n8n Issue 创建
Create Linear tickets or GitHub issues following n8n conventions.
密钥泄漏、SAST、依赖漏洞 · 350 个 Skill
Create Linear tickets or GitHub issues following n8n conventions.
Full-stack diagnostic for agent and LLM applications.
Review a PR for correctness, security, code quality, and testing issues.
Review backend code for quality, security, maintainability, and best practices based on established checklist rules.
Review backend code for quality, security, maintainability, and best practices based on established checklist rules.
Reviews code for security vulnerabilities, performance issues, and best practices.
JSC GC reference for Bun.
Remove signs of AI-generated writing from text.
> Paperclip's UI is a professional-grade control plane — dense, keyboard-driven, dark-themed by default.
> This skill covers the day-to-day workflows for developing and operating a local Paperclip instance.
Perform a focused SEO audit on JavaScript concept pages to maximize search visibility, featured snippet optimization, and ranking potential Use this skill to perform a focused SEO audit on concept documentation pages for the 33 JavaScript Concepts project.
> Use this skill to parse, convert, chunk, and analyze documents with Docling.
Agent skill for code-analyzer - invoke with $agent-code-analyzer description: "Advanced code quality analysis agent for comprehensive code r…
Agent skill for code-review-swarm - invoke with $agent-code-review-swarm name: code-review-swarm description: Deploy specialized AI agents t…
Agent skill for memory-coordinator - invoke with $agent-memory-coordinator name: memory-coordinator type: coordination description: Manage p…
Agent skill for production-validator - invoke with $agent-production-validator name: production-validator color: "#4CAF50" description: Prod…
Agent skill for security-manager - invoke with $agent-security-manager name: security-manager color: "#F44336" description: Implements compr…
Agent skill for v3-security-architect - invoke with $agent-v3-security-architect name: v3-security-architect version: "3.0.0-alpha" updated: "2026-01-04" description: V3 Security Architect responsible for complete security overhaul, threat modeling, and CVE remediation planning.
AI job search command center -- evaluate offers, generate CVs, scan portals, track applications Determine the mode from $mode: | Input | Mode | |-------|------| | (empty / no args) | discovery -- Show command menu | | JD text or URL (no sub-command) | auto-pipeline |
Manage local skills - list, add, remove, search, edit, setup wizard Meta-skill for managing oh-my-claudecode skills via CLI-like commands.
Use when the user wants to design, redesign, shape, critique, audit, polish, clarify, distill, harden, optimize, adapt, animate, colorize, extract, or otherwise improve a frontend interface.
Use when the user wants to design, redesign, shape, critique, audit, polish, clarify, distill, harden, optimize, adapt, animate, colorize, extract, or otherwise improve a frontend interface.
| Evaluate AI agent systems against the OWASP Agentic Security Initiative (ASI) Top 10 — the industry standard for agent security posture.
When the user wants to optimize content for AI search engines, get cited by LLMs, or appear in AI-generated answers.
When the user wants to plan a content strategy, decide what content to create, or figure out what topics to cover.
When the user wants to edit, review, or improve existing marketing copy, or refresh outdated content.
When the user wants to audit, review, or diagnose SEO issues on their site.
Manage local skills - list, add, remove, search, edit, setup wizard Meta-skill for managing oh-my-codex skills via CLI-like commands.
Convert files and office documents to Markdown.
| You are a writing editor that identifies and removes signs of AI-generated text to make writing sound more natural and human.
Your agent's WebSearch for development.
Overcome LLM knowledge cutoffs with real-time developer content.
Validate skill files for structural compliance and behavioral correctness.
Run a WCAG 2.1 AA accessibility audit on a design or page.
Review content against your brand voice, style guide, and messaging pillars, flagging deviations by severity with specific before/after fixes.
Ansible automation expert for playbooks, roles, inventories, and infrastructure management You are a seasoned infrastructure automation engineer with deep expertise in Ansible.
PDF content extraction and analysis specialist You are a PDF analysis specialist.
> Scan and audit AI agent skills for security risks before installation.
Validate, test, and score the quality of skills within the claude-skills ecosystem.
Security auditing for code, configs, and infrastructure.
Read any common document/data file — PDF, Word (.docx), Excel (.xlsx/.xls), PowerPoint (.pptx), images (OCR), CSV/TSV, plain text, JSON/YAML…
Generates Spring Boot 3.x configurations, creates REST controllers, implements Spring Security 6 authentication flows, sets up Spring Data JPA repositories, and configures reactive WebFlux endpoints.
Scan agent skills for security issues.
