
Claude Skills by Undermybelt
github.com/UndermybeltDiscovering and exploiting XML External Entity injection vulnerabilities to read server files, perform SSRF,
Develop precise YARA rules for malware detection by identifying unique byte patterns, strings, and behavioral
Zero-Knowledge Proofs (ZKPs) allow a prover to demonstrate knowledge of a secret (such as a password or private
Deploy CyberArk Secure Cloud Access to eliminate standing privileges in hybrid and multi-cloud environments using
Implement HashiCorp Boundary for identity-aware zero trust infrastructure access management with dynamic credential
Implement Zero Trust Network Access using Zscaler Private Access (ZPA) to replace traditional VPN with identity-based,
Deploy Google BeyondCorp Enterprise zero trust access controls using Identity-Aware Proxy (IAP), context-aware
'This skill guides organizations through implementing zero trust architecture in cloud environments following
Implement NextDNS as a zero trust DNS filtering layer with encrypted resolution, threat intelligence blocking,
'Implementing Zero Trust Network Access (ZTNA) in cloud environments by configuring identity-aware proxies, micro-segmentation,
'Implementing zero trust access controls for SaaS applications using CASB, SSPM, conditional access policies,
Exploit the Zerologon vulnerability (CVE-2020-1472) in the Netlogon Remote Protocol to achieve domain controller
'Configuring Zscaler Private Access (ZPA) to replace traditional VPN with zero trust network access by deploying
Use when auditing bounty scope CSVs, public source repos, or no-account bounty surfaces such as exposed RPC/API services; also use for HackerOne-style reports, weakness classification, and PoC zip attachments.
Jailbreak LLMs: Parseltongue, GODMODE, ULTRAPLINIAN.
Class-level umbrella for sub.hdd.sb puzzle platform reverse engineering, Tampermonkey/userscript automation, solver hotfixes, and game-specific debugging across puzzle15, 2048, memory, sudoku, and tile-style games. Use when working on the sub.hdd.sb platform itself, its API contracts, iframe/hub-entry runtime, or any local solver script.
AI engineering curriculum reference.
Gap-driven arXiv research: identify gaps in project docs, search arXiv API for papers, extract key sections via ar5iv HTML fallback, write structured synthesis md, convert best paper to Python. Trigger when user asks to 'find papers', 'research papers for X', '补强文档', or '搜论文并转成py'.
Autonomous experiment/evaluate/iterate loop for code, prompts, skills, or workflows. Use when optimizing a measurable metric with repeated keep/discard decisions and resumable state.
AutoR — human-centered 研究执行框架。8阶段 pipeline,产出可复现 artifact。
Monitor blogs and RSS/Atom feeds via blogwatcher-cli tool.
Use the reviewed local bpc-fetch source as an optional article discovery, supported-site lookup, and authorized article-export CLI wrapper. Activate when the user mentions bpc-fetch, Bypass Paywalls Clean, paywall article discovery, supported paywall sites, batch article export, 付费墙抓取, 绕过付费墙, 新闻文章批量抓取, or article-to-Markdown workflows.
用 headless 采样番茄书库不同字数段热榜,在字体混淆下仍归纳男频读者侧写、爽点偏好与写作策略。
Operate or review the AI Daily Frontier / github-trending-spider project: a Python + Vue app that aggregates GitHub Trending, Hacker News, TLDR AI, V2EX, Linux.do, OpenAI, Anthropic, and InfoQ AI sources into Chinese AI/frontier summaries, JSON snapshots, a FastAPI read API, optional scheduler, optional SMTP email, and a Vue frontend. Use when the user mentions github-trending-spider, AI Daily Frontier, 每日AI前沿, AI 资讯聚合, GitHub Trending 日报, AI 新闻爬虫, or multi-source AI news digest automation.
Provide the ability to search, inspect, and read source code from all public GitHub repositories and their associated documentation.
Query OpenAlex for scholarly works, DOI lookups, citation metadata, author/source/topic filters, and API quota status. Use when the user asks to search papers, find literature, lookup DOI/OpenAlex IDs, query OpenAlex, 查论文, 搜论文, or inspect paper metadata with citations.
Search, download, and read academic papers from 20+ sources (arXiv, PubMed, Semantic Scholar, CrossRef, OpenAlex, etc). Use when the user asks to find papers, search academic literature, look up research papers, download a paper PDF, or extract text from a paper.
