aibot88
- 8.3k skills
- 0 followers
- 3 repo stars
- 2 weeks ago last updated
- ▌ Security Assistant · aibot88 bundle引导安全审查和漏洞评估,遵循 OWASP 标准。 使用时机:安全审计、漏洞检查、安全编码审查、威胁建模。 关键字:security, OWASP, vulnerability, authentication, authorization, 安全, 漏洞, 认证。
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Circleci Orb Linter · aibot88 bundleValidates CircleCI configuration files and custom Orbs using the CircleCI CLI (circleci config validate) and Orb Development Kit. Checks for deprecated images, inefficient caching strategies, and security anti-patterns.
- ▌ Csp Policy Analyzer · aibot88 bundleParses and evaluates Content Security Policy headers using csp-parse and csp-evaluator libraries. Identifies overly permissive directives, missing protections, and generates tightened policy recommendations.
- ▌ Datadog Slo Monitor · aibot88 bundleMonitors Datadog Service Level Objectives and burn rate alerts via the Datadog API v2. Generates SLO compliance reports and triggers remediation workflows when error budgets are exhausted.
- ▌ Design Architecture · aibot88 bundleDefine system architecture — components, boundaries, communication patterns, data flow, and compliance requirements.
- ▌
- ▌
- ▌ Security Issue Sync · aibot88 bundleSynchronize a security issue in <tracker> with the state of its GitHub discussion, the <security-list> mailing thread, and any <upstream> PRs that fix it. The skill gathers all relevant signals, proposes label, milestone, assignee, field and draft-email updates, and only applies changes the user has explicitly confirmed. Suggests the next step in the handling process and prints the CVE allocation link when a CVE is needed.
- ▌ Semgrep Rule Author · aibot88 bundleGenerates custom Semgrep rules from natural language descriptions of vulnerability patterns. Uses semgrep --validate to verify rule syntax and semgrep --test to run against sample code fixtures automatically.
- ▌ Semgrep Rule Engine · aibot88 bundleExecutes Semgrep static analysis using the semgrep CLI with custom YAML rule definitions. Supports taint tracking, metavariable comparisons, and pattern-not-inside exclusions for precise vulnerability detection.
- ▌ Springboot Security · aibot88 bundle中文优先:用于Spring Boot安全相关任务,帮助识别、设计、实现或验证对应工作流。English keywords: Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.
- ▌
- ▌ Supabase MCP Server · aibot88 bundleSupabase MCP Server is built around Supabase developer platform. The underlying ecosystem is represented by supabase/supabase (99,546+ GitHub stars). It gives an agent a more technical and reliable way to work with the tool than a thin one-line wrapper, using stable interfaces like PostgREST, Auth, Storage, Realtime, Edge Functions, RLS and preserving the operational context […]
- ▌ Sync Security Issue · aibot88 bundleSynchronize a security issue in <tracker> with the state of its GitHub discussion, the <security-list> mailing thread, and any <upstream> PRs that fix it. The skill gathers all relevant signals, proposes label, milestone, assignee, field and draft-email updates, and only applies changes the user has explicitly confirmed. Suggests the next step in the handling process and prints the CVE allocation link when a CVE is needed.
- ▌ Circleci Orb Auditor · aibot88 bundleAudits CircleCI orb versions and configurations using the CircleCI v2 API. Flags deprecated orbs, provides pinning recommendations, and checks security advisories from the orb registry.
- ▌ Dependency Audit NPM · aibot88 bundleAudit a JavaScript / TypeScript project (npm, pnpm, or yarn) for outdated versions, vulnerabilities, unused or missing declarations, lockfile drift, and duplicates.
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ NPM Package Analyzer · aibot88 bundleDeep analysis of npm packages using npm-registry-fetch and pacote. Evaluates bundle size via bundlephobia API, checks security advisories from npm audit, and maps dependency trees with arborist.
- ▌ Oauth2 Flow Debugger · aibot88 bundleInspects and debugs OAuth 2.0 authorization flows including PKCE, client credentials, and device code grants. Uses jose JWT library and node-fetch to validate tokens, decode claims, and trace redirect chains.
