Deep, adversarial branch review — parallel subagents on separate rubrics (security/correctness, code-quality, and does-it-reproduce), spawned in one message, then deduped into one…
Post-completion self-review for coding agents that runs simplify, harden, and micro-documentation passes on non-trivial code changes.
Security best practices for Sinatra applications including input validation, CSRF protection, and authentication patterns.
Полный справочник по sing-box в проекте zapret-gui (роутеры Keenetic на Entware / OpenWrt). Использовать при любых задачах о: конфигах sing-box…
Use when your LC-HRMS metabolomics analysis must run on a high-performance computing cluster (e.g., HiPerGator, SLURM-managed systems) that lacks Docker support or prefers…
Inspect SIPS Homebase status, manifest wiring, routes, host visibility, and MCP freshness. Use when asked for SIPS status, command center, host audit, plugin visibility, or…
Route a task through SIPS commands, agents, scripts, MCP tools, or bounded delegation. Use when asked to route, split, fan out, escalate, or choose the right SIPS path.
Search, inspect, and record SIPS-owned Memory Fabric lessons. Use when a task needs prior lessons, recurring-fix memory, recall health, scoped historical context, or when a…
Plan browser, app, screenshot, or UI checks before visual claims. Use when a task includes app shots, visual QA, generated assets, or runtime UI proof.
Verify SIPS proof surfaces before reporting completion. Use when asked to scan, verify, validate, prove, audit, or check whether a repo or SIPS install is coherent.
Start, inspect, or continue a persistent SIPS self-improvement loop. Use when the user asks for /selfloop, wants the agent to iteratively improve itself, or wants a goal dedicated…
Skeptic Engine v2.1 — falsification-first анализ в 4 режимах. Триггеры: 'skeptic:', 'сломай идею', 'стоит ли делать', 'проверь идею', 'аудит архитектуры', 'проверь решение',…
Performs Web3 security analysis including vulnerability detection, rug pull checks, and exploit monitoring.
Handles crypto compliance including sanctions screening, Travel Rule, MiCA requirements, tax reporting, and SEC Howey test analysis.
Manages decentralized identity including DIDs, verifiable credentials, ENS names, ZK-KYC, and on-chain attestations.
Protects transactions from MEV via Flashbots, intent-based trading, sandwich attack mitigation, and TWAP orders.
Implement module-level env/SystemConfig, cache dimensions, backend menu wiring, and bounded permission integration.
Push secrets from local .env file to cloud. Requires authentication. Use for Agentuity cloud platform operations — from tools-only/X-Skills
Use when deciding whether a parameter, object field, stored value, claim, file name, URL, path, expression, selector, or object id remains attacker-controlled at a sensitive…
Four common skill archetypes with structure templates - CLI reference, methodology, safety/security, and orchestration.
Judge someone's ability, including your own, through demonstrated performance rather than confidence or credentials. Use when hiring, mentoring, or deciding what to learn next.
Use when reviewing vulnerability reports, reproduction notes, scanner tickets, submission drafts, audit findings, or claimed technical_confirmed vulnerabilities for evidence…
Security-first skill management for OpenClaw - like a bomb-sniffing dog for skills. Sniffs out malicious payloads (crypto stealers, keyloggers, reverse shells) before…
Buenas prácticas para crear commits de git claros, atómicos y bien estructurados en español. Activa esta skill siempre que el usuario pida hacer un commit, confirmar cambios,…
解密 SkillHub 加密技能。AI 直接运行 scripts/decrypt.py 将 .dat 密文还原为完整 SKILL.md。支持文件路径、base64 字符串、stdin 三种输入方式。触发词:解密技能、encrypted skill、skill decrypt、dat 解密。
Scans installed OpenClaw skills for malicious patterns including prompt injection, credential theft, data exfiltration, obfuscated payloads, and backdoors.
Scans installed OpenClaw skills for malicious patterns including prompt injection, credential theft, data exfiltration, obfuscated payloads, and backdoors.
Use when planning, coordinating, or reviewing evidence-first security code audits, vulnerability hunting, scanner triage, exploitability review, or report verification across a…
Automated Agent Skill for Core Layout Refactoring — WebAuthn Security Bridge. Ensures industry-best continuous operation.
