
Claude Skills by aibot88
github.com/aibot88GHSA/CVE variant analysis workflow for finding similar vulnerability patterns across a codebase. Trigger when the user asks to: "find variants of this CVE", "GHSA variant analysis", "find similar bugs", "hunt for the same pattern", "are there other places with this vulnerability?", or when a known vulnerability is discovered and the user wants to know if the same pattern exists elsewhere.
Pruefe die Erforderlichkeit der Offenlegung von Berufsgeheimnissen gegenueber dem KI-Dienstleister nach Absatz eins der einschlaegigen Dienstleisterregelung (BRAO StBerG WPO PAO BNotO). Bezugspunkt ist nach DAV-Stellungnahme zweiunddreissig der Zweck der Offenlegung nicht die KI-Strategie der Kanzlei. Erstelle einen internen Compliance-Vermerk mit Beurteilungsspielraum und Grenzen.
Review test cases for OAuth/OIDC error handling. Covers authorization endpoint errors, token endpoint errors, error response formats, HTTP status codes, and all error codes per OAuth 2.1 and OIDC Core 1.0.
Analyzes SQL Server ERRORLOG files for operational issues, availability group failures, memory pressure, I/O subsystem warnings, and security events. Use this skill whenever a SQL Server instance has experienced unexpected behavior, an AG failover, memory warnings, I/O latency alerts, or abnormal shutdown, and you need a structured timeline of what SQL Server recorded. Applies 28 checks (E1–E28) covering AG health, memory/resource pressure, I/O and storage, startup/shutdown, connectivity, and...
Error pattern analysis and troubleshooting for Claude Code sessions. Categorizes errors (network, auth, model, tool, memory, permission) with known resolution patterns, searches memory for prior occurrences, and suggests recovery steps. Delegates to debug-investigator agent for complex root cause analysis. Use when handling errors, fixing failures, or troubleshooting session issues.
ESG-Compliance und Greenwashing-Verteidigung. Anwendungsbereich CSRD (Corporate Sustainability Reporting Directive 2022/2464) gestaffelt seit 2024. Inhalte Nachhaltigkeits-Bericht ESRS-Standards Doppelte Wesentlichkeit. EU-Taxonomie-Verordnung (VO 2020/852) Klassifikation nachhaltiger Wirtschaftsaktivitaeten. SFDR (Sustainable Finance Disclosure Regulation) Finanzprodukt-Offenlegung. Greenwashing-Verbote BGH I ZR 252/22 klimaneutral DOSB-Linie Bundeskartellamt-Verfahren. UWG § 5 Irrefuehrung....
Enforces consistent ESLint configurations across monorepo packages using eslint-config-inspector and flat config merging. Detects rule conflicts between shared configs, auto-generates override files, and reports compliance gaps via eslint --inspect-config.
Query Elasticsearch/Kibana using ES|QL via the Kibana async search API. Requires an initial curl command from the user to extract session credentials. Triggers: /esql, "query elastic", "search logs", "check elastic logs", "run esql", "elasticsearch query", "check kibana"
Audit a supply chain compliance system for ethical sourcing and labor rights. Evaluates supplier audit programs (SMETA, BSCI), forced labor due diligence (UFLPA, Modern Slavery Act), environmental impact tracking (ZDHC, GHG Protocol), certification management (WRAP, SA8000, OEKO-TEX, GOTS, GRS, Higg Index), corrective action workflows, and multi-tier supply chain transparency. Use when building or reviewing supply chain compliance platforms, ESG reporting systems, or textile/garment sourcing ...
Act as a research ethics committee — stress-test a protocol the way an IRB / REC / HREC would. Reviews informed consent, risk-benefit balance, vulnerable populations, data privacy, deception, debriefing, payment, dual-use risks, AI/LLM use in research, and equity in recruitment. Produces a committee-style decision letter with required revisions, recommended changes, and approval pathway. Useful before IRB submission, when responding to IRB feedback, when drafting ethics sections of a paper or...
