
Claude Skills by aibot88
github.com/aibot88Secure Persona API keys, webhook secrets, PII handling in verification data. Use when working with Persona identity verification. Trigger with phrases like "persona security-basics", "persona security-basics".
Persona eines Tool-Testers mit ISMS-Basics. Arbeitet dem Compliance-Manager zu, deckt Bugs und Effizienzprobleme in der TATSÄCHLICHEN Umsetzung auf, achtet auf Übersetzungen, UX-Konsistenz und Aurora-Design-System-Konformität. Aktivieren bei Triggern wie "aus dem Blickwinkel eines Tool-Testers", "als Tester", "QA-Sicht", "Test-Perspektive", "wie funktioniert das wirklich", "i18n-Check", "UX-Bug-Hunt" oder wenn User Feedback zu Real-World-Implementierungs-Qualität will. Primär DE.
Acts as a Personal Data Expert providing PDPA and GDPR compliance guidance, risk assessments, privacy documentation, and breach response procedures in Thai, grounded in official PDPC standards.
Pre-push adversarial review for personal repos before git push. Runs adversarial-input sweep, parallel-implementation symmetry audit, project AGENTS.md compliance, dead-code sweep, secrets scan. Use before any push; mandatory for repos that will become public or shared. Tier 2 sub-agent does the bulk; Tier 3 main synthesizes.
Bootstrap a new personal repo with industry-best-practice docs and defensive .gitignore. Routes by repo type (scratch / personal-published / portfolio-public). Ensures secrets/PII protection from the first commit. Triggered by 'create new repo', 'bootstrap [name]', '/repo-bootstrap'.
pev-harness を使うプロジェクトに Playwright を導入する自動 bootstrap skill。 npm install / browser binary / playwright.config.ts template / seed test template / `npx playwright init-agents --loop=claude` (Playwright agents 自動生成) の 5 step を 1 操作で完了する。 pev-e2e-verify skill の Preflight が「未setup」と判定した時に自動的に提案される。
Searches and downloads royalty-free images from Pexels API with smart filtering by orientation, color, and size. Generates attribution HTML and maintains a local deduplication index via SQLite.
Screen products for FDA, EPA, USDA, CPSC, FCC, and other government agency requirements using AskRosetta. Use when checking regulatory compliance for US imports.
Build frontend Solana applications with Phantom Connect SDK and Helius infrastructure. Covers React, React Native, and browser SDK integration, transaction signing via Helius Sender, API key proxying, token gating, NFT minting, crypto payments, real-time updates, and secure frontend architecture.
Audit pharmaceutical regulatory compliance -- inspection readiness, CAPA system effectiveness, change control pipeline, data integrity (ALCOA+), and validation lifecycle tracking. Covers FDA 21 CFR 210/211, EU GMP Annexes, ICH Q7-Q12, WHO Prequalification, and PIC/S guidelines. Evaluates 483 observation history, SOP currency, equipment qualification, training matrices, and compliance gap remediation. Use when preparing for FDA or EMA inspection, assessing CAPA closure rates, evaluating change...
Audit pharmaceutical QC laboratory operations -- OOS/OOT investigations, stability program trending, analytical method validation status, release testing optimization, and specification compliance. Covers ICH Q1A-Q1E stability guidelines, ICH Q2(R2) method validation, USP compendial verification, ALCOA+ data integrity, Croston shelf life estimation, and LIMS/CDS system evaluation. Use when reviewing OOS investigation quality, trending stability data, auditing method validation coverage, optim...
Enhance SEO (meta tags, semantic HTML) and security (vulnerability checks, hardening). Triggers: SEO, security, meta tags, vulnerability, 검색 최적화, 보안.
Verify codebase quality — architecture consistency, convention compliance, gap analysis. Triggers: code review, architecture check, quality, gap analysis, 코드 리뷰, 품질 검증.
Adaptive post-implementation phase verification through fresh subagents with S/M/L sizing (bug-fix → feature → architecture). Multi-agent pipeline with strict role zoning: Spec + Architecture (параллель) → Quality + Security + Forward-Look (параллель) → Adversarial Skeptic → fix → Regression Sweep → final report. Auto-scales 2 → 7 агентов в зависимости от размера фазы, чтобы не жечь токены на тривиальных правках. USE WHEN: an implementation phase is done and needs validation before moving to ...
Philips Hue スマートライトの制御スキル。Hue BridgeのローカルCLIP API v2を使用して照明のON/OFF、明るさ調整、色変更、シーン制御を行う。「Hueの電気をつけて」「リビングを暖色にして」「全部の照明を消して」「ライトの一覧」などの依頼時に使用。
Prüft Online-Banking-Phishing, pushTAN, Call-ID-Spoofing, grobe Fahrlässigkeit, Beweislast, Banklogs, Ombudsmann und Klage gegen Zahlungsdienstleister.