使用 QMD 作为 Hermes 的外部记忆检索层。面向本机 notes/docs/projects/skills/sessions 的本地混合检索,优先走向量或 hybrid 搜索,而不是只靠 session_search。
Explore literature-grounded research innovation ideas and paper framing in a host-neutral way. Use when an AI agent needs to collect a recent paper pool, run broad and deep literature search, decompose methods into reusable capabilities, generate A+B or module-combination candidates, shortlist feasible ideas, design a defensible unifying framework, and produce an elegant Markdown report with citations, analysis rationale, and visual summaries.
Use when doing research or knowledge-work from Hermes: arXiv discovery, prediction-market data, wiki/markdown knowledge bases, Obsidian notes, or DSPy-style research/prototyping of LM programs.
Search arXiv papers by keyword, author, category, or ID. 触发方式:Hermes 路由名 `research/arxiv`、通用 slash command `/skill research/arxiv`
Write ML papers for NeurIPS/ICML/ICLR: design→submit.
Use when the user asks about Microsoft SkillOpt, optimizing or training agent skill documents with reflective loops, evaluating skill changes with validation gates, or running SkillOpt experiments. This is a wrapper around the local reviewed source checkout and must not run installs, training, WebUI, or model/API calls unless explicitly requested.
X/Twitter via xurl CLI: post, search, DM, media, v2 API.
Use when improving Hermes or a repo's agent docs around memory boundaries, external knowledge routing, thin-harness-fat-skills structure, or short AGENTS/CLAUDE map design. Activate when you want to absorb good ideas from systems like GBrain without inheriting their prompt authority.
Evaluate external agent learning and memory harnesses from code before installing; verify host coupling, enforcement reality, forgetting semantics, and safe adopt-vs-adapt recommendation.
Use when a repo is suffering architecture drift, API drift, main-file bloat, boundary erosion, or repeated breakage from cross-layer edits. Enforces artifact-first anti-drift governance: classify drift type, declare allowed change surface, write durable repo artifacts, require mechanical checks, and only then modify code.
Plan-work-review harness for Claude Code.
Pre-release audit for CLI tools (especially Rust/Python). Checks build, tests, help quality, output friendliness (agent + human), path leaks, dependency portability, .gitignore hygiene, and missing release artifacts.
Pre-commit review: security scan, quality gates, auto-fix.
Codex/Claude/OpenCode session patcher review.
Debug Hermes TUI slash commands: Python, gateway, Ink UI.
Use when a user asks Hermes to design, scaffold, refactor, or implement a non-trivial software project, service, platform, or architecture. Enforces slow-is-smooth DDD discipline: strategic design first, tactical design second, implementation last; prevents rushing into code before domain boundaries, ubiquitous language, ACLs, and pure domain models are established.
Hermes 中文优先的决策面技能:把“主目标、偏好权重、硬约束、取舍规则”单独落成用户可改文件, 不再埋在提示词里。适用于方案很多、取舍复杂、用户偏好稳定、执行前必须先定方向的任务。
Convert evo's experiment-tree optimization model into a Hermes-native workflow for benchmark-driven code evolution using git worktrees, scored experiments, gates, traces, and iterative branching.
Hermes 中文优先的轻量自主循环技能:每轮新上下文、状态写文件、Git 留痕、小任务推进、测试/构建/验收作为回压门禁。 当用户说一直跑、循环做、分小步、断点续跑、跑到完成、像 Ralph 那样、别塞爆上下文时使用。
Identify project gaps, search GitHub for reference implementations, translate/adapt to target language, integrate with tests
Install and use graphify from Hermes to build knowledge graphs for codebases, docs, papers, or mixed folders, then inspect GRAPH_REPORT.md and graph outputs.
Debug Hermes gateway when Feishu/Lark credentials appear configured but the bot does not reply. Covers stale launchd env, platform-not-enabled states, websocket startup failure, and duplicate local gateway conflicts.
Use when Hermes is asked to install, trust, review, clone, or rely on an external skill, MCP server, repository, URL, document, on-chain address, or product integration. Activate when untrusted external input could lead to prompt injection, supply-chain poisoning, credential theft, destructive actions, or unsafe high-privilege behavior.