Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
Home › Tag › Scanner

Scanner — Claude Code Skills

925 Claude Code skills tagged Scanner. Browse all behavioural skill type-related skills in the open ClaudSkills registry — free to install, one-click via the desktop app.

Showing top 200 of 925 skills, ranked by quality score.

scan-setup

Use when wiring a repo to maintained DETERMINISTIC scanner gates (SAST, dependency-CVE/SBOM, secret-history, IaC/container, mutation, fuzz) that produce ground-truth observables —

security

sdlc:repo-health

Run a multi-tool repository quality assessment — git object health, contributor analytics, commit hygiene, hook configuration, secret scanning, module dependency architecture, and

engineering

afm-spm-analyzer

Atomic Force Microscopy and Scanning Probe Microscopy skill for nanoscale topography, mechanical, and electrical property mapping

general

aws-security-scanner

AWS security configuration scanning and hardening using Prowler, Security Hub, and AWS Config

security

azure-security-scanner

Azure security configuration scanning and hardening using Azure Security Center, Azure Policy, and ScoutSuite

security

codeql-expert

Expert-level CodeQL for static analysis, vulnerability detection, and security code scanning

security

confirming-pentest-authorization

Verify that a penetration test has explicit, written, signed authorization before any scanning begins. Reads a Rules-of- Engagement (ROE) attestation file, validates required field

security

container-security-scanner

Container image and Kubernetes security scanning for CVEs, misconfigurations, and compliance

security

defining-pentest-scope

Parse the ROE scope definition, enumerate every in-scope target (hostnames, IPs, CIDRs, URLs, cloud accounts, SaaS tenants), validate syntax, detect overlap with out-of-scope or kn

security

fleet-payload-tasking

Deploy payloads and shell commands fleet-wide using reliable tasking. Execute scripts, collect data, or run commands across all endpoints with automatic handling of offline sensors

security

full-lp-workflow

Full LP workflow from opportunity scanning to position entry. Autonomously finds the best LP opportunity, designs a strategy, assesses risk, executes any needed swaps, enters the p

general

gcp-security-scanner

GCP security configuration scanning and hardening using Security Command Center, Forseti, and ScoutSuite

security

geo-brand-mentions

Brand mention and authority scanner for AI visibility. Analyzes brand presence across platforms that AI models rely on for entity recognition and citation decisions. Produces a Bra

growth

git-forensics-scanner

Git diff forensics for surfacing and classifying code changes for trojan detection

general

gs:cso

Chief Security Officer mode. Infrastructure-first security audit: secrets archaeology, dependency supply chain, CI/CD pipeline security, LLM/AI security, skill supply cha — from th

security

iac-security-scanner

Infrastructure as Code security scanning and policy enforcement for Terraform, CloudFormation, Kubernetes, and Pulumi

security

kics

Run Checkmarx KICS for Infrastructure as Code security scanning. Use when analyzing Terraform, CloudFormation, Kubernetes, Ansible, Dockerfile, or other IaC for misconfigurations a

security

loom-dependency-scan

Scan project dependencies for CVEs, outdated packages, and license compliance across npm, pip, cargo, go, maven, and other ecosystems. Use for vulnerability scanning, SBOM generati

security

reviewing-findings

Reviews AWS cost optimization findings for accuracy, validates recommendations, and filters false positives using confidence-based scoring. Use after scanning to ensure high-qualit

general

sarif-parsing

Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners. Triggers on "parse sarif", "read scan results", "aggregate findings", "deduplic

general

scanning-for-hardcoded-secrets

Scan a source-code tree for hardcoded credentials embedded in source files: AWS access keys, GitHub tokens, Stripe keys, Slack tokens, Anthropic API keys, OpenAI keys, JWT signing

security

sem-eds-analyzer

Scanning Electron Microscopy with Energy Dispersive X-ray Spectroscopy skill for morphology and elemental analysis

general

stm-analyzer

Scanning Tunneling Microscopy skill for atomic-resolution imaging and local density of states measurements

general

tech-stack-scanner

Automated technical architecture review, security assessment, scalability analysis

security

yara-authoring

Write and test YARA rules for malware detection and threat hunting. Use when creating YARA signatures, detecting malware families, scanning files or memory for indicators of compro

security

astgrep

Unified code search via ast-grep (AST structural) + ripgrep (text). TRIGGER when: searching code patterns, finding function calls, AST pattern matching, text keyword search, refact

engineering

audit-full

Single-pass codebase analysis leveraging Opus 4.6 1M context for comprehensive security scanning, architecture review, and dependency auditing. Loads entire codebases for cross-fil

security

blog-audit

Full-site blog health assessment scanning all blog files for quality scores, orphan pages, topic cannibalization, stale content, and AI citation readiness. Spawns parallel subagent

content

broken-link-scanner

Crawl a domain or sitemap to find broken links (4xx/5xx), orphan pages, and soft-404s — with a prioritised remediation register.