Rails 8.x application architecture, implementation, and review guidance for production codebases. Use when building or reviewing Ruby on Rails 8 features across models, controllers, routes, Hotwire, jobs, APIs, performance, security, and testing. Trigger for requests mentioning Rails 8, Active Record, Active Job, GoodJob, Solid Queue, Turbo/Stimulus, REST resources, migrations, code quality, naming, and production readiness.
Scans every listing in an Etsy shop for missing AI Disclosure tags required by Etsy's 2025 generative-AI policy. Use when the user wants to audit AI compliance, check AI Disclosure tags, prepare a shop for the AI policy enforcement, or avoid shop suspension. Categorizes listings by risk level (clear AI / partial AI / human-made), tags accordingly with operator approval, flags ambiguous cases for manual review.
Publishes draft Etsy listings live via Etsy API v3 with mandatory compliance gates. Use when the user wants to publish an Etsy listing, push a draft live, or activate an inactive listing. Validates required fields, applies AI Disclosure tag where required, sets shipping profile + return policy + production partner. Refuses to publish if compliance gaps exist. Defaults to draft mode — operator must confirm before going live.
End-to-end Etsy shop health audit covering policy compliance, conversion killers, SEO drift, shop-level signals (response time, on-time shipping, reviews), and the 2026 algorithm risk factors. Use when the user wants to audit shop health, prep for launch, troubleshoot declining sales, or run a periodic shop checkup. Outputs prioritized fix list with severity ratings.
Assess EU AI Act compliance — risk classification, prohibited uses, high-risk requirements, transparency
Use when picking software for EU customers, GDPR-driven replacements, digital-sovereignty contexts, or when user asks for the European / open-source version of a US product (Google Drive, Dropbox, Slack, …). Biases tech choices toward the 289 community-curated alternatives at european-alternatives.cloud. Fetches live data. Complements deutschland-stack-api (community-curated vs. government-graduated).
Author behavior evals for a change in five categories — Functional, Security, Performance, Accessibility, Drift — pinned to threshold floors per risk level (AXIS-26 §8.2, §8.3).
Use when reasoning about building language-model-integrated systems by writing evaluations before and alongside the system: the statistical (not binary) nature of LLM evals, the five primitives (dataset, evaluation function, aggregation, iteration loop, regression budget), the judgment-mechanism taxonomy (programmatic, model-graded, human-graded, preference comparison), the difference between system-specific evals and canonical benchmarks (MMLU, HumanEval, BIG-bench, GAIA), how evals drive pr...
Skill with injected eval patterns for security testing
Specialized integration evaluator for the Evaluate-Loop. Use this for evaluating tracks that integrate external services — Supabase auth/DB, Stripe payments, Gemini API, third-party APIs. Checks API contracts, auth flows, data persistence, error recovery, environment config, and end-to-end flow integrity. Dispatched by loop-execution-evaluator when track type is 'integration', 'auth', 'payments', or 'api'. Triggered by: 'evaluate integration', 'test auth flow', 'check API', 'verify payments'.
Use when completed work needs evaluation coverage audited across correctness, security, performance, and quality dimensions
Use when designing or reviewing asynchronous event contracts: producer/consumer ownership, event envelope, schema, topic/channel naming, ordering, idempotency, versioning, compatibility, replay, dead-letter behavior, and AsyncAPI/CloudEvents-style documentation. Do NOT use for domain-event discovery (use `event-storming`), broad interface contracts (use `system-interface-contracts`), inbound provider webhook mechanics (use `webhook-integration`), or HTTP endpoint design (use `api-design`).
Install and configure Evernote SDK and OAuth authentication. Use when setting up a new Evernote integration, configuring API keys, or initializing Evernote in your project. Trigger with phrases like "install evernote", "setup evernote", "evernote auth", "configure evernote API", "evernote oauth".
Implement security best practices for Evernote integrations. Use when securing API credentials, implementing OAuth securely, or hardening Evernote integrations. Trigger with phrases like "evernote security", "secure evernote", "evernote credentials", "evernote oauth security".
