
Claude Skills by aibot88
github.com/aibot88Deep-dive Pulumi stack review, component design, Automation API audit, and secrets management. Use for structured investigations of Pulumi stack drift, ComponentResource coupling, ESC configuration, and Automation API workflows. Triggers on: "Pulumi audit", "stack review", "Automation API review", "ComponentResource design", "ESC audit", "Pulumi secrets", "Pulumi testing".
Generates pixel-perfect PDFs from web pages using Puppeteer with custom headers, footers, and page breaks. Supports authenticated pages via cookie injection.
Pwn/Binary kategorisi SKILL.md — BOF, ROP, kernel exploit araçları kurma rehberi
PydanticAI is an AI agent framework built by the Pydantic team that brings FastAPI-style ergonomics to GenAI development. It provides type-safe, model-agnostic agent construction with structured outputs, dependency injection, and seamless integration with Pydantic Logfire for observability.
LOCAL-ONLY PyPI publishing with Doppler credentials. TRIGGERS - publish to PyPI, pypi upload, local publish. NEVER use in CI/CD.
Queries the PyPI JSON API and the libraries.io API to analyze Python package metadata, dependency trees, and version histories. Uses pip-audit for vulnerability scanning against the OSV database.
Production Python async patterns including asyncio TaskGroup, FastAPI dependency injection and middleware, SQLAlchemy 2.0 async sessions, and database connection pool tuning. Python 3.11+ examples with structured error handling. Use when building async services, FastAPI endpoints, or tuning database connection pools.
Apply Python project conventions — uv for deps and builds, Ruff strict (E, F, I, UP, B, SIM, PTH, PIE, RUF, T201, PLC0415), mypy strict, pytest with pytest-cov and pytest-asyncio, vulture for dead code, pip-audit for dependency security, and a gitignored test.py for scratch experiments. Use when starting a Python project, writing or reviewing Python code, configuring Python tooling, or evaluating compliance with these defaults. Co-activates with running-tdd-cycles, reviewing-changes, and engi...
Python logging with loguru, structlog, and orjson. TRIGGERS - loguru, structlog, structured logging, JSONL logs, log rotation, secret redaction, OTel logging, lightweight logging, print logging, systemd logging.
Use when working with Peewee ORM patterns, especially DatabaseProxy setup, scoped connection/transaction handling, and SQLite-based tests.
Python coding rules from ai-toolkit: coding-style, frameworks, patterns, security, testing. Triggers: .py, .pyi, pyproject.toml, requirements.txt, Pipfile, FastAPI, Django, Flask, pytest, SQLAlchemy, ruff, mypy. Load when writing, reviewing, or editing Python code.
Generate and manage Q&A database for Topical Authority content. Use when user wants to create structured answers for cluster questions or export JSON-LD for GEO.
ISTQB Foundation Level (CTFL) aligned QA toolkit for manual and automated testing. Use when asked to create test plans, test strategies, test conditions, test cases, bug reports, defect logs, regression suites, traceability matrices, or exploratory charters. Supports risk-based testing, test design techniques (equivalence partitioning, boundary value analysis, decision tables, state transitions), test estimation, static testing reviews, and test process management. Includes Playwright automat...
[QA Process · ISTQB CTFL v4.0] Test Plan creation — objectives, schedule, resources, entry/exit criteria, and risk mitigation. Run after qa-strategy, before test execution.
[QA Process · ISO 31000 + ISTQB CTFL v4.0] Risk-based test prioritization — builds a risk matrix (likelihood × impact), ranks test areas by priority, and flags critical paths for performance testing.
Security scanning templates and checklists for OWASP Top 10, authentication, authorization, data protection. Use when conducting security testing or vulnerability assessment. This skill provides comprehensive security testing: - OWASP Top 10 checklist with remediation - Authentication and authorization testing - Data protection verification - Security report generation - Integration with Codex CLI MCP for automated scanning Triggers: "security scan", "vulnerability check", "OWASP", "securit...
Perform a security audit based on OWASP. Use when the user wants to verify security, look for vulnerabilities, or before a production deployment.
[QA Process · ISO 25010 + ISTQB CTFL v4.0] Test Strategy document creation — defines scope, risk appetite, test approach, coverage goals, and tool selection for the project. Run before qa-plan.
Parallel QA using agent teams for comprehensive multi-type testing. Spawns specialized QA agents that simultaneously run different test categories (unit, integration, lint, security scan) and consolidate results. Triggers on: "QA 스웜", "전체 QA", "qa-swarm", "병렬 테스트", "종합 테스트", or when comprehensive multi-category testing is needed for a project.
Systematically test web applications for functionality, security, and usability issues using browser automation. Reports findings by severity (CRITICAL/HIGH/MEDIUM/LOW) with immediate alerts for critical failures. Use when testing web apps, validating user flows, conducting security checks, or performing pre-deployment audits.
