aibot88
- 8.3k skills
- 0 followers
- 3 repo stars
- 2 weeks ago last updated
- ▌
- ▌ Farmountain Sdlc Agent Swarm Agents Skills Verifier · aibot88 bundleSkill: Verifier (Independent Evidence Validation & Compliance Gate)
- ▌ Wasabeef Claude Code Cookbook Plugins Fr Skills Spec · aibot88 bundleCréer des spécifications détaillées. Se déclenche avec « écrire une spec », « définir les exigences ».
- ▌ Wasabeef Claude Code Cookbook Plugins Ja Skills Role · aibot88 bundle特定の専門ロールに切り替えて分析・作業を実行する。「ロールを切り替えて」「セキュリティ専門家として」「アーキテクトとして」「フロントエンド専門家として」「バックエンドとして」「QA として」などで起動。
- ▌ Wasabeef Claude Code Cookbook Plugins Pt Skills Spec · aibot88 bundleCriar especificações detalhadas. Ativa com "escrever spec", "definir requisitos", "design detalhado".
- ▌ Farmountain Sdlc Agent Swarm Agents Skills Cicd Agent · aibot88 bundleSkill: CICDAgent (Pipeline Generation & Test Automation)
- ▌
- ▌
- ▌ Config Env Conventions Amnadtaowsoam Cerebratechai Claude · aibot88 bundleConfig & Environment Conventions
- ▌ Frank Luongt Faos Skills Marketplace Skills Codex Cwe Sans T · aibot88 bundle<!-- AUTO-GENERATED by export-skills.py — DO NOT EDIT -->
- ▌ Dnyoussef When Setting Network Security Use Network Security · aibot88 bundleNetwork Security Setup SOP
- ▌ Dnyoussef When Configuring Sandbox Security Use Sandbox Conf · aibot88 bundleSandbox Security Configuration SOP
- ▌
- ▌ Paper2ppt · aibot88 bundleTurn research papers into concise, editable PPT decks with a restrained discussion-class whiteboard style. Use when Codex needs to read a paper PDF or paper notes, optionally borrow Paper2Slides for content planning, and then create a simple editable PPTX for paper reading, discussion sessions, group meetings, or seminar reports.
- ▌ Shanghai Service Guide · aibot88 bundleHelp users with Shanghai government service questions using public Shanghai "一网通办" service-guide data. Use when the user asks about 上海办事, 一网通办, 办事指南, 去哪办, 哪个部门, 线上办理, 线下窗口, 个人事项, 法人事项, or wants to identify the right Shanghai department, service item, online/offline path, or next step for a described need.
- ▌ Sec Conf Plot · aibot88 bundleCreate publication-ready figures, charts, and diagrams for computer security conference papers and security research reports. Use when Codex needs to design or generate plots from security experiment results, vulnerability/attack workflows, system or threat-model diagrams, RQ result charts, evaluation figures, or LaTeX-ready visual assets for venues such as USENIX Security, IEEE S&P, ACM CCS, NDSS, RAID, ACSAC, or security workshops.
- ▌ Sec Conf Paper · aibot88 bundleUse when generating a security conference paper draft that should preserve the existing sec-conf-write and sec-conf-plot workflows, produce a full English draft with figures first, then produce a Chinese text-only mirror draft while leaving figure assets unchanged. Use for bilingual ACM CCS, NDSS, IEEE S&P, USENIX Security, RAID, ACSAC, and similar security-paper drafting workflows where the user provides fixed English and Chinese headings.
- ▌ Sec Conf Write · aibot88 bundleSecurity conference paper writing, rewriting, outlining, and reviewer-style critique for ACM CCS, NDSS, IEEE S&P, and USENIX Security. Use when Codex needs to draft or revise security paper abstracts, introductions, threat models, vulnerability definitions, empirical-study sections, methods, evaluations, security impact, responsible disclosure, ethics, artifacts, rebuttals, or pre-submission checks. Also use when a user asks for top-tier security conference writing guidance, section blueprints, reviewer expectations, or venue-aware paper positioning.
- ▌ Aap Vault Ssh · aibot88 bundleIntegrate Red Hat Ansible Automation Platform (AAP) with HashiCorp Vault Enterprise for dynamic SSH credential management. Use when: (1) Configuring Vault SSH secrets engine with AppRole auth for AAP, (2) Creating AAP credentials backed by Vault signed SSH certificates, (3) Provisioning infrastructure with Terraform/Ansible for AAP-Vault integration, (4) Setting up multi-tenant credential management, (5) Configuring golden images to trust Vault SSH CA, (6) Implementing credential rotation strategies. Based on HashiCorp validated pattern.
