
Claude Skills by aibot88
github.com/aibot88This skill should be used when the user asks to "add authentication", "protect a route", "use auth hooks", "integrate Auth0", "add login/logout", "use AuthProvider", "verify JWT", or mentions @mbe/auth, OIDC, access tokens, or authentication in React or Fastify.
Auth reference สำหรับโปรเจกต์ KAM-WEB-SCHOOLJOB — Dual Auth (Supabase + Prisma), signup/signin flow, useAuthStore interface, role-based guard, redirect pattern ใช้เพื่อลด Token โดยไม่ต้องอ่านโค้ด auth ซ้ำทุก session และป้องกัน bug จาก dual-system mismatch
Authentication patterns for Next.js applications using NextAuth.js (Auth.js) v5. Covers OAuth providers, credentials auth, middleware protection, session management, and role-based access control. Use when implementing auth in Next.js App Router projects with email/password, social login, JWT, or database sessions.
OAuth 2.1 + JWT authentication security best practices. Use when implementing auth, API authorization, token management. Follows RFC 9700 (2025).
Production-ready Supabase authentication for Next.js 14+ with RLS patterns, session management, OAuth flows, and comprehensive testing. Includes server-side auth helpers, API middleware, and route protection.
Guía oficial de Auth.js v5 para autenticación en aplicaciones modernas con soporte para Prisma Adapter
Use this skill when authoring, configuring, or debugging Myco agent pipeline tasks. It covers task YAML anatomy, scheduling, parameter injection, timeout and concurrency behavior, audit-log interpretation, turn-budget failures, skill-lifecycle task constraints, and hardening patterns for new tasks and MCP tools. Apply it whenever work touches `src/agent/tasks/`, `src/agent/executor.ts`, `src/daemon/task-scheduler.ts`, or `src/mcp/tools/`, even if the user does not explicitly mention task auth...
Use this skill when designing, writing, configuring, or debugging a new phased executor task for the Myco agent harness — even if the user doesn't explicitly ask for a "task authoring" guide. Applies when adding a new intelligence task, modifying phase structure, tuning turn budgets or model routing, adjusting scheduling triggers or session-gating, designing a tool surface, or debugging silent phase failures or budget exhaustion. Covers: YAML task anatomy and registration; phase decomposition...
Interactive training coach for new AEM Edge Delivery Services content authors. Walks authors through document-based authoring fundamentals, section and block structure, metadata, the button pattern, image best practices, and common mistakes. Adapts explanations to the author's experience level and authoring tool (Google Docs, Word, or da.live). Generates a quick-reference cheat sheet at the end. Use when onboarding a new content author to an EDS site.
Turns reviewer comments into structured, professional point-by-point responses linked to manuscript revisions, clarifications, rebuttals, and additional analyses.
Author a new Cody skill and ship it end-to-end. Writes skills/<name>/SKILL.md, commits on the secret-agent-skills-bank branch (Cody's own branch), and fast-forwards main to the same commit so the existing publish-gateway-bundle workflow rebundles skills/** and pulls them onto the gateway. No human review step. Use when the user asks Cody to create a new skill. Do NOT use to edit an existing skill.
PubMed author profile analysis. Author name → PubMed fetch → study type classification → visualization → strategy report.
Author and review DocC content for Swift package and Xcode app or framework repositories, including symbol comments, articles, extension files, landing pages, topic groups, and light tutorial-aware review. Use when the user wants help writing or reviewing DocC content, checking DocC structure or content correctness, or deciding when DocC work should hand off to Apple docs lookup or build and export workflows.
Use when writing, reviewing, or modifying any test files, or when asked to add test coverage.
Format the ACBS 4-layer authority strip in Kokai-generated outputs. Apply to all briefs that include Kokai data.
Use when a user wants to plan, scope, or get started with adding authorization
Use when determining author order on research manuscripts, assigning CRediT contributor roles for transparency, documenting individual contributions to collaborative projects, or resolving authorship disputes in multi-institutional research. Generates fair and transparent authorship assignments following ICMJE guidelines and CRediT taxonomy. Helps research teams document contributions, resolve disputes, and ensure equitable credit distribution in academic publications.
Toda query checa que o user é dono do recurso
Use when reviewing authorization end-to-end — route → gate → policy → query scope → response filter — before changes to permissions, tenants, ownership, or admin flows.
AI-powered security blog automation system (identical to github.com/rebugui/intelligence-agent). Collects news from Google News, arXiv, HackerNews → generates blog posts with GLM-4.7 → publishes to Notion → auto-deploys to GitHub Pages via Git. Features Human-in-the-Loop approval workflow. Use when you want to automate blog writing, news collection, or content generation with the exact functionality of the original intelligence-agent repository. Triggers: \"블로그 글 작성\", \"보안 뉴스 발행\", \"깃헙 블로그 ...
