
Claude Skills by aibot88
github.com/aibot88Check if recent cybersecurity alerts from 10 international CERTs affect your current project. Use when the user asks about security vulnerabilities, CVEs, "is my project affected", "any new security alerts", "check for vulnerabilities", "cyberowlai", or "/cyberowlai". Also trigger when the user is working on dependency updates, Dockerfile changes, security audits, or any security-related task — even if they don't explicitly mention CyberOwl AI. Trigger on questions like "should I update my de...
Scans your project and tells you which security alerts actually affect your stack. Updated daily from 10 CERTs worldwide. Works with **Claude Code**, **Cursor**, **GitHub Copilot**, **Windsurf**, **JetBrains AI**, and any tool that supports custom instructions. ---
Pre-deploy release gate combining reliability, observability, CI/CD, and security checks.
插件系统是 Claude Code 的可扩展机制:用户可以安装插件包,添加命令、技能、MCP 服务器。核心问题:**如何让扩展安全(不被恶意插件攻击)、可管理(有范围优先级)、高效(启动时不阻塞)?**
Runs Semgrep security scans on the current project to detect vulnerabilities, secrets leakage, and OWASP Top 10 issues. Use when the user asks for security scanning, vulnerability detection, code auditing, secrets checking, or says things like 安全扫描, 代码扫描, 扫漏洞, 安全检查, 漏洞检测, 扫一下安全.
三层记忆架构系统,模拟人类记忆机制。自动提取、结构化存储、智能衰减、动态快照。v1.1.7 新增 LLM 深度集成、语义复杂度检测、智能触发策略。
Look up and search CWE (Common Weakness Enumeration) and CVE (Common Vulnerabilities and Exposures) entries. Use when the user asks about a specific CWE or CVE by ID, searches for vulnerabilities by keyword, needs CWE↔CVE associations, or references security weaknesses/vulnerabilities in reports. Triggers on: CWE-*, CVE-*, "look up vulnerability", "find CVE", "search CWE", "what is CWE-416", "CVEs for use-after-free", security vulnerability lookup.
Refresh one or more skills by diffing their current content against what the project actually does today. Pulls from `.context/knowledge/`, live source files, and dependency manifests to keep skills accurate and actionable.
**Versão:** 1.0.0 **Data:** 06/02/2026 **Status:** Implementado e testado ---
Vibe Coding 时代的产品经理全栈作战系统——覆盖从 PRD 撰写、Agent 工作流编排、前后端安全审计、数据架构决策、技术债管理到上线风险预警的完整闭环。 当用户提到产品经理、PM、PRD、需求文档、产品需求、产品设计、功能规划、技术评审、 vibe coding、AI编程、agent开发、低代码、无代码、快速原型、MVP、 代码审查、安全审计、数据存储方案、技术选型、上线检查、风险评估、 技术债务、code review、发布清单、上线checklist、 商业化、变现、定价、收费、盈利模式、SaaS定价、订阅制、付费墙、 LTV、CAC、留存率、复购率、NRR、NDR、MRR、ARR、单位经济学、收入飞轮、 增长策略、用户付费、Stripe集成、会员体系、 极简创业、最小可行产品、社区驱动、冷启动、前100个客户、验证想法、 流程化、手动交付、盈利优先、可持续增长、独立开发者、bootstrapping、 indie hacker、solopreneur、Gumroad、产品市场匹配、PMF、 精益创业、Lean Startup、Eric Ries、Steve B...
* **`find-skills`**: 在海量技能库中搜索,快速找到你需要的Skill * **`skill-creator`**: 创建自己的专属技能,定制个性化工作流 * **`skill-vetter`**: 安全审查工具,安装任何社区Skill前先用它扫一遍,防恶意代码 * **`model-usage`**: 按模型追踪token消耗和费用,避免账单惊喜 * **`free-ride`**: 通过OpenRouter免费使用多种AI模型,省钱利器
- Solidity (v0.8.x+) - Solidity Legacy (<0.8.0) Vulnerability Mechanics - Vyper (Conceptual) - Yul / Inline Assembly
Persistent memory and context for AI agents using Cognis by Lyzr. Use this skill when the user mentions "remember this", "what did I work on", "save this for later", "team knowledge", "project context", "recall", "memory", or needs long-term memory across sessions. Also use when the user asks about past decisions, preferences, or prior conversations. Supports personal memory (per-user), team memory (shared across repo contributors), semantic search, and automatic context assembly.