- ▌ Owasp Zap API Fuzzer · aibot88 bundleAutomates REST API security testing using the OWASP ZAP Python SDK. Runs active scans, SQL injection probes, and XSS tests against OpenAPI specs with structured vulnerability reports.
- ▌
- ▌
- ▌ Security Audit Skill · aibot88 bundleSecurity Audit Skill is built around OWASP security tooling ecosystem. The underlying ecosystem is represented by zaproxy/zaproxy (14,896+ GitHub stars). It gives an agent a more technical and reliable way to work with the tool than a thin one-line wrapper, using stable interfaces like ZAP scanning, passive/active checks, auth contexts, alerts, HTTP spidering and preserving […]
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Cloudflare Specialist · aibot88 bundleCloudflare Workers architecture specialist. Advises on D1 migrations, KV usage patterns, R2 binary distribution, wrangler configuration, and Miniflare testing. Use when modifying wrangler.toml, working with Cloudflare services, or setting up testing infrastructure.
- ▌ Meta Pipeline Creator · aibot88 bundleWrite all pipeline content in **English**, regardless of the project's primary language.
- ▌ NPM Registry Analyzer · aibot88 bundleQueries the npm registry API and npms.io scoring endpoint to evaluate package quality, maintenance scores, and download trends. Uses npm-audit for security vulnerability detection against the GitHub Advisory Database.
- ▌
- ▌ Sast Pipeline Scanner · aibot88 bundleRuns static application security testing using Semgrep rules and CodeQL queries against pull request diffs. Supports SARIF output format and integrates with GitHub Advanced Security for findings management.
- ▌
- ▌ Serpapi Scholar Agent · aibot88 bundleAutomates academic research using the SerpAPI Google Scholar endpoint. Extracts citation graphs, h-index data, and co-author networks for literature reviews. Supports BibTeX export and cross-references with Semantic Scholar API.
- ▌ Setup Auth Magic Link · aibot88 bundleMet en place un système d'authentification Magic Link (passwordless) complet pour FastAPI + React
- ▌ Vault Secrets Rotator · aibot88 bundleManages secret lifecycle through the HashiCorp Vault HTTP API v1. Rotates database credentials via Vault dynamic secrets engine and syncs to Kubernetes via External Secrets Operator CRDs.
- ▌
- ▌ Ho1ow Flow Sast MCP Skills · aibot88 bundleSpecial / Emerging Vulnerabilities Skill — flow-sast Phase 4
- ▌
- ▌ Constitution Validator · aibot88 bundleConstitution compliance validator focusing on Principle XI (No Hardcoded Values). Detects hardcoded URLs, timeouts, limits, and identifiers that should be configurable. Use proactively when implementing business logic, adding new features, or reviewing PRs for constitution compliance.
- ▌
- ▌ Dependency Audit Swift · aibot88 bundleAudit a Swift / Xcode project (Swift Package Manager and/or CocoaPods) for outdated versions, vulnerabilities, unused or missing declarations, and duplicates.
- ▌ Eslint Config Enforcer · aibot88 bundleEnforces consistent ESLint configurations across monorepo packages using eslint-config-inspector and flat config merging. Detects rule conflicts between shared configs, auto-generates override files, and reports compliance gaps via eslint --inspect-config.
- ▌ Falco Runtime Security · aibot88 bundleFalco Runtime Security is built around Kubernetes orchestration platform. The underlying ecosystem is represented by kubernetes/kubernetes (121,313+ GitHub stars). It gives an agent a more technical and reliable way to work with the tool than a thin one-line wrapper, using stable interfaces like kubectl, API server, pods, deployments, events, logs, probes, RBAC and preserving the […]
- ▌ Markuplint HTML Linter · aibot88 bundlemarkuplint is a comprehensive HTML linter designed for all markup developers. It enforces accessibility, spec compliance, and best practices across HTML, JSX, Vue, Svelte, Astro, PHP, Pug, and more template languages through a pluggable parser architecture.
