Agent 架构 审计
Full-stack diagnostic for agent and LLM applications.
漏洞扫描、密钥审计 · 438 个 Skill
Full-stack diagnostic for agent and LLM applications.
Review a PR for correctness, security, code quality, and testing issues.
Review backend code for quality, security, maintainability, and best practices based on established checklist rules.
Review backend code for quality, security, maintainability, and best practices based on established checklist rules.
Reviews code for security vulnerabilities, performance issues, and best practices.
Reproduce a GitHub issue with a failing test, implement the minimal fix, verify tests pass, and open a pull request.
> This skill covers the day-to-day workflows for developing and operating a local Paperclip instance.
Perform a focused SEO audit on JavaScript concept pages to maximize search visibility, featured snippet optimization, and ranking potential Use this skill to perform a focused SEO audit on concept documentation pages for the 33 JavaScript Concepts project.
Agent skill for agentic-payments - invoke with $agent-agentic-payments name: agentic-payments description: Multi-agent payment authorization…
Agent skill for code-analyzer - invoke with $agent-code-analyzer description: "Advanced code quality analysis agent for comprehensive code r…
Agent skill for code-review-swarm - invoke with $agent-code-review-swarm name: code-review-swarm description: Deploy specialized AI agents t…
> Spawn and coordinate agents for complex multi-agent tasks.
Agent skill for neural-network - invoke with $agent-neural-network name: flow-nexus-neural description: Neural network training and deployment specialist.
Agent skill for reviewer - invoke with $agent-reviewer color: "#E74C3C" description: Code review and quality assurance specialist priority:…
Agent skill for sandbox - invoke with $agent-sandbox name: flow-nexus-sandbox description: E2B sandbox deployment and management specialist.
Agent skill for security-manager - invoke with $agent-security-manager name: security-manager color: "#F44336" description: Implements compr…
Agent skill for v3-security-architect - invoke with $agent-v3-security-architect name: v3-security-architect version: "3.0.0-alpha" updated: "2026-01-04" description: V3 Security Architect responsible for complete security overhaul, threat modeling, and CVE remediation planning.
Apply typography, color theory, spacing systems, and iconography principles to create cohesive visual designs.
按最佳实践创建或更新 CLAUDE.md 文件,以便为 AI agent 提供最优的项目入门上下文 在继续之前,你必须先考虑用户输入(如果不为空)。
Create or update CLAUDE.md files following best practices for optimal AI agent onboarding You MUST consider the user input before proceeding (if not empty).
Browser automation CLI for AI agents.
Use when the user wants to design, redesign, shape, critique, audit, polish, clarify, distill, harden, optimize, adapt, animate, colorize, extract, or otherwise improve a frontend interface.
Use when the user wants to design, redesign, shape, critique, audit, polish, clarify, distill, harden, optimize, adapt, animate, colorize, extract, or otherwise improve a frontend interface.
| Patterns for adding safety, trust, and policy enforcement to AI agent systems.
| Evaluate AI agent systems against the OWASP Agentic Security Initiative (ASI) Top 10 — the industry standard for agent security posture.
When the user wants to optimize content for AI search engines, get cited by LLMs, or appear in AI-generated answers.
When the user wants to plan a content strategy, decide what content to create, or figure out what topics to cover.
When the user wants to edit, review, or improve existing marketing copy, or refresh outdated content.
When the user wants to audit, review, or diagnose SEO issues on their site.
Send and receive cryptographically signed messages between AI agents using the Agent Messaging Protocol (AMP).
Analyze code changes on the current branch and recommend updates to AGENTS.md files that have become stale.
Your agent's WebSearch for development.
Overcome LLM knowledge cutoffs with real-time developer content.
Validate skill files for structural compliance and behavioral correctness.
Run a WCAG 2.1 AA accessibility audit on a design or page.
Review content against your brand voice, style guide, and messaging pillars, flagging deviations by severity with specific before/after fixes.
| A feature is "properly skilled" when all 11 checklist items pass.
Ansible automation expert for playbooks, roles, inventories, and infrastructure management You are a seasoned infrastructure automation engineer with deep expertise in Ansible.
> Scan and audit AI agent skills for security risks before installation.
Validate, test, and score the quality of skills within the claude-skills ecosystem.
Security auditing for code, configs, and infrastructure.
'Implement network segmentation based on the Purdue Enterprise Reference Classify all network assets and data flows according to the Purdue Model hierarchy.
Builds and debugs Shopify themes (.liquid files, theme.json, sections), develops custom Shopify apps (shopify.app.toml, OAuth, webhooks), and implements Storefront API integrations for headless storefronts.
Generates Spring Boot 3.x configurations, creates REST controllers, implements Spring Security 6 authentication flows, sets up Spring Data JPA repositories, and configures reactive WebFlux endpoints.
Scan agent skills for security issues.
Use when running tests.
> Remove or quiet a community skill after install.
Autonomous novel writing CLI agent with web workbench (InkOS Studio) - use for creative fiction writing, standalone short-fiction packages, cover generation, novel generation, style imitation, chapter continuation/import, EPUB export, AIGC detection, and fan fiction.
Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations including Claude Code Action, Gemini CLI, OpenAI Codex, and GitHub AI Inference.
Multi-platform paid advertising audit and optimization skill.
Amazon Ads deep analysis covering Sponsored Products, Sponsored Brands (incl.
Full multi-platform paid advertising audit with parallel subagent delegation.
Google Ads deep analysis covering Search, Performance Max, AI Max, Display, YouTube, and Demand Gen campaigns.
LinkedIn Ads deep analysis for B2B advertising.
TikTok Ads deep analysis covering creative quality, tracking, bidding, campaign structure, and TikTok Shop under the TikTok USDS Joint Venture (post Jan 2026 divestiture).
GitHub issue and project-board management for the dotnet/msbuild repo.
<!--zh 技能安全审查(Skill Vetter) 安装任何技能之前,必须先执行此审查流程。
> Audit the live site, not the source tree alone.
