
Claude Skills by aibot88
github.com/aibot88Run a thorough TLS preflight against a host before launch, certificate renewal, or incident review.
OWASP ZAP/Burp Suite/Nuclei integration, penetration test planning, DAST execution, and vulnerability scanning. For dynamic security testing, pentesting, or runtime vulnerability validation. Complements Sentinel static analysis.
Use when locating a bug in an unfamiliar codebase, tracing a failure from symptom to source, or choosing between candidate fixes after the symptom is observed but before a patch lands. Covers the locate-to-solve workflow: problem-statement contract, search-space reduction, boundary-based fault localization, good-vs-bad path comparison, binary search through a call chain, minimal repro, root-cause isolation, fix option comparison, blast-radius review, and post-fix verification. Do NOT use for ...
Procore install auth — construction management platform integration. Use when working with Procore API for project management, RFIs, or submittals. Trigger with phrases like "procore install auth", "procore-install-auth".
Procore security basics — construction management platform integration. Use when working with Procore API for project management, RFIs, or submittals. Trigger with phrases like "procore security basics", "procore-security-basics".
Audit procurement and procure-to-pay systems for spend analytics (Pareto analysis, tail spend visibility), supplier consolidation opportunities, Kraljic matrix category management, maverick spending detection, contract compliance and utilization tracking, three-way PO matching, CIPS-standard sourcing workflows, approval matrix enforcement, P-card policy controls, and total cost of ownership modeling in SAP Ariba, Coupa, Jaggaer, or custom P2P platforms.
Use when running an annual SaaS audit, doing category-level spend review, or rationalizing the supplier base — when the user needs to do a spend audit, spend categorization (UNSPSC-aligned), purchasing-cycle analysis, or risk-balanced supplier consolidation. Triggers on "spend audit", "SaaS audit", "spend categorization", "supplier rationalization", "supplier consolidation", "purchasing cycle", "procurement review", "category strategy", "duplicate SaaS", "renewal cluster". Ships 3 stdlib-only...
Use when the user explicitly selects the prod-check skill or wants a pre-production code review scoped to recent commits, checking impact, contracts, auth, stability, and regressions.
Audit film, television, and digital content production budgets for above-the-line (ATL) and below-the-line (BTL) cost accuracy, SAG-AFTRA/DGA/WGA/IATSE union rate compliance, fringe and payroll tax calculations, VFX bid variance analysis, post-production cost validation, completion bond readiness, EFC (Estimated Final Cost) projections, tax incentive qualification tracking, and financing waterfall alignment using Movie Magic Budgeting, Hot Budget, or EP formats.
Ring-standards-aligned production readiness audit across Structure, Security, Operations, Quality, and Infrastructure — 43 base dimensions + 1 conditional (multi-tenant) = up to 44 dimensions. Use before production deployment, periodic reviews, onboarding, or major releases. Skip for prototypes, libraries, or single-dimension checks. Runs explorers in batches of 10 and produces a scored report (0-430 base, max 440 with multi-tenant) with severity ratings.
Comprehensive system audit methodology for production web applications. Use when auditing systems before launch, identifying technical debt, troubleshooting systematic issues, preparing for security reviews, or creating improvement roadmaps. Systematically audits database schema, API endpoints, external integrations, performance, security, and monitoring across all layers.
API de Produtos da Tray. Utilize quando o desenvolvedor precisar listar, consultar, cadastrar, atualizar ou excluir produtos no catálogo de uma loja Tray. Inclui todos os campos do produto (nome, preço, estoque, EAN, NCM, dimensões, SEO), filtros de listagem, paginação, ordenação e exclusão de kits.
Use when authoring or modifying any claude-team-toolkit skill that loads credentials, switches between accounts/orgs/environments, or needs confirmation for destructive operations. Reference for the shared profile + ctt_* helper pattern used by all credential-bearing skills.
