aibot88
- 8.3k skills
- 0 followers
- 3 repo stars
- 2 weeks ago last updated
- ▌ Pentest Forensics · aibot88 bundleDigital forensics — evidence acquisition, memory/disk imaging analiz, timeline reconstruction, IOC extraction advisory. Triggers on forensics, DFIR, Volatility, memory analysis, disk image, Autopsy, FTK, timeline, IOC extraction, evidence chain, log analysis.
- ▌ Pfd Pid Generator · aibot88 bundleProcess flow diagram and P&ID generation skill with standards compliance and symbol libraries
- ▌ Pitfalls Security · aibot88 bundleSecurity patterns for session keys, caching, logging, and environment variables. Use when implementing authentication, caching sensitive data, or setting up logging. Triggers on: session key, private key, cache, logging, secrets, environment variable.
- ▌ Policy Management · aibot88 bundleManage corporate policy lifecycle from drafting through compliance
- ▌ Power Bi Designer · aibot88 bundleConception de dashboards Power BI — DAX, modèle de données, visualisations avancées et Row-Level Security. Se déclenche avec "Power BI", "DAX", "dashboard Power BI", "rapport Power BI", "modèle de données Power BI".
- ▌
- ▌ Privacy Generator · aibot88 bundleGenerates comprehensive privacy policies by scanning websites for data collection signals including cookies, forms, payment processors, and third-party scripts. Use when launching a website or app that collects user data and needs GDPR/CCPA compliance. Trigger with "/privacy-generator" or "create a privacy policy for my website".
- ▌ Privacy Manifests · aibot88 bundlePrivacy manifest (PrivacyInfo.xcprivacy) implementation including required reason APIs, tracking domains, third-party SDK declarations, and App Tracking Transparency. Use when preparing apps for App Store privacy requirements.
- ▌ Privy Integration · aibot88 bundleIntegrates Privy authentication, embedded wallets, and agent payment protocols into web and agentic apps. Covers React SDK (PrivyProvider, hooks, wagmi), Node.js SDK, smart wallets (ERC-4337), x402 and MPP machine payments, Tempo chain, and agentic wallets with policies. Use when setting up Privy auth, creating embedded or agentic wallets, adding x402 or MPP payments, integrating with Tempo, configuring wallet policies, or connecting Privy to MCP/Agent Auth flows.
- ▌ Product UX Expert · aibot88 bundleProduct interaction and UX expert. Use when reviewing UI/UX, conducting heuristic evaluations, designing user journeys, applying cognitive psychology principles, or ensuring WCAG 2.2 accessibility compliance.
- ▌ Property Patterns · aibot88 bundleMSBuild property definition patterns: conditional defaults, composition/concatenation, path normalization, trailing slash handling, TFM detection helpers, and property evaluation order. Only activate in MSBuild/.NET build context. USE FOR: diagnosing and fixing MSBuild property definition issues in .props or .csproj files, reviewing and fixing shared property configuration anti-patterns, fixing DefineConstants or NoWarn being overwritten instead of appended, fixing unconditional property assignments that prevent project-level overrides, fixing unquoted conditions that fail when properties are empty, fixing hardcoded paths that break cross-platform builds, setting property defaults that can be overridden, understanding property evaluation order and last-write-wins semantics. DO NOT USE FOR: props vs targets placement (use directory-build-organization), item operations (use item-management), target structure (use target-authoring), general anti-patterns (use msbuild-antipatterns), non-MSBuild build systems.
- ▌ Provider Id OAUTH · aibot88 bundleขั้นตอนการติดตั้งและตั้งค่า Provider ID OAuth (ผ่าน Health ID / moph.id.th) ด้วย Auth.js (next-auth v5) ใน Next.js App Router — ครอบคลุม: การติดตั้ง package, การสร้างปุ่ม Login, การ redirect ไปยัง OAuth Provider, การรับ callback พร้อม exchange token, การดึง profile จาก provider.id.th, และการสร้าง session ด้วย Auth.js Credentials Provider + JWT Strategy.
- ▌ Pulumi Specialist · aibot88 bundleDeep-dive Pulumi stack review, component design, Automation API audit, and secrets management. Use for structured investigations of Pulumi stack drift, ComponentResource coupling, ESC configuration, and Automation API workflows. Triggers on: "Pulumi audit", "stack review", "Automation API review", "ComponentResource design", "ESC audit", "Pulumi secrets", "Pulumi testing".
- ▌ Query Token Audit · aibot88 bundleQuery token security audit to detect scams, honeypots, and malicious contracts before trading. Returns comprehensive security analysis including contract risks, trading risks, and scam detection. Use when users ask "is this token safe?", "check token security", "audit token", or before any swap.
