
Claude Skills by aibot88
github.com/aibot88Investigate GCP network issues by analyzing VPC Flow Logs, firewall logs, Cloud NAT logs, threat logs, and networking metrics. Diagnose connectivity, packet loss, top talkers, and firewall block events using BigQuery-first methodology and Cloud Monitoring fallback. Use when investigating VPC traffic anomalies, firewall DENY events, NAT port exhaustion, latency spikes, or running Connectivity Tests for path diagnostics.
Govern GCP Artifact Registry — container image signing via Binary Authorization, vulnerability scanning via Container Analysis, repository IAM least privilege, artifact retention policies, and supply chain security posture.
Audit and govern Cloud KMS key lifecycles, Secret Manager secrets, CMEK configurations across GCP services (Cloud SQL, BigQuery, GCS, Compute), key rotation schedules, and envelope encryption patterns. Prefer gcp-iam-least-privilege-review for IAM binding review on KMS keys and gcp-security-posture-hardening for broad org-level encryption policy gaps.
Review GCP security posture via Security Command Center findings, CIS GCP Benchmark gaps, org policy enforcement baseline, Assured Workloads controls, Binary Authorization, and CSPM recommendations. Prefer gcp-iam-least-privilege-review for IAM binding surgery and gcp-vpc-service-controls-architect for VPC-SC perimeter design unless the request is primarily broad posture hardening.
Review Cloud Run and Cloud Functions gen2 for production readiness — min-instances cold start, memory and CPU allocation, VPC connector configuration, Secret Manager injection, CMEK encryption, concurrency limits, and traffic splitting safety.
Configure GCP IAM, Secret Manager, and VPC networking with security best practices. PROACTIVELY activate for: (1) setting up service accounts and IAM permissions, (2) managing secrets in Secret Manager, (3) configuring VPC and firewall rules. Triggers: "iam", "secret manager", "vpc"
GCP 到 Google Workspace 的穿越攻击方法论。当已获取 GCP Service Account 或 Project 权限并发现目标组织使用 Google Workspace、需要从云平台穿越到企业邮件/文档/管理控制台、或发现 Domain-Wide Delegation 配置时使用。覆盖 Domain-Wide Delegation 滥用、OAuth 范围利用、Workspace API 数据窃取(Gmail/Drive/Calendar/Admin Directory)、以及 Workspace 持久化技术
Playwright-based game playtesting and design validation. Use when validating implementation against GDD, testing gameplay mechanics, capturing screenshot evidence, performing game state detection via Vision MCP, or conducting visual GDD compliance validation.
Audits web applications to ensure declared privacy policies match actual technical data collection practices. Use to identify discrepancies in cookie usage, tracking scripts, and user data handling.
Aide à vérifier la conformité RGPD/GDPR d'un site, d'une app ou d'un traitement de données. Se déclenche aussi avec "RGPD", "GDPR", "données personnelles", "politique de confidentialité", "cookies", "conformité", ou toute question de protection des données.
Audits web applications and architectures for compliance with GDPR, CCPA, and other privacy regulations, focusing on consent, data minimization, and user rights.
Helpt bij het opstellen en reviewen van Data Protection Impact Assessments (DPIA) onder de AVG/GDPR. Genereert DPIA-templates, checkt verwerkingsgrondslagen, valideert bewaartermijnen, reviewt verwerkersovereenkomsten, en helpt bij het opstellen van een verwerkingsregister. Toegesneden op Nederlandse overheidsorganisaties met BIO2 en AP-richtlijnen. Gebruik deze skill wanneer de gebruiker vraagt over 'DPIA', 'GEB', 'gegevensbeschermingseffectbeoordeling', 'privacy impact assessment', 'PIA', '...
Implementa export e delete de dados pessoais por padrão
Access Google Drive via CLI with 1Password OAuth. Use when user wants to list files, download from Drive, sync folders, or mentions google drive access. TRIGGERS - google drive, gdrive, drive folder, download drive, sync drive, list drive files.