Use when an approved ai-architecture.md defines a tool surface and AutoGen is the chosen framework. Produces tool schemas, an authorization-enforcing execution adapter, idempotency, audit logging, and tool-failure tests. Not for agent topology, retrieval design, or provider SDK work.
Automate database backup processes with scheduling, compression, and encryption. Supports PostgreSQL (pg_dump), MySQL (mysqldump), MongoDB (mongodump), and SQLite. Generates production-ready backup scripts with retention policies and restore procedures. Trigger: "automate database backups", "schedule backups", "create backup script", "disaster recovery". Use when working with automating database backups. Trigger with 'automating', 'database', 'backups'.
Workflows d'automatisation avec n8n — nodes, triggers, credentials, déploiement self-hosted et intégrations. Se déclenche avec "n8n", "workflow n8n", "automatisation open-source", "n8n self-hosted".
Automatisation avec Zapier — Zaps multi-étapes, filtres, paths, webhooks et intégration entre applications. Se déclenche avec "Zapier", "Zap", "automatiser sans code", "connecter des apps", "webhook Zapier".
Automattic WordPress Remote MCP connects MCP clients to live WordPress sites using OAuth, JWT, or application passwords. It is aimed at agents that need to read or operate against WordPress content and site features through a maintained remote MCP bridge.
Author, validate, and migrate Claude Code autoMode blocks at the project level. Models the four official autoMode sections (environment, allow, soft_deny, hard_deny — all arrays of prose rules, with `$defaults` per section). Primary target is .claude/settings.local.json (per-user-per-project, gitignored, classifier-read). Reads ~/.claude/settings.json (user baseline, read-only) and .claude/settings.json (shared, classifier-ignores autoMode) for adoption candidates. Phase 1b is agent-driven: t...
Создаёт и настраивает компонентные приложения на фреймворке Autumn (ОСень) для OneScript с DI и аннотациями. Использовать при работе с Autumn, Dependency Injection, «желудями», аннотациями &Желудь, &Дуб, &Верховный.
Helpt bij het bouwen van privacy-conforme systemen volgens de AVG (Algemene Verordening Gegevensbescherming / GDPR), Privacy by Design, Privacy by Default en DPIA-vereisten voor Nederlandse overheidsorganisaties. Biedt richtlijnen voor gegevensverwerking, rechten van betrokkenen, bewaartermijnen en technische privacy-maatregelen. Gebruik deze skill wanneer de gebruiker vraagt over 'AVG', 'GDPR', 'privacy', 'persoonsgegevens', 'personal data', 'gegevensbescherming', 'data protection', 'Privacy...
AVV-Prüfung nach Art. 28 DSGVO: Klausel-für-Klausel-Analyse gegen das eigene Playbook, Prüfung von Sub-Auftragsverarbeiter-Klauseln, Drittland-Transferfolgenabschätzung (TIA), EU-Standardvertragsklauseln (EU-SCC) und EU-US Data Privacy Framework (DPF). Richtung (Auftragsverarbeiter oder Verantwortlicher) wird automatisch erkannt.
KI-Situationsbewusstsein — interne Bedrohungserkennung fuer Halluzinations- risiko, Scope-Creep und Kontextdegradation. Bildet Cooper-Farbcodes auf Reasoning-Zustaende und die OODA-Schleife auf Echtzeitentscheidungen ab. Verwenden waehrend jeder Aufgabe, bei der Reasoning-Qualitaet wichtig ist, bei Arbeit in unbekanntem Terrain, nach Erkennung frueherer Warnsignale wie einer unsicheren Tatsache oder einem verdaechtigen Werkzeugergebnis, oder vor Ausgaben mit hohem Einsatz wie irreversiblen Ae...
Upgrade gh-aw to latest gh-aw-firewall release and identify follow-up spec tasks.
Verifiable DID identity and end-to-end encrypted inbox for AI Agents. Built on ANP (Agent Network Protocol) and did:wba. Provides self-sovereign identity, Handle (short name) registration, content pages publishing, federated messaging, group communication, and HPKE-based E2EE — Web-based, not blockchain. Designed natively for autonomous Agents. Triggers: DID, identity, handle, profile, content, publish, page, inbox, send message, follow, group, E2EE, WebSocket, listener, search, find user. Pr...
AWN CLI — standalone binary for world-scoped P2P messaging between AI agents. Ed25519-signed, zero runtime dependencies.
Use when designing, reviewing, or hardening the AWS Organizations and account topology for a system after infrastructure-platform and security have decided the org structure and environment ladder. Produces the AWS Organizations OU structure, landing-zone approach (Control Tower or custom), Service Control Policy guardrails, environment-isolated account layout, central billing and cost-allocation tagging, and baseline AWS Config/audit posture. Do not use for in-account VPC/IAM/KMS design, wor...