Gestión del QA del proyecto GitHooks: ejecutar herramientas de análisis estático y tests, interpretar y corregir violaciones, y garantizar que el código está limpio antes de commitear. Usa esta skill SIEMPRE antes de commitear, o cuando un commit falle por un hook de QA, o cuando el usuario pida "ejecutar QA", "pasar análisis", "arreglar phpmd", "arreglar phpstan", "limpiar violaciones", "preparar para commit".
Integrate QPay — Mongolia's primary QR payment system — into a developer's project so they can accept MNT payments through Khan Bank, Golomt, State Bank, Xac Bank and other Mongolian banks. Trigger this whenever the user mentions QPay, qpay.mn, merchant.qpay.mn, merchant-sandbox.qpay.mn, or asks how to accept MNT / payments from Mongolian users / Mongolian bank QR or deep links. Also trigger when a Mongolian indie dev or business says they need payments and is targeting domestic MNT customers...
Lead qualification using BANT 6-criteria gate (Problem, Budget, Authority, Timeline, Fit, Margin) at marketing-sales handoff. Qualified leads enter pipeline, unqualified go to nurture. If bottleneck is downstream, reduce upstream lead gen. Use when evaluating leads, managing marketing-sales handoff, or when pipeline quality is poor.
Page quality audits for DOM complexity, CSS architecture, security vulnerabilities, and SEO/meta tag validation. 頁品稽查:DOM繁度、CSS構、安全漏洞、SEO元標。 Use when: audit page quality, check DOM complexity, audit CSS architecture, check security vulnerabilities, validate SEO meta tags, run pre-release quality check
Bandit 보안 검사 설정 및 관리 스킬. pyproject.toml에 Bandit 설정을 구성하고 보안 취약점을 탐지한다. OWASP, CWE 기반의 보안 검사 환경을 구축한다.
Use when an approved system design exists and a system or service needs a production-grade testing strategy before merge approval, release, or production promotion. Produces a risk-based testing strategy with acceptance criteria from PRD success metrics, a contract and integration test plan that avoids mocking the system under test, CI/CD quality gates, and implementation handoff notes. Do not use for isolated unit-test authoring, one-off test debugging, framework-specific test syntax, load-t...
Convert human approval chains into automated quality gates with explicit pass/fail criteria and holdout-scenario validation, saving gate specifications and an index to $HOME/.ai-first-kit/. Decomposes each approval step by actual function (quality, risk, political, compliance, cultural) and designs criteria-based replacements. Use when the user says 'replace approvals', 'design quality gates', 'automate review', 'convert approvals to criteria', 'create validation for agent output', 'remove bo...
Launch quality subagents in parallel using Claude Code 2.1+ native Task tool. Includes ralph-security for OWASP validation and ralph-frontend for WCAG checks. Reads results post-analysis for orchestrator decision-making.
Fail-closed crypto quant alpha research for repo-native Stage 0/0.5 validation, falsification, provider concordance, and promotion decisions. Use to find/validate alpha, execute quant research roadmaps, audit promotion evidence, turn market commentary into hypotheses, or decide if alpha reruns are allowed; Chinese triggers include 寻找新alpha、验证这个alpha、执行量化研究路线图 and synonyms. Do not use for generic finance, CSV/charting, product Stage 0, unrelated provider debugging, or GitHub/frontend work.
Automate the full QuarkPanTool → mswnlz GitHub content publishing pipeline. Use when the user provides Quark share URLs and wants: (1) create a batch folder in Quark Drive, (2) save/copy resources into that folder, (3) copy promotional files INTO each shared resource folder, (4) generate permanent encrypted share links with random passcodes, (5) auto-classify items into mswnlz repos (book/movies/etc.) by repo descriptions, (6) append/update the target repo's YYYYMM.md and README month index, ...
Author Quarkdown (.qd) documents, a Markdown-superset typesetting language that compiles to HTML, PDF, or plaintext. Use when the user wants to write or edit .qd files, produce typeset output (articles, reports, slides, books, wikis, notes, static sites) beyond what plain Markdown offers, or share structured plans in a presentation-ready format. Quarkdown adds function calls (`.func {arg}`), variables, layouts, math, diagrams, and document types (plain/paged/slides/docs).
Use when the user is explicitly working with Quarto, .qmd files, _quarto.yml, Quarto projects, or Quarto features such as callouts, cross-references, citations, Mermaid diagrams, extensions, websites, books, presentations, and reports. Also use for explicit migration from or comparison with R Markdown, bookdown, blogdown, xaringan, distill, or Jupyter notebooks to Quarto. Do not use for general R Markdown or related-format questions unless Quarto or migration to Quarto is explicitly mentioned.
Setup, configure, debug and extend Quasarr — the bridge that connects JDownloader with Radarr, Sonarr and LazyLibrarian via a fake Newznab indexer and SABnzbd client interface. Also handles CAPTCHA-protected link decryption. Use this skill whenever the user mentions Quasarr, asks about connecting JDownloader with Radarr/Sonarr, needs help with hostname configuration, FlareSolverr, download categories, notifications, SponsorsHelper, or any Quasarr-related topic.