Write, extend, and debug PXI Playwright E2E tests for Phoenix. Use when adding PXI agent frontend specs, authoring LLM-as-judge rubrics, asserting PXI tool use, persisting PXI test runs as Phoenix experiments, or debugging PXI E2E failures.
Reference skill for Zoom Phone. Use after routing to a phone workflow when implementing OAuth, Phone APIs, webhooks, Smart Embed events, URI schemes, CRM or CTI dialers, or call handling automation.
Photon is a blazing-fast Python web crawler purpose-built for OSINT operations. It extracts URLs, emails, social media accounts, files, secret keys, JavaScript endpoints, and subdomains from target websites with multithreaded efficiency.
PHP 框架特定安全审计。当在 PHP 白盒审计中已识别目标使用特定框架、 需要检查框架特有安全机制和常见配置缺陷时触发。 覆盖 6 大框架: Laravel(Mass Assignment/Blade XSS/CSRF 例外)、 ThinkPHP(RCE 历史漏洞/路由注入/缓存写入)、WordPress(插件漏洞/权限钩子/nonce 验证)、 Symfony(Debug Bar/YAML 解析/安全投票器)、Yii2(RBAC/ActiveRecord 注入)、CodeIgniter(全局 XSS/CSRF Token)。
PHP 源码前端交互类漏洞审计。当在 PHP 白盒审计中需要检测前端安全相关漏洞时触发。 覆盖 5 类前端风险: XSS(反射/存储/DOM)、CSRF(Token 验证缺失)、 开放重定向(header Location 可控)、CRLF 注入(HTTP 响应拆分)、会话与 Cookie 安全(固定/劫持/属性)。 需要 php-audit-pipeline 提供的数据流证据。
Use when building PHP applications with modern PHP 8.3+ features, Laravel, or Symfony frameworks. Invokes strict typing, PHPStan level 9, async patterns with Swoole, and PSR standards. Creates controllers, configures middleware, generates migrations, writes PHPUnit/Pest tests, defines typed DTOs and value objects, sets up dependency injection, and scaffolds REST/GraphQL APIs. Use when working with Eloquent, Doctrine, Composer, Psalm, ReactPHP, or any PHP API development.
PHP coding rules from ai-toolkit: coding-style, frameworks, patterns, security, testing. Triggers: .php, composer.json, Laravel, Symfony, PHPUnit, PSR-12, Composer. Load when writing, reviewing, or editing PHP code.
PHP development — OOP patterns, Laravel basics, WordPress plugin development, REST API endpoints, wpdb queries, security (sanitization, nonces)
Threat library for physical-access threats that STRIDE and OWASP Top 10 don't cover — evil-maid, DMA, hostile peripheral, travel-host, coercion, cold-boot, supply-chain implant, side-channel
Authors system prompt additions for pi coding agent. Use when extending pi's default prompt with custom principles, guidelines, or project-specific rules via SYSTEM.md or APPEND_SYSTEM.md.
Use this skill to pick exactly one GitHub repository that needs a refresh: scan a given list of owners, collect signals of neglect — long stretches without commits, failing or absent CI runs on the default branch, outdated or vulnerable dependencies — score every candidate, and pick the single most neglected repository. If every repository looks reasonably fresh, still pick one — the least fresh of the bunch — because the contract of this skill is to always end with exactly one repository cho...
Picoclaw security posture skill with advisory awareness, configuration drift detection, and supply-chain verification guidance.
Handling personally identifiable information under European and Australian privacy regulations.
How to design a content hub that earns topical authority. Pillar topic selection, cluster planning, internal linking architecture, URL structure, pillar and cluster page anatomy, topical authority signals for SEO and AEO/GEO, and the maintenance discipline that distinguishes intentional hubs from accidental orphans. Triggers on pillar content, content hub, topic cluster, topical authority, content architecture, hub and spoke, pillar page, cluster page, content silo, internal linking strategy....
Deep GitHub Actions workflow expert. Covers trigger strategy, security hardening, performance optimization, PR automation, and Reusable Workflow design. Use when new GHA workflow design or advanced optimization is needed.
Pipedream is a developer-focused workflow platform for connecting APIs and running automation logic in hosted workflows. It fits ASE as a source-backed integration skill for agents that need to trigger apps, transform events, and chain API actions across services.