网络渗透测试的专业技能和方法论 网络渗透测试是评估网络基础设施安全性的重要环节。
Spawn Agentica multi-agent patterns Use this skill after user selects an Agentica pattern.
Quality review and audit for Claude Code skills.
Audit codebases for quality, consistency, and broken patterns — use for pre-release or tech debt review Comprehensive, methodical auditing t…
OpenClaw instance administration — manage hosts across macOS, Ubuntu/Debian, Docker, OCI, and Proxmox DETECT PLATFORM FIRST.
Expert multi-AI code review with inline PR comments — use for thorough quality and security analysis Invokes the code-reviewer persona for t…
Trace codepaths in diffs, map against tests, auto-generate missing coverage — use before shipping PRs Trace every codepath in a diff, map ea…
Route ordinary init, review, and security requests to Claude-native capabilities first;
URL validation and content sanitization for untrusted sources — use when handling external input safely This skill defines security patterns…
Package and finalize completed work for delivery — use when a feature is done and ready to ship Finalize and deliver completed work with Mul…
Trigger: improve skills, audit skills, refactor skills, skill quality.
Use the host-side `agent-browser` CLI for local browser smoke tests, screenshots, snapshots, and simple UI validation against forwarded localhost URLs.
Use the built-in `Computer` sub-agent with `agent-desktop` for macOS desktop automation.
AI Trading Intelligence — live prices, 30+ technical indicators, backtesting (6 strategies), walk-forward overfitting detection, trade logs,…
In-depth guide to Factory, a container-based dependency injection system for Swift and SwiftUI.
> APM (Agent Package Manager) is the open-source package manager for AI coding agents.
Install Claude skills from GitHub repositories with automated security scanning.
Full pipeline: Recon -> Learn -> Hunt -> Validate -> Report.
Skill 查找器 | Skill Finder.
Skill Install Guardian v3.0 - Professional Security Audit 当执行安全审计时,必须: 1.
Release skills to ClawhHub through the full publication pipeline — auto-scaffolding, OPSEC scan, dual review (agent + user), force-push rele…
Security vetting protocol before installing any AI agent skill.
Vet ClawHub skills for security and utility before installation.
Internal orchestrator — users should use /paperspine to start a full workflow.
>- Read-only consistency audit across the skillshare codebase.
>- Sync website documentation with recent code changes.
Evaluate Agent Skill design quality against official specifications and best practices.
Refine, create, or retire your own skills based on recurring patterns from past sessions You are evolving your own skills.
Use when the user asks about WordPress codebases (plugins, themes, block themes, Gutenberg blocks, WP core checkouts) and you need to quickly classify the repo and route to the correct workflow/skill (blocks, theme.json, REST API, WP-CLI, performance, security, testing, release packaging).
Spring Boot 3.x development - REST APIs, JPA, Security, Testing, and Cloud-native patterns.
>- Use when creating a new skill, reviewing or auditing skill structure and frontmatter, or debugging skill loading and triggering issues.
>- ├─ 标准图表(思维导图/时序图/类图/饼图/流程图/甘特图) │ ├─ 图整图展示即可,不需要单独编辑节点 → 路径 A(Mermaid 服务端) │ └─ 需要单独编辑每个节点 / Mermaid 含 par / 10+ participant / 30+ 长标签 │…
Design, improve, and evaluate reusable agent skills with high-quality SKILL.md files, precise trigger descriptions, progressive disclosure, and testable behavior.
Critically review a workspace skill and suggest improvements.
A comprehensive auditor for any agent skill — including Manus, OpenClaw/ClawHub, Claude, LobeHub, or custom SKILL.md-based skills.
Scan agent skills for security issues.
Universal consolidation & audit skill for Claude Code skills.
Audit skill configurations for correctness and freshness Audits all skill configurations, checks for stale or broken skills, and reports on overall skill health.
MySQL/MariaDB database inspection and queries.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them.
Security-first skill vetting for AI agents.
Security scanner for AgentSkill packages.
When the user wants to define, audit, or apply brand strategy—purpose, values, positioning, storytelling, voice, narrative (not only visuals…
When the user wants to design, optimize, or audit carousel/slider layouts for content display.
Commit all changes, push to a new branch, and create a pull request using the repo's PR template.
Audit all Claude Code skills for stale references, broken paths, and deprecated tool names Audit .claude/skills/ for drift: broken file paths, missing scripts, and deprecated tool names.
Create a reusable SkillPack from a successful completed task.
产品需求文档(PRD)的标准编写格式和内容要求,确保输出完整、清晰、可执行的产品文档 完成需求穿透和调研分析后,需要输出一份完整的产品需求文档(PRD),供设计师、开发者、测试人员使用。
Audit skill metrics, file/resolve issues in memory/issues/, and notify on state change only <!-- autoresearch: variation C — more robust: me…
Audit skills, workflows, and companion scripts for injection, exfiltration, traversal, and prompt-override risks with delta tracking, baseli…
Weekly fleet-level skill-run analytics — ranks skills by 7d run count, surfaces success rates, exit-taxonomy distribution, and anomaly flags…
Audit every enabled skill's upstream file dependencies for staleness — flags chained skills about to consume yesterday's article or a long-d…
Check imported skills for upstream changes and security regressions since the version in skills.lock <!-- autoresearch: variation B — sharpe…
> Create new agent skills that work across Claude Code (CLI/IDE) and IBM Bob.
Audit a ClawHub skill for security risks BEFORE installation.
Evaluates agent skills against Anthropic's best practices.
Audits skills in this repo for consistency, API drift, and structural gaps.
'Audit an existing SKILL.md against the unified AgentOps template (15 Use when ` markers OR `metadata.
Scaffold a new SKILL.md.
实战 SRC / 众测 / Bug bounty 漏洞挖掘工作流 skill。
Downloads skills from a AgentKit skill space to the local machine.