general

buildkite-plugin-security

Security review and vulnerability scanning for Buildkite plugins (Bash, Docker, Go). Use when auditing or hardening a plugin, reviewing plugin code for vulnerabilities before relea

security

phx:deps-vet

Record a vetted Hex package version in hex_vet.exs after a security review — manages the audit ledger, not the scanner. Use to approve a dep after /phx:deps-audit findings or to in

security

diagnose

Routes a vague symptom or complaint to the most relevant Clairvoyance skill via a decision tree. Use when someone describes a problem but doesn't know which skill to reach for. Not

general

do-skills-audit

Audit all Claude Code skills for compliance with canonical template standards. Use when checking skill quality, validating skill structure, linting SKILL.md files, verifying frontm

general

enumerate

Generate or refresh coverage manifest for a scanner — lists ALL items in scope so scans can track progress across sessions.

general

firebase-apk-scanner

Scans Android APKs for Firebase security misconfigurations including open databases, storage buckets, authentication issues, and exposed cloud functions. Use when analyzi — from Jo

engineering

firebase-apk-scanner

Scans Android APKs for Firebase security misconfigurations including open databases, storage buckets, authentication issues, and exposed cloud functions. Use when analyzi — from en

engineering

gh-repo-security-audit

OpenSSF-aligned security posture audit across all repos in a GitHub account: default workflow token permissions, allowed-actions policy, branch protection, secret scanning + push p

security

ghost-scan-secrets

Ghost Security - Secrets and credentials scanner. Scans codebase for leaked API keys, tokens, passwords, and sensitive data. Detects hardcoded secrets and generates findings with s

security

gungnir

Attack your own system — under explicit authorization — to prove its defenses hold, before launch and continuously after: scope and authorize, recon, scan and enumerate, exploit an

security

haipipe-insight-explore

Coverage / readability scanner of the haipipe-insight family. Reads the project's probes/ and existing insights/ folders; reports which probes are CONFIRMED and ready for synthesis

general

md-maximalist

Use markdown's full formatting range — tables, callouts, task lists, collapsible sections, code fences, bold-lead bullets — to build tasteful richness in docs. Chooses the form fro

general

misardefender

Manage and interact with MisarDefender — the local macOS security daemon. Use when: checking security daemon status, viewing security events, starting/stopping defender, scanning f

security

nio-scan

Nio code/skill execution-risk scanner. Use when the user wants to scan a file, repo, directory, or skill for execution risks — e.g. "scan this code for risks", "is this file/plugin

general

pipeline-security

Security review, hardening, and vulnerability scanning for Buildkite pipelines and self-hosted agents (CI/CD). Use when auditing a .buildkite/pipeline.yml or agent setup, hardening

security

sales-balto

Balto platform help — contact center real-time AI guidance with live call coaching, automated QA on 100% of calls, compliance monitoring, and automatic call summarization to CRM. U

sales

sales-devi

Devi AI platform help — Chrome extension for social media lead monitoring across Facebook groups, LinkedIn, X, Reddit, WhatsApp, Telegram, Nextdoor, Bluesky, Threads with AI buying

sales

sales-reddgrow

ReddGrow platform help — Reddit marketing for AI search visibility (GEO) with AI Visibility Scanning across 220+ countries and 4+ AI platforms, AI comment drafting with human revie

sales

sales-voicetonotes

VoiceToNotes platform help — AI voice-to-text transcription with real-time capture, AI summaries, grammar correction, OCR scanning, custom prompts, HIPAA compliance, web + iOS + An

sales

sast-scan

Static application security testing (SAST) for changed source files — Vulnetix''s built-in rule set plus optional Semgrep augmentation when `.semgrep` config is present. Use when r

security

ghost-scan-code

Ghost Security - SAST code scanner. Finds security vulnerabilities in source code by planning and executing targeted scans for issues like SQL injection, XSS, BOLA, BFLA, SSRF, and

security

ghost-scan-deps

Ghost Security - Software Composition Analysis (SCA) scanner. Scans dependency lockfiles for known vulnerabilities, identifies CVEs, and generates findings with severity levels and

security

scan-fix

Diagnose en fix scanner problemen. Gebruik bij "scanner", "scan", "OAuth", "tokens".