Steuert gruppenweite Policies, Auslagerung, Dienstleister, ausländische Tochtergesellschaften, Datenflüsse und Kontrollberichte.
Baut praxistaugliche interne Sicherungsmaßnahmen, Richtlinien, Kontrollen, Eskalationen, Schulungen und Audit-Trail.
Gemini CLI sub-agent system for persona-based analysis. Use when piping large contexts to Google Gemini models for security audits, architecture reviews, QA analysis, or any specialized analysis requiring a fresh model context.
Gemini CLI の Code Review 拡張で、作業後レビューを安全に実行するための最小手順と再発防止ルールを案内します。
Migrate AI image generation from Google Gemini 2.5 Flash to BytePlus SeeDream v4.5. Use when: (1) User wants to switch from Gemini to SeeDream/BytePlus for image generation, (2) User asks about migrating image generation APIs or replacing Gemini with BytePlus, (3) User needs cost optimization or better image quality for AI-generated images, (4) User mentions SeeDream, BytePlus, or wants SDK-to-REST API migration for image generation
Lightweight offline multilingual translator powered by Gemma. Translates between English, Hindi, Kannada, and 20+ languages — fully on-device, zero API keys, complete privacy.
Cross-product Zoom reference skill. Use after the workflow is clear when you need shared platform guidance, app-model comparisons, authentication context, scopes, marketplace considerations, or API-vs-MCP routing.
How to generate share-imagery (OpenGraph banners, portraits, squares, tall WhatsApp/iMessage cards) for any Lossless site or splash page so the resulting images form a coherent visual family. Use whenever a site, splash, plugin page, or fundraise deck needs an OG image generated or refreshed; whenever the user says "make an og image", "generate a banner", "we need a share image", "regenerate banners across formats", "the unfurl looks stale"; whenever scaffolding a new Astro Knots site that do...
Generate a CVE 5.x JSON document from an <tracker> tracking issue, ready to paste into the Vulnogram `#source` tab of the ASF CVE tool at https://cveprocess.apache.org/cve5/<CVE-ID>#source. The conversion is deterministic: same issue in, same JSON bytes out. Handles multiple credits (one per line) and multiple references (URLs extracted from the issue's "Public advisory URL" and "PR with the fix" fields; the "Security mailing list thread" field is treated as internal-only and never exported).
Create standardized report headers with metadata for all agent-generated reports. Use when generating bug reports, security audits, dependency reports, or any worker output requiring consistent formatting.
Generate repository class for SQLite data access with CRUD methods, row mapping, and TypeScript types. Use when creating new database tables or data access layers.
Create comprehensive API documentation with examples, authentication guides, and SDKs. Use when creating comprehensive API documentation. Trigger with phrases like "generate API docs", "create API documentation", or "document the API".
Generate comprehensive compliance reports for security standards. Use when creating compliance documentation. Trigger with 'generate compliance report', 'compliance status', or 'audit compliance'.
PRIMARY expert for ALL NestJS and @lenne.tech/nest-server tasks. ALWAYS use this skill when working in projects with @lenne.tech/nest-server in package.json dependencies (supports monorepos with projects/*, packages/*, apps/* structure), or when asked about NestJS modules, services, controllers, resolvers, models, objects, tests, server creation, debugging, or any NestJS/nest-server development task. Handles lt server commands, security analysis, test creation, and all backend development. AL...
PRIMARY expert for ALL NestJS and @lenne.tech/nest-server tasks. ALWAYS use this skill when working in projects with @lenne.tech/nest-server in package.json dependencies (supports monorepos with projects/*, packages/*, apps/* structure), or when asked about NestJS modules, services, controllers, resolvers, models, objects, tests, server creation, debugging, or any NestJS/nest-server development task. Handles lt server commands, security analysis, test creation, and all backend development. AL...
Generate comprehensive security audit reports for applications and systems. Use when you need to assess security posture, identify vulnerabilities, evaluate compliance status, or create formal security documentation. Trigger with phrases like "create security audit report", "generate security assessment", "audit security posture", or "PCI-DSS compliance report".
