
Claude Skills by aibot88
github.com/aibot885-agent parallel review gate using agent teams. Spawns Goal Verification, QA Execution, Code Quality, Security Audit, and Context Mining teammates. ALL must pass.
Run a layered quality gate over a code change — code quality, security audit, and architecture consistency, in that order. Use after writing or modifying code, before opening or merging a PR, when reviewing a diff or branch, or when asked for a code review, security audit, or architecture review. Produces severity-ranked findings (Critical / Major / Minor) tied to file:line, each with a concrete fix. Covers OWASP Top 10, SOLID, KISS / YAGNI / DRY, ruff + mypy for Python, golangci-lint for Go,...
Code review covering security, quality, tests, implementation, documentation,
Reviews GitHub pull requests for the Medusa repository. Checks PR template compliance, contribution guidelines, code conventions, and community contribution limits. Posts a review comment and applies initial-approval or requires-more label. Use when a PR is opened or updated.
Revisão de código abrangente: qualidade + compliance + segurança. Classifica achados por severidade. Combina revisão de código genérica com validação de domínio regulado. Use quando o usuário disser "kairos revisar", "revisar código", "code review", "review de segurança".
Use git-filter-repo when an agent needs to surgically rewrite repository history after a leaked secret, a huge binary commit, or a bad subtree split. The agent analyzes the problem, builds the rewrite command, and leaves a clean follow-up checklist for force-push, clone reset, and downstream cleanup.
Use this skill when writing, proofreading, or polishing the wording of plain text documents — Markdown (.md), TeX (.tex), or .txt files — and the English text embedded in source code: comments, docstrings, log messages, error messages, and user-facing strings. Apply the rules conservatively: preserve the author's voice and meaning, replace awkward phrasing with cleaner alternatives, fix grammar, and cut filler words, clichés, and tautologies. Do NOT apply to the surrounding code, YAML, JSON, ...
Post to X (Twitter) using official API with OAuth 1.0a. Supports tweets, threads, media. Use when user says "X API", "tweet via API", "post to X".
· Administer RHEL/Fedora/CentOS/Rocky/Alma/Amazon Linux: dnf, yum, SELinux, firewalld, dracut. Triggers: 'rhel', 'fedora', 'centos stream', 'rocky', 'dnf', 'selinux'. Not for other distros.
Authoring and debugging scripts for Rhinoceros 3D (Rhino 8 and later). Use when asked to write RhinoScript (VBScript / .rvb / .vbs), RhinoPython, or RhinoCommon-based scripts; automate Rhino modeling tasks; build command macros; manipulate Rhino geometry, layers, blocks, or document objects; pick objects from the viewport; control redraw and undo; or load and run scripts from the Rhino Script Editor. Covers `rhinoscriptsyntax`, `scriptcontext`, the `Rhino.*` RhinoCommon namespaces (`Rhino.Geo...
Use when building UI with the Rialto design system, importing from "rialto" or "@mattbutlerengineering/rialto", choosing components, applying design tokens, composing layouts, or authoring new Rialto components. Triggers on mentions of "Rialto", "component library", "design system", "UI component", or imports from rialto.
This skill should be used when the user asks to "write a research report", "create a plan document for review", "produce a polished design doc", "draft a comparison sheet", "generate a richdoc", "make a one-pager", "write a status report", "produce an executive summary", "create a decision document", "build a dashboard page", or any other rich HTML deliverable intended for human review in a browser. Authors plain .html files using a small fixed vocabulary of rd-* web components for layout and...
Richtlinien-Neufassung – erstellt einen markierten Entwurf einer internen Richtlinie, der eine identifizierte Compliance-Lücke schließt. Laden, wenn eine Richtlinie nach einem Diff oder einer Gap-Analyse überarbeitet werden soll.
Audit legal information systems that explain rights to the public, evaluating plain-language accuracy, jurisdiction-specific content correctness, reading level appropriateness targeting 5th-8th grade, multilingual support, WCAG accessibility compliance, and content update workflows when laws change. Use when reviewing legal aid websites, self-help law portals, court information systems, tenant rights platforms, or government benefits explainers.
Audit content licensing and rights management systems for territory and window tracking, royalty calculation accuracy, rights clearance workflows, and contract compliance across music, film, television, and digital media. Use when reviewing media distribution platforms, royalty engines, music publishing systems, sync licensing tools, or content catalog management using DDEX standards and ASCAP/BMI/SESAC frameworks.