general

magpie-security-issue-import-from-scan

Triage a security scanner's multi-finding output (read via a pluggable scan-format adapter) and turn findings into security work only after a complete operator-reviewed triage. Rea

security

spec-driven-w3-compliance

W3 compliance scanning with structural anti-skip enforcement. Detects auto-skill chaining violations (skills/commands that auto-invoke other skills without user approval) using the

general

think-in-code

Use ONE Bash script instead of N sequential Read calls when analyzing multiple files, auditing codebase, finding all matches, scanning dependencies, counting lines, or listing file

general

threat-feed

Daily threat-intel digest — AI-discovered vulnerabilities, AI-in-the-wild exploitation observations, AI-authored malware families, exploit-trends rollup, vendor-trends month-over-m

security

touchstone

The repository-evaluation lens: judge whether a repo is worth your time in a few minutes — by SCANNING its dashboards, not reading its code — scoring three axes: ALIVE, HEALTHY, an

general

triage

Convert raw scanner findings into atomic work items in the backlog. Assigns priority, category, effort, and identifies file conflicts.

general

ui-discover

Use when starting an epic's wireframe designs, scanning a frontend for UI components, cataloguing existing routes, or inventorying frontend state. Generates or refreshes the UI Dis

product

complexity-recognition

Diagnoses what makes code complex and why, using the three-symptom two-root-cause framework. Use when code feels harder to work with than it should but the specific problem is uncl

general

cso

Chief Security Officer mode. Infrastructure-first security audit: secrets archaeology, dependency supply chain, CI/CD pipeline security, LLM/AI security, skill supply cha — from Cl

security

index-repos

Use this skill when expanding a small set of candidate skills into the full breadth of what their host repos offer. Enumerates the full content of one or more GitHub repos that hos

tools

pka-librarian

ALWAYS use this skill when the user wants to process, route, OCR, index, or organize documents in their knowledge system. Triggers on: processing an inbox or team-inbox, routing dr

content

security-scanner

Run security scans including SAST, dependency scanning, and secret detection

security

setup-makefile

Generate a Makefile for a code directory by scanning scripts for output paths and building dependency rules.

tools

signal-pipeline

Technische Implementierung der Signal-Erkennung und Telegram-Zustellung. Nutze diesen Skill wenn du den Signal-Scanner einrichten, konfigurieren, starten oder debuggen wi — from st

general

planning-and-research

Deep web research, competitor scanning, technology evaluation, and implementation planning. Decomposes work into vertical slices, identifies parallel workstreams, tracks — from sci

science

112-java-maven-plugins

Use when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scan — from en

engineering

security-scanner

Security-Scanner Agent fuer fabrikIQ und andere Projekte. Fuehrt umfassende Sicherheitspruefungen durch. — from tools-only/X-Skills

security

301-frameworks-spring-boot-core

Use when you need to review, improve, or build Spring Boot 4.0.x applications — including proper usage of @SpringBootApplication, component annotations (@Controller, @Ser — from ja

engineering

a11y-audit

Accessibility audit skill for scanning, fixing, and verifying WCAG 2.2 Level A and AA compliance across React, Next.js, Vue, Angular, Svelte, and plain HTML codebases. Use when aud

product

a11y-test

Use when you need to run real accessibility tests — Playwright keyboard interactions, axe-core scanning, visual regression, and WCAG 2.2 compliance checks. The measurement layer th

product

Accessibility Tool Builder

Expert in building accessibility scanning tools, rule engines, document parsers, report generators, and audit automation. WCAG criterion mapping, severity scoring, CLI/GUI scanner

product

Academic Writer

Professional LaTeX writing assistant. Capabilities include: scanning existing LaTeX templates, reading reference materials (Word/Text), drafting content strictly following template

content

accessibility-test

Automated WCAG 2.1 AA accessibility testing with axe-core and Lighthouse CI. Auto-detects frontend framework (React, Next.js, Vue, Angular, Svelte, Astro, Flutter, React Native), d

product

accessorysetupkit

Discover and configure Bluetooth and Wi-Fi accessories using AccessorySetupKit. Use when presenting a privacy-preserving accessory picker, defining discovery descriptors for BLE or

general

add-camera

Internal implementation skill invoked by /add-native for camera, image picker, barcode scanner, QR scanner, and camera/gallery Dataverse artifact workflows.

