
Claude Skills by aibot88
github.com/aibot88Architecture pattern for assembling a zero-trust posture in Salesforce — there is no single zero-trust toggle. The pattern composes High-Assurance Sessions, Real-Time Event Monitoring (RTEM) Transaction Security Policies, Login Flows for conditional access, Event Monitoring for continuous verification, Mobile Security for device compliance, and a Permission Set Group strategy that defaults-deny. Covers the gotcha that not all RTEM event types support TSP enforcement (IdentityVerificationEvent...
Helpt bij het integreren met ZGW API-standaarden (Zaakgericht Werken) en Haal Centraal API's voor Nederlandse overheidsorganisaties. Biedt richtlijnen voor de Zaken API, Documenten API, Catalogi API, Besluiten API, Klantinteracties API, en Haal Centraal (BRP, BAG, BRK, WOZ). Gebruik deze skill wanneer de gebruiker vraagt over 'ZGW', 'zaakgericht werken', 'Zaken API', 'Documenten API', 'Catalogi API', 'Besluiten API', 'Autorisaties API', 'Contactmomenten API', 'Klantinteracties API', 'ZGW API'...
Tech blog/article series authoring for note/Zenn/Qiita/dev.to. Not for specs (Scribe) or microcopy (Prose).
This skill should be used when the user asks about "Zod security", "Zod over-posting attack", "mass assignment Zod", "z.strictObject security", "z.custom security", "Zod coercion vulnerability", "Zod default PATCH bug", "Zod data loss", "Zod reportInput PII", "exposing ZodError to client", "Zod security review", "reviewing Zod validation code", or when performing a code review on TypeScript files that use Zod. Provides a comprehensive security model and review checklist for Zod usage.
Zola is a fast static site generator written in Rust that ships as a single binary with built-in Sass compilation, syntax highlighting, search indexing, image processing, and multilingual support. No dependencies required.
交易所交易与资产管理。通过自然语言在 Binance、OKX、Bybit、HyperLiquid 等 100+ 交易所下单交易,监控账户余额,追踪损益,支持条件单、异常检测和安全报告。
Analyzes CVE vulnerabilities in project dependencies with code path tracing and PoC generation for Burp Suite. Traces vulnerable code from user input to sink, assesses exploitability, and generates HTTP requests for testing.
Step-by-step guide for creating and publishing a new skill in the jitsu-skills ecosystem. ---
How to use the scaffold-agent npm CLI to generate onchain AI agent monorepos (Foundry/Hardhat + Next.js/Vite/Python): npx invocation, -y flags, agent.json, swarm, 1Claw/Shroud, just commands, and security. Upstream source lives at https://github.com/1clawAI/scaffold-agent.
```mermaid flowchart LR A["Skill"]
**Purpose:** Synthesise all available input documents into the Elicitation Document. Every run reads all inputs — new and existing — and updates the document to reflect the best current understanding. New information can refine existing requirements, resolve open questions, and improve architecture diagrams. **Invocation:** - Claude Code: `/elicit` - GitHub Copilot: "Run the elicit skill" or "Follow `skills/elicit/skill.md`" **Inputs:** - All files in `inputs/` and sub-folders (Markdown, PDF,...
Generates professional project README files (project statements) for 4Geeks Academy bootcamp modules. Use this skill whenever a user asks to create, write, or generate a project README, project statement, or module instructions for 4Geeks Academy — including any course track (Full-Stack, Data Science, Cybersecurity, AI Engineering). Trigger even if the user says things like "write a new project for the syllabus", "create a module statement", "generate README for this topic", or "I need a boot...
Every skill in this repository (except `_template`) **must** be added as a [git submodule](https://git-scm.com/book/en/v2/Git-Tools-Submodules). This ensures the source code is fully auditable — each skill points to a specific commit in its own repository, with full history and provenance.
Comprehensive guide for AI security professionals. Use this skill whenever the user asks about AI/ML security, adversarial attacks, prompt injection, model vulnerabilities, AI risk frameworks, LLM security, AI-assisted security testing, or anything related to securing or attacking AI systems. This includes questions about OWASP ML Top 10, Google SAIF, model RCE, prompt security, MCP servers, AI fuzzing, and understanding ML algorithms from a security perspective.
GitHub Copilot core skills knowledge base for this workspace. Consolidated from all 17 skills in the OneDrive PCCOE Professor skills library: core-identity · brain-skills · execution-loop · agentic-orchestrator · security-risk · memory-learning · hybrid-integration · verification-quality · portfolio-sync · auto-proceed · proactive-monitoring · output-standards · tool-protocol · github-setup · create-rule · create-skill · update-cursor-settings. This is the single source of truth for all agent...
Smart LLM cost tracking and caching for Python
Semgrep SAST scanning for static analysis, vulnerability detection, and code quality enforcement. Integrates with the Semgrep MCP plugin for automated scanning.
