
Claude Skills by gaelic-ghost
github.com/gaelic-ghostValidate Python package surfaces with pyproject metadata, uv-managed builds, dependency boundaries, local smoke checks, semantic versioning, and release-boundary guidance.
Set up, run, and improve Python tests in uv projects and workspaces. Use for pytest configuration, focused and package-targeted runs, fixtures, parametrization, async and integration tests, coverage, CI parity, or failure triage.
Align Python formatting, linting, type checking, pytest configuration, dependency groups, local tooling, and CI validation around uv without overriding repo-local conventions.
Plan and validate Python version, dependency, uv lockfile, FastAPI, FastMCP, Pydantic, Ruff, mypy, pytest, and package metadata upgrades with staged checks.
Plan and align Codex GUI worktree-first workflows, local environments, actions, permanent worktrees, and handoffs to Git or Worktrunk worktrees. Use when a repo should make Codex app Worktree mode easier to use without mixing stack-specific commands into general guidance.
Safely inspect and perform everyday Git work: branches, focused commits, history, integration, conflicts, worktrees, and recovery. Use for local version-control tasks that are not GitHub settings or release publication.
Prepare and maintain GitHub pull requests, reviews, issues, CI triage, and durable handoffs. Use for collaboration work after local Git changes exist; not for GitHub settings or release publication.
Audit or align a GitHub repository's server-side settings, rulesets, security automation, Dependabot, and sign-off policy. Use for server-side GitHub policy work, not ordinary local Git commits, PR collaboration, or releases.
Maintain AGENTS.md as the agent-policy member of the canonical four-document repository suite.
Maintain CONTRIBUTING.md as the contributor-facing member of the canonical four-document repository suite.
Maintain README.md as the product-facing member of the canonical four-document repository suite.
Install or refresh deterministic FSX repository maintenance, maintain all four canonical project documents, validate and synchronize repository assets, and operate protected-main releases.
Maintain ROADMAP.md as the planning member of the canonical four-document repository suite.
Route repository work to focused Git, GitHub, documentation, worktree, settings, or release workflows. Use first when a request spans several repository operations or the correct owner is unclear.
Analyze AArch64 and Apple arm64e instruction, calling-convention, pointer-authentication, tagged-pointer, Rosetta, and hardware-mitigation evidence. Use when Codex must interpret Apple Silicon disassembly, registers, stack frames, SIMD, compiler idioms, PAC instructions or authenticated pointers, CPU subtypes, top-byte handling, SPTM or PPL context, memory tagging, or Memory Integrity Enforcement without generalizing behavior across unsupported hardware or OS builds.
Audit Apple code signatures, code directories, CDHashes, authorities, Team IDs, designated requirements, provisioning profiles, entitlements, hardened runtime, library validation, notarization, App Sandbox, SIP, Data Vaults, and platform-binary context. Use when Codex must explain an Apple artifact's declared identity and containment state, compare original and re-signed copies, or separate signed claims from access observed at runtime.
Compare exact compiled-artifact builds and record reproducible structural, metadata, symbol, dependency, signing, resource, or control-flow differences. Use when Codex must diff binaries, bundles, frameworks, firmware, assemblies, dyld caches, releases, security updates, or beta builds without assuming that marketing versions, filenames, or tool-generated names uniquely identify the compared inputs.
Connect an installed Hopper MCP server safely from Codex or Hermes for document navigation, assembly, pseudocode, strings, procedures, and cross-references with a private profile, read-only allowlist, approvals, and data boundaries.
Match Apple binaries, dSYMs, BCSymbolMaps when applicable, crash reports, IPS logs, panic excerpts, and static-analysis databases by UUID, architecture, load address, and exact build. Use when Codex must symbolicate or assess partial symbolication, translate crash addresses, correlate runtime frames with Mach-O functions, validate archived symbols, or hand a supported finding into Xcode or deeper reverse engineering.
Create reproducible reverse-engineering notes from artifacts, copied working files, commands, tool versions, decompiler or disassembler output, observations, inferences, open questions, and follow-up checks. Use when Codex needs to document a binary analysis session, preserve an evidence trail, compare tool output, or hand off reverse-engineering findings to a later agent or human pass.
Inspect Apple application bundles, extensions, frameworks, dylibs, static archives, XCFrameworks, IPA files, Mach-O executables, dSYMs, crash artifacts, dyld caches, kernel collections, IPSW files, or restore images without changing the original. Use when Codex must identify Apple container structure, executable and architecture slices, Mach-O load commands, UUIDs, imports, exports, rpaths, encryption, signing context, or the next Apple-specific analysis workflow.
