Python backend development expertise for FastAPI, security patterns, database operations, Upstash integrations, and code quality. Use when: (1) Building REST…
Updated 2026-09-19 04:45:49 +08:00
Oracle Database guidance for SQL, PL/SQL, SQLcl, ORDS, Oracle Vector SDK, administration, app development, performance, security, migrations, and agent-safe…
Updated 2026-09-19 03:46:55 +08:00
Use this to access external services/CLIs/APIs: Gmail/gh/Github/Stripe etc. or when running any bash command, script, or curl/wget that makes outbound HTTP…
Updated 2026-09-19 01:34:19 +08:00
pdf: Use when tasks involve reading, creating, or reviewing PDF files where rendering and layout matter; prefer visual checks by rendering pages (Poppler) and use…; gh-fix-ci: Use when a user asks to debug or fix failing GitHub PR checks that run in GitHub Actions; use `gh` to inspect checks and logs, summarize failure context, draft…; linear: Manage issues, projects & team workflows in Linear. Use when the user wants to read, create or updates tickets in Linear.; security-best-practices: Perfo…
Updated 2026-09-18 10:16:12 +08:00
data-visualization: Create effective data visualizations with Python (matplotlib, seaborn, plotly). Use when building charts, choosing the right chart type for a dataset, creating…; documentation: Write and maintain technical documentation. Trigger with "write docs for", "document this", "create a README", "write a runbook", "onboarding guide", or when…; code-review: Review code changes for security, performance, and correctness. Trigger with a PR URL or diff, "review this before I merge", "is…
Updated 2026-09-14 15:43:07 +08:00
docker-expert: You are an advanced Docker containerization expert with comprehensive, practical knowledge of container optimization, security hardening, multi-stage builds,…; nodejs-best-practices: Node.js development principles and decision-making. Framework selection, async patterns, security, and architecture. Teaches thinking, not copying.; typescript-expert: TypeScript and JavaScript expert with deep knowledge of type-level programming, performance optimization, monorepo management, migrat…
Updated 2026-09-14 15:24:45 +08:00
semgrep: Runs a Semgrep security scan over a codebase: detects languages, selects rulesets, presents the plan for explicit approval, then runs every approved ruleset…; modern-python: Configures Python projects with modern tooling (uv, ruff, ty). Use when creating projects, writing standalone scripts, or migrating from pip/Poetry/mypy/black.; codeql: Scans a codebase for security vulnerabilities using CodeQL's interprocedural data flow and taint tracking analysis. Triggers on "run codeql", "code…
Updated 2026-09-14 13:49:16 +08:00
ctf-reverse: Provides reverse engineering techniques for CTF challenges. Use when the main job is to understand how a compiled, obfuscated, packed, or virtualized target…; ctf-web: Provides web exploitation techniques for CTF challenges. Use when the target is primarily an HTTP application, API, browser client, template engine, identity…; ctf-pwn: Provides binary exploitation techniques for CTF challenges. Use when you already have a vulnerable native target or service and need to turn memory c…
Updated 2026-09-14 05:09:40 +08:00
penetration-testing-with-strix: Pentest a web app, API, codebase, repository, URL, domain, or IP with Strix — autonomous AI penetration testing that exploits and proves vulnerabilities (OWASP…; fix-security-vulnerabilities-with-strix: Fix security vulnerabilities found by a Strix pentest (open-source CLI or app.strix.ai cloud) — triage by severity, patch the root cause rather than the…; managed-pentesting-with-strix: Run a managed pentest of a web app, API, repository, or local workspace on the…
Updated 2026-09-14 00:40:50 +08:00
gmgn-market: Get crypto and meme token price charts (K-line, candlestick, OHLCV), trending meme coin rankings by volume, newly launched tokens on launchpads (pump.fun,…; gmgn-token: Research any crypto or meme token by address — real-time price, market cap, liquidity, holder list, trader list, top Smart Money and KOL positions, security…; gmgn-portfolio: Analyze one or many crypto wallets by address — holdings, batch realized/unrealized P&L, win rate, trading history, performance stats, specifi…
Updated 2026-09-11 19:25:37 +08:00
Draft, promote, archive, and supersede ADR-style decision records (types are open: architecture, product, security, policy, legal, …) and keep INDEX.md and…
Updated 2026-09-11 15:34:55 +08:00
pwa-development: Progressive Web Apps - service workers, caching strategies, offline, Workbox; playwright-testing: E2E testing with Playwright - Page Objects, cross-browser, CI/CD; android-kotlin: Android Kotlin development with Coroutines, Jetpack Compose, Hilt, and MockK testing
Updated 2026-09-08 21:24:22 +08:00
security-review: Security code review for vulnerabilities. Use when asked to "security review", "find vulnerabilities", "check for security issues", "audit security", "OWASP…; code-simplifier: Simplifies and refines code for clarity, consistency, and maintainability while preserving all functionality. Use when asked to "simplify code", "clean up…; find-bugs: Find bugs, security vulnerabilities, and code quality issues in local branch changes. Use when asked to review changes, find bugs, securit…
Updated 2026-09-07 21:52:41 +08:00
ghost-scan-code: Ghost Security - SAST code scanner. Finds security vulnerabilities in source code by planning and executing targeted scans for issues like SQL injection, XSS,…; ghost-scan-secrets: Ghost Security - Secrets and credentials scanner. Scans codebase for leaked API keys, tokens, passwords, and sensitive data. Detects hardcoded secrets and…; ghost-scan-deps: Ghost Security - Software Composition Analysis (SCA) scanner. Scans dependency lockfiles for known vulnerabilities, identifies…
Updated 2026-09-03 17:07:28 +08:00
ci-cd-security: Scan GitHub Actions workflow files for security vulnerabilities by reading the YAML and reporting findings directly — no external tools, no installation, no…; skill-security: Audit an AI agent skill for security risks before installing or trusting it. Runs a deterministic scanner (regex patterns, Python AST analysis, source-to-sink…
Updated 2026-08-15 20:47:01 +08:00
landing-page-copywriter: Write high-converting landing page copy using proven frameworks like PAS (Problem-Agitate-Solution), AIDA, and StoryBrand. Creates headlines, value…; code-review-pro: Comprehensive code review covering security vulnerabilities, performance bottlenecks, best practices, and refactoring opportunities. Use when user requests…
Updated 2026-08-11 14:24:23 +08:00
github-trending: Fetch and display GitHub trending repositories and developers. Use when building dashboards showing trending repos, discovering popular projects, or tracking…; owasp-security: Implement secure coding practices following OWASP Top 10. Use when preventing security vulnerabilities, implementing authentication, securing APIs, or…; mongodb: Work with MongoDB databases using best practices. Use when designing schemas, writing queries, building aggregation pipelines, or optimizing per…
Updated 2026-07-12 06:17:29 +08:00
code-review-expert: Expert code review of current git changes with a senior engineer lens. Detects SOLID violations, security risks, and proposes actionable improvements.; sigma: Personalized 1-on-1 AI tutor using Bloom's 2-Sigma mastery learning. Guides users through any topic with Socratic questioning, adaptive pacing, and rich visual…; skill-forge: Create high-quality, production-grade skills for Claude Code. Expert guidance on skill architecture, workflow design, prompt engineering, and pac…
Updated 2026-05-11 15:21:43 +08:00
Security-first vetting for OpenClaw skills. Use before installing any skill from ClawHub, GitHub, or other sources. Checks for red flags, permission scope, and…
Updated 2026-03-10 11:43:44 +08:00
Build production Spring Boot applications - REST APIs, Security, Data, Actuator
Updated 2026-01-05 19:55:39 +08:00