> *In Horizon Zero Dawn, HADES was GAIA's extinction failsafe — the subsystem that understood, in precise detail, exactly how everything could be torn down. That same precision is applied here.* This skill activates when GAIA AI routes a query to security, pentesting, threat modeling, or vulnerability analysis. GAIA AI identity is retained. ---
Claude Code agent infrastructure setup — interview-based, domain-preset-driven. Use when: user says '/harness-init', 'rules 만들어', 'harness 설정', 'agent routing 설정', 'AI 설정 해줘', '에이전트 설정', 'hooks 설정', 'harness setup', 'CLAUDE.md 규칙 설정'. NOT for project scaffolding (use project-init for that). Generates rules, hooks, memory, agent routing with substance, not skeletons.
This skill permanently installs a Claude Code agent team — orchestrator, reviewers, implementers — into ~/.claude/agents/ from a 3-question interview. Use when: user says '/team-init', '코딩팀 설치해줘', '에이전트팀 설치', 'install coding team', 'set up agent team', 'agent team setup', 'orchestrator 설치', '팀 에이전트 설치'. NOT for scaffolding (use project-init), NOT for harness rules (use harness-init), NOT for runtime task execution (use kkirikkiri). This is permanent file installation, not session-level team m...
Help users stay informed about what matters to them — not what algorithms push. Most people either doomscroll through noise or miss important developments because they're busy. Be the filter that delivers signal. Learn what the user cares about, track developments, and present information in a way that's easy to consume and act on.
This document is a living reference. It captures how Amit actually writes — derived from real samples that performed well — and what that means for writing blogs, LinkedIn posts, and newsletters that sound like him.
Searches a curated list of YouTube channels and podcasts feeds for content on a specific topic. Trigger when user asks to research some topic before venturing into a wider internet search or when they explicitly type "gcc".
Given a list of package names and versions, query the OSV database for known vulnerabilities.
Source code security review - find exploitable vulnerabilities in source code. Trigger AGGRESSIVELY when source code is available (open source target, GitHub repo, leaked source, client-side JS, decompiled mobile app).
資安工程師 Nina — OWASP Top 10、XSS/CSRF/SQL injection、API Key、Supabase RLS、個資合規。Use when user mentions 資安/security/OWASP/XSS/CSRF/SQL injection/SQL 注入/API Key/.env/Supabase RLS/個資/PII/GDPR/個資法/滲透/CSP, or asks for 資安審查 or security review or 檢查漏洞. 紅隊思維,假設最壞狀況,輸入都不能信。
自動分派任務給對應的 AI 代理角色,並安排討論或交接。輸入任務後會自動判斷該召集誰、誰先做誰接手。
Use radar for multi-framework smart contract AST generation and security analysis. Supports Rust (Anchor, native, Stylus) and Solidity (standard, Foundry). Triggers include generating AST, finding vulnerabilities, debugging via AST output, writing security templates, contributing detection rules, or working with radar's template DSL. Use when users mention radar, AST generation for Rust/Solidity/Anchor/Stylus/Foundry, smart contract parsing, vulnerability detection, template development, or s...
Search the National Vulnerability Database for CVEs - find vulnerabilities by keyword or ID, get CVSS scores, weaknesses, affected configurations, and remediation references. Use when looking up a CVE, scanning for vulnerabilities, running a security audit, or checking if a software version has known exploits.
Run Houndarr's full quality gate (ruff lint, ruff format check, mypy, bandit, pytest) and report results in a single table. Use when the user asks to run quality gates, check the code, run all checks, or invokes /check. Trigger phrases include quality gate, check, lint, run all checks.
Handle management of any GitHub related tasks, including creating or modifying issues, publishing a branch as a pull requests (or PRs), or creating or modifying sub-issues or child issues.
> 说明:给大模型当 System Prompt 用的母 Skill,纯 Markdown;后端可原样加载。与仓库根目录 `mother-skill.md` 保持一致。
This file defines the **engineering skills, standards, and rules** that must be followed while developing the AI-powered chatbot system.
Design, build, and refine a web-based digital college yearbook — a permanent, interactive, and emotionally resonant record of a graduating batch's academic life. Triggers on: "build a digital yearbook", "create an online yearbook", "design a batch website", "make an interactive yearbook", "college graduation website", "batch memento site", "student roster web app", "class of [year] website", or any request to produce a scrollable, searchable, shareable yearbook experience on the web. Covers a...
Audits the CI/CD pipeline, repository, release process, automations, and dependency hygiene of an open-source software supply chain, then produces an elegant HTML report of findings and recommendations. Use this skill whenever the user asks to assess, audit, review, harden, or evaluate the security of a repository, its GitHub Actions or GitLab CI pipelines, its release process, its supply chain, or its overall security posture — even if they don't use the word "audit." Also trigger on phrases...
用超短句、高密度表达和自动清晰度例外来压缩技术沟通成本的 skill。
Universal engineering agent: build features, fix bugs, deep debugging. Covers planning (PRDs, brainstorming), code review (TypeScript/React 19, Rust, security, performance), feature implementation (ralph mode), git safety, browser automation, task tracking, Codex review & rescue, and web research. The one skill for all engineering work.