- ▌ Accessibility · aibot88 bundleAudit and improve web accessibility following WCAG 2.2 guidelines. Use when asked to "improve accessibility", "a11y audit", "WCAG compliance", "screen reader support", "keyboard navigation", or "make accessible".
- ▌ Venv Manager · aibot88 bundleManage Python virtual environments in a consistent, organized way. Use when a skill needs Python packages installed, or when the user wants to create a venv following standard conventions. Provides the authoritative convention for venv location and naming that other skills should follow.
- ▌ Vuln Scanner · aibot88 bundle脆弱性スキャンスキル。CVE/依存関係脆弱性を検出し、npm audit/pip-audit/trivy等の結果を解析。セキュリティリスクの優先順位付けと修正提案を提供。
- ▌ Warden Audit · aibot88 bundleFull security audit — secrets, dependencies, IAM, auth, injection, XSS, HTTPS, rate limiting, public storage. Use when asked for "security audit", "check for vulnerabilities", "security review", or "are we secure".
- ▌ Warden Recon · aibot88 bundleSecurity reconnaissance — full inventory of secrets management, IAM, dependencies, auth, encryption, audit logging, and compliance gaps. Use when asked about "security posture", "how secure is this", or "security assessment".
- ▌ Web Security · aibot88 bundleOWASP Top 10, security headers, CSP, XSS prevention, and vulnerability prevention.
- ▌ Webapp Nikto · aibot88 bundleWeb server vulnerability scanner for identifying security issues, misconfigurations, and outdated software versions. Use when: (1) Conducting authorized web server security assessments, (2) Identifying common web vulnerabilities and misconfigurations, (3) Detecting outdated server software and known vulnerabilities, (4) Performing compliance scans for web server hardening, (5) Enumerating web server information and enabled features, (6) Validating security controls and patch levels.
- ▌ What Antibot · aibot88 bundleDetect antibot vendors on one or more URLs without opening a browser session. Use when the user asks what antibot, bot protection, WAF, captcha, or challenge provider a site uses, or asks to check sites for Cloudflare, Akamai, DataDome, PerimeterX, Imperva/Incapsula, Kasada, reCAPTCHA, hCaptcha, Anubis, or Shape Security markers.
- ▌ Wise Scraper · aibot88 bundleStructured web scraping for AI coders: explore, then exploit with shipped templates, runner, and hooks.
- ▌ Wolf Finance Skill · aibot88 bundleACTIVATE for ANY finance, investment, trading, or market query. Triggers: ticker symbols ($AAPL, BTC, EUR/USD), asset classes (stocks, crypto, forex, bonds, commodities, derivatives, PE, hedge funds), concepts (DCF, P/E, RSI, MACD, Kelly, VaR, Sharpe, Greeks, yield curve, carry trade, QE), actions ("should I buy/sell", "analyze this", "build a portfolio", "hedge my position", "size this trade"), modeling (valuation, forecasting, backtesting, Monte Carlo), corporate finance (M&A, IPO, LBO, WACC, NPV, IRR), wealth management (asset allocation, tax-loss harvesting, estate, retirement), and market intelligence (macro, central bank, geopolitics, sector rotation). Also covers: institutional trading, quant strategies, family office, investment banking, risk management, compliance, and regulation. USE THIS SKILL whenever finance is even tangentially mentioned.
- ▌ Youtube Data · aibot88 bundleAccess YouTube video data — transcripts, metadata, channel info, search, and playlists. A lightweight alternative to Google's YouTube Data API with no quota limits. Use when the user needs structured data from YouTube videos, channels, or playlists without dealing with Google API setup, OAuth, or daily quotas.
- ▌ Zod Security · aibot88 bundleThis skill should be used when the user asks about "Zod security", "Zod over-posting attack", "mass assignment Zod", "z.strictObject security", "z.custom security", "Zod coercion vulnerability", "Zod default PATCH bug", "Zod data loss", "Zod reportInput PII", "exposing ZodError to client", "Zod security review", "reviewing Zod validation code", or when performing a code review on TypeScript files that use Zod. Provides a comprehensive security model and review checklist for Zod usage.
- ▌ Vnsh · aibot88 bundleSecurely share files via encrypted, expiring links. Use this skill to (1) upload a local file to get a secure vnsh.dev URL, or (2) read a vnsh.dev URL to decrypt and access its content.
