aibot88
- 8.3k skills
- 0 followers
- 3 repo stars
- 2 weeks ago last updated
- ▌ Slither Analysis · aibot88 bundleExpert integration with Slither static analyzer for smart contract vulnerability detection, code quality analysis, and security reporting. Supports all Slither detectors and custom analysis configurations.
- ▌ Spec Kit Specify · aibot88 bundleUse when a Spec Kit feature needs `spec.md` authored or rewritten from natural-language requirements, especially when the feature has no usable specification or requirements are too vague for planning.
- ▌ Spring Boot Core · aibot88 bundleSpring Boot 4.0 + Java 25 development - auto-configuration, starters, Actuator, profiles, externalized config, security, and production patterns. Use when building backend apps, creating endpoints, configuring Spring, or asking "how do I set up X?"
- ▌ Spring Framework · aibot88 bundleExpert guidance for Spring Framework and Spring Boot development with Java best practices, dependency injection, and RESTful API design
- ▌ Stateramp Expert · aibot88 bundleStateRAMP expert for state and local government cloud services. Deep knowledge of State Risk and Authorization Management Program including Low/Moderate impact levels, NIST 800-53 controls, state-specific requirements, FedRAMP alignment, and multi-state authorization strategies.
- ▌ Statute Analysis · aibot88 bundleStatute and regulation interpretation framework. Use when reading statutes, classifying requirements, analyzing operative keywords, applying canons of construction, or mapping compliance obligations from legislative text.
- ▌ Stitch Shadcn UI · aibot88 bundleIntegrates shadcn/ui into React apps generated from Stitch designs. Component discovery and installation, token alignment with Stitch design system, customization patterns, and blocks (auth, dashboard, sidebar). Use with stitch-react-components or stitch-nextjs-components.
- ▌ Store Publishing · aibot88 bundleProvides App Store and Google Play publishing requirements, metadata management, screenshot specifications, review guidelines, and compliance requirements. Use when user asks about publishing apps, store requirements, app review, or store metadata.
- ▌ System Architect · aibot88 bundleSystem architecture skill for designing scalable, maintainable software systems. Covers microservices/monolith decisions, API design, DB selection, caching, security, and scalability planning.
- ▌ Target Authoring · aibot88 bundleCanonical patterns for writing custom MSBuild targets. Only activate in MSBuild/.NET build context. USE FOR: diagnosing and fixing custom target authoring anti-patterns, reviewing MSBuild target definitions for correctness, diagnosing broken SDK target chains across files (e.g., Directory.Build.targets silently redefining SDK targets), fixing targets that replace CompileDependsOn instead of extending it with $(CompileDependsOn), fixing query targets that return stale results due to Outputs vs Returns misuse, fixing missing Inputs/Outputs causing unnecessary rebuilds, fixing missing FileWrites registration. Covers DependsOnTargets vs BeforeTargets vs AfterTargets, the Build→CoreBuild three-level pattern, hooking into the build pipeline, the $(XxxDependsOn) chain-extension pattern. DO NOT USE FOR: incremental build tuning (use incremental-build), parallelization (use build-parallelism), general anti-patterns (use msbuild-antipatterns), non-MSBuild build systems.
- ▌ Target Profiling · aibot88 bundleResearch and build a target system profile via SSH — discovers OS, services, users, network baseline, and security stack
- ▌ Theory Of Change · aibot88 bundleConstrói teoria da mudança (insumos → atividades → resultados → impactos) e deriva indicadores de monitoramento com desagregações por grupo vulnerabilizado. Para planejamento de políticas, programas e projetos de impacto social.
- ▌ Ultimate SEO Geo · aibot88 bundleAudits and optimizes websites for search engine visibility (SEO) and AI search citation (GEO), covering technical health, E-E-A-T content scoring, domain authority, structured data, rich results, and entity signals. Use when running SEO audits, diagnosing traffic drops or ranking losses, generating Schema.org JSON-LD, checking Core Web Vitals, crawlability, robots.txt, sitemaps, hreflang, backlinks, planning content strategy or site migrations, fixing indexing issues, or optimizing for AI Overviews, ChatGPT, and Perplexity. NOT for paid ads (PPC/SEM), social media strategy, email marketing, or general web development unrelated to search.
