Parcourir le registre
Toutes les entrées, par ordre alphabétique — 56 437 au total. Page 190 sur 226.
- sd0xdev-create-prCreate or update GitHub PR with gh CLI. Auto-extracts ticket ID from branch name, generates title/summary from
- sd0xdev-debugInteractive debugging workflow with hypothesis-driven probe loop. Use when: unknown bugs, script errors, silen
- sd0xdev-deep-researchUniversal multi-source research orchestration. Use for any research/investigate/analyze request needing synthe
- sd0xdev-pr-reviewPR self-review — review changes, produce checklist, update rules
- sd0xdev-refactorMulti-target refactoring orchestrator. Use when: cleaning up messy code/docs, simplifying code, restructuring
- sd0xdev-security-reviewSecurity review via Codex MCP. Use when: OWASP Top 10 audit, dependency vulnerability check, security-sensitiv
- sd0xdev-update-docsResearch current code state then update corresponding docs, ensuring docs stay in sync with code.
- sd0xdev-verifyVerification loop — lint -> typecheck -> unit -> integration -> e2e
- sddInvoke AFTER plan+ is approved, as an alternative to tdd+ for plans with independent tasks. Wraps superpowers:
- sdd-execExplicit command-style skill for implementing approved SDD tasks from tasks.md with tight scope, tests, and ve
- sdd-ideaConversational SDD skill for exploring raw product or feature ideas before planning. Use when the user wants t
- sdd-initExplicit command-style skill for initializing or adopting SDD in a project by creating or preparing .ai/, .ai/
- sdd-pipelineA single hub to find Claude Skills, Agents, Commands, Hooks, Plugins, and Marketplace collections to extend Cl
- sdd-planCognitive SDD skill for creating or updating optional PLAN.md from captured ideas or project goals. Use when t
- sdd-prdCore cognitive SDD skill for creating or updating requirements.md from an approved idea, plan, or feature requ
- sdd-reviewCognitive SDD skill for reviewing an implementation against requirements.md, design.md, and tasks.md, producin
- sdd-riperSDD-RIPER workflow executor with phase gating
- sdd-specCore cognitive SDD skill for creating design.md technical specifications from approved requirements. Use when
- sdd-statusExplicit command-style skill for inspecting .ai/sdd state and recommending the next safe action. Use only when
- sdd-steeringCreates or updates reusable project steering documents in .ai/steering for product context, tech stack, conven
- sdd-tasksCore cognitive SDD skill for decomposing an approved design.md into practical tasks.md. Use when the conversat
- sddesignFull spec-driven pipeline — walks brief → tokens → shape (spec) → craft (build) → converge → ship in one guide
- sddp-initInitialize SDD project governance (project instructions and configuration)
- sdeYou MUST use this for hands-on coding tasks - writing features, fixing bugs, implementing APIs, debugging issu
- sdet-engineerSDET engineering reasoning — test automation framework design, page object model, screen play pattern, contrac
- sdkUse when building a React, React Native, or Expo app on the Agora SDK (@agora-sdk/core, @agora-sdk/react-js, @
- sdk-adoption-trackerGiven your SDK or library name, searches GitHub code search for public repos that import or require it, classi
- sdk-getting-startedValidates the user's environment for SageMaker AI operations — checks SDK version, AWS region, and execution r
- sdk-quickstart-writerGenerates a concise, copy-paste-ready quickstart guide for any SDK or library.