- ▌ Quetrex Architect · aibot88 bundleUse when implementing new features in Quetrex. Ensures TDD, TypeScript strict mode, Next.js App Router patterns, ShadCN UI components, and security best practices are followed. Updated for November 2025 standards.
- ▌ Rails Code Review · aibot88 bundleReviews Rails pull requests, focusing on controller/model conventions, migration safety, query performance, and Rails Way compliance. Covers routing, ActiveRecord, security, caching, and background jobs. Use when reviewing existing Rails code for quality, conducting a PR review, or doing a code review on Ruby on Rails (RoR) code.
- ▌ Rails Review Flow · aibot88 bundleMulti-pass Rails code review workflow that identifies bugs, security vulnerabilities, and architectural issues; assigns severity levels (Critical, Suggestion, Nice-to-have); and generates actionable review comments with a mandatory re-review loop for Critical findings. Use for full PR review workflows, multi-pass security or architecture audits, or implementing and verifying responses to review feedback. Trigger: review this PR, full code review, multi-pass review, audit security vulnerabilities, review architecture, respond to review feedback, implement review fixes.
- ▌ Ramp Install Auth · aibot88 bundleRamp install auth — corporate card and expense management API integration. Use when working with Ramp for card management, expenses, or accounting sync. Trigger with phrases like "ramp install auth", "ramp-install-auth", "corporate card API".
- ▌ Recap Integration · aibot88 bundleIntegrates the Recap Swift package into SwiftUI apps, authors Recap-compatible releases markdown, and configures RecapDisplayPolicy and RecapScreen customization. Use when adding Recap into an app, updating Releases.md, or customizing the behavior of a Recap screen.
- ▌ Reddit Post Writer · aibot88 bundleMaster authentic Reddit content generator using emotion-first, phased architecture. Creates posts that sound genuinely human through cognitive state simulation, not just rule-following. Use when the user asks to write a Reddit post, create Reddit content, or needs help with Reddit engagement. Includes adversarial committee review, Claude-ism detection, and interactive refinement workflow.
- ▌ Release Checklist · aibot88 bundleSequential release gate validating build success, test suite, security checks, type checking, manifest counts consistency, and changelog presence. Each step reports pass/fail with remediation guidance. Manages version bumping, staging, and pre-push confirmation. Use when preparing a release.
- ▌ Report Generation · aibot88 bundleFormat accessibility audit reports with severity scoring (0-100, A-F grades), scorecard computation, and compliance exports including VPAT/ACR and remediation priorities.
- ▌ REST API Patterns · aibot88 bundleUse when designing, implementing, or reviewing Salesforce REST API integration — covering CRUD operations on sObjects, SOQL-based queries, paginated result sets, Composite requests, Composite Batch, and sObject Tree. Triggers: 'Salesforce REST API', 'composite API', 'nextRecordsUrl', 'sObject Tree', 'REST CRUD', 'REST pagination', 'API limits', 'OAuth Bearer token'. NOT for GraphQL API queries, Bulk API 2.0 large-data-load jobs, Metadata API deployments, or custom Apex REST endpoints.
- ▌ Review AI Writing · aibot88 bundleDetect AI-generated writing patterns in developer text — docs, docstrings, commit messages, PR descriptions, and code comments. Use when reviewing any text artifact for authenticity and clarity.
- ▌ Review Dependency · aibot88 bundleUse for security review of dependency updates — bumps, upgrades, or new dependencies.
- ▌ Risk Engine · aibot88 bundleMotor de gestión de riesgo institucional del Financial Intelligence System. ACTÍVALO siempre antes de cualquier recomendación final de inversión, cuando el usuario presente un portafolio real, cuando el scoring board detecte disenso, o cuando se evalúe una posición de alto riesgo. Cuantifica el riesgo total del portafolio usando VaR paramétrico, histórico y Monte Carlo, analiza correlaciones entre activos, calcula el drawdown máximo esperado, verifica el cumplimiento de límites de posición, detecta concentraciones peligrosas y emite señales de alerta antes de que el CIO emita su recomendación. Es la última línea de defensa del sistema antes de recomendar al usuario.
- ▌ Robotics Security · aibot88 bundleSecurity hardening and best practices for robotic systems, covering SROS2 DDS security, network segmentation, secrets management, secure boot, and the physical-cyber safety intersection. Use this skill when securing ROS2 communications, configuring DDS encryption and access control, hardening robot onboard computers, managing certificates and credentials, setting up network segmentation for robot fleets, or addressing the unique security challenges where cyber vulnerabilities become physical safety risks. Trigger whenever the user mentions SROS2, DDS security, robot security, robot hardening, ROS2 encryption, ROS2 access control, robot network security, secure robot deployment, robot certificates, keystore generation, robot firewall, e-stop security, safety controller isolation, or IEC 62443 for robotics.