general

add-private-function-with-signatures

Add private functions from game DLLs (server.dll/engine.dll) to metamod plugins using signature scanning and symbol lookup. Use when adding new private function hooks that require

general

adobe-ci-integration

Configure CI/CD pipelines for Adobe integrations with GitHub Actions, including OAuth credential injection, PDF Services testing, Firefly API smoke tests, and secret scanning for A

engineering

adobe-policy-guardrails

Implement Adobe-specific lint rules, CI policy checks, and runtime guardrails covering credential scanning (p8_ patterns), Firefly content policy pre-screening, PDF Services quota

tools

affaan-m--ecc

Harness-native operator system cho agentic work — skills, instincts, memory optimization, security scanning, cross-harness workflows. 205K stars.

security

blocker-supervisor-cataloger

Cross-project blocker scanner. Reads the user-managed project list, runs the upgraded triage prompt against each registered project (catalog mode), maintains the per-project `.dev/

general

agent-delegation

Orchestration workflow for delegating work to the configured custom agents (bug-finder, bulk-scanner, codebase-analysis, debugger, executor, planning-agent, researcher, verifier, v

security

agent-ready-cloudflare

Audit and improve website readiness for AI agents using the Cloudflare "Is It Agent Ready?" scanner (isitagentready.com). Covers scanning via API, interpreting results, generating

engineering

agent-security-scanner

Agentic security patterns for AI agent systems including attack vector defense, sandboxing, input sanitization, security scanning, CVE awareness, and least-privilege tool access. U

security

agent-skill-security

Security scanning for Agent Skills and MCP servers using Snyk agent-scan. Use when installing new skills, auditing existing skills, reviewing MCP server security, or when user says

security

agent-test

Run agent evaluation tests via `sf agent test run` against the target org's Testing Center. Produces severity-graded findings; CI mode emits SARIF for GitHub Code Scanning. Persist

engineering

agentic-security-scanner

Scan and validate AI agent skills against the OWASP Agentic Skills Top 10 (AST10) security framework. Detects malicious skills, prompt injection, data exfiltration, supply chain ri

security

agentshield-security-scanner

AI agent configuration security scanner — 102 rules across secrets, permissions, hooks, MCP servers, and agent definitions. Detects hardcoded secrets, permission misconfigurations,

security

ai-code-reviewer

WHEN: Deep AI-powered code analysis, multi-model code review, security scanning with Codex and Gemini WHAT: Comprehensive code review using external AI models with severity-based f

engineering

ai-innovation-radar

AI Innovation Radar — strategic AI innovation scanning and advising system. Auto-trigger on ANY of these cues: 'drop' or pasting Perplexity findings/article batches for evaluation,

content

ai-sdlc-change-impact

AI SDLC change-impact and lifecycle recovery workflow. Use when a requirement, acceptance criterion, decision, API contract, risk assumption, or other traced source changed after d

general

ai-security-scanner

AI Agent 安全检测工具。扫描 OpenClaw 等 AI Agent 的安全风险,包括 API Key 泄露、Skill 投毒、敏感信息泄露、配置风险等。当用户询问 AI 安全、Agent 安全、API Key 泄露、Skill 风险、安全扫描、安全审计时触发。

security

aig-scanner

A.I.G Scanner — AI security scanning for infrastructure, AI tools / skills, AI Agents, and LLM jailbreak evaluation via Tencent Zhuque Lab AI-Infra-Guard. Uses built-in exec + Pyth

security

alfworld-environment-scanner

Performs an initial scan of the Alfworld environment to identify all visible objects and receptacles. Processes raw observation text into a structured list of entities to build a m

general

algorand-vulnerability-scanner

Scans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations, and access control issues. Use when

security

alibaba-registry-artifact-governor

Govern Alibaba Cloud Container Registry (ACR) — Enterprise Edition vs Personal Edition selection, image vulnerability scanning, namespace IAM least privilege, image retention polic

security

alibaba-security-center-hardening

Harden Alibaba Cloud security posture via Security Center (threat detection, vulnerability scanning, baseline checks), WAF, Anti-DDoS Pro, Cloud Firewall, and Network Traffic Analy

security

ami-tech-debt-scanner

Analyzes the repository for technical debt, including outdated dependencies, dead code, duplication, and architectural inconsistencies. Provides a classified report based on critic

engineering

aminet-scanner

Multi-layer virus scanning for Aminet packages. Signature-based detection, heuristic hunk analysis, boot block scanning, quarantine management, and scan orchestration. Use when sca

general

analyzing-malicious-url-with-urlscan

URLScan.io is a free service for scanning and analyzing suspicious URLs. It captures screenshots, DOM content,

general

analyzing-network-flow-data-with-netflow

Parse NetFlow v9 and IPFIX records to detect volumetric anomalies, port scanning, data exfiltration, and C2 beaconing

