Work on the Treeship source repository safely. Use when Codex or another coding agent is asked to modify, review, document, or test the zerkerlabs/treeship repo, especially…
Security scanning skill that runs Trivy to detect vulnerabilities, leaked secrets, misconfigurations, and licence risks in the local codebase and container images.
Review TypeScript code for quality, security, and correctness. Use this skill when the user asks for a code review, wants feedback on a PR or diff, or says "review this".
Expert TSA cybersecurity compliance advisor for critical infrastructure owners and operators. Use this skill whenever a user asks about TSA Security Directives for pipeli — from…
Expert TSA cybersecurity compliance advisor for critical infrastructure owners and operators. Use this skill whenever a user asks about TSA Security Directives for pipeli — from…
Navigate Taiwan fintech regulations including FSC oversight, electronic payment laws, VASP rules, AML/KYC requirements, and the regulatory sandbox.
Create and configure a Twilio account from scratch. Covers free trial signup, trial limitations, getting credentials (Account SID and Auth Token), buying a phone number, verifying…
Set up and manage Twilio authentication credentials: Auth Tokens, API keys (Standard, Main, Restricted), Access Tokens for client-side SDKs, and credential rotation.
Receive and respond to inbound messages and track outbound delivery status via Twilio webhooks — across SMS, MMS, WhatsApp, and RCS.
Choose the right Twilio authentication method and implement it correctly. Covers Auth Token (testing only), API Keys (production standard), OAuth2 client_credentials (time-limited…
Configure Twilio accounts for HIPAA compliance. Covers BAA requirements, HIPAA Project designation (self-service and support), eligible services list, per-product requirements…
Secure Twilio applications against common attacks. Covers credential management (API keys vs auth tokens), request validation (webhook signature verification), PCI DSS compliance,…
Set up a SendGrid account for email delivery. Covers API key creation (SG.-prefix), domain authentication (DKIM/SPF via CNAME records), Single Sender Verification for testing, SDK…
Send transactional and bulk email via the SendGrid v3 Mail Send API. Covers single sends, personalized batch sends with dynamic templates, scheduled sends with cancellation,…
> Use this skill whenever asked about the taxation of cryptocurrency or virtual assets for individuals in Ukraine under the framework legislated to take effect from 1 January…
> Use this skill whenever asked about the Ukrainian Unified Social Contribution (Єдиний соціальний внесок / ЄСВ / USC) paid by self-employed people — FOP sole proprietors and…
Use when /uberdev:uberscan is invoked. Read-only whole-codebase audit — packs the repo into a fixed fleet of byte-balanced areas (default 8), runs ONE multi-lens reviewer per…
> Use this skill whenever asked about UK capital gains tax for individuals. Trigger on phrases like \"SA108\", \"capital gains tax\", \"CGT UK\", \"annual exempt amount\",…
> Use this skill whenever asked about UK cryptocurrency or digital asset taxation. Trigger on phrases like \"crypto tax UK\", \"Bitcoin UK tax\", \"HMRC crypto\", \"cryptoassets…
This skill should be used when the user asks to "manage UniFi devices", "configure UniFi networks", "create a VLAN", "provision an SSID", "create firewall rules", "reorder…
Assess proxy pattern security and implementation transitions for storage collisions and initialization gaps.
ALWAYS USE THIS SKILL when a user asks about cryptocurrency taxation, digital asset reporting, or mentions any of these trigger phrases — crypto, bitcoin, ethereum, Form 8949,…
Use this skill to run Android-aware unit tests on the JVM with Robolectric — the right runner choice (AndroidJUnit4 vs RobolectricTestRunner), @Config sdk/qualifiers/application,…
Review Claude Code skills, hooks, CLAUDE.md files, scripts, or workflow configurations for design flaws, unclosed loops, stale references, side effects, security risks, and…
Produce data-flow and process-flow diagrams that let engineering and operations teams model threats together.
Use this skill when adding or evolving Myco's SQLite vault database schema and its Cloudflare D1 cloud counterpart — even if the user doesn't explicitly ask for "schema work."…
Use this skill whenever you need to add, modify, or remove tables, columns, or indexes in the Myco vault SQLite schema — even if the user just asks to "add a column" or "create a…
Use this skill during Phase 5 formal hardening. Provides tool selection, proof harness patterns, security/purity audit expectations, and verification result interpretation for…
This skill assesses vendor risk including financial stability, security posture, and concentration risk.