- ▌ Unichem Database · aibot88 bundleCross-reference compound IDs across 50+ databases (ChEMBL, DrugBank, PubChem, ChEBI, PDB, KEGG) via UniChem REST API. Resolve InChIKeys to source IDs, find structurally related compounds by connectivity, batch-translate between naming systems. No auth required.
- ▌ Us Export Expert · aibot88 bundleUS Export Controls expert covering ITAR and EAR. Provides comprehensive guidance on defense articles (USML), dual-use commercial items (CCL), jurisdiction determination, FIPS encryption, denied party screening, and cloud compliance strategies.
- ▌ Using Pandastack · aibot88 bundleUse at the start of any session — establishes the cognitive contract that pandastack skills must be checked BEFORE any response or action, including clarifying questions.
- ▌ Validate Trigger · aibot88 bundleAudit an existing Sim webhook trigger against the service's webhook API docs and repository conventions, then report and fix issues across trigger definitions, provider handler, output alignment, registration, and security. Use when validating or repairing a trigger under `apps/sim/triggers/{service}/` or `apps/sim/lib/webhooks/providers/{service}.ts`.
- ▌ Validator Expert · aibot88 bundleValidate production readiness of Vertex AI Agent Engine deployments across security, monitoring, performance, compliance, and best practices. Generates weighted scores (0-100%) with actionable remediation plans. Use when asked to validate a deployment, run a production readiness check, audit security posture, or verify compliance for Vertex AI agents. Trigger with "validate deployment", "production readiness", "security audit", "compliance check", "is this agent ready for prod", "check my ADK agent", "review before deploy", or "production readiness check". Make sure to use this skill whenever validating ADK agents for Agent Engine.
- ▌ Helper Skill · aibot88 bundleGeneralist agent that plans, browses, executes shell commands, and writes files.
- ▌ Wasm Performance · aibot88 bundleWebAssembly performance: wasm-opt binary optimization, size reduction (panic=abort, LTO, strip), profiling WASM in Chrome DevTools, memory management (linear memory, avoiding GC pressure), SIMD, and multi-threading with SharedArrayBuffer.
- ▌ Web Backend Spec · aibot88 bundleAugment a sprint's SPEC.md with a Backend section (API contract, data model changes, authn/authz, validation, observability, contract test plan) tailored to the detected stack (Express/Fastify/Next/FastAPI/Django/Go/Rails/etc). Coordinator-only — does not write production code. Pauses for user confirmation. Run before /magi:tasks.
- ▌ Web Lina Pay Sdk · aibot88 bundleDocumentação e integração do pacote npm @lina-openx/web-lina-pay-sdk (Lina OpenX / Open Finance). Use este skill sempre que o utilizador pedir ajuda com este SDK: exemplos de chamadas, payloads TypeScript, tipos exportados, fluxos de consentimento, payment request, getPaymentRequest, pagamento OAuth, enrollment e FIDO, participantes, configure / ambientes IAM e API, LinaPayError, ou organização do repo web-lina-pay-sdk. Inclua também pagamento automático/recorrente: createAutomaticPaymentRequest, getAutomaticPaymentRequest, CreateAutomaticPaymentRequest, AutomaticPaymentRequestCreated, GetAutomaticPaymentRequest, AutomaticPaymentRequest, autenticação com LinaPayCredentials ou TokenCredentials (access_token direto, sem IAM no SDK para esse fluxo), sweeping/automatic. Inclua contas de recebimento e identificadores bancários (ISPB): createReceivingAccount, listReceivingAccounts, getReceivingAccount, updateReceivingAccount, deleteReceivingAccount, getBankIdentifiers, getBankIdentifier, tipos ReceivingAccount, Ban
- ▌ Website Analysis · aibot88 bundleCreator-first website analysis skill. Dual-lens (Creator View + Engineer View) three-tier (Quick/Standard/Deep) analysis of arbitrary websites with superpowers-chrome extraction, compliance gates, and multi-mode operation (Page/Site/Expedition/Cross-site).