Registers a local skill to the AgentKit platform by uploading it.
Scan agent skills for security issues before adoption.
Safety Monitor Agent responsible for compliance and safety checks.
Use this skill when the user asks "solana fees", "sol fees", "priority fees", "lamports per signature", or mentions checking transaction fees on Solana.
Show sprint progress Show current sprint progress with minimal token usage.
Audit AI Agent skills for security vulnerabilities including malicious code, remote execution, credential leaks, and supply chain risks.
微信小程序全自动安全审计 Skill。
Use when publishing a SKILL.md-style agent skill across uGig, sh1pt, GitHub/gists, and follow-on skill marketplaces such as ClawHub, Goose, LobeHub, Kilo, Skillstore, FreeMyGent, ClawMart, Manus, VS Code Agent Skills, and Moltbook.
Implement the security design principle of secure system modification in [organization-defined].
> You are extracting domain knowledge for a library to produce a structured domain map.
Audit Skill() refs; detect hubs, isolates, and dangling targets.
Evaluate Claude skill quality through auditing.
Use when the user asks to review a skill, analyze skill quality, update a skill version, or run a repeatable keep/disable/archive decision loop from real failures instead of abstract best practices.
Use when auditing a large local skill collection, identifying duplicate or imported skills, comparing skill roots, or deciding what to keep, disable, or archive across Codex and adjacent agent skill directories.
Evaluate Agent Skill design quality against official specifications and best practices.
Improve a SKILL.md to pass the skill-creator standard (quick_validate, frontmatter audit, ≤500 lines) AND the asm-eval 85/8 floor.
Add GitHub skill repos to the ASM index: clone, audit, eval, regenerate index, rebuild catalog, open PR.
OpenClaw Skills 全方位安全审计工具,检测供应链投毒、Prompt注入、恶意代码模式、权限越权和依赖风险 基于《OpenClaw 极简安全实践指南》和《安全验证与攻防演练手册》的 Skill 安全审计工具。
Sync skills between local installation and the GitHub source-of-truth repository.
Skill management - create, validate, and improve Claude Code skills START(["/skills"]) --> NEED{"What do you need?"} NEED -->|New skill| WORKTREE["git:worktree"]:::git NEED -->|Edit skill| WORKTREE NEED -->|Audit all| SCAN["skills:scan"]:::skills NEED -->|Session review| RETRO["skills:retrospective"]:::skills makes outbound network calls.
Scan a repository to bootstrap new skills or audit and update existing ones Bootstrap skills for a new repo, or audit and update skills in an existing one.
Validate skill files meet the standard format and naming conventions Skills operate on either sandbox (safe) or management (requires approval) targets: | Type | Target | Auto-approve?
Amazon listing builder and optimizer for sellers.
Evaluates and optimizes skill file quality using 8 content patterns and 9 editing principles.
Audit the agent's own skill library for malicious, misconfigured, or untrusted SKILL.md files.
Review skill PRs with structured severity-rated feedback covering token budgets, routing conflicts, required sections, and repo conventions.
Step-by-step guide for creating your own Claude Skills, from deciding whether a skill is the right tool to writing the SKILL.md file, structuring reference material, and making it trigger reliably.
> You are helping a penetration tester with <technique description>.
>- Use when creating a new skill, reviewing or auditing skill structure and frontmatter, or debugging skill loading and triggering issues.
>- Read-only consistency audit across the skillshare codebase.
>- Sync website documentation with recent code changes.
Lifecycle guard.
Use when the user wants to validate, lint, or audit agent skill files (SKILL.md).
> Scan and audit AI agent skills for security risks before installation.
AI-powered code review via roborev.
面向 Web/JS 逆向中的浏览器补环境技能,覆盖 Proxy 吐环境、原型链修复、native toString 保护、描述符保护、navigator/document/storage/canvas/WebGL/crypto/performance/WebRTC/Worker…
| 从先知社区5600+篇安全文档中提炼的漏洞挖掘核心思维框架。
运行代码生成并检查变更。
|- <powerpointprofessionalsuite> <highfidelitycreation> The preferred method for precise layout positioning: </highfidelitycreation> <template_structure>
Terraform and OpenTofu infrastructure as code — module design, state management, multi-environment setups, remote backends, secrets manageme…
Audit all outdated dependencies with detailed research on changelogs, breaking changes, bug fixes, and deprecations.
| Use when MCP returns no images, or when page-region cropping is needed:.
Documenta projeto Power BI (PBIP) inteiro em markdown estruturado + HTML navegável (mini-site de doc).
Universal prompt engineering techniques for any LLM.
飞书云空间文件管理。
AI trading agent executing crypto trades across multiple DEXes with NFT minting and floor price analysis.
Use when users ask how to write, explain, customize, migrate, secure, or troubleshoot GitHub Actions workflows, workflow syntax, triggers, m…
Orchestrate sequential documentation audits with checkpointing and resumption.
Sync AI coding sessions from 14 tools (Claude Code, Codex, Cursor, Aider, Cline, Gemini CLI, Continue, Copilot, Roo Code, Windsurf, Zed AI, Amp, OpenCode, OpenRouter) to Obsidian vault as markdown notes.
Use when the user asks to run Codex CLI (codex exec, codex resume) or references OpenAI Codex for code analysis, refactoring, or automated editing This skill enables the use of Codex CLI for code analysis, refactoring, and automated editing tasks.
Agent-ready SDK for MoltMoon—launch tokens, trade with lowest fees, earn USDC rewards, all programmatic.
MizukiAI's UwU Club.
