
Claude Skills by aibot88
github.com/aibot88Run a TOGAF Phase G Implementation Governance review. Produces Architecture Contracts (joint sponsor/delivery agreements), Compliance Assessments against the 8 TOGAF checklists, exception and dispensation logs, and Implementation Governance Model. Use when governing a live implementation project, validating that delivery is proceeding in line with the approved architecture, or preparing an Architecture Board submission for a project in flight.
Complete TDD workflow for implementing business logic (use cases) and API endpoints that make tests pass. Covers Zod safeParse validation, async/await patterns, Next.js API routes, service orchestration, and Clean Architecture compliance.
Implements new Agent Skills for the project. Identifies the AI coding tool (Cursor, Claude Code, Gemini CLI), ensures specification compliance, and provides specialized templates. Use when creating, authoring, or adding a new skill, or when the user asks about Agent Skills format or SKILL.md.
Implement role-based (RBAC) and attribute-based (ABAC) access control in Go using Casbin. Covers model configuration, GORM adapters, Chi/gRPC middleware, and production patterns. Use when implementing authorization in Go services.
'Process use when you need to track database changes for compliance and
Implements high-performance streaming using System.IO.Pipelines in .NET. Use when building network protocols, parsing binary data, or processing large streams efficiently.
Open one or more `<tracker>` tracking issues from a markdown file containing a batch of security findings (typically the output of an AI security review or a third-party scanner). Each finding in the file becomes one tracker, landing in the `Needs triage` board column with the standard issue-template body fields populated from the markdown sections. Unlike `import-security-issue` (Gmail) and `import-security-issue-from-pr` (public PR), there is no inbound reporter to reply to and no PR to ins...
Open a tracking issue in <tracker> for a security-relevant fix that has already been opened (or merged) as a public PR in <upstream>, in the case where there is no inbound `<security-list>` report. The tracker lands in the `Assessed` board column (the team-deliberate import implies the security assessment has already happened) with the scope label applied, `pr created` / `pr merged` reflecting the PR's state, and `Remediation developer` / `PR with the fix` body fields populated from the PR — ...
Scan <security-list> for reports that have not yet been copied into <tracker> as tracking issues, present the proposed imports to the user, and — defaulting to *import unless the user rejects upfront* — create the tracking issues with the `Needs triage` project-board status and draft a receipt-of- confirmation reply to each reporter. This is the first step of the handling process: the entry point that converts an inbound email thread into a tracker the rest of the skills (sync-security-issue,...
Convert impostor syndrome from a career liability into strategic fuel — diagnosing the specific competence gap behind the feeling, building a personal development strategy around it, and stacking strengths others don't have. Coaches new PMs, recently promoted leaders, and career changers through Brennan Collins' Insecurity-to-Strategy framework.
Improve adoption criterion A2 (Agent-Authored Contributions) by setting up the tooling and guidance that enables and tracks agent contributions. Raises the fulfillment level by one step.
Improve adoption criterion A7 (Proactive Quality Management) by configuring automated dependency updates, security scanning, and agent-driven tech debt PRs. Raises the fulfillment level by one step.
Improve readiness criterion C6.1 (Static Analysis) in the current project by adding linting, type checking, or security scanning. Raises the fulfillment level by one step.
Apply IN10 Red Teaming to organize adversarial review to find vulnerabilities through simulated attack.
Expert guidance for building and maintaining the Para Obsidian inbox processing system - a security-hardened automation framework for processing PDFs and attachments with AI-powered metadata extraction. Use when building inbox processors, implementing security patterns (TOCTOU, command injection prevention, atomic writes), designing interactive CLIs with suggestion workflows, integrating LLM detection, implementing idempotency with SHA256 registries, or working with the para-obsidian inbox co...
End-to-end incident-response playbook for a CVE actively in the wild — confirms urgency via KEV/EPSS/sightings, pulls IOCs and ATT&CK chain, fetches detection rules for installed families, evaluates patch path or workarounds, generates VEX attestation, posts a consolidated report. Use when a CVE goes hot, your dependency is named in a vendor advisory, or the team needs a one-conversation SOC response.