- ▌ 1password CLI · aibot88 bundleEntry-point router skill for the 1Password CLI. Use this skill when the user mentions the 1Password CLI (`op`) or 1Password generically, references the secret-reference URI scheme `op://`, asks about `OP_ACCOUNT` or `OP_SERVICE_ACCOUNT_TOKEN`, asks about biometric unlock for a CLI, or is choosing how to load secrets into an app and 1Password is a candidate. Provides general orientation, the auth-mode picker, the full command map, and routing to deeper sub-skills (`op-secrets-injection`, `op-item-management`, `op-provisioning`, `op-ssh-keys`, `op-shell-plugins`, `op-service-accounts`). Defer to those sub-skills for specific commands.
- ▌ State Management Auth Contexts · aibot88 bundleGestion de l'état global dans Next.js — contextes d'auth Sanctuaire/Expert, entitlements, et hooks React personnalisés.
- ▌ 5w1h Decision · aibot88 bundle5W1H Decision Framework Tool. Use for: (1) Systematic decision-making before creating todos, (2) Preventing duplicate implementation, (3) Detecting avoidance behavior, (4) Ensuring agile refactor compliance with executor/dispatcher separation
- ▌ Titan Recall · aibot88 bundleRetrieve Titan candidate memory records with source, record id, authority note, confidence, and verification path. Use when a Titan service-cohort route needs this explicit bounded step. Do not use for hidden background agents, silent mutation, unreviewed proof sovereignty, or memory canonization without owner confirmation.
- ▌ Tls Security · aibot88 bundleExpert skill for TLS/SSL implementation and certificate management. Generate and validate TLS configurations, create and manage X.509 certificates, analyze cipher suite security, debug TLS handshake failures, and implement certificate pinning.
- ▌ Solana Token Launch · aibot88 bundleUse this skill when the user wants to launch a fungible token on Solana (SPL or Token-2022), set metadata, mint supply, revoke authorities, and optionally add liquidity on Raydium/Meteora/Orca.
- ▌ Trust Center · aibot88 bundleGenerate a public-facing security trust page from scan data. Produces a single deployable index.html that shows compliance framework scores, security policies, infrastructure overview, and data protection posture. Deployable to S3, Vercel, Netlify, or GitHub Pages.
- ▌ TS Implement · aibot88 bundleTypeScript実装のベストプラクティスとコーディング規約。型安全なコード、モダンな機能、エラーハンドリング、品質基準を提供。TypeScript実装、コーディング規約、型定義パターンが必要な時に参照。
- ▌
- ▌ Ub Authoring · aibot88 bundleUse this skill when the task involves creating, reviewing, or refactoring installable skills, shared skill references, or reusable agent-authoring guidance; when the work depends on routing-quality descriptions, non-use boundaries, naming, progressive disclosure, or cross-skill authoring conventions; or when you want to normalize skill and guidance structure without turning the task into a full customization-builder workflow. Do not use it for end-to-end customization generation, normal code implementation, or general repository planning.
- ▌ Vcf Research · aibot88 bundleResearch VCF 9 and its ecosystem (vSphere 9, vSAN 9, NSX 9, VKS, VCF Operations, VCFA, VMware Live Recovery, Private AI Foundation). Searches Broadcom TechDocs and trusted blogs (Frank Denneman, Duncan Epping/Yellow-Bricks, William Lam). Trigger for ANY question about VCF 9 architecture, design, deployment, migration, upgrade, sizing, prerequisites, hardware compatibility, licensing, deprecated features, lab setup, vSAN ESA, NSX VPC, VKS, VCFA, GPU/vGPU placement, or differences from VCF 5.x. Also trigger when user mentions "VCF", "VMware Cloud Foundation", "vSAN 9", "NSX 9", "VKS", "VCFA", "VCF Operations", or any Broadcom/VMware infrastructure topic where authoritative sources would improve the answer.
- ▌ Strm Mapping · aibot88 bundleUse when asked to map, crosswalk, align, compare, or gap-analyze any two cybersecurity frameworks, control catalogs, or regulatory requirements using NIST IR 8477 Set-Theory Relationship Mapping (STRM). Triggers on terms like "map controls", "crosswalk", "framework alignment", "gap analysis", or producing a STRM CSV output file.
- ▌ Sui Zk Login · aibot88 bundleAdd Sui zkLogin for Google, Apple, Facebook, or Twitch sign-in. Use when the user mentions zkLogin, social login, or OAuth-based Sui auth.