general

android-ble-hardware

Android BLE hardware integration using the Nordic Semiconductor BLE library (no.nordicsemi.android:ble). Covers UART/GATT service discovery, callbackFlow-based device scanning, con

general

android-playstore-setup

Complete Play Store setup - orchestrates scanning, privacy policy, version management, Fastlane, and workflows (Internal track only)

general

aosp-connectivity

AOSP Part VIII — Connectivity. Use when reasoning about Networking (ConnectivityService, Wi-Fi framework, netd, DNS resolver, VPN, tethering, NetworkSecurityConfig, VCN — from aosp

security

aosp-part-connectivity

AOSP Part VIII — Connectivity. Use when reasoning about Networking (ConnectivityService, Wi-Fi framework, netd, DNS resolver, VPN, tethering, NetworkSecurityConfig, VCN — from aosp

security

apex-ia-scanner

Professional scanner for Binance Futures. SMA 8/21 crossovers. 🇺🇸 | Scanner profissional para Binance Futures. Cruzamentos SMA 8/21. 🇧🇷

general

api-contract-init

Generate API_CONTRACT.md by scanning existing routes and controllers

general

api-inventory-scanner

Discover and document existing API endpoints from code, logs, and traffic analysis

general

aptos-scanner

Use when the user wants to audit Aptos Move smart contracts, scan Aptos-specific patterns including global storage model, resource accounts, or coin modules, review Aptos DeFi prot

security

ara-research-manager

Records research provenance as a post-task epilogue, scanning conversation history at the end of a coding or research session to extract decisions, experiments, dead ends — from NI

science

archi-diagrams

Agent de conception qui génère des diagrammes Mermaid à partir de l'index d'architecture produit par archi-scanner. Génère sur demande (jamais tout d'un coup) : diagramme de classe

engineering

architecture-doc-auditor

Systematic completeness audit of Architecture Documentation using 188-item viewpoint-based checklist, severity-classified gap detection, technical debt indicators, and architecture

engineering

architecture-health-scanner

Interpret and triage architecture scanner output — cluster findings by module and root cause, classify true positives vs false positives vs acceptable design, and produce a priorit

engineering

ast-injection-scanner

Statically scan agent-generated JavaScript and shell scripts for dangerous patterns using AST analysis (acorn/swc). Detect eval(), process.env access, dynamic require(), child_proc

engineering

audit-models

Audit Popoto Redis models for relationship gaps, missing fields, naming inconsistencies, and architectural weaknesses. Use when reviewing data model health, checking model integrit

general

automatisierter-audit-axe-lighthouse

Ordnet automatisierte Accessibility-Scans mit axe, Lighthouse, Pa11y oder ähnlichen Tools ein. Erklärt Treffer, False Positives, False Negatives, manuelle Nachprüfung und Entwickle

product

awcms-codeql-triage

Triase dan perbaiki temuan CodeQL code scanning AWCMS (github.com/ahliweb/awcms/security/code-scanning). Gunakan saat diminta "analisis code scanning"/"perbaiki CodeQL", saat sebua

security

aws-cloudformation-task-ecs-deploy-gh

Deploy ECS tasks and services with GitHub Actions CI/CD. Use for building Docker images, pushing to ECR, updating ECS task definitions, deploying ECS services, integrating with Clo

engineering

aws-cloudwatch-log-anomaly-scanner

Scans AWS CloudWatch Logs using the CloudWatch Logs Insights API and CloudWatch Anomaly Detection API. Identifies unusual error patterns, latency spikes, and log volume anomalies a

engineering

aws-sdk-java-v2-dynamodb

Amazon DynamoDB patterns using AWS SDK for Java 2.x. Use when creating, querying, scanning, or performing CRUD operations on DynamoDB tables, working with indexes, batch operations

tools

aws-sdk-java-v2-dynamodb

Provides Amazon DynamoDB patterns using AWS SDK for Java 2.x. Use when creating, querying, scanning, or performing CRUD operations on DynamoDB tables, working with indexes, batch o

tools

axiom-vision

Use when implementing ANY computer vision feature — image analysis, pose detection, person segmentation, subject lifting, text recognition, barcode scanning.