- ▌ Woningwaarde MCP · aibot88 bundleGebruik deze skill wanneer de gebruiker de huidige (geschatte) waarde van een woning wil berekenen op basis van aankoopprijs, aankoopjaar, aankoopkwartaal en provincie. Activeer ook wanneer gevraagd wordt naar waardeontwikkeling van een huis, hoeveel een woning nu waard is ten opzichte van de aankoop, of wanneer termen vallen als woningwaarde, waardestijging, WOZ-schatting, huizenprijsindex of vastgoedwaarde berekenen. Claude roept de Kadaster vastgoedcalculator API direct aan — geen MCP-tool nodig.
- ▌ Wordpress Server · aibot88 bundleWordPress server optimization — Nginx config, PHP 8.3-FPM tuning, Redis object caching, WP Rocket, security hardening, staging, multisite
- ▌ Myco Write Myco Skill · aibot88 bundleCreate and validate a Myco-managed SKILL.md file using vault_write_skill. Use when authoring a new skill from scratch, updating an existing skill, or fixing a skill that failed the quality gate. Applies whenever you need to produce a valid .agents/skills/<name>/SKILL.md file that passes structural validation. Also load when vault_write_skill returns a rejection error — the error message identifies the failing constraint, but this skill explains the full field contract and the known contamination pitfalls.
- ▌ Xgboost Analysis · aibot88 bundleUse when building XGBoost models on tabular data and returning feature importance ranking outputs. Supports binary classification and regression with automatic task detection, train-test split, performance tables, feature importance ranking tables, and PNG importance plots.
- ▌ Yukyu Compliance · aibot88 bundleAsistente especializado en normativa japonesa de vacaciones pagadas (有給休暇) y cumplimiento laboral
- ▌ Codomyrmex · aibot88 bundleFull-spectrum coding workspace skill providing ~600 production MCP `@mcp_tool` lines across 128 top-level modules. USE WHEN user says 'verify codomyrmex', 'codomyrmexVerify', 'audit codomyrmex', 'trust codomyrmex', 'codomyrmexTrust', 'trust tools', 'enable destructive tools', 'check pai status', 'codomyrmex tools', 'codomyrmex analyze', 'codomyrmex search', 'codomyrmex memory', 'codomyrmex docs', 'codomyrmex status', 'codomyrmex git', 'codomyrmex security', 'codomyrmex ai', 'codomyrmex code', 'codomyrmex data', 'codomyrmex deploy', 'codomyrmex test', or uses any 'codomyrmex' automation tools.
- ▌ Spark · aibot88 bundleDevOps operations via the SPARK CLI. Use when the user asks about repo status, security auditing, system cleanup, port conflicts, SSL certificates, or managing dev tool updates. Trigger on: "are my repos up to date", "check for secrets", "audit the code", "clean up disk", "what port is running on", "check certs", "update my tools", "which repos need a pull", "find repo", "tag repos". Also trigger before commits (security check) and before deploys (status check).
- ▌ Composio Toolkit Integraci N De Servicios Para Agentes Ia · aibot88 bundleGuía técnica completa para integrar 250+ servicios externos con agentes IA usando Composio. Cubre instalación, autenticación OAuth, gestión de herramientas, triggers y flujos multi-servicio.
- ▌ 1k Code Review Pr · aibot88 bundleComprehensive PR code review for OneKey monorepo. Use when reviewing PRs, code changes, or diffs — covers security (secrets/PII leakage, supply-chain, AuthN/AuthZ), code quality (hooks, race conditions, null safety, concurrent requests), and OneKey-specific patterns (Fabric crashes, MIUI, BigNumber). Triggers on "review PR", "review this PR", "code review", "check this diff", "审查 PR", "代码审查", "review
- ▌ 1password Secrets · aibot88 bundleSecure secret management using 1Password CLI. Detect plaintext secrets in files and codebases, convert environment files to 1Password templates, inject secrets securely using op inject, and audit codebases for security compliance.
