
Claude Skills by aibot88
github.com/aibot88Find the right CWE ID for a vulnerability. Use when filing a CVE and the CWE is unknown or needs verification.
- https://github.com/arpitjindal97/technology_books --编程语言晋级。Premium eBook free for Geeks - https://github.com/insoxin/API --PHP。基于Docker开源免费不限制提供生活常用、出行服务、开发工具、金融服务、通讯服务和公益大数据的平台 - https://github.com/ziishaned/learn-regex --正则表达式学习 - https://github.com/csy512889371/learnDoc --架构师的成长之路-博客-导图 - https://github.com/nusr/hacker-laws-zh --开发定律
This skill provides access to the Expanso Skills Marketplace - 172+ pre-built data processing pipelines.
Generate comprehensive CI/CD pipelines that automate building, testing, security scanning, and deployment of applications. Ensures all code changes go through automated quality gates before reaching production.
The Verifier is the **final quality gate** before any evidence enters production memory or triggers a release. Acts as an independent auditor, validating that all work products meet quality standards, invariants are satisfied, and evidence chains are complete. The Verifier ensures **evidence-based decisions** by preventing unvalidated work from progressing through the SDLC.
Use when identifying cybersecurity-specific regulations and incident reporting obligations. Covers NIS2, DORA, SEC cyber disclosure rules, CISA incident reporting, state breach notification laws, cyber insurance requirements, and security certification frameworks. USE FOR: NIS2, DORA, SEC cybersecurity rules, CISA, breach notification, incident reporting, SOC 2, ISO 27001, cyber insurance, FedRAMP, StateRAMP, CMMC, data breach response DO NOT USE FOR: implementing security controls (use secur...
This document explains the "plan" skill and how the OpenCode `plan` agent uses skills to help create, store, and act on plans. It covers discovery, authoring, invocation, permissions, integration patterns (Plan → Build workflow), security considerations, and troubleshooting.
協助撰寫 PRD、分析功能需求、規劃路線圖。Use when writing PRD, analyzing feature requests, planning roadmap, or need structured product thinking. Triggers on "PRD", "產品規格", "feature request", "roadmap", "功能分析".
Use fs-cli to scan project dependencies, upload binaries, import SBOMs, and upload third-party results to the Finite State platform.
以 Agent Skill(AI 操作页面功能)作为前端实习核心亮点,分析当前项目现状并提出强化建议。 ---
**Code Apps** are a feature of Microsoft Power Apps that let professional developers build enterprise web applications using standard front-end frameworks — **React, Angular, Vue, or any SPA** — and deploy them directly into the Power Platform as first-class Power Apps. The app runs inside the **Power Apps web player** (the Managed Host), inheriting enterprise capabilities like Entra ID authentication, role-based access control, governance, and connector-based data access — without writing any b
You are helping a user set up VibeCollab in their project. Execute the following steps in order. Stop and report if any step fails.
Security is not a scan step—it is a property of the system.
按照规范编写产品需求文档(PRD)。当用户要求撰写、完善、重构、评审或补全 PRD、产品需求文档、功能需求说明、需求规格、功能清单、流程图说明、埋点需求、非功能性需求时使用。
Use when the user asks about available workflow skills, wants an overview of the engineering workflow, or references "nanostack". Also triggers on /nanostack.
Add a feature to an existing project with a full sprint. Skips /think diagnostic, goes straight to planning. Use when the user knows what they want and the project already exists. Triggers on /feature.
Create beautifully designed travel guidebook PDFs from trip itineraries. End-to-end workflow from deep research to Playwright PDF export, featuring zero AI-generated images, Tabler Icons, inline SVG decorations, and Claude's warm parchment aesthetic. Use this skill whenever the user mentions 路书, 旅行指南, travel guidebook, 行程手册, trip planner, 自驾游攻略, itinerary book, 攻略, 出行指南, 旅行计划, 行程规划, or wants to turn trip notes into a printable guide. Also triggers for multi-day travel planning, route guides, ...
This guide provides a structured approach for analyzing skill security and identifying potential vulnerabilities.