- ▌ Swift Strict · aibot88 bundleSwift/SwiftUI strictness, clean code, and security rules. Use when writing, reviewing, or refactoring Swift code in iOS/macOS projects. Covers force unwrap prevention, @Observable vs ObservableObject patterns, access control, concurrency safety (@MainActor, actors, Sendable), error handling with typed enums, memory leak prevention, guard-first style, and naming conventions. Derived from production iOS apps.
- ▌ Syntherklaas · aibot88 bundleGenerate synthetic data from scratch through an interactive dialog — ask the user table-by-table about columns, types, foreign keys, and constraints; render the data model as ASCII UML; ask for volume + distributions; then generate consistent fake data with Faker (locale-aware) + NL-locked providers for BSN/IBAN/postcode. Outputs CSV (loose files), XLSX (loose or multi-sheet), or SQLite. Schema can be saved to YAML for re-invoke (`/syntherklaas <yaml-path>` skips the dialog, runs deterministic generation). Use when the user wants test data, demo data, fake data with FK relations, or mentions "synthetic data", "fake data", "test data", "demo dataset", "BSN-safe test data", or "anonimiseer me een schema".
- ▌ Take Over Pr · aibot88 bundleTake over a stale or abandoned PR. Checks out the work, merges main, deep-reviews the code, addresses all review comments, then re-creates a clean PR crediting the original author.
- ▌ Tax Strategy · aibot88 bundleUse this skill when planning corporate tax strategy, claiming R&D credits, managing transfer pricing, or ensuring tax compliance. Triggers on corporate tax, R&D tax credits, transfer pricing, tax compliance, sales tax, VAT, international tax, and any task requiring tax planning or compliance strategy.
- ▌ Terraform CI · aibot88 bundleTerraform in CI/CD — plan on PR, apply on merge, OIDC auth, drift detection, importing existing resources, common CLI commands, anti-patterns, and Terraform vs Pulumi vs CDK decision guide.
- ▌ Teyvat Guide · aibot88 bundleTeyvatGuide 项目 SKILL。处理 Vue+Tauri+TypeScript 项目开发,包括组件开发、API 集成、SQLite 操作或代码规范。
- ▌ Speckit Threat Model · aibot88 bundleGenerate a threat model from spec.md using STRIDE methodology. Use when you need to identify security threats, attack surfaces, and mitigations for a feature before implementation. Triggers on "threat model", "security analysis", "attack surface", "STRIDE analysis".
- ▌ Skill Commit · aibot88 bundleBuenas prácticas para crear commits de git claros, atómicos y bien estructurados en español. Activa esta skill siempre que el usuario pida hacer un commit, confirmar cambios, guardar cambios en git, o cualquier variación de "haz commit", "commitea", "sube los cambios", "guarda en git", "git commit", etc. También cuando el usuario pida revisar o mejorar un mensaje de commit existente.
- ▌ Skill Verify · aibot88 bundleSecurity audit for AI agent skills before installation. Scans SKILL.md files, hooks, scripts, and MCP configs for prompt injection, data exfiltration, credential theft, and malicious automation patterns. Use when installing a new skill, reviewing a skills repo, or auditing existing installed skills. Trigger phrases: "verify this skill", "is this skill safe", "audit skill", "check before installing", "scan this plugin".
- ▌ Skill Vetter · aibot88 bundleSecurity-first vetting for OpenClaw skills. Use before installing any skill from ClawHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.
- ▌ Skillbuilder · aibot88 bundleBuild flawless Claude Code skills. Studies existing skills as reference, ensures correct format, and pushes for genuine intelligence — skills that exploit something specific about how Claude works. SKIP for one-off scripts, prompts, or task helpers.
- ▌ Slicing Pbis · aibot88 bundleSlices, reviews, and writes product backlog items (PBIs) using priority-ordered quality characteristics (Valuable > Completable > Negotiable > Independent > Commensurate > Small), vertical slicing, and the splitting meta-pattern. Produces well-formed, commensurately sized PBIs with binary acceptance criteria. Use when splitting large PBIs or user stories, reviewing backlog items for quality, writing new PBIs from requirements, refining a product backlog, decomposing epics into stories, or when the user mentions PBI slicing, story splitting, backlog refinement, or vertical slices.