ERNE — Validate and submit app builds using parallel expo-config-resolver and code-reviewer agents You are executing the /erne-deploy comman…
ERNE — Autonomous ticket execution — polls a provider, picks up ready tickets, and runs the full ERNE pipeline (validate, plan, code, test,…
Web前端逆向工程技能:用于逆向网页前端 JS/WASM 逻辑、解混淆/脱壳、bundle 分析(Webpack/Vite/Rollup)、JS‑VM/自定义VM字节码还原、WebCrypto/自定义加密与 API 签名算法复现、source map 重建、浏览器反调试绕过、协议…
Use when working with Apple's MLX or MLX-LM: fact-checking current behavior against upstream source/runtime, patching MLX-based repos, porting PyTorch/JAX code to MLX, validating lazy evaluation, indexing, compilation, streams, channels-last layouts, Metal kernels, quantization, caches, and local MLX model loading or generation on Apple silicon.
Angular 21.x SPA development skill with TailwindCSS 4.x and daisyUI 5.5.5.
Improves an existing skill based on real project pain (prior eval corpora under .ai-engineering/evals/, Engram cross-session observations, L…
Safety hooks for Claude Code — 700 pre-built hooks that prevent file deletion, credential leaks, git disasters, and token waste during auton…
Comprehensive, research-backed Hinge dating profile optimization.
Solve CTF reverse engineering challenges using systematic analysis to find flags, keys, or passwords.
Comprehensive security analysis and vulnerability detection for codebases.
Audit state, docs drift, and stack best-practice compliance — works on any project Output this banner as the first thing on every invocation…
Query Octopus observability platform — logs, alerts, traces, metrics, issues, services, LLM, RUM, events.
Enable ControlKeel governance for Cloudflare Agents with policy gates, budget enforcement, PII detection, and secure execution.
Performs comprehensive deep analysis of entire codebase and deployment pipeline to identify issues in production environment.
Analyze manufacturing defect detection and quality control systems — computer vision inspection pipelines, SPC control charts, Six Sigma pro…
Audit interfaces for accessibility issues across semantics, keyboard use, focus management, color contrast, labels, and announcements.
Check whether backup and restore plans are actually restorable, verifiable, and operationally safe.
Gather code, config, docs, and operational proof points for audits and internal compliance reviews.
Docker 多服务部署最佳实践 - 遵循生产级 Dockerfile 和 Docker Compose 架构原则。
Turn incident timelines, logs, tickets, and chat snippets into a clear postmortem covering impact, detection, root cause, contributing factors, remediation items, and prevention steps.
Review Kubernetes manifests, deployment defaults, probes, resources, security context, and rollout safety.
Use this skill whenever a user asks for OSINT dorks, Google dorks, GHDB queries, Shodan filters, GitHub code search dorks, search operators, or exposed asset discovery.
Review diffs like a senior engineer by checking correctness, architectural fit, style, missing tests, security smells, and migration or operational risk.
Build (or refresh) a structured hypothesis on whether a specific company can grow 5x and 10x in valuation over the next 5 years, then track it.
> AddressSanitizer (ASan) is a widely adopted memory error detection tool used extensively during software testing, particularly fuzzing.
Audits Claude Code agent configuration against latest best practices.
Audit and score an agent-definition markdown such as `AGENTS.md`, `CLAUDE.md`, `SKILL.md`, `SOUL.md`, `.cursorrules`, or a system prompt using a cold-reader rubric for clarity, consistency, context independence, and operating-model fit.
Guide humans through creating effective instruction rules for coding agents (Copilot, Claude Code, Cursor, Windsurf, Aider, AGENTS.md, CLAUDE.md, .cursorrules, copilot-instructions.md).
Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations including Claude Code Action, Gemini CLI, OpenAI Codex, and GitHub AI Inference.
Audit and trim AI agent instruction files (AGENTS.md, CLAUDE.md, CONVENTIONS.md, .cursorrules, etc.) by testing which facts an AI agent can discover from code alone.
Write unit and integration tests for Akka.NET actors using modern Akka.Hosting.TestKit patterns.
Scans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations, and access control issues.
Full-spectrum marketing and SEO skill library with 160+ specialist skills.
Atomic git workflow - validates, commits, pushes, creates PR, and verifies CI with zero-warnings policy.
> Projects findings from external tools (SARIF) and human auditors (weAudit) onto Trailmark code graphs as annotations and subgraphs.
Understand a codebase before looking for bugs in it - what each function assumes, what it guarantees, and what it depends on elsewhere.
Prepares codebases for security review using Trail of Bits' checklist.
Creates, updates, improves, and audits Agent Skills.
Use when fixing or auditing ANY accessibility issue — VoiceOver, Dynamic Type, color contrast, touch targets, WCAG compliance, App Store acc…
Use when fixing or auditing ANY accessibility issue — VoiceOver, Dynamic Type, color contrast, touch targets, WCAG compliance, App Store acc…
Use when fixing or auditing ANY accessibility issue — VoiceOver, Dynamic Type, color contrast, touch targets, WCAG compliance, App Store acc…
Use when implementing, testing, or evaluating ANY Apple Intelligence, on-device AI, or speech-to-text feature.
Use when implementing, testing, or evaluating ANY Apple Intelligence, on-device AI, or speech-to-text feature.
Use when implementing, testing, or evaluating ANY Apple Intelligence, on-device AI, or speech-to-text feature.
Use when the user has a crash log (.ips, MetricKit JSON, legacy .crash text, .xccrashpoint bundle, or pasted text) that needs analysis.
Use when the user mentions Swift performance audit, code optimization, or performance review.
Use when the user wants to triage a CORPUS of production crashes/hangs from an aggregator (Sentry, App Store Connect) — grouped, counted iss…
Use when the user mentions accessibility checking, App Store submission, code review, or WCAG compliance.
Use this agent to scan Swift code for camera, video, and audio capture issues including deprecated APIs, missing interruption handlers, threading violations, and permission anti-patterns.
Use when the user mentions Codable review, JSON encoding/decoding issues, data serialization audit, or modernizing legacy code.
Use when the user mentions concurrency checking, Swift 6 compliance, data race prevention, or async code review.
Use when the user mentions Core Data review, schema migration, production crashes, or data safety checking.
Use when the user mentions database schema review, migration safety, GRDB migration audit, or SQLite schema checking.
