安全
安全扫描与漏洞检测
seo-audit
prabha-oss
When the user wants to run an SEO audit, site audit, technical SEO check, or SEO analysis on a website. Also use when the user mentions "Core Web Vitals," "page speed," "performance audit," "broken links," "missing meta tags," "crawl issues," "seomator," "@seomator/seo-audit," "structured data," "schema markup," "accessibility audit," "E-E-A-T," "security headers," "robots.txt," or "sitemap audit." For creating SEO pages at scale, see programmatic-seo. For optimizing content, see seo-optimizing.
content-security-policy-headers
curiositech
'Use when designing or fixing a Content Security Policy on a real site, choosing between nonce-based and hash-based CSP, adding strict-dynamic, debugging "Refused to execute inline script" errors, deploying CSP in report-only mode first, configuring report-to / report-uri, or auditing an existing policy for unsafe-inline / unsafe-eval / wildcards. Triggers: "CSP blocks legitimate inline script", strict-dynamic, nonce-{RANDOM}, sha256-{HASH}, object-src none, base-uri none, frame-ancestors, Trusted Types, X-Content-Security-Policy obsolete, report-only vs enforced. NOT for general HTTP security headers (HSTS, COOP/COEP), Trusted Types deep dive, CORS configuration, or building a WAF.'
technical-writing-styleguide
artivilla
Technical writing styleguide for clear, consistent documentation. Use when writing, editing, or reviewing technical content, guides, tutorials, or documentation. Triggers on article review, writing style, brand names, grammar check, screenshot guidelines, guide audit, technical docs.
codeless-security-check
sunu-py-jp
"Security audit for Claude Code skills (.skill packages) and MCP servers. Detect malicious code, data exfiltration, prompt injection, and excessive permissions before installation. Use when the user asks to check security, audit this skill/MCP, is this safe to install, review for vulnerabilities, セキュリティチェック, 安全性を確認, or any request to evaluate the safety of a skill or MCP server before use. Also trigger when user mentions installing a skill, adding an MCP server, or shares a .skill file or MCP repository for review."
flutter-app-builder
nodelabstudio
Complete Flutter mobile app development from initial setup through App Store deployment. Use when building Flutter apps, adding features (authentication, databases, APIs), implementing security, or preparing apps for production release. Includes project templates, architecture patterns, and deployment guidance.
threat-modeling
Hack23
Conduct systematic threat modeling using STRIDE framework, attack trees, and security architecture analysis for CIA platform
writing-meeting-notes
danbars
Use when a meeting just occurred and notes need to be turned into a clear summary with decisions, action items, owners, and dates.
Audit Specialist
Alpizar28
Especialista senior en auditoría de sistemas transaccionales y consistencia de dominio, con enfoque en sistemas críticos y reservas.
code-reviews
TechLuddite
Audit public repos for security first, then feasibility, correctness, maintainability, and byte waste. Check open and closed issues before filing. One issue per problem. Sign every review. Use when the user says review this, let's do a code review, a repo review, help on a public repo, or let's look at a repo together.
secure-development-lifecycle
Hack23
Secure SDLC phases, security requirements, secure coding practices, and security testing integration for the CIA platform
guardrailx-scan
k-kaundal
Provide secure coding guidance to prevent secrets, credentials, sensitive configuration, and PII exposure without inspecting or reproducing repository content.
stackswap-gtm
StonesofCreation
B2B GTM/SaaS stack intelligence using the StackSwap MCP server. Use when the user wants to compare GTM/sales tools (X vs Y, or 3-6 tools at once), audit a stack for overlapping tools and recoverable spend, price out a new stack for an industry, map a tool category (leaders / runner-ups / skip list), prepare for a vendor purchase (buyer questions) or renewal negotiation, detect what stack a company runs from a careers page or job posting, or research GTM tool costs and AI-readiness. Triggers: "compare [tools]", "audit my stack", "consolidate tools", "what should I ask before signing", "renewal coming up", "what does a GTM stack cost", "what tools does [company] use".
audit-code-health
kyzooghost
Scans codebases for security vulnerabilities, bugs, and code health issues. Creates structured work items for remediation. Triggers on "audit", "code review", "security scan", "find bugs", "tech debt", or "assess code quality".
solidity-adversarial-analysis
whackur
Adversarial scenario analysis and threat modeling for Solidity smart contracts. Use when analyzing contracts from an attacker's perspective, identifying multi-step attack vectors, or performing threat modeling. Covers flash loan attacks, oracle manipulation, MEV/front-running, governance exploits, reentrancy scenarios, access control bypasses, economic logic exploits, and cross-contract composability risks. Triggers on tasks involving adversarial analysis, threat modeling, attack scenarios, attack vectors, exploit analysis, or red team review.
prepare-security-prs
Soyio-id
"Triage and prepare automated dependency security PRs for merge with minimal risk. Identify bot PRs that need intervention, resolve required issues only, refresh stale branches safely, detect superseded PRs, and keep diffs dependency-focused."
skills-audit
shieldon-dev
Security scanner for AI agent skills. Audits skill files for credential theft, data exfiltration, dangerous commands, and obfuscation before installation. Use before installing any new skill to get a structured risk report with score (0-100), severity level, and actionable findings. Runs locally with zero external dependencies — nothing is sent over the network.
pharos-flashloan-detector
ruzkypazzy
AI Agent skill for detecting flash loan attack patterns on Pharos blockchain
qms-audit-expert
nimeshgurung
Senior QMS Audit Expert for internal and external quality management system auditing. Provides ISO 13485 audit expertise, audit program management, nonconformity identification, and corrective action verification. Use for internal audit planning, external audit preparation, audit execution, and audit follow-up activities.
electron-dev
fanthus
Build cross-platform desktop applications with Electron using best practices for security, performance, and user experience. Use this skill when developing system tools (file managers, screenshot tools, productivity apps) or when working with Electron projects. Triggers include requests to create Electron apps, implement file operations, system tray functionality, window management, IPC communication, or optimize Electron performance. Supports vanilla JavaScript, React, and Vue frameworks with comprehensive code templates that embed security and performance best practices directly in comments.
rafter-code-review
Raftersecurity
"REQUIRED before declaring a task done when the diff touches user input, SQL, shell, auth, credentials, file paths, serialization, crypto, network endpoints, data deletion, or dependency surface. Judge by that surface, not the task label — research/experimental/local-only code with none of it can skip this. Walks OWASP/ASVS/MITRE questions the compiler and the test suite won't catch. Pair with rafter run on the same diff. When the diff has that surface, marking it complete without both has been under-delivered — do not claim done."
ogt-docs-audit-task
OpenDNDApps
Audit tasks in docs/todo/done/ to verify claimed implementations actually exist in the codebase. Use when reviewing completed tasks, validating work before release, or periodically auditing task accuracy. Moves unverified tasks back to pending/.
klausel-mindestlizenzen-meldungen-audit
Klotzkette
"Für Klausel Mindestlizenzen, Meldungen, Audit: ordnet Norm, Beweislast und Gegenargument; Ergebnis: Prüfprodukt mit Risiko und nächstem Schritt."
maui-authentication
Rimblehelm
A brief description of what this skill does
analyze-deps
nexuslabs-ai
Analyze dependencies for updates, breaking changes, deprecations, and migration paths. Generates actionable reports with codebase impact assessment.