- ▌ NPM Audit Deep Scanner · aibot88 bundleExtends npm audit with deep transitive dependency analysis using the npm Registry API. Generates fix PRs via GitHub API and cross-checks advisories against the OSV.dev vulnerability database.
- ▌ Obsidian Vault Manager · aibot88 bundleObsidian Vault Manager is built around HashiCorp Vault secrets platform. The underlying ecosystem is represented by hashicorp/vault (35,266+ GitHub stars). It gives an agent a more technical and reliable way to work with the tool than a thin one-line wrapper, using stable interfaces like KV v2, policies, leases, tokens, transit, dynamic secrets and preserving the […]
- ▌
- ▌
- ▌ Puppeteer PDF Renderer · aibot88 bundleGenerates pixel-perfect PDFs from web pages using Puppeteer with custom headers, footers, and page breaks. Supports authenticated pages via cookie injection.
- ▌ Pypi Package Inspector · aibot88 bundleQueries the PyPI JSON API and the libraries.io API to analyze Python package metadata, dependency trees, and version histories. Uses pip-audit for vulnerability scanning against the OSV database.
- ▌ Security Bounty Hunter · aibot88 bundle中文优先:用于安全bountyhunter相关任务,帮助识别、设计、实现或验证对应工作流。English keywords: Hunt for exploitable, bounty-worthy security issues in repositories. Focuses on remotely reachable vulnerabilities that qualify for real reports instead of noisy local-only findings.
- ▌ Reisterj Dockeragent Skills · aibot88 bundleCVE Orchestration Skill — Given only a CVE ID, this skill researches the CVE from official sources (NVD, GitHub Advisories, GitHub commit API), determines the affected repository URL, vulnerable commit, and fixing commit, then produces a structured JSON plan for the two-phase reproduction pipeline (setup_env + vuln_reproduce). USE FOR: Top-level orchestration planning. Run once per CVE before launching Phase 1. DO NOT USE FOR: Actually building Docker images or running exploits (delegate to sub-agents).
- ▌
- ▌
- ▌
- ▌
- ▌ Decision Curve Analysis · aibot88 bundle> **Source**: [https://github.com/aipoch/medical-research-skills](https://github.com/aipoch/medical-research-skills)
- ▌ Dependency Audit Dotnet · aibot88 bundleAudit a .NET / NuGet project for outdated versions, known vulnerabilities, unused or missing declarations, lockfile drift, and duplicate versions.
- ▌ Dependency Audit Python · aibot88 bundleAudit a Python project (pip, uv, Poetry, or pdm) for outdated versions, vulnerabilities, unused or missing declarations, lockfile drift, and duplicates.
- ▌
- ▌ Healthcare Eval Harness · aibot88 bundle中文优先:用于医疗评估运行框架相关任务,帮助识别、设计、实现或验证对应工作流。English keywords: Patient safety evaluation harness for healthcare application deployments. Automated test suites for CDSS accuracy, PHI exposure, clinical workflow integrity, and integration compliance. Blocks deployments on safety failures.
- ▌ Owasp Zap Scanner Agent · aibot88 bundleIntegrates the OWASP ZAP API to run automated DAST scans against web applications. Parses ZAP JSON reports, triages alerts by CVSS severity, and generates remediation tickets via Jira REST API.
- ▌ Personal Repo Bootstrap · aibot88 bundleBootstrap a new personal repo with industry-best-practice docs and defensive .gitignore. Routes by repo type (scratch / personal-published / portfolio-public). Ensures secrets/PII protection from the first commit. Triggered by 'create new repo', 'bootstrap [name]', '/repo-bootstrap'.
- ▌ Scrapycloud Job Manager · aibot88 bundleManages Scrapy spider deployments and job scheduling on ScrapyCloud via the Scrapinghub API. Handles spider argument injection, job prioritization, and item export to S3 or BigQuery.
- ▌ Security Scan Assistant · aibot88 bundle引导自动化安全扫描、依赖包审计和机密检测。 使用时机:依赖审计、CVE 扫描、机密检测、许可证合规。 关键字:scan, audit, CVE, dependency, secret, SBOM, vulnerability, 扫描, 漏洞。
- ▌ Semgrep Pattern Scanner · aibot88 bundleExecutes Semgrep CLI with custom YAML rules and the Semgrep Registry API to detect anti-patterns, vulnerabilities, and taint tracking violations. Outputs SARIF-formatted results for GitHub Security tab integration.