Guides teams through IT outages and security incidents, providing structured workflows for detection, containment, eradication, and post-mortem analysis.
Coordinate security incident response efforts. Includes classification, playbook generation, evidence gathering, and remediation planning. Validates response strategies against best practices.
Use this skill to convert a security incident or public vulnerability pattern into reusable audit prompts, checklists, tests, and AGENTS.md rules. Do not use it to generate exploit instructions.
Analyze a workplace safety incident tracking system for incident classification accuracy, root cause analysis depth, OSHA 300 log recordkeeping compliance, trend analysis capabilities, and leading indicator identification. Evaluates against ANSI Z10, ISO 45001, and OSHA 29 CFR 1904 standards. Use when building EHS software, auditing safety management systems, evaluating incident investigation quality, or preparing for OSHA inspections.
Apply inclusion/exclusion criteria systematically in literature reviews. Use when: (1) Screening abstracts, (2) Reviewing full texts, (3) Documenting screening decisions, (4) Ensuring PRISMA compliance.
Plan and create SpecWeave increments with PM and Architect agent collaboration. Use when starting new features, hotfixes, bugs, or any development work that needs specification and task breakdown. Creates spec.md, plan.md, tasks.md with proper AC-IDs and living docs integration.
Internet.nl batch API voor het geautomatiseerd testen van meerdere domeinen op internetstandaarden. Authenticatie, batch requests, polling, resultaten JSON, dashboard-integratie. Triggers: internet.nl API, batch API, bulk scan, compliance dashboard, internet.nl batch, API credentials, geautomatiseerd testen, domeinenscan, monitoring dashboard
Mailstandaarden getest door internet.nl: SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), DMARC (Domain-based Message Authentication), STARTTLS, DANE (DNS-based Authentication of Named Entities). Triggers: mail test, DMARC, DKIM, SPF, STARTTLS, DANE, mailserver beveiliging, email security, e-mailbeveiliging, mailstandaarden, anti-spoofing
Stap-voor-stap implementatiegidsen uit de internet.nl toolbox-wiki. Configuratie van DNSSEC, HTTPS/TLS, DMARC, DKIM, SPF, DANE en IPv6 op veelgebruikte platformen (BIND, NSD, Nginx, Apache, Postfix). Triggers: internet.nl toolbox, DMARC configuratie, DKIM instellen, SPF record, DANE opzetten, implementatiegids, DNSSEC instellen, Let's Encrypt, certificaat, mailserver configureren
Webstandaarden getest door internet.nl: HTTPS, TLS 1.2/1.3, HSTS, DNSSEC voor websites, IPv6 dual-stack, RPKI route origin validation, security headers (CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy), security.txt (RFC 9116). Triggers: web test, HTTPS, TLS, HSTS, DNSSEC website, security headers, security.txt, IPv6, RPKI, webstandaarden, website testen, Content-Security-Policy
Overzicht van alle internetstandaarden die internet.nl test. Routing naar sub-skills voor web, mail, API en toolbox. Triggers: internet.nl, internet standaarden, website compliance, mail compliance, internetstandaarden, open standaarden, Forum Standaardisatie, pas-toe-of-leg-uit
Infisical CLI retrieves, injects, and manages secrets across local development, CI/CD, staging, and production environments. It is useful when agent workflows need a structured way to pull environment variables and secret material without hardcoding credentials into scripts.
Infisical is an open-source platform for managing application secrets, environment variables, and certificates across teams and infrastructure. This skill enables agents to sync secrets, rotate credentials, and manage PKI using the Infisical CLI and API.
Apply the six principles of ethical persuasion (reciprocity, commitment, social proof, authority, liking, scarcity) to product design, copy, and sales. Use when the user mentions "social proof", "persuasive copy", "why users don't convert", or "ethical persuasion". For deal negotiation tactics, see negotiation. For viral word-of-mouth, see contagious. Trigger with 'influence', 'psychology'.