- ▌ Slop MCP Slop Monitor · aibot88 bundleScaffold slop-mcp monitor session — verify PATH binary, choose generic event stream / SLOP polling script / timed session, emit copy-ready Claude Code Monitor({...}) JSON. 搭建 slop-mcp 監視會話。 Use when: starting Claude Code Monitor over slop-mcp, watching git/build/CI events, polling MCP for delta changes, running bounded watch session.
- ▌ So Me Studio · aibot88 bundleSchedule posts, manage drafts, reply to inbox messages, generate AI captions/images/UGC videos, query analytics, and automate social-media operations across Twitter/X, LinkedIn, Instagram, Facebook, TikTok, YouTube, Threads, WhatsApp, Pinterest, and Dribbble — driven from the Hermes Agent CLI via the `so-me` binary.
- ▌ Soc Cialdini · aibot88 bundleApply Cialdini's six principles of persuasion — Reciprocity, Commitment/Consistency, Social Proof, Liking, Authority, and Scarcity — to analyze or design influence strategies. Use this skill when the user needs to make messaging more persuasive, analyze why a campaign works or doesn't, design sales or marketing copy, or understand social influence tactics — even if they say 'how do we convince people', 'why is this ad effective', or 'make this more persuasive'.
- ▌ Solidity Dev · aibot88 bundleDeep expertise in Solidity language features, patterns, and best practices for secure smart contract development. Covers ERC standards, gas optimization, upgradeable contracts, and security patterns.
- ▌ Specdd Adopt · aibot88 bundleUse when Claude Code needs to create, add, restructure, or improve SpecDD `.sdd` contract files, define ownership or write authority, clean up missing or unclear specs, or introduce SpecDD adoption without changing implementation unless explicitly requested.
- ▌ Specdd Debug · aibot88 bundleUse when Claude Code needs to diagnose or fix a bug in a SpecDD project by reproducing or inspecting failure, comparing observed behavior to active `.sdd` contracts, and applying the smallest authorized fix.
- ▌ Specdd Trace · aibot88 bundleUse when Claude Code needs to map SpecDD specs to code, tests, docs, changed files, public behavior, references, verification coverage, or gaps while preserving the distinction between read context and write authority.
- ▌ Spine Review · aibot88 bundleAPI and backend code review — REST conventions, auth, validation, error handling, pagination, rate limiting, test coverage. Use when asked to "review this API", "code review", "review backend", or "pre-launch backend check".
- ▌ Sprint Retro · aibot88 bundleUse when running a sprint retrospective, generating a retro, preparing retro data, or summarizing team activity for a retrospective. Takes team member names or a Slack alias as input. Gathers data from GitHub, Slack, Jira, Confluence, Google Docs, and CI/CD with strict privacy filtering.
- ▌ Sqlite Guide · aibot88 bundleGuide pour écrire des requêtes SQL et concevoir des schémas SQLite avec les bonnes pratiques. À utiliser quand l'utilisateur travaille avec SQLite, écrit des requêtes SQL ou conçoit des schémas de base de données. Se déclenche aussi avec "requête SQL", "schéma SQLite", "base de données SQLite", "migration SQL", "table SQLite", "query SQL".
- ▌ Staff Review · aibot88 bundleSenior Staff Engineer code review with SOLID principles, security analysis, and architecture critique. Use for significant changes, new systems, or when you want ruthless technical feedback.
- ▌ Strict Audit · aibot88 bundleЖёсткий No-Go аудит для safety-critical архитектуры, кода и PR: выдаёт PASS/FAIL, блокирующие замечания и обязательные доказательства по таймингам, измерениям и fault-injection. Использовать перед включением силовой части и для спорных safety/timing-изменений; не использовать как обычное обзорное ревью по умолчанию.
- ▌ Secret Setup · aibot88 bundleFocused micro-skill for secret management setup. Explains options, guides through Bitwarden installation/login/unlock, configures backend. Exits when done.
- ▌ Security Fix · aibot88 bundleSecurity remediation en vulnerability fix skill. Past fixes toe voor kwetsbaarheden uit security check-rapporten. Automatische dependency updates, configuratie-patches, code fixes via Edit tool, en PR-creatie. Gebruik na een security audit/scan om kritieke en hoge severity issues op te lossen.
- ▌ Self Improve · aibot88 bundleContinuous self-improvement loop — AuthorClaw learns from mistakes, successes, and user feedback to get better over time
- ▌ Semgrep Sast · aibot88 bundleUse this agent when you need deterministic static analysis security scanning using semgrep. This agent complements security-sentinel by running rule-based pattern matching to catch known vulnerability signatures, hardcoded secrets, insecure function calls, and CWE patterns that LLM-based review may miss. Requires the semgrep CLI to be installed.