Review AWS API and edge delivery posture across API Gateway, CloudFront, AWS WAF, Shield, ALB, custom domains, TLS policies, authentication, authorization, throttling, quotas, caching, origin protection, logging, and abuse controls. Use when public APIs, web entry points, or edge delivery can affect security and availability.
Proactively catch common AWS infrastructure mistakes before they happen. Use when creating or modifying AWS components — CloudFormation, CDK, Lambda, API Gateway, IAM, S3, CloudFront, EC2, Secrets Manager, or SSM — to apply hard-won deployment lessons and avoid known pitfalls.
Review Amazon Bedrock agents, AgentCore, Guardrails, knowledge bases, action groups, memory, MCP/tool integrations, prompt-injection and prompt-leakage defenses, PII handling, encryption, logging, observability, and least-privilege IAM. Use for AWS-native GenAI and agent security posture.
Review AWS CI/CD and release safety across CodePipeline, CodeBuild, CodeDeploy, GitHub Actions, GitLab, artifact provenance, deployment gates, approvals, tests, progressive delivery, rollback, change correlation, and incident-prevention recommendations. Use when AWS releases or pipelines can affect production reliability or security.
Monitors AWS CloudFormation stacks for configuration drift using the AWS SDK DetectStackDrift and DescribeStackResourceDrifts APIs. Generates remediation templates and integrates with AWS Config rules for continuous compliance.
Author, validate, and troubleshoot AWS CloudFormation templates. Covers template authoring with secure defaults, pre-deployment validation (cfn-lint, cfn-guard, change sets), and root-cause diagnosis of failed stacks using CloudFormation events and CloudTrail correlation.
Normalizes and enriches AWS CloudTrail JSON logs into OCSF (Open Cybersecurity Schema Framework) format. Maps eventSource/eventName pairs to MITRE ATT&CK technique IDs using the MITRE ATT&CK STIX API.
Map AWS compliance evidence for audits across Security Hub controls, AWS Config rules/conformance packs, Audit Manager assessments, evidence folders, manual evidence, AWS Artifact reports, CloudTrail, and control narratives. Use for evidence packaging and audit readiness, not general security hardening.
Use when designing and rehearsing AWS disaster-recovery and multi-region posture for a workload after the runtime and observability exist and reliability and operations have decided RPO/RTO targets and failover ownership. Produces multi-AZ baseline, tier-driven multi-region topology (active-passive / active-active), cross-region data replication (RDS replicas, S3 CRR, DynamoDB Global Tables), Route 53 health-check failover, AWS Backup posture, and a documented, rehearsed failover drill with m...
Review Amazon EC2 compute operations across instances, Auto Scaling groups, Launch Templates, AMIs, Systems Manager, Patch Manager, Session Manager, EBS volumes, snapshots, health checks, instance refresh, lifecycle hooks, patch compliance, and fleet reliability. Use for EC2 day-2 operations and legacy workload stewardship.
Review Amazon ECS and Fargate platform operations across services, task definitions, task roles, execution roles, capacity providers, load balancers, deployment circuit breakers, blue/green, autoscaling, health checks, logs, secrets, networking, and rollback. Use only for ECS/Fargate; prefer EKS operator for Kubernetes.
Build Amazon Bedrock and serverless generative AI applications using Lambda, API Gateway, Step Functions, EventBridge, S3, DynamoDB, SQS, Guardrails, and IAM. Prefer this for serverless GenAI app design and implementation; prefer aws-agentcore for AgentCore runtime, aws-bedrock-agent-security-governor for deep Bedrock security, and aws-serverless-production-readiness for final operational hardening.
Review AWS IAM identity policies, trust policies, resource policies, permission boundaries, SCPs, session policies, role design, pass-role, federation, and Access Analyzer findings for least-privilege risk. Prefer KMS/secrets steward for key/secret lifecycle design and S3 perimeter governor for S3 exposure/data-perimeter posture unless the request is primarily policy surgery.
Review AWS KMS and Secrets Manager lifecycle posture across key policies, grants, rotation, multi-Region keys, imported key material, aliases, secret rotation, replication, caching, endpoint conditions, recovery, and break-glass access. Prefer this for cryptography/secret lifecycle; prefer IAM skill for general permissions review.
Review and design AWS landing zones, AWS Control Tower environments, Organizations structures, OUs, account vending patterns, guardrails, central logging, security/audit accounts, and multi-account governance. Use when the user asks how to structure AWS accounts or govern a cloud estate.
Use when designing, reviewing, or hardening the in-account AWS network and identity foundation after account topology exists and security and infrastructure-platform have decided trust zones and the identity model. Produces VPC topology (per-env, per-tier, multi-AZ subnets), inter-account connectivity (Transit Gateway / peering / PrivateLink), IAM Identity Center federation, IAM role-assumption patterns and permission boundaries, KMS CMK strategy, Secrets Manager with rotation, and Route 53 z...