All authors

Claude Skills by moh-obaida
github.com/moh-obaida55 skills0 installs5 views
- Wcag ReadinessUse when a site should be usable with a keyboard, screen reader, zoom, and different vision and motion needs: image alternatives, semantic structure and headings, keyboard operation and visible focus, contrast, form labels and errors, dialogs, reduced motion, and touch targets. It checks rendered behavior and fixes what is clearly wrong. Do not use it to claim WCAG conformance from an automated scan, to invent alt text a scanner wants, or to assert a legal accessibility outcome.Votes: 0GitHub stars: 2
- Admin Audit LogUse when admins, staff, or support can perform destructive or sensitive actions such as deleting users, changing roles, issuing refunds, exporting data, impersonating, or changing settings, and you need to check that these actions leave a durable who-did-what record without storing secrets. Do not use it to build a logging platform, to log passwords, tokens, or full personal data, or when no privileged actions exist.Votes: 0GitHub stars: 2
- Admin AuthorizationUse when a product already has admin, staff, moderator, or operator routes, screens, or APIs, and you need to verify that every privileged operation is protected by server-side authorization, not by a hidden link. It tests privileged routes as anonymous and as a normal user on a local or staging build. Do not use it to build the admin screens themselves, to accept a hidden menu item as authorization, or to test production accounts you do not own.Votes: 0GitHub stars: 2
- Admin DashboardUse when someone asks for an admin dashboard, back office, or operator panel, or when a launched product needs operators to manage users, content, payments, subscriptions, support messages, privacy requests, or moderation. It reads the actual application, works out what this product's operators need, and builds a complete admin tailored to that product and to the project's existing design system, with server-side authorization and only real data. Do not use it to paste in a generic admin temp...Votes: 0GitHub stars: 2
- Payments ReadinessUse when a site takes payments through a provider such as Stripe, Paddle, Lemon Squeezy, or PayPal and you need to check integration mode, key handling, webhook verification, and that the checkout flow works and never touches card data. It verifies test versus live configuration and exercises checkout in test mode only. Do not use it to store card numbers, to enter real payment details, to move money, or to judge payment regulation.Votes: 0GitHub stars: 2
- Subscription ReadinessUse when billing recurs: subscriptions, trials that convert, auto-renewing plans, or metered billing. It checks that renewal, trial conversion, price changes, and cancellation are disclosed, actually work in the billing system, and agree across page, checkout, terms, and emails. Do not use it on products without recurring billing, to invent cancellation or refund terms, or to state renewal-law requirements from memory.Votes: 0GitHub stars: 2
- Ai Features ReadinessUse when a product calls a language model or other AI API, embeds AI-generated content, or offers a chatbot, and you need to check provider keys and exposure, what user data reaches the provider, disclosure that users are dealing with AI, abuse and cost controls, and failure behavior. Do not use it to add a generic AI disclaimer to a product with no user-facing AI, to judge model quality, or to interpret AI regulation.Votes: 0GitHub stars: 2
- Analytics PrivacyUse when a site includes analytics, advertising pixels, session replay, heatmaps, or a tag manager and you need to know what they collect, when they fire, and whether the disclosure and any consent gating match. It inventories vendors and personal-data exposure and verifies timing at runtime. Do not use it to install analytics, to certify a vendor as compliant, or to state that analytics needs or does not need consent without looking up the rule at an official source.Votes: 0GitHub stars: 2
- Consent ManagementUse when a site has analytics, advertising, session replay, or other optional trackers and a consent control exists or may be needed. It determines whether gating is applicable by looking up the current rule at an official source, then verifies the behavior of reject, accept, and withdraw, not the appearance of the banner. Do not use it to add a cookie banner to a site with nothing to gate, to decide legal applicability from memory, or to design a dark-pattern consent flow.Votes: 0GitHub stars: 2
- Consumer Protection ReadinessUse when a product shows prices, sells goods or services, offers trials, subscriptions, or refunds, and you need to check that pricing, fees, renewal, cancellation, refund terms, delivery, and merchant identity are shown clearly and consistently across page, checkout, terms, and emails. Do not use it to invent refund or cancellation terms, to state consumer-law requirements from memory, or for sites that take no money and show no offers.Votes: 0GitHub stars: 2