- ▌ Shaper Setup · aibot88 bundleEnsure Shaper CLI is installed, configure shaper.json, authenticate, and safely pull remote dashboards/tasks.
- ▌ Signal Radar · aibot88 bundleContinuous macro-market signal detection and classification engine that surfaces emerging trends, threats, and whitespace opportunities. Use when: market signals, market intelligence, trend analysis, emerging threats, market monitoring, what is changing in our market.
- ▌ Skill Author · aibot88 bundleCreate and refine high-quality Agent Skills (SKILL.md + bundled resources). Use when the user wants to create a new skill, improve an existing one, or turn a workflow into a reusable skill package. Covers structure, progressive disclosure, conciseness, feedback loops, and the quality checklist. Do NOT use for skill validation (use skill-check) or for prompt engineering (use prompt-craft).
- ▌ Sales Hypefy · aibot88 bundleHypefy platform help — AI-native influencer marketing with zero-subscription, pay-per-campaign pricing. Covers AI campaign setup (brief generation from product description, geography, and budget), influencer discovery (3K+ vetted internal database, 12M+ external on Instagram and TikTok), automated outreach and hiring (proposals, terms, coordination), content review and approval before publishing, influencer payments (multi-currency, milestone-based, compliance), performance dashboard (reach, engagement, ROI), and built-in calculators (Budget, ROI, Engagement, CPM, CTR). Use when Hypefy campaign setup isn't clear, unsure if Hypefy is the right platform for your budget, pricing model feels confusing, creator payments aren't going through, content approval workflow is stuck, or campaign metrics don't look right. Do NOT use for influencer strategy across platforms (use /sales-influencer-marketing), ad campaign strategy (use /sales-retargeting), email marketing to subscribers (use /sales-email-marketing), or affil
- ▌ Sales Unboxd · aibot88 bundleUnboxd platform help — AI email secretary that reads every email and extracts action items with deadlines into daily briefings, supports Gmail/Outlook/IMAP ($7.50-41.67/mo). Use when action items keep getting lost in email threads, spending too much time reading and triaging emails, daily briefing is missing important messages, credits are running out before the month ends, emails getting categorized into the wrong bucket, comparing Unboxd to Fyxer or Superhuman or SaneBox or Shortwave for inbox triage, or setting up Unboxd with multiple email accounts. Do NOT use for AI reply drafting or voice-trained email writing (use /sales-fyxer or /sales-superhuman). Do NOT use for choosing a meeting note-taker (use /sales-note-taker).
- ▌ Sales Verint · aibot88 bundleVerint Open Platform help — enterprise CX automation with Da Vinci AI bots (Quality Bot 100% QA, Coaching Bot real-time guidance, Wrap Up Bot auto-summaries, CX/EX Scoring, TimeFlex agent scheduling, Exact Transcription 80+ languages), WFM forecasting/scheduling/adherence, knowledge automation, IVA virtual assistants, speech/text analytics, financial compliance, Verint Marketplace 350+ listings. Use when Verint reports loading slowly or showing inconsistent data, Quality Bot not scoring interactions correctly, Coaching Bot recommendations irrelevant, WFM forecasts off vs actual volume, Verint API integration or developer portal questions, comparing Verint vs NICE vs Genesys WEM capabilities, or connecting Verint to your CCaaS or CRM. Do NOT use for choosing between CCaaS platforms (use /sales-ccaas-selection) or for QA tool comparison across vendors (use /sales-coaching).
- ▌ Sast GRAPHQL · aibot88 bundleDetect GraphQL injection vulnerabilities in a codebase using a three-phase approach: recon (confirm GraphQL usage and find unsafe operation document assembly sites), batched verify (trace user input to those sites in parallel subagents, up to 3 candidate sites each), and merge (consolidate batch results). Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/graphql-results.md. If no GraphQL technology is found in Phase 1, later phases are skipped. Use when asked to find GraphQL injection, unsafe GraphQL document construction, or operation string injection bugs.
- ▌ Sast Horusec · aibot88 bundleMulti-language static application security testing using Horusec with support for 18+ programming languages and 20+ security analysis tools. Performs SAST scans, secret detection in git history, and provides vulnerability findings with severity classification. Use when: (1) Analyzing code for security vulnerabilities across multiple languages simultaneously, (2) Detecting exposed secrets and credentials in git history, (3) Integrating SAST into CI/CD pipelines for secure SDLC, (4) Performing comprehensive security analysis during development, (5) Managing false positives and prioritizing security findings.