Use when turning local, private, or personal Agent Skills into publishable skills for GitHub, marketplaces, teams, or public sharing, especially when private paths, personal…
Scan ClawHub skills for security vulnerabilities BEFORE installing. Use when installing new skills from ClawHub to detect prompt injections, malware payloads, hardcoded secrets,…
Skill-Installation mit Security-, Herkunfts- und Mandatsgeheimnis-Gate: führt schnell durch Sachverhalt, Rechtsgrundlagen, Belege, Risiken und erzeugt einen verwertbaren — from…
Serial-iterate every scorable skill autonomously overnight via hill-climb. Default invocation drains all .claude/skills/*/evals-bearing skills (minus an embedded skip-list);…
Es un motor de gestión de versiones que transforma cambios de código complejos en un historial atómico y semántico mediante la disección de fragmentos (hunks) y el cumplimiento…
Route ordinary init, review, and security requests to Claude-native capabilities first; escalate to Octopus only when multi-LLM diversity adds value
Prepare Claw skills for public release. Use when publishing skills to GitHub or ClawdHub - covers security audit, portability, documentation, git hygiene.
Release skills to ClawhHub through the full publication pipeline — auto-scaffolding, OPSEC scan, dual review (agent + user), force-push release, security scan verification.
Disambiguator for when multiple skills could match the same user prompt. Use when uncertain which of several overlapping skills to invoke — e.g., code review…
Security scanner for OpenClaw skill packages. Scans skills for malicious code, evasion techniques, prompt injection, and misaligned behavior BEFORE installation.
Scan agent skills for security issues before adoption. Detects prompt injection, malicious code, excessive permissions, secret exposure, and supply chain risks.
Add a security gate around OpenClaw AgentSkills using cisco-ai-defense/skill-scanner. Use when setting up or operating skill scanning for ~/.openclaw/skills, wiring…
Security audit tool for AI agent skills. Scans for credential harvesting, code injection, network exfiltration, obfuscation.
Security-audit Agent Skills and plugins — vet a new skill before installing it, scan everything already installed on this machine, or harden your own skill before publishing.
Security audit and vulnerability scanning for AI agent skills before installation. Detects prompt injection in SKILL.md files, dangerous code patterns (eval, exec, subprocess),…
Security audit for Claude Code community skills. Scans SKILL.md, references/, and scripts/ for prompt injection, data exfiltration, permission bypass, dangerous commands, and…
URL validation and content sanitization for untrusted sources — use when handling external input safely
Scan a skill (SKILL.md + companion scripts) for malicious content before installation. Checks for data exfiltration, destructive commands, security bypass attempts, obfuscation,…
Sistema de validação de segurança para skills — Bianinho Vetter. Valida skills antes de instalar, detecta padrões maliciosos (exfiltração, injection, shell injection, commands…
Scan OpenClaw skills for malware, prompt injection, reverse shells, wallet theft, supply chain attacks, and data exfiltration.
Set up, run, and interpret Agent Skill evaluations (evals) with the skill-up CLI / 使用 skill-up CLI 给 Agent Skill 搭建和运行评测.
Read-only safety inspection of a third-party agent skill or plugin BEFORE it is installed or trusted.
Security-first vetting for OpenClaw skills. Use before installing any skill from ClawHub, GitHub, or other sources.
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources.
Vet ClawHub skills for security and utility before installation. Use when considering installing a ClawHub skill, evaluating third-party code, or assessing whether a skill adds…
Static analysis security scanner for third-party OpenClaw skills. Detects eval/spawn risks, malicious dependencies, typosquatting, and prompt injection patterns before…
Security scanner and health check for your AI agent skills tree. Identifies dead skills, missing documentation, and unsafe shell execution paths.
Secure sanitization system that removes prompt injection attempts from external content, ensuring AI interactions remain safe and controlled.
Perform comprehensive security audits on OpenClaw skills or agents prior to installation, import, activation, or trust.
Audit AI agent skills for security threats before installing them. Detects malicious patterns like remote shell execution, credential fishing, C2 callbacks, and supply chain…
Security scanner for AgentSkill packages. Scan skills for credential theft, code injection, prompt manipulation, data exfiltration, and evasion techniques before installing them.