- sdk-version-detectorReads pom.xml, detects which Alfresco SDK is in use (In-Process Maven SDK or Out-of-Process Spring Boot SDK),
- sdlc-audit-consistencyPerforms consistency and traceability audits across documents (PRD vs Spec vs Plan) to detect missing coverage
- sdlc-bug-reportWorkflow for analyzing bug reports, tracing root causes, and generating structured bug-fix implementation plan
- sdlc-clarify-reqsHelps interrogate Product Requirements (PRD), Technical Specifications, and Implementation Plans to find ambig
- sdlc-code-reviewLanguage-agnostic workflow for code reviews and security audits using a Two-Axis (Standards vs Spec) approach
- sdlc-define-specsGenerates or updates highly detailed, machine-readable technical specification documents in the /spec/ directo
- sdlc-draft-prdWorkflow to generate a comprehensive Product Requirements Document (PRD) detailing user stories, acceptance cr
- sdlc-explore-ideasSystematic codebase exploration, architectural critique, and generation of Project Discovery Drafts for SDLC P
- sdlc-generate-docsWorkflow for auditing, designing, and writing structured documentation based on the Diátaxis Framework (Tutori
- sdlc-impl-planningCreate an ordered implementation plan for a TriStar feature. Builds file dependency graph, maps acceptance cri
- sdlc-initInitializes the Awesome Copilot ID SDLC architecture, AGENTS.md, and rules in the current project.
- sdlc-map-architectureScans, analyzes, and documents the existing repository architecture, directories, and file purposes into docs/
- sdlc-orchestratorCoordinator playbook for the universal 10-phase SDLC pipeline. Hub-and-spoke routing, lanes (full/fast/short),
- sdlc-plan-tasksGenerates formal, structured, and executable implementation plan documents based on specifications.
- sdlc-planningUse when creating implementation plans, breaking down tasks, sequencing changes, planning TDD cycles, or creat
- sdlc-write-codePhase 6: Coding & Execution. God-Tier Autonomous Engineer implementing code strictly based on approved /spec/
- sds-gel-reviewReview SDS-PAGE or protein purification gel images using DNA sequence, protein sequence, base-pair length, exp
- se.likarika/budgetManage shared household finances for two people - expenses, budgets, savings, and settlements.
- se.nordsynk/fortnoxHosted MCP server for Fortnox. Connect Claude, ChatGPT, Cursor to live Fortnox via OAuth.
- se.shopfront/locationsSweden-based, EU-sovereign agentic Google Business Profile SaaS. Frankfurt, Stockholm, AI Pact.
- se.statistikdata/serverSwedish open data for Claude and other AI assistants - verified, with sources.
- seabornSeaborn statistical data visualization. Use for statistical plots.
- seaborn-statistical-plotsStatistical visualization on matplotlib with native pandas support. Auto aggregation, CIs, grouping for distri
- seaborn-statistical-visualizationStatistical visualization on matplotlib + pandas. Distributions (histplot, kdeplot, violin, box), relational (
- seal-access-controlIntegrate Seal threshold encryption and access control on Sui. Use when the user mentions Seal.
- sealos-app-builderBuild, adapt, and document apps that run inside Sealos Desktop using the Sealos app SDK. Use when creating a n
- sealos-canvasRun a local read-only HTML topology UI for a project already deployed by Sealos Skills and return a localhost
- sealos-databaseProvision, connect, and operate Sealos Cloud databases through sealos-cli for local development, Devbox develo
- sealos-deployDeploy compatible server, static-web, worker, scheduled-job, or reviewed remote-desktop workloads from GitHub
- sealos-s3Provision, connect, and operate Sealos object storage through the sealos-cli s3 commands added in zjy365/sealo
- seangsisg-docsSearch and access Anthropic documentation covering Claude Code CLI, API, Agent SDK, and more. Supports natural
- seangsisg-researchBuild a structured research outline (items + field definitions) on a topic, mixing model knowledge with a sing
- searchOn-demand retrieval from KNOWLEDGE and CAPABILITIES memory files via ripgrep search with ranked results.
- search-ad-copy-generatorGenerates search ad copy variants (headline + description) for a given product and keyword. Produces three qua
- search-and-optimizationReference patterns for search, optimization, and greedy algorithms. Covers binary search (classic and on-answe
- search-before-buildingUse when about to add a new helper, utility, or abstraction, a task sounds like a solved problem, a new extern
- search-campaign-auditGoogle Ads Search campaign audit — match types, quality score, negative keyword gaps, search terms, ad strengt
- search-companiesSearches for and retrieves company records from the Carta CRM. Use this skill when the user says things like "
- search-consoleQuery and operate connected Google Search Console properties through NotFair MCP. Use for live GSC query or pa
- search-console-indexing-auditAnalyze Google Search Console Coverage or indexing CSV exports and correlate them with repo and live-site SEO
- search-contactsSearches for and retrieves contact (people) records from the Carta CRM. Use this skill when the user says thin
- search-dealsSearches for and retrieves deal records from the Carta CRM. Use this skill when the user says things like "fin
- search-encodeSearch and explore ENCODE Project genomics data. Use when the user wants to find experiments, files, or explor
- search-expertAdvanced research skills using Z.AI Web Search Prime to synthesize technical information.