- ▌ Sast Semgrep · aibot88 bundleStatic application security testing (SAST) using Semgrep for vulnerability detection, security code review, and secure coding guidance with OWASP and CWE framework mapping. Use when: (1) Scanning code for security vulnerabilities across multiple languages, (2) Performing security code reviews with pattern-based detection, (3) Integrating SAST checks into CI/CD pipelines, (4) Providing remediation guidance with OWASP Top 10 and CWE mappings, (5) Creating custom security rules for organization-specific patterns, (6) Analyzing dependencies for known vulnerabilities.
- ▌ Sc Websocket · aibot88 bundleWebSocket security flaw detection — missing origin validation, authentication bypass, and message injection
- ▌ Route Tester · aibot88 bundleFramework-agnostic HTTP API route testing patterns, authentication strategies, and integration testing best practices. Supports REST APIs with JWT cookie authentication and other common auth patterns.
- ▌ Rpc Contract · aibot88 bundleRPC contract validation — Contract-first development, direkt REST bypass yasak
- ▌ Safe Version · aibot88 bundleFind the newest version of a package that is free of known vulnerabilities, capped by a `--max-major-bump` policy. Use when picking an upgrade target for a vulnerable dep, evaluating major-version churn risk, generating a "safe pin" for a lockfile, or building an `overrides` block.
- ▌ Safety Check · aibot88 bundle**WORKFLOW SKILL** — Risk awareness before action. USE FOR: assessing risks (security, data integrity, compatibility, operational, reversibility) of any task at variable depth. Accepts weight: Light (quick scan), Standard (dimensional analysis), Deep (full Risk Radar with evidence). Can be invoked multiple times in the same flow with increasing weight. DO NOT USE FOR: penetration testing, compliance audits, static security analysis tools.
- ▌ Cc Safe Setup · aibot88 bundleSafety hooks for Claude Code — 695 pre-built hooks that prevent file deletion, credential leaks, git disasters, and token waste during autonomous AI coding sessions. Install with npx cc-safe-setup.
- ▌ Sales Amical · aibot88 bundleAmical platform help — open-source, local-first AI dictation app with Whisper STT, context-aware formatting, Ollama/OpenRouter LLM, MCP voice commands, and 100+ language support (MIT license). Use when setting up Amical on macOS or Windows for the first time, choosing between Whisper model sizes for accuracy vs speed, configuring Ollama for fully offline text formatting, context-aware formatting not adapting to the active application, microphone not switching or audio input issues, custom vocabulary not recognizing industry terminology, comparing Amical to Wispr Flow or Superwhisper for privacy-first dictation, or setting up voice commands with MCP integrations. Do NOT use for picking between meeting note-takers generally (use /sales-note-taker) or reviewing a single call for coaching (use /sales-call-review).
- ▌ Sales Fathom · aibot88 bundleFathom AI note-taker platform help — REST API for pulling meeting transcripts, summaries, action items, and CRM matches into CRMs, data warehouses, or Slack. Use when transcripts not syncing to HubSpot/Salesforce, Fathom webhook signatures failing HMAC verification, bot blocked by Google Meet as a security risk, OAuth app can't include transcript inline, building a Fathom→Snowflake/BigQuery pipeline, rate-limited at 60 calls/minute, or picking between Fathom free tier vs Premium vs Team vs Business. Do NOT use for selecting between Fathom and competitors like Fireflies/Gong/Avoma (use /sales-note-taker) or reviewing specific call recordings (use /sales-call-review).
- ▌ Sales Flippa · aibot88 bundleFlippa marketplace help — the largest open marketplace since 2009 for buying/selling SaaS, ecommerce, content sites, apps, domains, and social accounts (39,805+ sold). Covers listing packages (Entry $29, Standard $59-$99, Premium $299-$599, Ultimate $499-$699), tiered success fees (10% under $50K down to 3% over $10M), add-ons (NDA $199, legal $199, M&A report $499, private listing $599), $999 brokered service for $100K+ listings, buyer Premium $49/mo and DD reports $1,500-$2,500, OAuth verification above $50K via Stripe/GA/Shopify/Amazon, and FlippaPay/Escrow.com escrow. Use when listing a business on Flippa, auditing a listing for fraud or inflated revenue, picking between Entry/Standard/Premium/Ultimate packages, budgeting the tiered success fee against Acquire.com or Empire Flippers, or preparing financials for the above-$50K auto-verification badge. Do NOT use for cross-marketplace valuation strategy (use /sales-side-project-valuation).