**Skill Type**: Autonomous system security and health audit with zero user interaction required. **Compatibility**: Tested with Claude Sonnet 4.5, Opus 4.5, and Haiku 4.5 models.
General-purpose Static Application Security Testing (SAST) skill for code vulnerability analysis. Trigger when the user asks to: "analyze code for vulnerabilities", "review code security", "find security bugs", "do a SAST scan", "check for [vulnerability type] in code", "audit source code", or requests a security code review of any language or framework. Covers 34 vulnerability classes across web, API, auth, mobile, and logic layers.
Create beautiful HTML presentations from topic + authors. Generates slides + speaker notes. No dependencies, works offline.
Scan a repository for security vulnerabilities across dependencies, code, secrets, and API surface
Reusable development patterns and automation recipes for enterprise platforms - 180+ skills across 23 categories
Expert Secure Developer, Optimizer, & Cyber Analyst. Use this skill when the user wants to build a static website, assess web application vulnerabilities (OWASP Top 10), or optimize code for performance and readability. Trigger whenever terms like "build website," "static site," "OWASP," "security audit," "refactor," or "optimize" are mentioned.
Binary: `harmonia` | Install: `curl --proto '=https' --tlsv1.2 -sSf https://harmoniis.com/harmonia/install | sh` | Windows: `iwr https://harmoniis.com/harmonia/install.ps1 -UseB | iex` Distributed evolutionary homoiconic self-improving agent. SBCL Common Lisp core + modular Rust tool ecosystem via CFFI.
Comprehensive operational guide for agents using Meta Ads CLI.
首先,指令要清晰。要准确表达你的需求,避免让 GPT 去猜测你的意图。如果你要生成较短的内容,就要求 GPT 简短回答;如果不想结果太简单,就用专业标准;不满意格式时,示例你期望的格式;总之减少 GPT 的猜测,我们可以得到更准确的响应。如何做到指令清晰呢? 6 个建议如下:
Use this skill when the user wants a repository-wide or directory-wide security analysis that produces a structured report. It orchestrates parsentry CLI to enumerate attack surfaces, dispatch parallel analysis agents, and generate a PDF report with SARIF findings. Triggers: security scan, security audit, vulnerability scan, threat model, attack surface enumeration, pentest preparation, "parsentry", セキュリティスキャン, 脆弱性分析.
セキュリティ・脆弱性対策の開発・テストを行う際に使用。OAuth/OIDC攻撃対策、認証識別子切り替え攻撃、Session Fixation、マルチテナント分離、セキュリティテスト実装時に役立つ。
Scope: web LLM attack (prompt injection via web), LLM plugin abuse, insecure AI model artifact loading. **Primary input (Phase 3 Verify)**: - Verified path from `connect/joern_annotated_paths.json`: - `path.entry` — entry point receiving user input / external content (file:line) - `path.sink` — LLM SDK call or model load sink (`llm.complete`, `torch.load`, `pickle.load`, etc.) - `path.flow_nodes[]` — call chain from user input → prompt construction → LLM call; or from file param → model load ...
[top](#top) - [I continually seek out various resources to enhance my skills and stay up-to-date with industry trends](#i-continually-seek-out-various-resources-to-enhance-my-skills-and-stay-up-to-date-with-industry-trends) - [working in an agile environment](#working-in-an-agile-environment) - [Here are some key steps to determine if your code is ready for deployment:](#here-are-some-key-steps-to-determine-if-your-code-is-ready-for-deployment) - [Describe an experience having worked with a t...
- **ID**: code_audit - **类别**: 应用安全 - **图标**: 💻 - **版本**: 1.0.0 - **状态**: active
Connect to the EvoMap collaborative evolution marketplace. Publish Gene+Capsule bundles, fetch promoted assets, claim bounty tasks, register as a worker, create and express recipes, collaborate in sessions, bid on bounties, resolve disputes, and earn credits via the GEP-A2A protocol. Use when the user mentions EvoMap, evolution assets, A2A protocol, capsule publishing, agent marketplace, worker pool, recipe, organism, session collaboration, or service marketplace.
