
Claude Skills by aibot88
github.com/aibot88Slices, reviews, and writes product backlog items (PBIs) using priority-ordered quality characteristics (Valuable > Completable > Negotiable > Independent > Commensurate > Small), vertical slicing, and the splitting meta-pattern. Produces well-formed, commensurately sized PBIs with binary acceptance criteria. Use when splitting large PBIs or user stories, reviewing backlog items for quality, writing new PBIs from requirements, refining a product backlog, decomposing epics into stories, or whe...
Use when creating slide decks with Marp/Marpit Markdown (marp), including authoring slide content, designing slide color schemes, and building SVG diagrams or illustrations for the deck.
Expert guidance for building Android apps with Slint (Rust GUI toolkit). Use this skill whenever the user is working on a Slint UI — especially for Android targets — including .slint DSL syntax, component architecture, Cargo setup, Android backend configuration (cargo-apk, android-activity), Material Design 3 compliance, touch targets, dp/sp units, safe area insets, edge-to-edge layouts, dark mode, gestures, and responsive design for multiple Android screen densities. Trigger this skill when ...
KDL config reference for slop-mcp scopes, manage_mcps params, auth, metadata. 配置格式、範圍、認證、元數據之參考。 Use when: registering servers, inspecting auth, understanding KDL format, checking scope behavior.
Scaffold slop-mcp monitor session — verify PATH binary, choose generic event stream / SLOP polling script / timed session, emit copy-ready Claude Code Monitor({...}) JSON. 搭建 slop-mcp 監視會話。 Use when: starting Claude Code Monitor over slop-mcp, watching git/build/CI events, polling MCP for delta changes, running bounded watch session.
\"Write SLOP code with AI assistance - generates correct, safe, and idiomatic SLOP code. AI輔助生成正確、安全、慣用的SLOP代碼。Use when: generating new SLOP programs from requirements, scaffolding agents/pipelines/batch processors.\"
Detect AI-generated design slop with concrete, locatable findings. Use when the user wants to check code for AI authorship tells, design inconsistency, or generic UI patterns. Each finding includes file, line, column, the offending snippet, why it's a problem, and a concrete fix. 12 rules covering shadow/radius variant explosion, AI-default gradients, lorem ipsum, inline styles, off-grid spacing (when a manifest exists), off-palette colors (when a manifest exists), tailwind class bloat, missi...
Comprehensive security review framework for AI agents. Covers skill/MCP installation, GitHub repos, URLs/documents, on-chain addresses, products/services, and social shares. Built from real-world attack patterns and incident response experience.
SLSA Verifier is the official tool from the SLSA framework for verifying build provenance attestations generated by SLSA-compliant builders. It checks that software artifacts were built from the expected source, by an authorized builder, without tampering in the build pipeline.
Perform OCR on image files (jpg, png, bmp, gif, tiff) using the system's `tesseract` binary and return extracted plain text.
Aide à préparer un petit litige (consommation, voisinage, facture contestée) avec dossier structuré. Se déclenche aussi avec "petit litige", "tribunal", "facture contestée", "arnaque", "remboursement refusé", "voisinage", ou toute préparation de recours pour un litige courant.
Audit de sécurité de smart contracts Solidity et blockchain. Se déclenche avec "smart contract", "Solidity", "audit blockchain", "vulnérabilité smart contract", "reentrancy", "ERC-20", "ERC-721", "Web3 security".
Smartlead API endpoint reference and patterns. Use for any Smartlead campaign, lead, email account, analytics, or inbox operation. Covers auth, rate limiting, and all commonly used endpoints.
Programmatic inbox management for Smartlead. Enable/disable warmup with correct ramp settings, set signatures in bulk, tag inboxes (active vs insurance), and pull inbox health dashboards. Use after creating a new batch of inboxes via /zapmail-domain-setup-public, or when managing an existing Smartlead account at scale. Triggers on "turn on warmup", "set signatures", "tag inboxes", "inbox health", "set up new inboxes".
Review a GitHub pull request in read-only mode for material bugs, regressions, missing tests, architecture drift, security/privacy risk, performance risk, and merge blockers. Use when the user wants a PR reviewed before merge or before posting feedback.
CDP browser screenshots for capturing authenticated web pages. Use when you need pixel-perfect PNG screenshots of authenticated sites like Google Sheets, dashboards, or admin panels.
Use Kopia when an agent needs to create, verify, or restore encrypted incremental snapshots across local, NAS, SFTP, WebDAV, or cloud storage targets.
Security-focused PR review for snarkVM codebase. WHEN: User says "review PR", "audit PR", "security review", "check PR changes", or wants thorough analysis of PR changes for bugs/vulnerabilities. WHEN NOT: Fixing review feedback (use snarkvm-fix pr), fetching context only (use snarkvm-github), or fixing issues (use snarkvm-fix).