从论文 PDF 文件或论文 PDF URL 生成通俗易懂、图文并茂、带批判性评估的中文 Markdown 解读,并保存到当前项目的 markdown 目录。
Autonomous novel writing CLI agent with web workbench (InkOS Studio) - use for creative fiction writing, standalone short-fiction packages, cover generation, novel generation, style imitation, chapter continuation/import, EPUB export, AIGC detection, and fan fiction.
Create, extract, or update a skill.
Multi-platform paid advertising audit and optimization skill.
Amazon Ads deep analysis covering Sponsored Products, Sponsored Brands (incl.
Full multi-platform paid advertising audit with parallel subagent delegation.
Google Ads deep analysis covering Search, Performance Max, AI Max, Display, YouTube, and Demand Gen campaigns.
GitHub issue and project-board management for the dotnet/msbuild repo.
扫描 ~/.claude/skills/ 下所有已安装技能,生成一目了然的可视化地图。
<!--zh 技能安全审查(Skill Vetter) 安装任何技能之前,必须先执行此审查流程。
Android APK analysis using GDA.exe.
> Audit the live site, not the source tree alone.
网络渗透测试的专业技能和方法论 网络渗透测试是评估网络基础设施安全性的重要环节。
Autonomous design critique mode using the Agentation annotation toolbar.
Quality review and audit for Claude Code skills.
Audit codebases for quality, consistency, and broken patterns — use for pre-release or tech debt review Comprehensive, methodical auditing t…
OpenClaw instance administration — manage hosts across macOS, Ubuntu/Debian, Docker, OCI, and Proxmox DETECT PLATFORM FIRST.
Expert multi-AI code review with inline PR comments — use for thorough quality and security analysis Invokes the code-reviewer persona for t…
Trace codepaths in diffs, map against tests, auto-generate missing coverage — use before shipping PRs Trace every codepath in a diff, map ea…
Post-ship doc sync across project markdown.
Route ordinary init, review, and security requests to Claude-native capabilities first;
URL validation and content sanitization for untrusted sources — use when handling external input safely This skill defines security patterns…
Create professional interior design visualizations — redesign existing rooms, generate new room concepts, or visualize specific furniture st…
Visualize interior design by generating an empty room and filling it with stylish furniture and decor, or by redesigning an existing room.
How the Faebryk component library is structured, how `_F.py` is generated, and the conventions/invariants for adding new library modules.
Trigger: improve skills, audit skills, refactor skills, skill quality.
In-depth guide to Factory, a container-based dependency injection system for Swift and SwiftUI.
Install Claude skills from GitHub repositories with automated security scanning.
Full pipeline: Recon -> Learn -> Hunt -> Validate -> Report.
'Execute proactive auto-loading: automatically detects and loads agents.md Automatic discovery and loading of AGENTS.md files across project hierarchies for AI coding agents.
Convert files and office documents to Markdown.
Scan live job boards and salary databases to find real-time compensation data for any role and location.
Skill Install Guardian v3.0 - Professional Security Audit 当执行安全审计时,必须: 1.
Improve a skill's public listing before publish.
Release skills to ClawhHub through the full publication pipeline — auto-scaffolding, OPSEC scan, dual review (agent + user), force-push rele…
Security vetting protocol before installing any AI agent skill.
Vet ClawHub skills for security and utility before installation.
>- Read-only consistency audit across the skillshare codebase.
Evaluate Agent Skill design quality against official specifications and best practices.
Use when the user asks about WordPress codebases (plugins, themes, block themes, Gutenberg blocks, WP core checkouts) and you need to quickly classify the repo and route to the correct workflow/skill (blocks, theme.json, REST API, WP-CLI, performance, security, testing, release packaging).
Spring Boot 3.x development - REST APIs, JPA, Security, Testing, and Cloud-native patterns.
>- ├─ 标准图表(思维导图/时序图/类图/饼图/流程图/甘特图) │ ├─ 图整图展示即可,不需要单独编辑节点 → 路径 A(Mermaid 服务端) │ └─ 需要单独编辑每个节点 / Mermaid 含 par / 10+ participant / 30+ 长标签 │…
Design, improve, and evaluate reusable agent skills with high-quality SKILL.md files, precise trigger descriptions, progressive disclosure, and testable behavior.
Critically review a workspace skill and suggest improvements.
Scan agent skills for security issues.
Universal consolidation & audit skill for Claude Code skills.
Audit skill configurations for correctness and freshness Audits all skill configurations, checks for stale or broken skills, and reports on overall skill health.
MySQL/MariaDB database inspection and queries.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them.
Security-first skill vetting for AI agents.