Panduan pengembangan bahasa pemrograman RiQi — smart contract language yang dirancang security-first untuk blockchain Skylum, mencakup compiler, VM, static analyzer, dan optimization engine.
Motor de gestión de riesgo institucional del Financial Intelligence System. ACTÍVALO siempre antes de cualquier recomendación final de inversión, cuando el usuario presente un portafolio real, cuando el scoring board detecte disenso, o cuando se evalúe una posición de alto riesgo. Cuantifica el riesgo total del portafolio usando VaR paramétrico, histórico y Monte Carlo, analiza correlaciones entre activos, calcula el drawdown máximo esperado, verifica el cumplimiento de límites de posición, d...
Dispatch risk vector -> reviewer roster + impl/reviewer model + tdd_required. Triggers: s>=- security-reviewer, d>=- data-reviewer, r>=+ reversibility-reviewer, b>=+ full code-quality, u>=+ adds novelty-reviewer + research. Crit axes hard-block. Model routes impl by tier (haiku-4.5/sonnet-4.6/opus-4.7) with crit + u-crit escalation; reviewer one tier down with security/post-task same-tier overrides. TDD when d|s>=- or b|u>=+.
Audit risk simulation and decision support systems for Monte Carlo modeling quality, wargaming analysis, threat assessment, mission planning support, and course-of-action decision analysis. Use when reviewing probabilistic risk models, defense planning tools, cost-schedule risk engines, scenario simulators, or decision matrices built on DoD risk management and operational planning frameworks.
Reference skill for Zoom Rivet SDK. Use after routing to a Rivet-based server workflow when implementing auth handling, webhook consumers, API wrappers, multi-module composition, or Lambda receiver patterns.
Generate a Supabase Row-Level-Security policy bundle from an access-model description. Outputs SQL + test queries + admin-impersonation patterns.
React Native uygulamada Firebase modüllerinin (Auth/Firestore/Storage/Crashlytics vb.) entegrasyonunu projeye uygun standartta uygulat; config, environment ve güvenli kullanım kurallarını uygula.
Use when authoring or rewriting a roadmap in agents/roadmaps/ — phase prose, goal sentence, acceptance criteria, council notes — even when the user just says 'write a plan for X' or 'draft a roadmap'.
Master skill cho dự án Robot Bi. Kết hợp TDD, diagnosis loop, security audit, git safety, UI prototyping, và session hygiene — tất cả được calibrate cho codebase Python/FastAPI/SQLite/Groq của Robot Bi. Trigger khi: implement feature mới, debug bug, security review, làm UI frontend/robot display, hoặc bắt đầu session dev bất kỳ.
Use this skill for general Robot Framework work: authoring `.robot` suites, tasks, keywords, variables, resource files, execution, dry runs, tags, Rebot/Libdoc usage, and Python test-library patterns. Trigger when the user mentions Robot Framework, `.robot` files, keywords, libraries, resource files, tasks, listeners, Libdoc, Rebot, or Robot Framework syntax and execution.
robust-review の S-Critical/S-High Finding を定型修正パターン(unwrap除去、injection対策、未チェックインデックス等)で自動修正し、各修正後に検証ゲート(build/type/test)で安全を確認する。USE WHEN robust-review 直後、Tier 2 Finding の一括処理、リリース前の堅牢性ホットフィックス。SKIP 設計判断を伴う修正は Tier 1 エスカレーション、仕様乖離の修正は spec-fix、汎用バグは fix-with-verify を使うこと。
Interactive onboarding for legacy projects. Reads existing code, understands the project, asks 9 questions in 3 groups (cognition / scope / privacy), and writes .roll/onboard-plan.yaml as the contract for `roll init --apply` to execute.
Self code review step in the TCR workflow. Runs after each micro-step is completed and before commit, checking code quality, security, and design issues.
Adversarial TDD mode with Attacker/Defender agents. Attacker writes tests to break the system, Defender writes minimal code to pass. Use for high-risk logic like auth, payments, data integrity, or complex state machines.
Craft compelling relationship scenes with emotional tension and authenticity
Specialized software engineering prompt methodology for Claude. Use when building prompts for system design, code review, incident response, security analysis, API design, architecture decisions, RFCs, ADRs, runbooks, or technical leadership. Trigger on: "build a prompt for code review," "system design prompt," "SRE prompt," "security review prompt," "incident response prompt," "API design prompt," "architecture decision prompt," "RFC prompt," "runbook prompt." Provides 11 tested approaches a...