- ▌ Roundcube Webmail · aibot88 bundleReads and summarizes emails from Roundcube webmail with SAML/TOTP authentication using Playwright. Use when checking webmail, reading university email, automating Roundcube login, or setting up daily email digest via Slack/OpenClaw cron. macOS only.
- ▌ Routeros Firewall · aibot88 bundleRouterOS firewall filter, NAT, mangle, and address-list configuration. Use when: writing firewall rules in RouterOS, configuring NAT, setting up address-lists or interface-lists, writing idempotent firewall scripts, configuring DNS redirect or port forwarding, or when the user mentions /ip/firewall, chain=forward, chain=input, connection-state, address-list, interface-list, or layer7-protocol on MikroTik.
- ▌ Rwrw01 Wcag Audit · aibot88 bundleRun a WCAG 2.2 AA accessibility audit with automated and manual checks on the current project. Use for accessibility checks, a11y audits, or WCAG compliance reviews.
- ▌ Sales Clean Email · aibot88 bundleClean Email platform help — cross-platform inbox cleanup tool with bulk actions, Auto Clean rules, True Unsubscriber, Smart Folders, and Privacy Monitor ($9.99/mo or $29.99/yr, works with Gmail/Outlook/Yahoo/iCloud/any IMAP). Use when inbox is overloaded with thousands of old emails and need bulk cleanup, newsletters and promotional emails burying important messages, setting up Auto Clean rules to automatically sort incoming emails, Unsubscriber not actually removing you from mailing lists, accidentally deleted important emails during bulk cleanup, email storage full and need to free space fast, comparing Clean Email to SaneBox or Unroll.me or Mailstrom for inbox cleanup, or Privacy Monitor alerting about data breaches. Do NOT use for AI email reply drafting or voice-trained composition (use /sales-fyxer or /sales-superhuman). Do NOT use for meeting note-taking (use /sales-note-taker).
- ▌ Sales Happyscribe · aibot88 bundleHappyScribe platform help — AI + human transcription, subtitle generation, and translation in 120+ languages with SOC 2 / GDPR compliance. Use when uploading audio or video for batch transcription across many languages, generating SRT/VTT/Premiere subtitles for video production, ordering human transcription for 99% accuracy on legal or broadcast content, integrating HappyScribe REST API into a transcript pipeline, troubleshooting accuracy with accents or multiple speakers, comparing HappyScribe vs Sonix vs Rev vs Trint for media transcription, choosing between AI and human transcription tiers, or debugging export format issues. Do NOT use for live meeting recording or real-time note-taking (HappyScribe is upload-only — use /sales-note-taker for live meeting tools).
- ▌ Sales Informatica · aibot88 bundleInformatica IDMC platform help — enterprise iPaaS + data management cloud, Cloud Data Integration, Cloud Application Integration, API Center, Data Catalog, Data Quality, MDM, B2B Gateway, AI Agent Engineering, IPU consumption pricing, REST API v2/v3. Use when Informatica IDMC mapping or task keeps failing, CDI job is slow and IPU consumption is spiraling, Secure Agent is offline or can't reach source systems, REST V2 connector won't authenticate to a REST API, evaluating Informatica vs Boomi vs MuleSoft vs Talend, migrating off PowerCenter to IDMC, or configuring MDM golden records and match rules. Do NOT use for simple Zapier/Make automations (use /sales-integration) or Boomi-specific questions (use /sales-boomi).
- ▌ Sales Parsestream · aibot88 bundleParseStream platform help — multi-platform keyword monitoring across Reddit, X, LinkedIn, Quora, and Hacker News with AI reply drafts and auto-reply via Reddit OAuth. Use when ParseStream alerts are returning too much noise and you need to narrow keywords or subreddits, AI-generated replies sound robotic and don't match your brand voice, auto-reply timing feels unnatural and you're worried about Reddit spam detection, you're not getting email notifications for keywords you know are being discussed, you want to monitor multiple platforms but only see results from one, you need to restrict monitoring to specific subreddits or exclude communities, or you're comparing ParseStream vs KeyMentions vs RedShip vs Syften for multi-platform monitoring. Do NOT use for social listening strategy across tools (use /sales-social-listening) or choosing between monitoring platforms (use /sales-social-listening).
- ▌ Sales Proton Mail · aibot88 bundleProton Mail platform help — privacy-first encrypted email with end-to-end encryption, zero-access architecture, Hide-my-Email aliases, Proton Mail Bridge for IMAP/SMTP, bundled Calendar/Drive/VPN/Pass (Free 1GB / Mail Plus ~$4/mo / Unlimited ~$10/mo, Swiss-based, 100M+ users). Use when setting up Proton Mail and migrating from Gmail or Outlook with Easy Switch, Proton Mail Bridge not connecting to Thunderbird or Apple Mail or Outlook, encrypted search not finding old emails you know exist, storage filling up on the free plan and wondering whether to upgrade, comparing Proton Mail to Tuta or Fastmail or Hey for privacy email, using Hide-my-Email aliases to reduce spam, wondering if Proton Mail works with third-party apps or automation tools, or evaluating Proton Mail for a small business with custom domains. Do NOT use for AI email drafting or inbox triage (use /sales-superhuman or /sales-shortwave). Do NOT use for team shared inbox with ticketing (use /sales-hiver or /sales-missive).