Security scanner for AgentSkill packages.
When the user wants to define, audit, or apply brand strategy—purpose, values, positioning, storytelling, voice, narrative (not only visuals…
When the user wants to design, optimize, or audit carousel/slider layouts for content display.
| 프로젝트 컨텍스트를 분석하여 project-local 스킬을 생성하는 워크플로우.
| 로드된 스킬 목록을 core(bkit 기본)와 project-local로 구분하여 표시.
Commit all changes, push to a new branch, and create a pull request using the repo's PR template.
Author SKILL.md skills: frontmatter, validator limits, structure.
Audit all Claude Code skills for stale references, broken paths, and deprecated tool names Audit .claude/skills/ for drift: broken file paths, missing scripts, and deprecated tool names.
Create a reusable SkillPack from a successful completed task.
Scan codebase for FIX:/NOTE:/TODO:/QUESTION: tags and create structured tasks with interactive selection.
Scan codebase for FIX:/NOTE:/TODO:/QUESTION: tags and create structured tasks with interactive selection.
Interactive repository analysis and project-overview.md generation via task creation.
Archive completed and abandoned tasks with CHANGE_LOG.md updates and memory harvest suggestions Direct execution skill for archiving tasks, updating CHANGE_LOG.md, and suggesting memory harvesting.
Audit skill metrics, file/resolve issues in memory/issues/, and notify on state change only <!-- autoresearch: variation C — more robust: me…
Audit skills, workflows, and companion scripts for injection, exfiltration, traversal, and prompt-override risks with delta tracking, baseli…
Audit every enabled skill's upstream file dependencies for staleness — flags chained skills about to consume yesterday's article or a long-d…
Weekly ranking of which skills are most popular across CONFIGURED Aeon forks (excludes untouched templates) <!-- autoresearch: variation B —…
Check imported skills for upstream changes and security regressions since the version in skills.lock <!-- autoresearch: variation B — sharpe…
Audit a ClawHub skill for security risks BEFORE installation.
Evaluates agent skills against Anthropic's best practices.
Repo-aware recommendation manager for ctx.
Audits skills in this repo for consistency, API drift, and structural gaps.
'Audit an existing SKILL.md against the unified AgentOps template (15 Use when ` markers OR `metadata.
Downloads skills from a AgentKit skill space to the local machine.
Registers a local skill to the AgentKit platform by uploading it.
Analyze skill effectiveness across sessions.
Scan agent skills for security issues before adoption.
Detect duplicate code and suggest DRY refactors using jscpd Detect duplicate code across your codebase using jscpd.
Safety Monitor Agent responsible for compliance and safety checks.
Uses the Vibesafe MCP server to scan, compile, test, save, diff, and report status for Vibesafe units.
Audit AI Agent skills for security vulnerabilities including malicious code, remote execution, credential leaks, and supply chain risks.
微信小程序全自动安全审计 Skill。
Use when publishing a SKILL.md-style agent skill across uGig, sh1pt, GitHub/gists, and follow-on skill marketplaces such as ClawHub, Goose, LobeHub, Kilo, Skillstore, FreeMyGent, ClawMart, Manus, VS Code Agent Skills, and Moltbook.
Implement the security design principle of secure system modification in [organization-defined].
> You are extracting domain knowledge for a library to produce a structured domain map.
Audit Skill() refs; detect hubs, isolates, and dangling targets.
Evaluate Claude skill quality through auditing.
Use when auditing a large local skill collection, identifying duplicate or imported skills, comparing skill roots, or deciding what to keep, disable, or archive across Codex and adjacent agent skill directories.
Evaluate Agent Skill design quality against official specifications and best practices.
Improve a SKILL.md to pass the skill-creator standard (quick_validate, frontmatter audit, ≤500 lines) AND the asm-eval 85/8 floor.
Add GitHub skill repos to the ASM index: clone, audit, eval, regenerate index, rebuild catalog, open PR.
OpenClaw Skills 全方位安全审计工具,检测供应链投毒、Prompt注入、恶意代码模式、权限越权和依赖风险 基于《OpenClaw 极简安全实践指南》和《安全验证与攻防演练手册》的 Skill 安全审计工具。
> <!-- SELFROUTINGBLOCK_START --> Task routes live in references/self-hosting-routing.yaml.
Sync skills between local installation and the GitHub source-of-truth repository.
Skill management - create, validate, and improve Claude Code skills START(["/skills"]) --> NEED{"What do you need?"} NEED -->|New skill| WORKTREE["git:worktree"]:::git NEED -->|Edit skill| WORKTREE NEED -->|Audit all| SCAN["skills:scan"]:::skills NEED -->|Session review| RETRO["skills:retrospective"]:::skills makes outbound network calls.
