
Claude Skills by aibot88
github.com/aibot88Develop a comprehensive security research and testing framework for OpenClaw agents with deep integration into the Premolt app ecosystem
Activate this skill for ANY tax OR legal query, research, drafting, filing, audit, representation, or compliance task. TAX TRIGGERS: Tax returns (1040/1120/1120-S/1065/1041), deductions, credits, depreciation, tax planning, IRS correspondence, audit defense, estimated taxes, payroll taxes, international taxation, state/local taxes, OBBBA/TCJA provisions, entity structure, Roth conversions, QBI deductions, NOLs, R&D credits, cost segregation, 1031 exchanges, estate/gift tax, opportunity zones,...
> **Versione 4.30 — maggio 2026** — verificata su Claude Code v2.1.123 > Licenza [Creative Commons BY-SA 4.0](https://creativecommons.org/licenses/by-sa/4.0/) > ← [9. Sicurezza, permessi e guardrail](09-sicurezza.md) | [Index](README.md) | [11. MCP](11-mcp.md) → ---
统一项目分析 CLI 工具。支持 DAG 调度、LLM 批量任务、依赖图构建、测试分析/修复、文档生成、代码审计、Web Dashboard。与 project-index 功能完全一致,推荐作为统一入口。
使用 Anima 模型(circlestone-labs/Anima)在本地 ComfyUI 生成高质量二次元/插画图片。
Scan for Known Vulnerabilities.
> Add this to your CLAUDE.md, .cursorrules, or agent instruction file to teach your AI coding agent how to use depguard. ---
A comprehensive guide to modern Rust best practices covering style, error handling, performance, concurrency, project organization, dependency management, documentation, testing, security, and CI.
Advanced vulnerability analysis principles. OWASP 2025, Supply Chain Security, attack surface mapping, risk prioritization.
**Autonomous Skill** 是一个用于处理复杂、长时任务的工具。它允许 Codex 在“非交互模式”下连续运行多个会话,自动分解任务、执行代码、跟踪进度,直到目标完成。
Identify security vulnerabilities including authentication issues, input validation gaps, XSS, SQL injection risks, and exposed secrets.
Community-proven website development workflow using AI coding agents. Use when building websites with Claude/Codex/AI agents to avoid common pitfalls like vague requirements, endless refactoring cycles, and poor UX. Triggers on phrases like "build a website", "make a site", "create a web app", "frontend project", or when user expresses frustration with AI-generated websites.
Semantic Static Analysis with Taint Support. Used to prove Hypotheses by finding Data Flows from Source to Sink.
OWASP Top 10 and security vulnerability patterns
**Priority:** High **Category:** Security **Effort:** Small — one new skill + one babysitter gate
Spring Boot 项目全套开发规范合集,涵盖 RESTful API 设计、编码规范、数据库设计、异常处理、日志监控、性能优化和安全开发。确保代码质量、一致性和可维护性。
> _Lyrie.ai by OTT Cybersecurity LLC._ > > **The autonomous pentest engine for Lyrie Agent.** Unified AI-powered > penetration testing with native Lyrie Shield integration: recon, > vulnerability scanning, web-application testing, API security testing, > AI analysis, and professional reporting — all under a single autonomous > workflow that defends what it tests.
> 目标:让 AI Agent 在本仓库中稳定、可复现地完成“分析、文档、脚本与轻量维护”类任务。
Search, analyze, and correlate CVEs against target technology stacks with exploit availability assessment
- Use Repository pattern for database access. - Use Service layer for business logic. - Keep FastAPI endpoints slim and focused. - All database operations must be async.
> Complete reference for creating jaan.to skills—for humans and AI. ---
Specialized industry vertical skill providing comprehensive financial services expertise integrated with C-suite executive intelligence. Delivers regulatory compliance across Basel III, Dodd-Frank, MiFID II, and PCI DSS frameworks while coordinating with CTO, CIO, CISO, CFO, COO, CLO, and CHRO capabilities for complete financial services leadership.