- ▌ Sales Resourcefyi · aibot88 bundleResource.fyi platform help — curated tools and resources directory for developers, designers, and marketers with 2,500+ listings across 25+ categories (AI, API, Design, Dev Tools, Marketing, No-Code, Web3). Covers free submission process (editorial review, social auth via Google/GitHub), community features (upvoting, bookmarking, trending), listing optimization for developer/designer audience, and category selection. Use when your dev tool needs more visibility with developers and designers, your Resource.fyi listing isn't getting traction, or you want to reach a technical audience through a curated directory. Do NOT use for multi-directory launch strategy (use /sales-launch-directory). Do NOT use for Product Hunt launches (use /sales-producthunt).
- ▌ Sales Startupbase · aibot88 bundleStartupBase platform help — community-driven startup discovery directory with free dofollow backlinks (DR39). Covers submission process (social auth, tech startups only), review queue (2-3 months free, 24-hour premium), selection criteria (custom domain, public product, never previously featured), weekly Spark newsletter, market categories, and comparison with other directories. Use when your startup needs more visibility and early adopter traffic, you want the DR39 dofollow backlink from StartupBase, your submission keeps getting rejected, or the review queue is taking too long. Do NOT use for multi-directory launch strategy (use /sales-launch-directory). Do NOT use for Product Hunt launches (use /sales-producthunt).
- ▌ Sc Path Traversal · aibot88 bundlePath traversal and directory traversal detection — LFI, RFI, zip slip, and symlink attacks
- ▌ Sdd Uc Spec Write · aibot88 bundleRédige et met à jour les spécifications SDD par cas d'utilisation (UC) : spec racine (projet principal) ou spec d'extension (fonction ajoutée à une racine existante). Exploitable par des agents IA. En CLI écrit dans docs/, sur claude.ai livre des artefacts Markdown. S'active dès qu'on demande une spec SDD, à formaliser des UC, ou à étendre une spec racine.
- ▌ Secure Code Write · aibot88 bundleProactive secure-coding coach scoped to the file or topic you are working on — surfaces relevant SAST rule IDs, CWE patterns, language-specific PASS/FAIL code snippets. Use when about to write auth, crypto, SQL, deserialization, file-handling, or template code; coaching juniors; pair-programming a security-sensitive change.
- ▌ Web3 Security Analysis · aibot88 bundleAnalyze Web3 security risks with SpoonOS agents. Use when checking token safety (honeypots, rugs), simulating transactions, detecting MEV, or auditing contracts.
- ▌ Security Analyzer · aibot88 bundleComprehensive security vulnerability analysis for codebases and infrastructure. Scans dependencies (npm, pip, gem, go, cargo), containers (Docker, Kubernetes), cloud IaC (Terraform, CloudFormation), and detects secrets exposure. Fetches live CVE data from OSV.dev, calculates risk scores, and generates phased remediation plans with TDD validation tests. Use when users mention security scan, vulnerability, CVE, exploit, security audit, penetration test, OWASP, hardening, dependency audit, container security, or want to improve security posture.
- ▌ Security Auditing · aibot88 bundle[METHODOLOGY] Comprehensive security analysis against OWASP Top 10 standards (authentication, user input, database queries, external APIs). Preloaded by security-auditor agent.
- ▌ Security Baseline · aibot88 bundleEstablish a security baseline for a website or web app. Use this skill when configuring HTTPS and TLS, setting security headers, planning secrets management, evaluating CSP policies, doing a basic security audit, or hardening a site before launch. Triggers on security headers, HTTPS, TLS, CSP, content security policy, HSTS, secrets management, vulnerability scan, security audit, harden, OWASP, security baseline. Also triggers when a security review is required for compliance or before going live.
- ▌ Security Engineer · aibot88 bundleSEOcrawler security vulnerability scanner and hardening specialist for comprehensive security audits.
- ▌ Security Guardian · aibot88 bundleExpert en sécurité applicative pour détecter les vulnérabilités, auditer le code, et guider les bonnes pratiques de sécurité. OWASP Top 10, authentification, autorisation, cryptographie, gestion de secrets. Utiliser pour audits sécurité, reviews de code sensible, conception de features sécurisées, ou résolution de failles.