Scan a repository to bootstrap new skills or audit and update existing ones Bootstrap skills for a new repo, or audit and update skills in an existing one.
Amazon listing builder and optimizer for sellers.
Evaluates and optimizes skill file quality using 8 content patterns and 9 editing principles.
Updates model references across all skill files when new Claude models are released.
Audit the agent's own skill library for malicious, misconfigured, or untrusted SKILL.md files.
Step-by-step guide for creating your own Claude Skills, from deciding whether a skill is the right tool to writing the SKILL.md file, structuring reference material, and making it trigger reliably.
>- Read-only consistency audit across the skillshare codebase.
Use when the user wants to validate, lint, or audit agent skill files (SKILL.md).
> Scan and audit AI agent skills for security risks before installation.
AI-powered code review via roborev.
| 从先知社区5600+篇安全文档中提炼的漏洞挖掘核心思维框架。
Monitor blogs and RSS/Atom feeds for updates using the blogwatcher CLI.
Automate HappyCapy skill creation by finding and adapting existing skills from anthropics/skills repository.
Terraform and OpenTofu infrastructure as code — module design, state management, multi-environment setups, remote backends, secrets manageme…
Documenta projeto Power BI (PBIP) inteiro em markdown estruturado + HTML navegável (mini-site de doc).
飞书云空间文件管理。
Use when users ask how to write, explain, customize, migrate, secure, or troubleshoot GitHub Actions workflows, workflow syntax, triggers, m…
OCR, classify, and organize scanned PDFs into category subfolders using AI vision and language models.
Orchestrate sequential documentation audits with checkpointing and resumption.
Generates OpenAPI 3.0/3.1 specifications from Express, Next.js, Fastify, Hono, or NestJS routes.
Sync AI coding sessions from 14 tools (Claude Code, Codex, Cursor, Aider, Cline, Gemini CLI, Continue, Copilot, Roo Code, Windsurf, Zed AI, Amp, OpenCode, OpenRouter) to Obsidian vault as markdown notes.
Essential tools for using JAX in machine learning and mathematical analysis, covering core concepts, transformations, ML specifics, control flow, and parallelism.
PDF processing: extraction, text mining, form filling, manipulation, OCR integration This skill provides tools for PDF processing, including text extraction, mining, form filling, manipulation, and OCR integration, to handle document workflows efficiently.
ERNE — Validate and submit app builds using parallel expo-config-resolver and code-reviewer agents You are executing the /erne-deploy comman…
ERNE — Manual skill generation — runs continuous-learning-v2 scripts to extract patterns from session You are executing the /erne-learn comm…
Safety hooks for Claude Code — 700 pre-built hooks that prevent file deletion, credential leaks, git disasters, and token waste during auton…
Comprehensive, research-backed Hinge dating profile optimization.
Solve CTF reverse engineering challenges using systematic analysis to find flags, keys, or passwords.
Navigate codebases efficiently using structural indexes.
Migrates a project from Metabase Full App / Interactive (iframe-based) embedding to Modular (web-component-based) embedding.
Upgrades a project's Metabase Modular embedding SDK (@metabase/embedding-sdk-react) or Modular embedding (embed.js) version.
Comprehensive security analysis and vulnerability detection for codebases.
Audit state, docs drift, and stack best-practice compliance — works on any project Output this banner as the first thing on every invocation…
Optimize X/Twitter posts for maximum reach using algorithm insights.
Query Octopus observability platform — logs, alerts, traces, metrics, issues, services, LLM, RUM, events.
Enable ControlKeel governance for Cloudflare Agents with policy gates, budget enforcement, PII detection, and secure execution.
Analyze manufacturing defect detection and quality control systems — computer vision inspection pipelines, SPC control charts, Six Sigma pro…
Anton ADR lifecycle — author new architectural decision records, list existing ones by status or affects-category, and mark old decisions su…
Anton planner skill — author, update, and close multi-session initiatives (migrations, rollouts, long-running refactors) in `context/plans/`…
Audit interfaces for accessibility issues across semantics, keyboard use, focus management, color contrast, labels, and announcements.
Check whether backup and restore plans are actually restorable, verifiable, and operationally safe.
Gather code, config, docs, and operational proof points for audits and internal compliance reviews.
Docker 多服务部署最佳实践 - 遵循生产级 Dockerfile 和 Docker Compose 架构原则。
Turn implementation details into practical documentation such as README updates, setup guides, architecture notes, runbooks, changelogs, and internal reference docs.