Inspect .NET and .NET Framework assemblies, managed PE files, CIL, manifests, metadata tables, resources, dependencies, target frameworks, runtimeconfig and deps files, portable or Windows PDBs, and generated decompiler output. Use when Codex must distinguish managed, mixed-mode, single-file, ReadyToRun, NativeAOT, or obfuscated artifacts; map types and members; compare IL with C# or another generated language view; or hand ordinary source repair and rebuilding to dotnet-skills.
Inspect, map, extract from, or compare Apple dyld shared caches and subcaches while preserving cache-native identity and addresses. Use when Codex must identify a cache by platform, architecture, UUID, and OS build; inventory images, mappings, slide information, local symbols, chained fixups, closures, or subcaches; correlate a cache image with crash or static-analysis evidence; or compare exact cache builds without confusing extracted Mach-O addresses with cache-native locations.
Inspect compiled Unity player, package, data, managed Mono, and IL2CPP artifacts across supported platforms. Use when Codex must identify Unity version and scripting backend; inventory player executables, UnityPlayer, managed assemblies, Assembly-CSharp, GameAssembly, global-metadata.dat, native libraries, symbols, resources, assets, scenes, or package clues; choose managed decompilation versus native IL2CPP analysis; or hand project authoring, profiling, builds, and source changes to game-de...
Plan and record bounded dynamic analysis of Apple binaries using supported LLDB, Xcode, Instruments, unified logging, Simulator, physical-device, macOS VM, or research-device surfaces. Use when Codex must verify a static hypothesis at runtime, launch or attach, inspect images, memory regions, registers, exceptions, or generated data, correlate runtime addresses, or explain how Developer Mode, signing, get-task-allow, SIP, security policy, Rosetta, hardware, and exact OS build constrain the ob...
Create preservation-grade inventories and immutable working practices for compiled artifacts and reverse-engineering research. Use when Codex must preserve binaries, app bundles, firmware, archives, symbols, crash logs, decompiler projects, historical software, research evidence, or FOSS analysis materials while recording provenance, hashes, identifiers, transformations, generated outputs, and redistribution status separately.
Recover and validate Objective-C and Swift runtime structure from Apple binaries and generated analysis output. Use when Codex must inspect classes, categories, protocols, selectors, methods, properties, ivars, mangled Swift names, metadata, conformances, witness tables, generic specialization, async state machines, closure thunks, or Swift and Objective-C interoperability without presenting recovered metadata or decompiler guesses as original source declarations.
Turn Apple-platform security research evidence into a reproducible, exact-build technical report. Use when Codex must document affected hardware and OS builds, expected and observed behavior, a minimal test case, artifact hashes, crash or sysdiagnose evidence, impact, mitigations, version bounds, beta revalidation, unresolved questions, or a handoff to the current Apple Security Research, Security Bounty, or Security Research Device reporting process.
Inventory and correlate exact-build Apple kernel, kernel collection, KDK, panic, boot-chain, device-tree, IPSW, restore-image, LocalPolicy, SSV, AuxKC, personalization, and firmware artifacts. Use when Codex must compare public XNU or dyld source with shipping binaries, match KDK symbols and UUIDs, distinguish Mac restore from iPhone or iPad firmware, map Apple Silicon boot evidence, or preserve coprocessor and firmware payload metadata without assuming undocumented payload behavior.
Research one macOS security control on an exact build, separating public contracts, private evidence, and hypotheses. Use for TCC, sandbox, entitlements, Gatekeeper, XProtect, Hardened Runtime, SIP, or system-policy changes.
Review generated pseudocode or disassembly without presenting it as original source. Use when Codex must interpret, compare, annotate, validate, or summarize output from Cutter, Rizin, Malimite, Ghidra, Hopper, ILSpy, or another decompiler or disassembler; assess recovered types and control flow; track analyst renames; or reconcile disagreements between generated output and binary or runtime evidence.
Automate repeatable Hopper analysis with its installed Python SDK or extension APIs. Use for deterministic queries, controlled annotations, structured exports, or a scriptable document operation with a checkpointed evidence trail.
Choose the smallest useful reverse-engineering workflow from an artifact's format, runtime, platform, available evidence, and research question. Use when Codex must decide between metadata inspection, static analysis, decompilation, disassembly, symbol or crash correlation, resource inspection, dynamic analysis, version comparison, or a tool-specific workflow for binaries, bundles, assemblies, firmware, or generated analysis output.