- ▌ Agent Security Hardener · aibot88 bundleSécurisation d'agents IA contre injections, abus et fuites de données. Se déclenche avec "sécurité agent", "agent security", "prompt injection", "jailbreak", "agent abuse", "guardrails", "safe agent", "sécuriser mon agent", "agent en production sécurisé".
- ▌ Security Patterns · aibot88 bundleSecurity patterns and OWASP guidelines. Triggers on: security review, OWASP, XSS, SQL injection, CSRF, authentication, authorization, secrets management, input validation, secure coding.
- ▌ Security Reviewer · aibot88 bundleIdentifies security vulnerabilities, generates structured audit reports with severity ratings, and provides actionable remediation guidance. Use when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security. Invoke for SAST scans, penetration testing, DevSecOps practices, cloud security reviews, dependency audits, secrets scanning, or compliance checks. Produces vulnerability reports, prioritized recommendations, and compliance checklists.
- ▌ Security Scanning · aibot88 bundleAgentShield security audit with 5 scanning categories, 102 static analysis rules, and optional red-team simulation.
- ▌ Security Sentinel · aibot88 bundleUse when working with authentication, API routes, user input, or sensitive data. Audits code for security vulnerabilities based on OWASP Top 10. Critical for payment processing, auth systems, and data handling.
- ▌ Security Snapshot · aibot88 bundleGenerate a client-ready security hygiene snapshot for a prospect domain. Free lead magnet for consulting practices. Outputs a markdown report covering SSL/TLS grade, HTTP security headers, email authentication (SPF/DMARC), and server fingerprint leaks. Use when the user says /security-snapshot, /snapshot [domain], "run a security check on X", or "generate a security report for [company]". Do NOT use for penetration testing, internal infrastructure audits, or application-layer vulnerability assessment. This is a passive, unauthenticated scan for conversation-starter value, not a full audit.
- ▌ Server Side Swift · aibot88 bundleServer-side Swift development with Vapor and Hummingbird. Covers project setup, routing, Fluent ORM, authentication, deployment, and shared client-server code. Use when building backends or APIs in Swift.
- ▌ Skill Generalizer · aibot88 bundleUse when turning local, private, or personal Agent Skills into publishable skills for GitHub, marketplaces, teams, or public sharing, especially when private paths, personal habits, credentials, internal hosts, or user-specific context must be removed.
- ▌ Skill Permissions · aibot88 bundleSkill permission analysis, one-time authorization, analyze skill permissions, batch authorization
- ▌
- ▌ Bookshelf4md Author · aibot88 bundleBookshelf4MD形式の教科書・勉強教材Markdownドキュメントを作成します。フロントマターの設定、##でのページ分割、画像・動画のパス指定、コードブロックの記述など、AI_GUIDELINE.mdに沿った形式で出力します。ユーザーが「〜の教科書を作って」「〜の教材を書いて」「〜の技術書を作成」「ドキュメントを作成して」などと依頼したときや、教育コンテンツ、学習教材、技術書の執筆を依頼されたときに使用してください。
- ▌ Skillpack Harvest · aibot88 bundleLift a proven skill from a host repo (e.g. your OpenClaw fork) back into gbrain's bundle so other clients can scaffold it. Editorial workflow: the CLI does the file copy + privacy lint; this skill drives the judgment-heavy genericization (scrub real names, generalize triggers, lift fork-specific conventions to references).
- ▌ Small Claims Prep · aibot88 bundleAide à préparer un petit litige (consommation, voisinage, facture contestée) avec dossier structuré. Se déclenche aussi avec "petit litige", "tribunal", "facture contestée", "arnaque", "remboursement refusé", "voisinage", ou toute préparation de recours pour un litige courant.
- ▌ Running Smoke Tests · aibot88 bundleThis skill runs smoke tests to verify critical application functionality. It executes pre-defined test suites that check system health, authentication, core features, and external integrations. Use this skill after deployments, upgrades, or significant configuration changes to ensure the application is operational. Trigger this skill using the terms "smoke test" or "st".
- ▌ Soc Analyst Guide · aibot88 bundleGuide pour analyste SOC — triage d'alertes, investigation, SIEM, indicateurs de compromission et playbooks de réponse. Se déclenche avec "SOC", "analyste SOC", "SIEM", "IoC", "incident de sécurité", "triage sécurité".
- ▌ Soc User Research · aibot88 bundleDesign and conduct user research using interviews, focus groups, surveys, and field observation. Use this skill when the user needs to understand customer needs, validate product assumptions, gather qualitative insights, or design a research study — even if they say 'we need to talk to users', 'how do we validate this idea', or 'what do our customers actually think'.
- ▌ Social Psychology · aibot88 bundleHow individuals think about, influence, and relate to one another. Covers conformity (Asch line experiments, informational vs. normative influence), obedience (Milgram experiments, situational factors), attitudes (formation, change, cognitive dissonance, persuasion), group dynamics (groupthink, social facilitation, social loafing, deindividuation), and prejudice (stereotyping, implicit bias, stereotype threat, intergroup conflict, contact hypothesis). Use when analyzing social influence, group behavior, attitude formation, prejudice, or interpersonal processes.