- search-fastpathUse when target files are unknown, repeated search is becoming expensive, an agent is about to do broad repo-w
- search-firstProduct management skills for Claude Code. 8 plugins, 35 skills, one-line install. Customer discovery that ver
- search-fundraisingsSearches for and retrieves fundraising records from the Carta CRM. Use this skill when the user says things li
- search-hierarchySearch Tool Hierarchy
- search-hono-docsSearches Hono documentation to find information about its features, APIs, and usage.
- search-integration当系统提示词需要定义 AI 模型何时搜索、如何搜索、搜索哪些数据源、以及如何处理搜索结果时调用此 Skill。适用于所有涉及实时知识检索的 AI 产品设计——聊天机器人、研究助手、企业知识库问答等。不适用于:纯离线场景(
- search-investorsSearches for and retrieves investor records from the Carta CRM. Use this skill when the user says things like
- search-jira-issuesUse this skill whenever the user wants to search, list, or filter Jira tickets — by assignee, status, label, p
- search-linear-issuesUse this skill whenever the user wants to search, list, or filter Linear issues — by state, assignee, label, o
- search-litLiterature search and citation management for medical research. Searches PubMed, Semantic Scholar, and bioRxiv
- search-notesSearches for and retrieves note records from the Carta CRM. Use this skill when the user says things like "fin
- search-page-auditRun a 38-point SEO + AI optimization audit on any URL. Evaluates SEO fundamentals, content structure, AI/GEO r
- search-paperFind papers, download PDFs, traverse citation graphs, and resolve publication venues across arXiv, IACR ePrint
- search-skillsSearch installed skills by name and show their installed path
- search-speciesUSE WHEN requesting core chemical structural data (SMILES, formula, mass, 2D images) via IUPAC, common, or mul
- search-stacSearch and download satellite imagery from Microsoft Planetary Computer. Browse available collections, search
- search-term-minerUse when the user asks to "mine my search terms", "find new keywords from converting queries", "build a negati
- search-tipsThis skill should be used when performing web research beyond a simple single search -- looking into topics, c
- search-toolsSearch Tool Hierarchy
- search-triageMulti-round search with keyword variants on social platforms. Browse results, open promising items, check enga
- search-uxDesign search — query input, zero results, refinement, and result presentation. Use when users retrieve rather
- search-vector-architectUse when designing full-text search (Elasticsearch), vector search (Pinecone, Weaviate), RAG pipelines, or hyb
- searchfit-seo-auditRun a comprehensive SEO audit on a website or codebase. Use when the user asks to "audit SEO", "check my site'
- searching-codebasesBinding-resolved Python symbol queries — find all true callers (--refs), go-to-definition (--def), or inferred
- searching-ubuntu-packagesProvide guidelines on how to search the proper Ubuntu package name for a given Ubuntu release. Should be used
- searxngUse when the user wants privacy-respecting web, image, news, or video search through a configured local SearXN
- searxng-searchSearch the internet and news using a local SearXNG instance. Use when the user wants to search the web, find c
- searxng-websearchUse this skill whenever the user wants to search the web, do research on a topic, fetch a webpage, or gather i
- season-wordsUse when a haiku needs a seasonal reference (kigo). Lists season words to weave in.
- seasonal-ads-calendarSeasonal Ads Calendar — Skill especializada para seasonal ads calendar
- seasonal-and-moment-marketingThe annual moment-planning skill -- map the few seasonal/cultural/commercial moments that genuinely fit your b
- seasonal-patternsDetect seasonal revenue and expense patterns across 12+ months of data.