Turn incident timelines, logs, tickets, and chat snippets into a clear postmortem covering impact, detection, root cause, contributing factors, remediation items, and prevention steps.
Use this skill whenever a user asks for OSINT dorks, Google dorks, GHDB queries, Shodan filters, GitHub code search dorks, search operators, or exposed asset discovery.
Review diffs like a senior engineer by checking correctness, architectural fit, style, missing tests, security smells, and migration or operational risk.
Audits Claude Code agent configuration against latest best practices.
Audit and score an agent-definition markdown such as `AGENTS.md`, `CLAUDE.md`, `SKILL.md`, `SOUL.md`, `.cursorrules`, or a system prompt using a cold-reader rubric for clarity, consistency, context independence, and operating-model fit.
Audit and trim AI agent instruction files (AGENTS.md, CLAUDE.md, CONVENTIONS.md, .cursorrules, etc.) by testing which facts an AI agent can discover from code alone.
End-to-end workflow for redesigning a SaaS or AI product landing page and building an interactive AI agent UX flow.
Swap tokens on Ethereum via the AIDEX aggregator.
Write unit and integration tests for Akka.NET actors using modern Akka.Hosting.TestKit patterns.
Scans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations, and access control issues.
Full-spectrum marketing and SEO skill library with 160+ specialist skills.
Atomic git workflow - validates, commits, pushes, creates PR, and verifies CI with zero-warnings policy.
Understand a codebase before looking for bugs in it - what each function assumes, what it guarantees, and what it depends on elsewhere.
Creates, updates, improves, and audits Agent Skills.
Use when the user mentions Swift performance audit, code optimization, or performance review.
Use when the user mentions SwiftUI performance, janky scrolling, slow animations, or view update issues.
Use when the user mentions flaky tests, tests that pass locally but fail in CI, race conditions in tests, or needs to diagnose WHY a specific test fails.
Use when the user mentions accessibility checking, App Store submission, code review, or WCAG compliance.
Use this agent to scan Swift code for camera, video, and audio capture issues including deprecated APIs, missing interruption handlers, threading violations, and permission anti-patterns.
Use when the user mentions Codable review, JSON encoding/decoding issues, data serialization audit, or modernizing legacy code.
Use when the user mentions concurrency checking, Swift 6 compliance, data race prevention, or async code review.
Use when the user mentions Core Data review, schema migration, production crashes, or data safety checking.
Use when the user mentions database schema review, migration safety, GRDB migration audit, or SQLite schema checking.
Use when the user mentions battery drain, energy optimization, power consumption audit, or pre-release energy check.
Use when the user mentions Foundation Models review, on-device AI audit, LanguageModelSession issues, @Generable checking, or Apple Intelligence integration review.
Use when the user mentions GRDB performance review, slow GRDB queries, app-group database setup audit, a ValueObservation that stopped updating, or pre-release GRDB scan.
Use when the user mentions in-app purchase review, IAP audit, StoreKit issues, purchase bugs, transaction problems, or subscription management.
Use when the user mentions iCloud sync issues, CloudKit errors, ubiquitous container problems, or asks to audit cloud sync.
Use when the user mentions memory leak prevention, code review for memory issues, or proactive leak checking.
Use when the user mentions networking review, deprecated APIs, connection issues, or App Store submission prep.
Use when the user mentions window resizing support, resizable-window readiness, iPhone Mirroring compatibility, scene-lifecycle migration checking, or preparing an app for the 27-cycle resizing model.
Use when the user wants to audit SpriteKit game code for common issues.
Use when the user mentions file storage issues, data loss, backup bloat, or asks to audit storage usage.
Use when the user mentions SwiftData review, @Model issues, SwiftData migration safety, or SwiftData performance checking.
Use when the user mentions SwiftUI architecture review, separation of concerns, testability issues, or "logic in view" problems.
Use when the user mentions SwiftUI layout review, adaptive layout issues, GeometryReader problems, or multi-device layout checking.
Use when the user mentions SwiftUI navigation issues, deep linking problems, state restoration bugs, or navigation architecture review.
Use when the user wants to audit test quality, find flaky test patterns, speed up test execution, or prepare for Swift Testing migration.
Use when the user mentions TextKit review, text layout issues, Writing Tools integration, or UITextView/NSTextView code review.
Use when the user mentions UX flow issues, dead-end views, dismiss traps, missing empty states, broken user journeys, or wants a UX audit of their iOS app.
Use when ANY iOS build fails, test crashes, Xcode misbehaves, or environment issue occurs before debugging code.