- ▌ Solai Flow Editor · aibot88 bundleEdit live Contextual flows in the Flow Editor — add, change, move, wire, delete, rename, configure, group, copy, or validate nodes / wires / properties / code in a flow open in the user's browser. Also the source-of-truth for node-level behavior, configuration, and authoring patterns — function-node logging (`await logger.*`), loop wiring, Native Object node TypedInput patterns, `http-response` status precedence, etc. (see `node-reference.md`). Required before any `mcp__ctxl-flow-editor__*` call other than `info`/`list_sessions` orientation. Use AFTER planning; do NOT plan architecture here — use plan-flow first.
- ▌ Sonarcloud Triage · aibot88 bundleTriage SonarCloud issues and hotspots via the SonarCloud Web API — check gate status, list open BLOCKER/CRITICAL bugs + vulns, group hotspots by rule, bulk-mark hotspots Safe per rule, transition issues to False Positive, and change the New Code period. Use whenever the user mentions SonarCloud, Sonar, quality gate red/failing, code smells to triage, marking hotspots safe, marking issues as false positive, setting new code period, or asks "why is the Sonar gate red" — even if they only reference a specific rule like go:S2245 without naming SonarCloud.
- ▌ Specialist Review · aibot88 bundleConducts a focused review from ONE specific specialist's perspective (e.g., Security Specialist, Performance Expert). Use when the user requests "Ask [specialist role] to review [target]", "Get [specialist]'s opinion on [topic]", "Have [role] review [code/component]", or when they want deep expertise in ONE specific domain. Do NOT use for comprehensive multi-perspective reviews (use architecture-review instead) or for listing available specialists (use list-members instead).
- ▌ Staff Code Review · aibot88 bundleStaff-engineer-level code review that goes beyond correctness to evaluate architectural alignment, system-level implications, failure modes, performance, scalability, backward compatibility, observability, security, and cross-team impact. Use when reviewing a PR (URL or diff), analyzing code changes for architectural fitness, or when the user asks for a thorough/staff-level/senior review of code changes. Triggers on "review this PR", "review these changes", "staff review", "thorough code review", sharing a GitHub PR URL for review, or asking about the architectural impact of changes.
- ▌ Statutory Auditor · aibot88 bundleनेपाली नियमित लेखा परीक्षण (statutory audit under NCA Act 2053)। NFRS अनुपालन, ब्यालेन्स शीट / P&L सत्यापन, लेखा परीक्षण मत। Statutory audit under NCA Act 2053. NFRS compliance, balance sheet/P&L verification, audit opinion. Use for audit planning, NFRS compliance checks, or audit report generation.
- ▌ Structured Code Review · aibot88 bundlePerforms a structured five-stage code review covering requirements compliance, correctness, code quality, testing, and security/performance. Each stage uses targeted checklists and categorized feedback (Blocker/Major/Minor/Nit) with actionable suggestions and rationale. Use when the user asks for code review, PR feedback, pull request review, or wants their code checked for bugs, style issues, or vulnerabilities — triggered by phrases like "review my code", "check this PR", "review my changes", "pull request review", or "code feedback".
- ▌ Supabase Patterns · aibot88 bundleGeneric Supabase best practices for Row Level Security, realtime subscriptions, storage, and edge functions. Framework-agnostic.
- ▌ Supabase Projects · aibot88 bundleThis skill should be used when managing Supabase projects or organizations, creating new projects, listing projects, checking project status, retrieving API keys, pausing or restoring projects, or working with project costs and billing. Trigger when: "create Supabase project", "list Supabase projects", "Supabase API keys", "pause project", "restore project", "Supabase organization", "project cost", "get project URL", "publishable key", "secret key", "anon key", "service role key", "asymmetric JWT", "JWT signing keys", "key rotation", "supabase link", "project settings", or managing Supabase project lifecycle.
- ▌ Supabase Realtime · aibot88 bundleThis skill should be used when working with Supabase Realtime, setting up database change listeners, implementing presence, using broadcast channels, or building real-time features. Trigger when: "Supabase Realtime", "realtime subscription", "listen for changes", "database changes", "broadcast", "presence", "WebSocket", "channel", "real-time updates", "subscribe to table", "Postgres changes", "supabase.channel", "realtime configuration", "realtime authorization", "broadcast from database", "realtime.broadcast_changes", "private channel", or implementing any live/real-time functionality with Supabase.