Classify compiled artifacts before deeper reverse engineering. Use when Codex needs to inspect an unknown or mixed artifact set such as binaries, app bundles, frameworks, dylibs, DLLs, EXEs, Unity build outputs, IL2CPP metadata, archives, symbol files, crash logs, decompiler output, or disassembler output and choose the next technical workflow without mutating original inputs.
Use Cutter for interactive Rizin-backed binary analysis and Rizin CLI for repeatable inspection, queries, scripts, and exports. Use when Codex must open a binary or shellcode, choose a loader, image, architecture, base address, or analysis preset; navigate functions, graphs, strings, sections, imports, exports, and references; record types, comments, flags, or renames; compare disassembly with available decompiler output; or hand GUI findings into reproducible Rizin commands.
Create Ghidra projects for compiled artifacts. Use for import, loader and analyzer choices, listings, functions, symbols, types, references, graphs, decompiler review, scripts, headless analysis, PyGhidra, comparisons, and archives.
Use Hopper on macOS for disassembly, graphs, pseudocode, Objective-C and Swift presentation, procedure and type edits, extensions, and debugging. Use for document setup, navigation, annotation, evidence, comparison, and discovery.
Use Malimite as a Ghidra-backed Apple app-package exploration front end for supported IPA files and copied ZIP or application-bundle inputs. Use when Codex must inspect bundle metadata, resources, provisioning data, classes, functions, strings, entry points, cross-references, reconstructed Swift or Objective-C views, or optional generated method translations while preserving Malimite, Java, Ghidra, project-database, privacy, and unsupported-format evidence.
Bootstrap or guide a reproducible Rust Cargo project with explicit package or workspace shape, cargo new or cargo init usage, edition and MSRV checks, rust-toolchain handling, test layout, and initial validation commands. Use after the Rust project shape is settled or when adding a new Cargo package to an existing repository.
Implement Rust command-line tools after the project shape is chosen, including argument parsing boundaries, command dispatch, stdin/stdout/stderr behavior, exit codes, configuration input, error messages, tests, and Cargo validation. Use for Rust CLI feature work, CLI refactors, or new binary crate implementation.
Implement reusable Rust library crates after the project shape is chosen, including public API design, module visibility, error types, feature flags, documentation examples, unit tests, integration tests, doctests, and Cargo validation. Use for Rust library implementation, API refactors, crate-boundary cleanup, or package-facing behavior.
Choose the right Rust project shape before implementation, including crate type, Cargo package or workspace layout, edition and MSRV checks, validation commands, package boundaries, and documentation updates. Use when a user wants to start, restructure, or extend a Rust project and the binary, library, workspace, CLI, service, proc macro, FFI, embedded, no_std, or maintenance shape is not already settled.
Design, inspect, and align Rust CI workflows with local Cargo validation, including cargo fmt, cargo clippy, cargo test, cargo build, cargo doc, cargo package, workspace package selection, feature matrices, MSRV checks, rustup toolchain setup, Clippy warnings-as-errors policy, caches, artifacts, and GitHub Actions-style automation.
Prepare and validate Rust Cargo package surfaces, including Cargo.toml metadata, rust-version and MSRV policy, license/readme/repository fields, include and exclude rules, path dependency restrictions, Cargo.lock policy, cargo package dry runs, and publish versus no-publish decisions. Use for publishable crates, package metadata cleanup, crates.io readiness, or release-adjacent Rust package checks.
Plan, run, and triage Rust tests with Cargo, including unit tests, integration tests, documentation tests, examples compiled by cargo test, targeted reruns, feature matrices, workspace package selection, and failure explanation. Use when adding tests, running Rust validation, or diagnosing cargo test failures.
Align Rust formatting, linting, toolchain, and CI behavior with repository policy, including cargo fmt, rustfmt style edition, cargo clippy, rust-toolchain.toml, MSRV checks, warnings-as-errors decisions, and validation command selection. Use when configuring or fixing Rust style, lint, toolchain, or CI workflows.
Implement and maintain idiomatic Java backend services, including package structure, records, sealed types, nullability, optionals, exceptions, concurrency, dependency boundaries, API and persistence seams, tests, and human-friendly diagnostics.
Build a local-first Java or Kotlin Google ADK agent service with explicit tools, model capability checks, evaluation fixtures, and draft-before-write promotion.
Implement and maintain idiomatic Scala backend services, including immutable data modeling, algebraic data types, options/eithers, effect or future-based async boundaries, framework routing, module design, tests, and functional service structure.
Inspect and maintain server-side JVM build tooling across Gradle, Maven, and SBT, including wrapper policy, Java toolchains, dependencies, multi-module boundaries, local run commands, tests, package tasks, and machine-local dependency guardrails.