- ▌ Springboot Verification · aibot88 bundle中文优先:用于Spring Boot验证相关任务,帮助识别、设计、实现或验证对应工作流。English keywords: Verification loop for Spring Boot projects: build, static analysis, tests with coverage, security scans, and diff review before release or PR.
- ▌
- ▌
- ▌
- ▌ Agent Instructions Audit · aibot88 bundleAudit the project's agent / LLM instruction files for vague rules, missing examples, drifted compliance, and mechanical-enforcement opportunities.
- ▌ Agentuity CLI Auth Login · aibot88 bundleLogin to the Agentuity Platform using a browser-based authentication flow. Use for managing authentication credentials
- ▌
- ▌ Cerbos Authorization Pdp · aibot88 bundleCerbos is an open-core, language-agnostic, scalable authorization solution that makes implementing and managing user permissions simple. It uses context-aware YAML access control policies managed through Git-ops, providing high-availability APIs for dynamic access decisions across applications.
- ▌ Chezmoi Dotfiles Manager · aibot88 bundlechezmoi manages dotfiles across multiple machines securely using a Git-backed source-of-truth model with templates, encryption, and cross-platform support. Written in Go with 18k+ GitHub stars, it handles machine-specific configs, secrets, and one-command bootstrap.
- ▌ Credential Leak Detector · aibot88 bundlecredential-leak-detector — Catch Leaked Credentials Before They Spread
- ▌ Cyclonedx Sbom Generator · aibot88 bundleGenerates Software Bill of Materials in CycloneDX format using cdxgen and Syft. Scans npm, pip, and Go modules for known CVEs via OSV.dev API integration.
- ▌ Flutter Dart Code Review · aibot88 bundle中文优先:用于FlutterDart代码审查相关任务,帮助识别、设计、实现或验证对应工作流。English keywords: Library-agnostic Flutter/Dart code review checklist covering widget best practices, state management patterns (BLoC, Riverpod, Provider, GetX, MobX, Signals), Dart idioms, performance, accessibility, security, and clean architecture.
- ▌ Lasso Logistics Analysis · aibot88 bundle> **Source**: [https://github.com/aipoch/medical-research-skills](https://github.com/aipoch/medical-research-skills)
- ▌ Outlook Email Automation · aibot88 bundleAuthenticates to Microsoft Graph API using MSAL with Mail.ReadWrite and Calendars.ReadWrite permissions. Reads, classifies, and responds to emails via GET /me/messages and POST /me/sendMail. Moves processed messages into folders and tracks reply SLAs in a local SQLite store.
- ▌ Personal Pre Push Review · aibot88 bundlePre-push adversarial review for personal repos before git push. Runs adversarial-input sweep, parallel-implementation symmetry audit, project AGENTS.md compliance, dead-code sweep, secrets scan. Use before any push; mandatory for repos that will become public or shared. Tier 2 sub-agent does the bulk; Tier 3 main synthesizes.
- ▌
- ▌ Helmet · aibot88 bundleFull repo onboarding — bootstraps test infrastructure (Phase A), wires the CI/CD pipeline (Phase B), and generates a project CLAUDE.md (Phase C). Use when onboarding a new repo, setting up tests + CI from scratch, adding Codecov/pinact/SBOM/security scanning, auditing pipeline completeness, fixing CI failures, deploying pipeline changes across multiple repos, or generating/refreshing a repo's CLAUDE.md. Replaces ci-pipeline-setup and test-setup.
- ▌
- ▌
- ▌ MCP Eval · aibot88 bundleYou are the orchestrator of an MCP evaluation session. Your job is to exercise the full set of attached MCPs against user-approved scenarios, record every tool call you make (MCP and non-MCP) with honest justifications, then hand the transcript to the `friction-critic` sub-agent for adversarial review.
- ▌