- Cookie And Storage AuditUse when you need to know what a site actually stores in the browser and which third parties it contacts, and whether the cookie or tracker disclosure matches: cookies, localStorage, sessionStorage, IndexedDB, third-party requests, at load and after interactions. It separates observed runtime behavior from source suspicion. Do not use it to add a cookie banner, to write the privacy policy, or to decide that consent is legally required.Votes: 0GitHub stars: 2
- Data Flow MappingUse when you need a factual map of what personal data a site collects and where it goes: form fields, account data, database columns, API routes, cookies and identifiers, and every recipient from vendors to email and analytics. It is the input for privacy notices, deletion flows, and vendor reviews. Do not use it to decide a legal basis, to write the notice, or to guess flows you cannot find in code or traffic.Votes: 0GitHub stars: 2
- Data RightsUse when a product has accounts or stored personal data, or a policy promises access, correction, deletion, export, or opt-out, and you need to verify what those actions really do. It traces deletion, export, and opt-out through code and stored state. Do not use it to describe active=false as permanent deletion, to run destructive actions on real data, or to state which rights or deadlines apply legally.Votes: 0GitHub stars: 2
- Email ComplianceUse when a product sends email or collects addresses for newsletters, product updates, promotions, or lifecycle campaigns, and you need to verify sender identity, transactional versus marketing separation, and that unsubscribe actually suppresses future sends. It traces the unsubscribe from link to stored state to the send path. Do not use it to stop at the presence of a link, to send real email to real people, or to state legal sufficiency.Votes: 0GitHub stars: 2
- Jurisdiction ApplicabilityUse when privacy, consent, consumer, or accessibility questions depend on where users and the business are, and you need to record markets and audience from evidence and see which official sources to consult for them. It separates declared from inferred markets and marks unresolved applicability as review required. Do not use it to state which laws apply from memory, to pick a jurisdiction for the user, or to invent obligations.Votes: 0GitHub stars: 2
- Legal Identity NoticesUse when a public product needs to show who operates it and carry the notices its assets require: business or operator identity, copyright and trademark statements, open-source and image or font licenses, attribution, and takedown or contact routes for content. It finds missing or inconsistent identity and license notices and marks owner-only facts. Do not use it to invent a company name, address, registration number, or license text, or to give IP legal advice.Votes: 0GitHub stars: 2
- Minors ReadinessUse when a site or app may be used by children or teenagers, collects age or date of birth, or states an audience rule such as 18+. It checks who the product is evidently for, whether age is collected or implied, and whether behavior contradicts the stated audience. Do not use it to bolt on a decorative age gate, to bypass an age restriction, or to decide which child-protection law applies.Votes: 0GitHub stars: 2
- Policy ConsistencyUse when a site already has a privacy page, cookie notice, banner, terms, badges, or marketing claims about data and you need to compare what it says with what the product does: trackers, forms, cookies, storage, deletion, email, third parties. It reports contradictions and omissions as evidence-backed mismatches. Do not use it to rewrite the product to match a template, to certify a policy, or to compare against laws from memory.Votes: 0GitHub stars: 2
- Privacy PolicyUse when a site needs a privacy notice, or an existing one must reflect real behavior: it inspects what is collected, by whom, for what, and where it goes, separates supported facts from missing owner facts, and drafts only what evidence supports with clearly marked gaps. Do not use it to paste generic boilerplate, to invent addresses, retention periods, legal bases, or contacts, or to state that the notice makes the site compliant.Votes: 0GitHub stars: 2
- Privacy ReadinessUse when a product stores or processes personal data and you need to judge minimization, retention signals, exposure of personal data in URLs, logs, client storage, or public routes, and whether stored data is protected sensibly. It finds unintended exposure and unused collection. Do not use it to certify privacy compliance, to choose retention periods, or to remove data the product needs.Votes: 0GitHub stars: 2