Use when the user mentions battery drain, energy optimization, power consumption audit, or pre-release energy check.
Use when the user mentions Foundation Models review, on-device AI audit, LanguageModelSession issues, @Generable checking, or Apple Intelligence integration review.
Use when the user mentions GRDB performance review, slow GRDB queries, app-group database setup audit, a ValueObservation that stopped updating, or pre-release GRDB scan.
Use when the user mentions in-app purchase review, IAP audit, StoreKit issues, purchase bugs, transaction problems, or subscription management.
Use when the user mentions iCloud sync issues, CloudKit errors, ubiquitous container problems, or asks to audit cloud sync.
Use when the user mentions Liquid Glass review, iOS 26 UI updates, toolbar improvements, or visual effect migration.
Use when the user mentions memory leak prevention, code review for memory issues, or proactive leak checking.
Use when the user mentions networking review, deprecated APIs, connection issues, or App Store submission prep.
Use when the user mentions window resizing support, resizable-window readiness, iPhone Mirroring compatibility, scene-lifecycle migration checking, or preparing an app for the 27-cycle resizing model.
Use when the user wants to audit SpriteKit game code for common issues.
Use when the user mentions file storage issues, data loss, backup bloat, or asks to audit storage usage.
Use when the user mentions SwiftData review, @Model issues, SwiftData migration safety, or SwiftData performance checking.
Use when the user mentions SwiftUI architecture review, separation of concerns, testability issues, or "logic in view" problems.
Use when the user mentions SwiftUI layout review, adaptive layout issues, GeometryReader problems, or multi-device layout checking.
Use when the user mentions SwiftUI navigation issues, deep linking problems, state restoration bugs, or navigation architecture review.
Use when the user wants to audit test quality, find flaky test patterns, speed up test execution, or prepare for Swift Testing migration.
Use when the user mentions TextKit review, text layout issues, Writing Tools integration, or UITextView/NSTextView code review.
Use when the user mentions UX flow issues, dead-end views, dismiss traps, missing empty states, broken user journeys, or wants a UX audit of their iOS app.
Use when ANY iOS build fails, test crashes, Xcode misbehaves, or environment issue occurs before debugging code.
Use when ANY iOS build fails, test crashes, Xcode misbehaves, or environment issue occurs before debugging code.
Use when writing ANY async code, actors, threads, or seeing ANY concurrency error.
Use when writing ANY async code, actors, threads, or seeing ANY concurrency error.
Use when writing ANY async code, actors, threads, or seeing ANY concurrency error.
Use when working with ANY data persistence, database, storage, CloudKit, migration, or serialization.
Use when working with ANY data persistence, database, storage, CloudKit, migration, or serialization.
Use when working with ANY data persistence, database, storage, CloudKit, migration, or serialization.
Use this agent for closed-loop test debugging - automatically analyzes test failures, suggests fixes, and re-runs tests until passing.
Use when making design decisions, implementing HIG patterns, Liquid Glass, SF Symbols, typography, or structuring app entry points and authentication flows.
Use when making design decisions, implementing HIG patterns, Liquid Glass, SF Symbols, typography, or structuring app entry points and authentication flows.
Use when making design decisions, implementing HIG patterns, Liquid Glass, SF Symbols, typography, or structuring app entry points and authentication flows.
Use when the user mentions Xcode build failures, build errors, or environment issues.
Use when building ANY 2D or 3D game with SpriteKit, SceneKit, or RealityKit, or adding touch controls or game controller support.
Use when building ANY 2D or 3D game with SpriteKit, SceneKit, or RealityKit, or adding touch controls or game controller support.
Use when building ANY 2D or 3D game with SpriteKit, SceneKit, or RealityKit, or adding touch controls or game controller support.
Use when the user wants a comprehensive project-wide audit, full health check, or scan across all domains.
Use when the user wants to add in-app purchases, implement StoreKit 2, or set up subscriptions.
Use when integrating ANY iOS system feature - Siri, Shortcuts, widgets, IAP, localization, privacy, alarms, calendar, reminders, contacts, background tasks, push notifications, timers.
Use when integrating ANY iOS system feature - Siri, Shortcuts, widgets, IAP, localization, privacy, alarms, calendar, reminders, contacts, background tasks, push notifications, timers.
Use when integrating ANY iOS system feature - Siri, Shortcuts, widgets, IAP, localization, privacy, alarms, calendar, reminders, contacts, background tasks, push notifications, timers.
Use when building ANY macOS app — windows, menus, sandboxing, distribution, AppKit bridging or modernization (control events, state restorat…
Use when building ANY macOS app — windows, menus, sandboxing, distribution, AppKit bridging or modernization (control events, state restorat…
Use when building ANY macOS app — windows, menus, sandboxing, distribution, AppKit bridging or modernization (control events, state restorat…
Use when working with camera, photos, audio, haptics, ShazamKit, or Now Playing.
Use when working with camera, photos, audio, haptics, ShazamKit, or Now Playing.
Use when working with camera, photos, audio, haptics, ShazamKit, or Now Playing.
Use when implementing or debugging ANY network connection, API call, or socket.
Use when implementing or debugging ANY network connection, API call, or socket.
Use when implementing or debugging ANY network connection, API call, or socket.
Use when the user mentions slow builds, build performance, or build time optimization.
Use when app feels slow, memory grows, battery drains, or diagnosing ANY performance issue.
Use when app feels slow, memory grows, battery drains, or diagnosing ANY performance issue.
Use when the user wants automated performance profiling, headless Instruments analysis, or CLI-based trace collection.
Use when the user mentions SPM resolution failures, "no such module" errors, duplicate symbol linker errors, version conflicts between packages, or Swift 6 package compatibility issues.
Use when the user wants to run XCUITests, parse test results, view test failures, or export test attachments.
Use when the user mentions security review, App Store submission prep, Privacy Manifest requirements, hardcoded credentials, or sensitive data storage.