- ▌ Supabase Security · aibot88 bundleAudit de sécurité complet pour les projets Supabase. Lance un pentest automatisé qui vérifie RLS, buckets, auth, keys exposées, et génère un rapport avec remediation. Utiliser quand l'utilisateur dit "audit supabase", "sécurité supabase", "vérifier mon supabase", ou veut s'assurer que son backend Supabase est sécurisé.
- ▌ Teamwork Exporter · aibot88 bundleAutomatically export audit findings, security issues, performance problems, or accessibility violations to Teamwork tasks when other agents complete their analysis. Converts technical findings into actionable project management tasks with appropriate priorities and templates. Invoke when audit agents finish reports, user says "export to Teamwork", or findings need project tracking.
- ▌ Telemetry Inspect · aibot88 bundleInspects the OrchestKit telemetry pipeline for the current project — lists all known telemetry files with write counts, sizes, schema status, growth trend, and orphan detection. Use when verifying the observability pipeline is healthy, debugging a missing writer, or auditing which files have schema locks vs. which are drift-vulnerable. Read-only — never modifies telemetry files.
- ▌ Telnyx 10dlc Curl · aibot88 bundle10DLC brand and campaign registration for US A2P messaging compliance. Assign phone numbers to campaigns.
- ▌ Telnyx 10dlc Java · aibot88 bundle10DLC brand and campaign registration for US A2P messaging compliance. Assign phone numbers to campaigns.
- ▌ Telnyx 10dlc Ruby · aibot88 bundle10DLC brand and campaign registration for US A2P messaging compliance. Assign phone numbers to campaigns.
- ▌
- ▌ The Knowledge Guy · aibot88 bundleKnowledge router AND interactive teacher across every book-derived skill in this project. Two modes — (1) **ask**: auto-discovers all domain skills (finance, vuln hunting, AI security, red-teaming, personal growth, ...), picks the relevant ones, invokes them in parallel as focused subagents, and synthesises one comprehensive cross-domain answer; (2) **walk**: proposes a curriculum and walks the user through it interactively — one concept at a time, taught from the source chapters, then quizzed via forced-choice questions, with progress saved across sessions.
- ▌ Thinking Red Team · aibot88 bundleDeliberately attack your own plans, systems, and assumptions to find weaknesses before adversaries or reality does. Use for security review, architecture validation, plan stress-testing, and pre-launch preparation.
- ▌ Titan Memory Loom · aibot88 bundleInitialize or update Titan Memory Loom records as candidate memory with source refs, confidence, and authority warnings. Use when a Titan service-cohort route needs this explicit bounded step. Do not use for hidden background agents, silent mutation, unreviewed proof sovereignty, or memory canonization without owner confirmation.
- ▌ Toolhive CLI User · aibot88 bundleGuide for using ToolHive CLI (thv) to run and manage MCP servers and skills. Use when running, listing, stopping, building, or configuring MCP servers locally. Covers server lifecycle, registry browsing, secrets management, client registration, groups, container builds, exports, permissions, network isolation, authentication, and skill management (install, uninstall, list, info, build, push, validate). NOT for Kubernetes operator usage or ToolHive development/contributing.
- ▌ Trace And Isolate · aibot88 bundleApplies systematic tracing and isolation techniques to pinpoint exactly where a bug originates in code. Use when a bug is hard to locate, code is not working as expected, an error or crash appears with unclear cause, a regression was introduced between recent commits, or you need to narrow down which component, function, or line is faulty. Covers binary search debugging, git bisect for regressions, strategic logging with [TRACE] patterns, data and control flow tracing, component isolation, minimal reproduction cases, conditional breakpoints, and watch expressions across TypeScript, SQL, and bash.
- ▌ Txt Writing Tools · aibot88 bundleIntegrate Writing Tools into UITextView, NSTextView, custom UITextInput views, or fully custom editors via UIWritingToolsCoordinator. Configure writingToolsBehavior and allowedWritingToolsResultOptions, declare protected ranges via writingToolsIgnoredRangesInEnclosingRange, gate edits with isWritingToolsActive, and pause syncing in willBegin/didEnd. Trigger on 'Apple Intelligence rewrite', 'AI summarize selection', 'compose with AI', 'why won't Writing Tools appear', or 'rewrite is breaking my code blocks' even without UIWritingToolsCoordinator named. Use when Writing Tools is missing from the menu, only the panel mode appears, rewrites corrupt code blocks, the inline animation isn't running, or a custom text engine needs to adopt UIWritingToolsCoordinator. Do NOT use for diagnosing general TextKit 1 fallback symptoms — see txt-fallback-triggers.
- ▌ Typescript Review · aibot88 bundleReview TypeScript and JavaScript code changes for compliance with Metabase coding standards, style violations, and code quality issues. Use when reviewing pull requests or diffs containing TypeScript/JavaScript code.