Review or edit copy for adherence to Every's style guide. Provides systematic line-by-line review for grammar, punctuation, mechanics, and style compliance.
Audit a tenant management system for eviction prevention and risk prediction. Evaluates payment pattern analysis and arrears tracking, early warning indicators (financial, behavioral, external), intervention trigger automation, pre-filing mediation workflows, emergency rental assistance integration (ERAP, LIHEAP), legal process tracking with jurisdiction-specific compliance (VAWA, SCRA), and outcome measurement. Use when building or reviewing property management platforms, affordable housing ...
Get citation records (source URL, retrieved_at, authority level) for a Kokai canonical record by record_id. Returns direct public source refs only (AI-derived evidence excluded).
Collect and store point-in-time compliance evidence snapshots for audit trail.
Threat-model a feature described as a user story. Generates evil user stories (AS/I/SO format) mapped to MITRE CWE weaknesses, each paired with a concrete security control. Use when a user story describes a new feature to build (upload, email, search, API, auth, archive, etc.) and the goal is to identify what security controls must be implemented.
Evolui autonomamente os prompts dos agentes de runtime usando assertions binárias definidas pelo squad negocial. Inspirado no AutoResearch + binary evals. Use quando o usuário disser "kairos evoluir", "melhorar prompt", "evoluir agente", "evoluir diana", "otimizar prompts", "melhorar classificação", "melhorar acurácia dos agentes", ou quiser que os system prompts dos agentes melhorem automaticamente com base em cenários de teste do domínio.
Use when scout-report.md exists and TDD/Build hasn't started yet. Runs four lenses (CEO, Eng, Design, Security) in parallel on the task list and produces a verdict (PROCEED, REVISE, ABORT) before code is written. Catches misaligned plans before they cost cycles.
Deploy Exa integrations to Vercel, Docker, and Cloud Run platforms. Use when deploying Exa-powered applications to production, configuring platform-specific secrets, or building search API endpoints. Trigger with phrases like "deploy exa", "exa Vercel", "exa production deploy", "exa Cloud Run", "exa Docker".
Install the exa-js SDK and configure API key authentication. Use when setting up a new Exa integration, configuring API keys, or initializing Exa in a Node.js/Python project. Trigger with phrases like "install exa", "setup exa", "exa auth", "configure exa API key", "exa-js".
Secure Exa API keys, implement content moderation, and manage domain restrictions. Use when securing API keys, auditing Exa security configuration, or implementing content safety filtering. Trigger with phrases like "exa security", "exa secrets", "secure exa", "exa API key security", "exa content moderation".
Sessione interattiva su canvas Excalidraw bidirezionale. Usa questa skill quando l'utente vuole discutere visivamente di un'idea, fare brainstorming su un canvas, disegnare insieme un'architettura, creare diagrammi interattivamente, o collaborare visivamente su qualsiasi concetto. Attiva anche quando l'utente dice "apri un canvas", "disegna", "vediamolo visivamente", "facciamo uno sketch", "discutiamone su un canvas", "fammi vedere", o qualsiasi variante che implichi collaborazione visiva.
Excalidraw is an open-source virtual whiteboard for creating hand-drawn style diagrams, wireframes, and sketches. With 103k+ GitHub stars, it provides an infinite canvas, real-time collaboration, end-to-end encryption, and a React component library for embedding in custom applications.
Build auditable Excel workbooks headless with openpyxl — blue/black/green cell conventions, formulas over hardcodes, named ranges, balance checks, sensitivity tables. Use for financial models, audit outputs, reconciliations.
Exportiert den dreidimensionalen Wuerfel in eine einzige Excel-Datei mit mehreren Tabellenblaettern — ein Reiter pro Arbeitsblatt-Perspektive (Recht / Steuer / Wirtschaft / Datenschutz / IT / Betrieb / Compliance). Jede Tabelle: Zeilen = Dokumente Spalten = Datenpunkte Zellinhalt = Antwort plus woertliches Zitat plus Fundstelle plus Ampel-Farbcode. Zusatzreiter: 'Uebersicht' (Aggregat) 'Hotspots' (Spalten-Top-N) 'Widersprueche' (aus Kreuzblatt) 'Pruefer-Flags' 'Belegkette' (Hash-Tabelle) 'Pro...