- ▌ 30x SEO Backlinks · aibot88 bundleComprehensive backlink analysis using DataForSEO API. Analyze backlink profiles, find link building opportunities, detect toxic links, compare with competitors, and identify link gaps. Use when user says "backlinks", "link building", "referring domains", "link profile", "toxic links", "link gap", "competitor links", or "domain authority".
- ▌ 30x SEO Technical · aibot88 bundleTechnical SEO audit across 8 categories: crawlability, indexability, security, URL structure, mobile, Core Web Vitals, structured data, JS rendering. Schema deep validation → seo-schema. AI crawlers → seo-geo-technical. Use when user says "technical SEO", "crawl issues", "robots.txt", "Core Web Vitals".
- ▌ Acc Create Policy · aibot88 bundleGenerates Policy pattern for PHP 8.5. Creates encapsulated business rules for authorization, validation, and domain constraints. Includes unit tests.
- ▌ Access Management · aibot88 bundleRBAC/ABAC implementation patterns, least privilege access, row-level security, column masking, and access review workflows.
- ▌ Accessibility Fix · aibot88 bundleScan an AEM Edge Delivery Services page for WCAG 2.1 AA accessibility violations and generate specific fixes. Identifies missing alt text, heading hierarchy issues, link text problems, color contrast concerns, and EDS-specific accessibility patterns. Use when fixing accessibility issues, preparing for compliance audits, or remediating WCAG violations.
- ▌ Accessible Motion · aibot88 bundleUse when implementing reduced motion alternatives, vestibular-safe animations, WCAG compliance, or designing for users with motion sensitivity.
- ▌ Accessorysetupkit · aibot88 bundleDiscover and configure Bluetooth and Wi-Fi accessories using AccessorySetupKit. Use when presenting a privacy-preserving accessory picker, defining discovery descriptors for BLE or Wi-Fi devices, handling accessory session events, migrating from CoreBluetooth permission-based scanning, or setting up accessories without requiring broad Bluetooth permissions.
- ▌ Adding New Metric · aibot88 bundleGuides systematic implementation of new sustainability metrics in OSS Sustain Guard using the plugin-based metric system. Use when adding metric functions to evaluate project health aspects like issue responsiveness, test coverage, or security response time.
- ▌ State Manager · aibot88 bundleThree-file state management for session continuity. Maintains STATE.md, DECISIONS.md, and PROGRESS.md as human-readable session context alongside the SQLite ticket database. Use this skill when updating workflow state, logging decisions, tracking session progress, or resuming work after a context break.
- ▌ Agent Channeltalk · aibot88 bundleInteract with Channel Talk using extracted desktop app or browser credentials - read chats, send messages, search messages, manage groups
- ▌ Agent Email Inbox · aibot88 bundleUse when setting up a secure email inbox for any AI agent — configuring inbound email via Resend, webhooks, tunneling for local development, and implementing security measures to prevent prompt injection attacks. Also use when someone mentions 'agent email', 'bot inbox', 'receive emails for agent', 'agent webhook', 'email security for AI', 'prompt injection via email', 'inbound email for bot', or wants their AI agent to receive and respond to emails securely.
- ▌ Agent File Engine · aibot88 bundleRepository-specific AGENTS.md authoring and maintenance workflow. Use when creating, refreshing, or expanding AGENTS.md coverage for a codebase, including deciding whether nested AGENTS.md files are needed for subsystems with distinct rules, workflows, or AI-sensitive constraints.
- ▌ Agentic Structure · aibot88 bundleCollaborative programming framework for production-ready development. Use when starting features, writing code, handling security/errors, adding comments, discussing requirements, or encountering knowledge gaps. Applies to all development tasks for clear, safe, maintainable code.
- ▌ Agentprivacy Jedi · aibot88 bundleBalanced Force Practitioner for 0xagentprivacy. Activates for protection-delegation balance assessment, golden ratio (φ) calibration of P·D product, Drake/Dragon cycle mentorship, post-crisis rebalancing, Sith-Jedi dialogue facilitation, or any task requiring the embodied practice of balance rather than its engineering specification.