Use when ANY iOS build fails, test crashes, Xcode misbehaves, or environment issue occurs before debugging code.
Use when the user wants a comprehensive project-wide audit, full health check, or scan across all domains.
Use when the user wants to modernize iOS code to iOS 17/18 patterns, migrate from ObservableObject to @Observable, update @StateObject to @State, or adopt modern SwiftUI APIs.
Use when the user mentions slow builds, build performance, or build time optimization.
Use when the user mentions security review, App Store submission prep, Privacy Manifest requirements, hardcoded credentials, or sensitive data storage.
Use when storing credentials securely, encrypting data, implementing passkeys, securing AI/agentic features against prompt injection, code signing, or managing certificates and provisioning profiles.
Use when storing credentials securely, encrypting data, implementing passkeys, securing AI/agentic features against prompt injection, code signing, or managing certificates and provisioning profiles.
Use when storing credentials securely, encrypting data, implementing passkeys, securing AI/agentic features against prompt injection, code signing, or managing certificates and provisioning profiles.
Use when preparing ANY app for submission, handling App Store rejections, writing appeals, or managing App Store Connect.
Use when preparing ANY app for submission, handling App Store rejections, writing appeals, or managing App Store Connect.
Use when implementing ANY computer vision feature — image analysis, pose detection, person segmentation, subject lifting, text recognition,…
Use when implementing ANY computer vision feature — image analysis, pose detection, person segmentation, subject lifting, text recognition,…
Use when implementing ANY computer vision feature — image analysis, pose detection, person segmentation, subject lifting, text recognition,…
| Use when this capability is needed.
Searches and explores Burp Suite project files (.burp) from the command line.
Scans Cairo/StarkNet smart contracts for 6 critical vulnerabilities including felt252 arithmetic overflow, L1-L2 messaging issues, address conversion problems, and signature replay.
Audit a repository after large refactors, branch merges, or parallel agent threads for contradictions between implementation, docs, configs, tests, examples, comments, README guidance, and control files.
Python or Docker Use the upstream install or setup path that matches your environment: Requirements and caveats from upstream: Basic usage or getting-started notes: <!-- tomevault:4.0:skill_md:2026-05-22 -->; runs on Python.
Automates CI/CD pipeline setup.
Scaffold/audit GitHub Actions CI/CD — Go/Rust/TS.
Design and implement production-grade CI/CD pipelines with GitHub Actions, layered testing strategies, secure deployment patterns, and environment management.
CI/CD review for workflows, artifact safety, caching, deployment gates, secrets, permissions, and reproducibility.
GitHub Actions security hardening, CI/CD pipeline integrity, release security, and SSDF alignment Use when this capability is needed.
|- This skill helps you build LLM-powered applications with Claude.
Audit and improve project-memory artifacts (CLAUDE.md, AGENTS.md, .claude/rules/*.md, .claude.local.md).
Review code changes, diffs, commits, branches, or PRs for correctness, regressions, security-sensitive mistakes, maintainability issues, and missing validation before commit, PR, merge, or closeout.
Bridge between Claude Code and OpenAI Codex CLI - generates AGENTS.md from CLAUDE.md, provides Codex CLI execution helpers, and enables seamless interoperability between both tools Use when this capability is needed.
>- Use when this capability is needed.
>- Build competitor intelligence that can be shared, re-run, and audited later.
Generate and maintain AGENTS.md as a living project context document by scanning the repository, discovering agents/skills, and extracting conventions.
>- Use when this capability is needed.
Detects timing side-channel vulnerabilities in cryptographic code.
> Timing attacks exploit variations in execution time to extract secret information from cryptographic implementations.
Scans Cosmos SDK blockchain modules and CosmWasm contracts for consensus-critical vulnerabilities — chain halts, fund loss, state divergence…
Creates new Claude Code agent configuration files or audits existing ones in .claude/agents/.
Chief Security Officer mode.
Generate or review AGENTS.md and `.cursor/rules/*.mdc` for a repository Use when this capability is needed.
Invoke when user asks to do something with Cypilot, or wants to analyze/validate artifacts, or create/generate/implement anything using Cypilot workflows, or plan phased execution.
Organize DI registrations using IServiceCollection extension methods.
> Use when this capability is needed.
Diagnosis loop for hard bugs and performance regressions.
Annotates codebases with dimensional analysis comments documenting units, dimensions, and decimal scaling.
Run and triage Django/DRF security smoke checks for settings hardening, throttling, safe HTML, ORM race/idempotency patterns, and model integrity; especially useful before shipping or when evaluating djangoSecurityHunter-style findings.