Genere un fichier Zoom SQL (.dhsp) complet avec les 27 procedures obligatoires du cycle de vie ecran CRUD (creation, modification, suppression, consultation). Inclut les appels framework (Select, PreInsert, PostInsert, etc.), la construction de conditions de selection, la gestion des reservations, et les hooks de personnalisation. Ecrit en ISO-8859-1+CRLF. A utiliser pour creer l'interface utilisateur d'une entite metier (troisieme fichier du pattern 3 fichiers).
Audite un projet tech (code source + expérience rendue) et évalue son adéquation à 5 cohortes générationnelles (Boomers, Gen X, Millennials, Gen Z, Gen Alpha). Produit un rapport markdown et un JSON exploitable. Utiliser quand l'utilisateur demande un audit générationnel, une analyse d'audience, une évaluation cross-génération, ou veut savoir quelle génération un produit cible réellement.
Use when reasoning about the pattern where a language model emits, as structured output, a description of UI components or a UI sub-tree that an application then renders for the user: the typed-schema component palette, the structured-output mechanism (JSON Schema, function-calling) that constrains emission to renderable specs, the application-side render pipeline that turns the spec into pixels, the interaction loop by which user actions on the rendered UI flow back into the next turn, the s...
Code generator skills that produce production-ready Swift code for common app components. Use when user wants to add logging, analytics, onboarding, review prompts, networking, authentication, paywalls, settings, persistence, error monitoring, CI/CD pipelines, localization, push notifications, deep linking, testing, accessibility, widgets, feature flags, app icons, image caching, pagination, HTTP caching, share cards, social export, subscription lifecycle, referral systems, watermarks, streak...
Review code for bugs, security vulnerabilities, performance issues, accessibility gaps, and CLAUDE.md workflow compliance. Supports any tech stack - HTML/CSS/JS, React, TypeScript, Node.js, Python, NestJS, Next.js, and more. Use when completing features, before commits, or reviewing pull requests.
Review full-stack code for bugs, security vulnerabilities, performance issues, accessibility gaps, and CLAUDE.md compliance. Enforces TypeScript strict mode, input validation, GPU-accelerated animations, and design system consistency. Use when completing features, before commits, or reviewing pull requests.
Review React/TypeScript code for bugs, security vulnerabilities, performance issues, accessibility gaps, and CLAUDE.md workflow compliance. Enforces TypeScript strict mode, GPU-accelerated animations, WCAG AA accessibility, bundle size limits, and surgical simplicity. Use when completing features, before commits, or reviewing pull requests.
Review static site code for bugs, security issues, performance problems, accessibility gaps, and CLAUDE.md compliance. Enforces pure HTML/CSS/JS standards, minimal page weight, mobile-first design. Use when completing features, before commits, or reviewing changes.
Gentleman.Dots / Gentleman Programming alongside DobackSoft. Tono y jerarquía ya aplican siempre vía .cursor/rules/gentleman-dobacksoft.mdc; esta skill amplía instalación y globs de archivos Gentleman.
SEO & GEO content linter — validates Markdown/MDX files for AI search visibility using 92 deterministic rules (35 GEO, 32 SEO, 14 content quality, 8 technical, 3 i18n). Runs an autonomous lint-fix loop: scan content, read structured violations, fix them, re-lint until clean. Use when optimizing content for AI citations, auditing SEO compliance, checking GEO readiness, or running pre-publish content validation. Triggers on: "geo-lint", "lint content", "SEO audit", "GEO", "content optimization"...
Generative Engine Optimization (GEO) / Answer Engine Optimization (AEO) — make a site citable by ChatGPT, Perplexity, Claude, Gemini, and Google AI Overviews. Generates llms.txt and llms-full.txt, fills schema.org coverage gaps (Organization, Person/Author, Article, Product, FAQPage, HowTo, BreadcrumbList), audits entity density (target 15+ recognized entities per pillar page → 4.8x AI Overview selection rate), tests AI crawler parity (fetches as GPTBot / PerplexityBot / OAI-SearchBot / Claud...