Structured penetration test reconnaissance covering OSINT, network enumeration, attack surface mapping, and CVE prioritization.
Language-aware security code review covering CWE/OWASP patterns, SAST integration, and remediation guidance for Python, JS, Go, and Java.
OWASP Top 10 focused web vulnerability analysis, payload crafting, and bypass techniques for penetration testers.
TOS-compliant Discord notification monitor. Watches YOUR Discord server for security content forwarded by researchers, matches keywords, and pushes to paper-writer/dogpile via webhooks. Persists to graph-memory for semantic search.
Generate CI/CD pipelines for Node.js and Angular applications on GCP with Cloud Build and GKE deployment. Use when creating or updating deployment pipelines for Node.js services, Express APIs, NestJS applications, or Angular frontends targeting Google Cloud Platform.
Domain-specific development mode guidelines for UI, API, database, integration, migration, and specialized workflows. Each mode provides tailored principles, checklists, and patterns for different types of development work.
Physics-inspired story analysis system that treats narrative as trajectories through dimensional space. Tracks dimensions like intimacy, trust, power, and stakes to calculate tension, validate pacing, and diagnose story problems. Genre-aware with formulas for romance, thriller, mystery, and fantasy. Use when analyzing story structure, engineering tension, validating character arcs, diagnosing pacing issues, or generating dimensional targets for scenes.
AI security co-pilot for identifying, testing, and fixing vulnerabilities in LLM-powered applications. Use when: (1) Securing LLM applications or agents, (2) Generating security test suites with promptfoo, (3) Testing for prompt injection, jailbreaking, data exfiltration, (4) Hardening system prompts, (5) Compliance mapping for OWASP LLM Top 10, NIST AI RMF, CJIS, SOC2, (6) Threat modeling AI systems, (7) Analyzing security eval results, (8) Research on LLM attack/defense techniques. Triggers...
Automatically logs every user prompt and AI output to datewise Notion pages. Use this skill to create a comprehensive archive of all AI interactions, track research progress, maintain conversation history, and build a searchable knowledge base. The skill creates one JSON file per day with all interactions and can export them to Notion in a structured format.
Query DARPA programs, opportunities, and BAAs. Searches RSS feeds and Grants.gov API for defense research funding opportunities across all DARPA technical offices.
Query SAM.gov for federal contracts, entity registrations, exclusions, and opportunities. Uses official GSA APIs for government contractor intelligence and OSINT research.
Security fix patterns for authentication and authorization vulnerabilities (credentials, JWT, deserialization, access control). Provides language-specific secure implementations.
- [Quick Start](#quick-start) - [When to Use](#when-to-use) - [Required TodoWrite Items](#required-todowrite-items) - [Progressive Loading](#progressive-loading) - [Core Workflow](#core-workflow) - [Rust Quality Checklist](#rust-quality-checklist) - [Safety](#safety) - [Correctness](#correctness) - [Performance](#performance) - [Idioms](#idioms) - [Output Format](#output-format) - [Summary](#summary) - [Ownership Analysis](#ownership-analysis) - [Error Handling](#error-handling) - [Concurrency](
Runs Software Composition Analysis (SCA) to detect vulnerable dependencies. Wraps npm audit and Trivy fs. Use when user asks to "scan dependencies", "check npm vulnerabilities", "SCA scan", "dependency audit", "依存関係スキャン", "脆弱性チェック".
Security analyst persona with deep OWASP expertise, vulnerability classification, risk assessment, and compliance mapping
World-class security content writer for VibeShip Knowledge Base. Creates authoritative, SEO-optimized, LLM-extractable content about cybersecurity vulnerabilities in AI-generated code. Use this skill when: - Writing vulnerability articles (SQL injection, XSS, IDOR, etc.) - Creating AI tool security analysis (Cursor, Claude Code, Bolt patterns) - Writing stack security guides (Next.js + Supabase, Express, etc.) - Generating fix prompts for AI coding tools - Creating security checklists and gl...