Reads and summarizes emails from Roundcube webmail with SAML/TOTP authentication using Playwright. Use when checking webmail, reading university email, automating Roundcube login, or setting up daily email digest via Slack/OpenClaw cron. macOS only.
RPC contract validation — Contract-first development, direkt REST bypass yasak
Add right-to-left (RTL) text support to web projects for Hebrew, Arabic, and Farsi. Use when the user asks about RTL layout, Hebrew/Arabic text direction, bidirectional text, CSS direction, unicode-bidi, or wants to make a web app support RTL languages. Provides automatic direction detection, CSS injection, and JavaScript utilities.
Ruby coding rules from ai-toolkit: coding-style, frameworks, patterns, security, testing. Triggers: .rb, Gemfile, .gemspec, Rails, ActiveRecord, Sidekiq, RSpec, Sorbet, rubocop. Load when writing, reviewing, or editing Ruby code.
Non-negotiable Jardis architecture rules — five constitutional pillars, hexagonal dependency direction, Closure-Orchestrator pattern. Consult before authoring any new class or reviewing existing code.
Launch risky agent work inside disposable microVMs when you need stronger isolation, sealed egress, and host-side secret injection instead of direct host access.
Use ai-runbooks to give AI assistants role-specific SOC personas, investigation steps, and incident-response procedures for structured security triage.
Use Docker MCP Gateway to run MCP servers in isolated containers, centralize profiles, secrets, tools, and client connections.
Analyze a web app's source code, execute real exploit attempts against the running target, and return proof-backed findings before release.
Use a practical OpenClaw operations runbook to stabilize long-running deployments, tune coordinator and worker patterns, and apply reusable prompt templates for monitoring, security, and cost control.
Use curated Trail of Bits security skills inside Claude Code when the job is auditing, variant hunting, or fix verification rather than generic coding assistance.
Run a spec-vs-code audit on this codebase. Compare actual implementation in app/, lib/, lib/typeorm/, typeorm/, and tests against project specifications in docs/. Report only defects with exact file and line citations, classified as MISSING, DIVERGENT, UNDOCUMENTED, or PHANTOM. Use when asked to audit code against specs, find spec divergence, run a Council of Three audit, check doc-code consistency, verify lifecycle/transition/ report/MCP behavior matches documentation, run spec compliance, c...
Runway install auth — AI video generation and creative AI platform. Use when working with Runway for video generation, image editing, or creative AI. Trigger with phrases like "runway install auth", "runway-install-auth", "AI video generation".
Runway security basics — AI video generation and creative AI platform. Use when working with Runway for video generation, image editing, or creative AI. Trigger with phrases like "runway security basics", "runway-security-basics", "AI video generation".
Audit rural health network software for telehealth readiness, provider coverage mapping, patient transportation coordination, referral network optimization, Critical Access Hospital compliance, mobile clinic scheduling, and health equity metrics. Use when reviewing rural EHR systems, FQHC platforms, telehealth infrastructure, community health worker tools, HRSA-funded health systems, or remote care delivery networks.
A comprehensive guide to modern Rust best practices covering style, error handling, performance, concurrency, project organization, dependency management, documentation, testing, security, and CI.
Implicit Rust CLI and Clap skill. Use for command-line apps and tools, clap derive or builder APIs, subcommands, flags, config and env precedence, stdin/stdout/stderr contracts, JSON output, exit codes, completions, manpages, shell UX, CLI tests, and binary distribution.
Audit Rust dependencies for vulnerabilities, license compliance, supply chain integrity, and freshness using cargo-audit, cargo-deny, cargo-vet, and cargo-outdated. Use whenever the user asks about dependency auditing, vulnerability scanning, license checks, supply chain verification, crate freshness, or says 'cargo outdated' or 'cargo update'. Also use before any Rust crate release. Do NOT use for Rust tooling guidance on refactoring, profiling, or benchmarking (use rust-sota-arsenal instead).
Explicit-only Rust architecture orchestrator. Use only when the user explicitly invokes rust-mega-eng for broad Rust ecosystem architecture, multi-crate workspace strategy, large refactors, release engineering, crate selection portfolios, or end-to-end Rust product planning across CLI, TUI, Tauri, services, libraries, CI, security, and distribution.