Use this skill when working with Abnormal Security VendorBase vendor risk assessment - vendor risk scores, compromised vendor detection, vendor domain analysis, and supply chain…
Extends Capability Evolver with verification, rollback, and promotion gating. Use when an agent logs a learning, proposes a self-improvement, or wants to promote a learning to…
This skill helps Claude write secure web applications. Use this when working on any web application or when a user requests a scan or audit to ensure security best practices are…
Secure credential management for agents. Use this skill when users need to store API keys,\n passwords, OAuth tokens, or SSH keys and write them to .env files without exposing…
Advanced negotiation and communication advisor grounded in Chris Voss's tactical empathy methodology (Never Split the Difference, The Black Swan Group).
Use this skill when working with SentinelOne XSPM vulnerabilities - tracking CVEs, reviewing EPSS scores, assessing exploit maturity, managing vulnerability status, prioritizing…
Automated discovery and triage of security weaknesses in network systems, applications, or cloud configurations.
Use this skill when analyzing Blackpoint Cyber (CompassOne) exposure data — host vulnerability findings filtered by CVE and exploitability, vulnerability scan history, dark-web…
Rank potential system threats by risk level and business impact to guide remediation effort. Use this skill whenever the user mentions vulnerability prioritization, epss, cisa…
This skill should be used when the user asks to "review architecture", "Well-Architected review", "check bestpractices", "security assessment",or "cost optimization analysis".
Enforce role-based access control and audit user permissions against live security policy for warehouse datasets and endpoints.
Scan and obfuscate sensitive personal data inside warehouse tables and pipelines using deterministic pattern matching or cryptographic salting for compliance.
Use this skill for Rive web and React runtime integration, .riv assets, state machines, inputs, lifecycle cleanup, accessibility, remote asset security, and fallback behavior.
Use this skill when writing, reviewing, auditing, or deploying Solidity smart contracts. Triggers on Solidity development, smart contract security auditing, DeFi protocol…
Use this skill when working with Hudu website records - website monitoring, SSL/TLS tracking, email security (DMARC, DKIM, SPF), DNS records, and linking websites to companies.
Android WebView security assessment and exploitation. Use this skill whenever the user mentions WebView vulnerabilities, Android app pentesting, JavaScript bridges, deep-linking…
Use this skill when working with RunZero wireless network discovery — listing discovered wireless networks, identifying rogue access points, analyzing wireless security…
This skill should be used when the user asks to "analyze network traffic with Wireshark", "capture packets for troubleshooting", "filter PCAP files", "follow TCP/UDP streams",…
ACTIVATE for ANY finance, investment, trading, or market query. Triggers: ticker symbols ($AAPL, BTC, EUR/USD), asset classes (stocks, crypto, forex, bonds, commodities,…
Produce a structured senior-architect code review of a WordPress plugin or theme — file-by-file audit covering security, performance, architecture, correctness, WordPress…
This skill should be used when the user asks to "review my WordPress site", "audit my WordPress architecture", "WordPress performance audit", "WordPress security review", "scale…
Founder-mode plan review — stress-test a plan before implementation begins. Four modes: EXPAND (dream big), SELECTIVE (hold scope + cherry-pick expansions), HOLD (maximum rigor),…
Use whenever the user wants to add payments to an API, monetize endpoints, implement x402, handle HTTP 402 responses, create paid APIs, set up crypto paywalls, accept USDC, or…
Use this skill when the user wants to send or fetch files through an Xdrop server from the terminal, asks to automate encrypted Xdrop share-link workflows, provides an Xdrop…
Secret management expert. ALWAYS invoke this skill when you need to read API keys, tokens, or other secrets configured by the user.
Scrape daily job listings from YCombinator's Workatastartup platform without duplicates. Use this skill when asked to scrape YC jobs, update the YC companies list, or retrieve the…
This skill should be used when the user asks about zero-knowledge proofs, ZK SNARKs, witness data, prover/verifier roles, constraint systems, proof generation, proof verification,…
This skill should be used when the user asks about "Zod security", "Zod over-posting attack", "mass assignment Zod", "z.strictObject security", "z.custom security", "Zod coercion…
AI trading agent executing crypto trades across multiple DEXes with NFT minting and floor price analysis.
Perform comprehensive codebase analysis and generate reports (usage: /analyze [full|security|performance])
Use for five-agent-dev-team secret handling, workflow permissions, Docker safety, dependency audit, local binding, and supply-chain review.