general

axiom-vision-ref

Vision framework API, VNDetectHumanHandPoseRequest, VNDetectHumanBodyPoseRequest, person segmentation, face detection, VNImageRequestHandler, recognized points, joint lan — from ma

general

axiom-vision-diag

subject not detected, hand pose missing landmarks, low confidence observations, Vision performance, coordinate conversion, VisionKit errors, observation nil, text not recognized, b

general

axiom-vision-ref

Vision framework API, VNDetectHumanHandPoseRequest, VNDetectHumanBodyPoseRequest, person segmentation, face detection, VNImageRequestHandler, recognized points, joint lan — from ge

general

azure-resource-visualizer

Analyze Azure resource groups and generate detailed Mermaid architecture diagrams showing the relationships between individual resources. USE FOR: create architecture dia — from en

engineering

azure-resource-visualizer

Analyze Azure resource groups and generate detailed Mermaid architecture diagrams showing the relationships between individual resources. USE FOR: create architecture dia — from ma

engineering

azure-resource-visualizer

Analyze Azure resource groups and generate detailed Mermaid architecture diagrams showing the relationships between individual resources. USE FOR: create architecture dia — from ma

engineering

backlog-scan

Bulk backlog scanner that analyzes the entire finans codebase vs CLAUDE.md, identifies ALL gaps, and generates a comprehensive, prioritized, numbered task backlog. Uses broad→narro

general

financial-intel

Stock momentum scanner and portfolio intelligence. Look up any ticker for momentum scores, RSI, coil breakout patterns, and AI analysis. Scan top signals across 6,500+ stocks and c

security

battle-scanner

Competitive intelligence engine that deconstructs competitor positioning, surfaces exploitable weaknesses, and predicts competitive responses. Use when: competitive analysis, compe

security

bbot-recon

Automated reconnaissance using BBOT (Black Lantern Security's recursive internet scanner). Use when performing bug bounty recon, attack surface management, subdomain enumeration, w

security

bearer-cli-sast-code-security-privacy-scanner

Bearer CLI is an open-source static application security testing (SAST) tool that scans source code to identify, filter, and prioritize security vulnerabilities and privacy risks.

security

best-practice

Cross-cutting best practices enforcement across code, templates, skills, prompts, scripts, documentation, pages, and design. The enforcement layer that catches violations any speci

security

betterleaks-secrets-scanner

A fast, configurable secrets scanner built by the creator of Gitleaks and backed by Aikido Security. Betterleaks detects leaked passwords, API keys, and tokens in git repositories,

security

bicep-security-scanner

Scans Azure Bicep templates for security misconfigurations and compliance violations. Detects issues like public endpoints, missing encryption, overly permissive access, disabled l

security

bio-crispr-screens-base-editing-analysis

Analyzes base-editing screens for variant function. Covers library design (Sanson 2020 GRACE, Hanna 2021 BRCA1/2 SNV scanning, Cuella-Martin 2021), CBE vs ABE chemistry choice (BE3

science

bio-genome-engineering-grna-design

Designs and ranks guide RNAs (sgRNAs) for CRISPR-Cas9/Cas12a gene knockout by scanning a target for PAM sites (NGG SpCas9, NNGRRT SaCas9, TTTV Cas12a, NG SpCas9-NG, near-PAMless Sp

science

bizcard

Business card scanner + Google Contacts manager. Auto-detects business card images, extracts contact info via OCR (imageModel), confirms with user, saves to Google Contacts with co

general

blacklight

Behavioural intelligence layer for OpenClaw agents. Monitors live decisions, forces transparent financial reasoning before any purchase, detects SOUL identity drift, maps combinato

security

bmad-document-project

Document brownfield projects for AI context by scanning source code and generating comprehensive documentation. Detects project type, scans codebase at configurable depth (quick/de

general

brakeman

Static analysis security vulnerability scanner for Ruby on Rails applications. Use when analyzing Rails code for security issues, running security audits, reviewing code for vulner

security

brownfield-analyzer

Analyzes existing brownfield projects to map documentation to SpecWeave's structure (PRD/HLD/Spec/Runbook). Use when migrating existing projects to SpecWeave, scanning le — from pr

product

brownfield-analyzer

Analyzes existing brownfield projects to map documentation to SpecWeave's structure (PRD/HLD/Spec/Runbook). Use when migrating existing projects to SpecWeave, scanning le — from ma

product

browse

Discover trending topics and content ideas from social feeds for post creation. Use when scanning Twitter timeline or finding content inspiration.

general

building-devsecops-pipeline-with-gitlab-ci

Design and implement a comprehensive DevSecOps pipeline in GitLab CI/CD integrating SAST, DAST, container scanning,

security

building-vulnerability-dashboard-with-defectdojo

Deploy DefectDojo as a centralized vulnerability management dashboard with scanner integrations, deduplication,

security

building-vulnerability-scanning-workflow

Builds a structured vulnerability scanning workflow using tools like Nessus, Qualys, and OpenVAS to discover,

security

building-with-cloud-security

Use when implementing Kubernetes security patterns including RBAC, NetworkPolicies, Pod Security Standards, secrets management, image scanning with Trivy, Cosign signing, and Dapr

security

burp-suite-testing

Execute comprehensive web application security testing using Burp Suite's integrated toolset, including HTTP traffic interception and modification, request analysis and replay, aut

security

business-card-scanner

Extract contact information from business card images using OCR - name, company, email, phone, address.