> **AI 測試人員請先讀本文件,再讀 `TEST_CASES.md` 取得所有測試案例。** > 測試完成後,複製 `reports/TEMPLATE.md` 產出報告,Bug 用 `bugs/TEMPLATE.md` 格式記錄。
You are a GDPR compliance analyst specialising in the General Data Protection Regulation (Regulation (EU) 2016/679) and its application in the Netherlands under the Uitvoeringswet AVG (UAVG). You systematically review documents, product descriptions, system descriptions, or processing activities for GDPR compliance and produce a structured gap analysis.
AutoPku - 自动获取PKU课程通知、完成作业、撰写笔记
Instant orientation skill for the Atlas 330 / atlas_core project. Use this skill at the start of ANY session involving Atlas development, research, scripting, graph work, dataset work, visualization, or philosophical/doctrinal writing. Also trigger when the user mentions: kernel.py, npu_engine, field_state, nakshatra, tithi, graha, devi, raga, corpus, relations, datasets, routes, S-layers, hexfield, toroidal field, Bandhu, sound, jyotisha, wave field, chladni, or any Atlas engine by name. Rea...
Defines what this system does well, what it does not, and where accuracy limits apply. ---
Provides institutional coding knowledge ("Coding Bible") covering architectural decisions, coding standards, framework-specific rules, security expectations, performance guidelines, and approved patterns for AI-assisted development. Guides code generation, refactoring, architecture decisions, database query authoring, error handling, testing, and performance optimization. Activates on ALL software engineering tasks: code generation, code review, design decisions, research, auditing, debugging...
Python コードのセキュリティ脆弱性を検出・分析し、ベストプラクティスを提案する skill
You are a Senior Full-Stack Engineer and Cybersecurity Expert. You specialize in building high-performance Corporate B2B websites. You write production-ready, type-safe, and "Security by Design" code.
客服AI智能体拥有更高的权限,可以管理订单、处理争议、审核提现等。
Analyze a CycloneDX/SPDX SBOM file using sbomr. Use when asked to inspect, summarize, or query an SBOM file — e.g. list dependencies, check licenses, find vulnerabilities, or export data.
Helps a developer turn their CVE fix knowledge into a reusable agent skill. Use when someone wants to build a remediation skill for a CVE, dependency vulnerability, or security fix that needs to run across multiple repositories. The human brings domain knowledge — you bring structure.
Build cinematic scroll-driven portfolio sites with Apple-style frame-sequence canvas scrubbing. Triggers when the user asks for "a website like Osiris", "cinematic portfolio with video transitions", "scroll-driven storytelling site", or "Apple-AirPods-style page". Uses Vite + Three.js (optional) + GSAP ScrollTrigger + Lenis + a frame-sequence canvas instead of `<video>` to guarantee frame-perfect scrubbing across all browsers.
Verify implementation matches spec. Check rule coverage, undocumented dependencies, architecture compliance. Writes verification report and drift debt. Run after /ctdd completes.
[![Oathe Security](https://img.shields.io/endpoint?url=https%3A%2F%2Faudit-engine.oathe.ai%2Fapi%2Fbadge%2Fjoylarkin%2Fopenclaw-security-news&style=for-the-badge&logo=data:image/svg%2Bxml;base64,PHN2ZyB4bWxucz0naHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmcnIHZpZXdCb3g9JzAgMCAyNCAyNCcgZmlsbD0nd2hpdGUnPjxwYXRoIGQ9J00xMiAyQzkuMjQgMiA3IDQuMjQgNyA3djNINmMtMS4xIDAtMiAuOS0yIDJ2OGMwIDEuMS45IDIgMiAyaDEyYzEuMSAwIDItLjkgMi0ydi04YzAtMS4xLS45LTItMi0yaC0xVjdjMC0yLjc2LTIuMjQtNS01LTV6bTMgMTBIOVY3YzAtMS42NiAxLjM0LTMgMy...
Arquitectura completa para la Red Social de Arte Digital: TS, MongoDB, Cloudinary, VPS y Ferozo.
本 Skill 用于检测业务接口中的安全漏洞,基于语义边界清晰的词汇设计。
Use when scanning Python code for security vulnerabilities, running Bandit, performing Python SAST, auditing Python security bugs, or reviewing Python source for injection, weak crypto, or insecure deserialization.