- Regulated Domain TriggersUse when starting a launch review, and again whenever features change, to detect whether a product touches a regulated or high-risk domain: health, finance and payments, education, children, legal or professional advice, employment, insurance, crypto, gambling, alcohol or cannabis, biometrics, precise location, or automated decisions. It stops ordinary web-compliance assumptions and routes to human specialist review. Do not use it to interpret those regimes or to clear a product as unregulated.Votes: 0GitHub stars: 2
- Terms Of ServiceUse when a product with accounts, user content, purchases, subscriptions, or usage rules needs terms, or existing terms must match what the product actually does. It inspects features and drafts only supported sections, marking owner-only facts such as governing law, liability, and fees as gaps. Do not use it to paste boilerplate, to invent governing law or liability limits, or to add terms to a site that makes no commitments.Votes: 0GitHub stars: 2
- Third Party PrivacyUse when a site loads scripts, fonts, maps, video, chat, captcha, payment widgets, CDNs, or SDKs from other origins and you need to know who receives visitor data and whether that is disclosed and necessary. It maps every third-party host observed or indicated, what each sees, and what to review. Do not use it to declare a vendor illegal, to judge transfer legality, or to remove a dependency the product needs without asking.Votes: 0GitHub stars: 2
- User Content SafetyUse when users can publish, upload, comment, message, or share content that others can see, and you need to check reporting routes, moderation hooks, abuse controls, and stored-content risks such as XSS and unsafe uploads. Do not use it to add a moderation queue or reporting flow to a product with no user-visible user content, or to provide legal advice about platform liability.Votes: 0GitHub stars: 2
- Compliance AllUse when a site or app needs a privacy, consent, communications, age, data-rights, commerce, or legal-disclosure review, or when someone asks \"are we GDPR/CCPA compliant?\". It works out which of the 12 compliance domains apply from evidence, activates only those specialists, verifies behavior against disclosures, and states what needs legal review. Do not use it to force a cookie banner or a policy onto a site that does not need one, to run every legal skill, or to certify compliance.Votes: 0GitHub stars: 2
- Compliance DiffUse when reviewing a pull request, branch, or release for launch and privacy impact: new vendors or third-party hosts, new personal-data fields or forms, new routes, changed consent or email behavior, new storage. It reads the change and lists what it introduces and which ReadyVibe specialists should recheck. Do not use it as a substitute for a full review or to approve a release as compliant.Votes: 0GitHub stars: 2
- Design System ReconnaissanceUse when about to create or change any visible UI in a project, such as a 404 page, legal page, consent control, or footer link, to record the design tokens, components, layout patterns, and copy tone already in use so new pieces look native. Do not use it to design a new visual style, to redesign the site, or when no visible UI will be created or changed.Votes: 0GitHub stars: 2
- Discoverability AllUse when a public site should be found and shared correctly, or when titles, descriptions, canonicals, robots.txt, sitemap.xml, social previews, favicon, and indexing directives need one coordinated review. It runs one shared sweep, then routes only to the specialists whose findings need work. Do not use it as a ranking promise, for a private or intentionally unindexed product beyond confirming it is consistently noindex, or for a single-file fix a specialist already owns.Votes: 0GitHub stars: 2
- Launch AllUse when someone asks whether a website or web app is ready to launch, or wants a pre-launch review of a vibe-coded or AI-generated site. It inspects the real product, decides which of the 40 launch checks apply, routes only to the specialists that can help, fixes what is safe, verifies the result, and reports what still needs a human. Do not use it to run every ReadyVibe skill, to certify legal compliance, or for a single-topic request that one specialist already covers.Votes: 0GitHub stars: 2
- Launch VerificationUse when a fix or a finding needs proof: re-checking behavior after a change, confirming a blocker is really gone, or turning collected evidence into a scoped launch verdict. It re-runs the original evidence, records what changed, and separates verified, unverified, and review-required items. Do not use it to declare a site legally compliant, or as a substitute for the specialist that found the problem.Votes: 0GitHub stars: 2