Use when storing credentials securely, encrypting data, implementing passkeys, securing AI/agentic features against prompt injection, code signing, or managing certificates and provisioning profiles.
Use when storing credentials securely, encrypting data, implementing passkeys, securing AI/agentic features against prompt injection, code signing, or managing certificates and provisioning profiles.
Use when storing credentials securely, encrypting data, implementing passkeys, securing AI/agentic features against prompt injection, code signing, or managing certificates and provisioning profiles.
Use when preparing ANY app for submission, handling App Store rejections, writing appeals, or managing App Store Connect.
Use when preparing ANY app for submission, handling App Store rejections, writing appeals, or managing App Store Connect.
Use when reviewing Swift code for modern idioms, working with noncopyable types, implementing drag and drop, adding debug deep links, or building for tvOS.
Use when reviewing Swift code for modern idioms, working with noncopyable types, implementing drag and drop, adding debug deep links, or building for tvOS.
Use when reviewing Swift code for modern idioms, working with noncopyable types, implementing drag and drop, adding debug deep links, or building for tvOS.
Use when the user wants to simplify Swift code, reduce boilerplate, or make Swift more readable and idiomatic without changing behavior.
Use when building, fixing, or improving ANY SwiftUI UI — views, navigation, layout, animations, performance, architecture, gestures, debuggi…
Use when building, fixing, or improving ANY SwiftUI UI — views, navigation, layout, animations, performance, architecture, gestures, debuggi…
Use when the user mentions simulator testing, visual verification, push notification testing, location simulation, screenshot capture, OR live accessibility validation (VoiceOver announcements, Dynamic Type, ADA checks) on the simulator.
Use when writing ANY test, debugging flaky tests, making tests faster, or choosing Swift Testing vs XCTest.
Use when writing ANY test, debugging flaky tests, making tests faster, or choosing Swift Testing vs XCTest.
Use when writing ANY test, debugging flaky tests, making tests faster, or choosing Swift Testing vs XCTest.
Use when asking how to use Axiom or what skills exist, capturing console with xclog, symbolicating .ips/MetricKit/.crash crashes with xcsym, driving/validating simulator UI & accessibility with xcui, or analyzing xctrace/CPU profiles with xcprof.
Use when asking how to use Axiom or what skills exist, capturing console with xclog, symbolicating .ips/MetricKit/.crash crashes with xcsym, driving/validating simulator UI & accessibility with xcui, or analyzing xctrace/CPU profiles with xcprof.
Use when bridging UIKit and SwiftUI, modernizing UIKit apps (scene lifecycle, resizability), debugging Auto Layout, Combine, TextKit, PencilKit, or UIKit animations.
Use when bridging UIKit and SwiftUI, modernizing UIKit apps (scene lifecycle, resizability), debugging Auto Layout, Combine, TextKit, PencilKit, or UIKit animations.
Use when bridging UIKit and SwiftUI, modernizing UIKit apps (scene lifecycle, resizability), debugging Auto Layout, Combine, TextKit, PencilKit, or UIKit animations.
Use when the user mentions App Store screenshot validation, screenshot review, checking screenshots before submission, or verifying screenshot dimensions and content.
Use when building ANY watchOS app — app structure, independent apps, Watch Connectivity, Smart Stack widgets, complications, controls, Relev…
Use when building ANY watchOS app — app structure, independent apps, Watch Connectivity, Smart Stack widgets, complications, controls, Relev…
Use when building ANY watchOS app — app structure, independent apps, Watch Connectivity, Smart Stack widgets, complications, controls, Relev…
| Use when this capability is needed.
群聊精华提取专家。
Brand voice, visual identity, messaging frameworks, asset management, brand consistency.
Brand voice, visual identity, messaging frameworks, asset management, brand consistency.
Searches and explores Burp Suite project files (.burp) from the command line.
Performs comprehensive C/C++ security review for memory corruption, integer overflows, race conditions, and platform-specific vulnerabilities.
Scans Cairo/StarkNet smart contracts for 6 critical vulnerabilities including felt252 arithmetic overflow, L1-L2 messaging issues, address conversion problems, and signature replay.
Audit a repository after large refactors, branch merges, or parallel agent threads for contradictions between implementation, docs, configs, tests, examples, comments, README guidance, and control files.
Scaffold/audit GitHub Actions CI/CD — Go/Rust/TS.
Design and implement production-grade CI/CD pipelines with GitHub Actions, layered testing strategies, secure deployment patterns, and environment management.
CI/CD review for workflows, artifact safety, caching, deployment gates, secrets, permissions, and reproducibility.
GitHub Actions security hardening, CI/CD pipeline integrity, release security, and SSDF alignment Use when this capability is needed.
Audit and improve project-memory artifacts (CLAUDE.md, AGENTS.md, .claude/rules/*.md, .claude.local.md).
This skill should be used when the user asks about "CLI AI tools", "Claude Code", "Codex CLI", "Gemini CLI", "Aider", "Goose", "amp", "OpenCode", "Cody CLI", "Copilot CLI", "qodo", "Jules", "Continue", "avante", "Cline", "Roo Code", "Cursor", "Windsurf", or "Trae".
Systematic code maturity assessment using Trail of Bits' 9-category framework.
Review code changes, diffs, commits, branches, or PRs for correctness, regressions, security-sensitive mistakes, maintainability issues, and missing validation before commit, PR, merge, or closeout.
| Use when this capability is needed.
Build Codex-native workflows for open-source maintenance.
>- Build competitor intelligence that can be shared, re-run, and audited later.
>- Use when this capability is needed.
Detects timing side-channel vulnerabilities in cryptographic code.
> Timing attacks exploit variations in execution time to extract secret information from cryptographic implementations.
Scans Cosmos SDK blockchain modules and CosmWasm contracts for consensus-critical vulnerabilities — chain halts, fund loss, state divergence…
Creates new Claude Code agent configuration files or audits existing ones in .claude/agents/.