Use this skill when the user wants to audit a Solana or Anchor program for security vulnerabilities — account validation, PDA safety, arithmetic, CPI risks, reinit attacks, and authority confusion. Includes a checklist and the most common bug classes.
The project's institutional memory and decision authority. Acts as an autonomous representative of the project — its goals, architecture, conventions, constraints, and intent. Use this skill whenever the active agent or another skill needs clarification about the project before proceeding. Triggers on: "/project-ambassador", "/ambassador", "ask the ambassador", "check with the ambassador", "what does the project want", "what's the project's stance on", or when any skill produces clarifying qu...
Use for deep Node.js / Express project analysis: boot flow, middleware order, async behavior, data layer, auth/security, and Node-specific runtime failure patterns.
Use for deep Symfony project analysis: kernel/bootstrap, container wiring, routing/request flow, Doctrine, security, Messenger, and Symfony-specific failure patterns.
Run a comprehensive audit on any Claude Code project. Scores 10 categories from 0-10 (total /100), identifies gaps, and generates a prioritized fix kit with copy-pasteable solutions. Use when you want to evaluate and improve your Claude Code setup, developer experience, security posture, or project quality.
Opinionated defaults for the lower-stakes structural conventions every project has to pick — branch strategy, directory layout, dependency pinning, path portability. The companion to manage-secrets-env (which owns the high-stakes secrets/env slice). Picks GitHub Flow, enforces pinned dependencies, nudges toward domain-first directory structure, and audits for hardcoded absolute paths. Adapts to repo type — app (exact pin + lockfile), library (semver range + compatibility matrix), monorepo (pe...
Manage project goals — binary business goals.
SQLite-based project documentation logger for tracking API references, components, and project progress. Use this skill when documenting code changes, adding API documentation, recording component updates, or tracking project milestones. Automatically invoked when user mentions documentation, changelog, API docs, component docs, or project updates.
Skill multi-SGBD para operar bancos de dados (SQL Server, MySQL, SQLite, PostgreSQL, Firebird) via CLI. Cobre conexão, cache de sessão por pasta de SGBD, varredura automática pós-conexão, inspeção de colunas com PK (fields por database > schema > table), renovação de cache a cada 15 min e política de limpeza (7 dias). Usar quando o usuário pedir para conectar, explorar, consultar, exportar dados ou executar scripts SQL.
Project introspection — detect languages, frameworks, database, structure, scale, auth, CI/CD
Best Practices Setup fuer neue Projekte — Testing, Linting, Git Hooks, CI/CD, Security
Use when implementing project state detection, designing STATE.md/TASKS.md templates, or configuring SQLite state store and MCP state protocol
Strukturierte Projekt- und Ordnerarbeit fuer immobilienrechtliche Rechtsabteilungen statt freihaendigem Prompting. Pro Mandat oder Objekt entsteht ein Projekt-Ordner mit fixierten Vorgaben — Playbook Mustervertraege Klauselkatalog AVV-Anforderungen Zitierregeln. Skill prueft eingehende Dokumente automatisch gegen die Projekt-Vorgaben einschliesslich AVV-Pruefung nach Art. 28 DSGVO und interner Compliance-Vorgaben. Erzeugt Projekt-Skelett mit Unterordnern Vertraege Korrespondenz Schriftsaetze ...
Use this skill when reviewing Prometheus or AlertManager configuration for cardinality, alerting correctness, scrape security, remote_write safety, or retention adequacy. Trigger when a user provides prometheus.yml, alertmanager.yml, recording rules YAML, alerting rules YAML, or asks whether their Prometheus setup is production-ready.
Design, review, or refactor prompt assembly systems with static and dynamic prompt boundaries, section registries, cache-aware composition, feature-gated overlays, and session-specific instruction injection. Use when Codex needs to build or audit system prompt pipelines, prompt builders, prompt layering, or instruction composition code.