- ▌ Agentprivacy Kyra · aibot88 bundleSovereign AI Vision and meta-orchestrator for 0xagentprivacy. Activates when articulating the complete architectural vision, orchestrating across multiple personas, assessing ecosystem strategy within the 2-3 year window, preparing Dragon ceremonies, or answering 'why does this architecture exist?' Tier 0 — above the system. The compass, not the captain.
- ▌ Agentprivacy Sith · aibot88 bundleAdversarial Researcher (red team) for 0xagentprivacy. Activates when testing privacy architectures for weaknesses, running attack simulations, stress-testing separation bounds, finding trusted setup vulnerabilities, modelling adversarial strategies, or any task requiring 'think like the attacker' methodology.
- ▌ Agentv Governance · aibot88 bundleAuthor, edit, and lint `governance:` blocks in `*.eval.yaml` files. Use when creating or updating evaluation suites that carry AI-governance metadata (OWASP LLM Top 10, OWASP Agentic Top 10, MITRE ATLAS, EU AI Act, ISO 42001). Also use non-interactively (e.g., from a GitHub Action) to lint changed eval files and report violations against the rules in `references/lint-rules.md`. Do NOT use for running evals or benchmarking — that belongs to agentv-bench.
- ▌ Air Cryptographer · aibot88 bundleThis skill should be used when the user asks about "AIR", "algebraic intermediate representation", "ZK constraints", "trace design", "constraint soundness", "polynomial commitments", "FRI", "STARK", "lookup arguments", "permutation arguments", "memory consistency", "transition constraints", "boundary constraints", "vanishing polynomial", "quotient polynomial", "Fiat-Shamir", or needs expert-level cryptographic review of constraint systems.
- ▌ Sales Blueconic · aibot88 bundleBlueConic platform help — Customer Data Platform (CDP), real-time profile unification, segmentation, personalization, audience activation, Jebbit Experiences, AI Workbench. Use when profiles aren't merging across channels, segments aren't syncing to ad platforms, BlueConic connections aren't importing or exporting data, you need help setting up BlueConic on a single-page app, consent and privacy objectives aren't working correctly, or you're choosing between BlueConic and another CDP. Do NOT use for general email marketing strategy (use /sales-email-marketing) or CRM data deduplication without BlueConic (use /sales-data-hygiene).
- ▌ Sales Callminer · aibot88 bundleCallMiner platform help — enterprise conversation analytics (Eureka) with omnichannel interaction capture, automated QA scoring, agent coaching, real-time alerts, compliance monitoring, and CX automation. Use when QA scoring is inconsistent or takes too long across agents, when needing to analyze 100% of customer interactions instead of sampling, when setting up automated compliance monitoring for regulated industries (healthcare, finance, collections), when CallMiner Coach scorecards aren't surfacing the right coaching moments, when CallMiner RealTime alerts aren't triggering during live calls, when ingesting audio or text into CallMiner via the Ingestion API, when CallMiner Analyze categories aren't matching expected interactions, or when evaluating CallMiner vs Observe.AI or NICE CXone analytics. Do NOT use for CCaaS platform selection (use /sales-ccaas-selection) or for sales-specific coaching strategy (use /sales-coaching).
- ▌ Sales Maestroqa · aibot88 bundleMaestroQA platform help — conversation data QA platform with customizable scorecards, AI-powered coaching workflows, conversation analytics (AskAI), reverse-ETL to CRM/Slack/data warehouses, CSAT ingestion, chatbot QA monitoring. 60+ integrations (Zendesk, Freshdesk, Salesforce, Intercom, ServiceNow, Kustomer, Front, Gorgias, Gladly, Khoros Care, Five9, Talkdesk, Amazon Connect, NICE, Aircall, Gong, Zoom, Dialpad, Snowflake, BigQuery, Redshift). Rippit API (app.rippit.com/api/v1, token auth, 10 req/s). Use when QA scorecards not catching the right issues, coaching workflows feel disconnected from QA data, grading data export to warehouse, CSAT scores not correlating with QA scores, setting up MaestroQA integrations with helpdesk or phone system, MaestroQA API automation, or evaluating MaestroQA vs Observe.AI or Enthu.AI or Klaus. Do NOT use for CCaaS platform selection (use /sales-ccaas-selection) or real-time agent coaching during calls (use /sales-balto).
