
Claude Skills by ulises-jeremias
github.com/ulises-jeremiasGetting started guide for new users. Walks through setup validation, the skill/agent hierarchy,
'WHAT — Default gate for any deliverable: confirm where the final artifact will be stored
OWASP-mapped agentic security review — prompt injection, tool poisoning, identity, excessive agency, credential exposure, supply-chain, insecure output handling, overreliance, data leakage, insecure plugin/MCP design. Evidence-cited, severity-ranked.
WHAT - Planning, estimation, task breakdown, and iteration capacity fallback based on Best
Drive a real browser from the terminal using the Playwright CLI (snapshot, click, fill, screenshots,
WHAT — When the repo has no GitHub PR template, structure the pull-request body using the
WHAT — Draft and review a Product Requirements Document (PRD) using the template. Business-level
WHAT - Interactive evidence intake for project assessments. Ask the user where each evidence
'WHAT - Interactive project assessment router: define assessment scope and units, collect
Clone, index, and orchestrate multi-repo work via agent-toolkit project — symlinks, quick
WCAG 2.2 AA curated accessibility review — distinguishes automatically detectable, browser-assisted, and manual/human-judgment findings with evidence citations and SC mapping. Composes with design-assessment/design-improvement/frontend-design-review.
Interact with Slack workspaces for reading channels/messages, sending messages, adding reactions,
Interact with the official Slack CLI to create, run, deploy, and manage Slack apps, environments,
'HOW — Read-only Snowflake validation patterns: use repo-documented CLI (snowflake/sql) or
WHAT - Produce spike and research findings using the spike template; captures purpose, findings,
Inspect agent supply chain — skills/plugins/MCP/npm/py packages, hooks, scripts, remote prompts,
Create artifact/commit file handoffs for Agent Toolkit swarms with worktree-per-writer, branch,
Observe, diagnose, and recover Agent Toolkit swarm runs via status, handoffs, logs, and attach
Launch an Agent Toolkit swarm from a natural language request using agent-toolkit swarm CLI
WHAT - Draft and review technical tasks using the Best Practices Task Template; includes
WHAT - Evidence-based technical unit assessment for repositories, platforms, frontend, backend,
STRIDE + agentic threat modeling — architecture discovery → assets/trust boundaries/data flows/actors → STRIDE + agentic threats → risk-ranked mitigations → incremental review → security acceptance criteria. Swarm-friendly.
WHAT — Draft and review a Technical Requirements Document (TRD) using the template, typically
Workstation health triage — validate tooling, directory layout, and run doctor with remediation
Cut AI tells from any writing. Must always apply.
WHAT - Draft and review user stories using the task template plus the As a/I want/so that
Review UI code for Web Interface Guidelines compliance. Use when asked to "review my UI",
WHAT - Router for creating and refining epics, user stories, tasks, bugs, and incidents using
WHAT — Interactive interview to capture client delivery context and store it inside the user's
'WHAT — Generic client delivery: Jira or ClickUp, full repo context, human gates, English
Syncs knowledge to the agentic-harness knowledge base and AGENTS.md learned facts.
Scaffold and manage the stateless AI workspace — context, packs, repos, and knowledge for
Manage Git worktrees per writer for Agent Toolkit swarms — isolated branches, handoff promotion,
WHAT — Create and maintain Architecture Decision Records (ADRs) per the process. Covers when
WHAT - Capture explicit agreements, terms, parties involved, dates, validity, and linked
WHAT — Create polished dark-themed architecture diagrams as self-contained HTML+SVG files (inline SVG, CSS styling, PNG/PDF export toolbar). Use when the user asks for system, infrastructure, cloud, security, or network topology diagrams rendered as a shareable visual artifact rather than code.
Assistant — on any repo, scan README→docs→AGENTS→CONTRIBUTING→PR templates→task runners→devcontainer→CI→configs
WHAT — AWS Well-Architected Framework review (6 pillars) — operational excellence, security, reliability, performance, cost, sustainability + WAR process. Checklist for workload evaluation on AWS; complementary to official AWS MCP for live account data.
Find what a change could break somewhere else before it ships, beyond the diff, and prove the one fact it's safe because of by running real code instead of writing it up. Use for 'blast radius of X', 'what could this break', or reviewing a small diff you don't trust.
WHAT - Draft and review bugs using the Bug Template; classifies whether an issue should be
WHAT — C4 model methodology (Context, Container, Component, Code) guidance — what to draw at each level, when, and how to render C4-inspired diagrams via Mermaid (PlantUML/Structurizr optional advanced). Methodology not renderer.
Use Chrome DevTools MCP to control and inspect a live Chrome instance for network, console, performance, rendering, and Deep debugging. Pairs with playwright-cli (deterministic interaction/E2E) — complements, not duplicates.
Designs or reviews CLIs so coding agents can run them reliably: non-interactive flags, layered --help with examples, stdin/pipelines, fast actionable errors, idempotency, dry-run, and predictable structure. Use when building a CLI, adding commands, writing --help, or when the user mentions agents, terminals, or automation-friendly CLIs.
ClickUp CLI for managing tasks, sprints, comments, statuses, and Docs. Use when the user
WHAT — Vendor-neutral distributed cloud patterns (Retry, Bulkhead, Circuit Breaker, CQRS, Event Sourcing, etc.) abstracted from AWS/Azure/GCP sources — when to apply, tradeoffs, mapping to AWS/GCP/Azure primitives. Offline checklist, no live account required.
CodeQL operational workflow — discover/config, run/inspect, triage SARIF findings (rule/query ID, source→sink, evidence), remediate, re-validate. Distinguishes broad MegaLinter linting from semantic security analysis.
Confluence administration including users, groups, space settings, and permission diagnostics. Use when managing user access, group membership, viewing space configuration, or checking permissions.
View analytics, statistics, and popularity metrics for Confluence content. ALWAYS use when user wants to see views, popularity, or contributor stats.
Central hub for Confluence operations - routes requests to specialized skills. ALWAYS use when user mentions confluence, wiki, or Atlassian wiki operations.
Manage file attachments - upload, download, list, and delete attachments. ALWAYS use when user wants to work with files on pages.