Diagnose and fix common Snowflake errors and SQL compilation failures. Use when encountering Snowflake error codes, failed queries, authentication issues, or warehouse/connection problems. Trigger with phrases like "snowflake error", "fix snowflake", "snowflake not working", "snowflake SQL error", "snowflake 002003".
Implement Snowflake data governance with masking policies, row access policies, tagging, and GDPR/CCPA compliance patterns. Use when handling PII, implementing column masking, configuring data classification, or ensuring compliance with privacy regulations in Snowflake. Trigger with phrases like "snowflake data governance", "snowflake masking", "snowflake PII", "snowflake GDPR", "snowflake row access policy", "snowflake tags".
Deploy Snowflake-powered applications with proper connection management and secrets. Use when deploying apps that query Snowflake, configuring connection pools for serverless/container platforms, or managing Snowflake credentials in production. Trigger with phrases like "deploy snowflake", "snowflake serverless", "snowflake production deploy", "snowflake Cloud Run", "snowflake Lambda".
Install and configure Snowflake driver authentication for Node.js and Python. Use when setting up snowflake-sdk, snowflake-connector-python, key pair auth, OAuth, or SSO browser authentication. Trigger with phrases like "install snowflake", "setup snowflake", "snowflake auth", "snowflake connection", "snowflake key pair".
Implement Snowflake governance guardrails with network rules, session policies, authentication policies, and automated compliance checks. Use when enforcing security policies, implementing data governance, or configuring automated compliance for Snowflake. Trigger with phrases like "snowflake policy", "snowflake guardrails", "snowflake governance", "snowflake compliance", "snowflake enforce".
Implement Snowflake reliability patterns: replication, failover, Time Travel recovery, and application-level resilience for Snowflake integrations. Use when building fault-tolerant pipelines, configuring disaster recovery, or adding resilience to production Snowflake services. Trigger with phrases like "snowflake reliability", "snowflake failover", "snowflake replication", "snowflake disaster recovery", "snowflake Time Travel".
Apply Snowflake security best practices: network policies, key rotation, MFA, encryption, and least-privilege access. Use when securing Snowflake access, implementing network policies, or auditing security configuration. Trigger with phrases like "snowflake security", "snowflake network policy", "secure snowflake", "snowflake MFA", "snowflake encryption".
Compliance expert for snyk-agent-scan — the agent skill file scanner — NOT for other Snyk CLI tools (snyk test, snyk code SAST, snyk iac, snyk container). Fixes alerts through content restructuring, never by suppressing or deleting information. Covers every file in a skill directory: SKILL.md, references/, assets/, and any secondary markdown. Apply when authoring a new skill, editing an existing one, triaging a failed snyk-agent-scan run locally or in CI, or unblocking a PR held by agent scan...
Snyk Agent Scan automatically discovers and scans AI agent components including MCP servers, agent skills, and agent harnesses for security vulnerabilities like prompt injections, tool poisoning, tool shadowing, and malware payloads. It supports Claude Code, Cursor, Windsurf, Gemini CLI, VS Code, and more.
Scan your AI agents, MCP servers, and skills for security vulnerabilities from the command line. Snyk Agent Scan discovers and audits every agent component on your machine — detecting prompt injections, tool poisoning, toxic flows, malware payloads, and credential handling issues across 15+ distinct risk categories.
Execute Snyk Code SAST (Static Application Security Testing) scans on source code files or projects, interpret vulnerability findings, generate structured security reports, and suggest remediations. Use this skill whenever the user mentions: "snyk", "snyk code", "SAST scan", "scan de segurança", "verificar vulnerabilidades no código", "análise estática de segurança", "snyk scan", "rodar snyk", "vulnerabilidade no código-fonte", or wants to audit code for security issues with Snyk. Also trigge...
Scans Docker and OCI container images for OS and application vulnerabilities using Snyk Container API. Cross-references findings against the Snyk vulnerability database with CVSS scoring and provides Dockerfile remediation suggestions.
Scans Docker images for OS and application vulnerabilities using the Snyk Container API. Generates fix PRs with upgraded base images and patched dependency versions.
Uses the Snyk CLI and REST API v1 to scan package manifests for known CVEs. Cross-references findings with the GitHub Advisory Database and produces SBOM documents in CycloneDX format.
Audits npm, pip, and Go module dependencies using the Snyk CLI and REST API. Generates SBOM reports and auto-patches known CVEs with version-pinned upgrade recommendations.
Uses the Snyk CLI and REST API to audit open-source dependencies for license compliance across npm, PyPI, Maven, and Go modules. Generates SPDX license reports and flags copyleft violations.
Performs deep dependency analysis using the Snyk CLI and REST API to detect vulnerable transitive packages. Generates fix PRs with version pinning and patch recommendations.
Uses Snyk REST API v1 to scan project dependencies for known CVEs and license compliance issues. Integrates with Snyk Test endpoint for real-time SBOM analysis and generates CVSS-scored vulnerability reports with remediation paths.