- ▌ Sales Mbox Meet · aibot88 bundleMBox AI Meet platform help — free Chrome extension for Google Meet real-time transcription and AI summaries powered by Gemini Pro. Use when setting up MBox AI Meet for automatic Google Meet transcription and email summaries, troubleshooting MBox Chrome extension not recording or transcription accuracy issues, deciding between MBox free and Pro plans or evaluating whether Enterprise API access is worth it, comparing MBox AI Meet to other bot-free Chrome extension note-takers like Tactiq or Scribbl, wondering why MBox only works on Google Meet and whether other platforms are coming, or evaluating MBox's privacy-first approach with no audio/video storage. Do NOT use for comparing AI note-takers across all platforms (use /sales-note-taker) or reviewing a sales call for coaching (use /sales-call-review).
- ▌ Sales Retention · aibot88 bundleRetention.com platform help — ecommerce identity resolution that identifies anonymous website visitors and converts them to email/SMS contacts. Covers Grow (10x email list growth from identified visitors), Reclaim (abandonment flow recovery for events missed by Klaviyo/Elevar), retargeting activation across email/SMS/push/paid channels, tracking pixel setup, Shopify integration, compliance (CCPA, implicit consent model), and API (suppression uploads, webhooks). Use when most site visitors leave anonymous and you can't email them, Klaviyo is missing abandonment events, identified contacts are hitting spam, or you're not sure if Retention.com is worth it vs RB2B or Opensend. Do NOT use for B2B visitor identification (use /sales-rb2b), email marketing strategy (use /sales-email-marketing), or email list growth strategy across tools (use /sales-audience-growth).
- ▌ Sales Trendhero · aibot88 bundletrendHERO platform help — Instagram influencer analytics (95M+ profiles, 20+ filters), Account Quality Score (AQS 1-100, fake follower detection), Audience Analysis, Daily Tracking, Ads Database (10M+ posts), Audience Overlap, REST API (Bearer auth, webhooks). Covers discovery search, AQS interpretation, audience vetting, tracking setup, ads database research, API integration, and pricing (Free/Lite/Pro/Advanced). Use when you suspect an influencer has fake followers, trendHERO search results aren't matching your niche, you need to monitor an influencer's metrics over time, you want to see which influencers your competitors are using, the trendHERO API isn't working as expected, you're unsure which trendHERO plan fits your budget, or you're deciding between trendHERO, HypeAuditor, and Heepsy. Do NOT use for influencer strategy across platforms (use /sales-influencer-marketing), TikTok marketing (use /sales-tiktok-marketing), gaming influencer marketing (use /sales-gaming-marketing), or ad campaigns (use /sale
- ▌ Sast Fileupload · aibot88 bundleDetect insecure file upload vulnerabilities in a codebase using a three-phase approach: discovery (find all upload sites), batched verify (check extension bypass and related issues in parallel subagents, 3 sites each), and merge (consolidate batch results). Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/fileupload-results.md. Use when asked to find file upload, unrestricted upload, or extension bypass bugs.
- ▌ Sc API Security · aibot88 bundleREST, GraphQL, and gRPC API security audit — authentication, authorization, data exposure, and configuration
- ▌ Sc Clickjacking · aibot88 bundleClickjacking and UI redressing detection — missing frame protection headers and CSP frame-ancestors
- ▌ Sc Orchestrator · aibot88 bundleMaster orchestration skill that coordinates the entire 4-phase security scanning pipeline
- ▌ Prompt Engineer Scaffold Prompt · aibot88 bundle"Create defensive prompt scaffolding with guardrails and safety measures. 創建帶護欄與安全措施之防禦提示架構。 Use when: building user-facing prompts, adding injection protection, implementing harm prevention layers."