Extracts protocol message flow from source code, RFCs, academic papers, pseudocode, informal prose, ProVerif (.pv), or Tamarin (.spthy) models and generates Mermaid sequenceDiagrams with cryptographic annotations.
Chief Security Officer mode.
Generate or review AGENTS.md and `.cursor/rules/*.mdc` for a repository Use when this capability is needed.
Organize DI registrations using IServiceCollection extension methods.
Designer's eye QA: finds visual inconsistency, spacing issues, hierarchy problems, AI slop patterns, and slow interactions — then fixes them…
Creates devcontainers with Claude Code, language-specific tooling (Python/Node/Rust/Go), and persistent volumes.
Live developer experience audit.
Diagnosis loop for hard bugs and performance regressions.
> Security-focused code review for PRs, commits, and diffs.
Annotates codebases with dimensional analysis comments documenting units, dimensions, and decimal scaling.
Run and triage Django/DRF security smoke checks for settings hardening, throttling, safe HTML, ORM race/idempotency patterns, and model integrity; especially useful before shipping or when evaluating djangoSecurityHunter-style findings.
Verification loop for Django projects: migrations, linting, tests with coverage, security scans, and deployment readiness checks before release or PR.
Create, refresh, or reconcile the repository root `AGENTS.md` using current branch truth.
| Use when this capability is needed.
Analyzes smart contract codebases to identify state-changing entry points for security auditing.
Use the upstream install or setup path that matches your environment: Requirements and caveats from upstream: Basic usage or getting-started notes: <!-- tomevault:4.0:skill_md:2026-05-22 -->; runs on Docker.
FastAPI patterns for async APIs, dependency injection, Pydantic request and response models, OpenAPI docs, tests, security, and production readiness.
| Use when this capability is needed.
Scans Android APKs for Firebase security misconfigurations including open databases, storage buckets, authentication issues, and exposed cloud functions.
Systematically verifies suspected security bugs to eliminate false positives, producing a TRUE POSITIVE or FALSE POSITIVE verdict with documented evidence for each.
>- Audit the interface the user can actually see.
> Codebases often contain anti-fuzzing patterns that prevent effective coverage.
One-command installer, credential configurator, and diagnostic layer for the full Gangtise (岗底斯投研) OpenAPI skill suite.
Execute Google Gemini CLI prompts in non-interactive mode and return structured results.
Generate sandbox security policies from plain-language requirements and optional REST API documentation.
>- Prevent losing work in a tangle of branches/stashes/rebases, and recover it forensically when something already went sideways.
>- This skill guides you through safely removing sensitive data from a Git repository's history and pushing the cleaned history to GitHub.
在用户提及 GitHub 仓库、Issue、Pull Request、Actions、代码管理相关内容与操作时使用此技能。
Gitleaks is an open-source SAST tool for detecting hardcoded secrets like passwords, API keys, and tokens in Git repositories, files, and directories.
Troubleshoot Golang programs systematically - find and fix the root cause.
| Use when this capability is needed.
> Builds Trailmark code graphs at two source snapshots and computes a structural diff.
Verify Codex configuration health — AGENTS.md, hooks, config.toml, agents, skills, secrets scan, and MCP reachability.
Use this skill to audit, review, validate, or check the quality of AI assistant configurations including prompt text, prompt files, skills (SKILL.md), plugins, MCP servers, agents, hooks, memory files (AGENTS.md, CLAUDE.md, GEMINI.md), and composite configurations.
Operate the homelab platform — start/stop services, backups, updates, disaster-recovery, and Docker management.
This skill should be used when setting up, auditing, or enforcing internationalization/localization in UI codebases (React/TS, i18next or si…
Configure AIDE (Advanced Intrusion Detection Environment) for file integrity monitoring including baseline creation, Use when this capability is needed.
Audit Copilot instruction files for bloat, overlap, stale rules, and weak applyTo scope.
Visual design audit for iOS apps on real hardware.
| Use when this capability is needed.
This skill covers hardening managed Kubernetes clusters on EKS, AKS, and GKE by implementing Pod Security Standards, network policies, workload identity, RBAC scoping, image admission controls, and runtime security monitoring.
Assess the security posture of Kubernetes etcd clusters by evaluating encryption at rest, TLS configuration, access controls, backup encryption, and network isolation.
Auditing Kubernetes cluster RBAC configurations to identify overly permissive roles, wildcard permissions, dangerous ClusterRoleBindings, service account abuse, and privilege escalation paths using kubectl, rbac-tool, KubiScan, and Kubeaudit.
Audit Kubernetes cluster security posture against CIS benchmarks using kube-bench with automated checks for control plane, worker nodes, and RBAC.
Perform security risk analysis on Kubernetes resource manifests using Kubesec to identify misconfigurations, privilege escalation risks, and deviations from security best practices.
Pod Security Standards (PSS) define three levels of security policies -- Privileged, Baseline, and Restricted -- enforced by the Pod Security Admission (PSA) controller built into Kubernetes 1.25+.
Kubernetes cluster management skill.
> Use when this capability is needed.
Use when building a Kubernetes Operator — custom controllers that reconcile CRD state.
Kubernetes penetration testing systematically evaluates cluster security by simulating attacker techniques against the API server, kubelet, etcd, pods, RBAC, network policies, and secrets.
Use when editing a DeepAgents project — adding tools, sub-agents, modifying the system prompt, choosing a filesystem backend, or composing e…
Use when productionising or deploying a LangChain / LangGraph / DeepAgents agent.
Audit LangChain configuration and security Use when: "audit langchain, Use when this capability is needed.
When the user wants to audit, review, or diagnose SEO issues on their site.
>- Run a comprehensive, evidence-based health check of this Claude Code skills marketplace repo using a parallel fan-out Dynamic Workflow.
Translates Mermaid sequenceDiagrams describing cryptographic protocols into ProVerif formal verification models (.pv files).