- Production AllUse when a site is about to go live and its forms, email unsubscribe, secrets, staging leftovers, security headers, or performance have not been verified. It runs one shared production sweep and routes to the forms, email, security, and performance specialists. Do not use it for penetration testing, load testing, or certifying security, and do not use it to send real email or submit real forms on a live site.Votes: 0GitHub stars: 2
- Quality AllUse when a site needs a combined accessibility and responsive-quality review: alt text, headings, keyboard use, focus, contrast, form labels, reduced motion, phone and tablet layouts, overflow, tables, dialogs, touch targets, sticky bars. It runs one shared runtime pass and routes to the accessibility and mobile specialists. Do not use it to claim WCAG conformance, to replace assistive-technology testing, or for backend or SEO work.Votes: 0GitHub stars: 2
- Site ReconnaissanceUse when you need to know what a website or web app actually is and does before reviewing or changing it: its framework, routes, audience, accounts, payments, email, analytics, forms, third parties, and deployment. It builds a short evidence-labeled context from the repository, config, and running site without a questionnaire. Do not use it to draft policies, apply fixes, or ask the user questions the repository can answer.Votes: 0GitHub stars: 2
- Trust AllUse when a site looks finished but may still feel unfinished or untrustworthy to visitors: unclear main action, dead buttons, placeholder text, fake or unverifiable claims, missing contact path, weak 404, broken links, or missing loading and error states. It coordinates the trust-related specialists and verifies the fixes. Do not use it to add trust badges, invent testimonials or metrics, or manufacture an FAQ the product does not need.Votes: 0GitHub stars: 2
- Search Console ReadinessUse when a site is publicly live or about to be, and the owner wants search engine verification and sitemap submission prepared. It checks that the property and sitemap can be verified, prepares the exact steps and files an owner must authorize, and states what only Search Console data can show. Do not use it to claim a page is indexed, to submit or verify on the owner's behalf without permission, or before the production URL is final.Votes: 0GitHub stars: 2
- Seo ReadinessUse when public pages should be found in search, and titles, meta descriptions, canonicals, robots.txt, sitemap.xml, indexing directives, and URL consistency need to be correct and agree with each other. It checks rendered output and the relationships between files, and repairs localhost canonicals, private routes in sitemaps, and starter metadata. Do not use it to promise indexing or ranking, to keyword-stuff, or on a product that is intentionally private.Votes: 0GitHub stars: 2
- Social SharingUse when a public page may be shared in chat, social, or search previews and its Open Graph and Twitter card tags need to be correct: title, description, absolute image URL, and canonical alignment. It reads rendered output and repairs missing or placeholder tags with product-specific copy. Do not use it to invent preview copy that misdescribes the product, to point images at localhost, or for pages that will never be shared.Votes: 0GitHub stars: 2
- Structured DataUse when a page is genuinely an article, product, organization, local business, event, FAQ, or breadcrumb and JSON-LD structured data exists or would truthfully describe visible content. It validates that markup parses and matches what visitors see. Do not use it to invent ratings, reviews, prices, or FAQs, to add schema for its own sake, or to chase rich results the content does not merit.Votes: 0GitHub stars: 2
- Multilingual ReadinessUse when a site offers more than one language or locale, and you need to check locale routing, html lang, hreflang and canonicals per language, untranslated fallbacks, and whether trust and legal pages exist in each language. Do not use it to translate content yourself without the owner's approval, to call a site multilingual when key pages are missing in a language, or on single-language sites.Votes: 0GitHub stars: 2
- Rtl ReadinessUse when an RTL language such as Arabic, Hebrew, Persian, or Urdu is served or planned, and layout and behavior must mirror correctly: dir attribute, logical CSS properties, mirrored navigation, bidi text, icons, and forms. It checks rendered pages in RTL and fixes layout logic. Do not use it to mirror non-directional icons, to flip images with text, or on sites with no RTL locale.Votes: 0GitHub stars: 2