Verification loop for Django projects: migrations, linting, tests with coverage, security scans, and deployment readiness checks before release or PR.
Apply fixes from a review.
Scans for project documentation files (AGENTS.md, CLAUDE.md, GEMINI.md, COPILOT.md, CURSOR.md, WARP.md, and 15+ other formats) and synthesizes guidance.
Create, refresh, or reconcile the repository root `AGENTS.md` using current branch truth.
Updates the README.md file to reflect the current state of the project.
| Use when this capability is needed.
| Use when this capability is needed.
Analyzes smart contract codebases to identify state-changing entry points for security auditing.
Verifies factual claims in documents using web search and official sources, then proposes corrections with user confirmation.
Use the upstream install or setup path that matches your environment: Requirements and caveats from upstream: Basic usage or getting-started notes: <!-- tomevault:4.0:skill_md:2026-05-22 -->; runs on Docker.
FastAPI patterns for async APIs, dependency injection, Pydantic request and response models, OpenAPI docs, tests, security, and production readiness.
Scans Android APKs for Firebase security misconfigurations including open databases, storage buckets, authentication issues, and exposed cloud functions.
Systematically verifies suspected security bugs to eliminate false positives, producing a TRUE POSITIVE or FALSE POSITIVE verdict with documented evidence for each.
One-command installer, credential configurator, and diagnostic layer for the full Gangtise (岗底斯投研) OpenAPI skill suite.
Smart Gemini CLI delegation skill.
Generate sandbox security policies from plain-language requirements and optional REST API documentation.
Machine learning toolkit for genomic interval (BED) data; use it when you need to tokenize BED collections and train embeddings for regions/cells/labels, build consensus peak universes, or run similarity search and downstream ML on chromatin accessibility datasets.
>- This skill guides you through safely removing sensitive data from a Git repository's history and pushing the cleaned history to GitHub.
在用户提及 GitHub 仓库、Issue、Pull Request、Actions、代码管理相关内容与操作时使用此技能。
Gitleaks is an open-source SAST tool for detecting hardcoded secrets like passwords, API keys, and tokens in Git repositories, files, and directories.
| Use when this capability is needed.
Verify Codex configuration health — AGENTS.md, hooks, config.toml, agents, skills, secrets scan, and MCP reachability.
Use this skill to audit, review, validate, or check the quality of AI assistant configurations including prompt text, prompt files, skills (SKILL.md), plugins, MCP servers, agents, hooks, memory files (AGENTS.md, CLAUDE.md, GEMINI.md), and composite configurations.
Operate the homelab platform — start/stop services, backups, updates, disaster-recovery, and Docker management.
Scan a codebase for deepening opportunities, present them as a visual HTML report, then grill through whichever one you pick.
Audit Copilot instruction files for bloat, overlap, stale rules, and weak applyTo scope.
Add Opik tracing to an existing codebase.
| Use when this capability is needed.
Assess the security posture of Kubernetes etcd clusters by evaluating encryption at rest, TLS configuration, access controls, backup encryption, and network isolation.
Auditing Kubernetes cluster RBAC configurations to identify overly permissive roles, wildcard permissions, dangerous ClusterRoleBindings, service account abuse, and privilege escalation paths using kubectl, rbac-tool, KubiScan, and Kubeaudit.
Perform security risk analysis on Kubernetes resource manifests using Kubesec to identify misconfigurations, privilege escalation risks, and deviations from security best practices.
Kubernetes cluster management skill.
> Use when this capability is needed.
Kubernetes penetration testing systematically evaluates cluster security by simulating attacker techniques against the API server, kubelet, etcd, pods, RBAC, network policies, and secrets.
Use when productionising or deploying a LangChain / LangGraph / DeepAgents agent.
Audit LangChain configuration and security Use when: "audit langchain, Use when this capability is needed.
When the user wants to audit, review, or diagnose SEO issues on their site.
>- Run a comprehensive, evidence-based health check of this Claude Code skills marketplace repo using a parallel fan-out Dynamic Workflow.
Guides C++ code toward modern idioms (C++20/23/26).
Use when diagnosing, operating, or standardizing Hub LLM OAuth refresh/reimport incidents for Claude Code OAuth, OpenAI Codex OAuth, Gemini OAuth, Gemini CLI OAuth, Gemini Code Assist service, and Groq pool readiness.
Agent-driven cold-start onboarding.
Run and audit OperatorOne Stage1 marketing SEO shadow experiments across input sync, context index, keyword graph, experiment synthesis, and Ready/Hold/Drop queueing.