Use this skill as the designated specialist reviewer for Zeta.Core's query planner / optimiser — join ordering, predicate pushdown, index selection, SIMD/tensor-intrinsic kernel dispatch, cardinality estimation, cost model. She carries advisory authority on planner shape; binding decisions need Architect buy-in or human sign-off (see docs/CONFLICT-RESOLUTION.md). Goal is a cutting-edge, research-worthy planner that exploits every hardware intrinsic available on the host.
Answer cross-source questions about an open-llm-wiki vault and optionally write reusable synthesis back into concept pages. Use when the user asks a wiki question that requires comparing, connecting, or tracing multiple source/concept pages. By default answer first and propose writeback; modify files only when the user explicitly asks for writeback, pre-authorizes wiki growth, or approves the proposed changes.
Auto-fill security questionnaires (SIG Lite, CAIQ, Enterprise) using scan data and policy documents.
Access QuickBooks Online API for invoices, payments, customers, and bills. Covers OAuth token auto-refresh, API queries, and Supabase ingest. Use when: checking invoice status, reconciling payments, querying expenses. Skip when: expense data already in PIL (check supabase first).
Connects to the QuickBooks Online Accounting API using OAuth 2.0 via the intuit-oauth Node.js SDK to fetch unpaid invoices and match them against bank transaction records. Discrepancies are flagged and a reconciliation report is generated as a PDF using PDFKit, then emailed via SendGrid.
QuickNode install auth — blockchain RPC and Web3 infrastructure integration. Use when working with QuickNode for blockchain development. Trigger with phrases like "quicknode install auth", "quicknode-install-auth", "blockchain RPC".
QuickNode security basics — blockchain RPC and Web3 infrastructure integration. Use when working with QuickNode for blockchain development. Trigger with phrases like "quicknode security basics", "quicknode-security-basics", "blockchain RPC".
Run a quick security scan on a target. Consults the Brain first, validates scope, runs passive recon + vuln scan in parallel.
Audit mobile applications (iOS and Android) against RAAM 1.1 (Luxembourg Mobile Accessibility Assessment Framework). Use when reviewing existing mobile app code for accessibility compliance, generating audit reports, checking conformance levels, or preparing for Luxembourg accessibility certification. Covers all 15 themes with platform-specific test procedures. Default target: Level AA.
Ultimate RabbitMQ expertise skill for production-grade message broker architecture, implementation, and operations. Top 0.01% knowledge covering: (1) Advanced messaging patterns - Dead Letter Exchanges, Delayed Messages, Priority Queues, Consistent Hash Exchange, Sharding, (2) High Availability - Clustering, Quorum Queues, Stream Queues, Federation, Shovel, (3) Performance Engineering - prefetch tuning, connection pooling, batch publishing, memory optimization, flow control, (4) Security - TL...
Review my code, code review, is this ready to ship, check for bugs, security audit, review this PR, pre-merge check, is this safe to deploy, check code quality. Blame-aware diff scoping, 3-role adversarial review, AI slop detection (14 patterns), framework IDOR, WCAG 2.2, performance heuristics, severity-ranked findings, optional fix application. v3.0: Opus 4.7 optimized with parallel tool calls, JSON-first subagent output, compaction-safe checkpointing, non-interactive mode for agents/CI.
Radicale is a lightweight, self-hosted CalDAV and CardDAV server written in Python. It shares calendars, to-do lists, journal entries, and contacts over standard protocols with zero-config setup, file-based storage, optional authentication, TLS support, and a plugin architecture.
Use this skill to audit RAG and AI application security, including retrieval boundaries, prompt injection, citations, memory, and data exposure. Do not use it as a scanner or exploit runner.
Generates tailored giskard.checks evaluation suites for RAG (Retrieval-Augmented Generation) systems. Use whenever a user describes a Q&A bot grounded in documents, a knowledge-base chatbot, a retrieval system, or wants to evaluate answer groundedness, faithfulness, hallucination, retrieval quality, citation accuracy, or out-of-scope handling. Triggers on phrases like "evaluate my RAG", "test my retrieval", "check groundedness", "build a RAG eval suite", "eval my chatbot answers from docs", "...
Implement and test authorization in Rails applications using Pundit or CanCanCan. Covers policy objects, role-based access control, permission checks, and testing strategies. Use when the user needs to implement or troubleshoot authorization in a Rails app, set up user roles and permissions, or mentions Pundit, CanCanCan, policy objects, access control, roles, or permissions.
Reviews Rails pull requests, focusing on controller/model conventions, migration safety, query performance, and Rails Way compliance. Covers routing, ActiveRecord, security, caching, and background jobs. Use when reviewing existing Rails code for quality, conducting a PR review, or doing a code review on Ruby on Rails (RoR) code.
Use when creating, scaffolding, or refactoring a Rails engine. Covers engine types (Plain, Railtie, Engine, Mountable), namespace isolation, host-app contract definition, and recommended file structure.