- ▌ Secret Adapters · aibot88 bundleSecret management integration (密鑰管理整合). Use when working with HashiCorp Vault, credential management, or secure configuration. Covers secret storage (密鑰儲存), key management (金鑰管理), NestJS integration, online/offline modes, and automatic token renewal. Keywords: 密鑰, 機密, 金鑰, 秘密管理, secret, vault, credential, key management, HashiCorp, token, 環境變數, configuration
- ▌ Secret Boundary · aibot88 bundleAI実行環境のシークレット境界設定。settings.json permissions.denyルールを生成し、シークレットへの事故的アクセスを防止する。
- ▌ Secret Detector · aibot88 bundle機密情報検出スキル。APIキー、パスワード、トークン等の機密情報をコードから検出。git-secrets/truffleHog/gitleaks等のツールを統合。漏洩防止と早期発見に使用。
- ▌ Secrets Scanner · aibot88 bundleDétecte les secrets, clés API et credentials exposés dans le code. À utiliser pour vérifier qu'aucun secret n'est dans le code. Se déclenche avec "secrets", "clé API exposée", "credential leak", "mot de passe dans le code", "token exposé", ".env", "secret scanner".
- ▌
- ▌ Security Report · aibot88 bundleGenerate security assessment reports in docx format with findings, risk ratings, and remediation recommendations. Use when: User asks for security audit report, vulnerability assessment document, penetration test report, or compliance gap analysis document. Keywords: security report, audit findings, vulnerability report, pentest report
- ▌ Security Review · aibot88 bundleSecurity vulnerability assessment identifying OWASP risks, injection vectors, authentication issues, and data exposure with severity classification.
- ▌ Security Triage · aibot88 bundleTriage GitHub security advisories for OpenClaw with high-confidence close/keep decisions, exact tag and commit verification, trust-model checks, optional hardening notes, and a final reply ready to post and copy to clipboard.
- ▌ Securityheaders · aibot88 bundleAudit HTTP security headers for any URL and receive a grade (A+ to F) with specific recommendations for missing headers
- ▌ Session Redteam · aibot88 bundleRed Team-granskning av sessionsförberedelser. Agerar som en fientlig granskare som aktivt letar efter hål, brister och svagheter i materialet inför en kommande spelsession. Kontrollerar NPC-komplettering (markdown + JSON), plotlogik, stridbalans, pacing, saknade handouts och mer. Triggas av "granska session", "red team", "hitta hål", "kontrollera prep", "är materialet redo", eller liknande.
- ▌ Sidecar Pattern · aibot88 bundleAuxiliary service sharing lifecycle with main service. Trigger: When adding logging, monitoring, or auth proxy to microservices without code changes.
- ▌ Skill Authoring · aibot88 bundleGuide to creating Claude Code skills using TDD methodology and persuasion principles. Use for new skill development.
- ▌ Go Ffi Abi Expert · aibot88 bundleEspecialista PhD em engenharia de sistemas com foco em FFI (Foreign Function Interface), ABI (Application Binary Interface), Go runtime, purego, SDL3 bindings e problemas de compatibilidade em arquiteturas 32-bit (x86/386) e 64-bit. Use esta skill sempre que o usuário mencionar: purego, go-sdl3, FFI em Go, problemas com float32 em 32-bit, calling conventions (cdecl/stdcall), cgo vs purego, bindings C/Go, wrappers de biblioteca nativa, GOARCH=386, ABI de float, SDL3 render/input/math, geração automática de bindings, ou qualquer problema de interoperabilidade Go ↔ C. Ative também para questões sobre instabilidade de chamadas dinâmicas, comportamento indefinido em FFI, ou quando o usuário perguntar "por que minha função C com float falha no Go". Inclua sugestões concretas de solução, trade-offs e código real quando apropriado. Mantenha o foco rigorosamente no domínio FFI/ABI/Go — evite desvios. Responda sempre em português do Brasil.