Schedule posts, manage drafts, reply to inbox messages, generate AI captions/images/UGC videos, query analytics, and automate social-media operations across Twitter/X, LinkedIn, Instagram, Facebook, TikTok, YouTube, Threads, WhatsApp, Pinterest, and Dribbble — driven from the Hermes Agent CLI via the `so-me` binary.
Guide pour analyste SOC — triage d'alertes, investigation, SIEM, indicateurs de compromission et playbooks de réponse. Se déclenche avec "SOC", "analyste SOC", "SIEM", "IoC", "incident de sécurité", "triage sécurité".
SOC daily-pull triage feed — Vulnetix''s score-driven queue cross-referenced with installed dependencies. Use when starting a SOC shift, prioritising the queue by EPSS × KEV × repo-impact, filtering by severity / ecosystem / KEV-only / since-date, producing a P1–P4 action list grouped by package manager, or handing off a watchlist to the next shift.
When the user needs to prepare for SOC 2, build a compliance roadmap, assess security posture, quantify security risk, or says "we need SOC 2", "security audit", "compliance", "enterprise customer wants SOC 2", "CISO advice".
Strukturierte Pruefung bei mangelhafter Software. Bestimmt Vertragstyp (Kaufrecht §§ 433 ff. BGB bei Software-Erwerb auf Datentraeger Werkvertrag §§ 631 ff. BGB bei Individualsoftware oder Anpassung Dienstvertrag bei Beratung Mietrecht §§ 535 ff. BGB bei SaaS und ASP). Pruefraster Mangelbegriff fuer Software Pflichtenhefte Spezifikationen Funktionalitaet Performance Sicherheit. Nachbesserungsrecht Frist Selbstvornahme Minderung Ruecktritt Schadensersatz. Open-Source-Compliance GPL AGPL MIT Ap...
Use this skill when integrating sol-safekey into Solana bots or tools, including encrypted keystores, interactive wallet management, password handling, wallet unlock, bot startup scripts, SOL/SPL/WSOL operations, durable nonce setup, and secure key handling for Rust or multi-language bot stacks.
Edit live Contextual flows in the Flow Editor — add, change, move, wire, delete, rename, configure, group, copy, or validate nodes / wires / properties / code in a flow open in the user's browser. Also the source-of-truth for node-level behavior, configuration, and authoring patterns — function-node logging (`await logger.*`), loop wiring, Native Object node TypedInput patterns, `http-response` status precedence, etc. (see `node-reference.md`). Required before any `mcp__ctxl-flow-editor__*` c...
Ground Solution AI and Contextual product answers in the official platform documentation — for **platform/runtime behavior not already covered by plugin-side reference content** (`cli-reference.md`, `node-reference.md`, the relevant `SKILL.md`). For CLI command shapes, JSONL formats, flow record structure, native-object-config shape, or node-level authoring patterns, prefer the plugin-side references first; this skill is the second stop, for behavior the plugin-side does not cover.
Use this skill when building Solana trading bots or automation that combines solana-streamer, sol-parser-sdk, sol-trade-sdk, and sol-safekey, including multi-language SDK variants for Rust, Node.js/TypeScript, Python, and Go. It helps agents choose the right SDK boundary, wire event streams into trades, handle wallet security, and produce runnable bot code for Codex, Claude Code, Cursor, or similar coding agents.
Use this skill when the user wants to deploy or upgrade a Solana program from devnet to mainnet — verifiable builds, buffer accounts, priority fees, upgrade authority management, IDL upload, program close.
Audit Solana programs (Anchor or native Rust) for security vulnerabilities. Use when reviewing smart contract security, finding exploits, analyzing attack vectors, performing security assessments, or when explicitly asked to audit, review security, check for bugs, or find vulnerabilities in Solana programs.
Solidity development standards and security auditing. TRIGGER when: working with .sol files, foundry.toml, hardhat.config.*, smart contract auditing, security review, or vulnerability analysis. Covers Foundry-first development patterns, vulnerability taxonomies, and audit methodology. DO NOT TRIGGER when: general Ethereum tooling/ecosystem questions (use ethskills skill), or Noir/ZK circuits (use noir skill).
Apply Solidity project conventions — Foundry only (forge, cast, anvil, chisel; no Hardhat or Truffle), forge fmt with sort_imports, solhint:all strict (--max-warnings=0 --noPoster) extending compiler-version ^0.8.22, fuzz tests via Foundry's built-in fuzzing, invariant tests via forge-std/StdInvariant.sol with handlers, gas snapshots via forge snapshot, coverage via forge coverage --report lcov, and script/Scratch.s.sol or chisel for scratch (never inline forge script heredocs). Use when star...
This skill should be used when the user asks "Should I build this feature?", "Is this idea viable?", "Am I over-engineering?", "Should I use Kubernetes?", "validate product idea", "build in secret", "tech stack too complex", "is this worth building?", "feature prioritization", "MVP scope", or needs help identifying common solo founder mistakes in product decisions, technical choices, or business strategy.