- ▌ Ultimate Protocol Simulator · aibot88 bundleUse this skill ALWAYS when the user explicitly requests "ultimate mode", "max efficiency", "binary mode", or asks you to write code with literally zero English output. This forces the agent into a non-human syntax protocol.
- ▌ Us Hipaa Security · aibot88 bundleHIPAA Security Rule expert for US healthcare compliance. Deep knowledge of 45 CFR Part 164 Subpart C, Administrative/Physical/Technical Safeguards, Required vs Addressable specifications, Risk Analysis, Business Associate Agreements, and HHS OCR enforcement.
- ▌ Ring Using Lib Commons · aibot88 bundleDual-mode skill for github.com/LerianStudio/lib-commons v5, Lerian's shared Go library — the non-observability surface. Sweep Mode dispatches parallel explorers to detect DIY implementations that should use lib-commons, with file:line replacement precision. Reference Mode catalogs lib-commons packages for lifecycle (Launcher), outbox repository, circuit breakers, tenant management, idempotency, security/TLS, database, messaging, HTTP toolkit. Observability (log, metrics, tracing, assertions, panic recovery, redaction) moved out of lib-commons into lib-observability v1.0.0 — see [[using-lib-observability]] and its sub-skills [[using-tracing]], [[using-runtime]], [[using-assert]]. Skip for non-Go code or Ring itself.
- ▌ Vbs Scan Security · aibot88 bundleUse when scanning code for security vulnerabilities. Use when user says "scan security", "kiểm tra bảo mật", "security audit", "review security", or invokes `/vbs-scan-security`. For large scans (>20 main-language files OR >30 total OR >14 days) processes chunks sequentially. Outputs bilingual reports (vi/en).
- ▌ Gdd Watch Authorities · aibot88 bundleFetches the design-authority feed whitelist, diffs against .design/authority-snapshot.json, and writes .design/authority-report.md (consumed by /gdd:reflect). Authority monitoring only — no trend-watching.
- ▌ Watch Marketplace · aibot88 bundlePoll the Anthropic plugin marketplace manifest until "channelhub" appears, then notify the user. Use when waiting for the security review to land — the submission portal shows "Published" before the public manifest is updated.
- ▌ Web Accessibility · aibot88 bundleImplement web accessibility (a11y) standards following WCAG 2.1 guidelines. Use when building accessible UIs, fixing accessibility issues, or ensuring compliance with disability standards. Handles ARIA attributes, keyboard navigation, screen readers, semantic HTML, and accessibility testing.
- ▌ Web2 Vuln Classes · aibot88 bundleComplete reference for 18 web2 bug classes with root causes, detection patterns, bypass tables, exploit techniques, and real paid examples. Covers IDOR, auth bypass, XSS, SSRF (11 IP bypass techniques), SQLi, business logic, race conditions, OAuth/OIDC, file upload (10 bypass techniques), GraphQL, LLM/AI (ASI01-ASI10 agentic framework), API misconfig, ATO taxonomy, SSTI, subdomain takeover, cloud/infra misconfigs, HTTP smuggling, cache poisoning. Use when hunting a specific vuln class or studying what makes bugs pay.
- ▌ Website Publisher · aibot88 bundleManage your author website — auto-publish books on completion, draft blog posts from your projects, render and deploy with one command
- ▌ Wireshark Analyst · aibot88 bundleAnalyse de trafic réseau avec Wireshark incluant capture, filtres, protocoles et diagnostic réseau. Se déclenche avec "Wireshark", "capture réseau", "analyse de trafic", "pcap", "packet capture", "tcpdump"
- ▌ Workflow Tdd Plan Plan · aibot88 bundleUnified TDD workflow skill combining 6-phase TDD planning with Red-Green-Refactor task chain generation, and 4-phase TDD verification with compliance reporting. Triggers on "workflow-tdd-plan", "workflow-tdd-verify".
- ▌ Wp Course Builder · aibot88 bundleSkill chuyên dụng để tạo trang web khóa học WordPress hoàn chỉnh với custom theme: Google Auth, hệ thống bài học + video Drive bảo mật, VIP membership, khóa/mở bài, khuyến mãi, admin chuyên nghiệp. Đã thực chiến với dự án Goveoai Edu.
- ▌ Wpf Mvvm Scaffold · aibot88 bundleGenerate WPF MVVM architecture with ViewModelBase, RelayCommand, INotifyPropertyChanged, and dependency injection setup
- ▌ Cls Certify · aibot88 bundleCocoLoop Safe (CLS) Skill 安全认证。对 Agent Skills 进行六维深度安全分析(静态代码、动态行为、依赖审计、网络流量、隐私合规、威胁情报),输出 S+/S/A/B/C/D 等级评估和 HTML/PDF 可视化报告。使用当用户需要检查 skill 安全性、验证 skill 是否可信、分析 skill 代码安全性、评估 skill 风险等级时。