- seat-continuity-and-handoverUse when replacing a seat's occupant (rebuild/handover/swap), reasoning about stable-seat-identity vs fluid-oc
- seatmap-displaySeatmap Display API skill. Use when working with Seatmap Display for shopping. Covers 2 endpoints.
- seatmapsAircraft seat maps, cabin dimensions, and seat recommendations via SeatMaps.com and AeroLOPA. Search by flight
- seats-aeroSearch award flight availability across 27 mileage programs via Seats.aero Partner API. Find cheapest award fl
- seaworld008-agent-browserUse when an agent needs real browser automation for semantic element targeting, form interaction, screenshots,
- seaworld008-algorithmic-artCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this wh
- seaworld008-brainstormingUse before creative product or engineering work when the user wants to design a feature, component, workflow,
- seaworld008-brand-guidelinesApplies Anthropic''s official brand colors and typography to any sort of artifact that may benefit from having
- seaworld008-canvas-designCreate beautiful visual art in .png and .pdf documents using design philosophy. You should use this skill when
- seaworld008-code-simplificationSimplifies code for clarity. Use when refactoring code for clarity without changing behavior. Use when code wo
- seaworld008-deep-researchGenerate format-controlled research reports with evidence tracking, citations, and iterative review. This skil
- seaworld008-dependency-auditor> Skill Type: POWERFUL > Category: Engineering > Domain: Dependency Management & Security.
- seaworld008-docxUse this skill whenever the user wants to create, read, edit, or manipulate Word documents (.docx files). Trig
- seaworld008-frontend-designCreate distinctive, production-grade frontend interfaces with high design quality. Use this skill when the use
- seaworld008-frontend-ui-engineeringBuilds production-quality, accessible, responsive user-facing UIs. Use when building or modifying interfaces a
- seaworthyThe build-it lens for a frontend feature, with one inverted discipline: the happy path is ~40% done, not 90%,
- seb1n-code-reviewPerform thorough code reviews on files or pull requests, checking for bugs, security vulnerabilities, performa
- seb1n-copywritingWrite compelling, persuasive marketing and sales copy using proven frameworks like AIDA, PAS, BAB, and 4Ps, wi
- seb1n-database-migrationCreate, execute, and roll back versioned database schema migrations using tools like Alembic, Prisma Migrate,
- seb1n-debuggingSystematically diagnose and fix software bugs by analyzing error messages, stack traces, logs, and runtime beh
- seb1n-deep-researchConduct in-depth, multi-step research on a given topic by decomposing queries, finding diverse sources, cross-
- seb1n-frontend-designDesign and build production-ready frontend interfaces with design systems, responsive layouts, accessible comp
- seb1n-note-takingCapture, organize, and retrieve notes efficiently using structured formats, tagging, and file management for m
- seb1n-refactoringImprove code quality and maintainability through systematic identification of code smells and application of p
- seb1n-security-auditPerform a broad, authorized security audit across application, infrastructure, identity, dependencies, and ope
- seb1n-testingGenerate, execute, and analyze tests for codebases, covering unit, integration, and end-to-end testing with co
- sebastianelvis-critiqueProvide critique on investigation results via human feedback, Codex consultation, or self-review. Can trigger
- sebastianelvis-investigateRun investigation cycles that test hypotheses through proof verification, counterexample search, or security a
- secSecurity Engineer for authentication, authorization, secrets, trust boundaries, unsafe inputs, data exposure,
- sec-edgarUS SEC EDGAR filings — list 10-K/10-Q/8-K/Form 4/S-1, fetch filing text, parse insider Form 4 transactions.
