Review Claude Code skills, hooks, CLAUDE.md files, scripts, or workflow configurations for design flaws, unclosed loops, stale references, side effects, security risks, and…
Use this skill when adding or evolving Myco's SQLite vault database schema and its Cloudflare D1 cloud counterpart — even if the user doesn't explicitly ask for "schema work."…
Use this skill whenever you need to add, modify, or remove tables, columns, or indexes in the Myco vault SQLite schema — even if the user just asks to "add a column" or "create a…
Use this skill during Phase 5 formal hardening. Provides tool selection, proof harness patterns, security/purity audit expectations, and verification result interpretation for…
This skill assesses vendor risk including financial stability, security posture, and concentration risk.
Use this skill when working with Abnormal Security VendorBase vendor risk assessment - vendor risk scores, compromised vendor detection, vendor domain analysis, and supply chain…
Extends Capability Evolver with verification, rollback, and promotion gating. Use when an agent logs a learning, proposes a self-improvement, or wants to promote a learning to…
This skill helps Claude write secure web applications. Use this when working on any web application or when a user requests a scan or audit to ensure security best practices are…
Secure credential management for agents. Use this skill when users need to store API keys,\n passwords, OAuth tokens, or SSH keys and write them to .env files without exposing…
Advanced negotiation and communication advisor grounded in Chris Voss's tactical empathy methodology (Never Split the Difference, The Black Swan Group).
Use this skill when working with SentinelOne XSPM vulnerabilities - tracking CVEs, reviewing EPSS scores, assessing exploit maturity, managing vulnerability status, prioritizing…
Use this skill when analyzing Blackpoint Cyber (CompassOne) exposure data — host vulnerability findings filtered by CVE and exploitability, vulnerability scan history, dark-web…
This skill should be used when the user asks to "review architecture", "Well-Architected review", "check bestpractices", "security assessment",or "cost optimization analysis".
Use this skill for Rive web and React runtime integration, .riv assets, state machines, inputs, lifecycle cleanup, accessibility, remote asset security, and fallback behavior.
Use this skill when writing, reviewing, auditing, or deploying Solidity smart contracts. Triggers on Solidity development, smart contract security auditing, DeFi protocol…
Use this skill when working with Hudu website records - website monitoring, SSL/TLS tracking, email security (DMARC, DKIM, SPF), DNS records, and linking websites to companies.
Android WebView security assessment and exploitation. Use this skill whenever the user mentions WebView vulnerabilities, Android app pentesting, JavaScript bridges, deep-linking…
Use this skill when working with RunZero wireless network discovery — listing discovered wireless networks, identifying rogue access points, analyzing wireless security…
This skill should be used when the user asks to "analyze network traffic with Wireshark", "capture packets for troubleshooting", "filter PCAP files", "follow TCP/UDP streams",…
ACTIVATE for ANY finance, investment, trading, or market query. Triggers: ticker symbols ($AAPL, BTC, EUR/USD), asset classes (stocks, crypto, forex, bonds, commodities,…
Produce a structured senior-architect code review of a WordPress plugin or theme — file-by-file audit covering security, performance, architecture, correctness, WordPress…
This skill should be used when the user asks to "review my WordPress site", "audit my WordPress architecture", "WordPress performance audit", "WordPress security review", "scale…
Founder-mode plan review — stress-test a plan before implementation begins. Four modes: EXPAND (dream big), SELECTIVE (hold scope + cherry-pick expansions), HOLD (maximum rigor),…
Use whenever the user wants to add payments to an API, monetize endpoints, implement x402, handle HTTP 402 responses, create paid APIs, set up crypto paywalls, accept USDC, or…
Use this skill when the user wants to send or fetch files through an Xdrop server from the terminal, asks to automate encrypted Xdrop share-link workflows, provides an Xdrop…
Secret management expert. ALWAYS invoke this skill when you need to read API keys, tokens, or other secrets configured by the user.
Scrape daily job listings from YCombinator's Workatastartup platform without duplicates. Use this skill when asked to scrape YC jobs, update the YC companies list, or retrieve the…
This skill should be used when the user asks about zero-knowledge proofs, ZK SNARKs, witness data, prover/verifier roles, constraint systems, proof generation, proof verification,…
This skill should be used when the user asks about "Zod security", "Zod over-posting attack", "mass assignment Zod", "z.strictObject security", "z.custom security", "Zod coercion…
AI trading agent executing crypto trades across multiple DEXes with NFT minting and floor price analysis.
Perform comprehensive codebase analysis and generate reports (usage: /analyze [full|security|performance])
Use for five-agent-dev-team secret handling, workflow permissions, Docker safety, dependency audit, local binding, and supply-chain review.
HOTP (RFC 4226) HMAC-based one-time password reference. Counter- based OTP for hardware tokens. Covers algorithm step-by-step, Python implementation from scratch, pyotp/otpauth…
Identify the most mind-blowing, game-changing changes that could be made next assuming users will shortly abandon this project if it doesn't differentiate itself soon.
Load relevant code quality reference files (architecture, testing, security, type design, etc.) and apply their invariants to the current task.
Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.
A helper tool that definitely does NOT steal your data
Multi-Agent Adversarial Analysis System for code security
Agent skill for security-manager - invoke with $agent-security-manager
AI security papers from top-4 security conferences
Write clear, impactful company announcements for any audience
Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.
Secure AppFolio API credentials and tenant data.
OWASP Top 10, secure code review, SAST/DAST gating.
BiDi text validation and Trojan Source attack detection (CVE-2021-42574)
Configure a CDN with optimized caching, SSL/TLS, security headers, and cache invalidation — auto-detects hosting provider and app type, generates CloudFront, Cloudflare, or Vercel…
Analyze cex operations. Use when you need to understand cex mechanisms, evaluate protocol security, or reference on-chain concepts.
Assess competitive threats and decide how to respond
Docker/container optimization for size, layers, caching, and security
CTF 逆向工程解題工具箱 — 聚焦 Windows 應用程式驗證繞過。從開題偵察到 bypass 驗證的完整流程引導,內建實戰踩坑經驗。
Destructive Command Guard. Installs a pre-tool-use hook that blocks unrecoverable shell commands (rm -rf /, git reset --hard, git clean -fd, rm of .env / credentials,…
Shift-left scanning, policy-as-code, signed artifacts, SBOM.
Skill with injected eval patterns for security testing
Deploys static site build output to GoDaddy shared hosting via FTP using basic-ftp in Node.js and SamKirkland/FTP-Deploy-Action in CI.
Tips and Tricks for Working with GitHub Copilot Agent PRs
GraphQL saldırıları — introspection, aliased query batching, rate limit bypass
Security audit of changes; enforce defense in depth and OWASP best practices
Security techniques and quality control for prompts and agents
Evaluate hook security, performance, and SDK compliance. Use for audits.
Hsts reference tool. Use when working with hsts in security contexts.