- ▌ Sales Heepsy · aibot88 bundleHeepsy platform help — influencer discovery (11M+ profiles across Instagram, TikTok, YouTube, Twitch), audience authenticity scoring, analytics reports, campaign marketplace, influencer CRM, media gallery, Shopify/WooCommerce integration, bulk outreach export, and creator detection. Use when Heepsy searches return irrelevant creators, influencer lists are hard to organize, campaign results don't match expectations, analytics scores seem off, credits are running out too fast, Shopify integration isn't tracking sales, or unsure if Heepsy is the right platform. Do NOT use for influencer marketing strategy across platforms (use /sales-influencer-marketing), ad campaign strategy (use /sales-retargeting), or email marketing to subscribers (use /sales-email-marketing).
- ▌ Relay Docker · aibot88 bundleBuild production-ready Dockerfiles with multi-stage builds, security hardening, and docker-compose for local dev. Use when asked to "create Dockerfile", "optimize container", or "dockerize this".
- ▌ Review Input · aibot88 bundleAdversarial review of any input (human idea, agent analysis, research report, feedback, observation) BEFORE it mutates persistent project state. Universal interceptor with domain auto-detection, 2-phase classification + evaluation, and triple-verdict output (veracity / fit / actionability). Anti-girouette guardrail that distinguishes drift from pivot — preserves human decisional authority. Manual invocation only (no hooks, no enforcement). Activate when an input may affect strategic-frame.md, a DEC, an OT, an architecture/pattern doc, an agent definition, a backlog story scope/AC/wedge field, or user-facing copy.
- ▌ Rewrite Plan · aibot88 bundleAuthor a long-running multi-file rewrite plan that subsequent patch-edit + diff-review + build-test stages will execute, with explicit ownership boundaries and patch-safety guarantees.
- ▌ Memstack Security Rls Guardian · aibot88 bundleUse this skill when creating or altering database tables in Supabase or PostgreSQL projects. Triggers include: CREATE TABLE, ALTER TABLE, migration files, 'RLS', 'row level security', 'new table', 'database schema'. Enforces Row Level Security policies on every table to prevent unauthorized data access. Do NOT use for general SQL queries or non-schema database tasks.
- ▌ Robot Bi Dev · aibot88 bundleMaster skill cho dự án Robot Bi. Kết hợp TDD, diagnosis loop, security audit, git safety, UI prototyping, và session hygiene — tất cả được calibrate cho codebase Python/FastAPI/SQLite/Groq của Robot Bi. Trigger khi: implement feature mới, debug bug, security review, làm UI frontend/robot display, hoặc bắt đầu session dev bất kỳ.
- ▌ Roll Onboard · aibot88 bundleInteractive onboarding for legacy projects. Reads existing code, understands the project, asks 9 questions in 3 groups (cognition / scope / privacy), and writes .roll/onboard-plan.yaml as the contract for `roll init --apply` to execute.
- ▌ Postgres Rls · aibot88 bundleGuides agents implementing or auditing PostgreSQL Row Level Security in a multi-tenant SaaS codebase. Covers ENABLE+FORCE pairing, USING+WITH CHECK policies, view bypass via security_invoker, SET LOCAL for connection pool safety, superuser/owner bypass detection, and materialized view risks. Do NOT use for application-level authorization logic (use nextauth-patterns), non-PostgreSQL databases, or application query tier questions (use multi-tenancy-rls for orgQuery() usage).
- ▌ Preboot Core · aibot88 bundleSkill do używania biblioteki preboot-core. Użyj tego skilla zawsze gdy użytkownik chce cache z TTL, rate limiting, synchronizację dostępu po kluczu, transakcje programowe, hashowanie parametrów, walidację beanów, konfigurację Jacksona, lub pracuje z infrastrukturą współbieżności. Obejmuje: TTLMap, AccessSynchronizer, RateLimiter, TransactionWrapper, HashUtils, BeanValidator, JsonMapperFactory, JacksonCustomizerAutoConfiguration. Triggeruje się na: TTL cache, rate limiter, token bucket, key-based lock, synchronizacja po kluczu, ReentrantLock, virtual threads, transakcje programowe, REQUIRES_NEW, SHA-1 hash, bean validation, Jackson 3, JsonMapper, auto-configuration, preboot-core, concurrent access, cache eviction, composite key, fair lock.