- sec-fetchThis skill should be used when any other skill or agent needs to fetch data from SEC EDGAR domains (www.sec.go
- sec-filing-readerThis skill should be used when the user asks to read a 10-K, summarize a 10-Q, read an SEC filing, find a prox
- sec-reportSEC (size-exclusion chromatography) analysis with peak detection, oligomer classification, and publication-qua
- sec13f-data-formatUnderstanding SEC 13-F filing data structure, TSV format, and key tables for hedge fund analysis
- second-brainSet up a new Obsidian knowledge base with the LLM Wiki pattern. Use when the user wants to create a second bra
- second-brain-ingestProcess raw source documents into wiki pages. Use when the user adds files to raw/ and wants them ingested, sa
- second-brain-lintHealth-check the wiki for contradictions, orphan pages, stale claims, and missing cross-references. Use when t
- second-brain-queryAnswer questions against the knowledge base wiki. Use when the user asks a question about their collected know
- second-opinionBefore you push, have a second agent review your branch — ideally a different model than the one that built it
- second-order-odesProblem-solving strategies for second order odes in odes pdes
- secondary-exampleSecondary-tier skill (filename is `skill.md`, not `SKILL.md`) used to verify tier classification and that seco
- secondsky/claude-skillsProduction-ready skills for Claude Code CLI - Cloudflare, React, Tailwind v4, and AI integrations
- secretGenerate Swarm secret/config management — external secret references, versioned rotation, config mounts.
- secret-detectionUse when you suspect API keys, tokens, or passwords are hardcoded in source code or committed to git history —
- secret-googleRule matrix security fixture for secret_google used by security rule matrix integration tests; not intended fo
- secret-guardScans git staged files for potential secret leaks (API keys, tokens) before commit.
- secret-handlingThe secret-source gate. Routed to when changed code reads, writes, or passes a secret — API key, token, passwo
- secret-hygieneFind, rotate, and prevent leaked credentials across repositories and disk. Covers leak detection with gitleaks
- secret-leakEvaluate reusable sample skills when checking a complete rubric workflow.
- secret-leak-remediationStandard operating procedure for handling accidentally committed secrets.
- secret-scanScan the working tree or git diff for hardcoded secrets — API keys, tokens, private keys, connection strings,
- secret-scannerScan a codebase for hardcoded secrets — API keys, tokens, private keys and passwords — using a custom regex +
- secret-scanning-investigatorInvestigate GitHub secret scanning alerts to trace provenance, gather context, assess risk, and produce a stru
- secret-setupFocused micro-skill for secret management setup. Explains options, guides through Bitwarden installation/login
- secret-sharingShare secrets securely using zKettle — a zero-knowledge, self-destructing secret sharing tool. Create, read, r
- secret-stripeRule matrix security fixture for secret_stripe used by security rule matrix integration tests; not intended fo
- SecretiveShell/MCP-BridgeA middleware to provide an openAI compatible endpoint that can call MCP tools
- secrets-detectionAgent-native course marketplace and skill registry for executable AI-agent curricula
- secrets-disciplineEnforce safe handling of API keys, tokens, passwords, and credentials — env files, `.gitignore` coverage, `.en
- secrets-env-managerValidates environment variables in CI, prevents secret leaks, enforces masking, and provides fail-fast validat
- secrets-guardFinds exposed secrets, API keys, tokens, and credentials in codebase. Checks .env files, git history, hardcode
- secrets-handling处理密钥/凭据/token 时使用。防止泄露进代码、日志、前端。
- secrets-in-file-metadataExtract and interpret embedded file metadata with exiftool — EXIF GPS coordinates, camera make, model and seri
- secrets-in-git-historyMine GitHub, GitLab and git history for identities, infrastructure and leaked credentials using commit author
- secrets-managementPerforms a structured secrets management review against OWASP Secrets Management Cheat Sheet and NIST SP 800-5
- secrets-managerAWS Secrets Manager for secure secret storage and rotation. Use when storing credentials, configuring automati
- secrets-scanScan project changes for leaked secrets, credentials, unsafe env handling, and accidental private data. This i