general

cairo-vulnerability-scanner

Scans Cairo/StarkNet smart contracts for 6 critical vulnerabilities including felt252 arithmetic overflow, L1-L2 messaging issues, address conversion problems, and signature replay

security

myco:canopy-code-intelligence-development

Comprehensive procedures for building and extending Myco's Canopy code intelligence system. Covers agent harness task standardization, three-layer file exclusion models, context in

engineering

capability-radar

Produce a living map of what the intelligence system can do today vs. what's been surfaced to users. The gap between "possible" and "exposed" is the product opportunity space. Use

general

capture-linkedin-card

Capture a real LinkedIn search-result card from a live profile session, sanitize it, and add it as a regression fixture. Use when LinkedIn DOM drift broke a scanner (people-search,

general

cariddi-domain-crawler-endpoint-secret-scanner

Cariddi is a Go-based security tool that takes a list of domains, crawls their URLs, and scans for endpoints, secrets, API keys, file extensions, tokens, and errors. It supports co

security

castai-security-basics

Secure CAST AI API keys, RBAC configuration, and Kvisor security agent. Use when hardening CAST AI cluster access, configuring security scanning, or implementing API key rotation p

security

cdk-testing

Run CDK validation, security scanning, build, test, and deployment. Use when the user asks to test CDK code, validate CDK configurations, run CDK checks, or deploy CDK to a dev env

engineering

check-agent-compatibility

Run the full repository compatibility pass: scanner score, startup path, validation loop, and docs reliability.

general

checkov-iac-scanner

Checkov IaC Scanner is built around Kubernetes orchestration platform. The underlying ecosystem is represented by kubernetes/kubernetes (121,313+ GitHub stars). It gives an agent a

tools

checkov-infrastructure-policy-scanner

Scans IaC files with Bridgecrew Checkov for policy violations across Terraform, CloudFormation, Kubernetes, and Dockerfile configurations. Supports custom Python-based policy autho

engineering

checkpoint-from-receipt

Create checkpoints from receipt photos using QR scanning, e-Kasa API, and GPS extraction (10-40s) — from general/general-misc

general

checkpoint-from-receipt

Create checkpoints from receipt photos using QR scanning, e-Kasa API, and GPS extraction (10-40s) — from majiayu000/claude-skill-registry

general

checkup

Health check — verify dev-core config, GitHub project, labels, workflows, branch protection, secret scanning, CI hardening. Triggers: "checkup" | "health check" | "check setup" | "

security

ci-cd-pipeline-builder

Design and generate CI/CD pipelines from detected project stack signals. Covers GitHub Actions, GitLab CI, CircleCI, and Buildkite with caching, matrix builds, deployment strategie

engineering

ci-cd-reviewer

WHEN: CI/CD pipeline review, GitHub Actions, GitLab CI, Jenkins, build optimization WHAT: Pipeline structure + Job optimization + Security scanning + Caching strategy + Deployment

engineering

ci-doctor

Diagnose and fix CI/CD pipeline failures, test errors, GitHub Actions issues, and code scanning alerts.

engineering

cicd-integration

Generate CI/CD pipeline configurations that automate design system quality checks — token validation, component linting, visual regression, accessibility scanning, and release gati

engineering

cicd-review

Use when reviewing a CI/CD pipeline for build efficiency, test coverage, security scanning, deployment strategy, and rollback capability. Produces a structured audit with prioritiz

engineering

circleci-orb-dependency-auditor-4

Audits CircleCI orb dependencies using the CircleCI v2 API and orb registry. Detects outdated orb versions, deprecated commands, and known CVEs in orb executor images via Trivy sca

engineering

circleci-orb-dependency-scanner-4

Scans CircleCI config.yml for outdated orb versions using the CircleCI Orbs Registry API. Reports CVEs linked to orb dependencies via Snyk vulnerability database lookups.