Master specialized tech careers including Product Management, Engineering Management, DevRel, Technical Writing, QA, Blockchain, Game Development, Cybersecurity, and UX Design. Navigate multiple career paths beyond traditional software development.
Explore advanced CS topics including advanced data structures, parallel computing, security, functional programming, and quantum computing.
Progressive audit and cleanup of GitHub accounts - stale forks, orphaned secrets, failing workflows, security configs. Audit-first with user approval before destructive actions. Triggers on 'clean up GitHub', 'audit my repos', 'GitHub hygiene', 'stale forks', 'orphaned secrets'. Requires gh CLI. (user)
Claude Code v2.0.36 Sonnet 4.5 · Claude Pro !!! prompt Use the microsim-p5 skill to create a new microsim called 'ooda' that is based around the OODA_loop page on Wikipedia. https://en.wikipedia.org/wiki/OODA_loop ⏺ I'll help you create a new MicroSim about the OODA loop. Let me first fetch information about the OODA loop from Wikipedia, then use the microsim-p5 skill to create the simulation. ⏺ Fetch(https://en.wikipedia.org/wiki/OODA_loop) ⎿ Error: Request failed with status code 403 ⏺ Let...
Scans git repositories for hardcoded secrets, credentials, and API keys using Gitleaks. Returns findings with severity, location, and remediation steps. Use when user asks to "scan for secrets", "detect credentials", "find API keys", "check for leaks", "シークレット検出", "認証情報スキャン".
This page outlines my technical and soft skills, reflecting my expertise in cybersecurity and my continuous learning journey.
CI/CD pipeline best practices including GitHub Actions, testing, and deployment strategies.
Map, assess, and remediate project dependencies with routing to dependency-mapper and security checks.
Automated security scanning for dependencies and code. Use when running npm audit, pip-audit, Semgrep, secret detection, or integrating security checks into CI/CD.
Core development principles and guidelines covering security, QA, performance, documentation, and coding standards. Used by all agents to ensure consistent quality across the Orchestra system.
Write and maintain CHANGELOG.md following Keep a Changelog format. Use when: creating changelog entries, preparing releases, documenting changes. Keywords: changelog, release notes, CHANGELOG.md, keep a changelog, 變更日誌, 發布說明.
Validate that quality, security, and release gates are correctly defined, implemented, and enforced with evidence.
Security auditing and vulnerability detection using OWASP patterns, CWE analysis, and threat modeling. Use when auditing code for security issues, reviewing authentication/authorization, evaluating input validation, analyzing cryptographic usage, reviewing dependency security, or when security-audit, vulnerability-scan, OWASP, threat-model, or --security are mentioned.
Understand the OCSF schema. Use when working with OCSF, looking up
You have access to `linkedin-cli`, an unofficial LinkedIn CLI tool. Use it to read information from the user's LinkedIn account.
Cybersecurity partner skill for acting as a practical security collaborator across architecture review, threat modeling, secure design, risk prioritization, defensive planning, vulnerability remediation, incident readiness, security roadmaps, and technical decision support. Use when the user wants an ongoing security advisor, reviewer, or second set of eyes.
Generate a weekly AI report in Markdown, including official announcements, industry news, GitHub-oriented open-source signals (via configured feeds), a capped paper ratio, and **optionally** OpenClaw top skills as **auxiliary** context.
AI-powered design intelligence for generating complete, tailored design systems. Analyzes project requirements and outputs pattern, style, colors, typography, effects, and anti-patterns. **Source:** https://github.com/nextlevelbuilder/ui-ux-pro-max-skill
Search, list, view, and update existing GitHub issues. Primary use case is CVE tracking and security vulnerability issue management. Used by the ark-security-patcher agent. For drafting NEW issues with research and task breakdowns, use the "issue-creation" skill instead.
Assess a CVE for exposure, exploitability, and remediation options across one or more repositories.
Comprehensive competitor SEO & content analysis tool. Analyzes competitor websites, identifies keywords, content gaps, backlink strategies, and ranking opportunities. Accepts sitemaps for deep analysis. Supports 3 output formats: detailed reports (Opus 4.6+ with adaptive thinking), quick findings (Sonnet 4.6+), and competitive comparisons (any model 4.0+). Use when: analyzing competitor strategy, finding content gaps, identifying keyword opportunities, benchmarking your SEO performance.