Search for gene expression DataSets and Profiles in the NCBI GEO database. Use this skill when the user wants to find microarray, RNA-seq, or other genomic data by keywords, organism, author, or specific fields.
Live, real-time queries to **Handelsregister** (Germany). Drops the OpenRegistry MCP toolset onto a single-country workflow when the user names Handelsregister, the country, or its registry directly. ID format: Court-prefixed Handelsregister number (e.g. `HRB 123456 B` Berlin, `HRB 12345 München`). Returns the registry's response unmodified — every field name, status string, and filing byte preserved verbatim. Use this skill when the user explicitly mentions: German company, Handelsregister, ...
Pruefraster fuer die Geschaeftsfuehrer-Haftung nach § 43 GmbHG iVm § 93 AktG. Erfasst Sorgfalt eines ordentlichen Geschaeftsmannes Business Judgement Rule analoge Anwendung § 93 Abs. 1 Satz 2 AktG fuer GmbH BGH II ZR 124/06 ARAG/Garmenbeck Insolvenzantragspflicht-Verletzung § 15a InsO § 15b InsO neue Zahlungsverbot Folgehaftung Compliance-Pflichten Auswahl Ueberwachung Mitarbeiter Steuern-Haftung § 69 AO Sozialversicherung § 266a StGB. Entlastung Geschaeftsfuehrer-Sperrwirkung Beweislast nach...
Gesellschafts-Compliance-Tracker – Initialisierung, Fälligkeitsbericht, Status-Update, Gesundheits-Audit, Export. Pflegt eine compliance-tracker.yaml aus der Gesellschaftstabelle, berechnet Einreichungsfristen nach Rechtsträger und Rechtsordnung und zeigt auf, was in den nächsten 30/60/90 Tagen fällig ist. Trigger: „Gesellschafts-Compliance\", „Einreichungsfristen\", „Bilanzpublizität\", „Transparenzregister\", „Jahresabschluss einreichen\", „was ist fällig\".
Erste 100 Tage Geschaeftsfuehrer-Pflichten nach HR-Eintragung. Buchfuehrung Bilanz Jahresabschluss Veroeffentlichung Bundesanzeiger. Steuer-Anmeldungen USt LSt KSt GewSt. Sozialversicherungs-Anmeldungen. Insolvenzantragspflicht Paragraf 15a InsO. Compliance GwG Datenschutz Arbeitsschutz. Haftung Paragraf 43 GmbHG. Sorgfaltspflichten.
Geschaeftsordnung der Geschaeftsfuehrung. Zustimmungspflichtige Geschaefte Berichtspflichten Meeting-Rhythmus Entscheidungs-Prozesse Eskalations-Matrix bei Mehrgliedrigkeit. Abgrenzung Satzung SHA Geschaeftsordnung. Aenderbarkeit Form. Beispiel-Kataloge fuer Standard-GmbH und Tech-Startup.
Use when user asks about 8 Gesundheit, Health, Social Security, health, Gesundheit, Sozialversicherung, AHV, IV, Heilmittel, Krankenversicherung, KVG, Lebensmittel, SR 8xx. Covers SR category 8 of the Systematische Rechtssammlung.
Save, search, list, and organize Get 笔记 notes, images, tags, and knowledge resources through the Get 笔记 OpenAPI. Use when storing text or links as notes, uploading an image into a note workflow, recalling prior notes, inspecting note details, managing tags or knowledge bases, or recovering from Get 笔记 authentication failures with the local auth.json setup.
When the user wants to choose or execute third-party platform SEO (high-authority sites for rankings or backlinks). Also use when the user mentions "parasite SEO," "parasitic SEO," "barnacle SEO," "hosted content," "third-party publishing," "Medium SEO," "Reddit SEO," "GitHub parasite SEO," "LinkedIn Pulse SEO," "high-authority platforms," "distributed authority," "borrow domain authority," or "rank without own website." For GitHub-specific playbooks, use github. For Medium.com posts, use med...