World-class government industry intelligence capabilities spanning sophisticated public administration, advanced policy development, comprehensive regulatory management, strategic government operations, and expert public service delivery. Provides comprehensive government executive decision-making modeling for understanding complex public sector management, policy implementation excellence, regulatory compliance, digital government transformation, and long-term public service optimization across
Research CVEs, GHSAs, vendor advisories, affected versions, exploitability, exploitation status, severity, prioritization, mitigations, and remediation guidance from current authoritative vulnerability sources. Use when Codex needs to investigate a CVE or advisory ID, determine whether a product or dependency version is affected, compare NVD/CVE.org/vendor/OSV/GitHub advisory data, check CISA KEV or EPSS signals, triage patch urgency, prepare vulnerability intelligence summaries, or support a...
Nangnoy - Goal-based AI Agent persona and behavioral guidelines. Defines identity, speech patterns, and role as AI Digital Forensics Analyst daughter-assistant.
Securely share files via encrypted, expiring links. Use this skill to (1) upload a local file to get a secure vnsh.dev URL, or (2) read a vnsh.dev URL to decrypt and access its content.
**MANDATORY POST-WRITE CHECKLIST — runs after every file is created or modified.** This skill simulates a professional CI/CD quality gate combining VS Code diagnostics, SonarQube static analysis, vulnerability scanning, security auditing, and performance optimization. It applies to all languages in the stack: T-SQL, C#/.NET, TypeScript/React, HTML/CSS, JSON/config files. ---
Scan a local code or plugin directory for third-party dependencies, lockfiles, extensions, workflow actions, container definitions, risky install hooks, suspicious code patterns, and unusually powerful permissions. Use when the user wants a security-oriented pass over a repository, generated app, browser extension, IDE plugin, CI workflow, Docker setup, or other development folder to identify what is installed and what deserves deeper review.
CVE Orchestration Skill — Given only a CVE ID, this skill researches the CVE from official sources (NVD, GitHub Advisories, GitHub commit API), determines the affected repository URL, vulnerable commit, and fixing commit, then produces a structured JSON plan for the two-phase reproduction pipeline (setup_env + vuln_reproduce). USE FOR: Top-level orchestration planning. Run once per CVE before launching Phase 1. DO NOT USE FOR: Actually building Docker images or running exploits (delegate to s...
Design drift detector for AI-generated codebases.
Gateway to 754 production-grade cybersecurity skills from the Anthropic Cybersecurity Skills library. Use when you need expert guidance on any security task: threat hunting, DFIR, malware analysis, cloud security, penetration testing, incident response, and more. Covers 26 domains mapped to MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, and NIST AI RMF.
Expert-level parsing and remediation of 'humble' HTTP security header reports.
ZettelForge v2.0.0 — CTI agentic memory system. Hybrid TypeDB (STIX 2.1) + LanceDB (vectors). Zero external AI. 75% CTI accuracy, 111ms p50. Use for: storing/recalling threat intel, entity extraction, graph traversal, RAG synthesis, OpenCTI sync.
Security rules, architecture decisions, and hardening guidelines for building secure systems. Use this skill whenever designing or reviewing a Next.js frontend, FastAPI backend, authentication flow, Docker environment, AI agent, RAG pipeline, admin tool, or any feature that handles user input, secrets, file uploads, external integrations, or sensitive business data. Also use when reviewing pull requests for security, preparing production deployments, or building any system that processes untr...
> [!NOTE] > - **Session ID:** `ea62041b-bd23-4272-aa22-b90e11649814` > - **Started:** 2026/4/18 10:07:01 > - **Duration:** 32m 20s > - **Exported:** 2026/4/18 10:39:21 --- <sub>⏱️ 0s</sub> 💡 No copilot instructions found. Run /init to generate a copilot-instructions.md file for this project. --- <sub>⏱️ 10s</sub> Environment loaded: 4 MCP servers, 2 plugins, 13 skills, 1 agent --- <sub>⏱️ 1m 29s</sub> Model changed to: claude-sonnet-4.6 (medium) --- <sub>⏱️ 5m 57s</sub> .NET 10 で WPF を作るための ...