engineering

claude-md-starter

Generates a fully structured, project-specific CLAUDE.md by scanning the repo for signal files (package.json, Makefile, .github/workflows/, .env.example, etc.), inferring stack, co

engineering

clawdefender

Security scanner and input sanitizer for AI agents. Detects prompt injection, command injection, SSRF, credential exfiltration, and path traversal attacks. Use when (1) installing

security

clawsec-scanner

Automated vulnerability scanner for agent platforms. Performs dependency scanning (npm audit, pip-audit), multi-database CVE lookup (OSV, NVD, GitHub Advisory), SAST analysis (Semg

security

ClawSentinel

Pure local 2026 ClawHub/OpenClaw skill scanner. Detects ClawHavoc malware, MCP backdoors, obfuscated payloads, and supply-chain attacks. 100% read-only analysis.

security

cloud-recon

Cloud asset discovery — AWS, Azure, GCP enumeration, S3/Blob/GCS bucket scanning, cloud configuration analysis, and SaaS footprinting. Use when the user wants to enumerate cloud re

security

cm-secret-shield

Defense-in-depth security for AI-assisted development. Pre-commit secret scanning (Gitleaks + native fallback), repo-wide pattern detection, token lifecycle management, and AI agen

security

cm-security-gate

Pre-production security audit and vulnerability scanning. Run Snyk + Aikido dependency scans, OWASP analysis, and set up automated GitHub security checks with Jules. Use when asked

security

cobuilder-heartbeat

Behavioral specification for the CoBuilder Heartbeat teammate. Loaded as prompt when spawning the Haiku work-finder agent within the session-scoped cobuilder-live-{hash} team. Defi

general

code-exemplars-blueprint-generator

Technology-agnostic prompt generator that creates customizable AI prompts for scanning codebases and identifying high-quality code exemplars. Supports multiple programming language

tools

code-hardcode-audit

Detect hardcoded values, magic numbers, and leaked secrets. TRIGGERS - hardcode audit, magic numbers, PLR2004, secret scanning.

general

code-review-security

Security-focused code review for OpenSite/Toastability platform. Use when reviewing PRs for security issues, auditing new API endpoints, checking for HIPAA/SOC2 compliance violatio

security

code-reviewer

Comprehensive code review skill for TypeScript, JavaScript, Python, Swift, Kotlin, Go. Includes automated code analysis, best practice checking, security scanning, and re — from Al

engineering

code-reviewer

Comprehensive code review skill for TypeScript, JavaScript, Python, Swift, Kotlin, Go. Includes automated code analysis, best practice checking, security scanning, and re — from bg

engineering

code-reviewer

Automated code review with security scanning, quality metrics, and best practices analysis. Use when reviewing code for: (1) Security vulnerabilities and common attack vectors, (2)

engineering

code-reviewer

Comprehensive code review skill for TypeScript, JavaScript, Python, Swift, Kotlin, Go. Includes automated code analysis, best practice checking, security scanning, and re — from bg

engineering

code-reviewer-pro

Review code with security scanning, complexity analysis, and auto docs. Use when auditing codebases, suggesting refactors, or enforcing standards.

engineering

code-security-audit

Comprehensive code security audit toolkit combining OWASP Top 10 vulnerability scanning, dependency analysis, secret detection, SSL/TLS verification, AI Agent security checks, and

security

codebase-cleanup-deps-audit

You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnera — from Ah

security

coderabbit-inheritance-scanner-check

Use when checking a repository's .coderabbit.yaml (or .coderabbit.yml) to determine whether inheritance: true is set

general

coderabbit-security-basics

Configure CodeRabbit for security-focused code review with secret detection and vulnerability scanning. Use when setting up security review rules, configuring secret detection in P

security

tokf-discover

Find missed token savings by scanning AI coding session files for commands that ran without tokf filtering.

general

vmware-monitor

VMware vCenter/ESXi read-only monitoring. Code-level enforced safety — no destructive operations exist in this codebase. Use when monitoring VMware infrastructure via nat — from Da

general

codifying-disciplines

Scans a repo for disciplines that exist only in prose, convention, or agent memory but are NOT enforced by executable code, then codifies each into the right surface — a script, a

general

coding-mastery

Use when writing security tooling, exploits, scanners, or C2 in Python/C/Go/Rust/ASM — systems & network programming, automation, cryptography implementation

security

common-law-false-friends-scanner

Findet missverständliche deutsch-englische Rechtsbegriffe und schlägt sichere Formulierungen für Verträge und Memos vor.

general

company-intel

Deep research on any company by scanning their public website to extract customers, partners, case studies, testimonials, key metrics, and competitive positioning. Produces a polis

science

competitor-monitor

Use when the user wants to set up ongoing competitor monitoring — define competitors to track, configure scanning frequency, enable change detection alerts, and establish competiti

general

compose-gen

Generate docker-compose.yml by scanning your project. Use when containerizing an existing app.

engineering