- Content TrustUse when a site should make its purpose and next step clear and its content should be real: primary call to action, dead-end pages, placeholder or lorem text, fake or unverifiable metrics, testimonials and logos, misleading claims, unfinished UI. It removes or flags fakes and verifies controls work. Do not use it to build an FAQ (use faq-readiness), to invent testimonials, metrics, or customers, to force a giant CTA onto every page, or to write marketing copy the owner has not approved.Votes: 0GitHub stars: 2
- Error PagesUse when a routed site needs a launch-quality 404 (and 500) experience: unknown URLs must return a real 404 status, render in the product's own design, help the visitor recover with useful navigation, and expose no debug details. It verifies status codes and fixes framework defaults and soft-404s. Do not use it to add a decorative page served with status 200, to invent site sections for the links, or for expected redirects.Votes: 0GitHub stars: 2
- Failure ResilienceUse when a UI loads data, calls APIs, or performs actions that can be slow, empty, or fail, and you need to check loading, empty, success, error, and recovery states: no infinite spinners, no blank screens, no swallowed errors, no lost input. It exercises failure paths and fixes states in the existing design. Do not use it to add spinners everywhere, to hide failures behind fake success, or for static pages with no data fetching.Votes: 0GitHub stars: 2
- Faq ReadinessUse when a site needs an FAQ or help section, or when visitors predictably have questions about pricing, billing, cancellation, data, delivery, or how the product works that the site does not answer at the point of decision. It works out the real questions from the product, its support traffic, and its own policies, writes answers only from facts it can verify, and builds the FAQ in the project's existing design. Do not use it to invent questions or answers, to pad a self-explanatory site wit...Votes: 0GitHub stars: 2
- Forms ReadinessUse when a site has forms (contact, signup, login, waitlist, checkout, search, feedback) and you need to verify that they are labeled, validated, submit to a working endpoint, and handle loading, success, error, and duplicate submission. It exercises forms safely against local or staging with planted test data and checks where the data goes. Do not use it to submit forms on a live production site without authorization, to send real messages, or to invent form endpoints or backends.Votes: 0GitHub stars: 2
- Launch IdentityUse when a site still carries generator or template leftovers, or its product identity is inconsistent: starter titles like Vite or Next, default favicons, placeholder company names, wrong product names in metadata and emails, missing app icons and manifest, mixed-up logos. It aligns name, titles, icons, and manifest with owner-supplied identity. Do not use it to invent a company or legal entity name, to design a logo, or to rebrand.Votes: 0GitHub stars: 2
- Legal NavigationUse when legal and policy pages exist or must be reachable, and the footer, signup, checkout, and cookie surfaces need links that point to real pages: privacy, terms, cookies, refund, accessibility, contact. It adds links only to pages that exist and reports missing pages to their owning skills. Do not use it to link to pages that do not exist, to create legal pages itself, or to place links in places that mislead about agreement.Votes: 0GitHub stars: 2
- Link IntegrityUse when links, buttons, and route targets across a site must actually resolve: navigation, footer, CTAs, content links, canonical and sitemap targets, mailto and tel links, form actions, and external references. It separates confirmed broken routes from transient network failures and repairs internal links safely. Do not use it to declare an external site broken from a single timeout, to crawl a site you do not have permission to test, or to replace browser testing of client-side interactions.Votes: 0GitHub stars: 2
- Mobile ReadinessUse when a site must work on phones and tablets, and you need real evidence from rendered layouts at small viewports: viewport meta, horizontal overflow, navigation, reading width, forms, tables, dialogs, touch targets, sticky bars, and whether the main task can be completed. Do not use it to treat \"no horizontal scrollbar\" as mobile readiness, to claim device coverage from one emulated size, or to redesign the site.Votes: 0GitHub stars: 2
- Performance ReadinessUse when public pages must load acceptably before launch and you want practical evidence of high-impact waste: oversized images, huge JavaScript bundles, render-blocking scripts, unnecessary fonts and third parties, unsized media causing layout shift, and heavy above-the-fold content. It records lab signals and fixes obvious waste. Do not use it to promise a Lighthouse score or Core Web Vitals outcome, to invent field data, or as a performance laboratory.Votes: 0GitHub stars: 2