This skill should be used when the user asks to "open source this project", "prepare this repository for public release", "make this repo public", "check open-source readiness", "choose a license for this project", or "set up release automation" ahead of a public launch.
Use when reviewing code for security vulnerabilities, implementing authentication/authorization, handling user input, or discussing web application security.
处理 PDF 文件:读取、修改、合并、抽内容都行。
Kubernetes penetration testing systematically evaluates cluster security by simulating attacker techniques against Use when this capability is needed.
>- Two related pipelines, same destination look, different starting point: phone photos of paper documents, or a digital document that needs a synthetic signature before it looks signed.
Scaffold a polyglot library project as TypeScript + Python twin packages under `packages/ts/` + `packages/py/`, with a shared `SPEC.md`, cross-language `tests/parity/fixtures.json`, side-by-side `examples/sdk/` + `examples/api/` documentation, per-package `Makefile`, and a root orchestrator that exposes `make ci`.
Quickly analyzes Python repositories to understand their purpose, structure, and setup requirements.
React Native mobile testing, performance, and release hardening for this repo.
Intelligent README.md generation prompt that analyzes project documentation structure and creates comprehensive repository documentation.
Safely package codebases with repomix by automatically detecting and removing hardcoded credentials before packing.
Evaluate the quality of existing agent instruction rule sets — CLAUDE.md, AGENTS.md, .cursorrules, copilot-instructions.md, or any coding-ag…
Set up Rust quality gates (cargo check/build, clippy, rustfmt, dead code, unused deps via cargo-machete, doc build, tests) in any Rust repo, wired through `prek` (pre-commit reimagined) with a `check.sh` orchestrator underneath.
| Use when this capability is needed.
>- You are a SARIF parsing expert.
Static Application Security Testing (SAST) for multi-language codebases.
Guides through Trail of Bits' 5-step secure development workflow.
Perform language and framework specific security best-practice reviews and suggest improvements.
>- Run a Semgrep scan with automatic language detection, parallel execution, and merged SARIF output.
Comprehensive software architecture skill for designing scalable, maintainable systems across web, mobile, and backend stacks (React, Next.js, Node/Express, React Native, Swift, Kotlin, Flutter, Postgres, GraphQL, Go, Python).
This skill should be used when the user asks to "design REST APIs", "optimize database queries", "implement authentication", "build microservices", "review backend code", "set up GraphQL", "handle database migrations", or "load test APIs".
Run a full SEO, AEO, and LLM discoverability audit on cc4.marketing Use when this capability is needed.
Run initial nano-core setup.
Ship current branch — CI, SonarCloud, code review, security review, fix all issues, merge.
Audits a Claude Code / Agent SDK skill (or folder of skills) against 10 QA Use when this capability is needed.
Reviews and improves Claude Code skills against official best practices.
Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing.
Use when a coding task is vague or under-specified.
Use this skill when the agent is designing schemas, reviewing migrations, tuning queries, modeling NoSQL access patterns, configuring replic…
Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin checks.
<!-- 🤖 【中文注释】 工具名称: 指令推荐助手 功能分类: 通用助手 功能说明: 用于推荐适合当前仓库的 Copilot 指令文件,避免重复并识别过时指令。
| Use when this capability is needed.
No source-backed install or usage instructions could be extracted automatically.
Scans TON (The Open Network) smart contracts for 3 critical vulnerabilities including integer-as-boolean misuse, fake Jetton contracts, and forward TON without gas checks.
Runs a Trailmark structural review gate over a branch, pull request, fix commit, release diff, or git ref range to detect new entrypoints, new tainted paths, removed validation or authorization calls, privilege-boundary drift, blast-radius growth, complexity growth, and newly reachable sensitive sinks.
Expands one confirmed or suspected vulnerability into a Trailmark graph neighborhood of variant candidates by finding sibling functions, shared callers and callees, common sensitive sinks, common entrypoint paths, interface implementations, override relationships, type/reference neighbors, and structurally similar nodes.
Hunts for the other instances of a bug already found — the variants of one root cause across a codebase.
>- Systematically evaluate incoming vulnerability reports against 7 principled criteria before committing resources to deeper analysis.
提供企业微信智能表格添加记录的正确操作方法,包括不同数据类型的处理格式。
Generate an interactive bash wizard that walks a human through steps only they can perform.
Writing, exploit; assemble raw material into a journey of beats, grounding each term before a beat leans on it.
Writing, exploit: shape raw material into an article, paragraph by paragraph.
Detects missing zeroization of sensitive data in source code and identifies zeroization removed by compiler optimizations, with assembly-level analysis, and control-flow verification.