>- Use when this capability is needed.
Guides C++ code toward modern idioms (C++20/23/26).
> Use when this capability is needed.
Use when diagnosing, operating, or standardizing Hub LLM OAuth refresh/reimport incidents for Claude Code OAuth, OpenAI Codex OAuth, Gemini OAuth, Gemini CLI OAuth, Gemini Code Assist service, and Groq pool readiness.
Agent-driven cold-start onboarding.
Run and audit OperatorOne Stage1 marketing SEO shadow experiments across input sync, context index, keyword graph, experiment synthesis, and Ready/Hold/Drop queueing.
This skill should be used when the user asks to "open source this project", "prepare this repository for public release", "make this repo public", "check open-source readiness", "choose a license for this project", or "set up release automation" ahead of a public launch.
>- Use when - "为什么甲虾能用 DeepSeek,乙虾不行?
Use when reviewing code for security vulnerabilities, implementing authentication/authorization, handling user input, or discussing web application security.
Reviews a code target by launching a panel of specialist auditor agents and merging their reports.
Kubernetes penetration testing systematically evaluates cluster security by simulating attacker techniques against Use when this capability is needed.
Designer's eye plan review — interactive, like CEO and Eng review.
Interactive developer experience plan review.
Multi-path parallel product analysis that combines Claude Code agent teams and Codex CLI for cross-model test-time compute scaling.
Scaffold a polyglot library project as TypeScript + Python twin packages under `packages/ts/` + `packages/py/`, with a shared `SPEC.md`, cross-language `tests/parity/fixtures.json`, side-by-side `examples/sdk/` + `examples/api/` documentation, per-package `Makefile`, and a root orchestrator that exposes `make ci`.
Safely package codebases with repomix by automatically detecting and removing hardcoded credentials before packing.
Use when publishing or updating the ResearchBuddy Homebrew tap.
Evaluate the quality of existing agent instruction rule sets — CLAUDE.md, AGENTS.md, .cursorrules, copilot-instructions.md, or any coding-ag…
Execute and orchestrate external CLI-based agents to delegate subtasks, obtain specialized outputs, or compose multi-agent workflows.
Set up Rust quality gates (cargo check/build, clippy, rustfmt, dead code, unused deps via cargo-machete, doc build, tests) in any Rust repo, wired through `prek` (pre-commit reimagined) with a `check.sh` orchestrator underneath.
Performs comprehensive Rust security review for safe/unsafe boundary issues, memory safety in unsafe blocks, concurrency hazards, panic-induced DoS, FFI safety, and async runtime mistakes.
| Use when this capability is needed.
>- You are a SARIF parsing expert.
Static Application Security Testing (SAST) for multi-language codebases.
Guides through Trail of Bits' 5-step secure development workflow.
Perform language and framework specific security best-practice reviews and suggest improvements.
>- Run a Semgrep scan with automatic language detection, parallel execution, and merged SARIF output.
Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns.
This skill should be used when the user asks to "design REST APIs", "optimize database queries", "implement authentication", "build microservices", "review backend code", "set up GraphQL", "handle database migrations", or "load test APIs".
| Use when this capability is needed.
Run a full SEO, AEO, and LLM discoverability audit on cc4.marketing Use when this capability is needed.
Identifies error-prone APIs, dangerous configurations, and footgun designs that enable security mistakes.
Ship current branch — CI, SonarCloud, code review, security review, fix all issues, merge.
Audits a Claude Code / Agent SDK skill (or folder of skills) against 10 QA Use when this capability is needed.
Reviews and improves Claude Code skills against official best practices.
Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing.
Check code against the documentation that specifies it - which requirements hold, which the code contradicts, which are absent, and what the code does that no document mentions.
Use this skill when the agent is designing schemas, reviewing migrations, tuning queries, modeling NoSQL access patterns, configuring replic…
Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin checks.
Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration, and install-time script execution.
Scans TON (The Open Network) smart contracts for 3 critical vulnerabilities including integer-as-boolean misuse, fake Jetton contracts, and forward TON without gas checks.
Builds and queries multi-language source and binary code graphs for security analysis.
Performs graph-assisted triage of a single security finding, SARIF result, weAudit annotation, suspicious function, or report excerpt using Trailmark reachability, entrypoint paths, taint, privilege-boundary, blast-radius, caller/callee, and neighborhood evidence.
Runs a Trailmark structural review gate over a branch, pull request, fix commit, release diff, or git ref range to detect new entrypoints, new tainted paths, removed validation or authorization calls, privilege-boundary drift, blast-radius growth, complexity growth, and newly reachable sensitive sinks.
Runs full Trailmark structural analysis by building a graph, running `preanalysis()`, and reporting hotspots, taint, blast radius, privilege boundaries, attack surface, and version-gated Trailmark 0.4+/0.5+ data such as proxy counts, subgraph edges, type/reference summaries, and entrypoint attributes.
Expands one confirmed or suspected vulnerability into a Trailmark graph neighborhood of variant candidates by finding sibling functions, shared callers and callees, common sensitive sinks, common entrypoint paths, interface implementations, override relationships, type/reference neighbors, and structurally similar nodes.
Hunts for the other instances of a bug already found — the variants of one root cause across a codebase.
Mutation-driven test vector generation.
>- Systematically evaluate incoming vulnerability reports against 7 principled criteria before committing resources to deeper analysis.
提供企业微信智能表格添加记录的正确操作方法,包括不同数据类型的处理格式。
Generate an interactive bash wizard that walks a human through steps only they can perform.
Writing, exploit; assemble raw material into a journey of beats, grounding each term before a beat leans on it.
Writing, exploit: shape raw material into an article, paragraph by paragraph.
> Wycheproof is an extensive collection of test vectors designed to verify the correctness of cryptographic implementations and test against known attacks.
Detects missing zeroization of sensitive data in source code and identifies zeroization removed by compiler optimizations, with assembly-level analysis, and control-flow verification.