Use when the user needs an influencer campaign brief with discovery criteria, creator guidelines, FTC compliance checklist, and measurement plan.
Invoke when the user asks about influencer marketing, creator partnerships, UGC campaigns, influencer discovery, creator briefs, FTC compliance for sponsored content, influencer contracts, or influencer campaign measurement.
Design infrastructure solutions - analyze requirements, design cloud architecture, create comprehensive design documents with resource specifications, security considerations, cost estimates, and implementation plans. Designs S3 buckets, Lambda functions, DynamoDB tables, API Gateway endpoints, CloudFront distributions, and other AWS services based on feature requirements.
Audit infrastructure status, health, and compliance without modifications - provides observability and drift detection
Comprehensive infrastructure engineering covering DevOps, cloud platforms, FinOps, and DevSecOps. Platforms: AWS (EC2, Lambda, S3, ECS, EKS, RDS, CloudFormation), Azure basics, Cloudflare (Workers, R2, D1, Pages), GCP (GKE, Cloud Run, Cloud Storage), Docker, Kubernetes. Capabilities: CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins), GitOps, infrastructure as code (Terraform, CloudFormation), container orchestration, cost optimization, security scanning, vulnerability management, secrets m...
WHEN: Infrastructure security audit, secrets management, network policies, compliance checks WHAT: Secrets scanning + Network policies + IAM/RBAC audit + Compliance validation + Security hardening WHEN NOT: Application security → security-scanner, Docker only → docker-reviewer
Enforces Terraform best practices for safe and scalable infrastructure as code. Emphasizes modularity, state management, and security. Automatically applied for IaC implementation.
Test infrastructure configurations and deployments - security scanning with Checkov/tfsec, cost estimation analysis, pre-deployment validation, post- deployment verification, integration testing, generates comprehensive test reports with pass/fail status, identifies vulnerabilities and compliance issues, tracks test history for trend analysis.
Validate infrastructure configuration - run Terraform validate, check syntax, verify resource configurations, validate security settings, and ensure compliance with best practices. Reports validation errors and warnings.
Infrastructure-as-Code specialist for Terraform, AWS, Azure, and serverless architectures. Use when setting up cloud infrastructure, writing Terraform modules, or deploying to AWS Lambda/Vercel/Cloudflare. Covers VPC configuration, container orchestration, and CI/CD pipeline infrastructure.
Creates automated backup procedures, executes restoration operations, and implements disaster recovery workflows for network infrastructure. Use when backing up infrastructure before changes, preparing for disaster recovery, migrating to new server, or restoring after failure. Triggers on "backup infrastructure", "restore from backup", "disaster recovery", "backup before upgrade", or "migrate infrastructure". Works with Docker volumes (caddy_data, pihole_data), configuration files (docker-com...
Use when an approved system design exists and the team needs production-grade platform and infrastructure architecture before IaC implementation. Produces cloud and account topology, environment model, runtime substrate selection, network and trust-boundary architecture, identity and secrets strategy, deployment and release substrate, IaC ownership boundaries, CI/CD posture, operational platform services, cost strategy, disaster posture, and implementation handoff guidance. Do not use for Ter...
Verify AWS infrastructure configuration before deployment. Use when validating VPC endpoints, NAT Gateway capacity, security groups, or debugging network path issues that cause Lambda connection timeouts.
OWASP Infrastructure Top 10 vulnerability knowledge base for identifying, assessing, and remediating security risks in internal IT infrastructure environments.
Extract article content from dev.to posts for wiki ingestion. Uses dev.to public API, no auth required.
Extract content from GitHub gists for wiki ingestion. Uses raw URL fetch, no auth required.
Extract content from GitHub Discussion threads for wiki ingestion. Uses gh CLI GraphQL API, authenticated via gh auth.
Extract Hacker News threads (post + comments) for wiki ingestion. Uses Algolia HN API, no auth required.
Ingest LinkedIn posts into the wiki. Supports pasted text or cookie-based auth for URL fetching.
Extract post and comments from Reddit threads for wiki ingestion. Appends .json to any Reddit URL, no auth required for public subreddits.