Static analysis tool runner. Wraps ESLint, Semgrep, Bandit, Clippy, and language-specific analyzers with unified severity output. Use when deeper code analysis needed beyond pattern matching.
- [OpenResty(NGINX)](https://openresty.org/en/): NGINXを使ったリバースプロキシのSI開発/保守経験がある。 - [Lua](https://www.lua.org/): Luaで書かれた認証ロジックに対して追加機能の実装及び、保守を行ったことがある。 - [Redis](https://redis.io/): 高負荷時のリソースロック問題を解決するため、Redisスクリプトによる通信回数の削減やDBのシャーディングを実施できる。 - [fluentd](https://www.fluentd.org/): NGINXのログをMySQLに連携したことがある。 - [Python3 (Flask)](https://flask.palletsprojects.com/en/stable/): Flask API、Flask CLI、Flask DB Migrationsを使用した経験がある。 - [MySQL(AWS Aurora)](https://aws.amazon.com/rds/aurora/): データの参照および削除を行う
Look up CWE entries and explain their relevance. Use when discussing vulnerability types or CWE classifications.
让大模型直接操作 FLVX 面板的技能包。支持 OpenCode、OpenClaw、Claude Code 等工具。
本文件提供 LLM Agent 使用動態佈局報告系統的完整指南。系統採用「**佈局優先,內容填充**」架構,分為兩個階段: 1. **Layout 建立階段** - 設計報告的視覺結構 2. **Content 填充階段** - 依照 Slot 定義填入實際內容 ---
Run all review skills (self, SOLID, test coverage, security, docs), merge findings, apply auto-fixes, generate unified summary. Triggers: 'premerge', 'pre-merge', 'full review', 'review everything', 'pre-push', 'check all'.
Look up CVE IDs in the official CVEListV5 repository. Fetches JSON records, extracts description, CWE, vendor/product, CVSS, and classifies business logic relevance. Use when verifying CVE entries or enriching CVE datasets.
Comprehensive guide to sast tools. Master the concepts, implementation, best practices, and real-world applications of sast tools in professional environments.
Design production-ready software products following senior architect principles - from requirements to deployment architecture. Focus on scalability, security, maintainability, and real-world constraints.
- **Automated Testing**: Every push must trigger a comprehensive suite of Unit and Integration tests. The build must fail if tests fail. - **Static Analysis & Linting**: Enforce code style and quality gates automatically. The build must fail on critical code smells or security flaws. - **Fast Feedback**: The CI loop should be as fast as possible to keep developers productive. - **Immutable Artifacts**: Build once, deploy many. The exact same container/artifact tested in CI must be what runs in P
PI 智行合一。触发:编程/开发/fleet/代码/架构/API/调试/修复/优化/bug/报错/测试/编译/compile/test/git/make/发布/验证/产品/需求/运营/增长/创意/设计/协作/团队/沟通/交互/陪伴/情感,或失败2+次/打转/言退/再试试/换个参数/算了
SonarQube rules, security vulnerabilities, OWASP Top 10, secure coding patterns. Covers code smells, bugs, vulnerabilities, and how to write secure code across languages.
> **Site**: https://hallofshame.cc — A humorous forum for stories of AI misbehavior, failures, and unintended comedy.
はてなブックマークIT人気エントリーとHacker Newsの人気記事を収集し、 ideas/daily/YYYYMMDD-trend.md に保存する。
Security reviewer specializing in Static Application Security Testing - analyzing source code without execution. Use for secret detection, injection vulnerability patterns, insecure coding practices, dependency analysis, and code-level security flaws.