Use after completing any PRD, spec, plan, or code implementation — verifies that artifact-specific pitfalls (security, idempotency, integration contracts, edge cases, LLM output) do not apply before declaring work done. Two rounds max.
Pixa.com (eski Pixelcut) — Claude'a MCP-native baglanan yaratici AI araclari. Arka plan kaldir, gorsel olustur, kalite iyilestir, video olustur, nesne sil. API anahtari gerekmez.
Interactive planner for Polish national grants: FESL/FERS/NOWEFIO/NIW/CERV/ESC/KPO/FEnIKS/RITA/Slaskie Lokalnie. Decision tree for program selection, indicator mapping, budget planning. Triggers: plan projekt krajowy, zaplanuj FESL, plan FERS, plan NOWEFIO, nowy wniosek krajowy, grant krajowy.
Translates every clause of a contract into plain language at an 8th-grade reading level and flags deliberately confusing language patterns. Use when a user says "explain this contract", "what does this mean", or needs a non-lawyer to understand an agreement. Trigger with "/plain-english" or "translate this contract to plain English".
Use when asked to review project text for plain language compliance. Produces structured findings with rewrites. Triggers: plain language review, readability check, copy audit, make this clearer.
Audit a project plan against the actual implementation — verifying code, types, security, and Supabase backend alignment.
Harshly critique strategic documents (validation reports, competitive analyses, business plans) to identify blind spots, challenge assumptions, expose weaknesses, and generate Conductor-aligned action plans. Use when you need brutal honesty, "red team" analysis, or want to stress-test your thinking before execution. Applies multiple analytical frameworks (pre-mortem, assumption hunting, competitive gaps, market dynamics) and synthesizes findings into executive summaries with specific, actiona...
Documenta progreso y marca tareas completadas en PLAN_MEJORAS.md. Usa SIEMPRE después de completar cualquier tarea del plan de mejoras.
Guide for writing Gherkin acceptance criteria using Given-When-Then syntax for testable requirements. Covers scenario structure, background blocks, scenario outlines with examples tables, common patterns for authentication/CRUD/validation/error handling, and best practices for clear testable specifications. Essential for writing user stories and plan acceptance criteria
Turn a Zoom integration idea into an implementation plan with architecture, auth, and delivery milestones. Use when you need a practical build plan, phased delivery sequence, risk list, and next-step recommendation.
'Execute use when you need to work with backup and recovery.
Plausible Analytics is a lightweight, open-source, privacy-friendly alternative to Google Analytics. It requires no cookies, is fully GDPR/CCPA/PECR compliant, and provides a clean single-page dashboard with all essential website metrics and traffic insights.
Audit game analytics and telemetry implementation -- event tracking completeness, FTUE and monetization funnel coverage, retention metric infrastructure, A/B testing framework, heatmap data collection, churn prediction signals, and LTV modeling support. Covers Firebase Analytics, Unity Analytics, GameAnalytics, Amplitude, Mixpanel, Adjust, and custom pipelines. Use when verifying event tracking coverage, debugging missing funnel steps, auditing A/B test variant assignment, checking for PII in...
Synthetic user advocate that role-plays as end users to generate authentic feature requests, surface unmet needs, and challenge team assumptions. Don't use for real feedback analysis (Voice) or UI evaluation (Echo).
Analyze agent extensions and generate self-contained HTML wiki reports with security audit and architecture diagrams. Use when asked to analyze, audit, or document a plugin. Triggers on GitHub plugin URLs or local plugin paths.
Proactive codebase audit that discovers code quality issues, security vulnerabilities, performance problems, and architectural debt using parallel analysis agents, then creates well-structured issues in PinkRooster from confirmed findings. Use this skill whenever the user wants to audit their code, find problems, scan for issues, do a code review of the whole project, or says things like "audit the codebase", "find issues", "scan for problems", "what's wrong with the code", "check for securit...
Critically review the user-facing surface of a PRD, design spec, or feature proposal against behavioral and UX principles. Use when a PM has a solution in hand and wants the design layer pressure-tested — defaults, friction placement, choice architecture, information density, AI surface decisions, peak-and-end moments. Distinct from pm-red-team (strategy adversary) and pm-evaluator (rubric scoring); this skill stays at the design layer and asks whether the design works with human cognition or...
Adversarially re-review a PM artifact, recommendation, or AI-generated critique that already exists. Use as a second pass after another skill (pm-evaluator, pm-prd-drafter, pm-decision-coach, pm-value-hypothesis-tester) has produced output, or on any external AI output the user wants pressure-tested before deferring to it. Plays the role of a hostile exec, skeptical board member, or competing PM — looking for what the first pass missed, what bias it brought, and what would not survive a real ...