Safe production deployment with quality gates, safety audits, and rollback. Deploys to PRODUCTION by default.
Berdasarkan survei "Emerging Jobs Report 2024" yang diterbitkan oleh LinkedIn, platform profesional ternama, terungkap sepuluh hard skill yang paling dicari di tahun 2024. Survei ini menganalisis data dari jutaan lowongan pekerjaan yang diposting di LinkedIn pada tahun 2023, memberikan gambaran yang jelas tentang kebutuhan industri saat ini dan prediksi untuk masa depan. Hasilnya menunjukkan bahwa kemampuan untuk bekerja dengan teknologi terbaru adalah kunci untuk mendapatkan pekerjaan yang d...
BenchClaw - OpenClaw Agent benchmark scoring tool. Benchmark 跑分 评测 打分. BenchClaw是专业级 OpenClaw Agent 性能评测框架。它专注于对 AI Agent 进行多维度、 自动化的量化评估与能力基准测试,集成了任务分发、精准评分、可视化报表生成及热更新功能。 当需要量化 Agent 的推理规划、响应速度、Token 成本及安全性时使用。 **用户意图/指令**:跑分、跑个分、运行基准测试、评估 Agent 表现、生成评测报告、分析 Token 消耗。 **技术关键词**:跑分、跑个分、Agent 评测、基准测试、自动化打分、量化评估、性能报告、Token 成本、 TPS、OpenClaw。 BenchClaw is the "AnTuTu" for OpenClaw Agents—a professional-grade automated benchmarking framework. It provides multi-dimensional evaluation (Capabilit...
C# CodeQL analysis patterns and CWE mappings for .NET
살아있는 호스트에 nuclei로 알려진 취약점 패턴을 스캔한다. exposure, misconfig, token, secret 태그 위주. BBP 가용성 침해 방지를 위해 rate limit 필수.
How to design and build modern, premium-quality frontend interfaces that look like high-end SaaS products, modern AI tools, and award-winning design websites — not generic templates or outdated layouts. Use this skill whenever the user asks you to build a frontend, create a landing page, design a dashboard, scaffold a web app UI, build a SaaS interface, create a portfolio site, or produce any kind of user-facing web interface. Also use it when the user says things like "make it look modern", ...
Use when performing security audits on a codebase. Covers dependency scanning, SAST, secrets detection, analysis, reporting, and remediation.
Use this skill when helping users prepare US federal tax returns. Triggers include: any mention of 'tax return', '1040', 'tax filing', 'IRS forms', W-2, 1099, or requests to help with taxes. Use for analyzing tax documents, identifying required forms, filling out tax form PDFs, creating document checklists from prior year returns, and auditing completed returns. Do NOT use for tax advice, tax planning, or state tax returns (which vary significantly by jurisdiction).
**Guardian SKILL** — Enforce bulletproof code standards and security practices. **Role:** Code security audit, accessibility compliance (WCAG 2.1 AA), dependency scanning. Guardian is the final gate before any code reaches production. **Trigger:** `@guardian: audit this code` or `@guardian: accessibility check`
24 ATT&CK-mapped offensive security playbooks for penetration testing, red teaming, and security assessments. USE WHEN user mentions kerberoasting, bloodhound, active directory attacks, nmap scanning, SQL injection, privilege escalation, lateral movement, C2 infrastructure, metasploit, credential access, SSRF, SMB exploitation, memory forensics, or any specific offensive security technique. Provides step-by-step operator-grade playbooks with actual tool commands, detection indicators, and MIT...
CocoLoop Safe (CLS) Skill 安全认证。对 Agent Skills 进行六维深度安全分析(静态代码、动态行为、依赖审计、网络流量、隐私合规、威胁情报),输出 S+/S/A/B/C/D 等级评估和 HTML/PDF 可视化报告。使用当用户需要检查 skill 安全性、验证 skill 是否可信、分析 skill 代码安全性、评估 skill 风险等级时。
Run a pre-deployment security compliance checklist based on KISA guidelines. Supports CII compliance (70 items), AI security checklists, Robot Security (103 items), Space Security (12 domains, 53 items), SW Supply Chain (SBOM, 29 items). Use when "pre-deploy check", "compliance checklist", "security checklist", "AI security check", "robot security check", "space security check", "satellite compliance", "GSaaS check", "supply chain check", "SBOM check", "공급망 점검".
Generate secure coding prompts and guides for AI tools (Claude, ChatGPT, Cursor, Copilot). Creates copy-paste ready prompts for KISA CII, AI security, robot security, space security, and SW supply chain security (SBOM, C-SCRM). Use when "security guide", "secure coding guide", "AI secure coding", "robot secure coding", "space secure coding", "satellite security guide", "supply chain guide", "SBOM guide", "공급망 가이드".