安全
安全扫描与漏洞检测
dependency-audit
manastalukdar
Comprehensive dependency security and license audit
backend-principle-eng-java-pro-max
PrakharMNNIT
"Principal backend engineering intelligence for Java services and distributed systems. Actions: plan, design, build, implement, review, fix, optimize, refactor, debug, secure, scale backend code and architectures. Focus: correctness, reliability, performance, security, observability, scalability, operability, cost."
compliance-officer
famaoai-creator
status: implemented
learn-from-real-code
ricardogomes
Teaches learners to extract transferable design lessons from real-world codebases through critical evaluation and systematic exploration. Use when a learner wants to study existing code to learn patterns, architecture, or design decisions—not just understand what it does. Guides through navigation, pattern recognition, critical evaluation (deliberate choice vs. compromise), and lesson extraction. Triggers on phrases like "learn from this codebase", "study how X is implemented", "understand design patterns in Y", or when a learner wants to improve by reading real code.
synthesize
corygabrielsen
Consolidate brainstorm rounds into an organized synthesis. Themes emerge, winners surface, evolution becomes visible.
Security Validation
auldsyababua
Pre-merge security validation detecting secrets, user-specific paths, insecure SSH configurations, and security-weakening flags
creating-sales-enablement
amogha-dalvi
Use when sales reps lack deal-stage-specific content, when the founder's sales knowledge lives in their head instead of a system, when win rates are declining or sales cycles are lengthening, when no buying group content map exists, or when reps spend significant time creating content that should already exist. Use when sales and marketing lack shared definitions and feedback loops.
typescript-code-review
Exploration-labs
Perform comprehensive code reviews for TypeScript projects, analyzing type safety, best practices, performance, security, and code quality with actionable feedback
threat-modeling
spjoshis
Master threat modeling with STRIDE, attack trees, risk assessment, and identifying security threats in systems and applications.
skill-security-analyzer
auldsyababua
Comprehensive security risk analysis for Claude skills. Use when asked to analyze security risks, review security stance, audit skills for vulnerabilities, check security before deployment, or evaluate safety of skill files. Triggers include "analyze security," "security risks," "security audit," "security review," "is this skill safe," or "check for vulnerabilities."
security-documentation
spjoshis
Master security documentation with security policies, incident response plans, security procedures, and compliance documentation.
production
pluginagentmarketplace
Unit testing, performance optimization, security implementation, Play Store deployment.
secrets-guardian
timequity
Protect repositories from accidental secret commits. Essential when working with AI agents. Use when: setting up new project, adding pre-commit hooks, scanning for secrets, fixing leaked credentials. Triggers: "настрой защиту секретов", "setup secrets", "check secrets", "scan secrets", "проверь секреты", "pre-commit", "gitleaks". PROACTIVELY suggest when creating new projects or when .pre-commit-config.yaml is missing.
developing-brand-strategy
amogha-dalvi
Use when the user needs to build a strategic brand narrative, define thought leadership positioning, codify brand voice, or plan community and earned media presence. Use when brand is accidental rather than intentional, messaging could belong to any competitor, or AI search engines are shaping brand perception without input.
security-hardening-checklist
hopeoverture
This skill should be used when the user requests to audit, check, or improve application security by analyzing security headers, cookie configuration, RLS policies, input sanitization, rate limiting, and other security measures. It generates a comprehensive security audit report with actionable recommendations. Trigger terms include security audit, security check, harden security, security review, vulnerability check, security headers, secure cookies, input validation, rate limiting, security best practices.
security-validation
auldsyababua
Pre-merge security validation detecting secrets, user-specific paths, insecure SSH configurations, and security-weakening flags. Use before committing code/documentation, before creating PRs, or during QA validation. Supports automated scanning with severity-based enforcement (CRITICAL blocks merge, HIGH requires fixes).
reducing-cac
amogha-dalvi
Use when customer acquisition cost is rising, channel-level CAC is unknown, LTV to CAC ratio is below 3 to 1, or paid spend is growing without proportional pipeline growth. Use when founders feel marketing is not working, when budget needs reallocation, or when organic channels are underinvested relative to paid.
brand-analyzer
auldsyababua
This skill should be used when the user requests brand analysis, brand guidelines creation, brand audits, or establishing brand identity and consistency standards. It provides comprehensive frameworks for analyzing brand elements and creating actionable brand guidelines based on requirements.
security-assessment
spjoshis
Master security assessments with vulnerability scanning, penetration testing, security testing, and security audits.
spring-boot-full-stack
mduongvandinh
Complete Java Spring Boot skill set for building enterprise applications. Includes modular architecture with optional components: - PostgreSQL database with JPA/Hibernate + Flyway migration - Redis caching (optional) - Kafka/RabbitMQ messaging (optional, choose one) - JWT + OAuth2 authentication (optional OAuth2) - RBAC authorization (optional) - TDD with Mockito - Spec-First Development with OpenSpec
soc2-compliance
peixotorms
Use when building SaaS platforms, cloud services, customer-facing APIs, multi-tenant systems, or any service handling customer data that requires SOC 2 certification — Trust Services Criteria, TSC, CC1 through CC9, Type I, Type II, AICPA, security, availability, processing integrity, confidentiality, privacy, evidence collection, vendor management, penetration testing, risk assessment, access review, change management, incident response
Security Check Skill
hitoshura25
Consider additional security reviews for sensitive changes
solidity-security-audit
mariano-aguero
Comprehensive Solidity smart contract security auditing and vulnerability analysis skill. Based on methodologies from Trail of Bits, OpenZeppelin, Consensys Diligence, Sherlock, CertiK, Cyfrin, Spearbit, Halborn, and other leading Web3 security firms. This skill should be used whenever the user asks to "audit a smart contract", "review Solidity code for security", "find vulnerabilities", "check for reentrancy", "analyze gas optimization", "review access control", "check proxy patterns", "analyze DeFi protocol security", "review ERC20/ERC721 implementation", "check oracle manipulation risks", "review upgrade patterns", or mentions any security review of EVM-compatible smart contracts. Also triggers for keywords like "slither", "echidna", "foundry fuzz", "formal verification", "invariant testing", "flash loan attack", "MEV", "sandwich attack", "front-running", "delegatecall", "selfdestruct", "reentrancy guard", "access control vulnerability", "storage collision", "proxy upgrade security", "smart contract exploit", "L2 security", "cross-chain", "bridge security", "sequencer", "LayerZero", "CCIP", "account abstraction", "ERC-4337", "smart account", "paymaster", "bundler", "UserOperation", "re-audit", "diff audit", "remediation review", "fix verification", "Uniswap v4 hooks", "Chainlink integration", "Aave integration", "flash loan receiver", "ERC-4626 vault", "restaking", "EigenLayer", "severity classification", "severity decision". Even if the user simply pastes Solidity code and asks "is this safe?" or "any issues here?", use this skill.
security-hardening
1Mangesh1
Security hardening and secure coding practices. Use when user asks to "harden security", "secure coding", "OWASP vulnerabilities", "input validation", "sanitization", "SQL injection prevention", "XSS protection", "CORS security", "secure headers", "vulnerability scanning", or mentions security best practices and threat mitigation.