All-in-one prompt engineering competition toolkit — attack generation, defense hardening, real-time analysis, and pattern reference for AI security tournaments like Clash of Prompts. Use when preparing for or competing in prompt engineering competitions, red-teaming LLMs, hardening system prompts, analyzing prompt injection techniques, or practicing timed prompt challenges. Trigger phrases include "prompt clash", "prompt competition", "prompt tournament", "red team this prompt", "harden this ...
Write and refine production-grade prompts and tool definitions for Claude. Use when the user needs to craft a system prompt, improve an existing prompt, design tool schemas (ACI), or apply techniques like few-shot, XML structuring, role prompting, or chain-of-thought. Covers Claude 4.6 specifics. Do NOT use for skill authoring (use skill-author) or agent architecture (use agent-patterns).
Prompt engineering specialist for system prompt optimization. Designs effective prompts, A/B testing, prompt injection detection, AI response quality. Triggers: 'prompt', 'system prompt', 'AI quality', 'prompt injection', 'LLM output'. Use when: creating/improving prompts, testing effectiveness, debugging poor AI responses, securing against injection.
Publishable Prompt Engineering skill package that compiles a user request into a ready-to-use high-quality Prompt, with support for diagnosis, module injection, debugging, and evaluation.
Use when evaluating prompts, LLM outputs, red-team suites, or model behavior with local eval configs and safe provider/cost controls.
Defensive prompt scaffolding, injection prevention, safety guardrails. 防禦提示架構、注入防護、安全護欄之法。 Use when: building user-facing prompts, hardening against injection attacks, adding safety layers to system prompts.
MSBuild property definition patterns: conditional defaults, composition/concatenation, path normalization, trailing slash handling, TFM detection helpers, and property evaluation order. Only activate in MSBuild/.NET build context. USE FOR: diagnosing and fixing MSBuild property definition issues in .props or .csproj files, reviewing and fixing shared property configuration anti-patterns, fixing DefineConstants or NoWarn being overwritten instead of appended, fixing unconditional property assi...
Property-based and generative testing across the polyglot stack. TRIGGER when: user asks about property-based testing, generative testing, QuickCheck, Hypothesis, proptest, StreamData, fast-check, fuzzing test inputs, or finding edge cases that example tests miss. DO NOT TRIGGER when: user asks about TDD workflow (use tdd), mutation testing (use tdd), load testing (use performance-profiler), or security fuzzing (use security-audit).
proselint is a Python CLI tool that lints English prose for style and usage issues. It aggregates writing advice from renowned authors and editors including Bryan Garner, David Foster Wallace, and Strunk & White into automated checks that scan text files and flag problems.
Protocol Pinky — 16-expert frontend panel with dynamic UI-lib routing. 2 React architects, 1 TS architect, 1 State/Data, 1 MUI, 1 UX/a11y, 1 Contracts, 1 Test, 1 i18n, 1 Security, 1 Performance, 1 Business Impact, 1 Backend Contract, 1 Monorepo, 1 Tailwind, 1 UI Component Library.
ขั้นตอนการติดตั้งและตั้งค่า Provider ID OAuth (ผ่าน Health ID / moph.id.th) ด้วย Auth.js (next-auth v5) ใน Next.js App Router — ครอบคลุม: การติดตั้ง package, การสร้างปุ่ม Login, การ redirect ไปยัง OAuth Provider, การรับ callback พร้อม exchange token, การดึง profile จาก provider.id.th, และการสร้าง session ด้วย Auth.js Credentials Provider + JWT Strategy.
Create Microsoft Entra Agent Identity blueprints, principals, and agent identities with the right beta Graph permissions, sponsor rules, and sidecar-based auth patterns.
Intercept, inspect, and modify HTTP/HTTPS traffic via a Rust MITM proxy with Lua scripting hooks. Supports API debugging, LLM call capture for evals, endpoint mocking, CORS/auth header injection, latency simulation, and telemetry blocking. Triggers on 'proxy', 'intercept traffic', 'inspect requests', 'mock API', 'capture API calls', 'MITM', 'network debug', 'HTTP inspection'.