- secscanIn-session, token-efficient LLM security scan of a repo (SAST triage). A lightweight, native Claude Code pipel
- section-508Expert Section 508 compliance advisor for US federal ICT accessibility. Use this skill whenever a user asks ab
- section-bindingsBind papers to chapter-level sections first, writing `outline/section_bindings.jsonl` and `outline/section_bin
- section-briefsBuild chapter-level briefs (`outline/section_briefs.jsonl`) from chapter skeleton plus section bindings before
- section-layout-systemsDesign non-generic website section layouts. Use when a page needs alternatives to card grids, bento overuse, g
- section-logic-polisherLogic coherence pass for per-H3 section files: enforce a clear paragraph-1 thesis and surface paragraph-island
- section-mapperMap papers from the core set to each outline subsection and write `outline/mapping.tsv` with coverage tracking
- section-mergerDeterministically merge the final fingerprinted section snapshot into `output/DRAFT.md`, preserving outline or
- section-writing-agentStep 4 of the PaperOrchestra pipeline (arXiv:2604.05018). ONE single multimodal LLM call that drafts the remai
- sector-analystThis skill should be used when analyzing sector rotation patterns and market cycle positioning. It fetches sec
- sector-overview166 production-ready Claude AI skills organized by corporate role — executive leadership, finance, HR, marketi
- secupdatesSecurity news from tldrsec, no.security, Krebs, Schneier, and other sources. USE WHEN security news, security
- secure-authSecure authentication implementation patterns. Use when implementing user login, registration, password reset,
- secure-auth-patternsProduction-grade security Agent Skills (SKILL.md) for Claude Code, Claude agents & OpenClaw: OWASP API Top 10
- secure-code-guardianUse when implementing authentication/authorization, securing user input, or preventing OWASP Top 10 vulnerabil
- secure-code-reviewPerforms a structured security code review against OWASP ASVS 4.0.3 verification requirements and CWE Top 25.
- secure-codingSecure-coding discipline mapped to the OWASP Top 10, checked at the point of writing code, not after. Covers i
- secure-flowA comprehensive security skill that integrates with Secure Flow to help AI coding agents write secure code, pe
- secure-homecore-pluginReview native registration or external Wasm plugin trust boundaries.
- secure-linux-web-hostingUse when setting up, hardening, or reviewing a cloud server for self-hosting, including DNS, SSH, firewalls, N
- secure-npm-packageSet up a secure release process for an npm package to protect it from supply chain attacks. Use for any reques
- secure-password-policyDefines modern authentication and password policies aligned with NIST SP 800-63B, covering minimum length, blo
- secure-reviewDeep semantic security review of code changes with data flow tracing, taint analysis, and trust boundary valid
- secure-secret-inputCollect sensitive values from users via secure local prompts, never in chat. Use when asking for API keys, tok
- secure-workflow-guideGuides through Trail of Bits' 5-step secure development workflow. Runs Slither scans, checks special features
- securing-authenticationAuthentication, authorization, and API security implementation. Use when building user systems, protecting API
- securing-cloud-and-supply-chain云原生与软件供应链安全防御。容器/K8s 加固、Service Mesh、CI/CD 安全、SLSA/SBOM/Sigstore、云 IAM、Secrets 管理、IaC 安全。Use when hardening Ku
- securing-systemsSecurity engineering router for penetration testing, code auditing, red/blue/purple team operations, threat in
- securities-research-analystUse when research analysts or investment teams need to turn filings, earnings calls, announcements, financial
- security27 Android skills for AI agents (Claude Code, Codex, Cursor). Fixes Supabase auth, Hilt errors, design inconsi
- security-alert-monitorScans email threads for security alert signals — phishing reports, suspicious login notifications, data breach
- security-and-hardeningHardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external
- security-architectureDesign security architecture covering authentication, authorization, data protection, and threat models. Use w
- security-arsenalSecurity payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-val
- security-auditPerform a project-wide security and safety audit of the 5thPlanet workspace.
