDome, PerimeterX, Imperva/Incapsula, Kasada, reCAPTCHA, hCaptcha, Anubis, or Shape Security markers.
3 -
aibot88 Bundle Wise ScraperStructured web scraping for AI coders: explore, then exploit with shipped templates, runner, and hooks.
3 -
aibot88 Bundle 1password CLIEntry-point router skill for the 1Password CLI. Use this skill when the user mentions the 1Password CLI (`op`) or 1Password generically, references the secret-reference URI scheme `op://`, asks about `OP_ACCOUNT` or `OP_SERVICE_ACCOUNT_TOKEN`, asks about biometric unlock for a CLI, or is choosing how to load secrets into an app and 1Password is a candidate. Provides general orientation, the auth-mode picker, the full command map, and routing to deeper sub-skills (`op-secrets-injection`, `op-item-management`, `op-provisioning`, `op-ssh-keys`, `op-shell-plugins`, `op-service-accounts`). Defer to those sub-skills for specific commands.
3 -
personamanagmentlayer Bundle Security ExpertExpert-level application security, OWASP Top 10, penetration testing, and security best practices. Use when the user mentions OWASP, pentesting, appsec, vulnerability, encryption, or authentication, or when the task involves Security Principles, OWASP Top 10, Security Domains, or Broken Access Control.
-
personamanagmentlayer Bundle Code Review ExpertExpert-level code review focusing on quality, security, performance, and maintainability. Use this skill for conducting thorough code reviews, identifying issues, and providing constructive feedback.
-
personamanagmentlayer Skill Blockchain ExpertExpert-level blockchain, Web3, smart contracts, DeFi, and cryptocurrency development. Use when the user mentions Web3, smart contracts, DeFi, Ethereum, or Solidity, or when the task involves Blockchain Fundamentals, Web3 & DeFi, Smart Contract Security, or Gas Optimization.
-
personamanagmentlayer Bundle Healthcare ExpertExpert-level healthcare systems, medical informatics, HIPAA compliance, and health data standards. Use when the user mentions medical, HIPAA, HL7, FHIR, or EHR, or when the task involves Healthcare IT, Standards and Protocols, Regulatory Compliance, or Security and Compliance.
-
personamanagmentlayer Bundle Zero Trust ExpertExpert in zero-trust security architecture, identity verification, micro-segmentation, continuous authentication, and least-privilege access. Use when the user mentions identity, authentication, micro segmentation, least privilege, or security architecture, or when the task involves Zero Trust Principles, Identity and Access Management, Network Segmentation, or Continuous Verification.
-
personamanagmentlayer Bundle Cybersecurity ExpertBuild comprehensive cybersecurity solutions including threat detection, incident response, vulnerability management, and security compliance monitoring. Use when the user mentions threat detection, SIEM, incident response, vulnerability management, security monitoring, or security compliance programs.
-
personamanagmentlayer Bundle Cryptography ExpertExpert in cryptographic algorithms, PKI, TLS/SSL, encryption standards, key management, and secure communication protocols. Use when the user mentions encryption, PKI, TLS, SSL, key management, or security, or when the task involves Cryptographic Fundamentals, Public Key Infrastructure, TLS/SSL Protocol, or Modern Cryptography.
-
personamanagmentlayer Bundle Code Review WorkflowReview a change in a fixed order — context, correctness, security, then style — and write feedback that is actionable and ranked by severity. Use when the user asks for a code review, wants a pull request or diff reviewed before merge, asks whether a change is safe to ship, or when the task involves reviewing a patch, giving review feedback, triaging review comments, or setting review standards for a team.
-
personamanagmentlayer Bundle Identity Access ExpertDesign authentication and authorisation: OAuth 2.1 and OpenID Connect, session and token handling, RBAC and ABAC, and multi-tenant access control. Use when the user mentions OAuth, OIDC, SAML, SSO, JWT, refresh tokens, PKCE, login flows, sessions, roles and permissions, RBAC or ABAC, or when the task involves securing an API, implementing sign-in, or fixing a broken access control finding.
-
personamanagmentlayer Bundle Quality Management ExpertBuild comprehensive quality management solutions including QMS implementation, audit tracking, nonconformance management, and continuous improvement programs. Use when the user mentions a QMS, ISO 9001, audits and CAPA, nonconformance tracking, Six Sigma, or continuous improvement programs.
-
personamanagmentlayer Skill Incident Response ExpertExpert in security incident response, NIST framework, digital forensics, containment strategies, and recovery procedures. Use when the user mentions forensics, NIST, containment, recovery, or cybersecurity, or when the task involves NIST Incident Response Lifecycle, Incident Classification, Incident Response Workflow, or Forensic Collection.
-
personamanagmentlayer Bundle Penetration Testing ExpertExpert in ethical hacking, penetration testing, OWASP Top 10, vulnerability assessment, exploitation techniques, and security reporting. Use when the user mentions pentesting, ethical hacking, OWASP, vulnerability assessment, exploitation, or security testing, or when the task involves Penetration Testing Fundamentals, OWASP Top 10, Testing Methodologies, or Tools and Frameworks.
-
onewave-ai Bundle Compliance CheckerAudits a codebase or business process for regulatory compliance across GDPR, HIPAA, SOC2, CCPA, and PCI-DSS. Scans for PII handling, data retention, encryption, access controls, audit logging, consent management, and data transfer issues. Generates a structured compliance report with findings, gap analysis, remediation steps, and evidence requirements.
-
onewave-ai Skill Dependency AuditorAudit npm dependencies for security vulnerabilities, outdated packages, and unused dependencies. Use when checking for security issues, updating packages, or cleaning up dependencies.
-
onewave-ai Skill Cowork Expense AuditCowork-style sweep of a folder of receipts, statements, and expense exports -- categorizes every transaction, matches receipts to statement lines, flags policy violations and anomalies, and outputs a clean expense report plus a findings memo.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include warden-audit, python-rules, safety-check. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.