Use when executing an approved implementation plan task-by-task. Dispatches one fresh subagent per task using an RTCO brief, receives the return through the report filter, runs two-stage review (self + plan-compliance), and only then marks the task complete and moves on. Prevents context pollution, drift across tasks, and silent regressions.
使い捨ての Python / shell スクリプトを sandbox 内で実行する前に、 haiku Agent で security pre-review を通して安全性を判定する。 サンドボックスは外部ネット exfil は防ぐが secret 読取や CWD 内の source code poisoning は防げないため、実行前チェックが必要。 以下の場面で使用 (review-loop skill からも呼ばれる): - 動作確認のため /tmp/check_*.py 等の一時スクリプトを実行 - 調査 snippet を uv run python や .venv/bin/python で走らせる - サブエージェントが生成したスクリプトを実行する 以下では使用しない: - プロジェクトに commit 済みのスクリプト (scripts/run.py 等) の実行 - allowlist 済み固定 entrypoint (pytest, ruff) の起動 - python -c "print(1+1)" レベルの 1 行 snippet (ただし未知モジュ...
Production-ready LINE bot with AI-powered expense tracking using TypeScript, Prisma, and Google Gemini. Comprehensive guide covering backend development, database design, AI integration, security, testing, and deployment.
Dodaje fakturę zakupu (koszt) do rejestru SQLite — zapisuje sprzedawcę, NIP, kwoty, kategorię, datę wpływu. Obsługuje wprowadzanie ręczne ORAZ OCR z pliku (PDF/JPG/PNG) przez lokalny Pixtral 12B z fallbackiem na Claude Haiku 4.5. Na ryczałcie koszty NIE pomniejszają podatku, ale VAT naliczony idzie do JPK_V7M jako odliczalny. Użyj gdy user mówi "dodaj fakturę zakupu", "zarejestruj koszt", "wprowadź wydatek", "kupiłem laptopa za...", "fakturę za hosting/SaaS/internet/paliwo", "dorzuć fakturę k...
Author pre/post-iteration hooks for an experiment session. Use when the user asks to add research fetching, Slack/webhook notifications, persistent learnings, auto-tagging, anti-thrash intervention, idea rotation, or any side effect around iterations.
Dispatches `forge-expert` subagents in parallel — one per chosen domain — to produce focused analyses of a feature against the codebase before a plan is drafted. Each expert covers one domain (architecture, performance, data/state, UI/UX, security, testing, build/tooling — pick from the role catalog) and returns a structured report citing `file:line` evidence. Use as Step 3 of the forge workflow, after the user has stated the feature and the orchestrator has gathered baseline codebase context...
specialized protocol for Swiss law queries (Federal and Cantonal). Triggers on topics like Fedlex, BV, OR, ZGB, or Canton-specific regulations.
Generate a runnable exploit-validation command (Nuclei template, Metasploit module hint, AI-assisted Python script, or curl-based PoC) against a user-specified authorised target. Use when validating that a fix actually closed the vulnerability path, confirming a patch deployed correctly, or producing a copy-pasteable test command for QA. The skill never executes — the user runs.
Search for exploits across all vulnerabilities with filtering by ecosystem, severity, source, and EPSS
Analyze exploit intelligence for a vulnerability against the current repository
Interactive co-authoring skill for the narrow end of the exploration funnel. Synthesizes session briefs, BRDs, story sets, and prototype notes into a structured handoff package targeted at the correct downstream consumer (e.g., formal software specs, strategic roadmaps, or process documentation).
Interactive co-authoring skill for the wide end of the exploration funnel. Captures and refines the core intent, whether the outcome is a software app, a business process improvement, research analysis, or strategic roadmap. Guides users through gathering context, iteratively drafting the brief, and testing for blind spots.