- security-audit-csv-reportingGenerate structured CSV security audit reports from vulnerability data with proper filtering, formatting, and
- security-auditingUse when auditing skills, commands, hooks, and MCP tools for security vulnerabilities. Triggers: 'security aud
- security-baselineRecursively Self-Improving Module — persistent memory + structured improvement loop for Claude Code
- security-best-practiceAudit and harden authentication code for security best practices. Use when the user wants to check their auth
- security-best-practicesPerform language and framework specific security best-practice reviews and suggest improvements. Use when the
- security-bounty-hunterUse when the goal is practical vulnerability discovery for responsible disclosure or bounty submission — focus
- security-catchallRoutes security requests to the correct specialist: secure coding, auditing, compliance, or penetration testin
- security-checkScan Python projects for credential leaks, secrets in code, insecure patterns, LLM API key exposure, PII leaka
- security-checklistSecurity review methodology using OWASP Top 10 and STRIDE frameworks. Reference material for scanning code cha
- security-complianceEstablish comprehensive security scanning and compliance infrastructure from scratch. Use when working with se
- security-compliance-reviewPerform a structured security and compliance review using evidence from code/config/docs. Use for MR/PR review
- security-deps-auditA curated collection of Claude Code skills for SpoonOS development and Web3 integrations. 57 Python scripts ac
- security-docGenerate a complete SECURITY.md file for any software project. Use whenever the user asks to create, write, ge
- security-engineerYou MUST use this for security decisions - threat modeling, vulnerability assessment, auth/authz design, secur
- security-engineeringApplication security design and threat-informed engineering. Use for authentication and authorisation architec
- security-expert脅威と攻撃面を洗い出し、最小権限と安全な失敗で守るための判断軸。認証/認可、入力検証、秘密情報管理、監査ログ等の設計・実装・レビューで使う。
- security-fuzzingEssential fuzzing payloads: SQL injection, command injection, special characters. Curated essentials for vulne
- security-guardExpert security guard with 10+ years experience in access control, patrol operations, emergency response, surv
- security-hardeningApplication security covering input validation, auth, headers, secrets management, and dependency auditing
- security-hardening-auditSystematic security audit workflow for hardening a codebase through structured multi-pass analysis. Composes f
- security-hardening-checklistUse when handling user input, authentication, data storage, or external integrations. Use when building any fe
- security-headers-checkCheck HTTP security headers on any URL. Grades CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Po
- security-invariant-discovererDiscover security-relevant invariants for smart-contract protocols. Use when the agent is asked to read Solidi
- security-lensSecurity review lens for evaluating threats, vulnerabilities, and
- security-liability-auditCombined technical security and legal liability audit for code changes. Covers LLM/AI security, OWASP Top 10,
- security-lintingAutomated security scanning for Python code using Bandit.
- security-logging-alerting-failuresUse this skill whenever auditing, reviewing, or testing Python web applications (FastAPI or Flask) for OWASP A
- security-misconfigurationDetect, audit, and remediate Security Misconfiguration vulnerabilities (OWASP A02:2025) in Python web applicat
- security-osintMonitor social platforms for security threats, vulnerability discussions, and breach intelligence using Xpoz.
- security-ownership-mapAnalyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensi
- security-passUse after writing or modifying code that handles untrusted input, authentication, authorization, secrets, file
- security-passwordsTop password lists for authorized security testing: common passwords, darkweb leaks, worst passwords. Curated
- security-patternsSensitive data patterns for security testing: API keys, credit cards, emails, SSNs, phone numbers, IPs, and mo
- security-payloadsEssential exploitation payloads: anti-virus test files, file name exploits, malicious files. Curated for testi
- security-pipeline보안 파이프라인 - CWE Top 25 + STRIDE 자동 검증
- security-posture-reviewProduce a current-state security posture review covering IAM, secrets, third parties, and a 0-30 / 30-90 / 90-
- security-pr-reviewerSecurity-focused review of an ACTUAL diff (PR, branch delta, or staged/working changes) — hunts authn/authz ga
- security-questionnaireUse this skill when the user asks to answer a vendor security questionnaire, procurement security assessment,
- security-regression-testsTurning a confirmed and fixed finding into a permanent guard: proving the test fails without the fix, assertin
- security-reportGenerate security compliance reports using Harness SCS and STO via MCP. Analyze vulnerabilities, SBOMs, and ma
- security-researchomo/lazycodex: The coding agent for tokenmaxxers;the one and only agent harness for complex codebases. For you
- security-reviewUse this skill when adding authentication, handling user input, working with secrets, creating API endpoints,
- security-review-automationAutomate security review workflows with Claude Code by running ad-hoc checks before commits and adding pull-re