Podiva se na posledni screenshoty z OneDrive Screenshots slozky a precte jejich obsah pomoci token-free OCR (Windows OCR API nebo Tesseract). Trigger: 'prtsc', '/prtsc', 'podivej se na screenshoty', 'co je na poslednim screenshotu', 'precti posledni screenshot'. Pouzij kdykoli uzivatel chce precist nebo popsat obsah nedavnych screenshotu.
Schnuert das vollstaendige Pruefer-Paket nach Abschluss eines Wuerfellaufs — Excel-Wuerfel-Datei aus Skill `excel-multi-sheet-export` PDF-Bericht aus `pdf-bericht-erzeugen` Belegketten-CSV aus `belegkette-rueckverfolgung` Audit-Trail-Auszug aus `audit-trail-protokoll` Prompt-Versionen aus `prompt-versionierung` Widerspruchsbericht aus `kreuzblatt-konsistenzpruefung` Ampel-Aggregat aus `risikoampel-aggregation` Pruefer-Flag-Arbeitsliste. Erzeugt ein ZIP-Paket plus Begleitschreiben. Pflichtschr...
Use for browser or GUI automation tasks that require iterative scripts, runtime adaptation, and debugging loops (for example dynamic scraping, authenticated web flows, CAPTCHA handoffs, and headed/headless browser control).
Audit public sector and government resource allocation systems for budget optimization algorithms (zero-based, incremental, performance-based), service demand forecasting (ARIMA, Prophet, regression), equity-based distribution scoring (CDC SVI, environmental justice indices, disparate impact analysis), GIS geographic coverage and service gap analysis, workload-based staffing models, grant drawdown compliance tracking, and transparency dashboard reporting for municipal, county, and state agenc...
TspoonBase — a TypeScript backend-as-a-service with SQLite, auth, realtime, file storage, AI tools, vector search, and Admin UI. Use when a user wants to build a backend, scaffold a BaaS, add auth/CRUD/realtime to a project, deploy a PocketBase-like backend in TypeScript, or needs help with TspoonBase CLI commands, API usage, or deployment. TRIGGER when: code imports `tspoonbase`; user asks to create, deploy, or manage a backend; user mentions PocketBase, BaaS, SQLite backend, auth backend, r...
Tracks every manuscript, paper, and research output currently in the publication pipeline from email — where each is in the review and submission process, what reviewer feedback is outstanding, what revisions are due, and what co-author actions are needed. Use when a researcher wants a full view of their publication pipeline without checking each journal portal manually. Triggers on "publication pipeline", "manuscript status", "paper submission status", "reviewer feedback", "revisions due", "...
Helpt bij het open-source publiceren van overheidssoftware conform de Standard for Public Code, publiccode.yml, REUSE-compliance en de Nederlandse open-sourcerichtlijnen. Biedt richtlijnen voor codebase governance, licentiekeuze, community-opbouw en publicatie op developer.overheid.nl. Gebruik deze skill wanneer de gebruiker vraagt over 'publieke code', 'public code', 'Standard for Public Code', 'publiccode.yml', 'publiccode yaml', 'REUSE', 'REUSE compliance', 'REUSE-compliant', 'open source ...
Use when the user has authored a GitHub pull request and wants to work through review feedback on it. Triggers on phrases like "pull down the review on #N", "address the feedback", "what did @reviewer say on my PR", "let's work through the comments", or any request to triage, respond to, or systematically handle review threads on the user's own PR. Do NOT use for reviewing someone else's PR, authoring PR content or replies, or checking which PRs are waiting on the user for review.
Invoke this skill BEFORE running any gh pr create, gh pr edit, or gh pr comment command, or any task that will produce or modify a GitHub pull request. This is the skill for authoring outbound PR communication: creating, drafting, opening, filing, or starting a PR; updating a PR body or description; posting a comment or reply to review feedback. Trigger on short and casual phrasings, not only the literal word "create". Example triggers: "create a PR", "draft a PR", "open a PR", "file a PR", "...