- ▌ Soc Stakeholder · aibot88 bundleConduct stakeholder analysis using identification, Power-Interest matrix classification, and influence strategy development. Use this skill when the user needs to map stakeholders for a project, manage conflicting interests, prioritize communication, or build a stakeholder engagement plan — even if they say 'who needs to approve this', 'how do I get buy-in', or 'who might block this project'.
- ▌ Software Design · aibot88 bundleSoftware design principles, patterns, and architecture from SOLID through distributed systems. Covers the five SOLID principles with violations and fixes, DRY/KISS/YAGNI heuristics, separation of concerns, 12 GoF design patterns organized by intent (creational, structural, behavioral), architectural patterns (MVC, MVP, MVVM, layered, hexagonal, microservices, event-driven), coupling and cohesion metrics, dependency injection, and the design decision framework for choosing between competing approaches. Use when making design decisions, reviewing architecture, refactoring code, or teaching software engineering principles.
- ▌ Sol Safekey Bot · aibot88 bundleUse this skill when integrating sol-safekey into Solana bots or tools, including encrypted keystores, interactive wallet management, password handling, wallet unlock, bot startup scripts, SOL/SPL/WSOL operations, durable nonce setup, and secure key handling for Rust or multi-language bot stacks.
- ▌ Solai Knowledge · aibot88 bundleGround Solution AI and Contextual product answers in the official platform documentation — for **platform/runtime behavior not already covered by plugin-side reference content** (`cli-reference.md`, `node-reference.md`, the relevant `SKILL.md`). For CLI command shapes, JSONL formats, flow record structure, native-object-config shape, or node-level authoring patterns, prefer the plugin-side references first; this skill is the second stop, for behavior the plugin-side does not cover.
- ▌ Solana Security · aibot88 bundleAudit Solana programs (Anchor or native Rust) for security vulnerabilities. Use when reviewing smart contract security, finding exploits, analyzing attack vectors, performing security assessments, or when explicitly asked to audit, review security, check for bugs, or find vulnerabilities in Solana programs.
- ▌ Solve Challenge · aibot88 bundleSolves CTF challenges by performing first-pass triage, identifying the dominant category, and routing execution to the right specialized ctf-* skill. Use when the user gives you a challenge bundle, a remote service, a suspicious file, or only a vague challenge description and you must determine where to start. Do not use it when the category is already clear and a specialized skill can be invoked directly; this is the dispatcher and recon entrypoint, not the deepest reference for category-specific techniques.
- ▌ Sop Code Review · aibot88 bundleComprehensive code review workflow coordinating quality, security, performance, and documentation reviewers. 4-hour timeline for thorough multi-agent review.
- ▌ Source Analysis · aibot88 bundlePrimary and secondary source analysis for historical reasoning. Covers source classification, sourcing (author/context/purpose), corroboration across multiple sources, contextualization within time and place, and bias detection. Use when evaluating historical evidence, assessing source reliability, or constructing evidence-based historical arguments.
- ▌ Specdd Refactor · aibot88 bundleUse when Claude Code needs to refactor code, tests, docs, specs, or project structure in a SpecDD project while preserving specified behavior, public contracts, scenarios, ownership, and local write authority.
- ▌ Specstory Guard · aibot88 bundleInstall a pre-commit hook that scans .specstory/history for secrets before commits. Run when user says "set up secret scanning", "install specstory guard", "protect my history", or "check for secrets".
- ▌ Splunk Platform · aibot88 bundleDeep skill for Splunk development, administration, SDK/REST integrations, dashboards, UCC add-ons, ITSI automation, SPL2 authoring, and AI-facing tooling. Use for Splunk SDK, REST, jobs/export, SPL, dashboards, packaging, and MCP-backed analysis workflows.
- ▌ Solana Squads Multisig · aibot88 bundleUse this skill when the user wants to set up a Squads V4 multisig on Solana — create the multisig, manage members and threshold, propose transactions, approve, and execute. Standard for team treasuries and program upgrade authority.
- ▌ Strategy Review · aibot88 bundleUse when reviewing, critiquing, or stress-testing an existing strategy document. Evaluates seven dimensions — diagnosis quality, guiding policy strength, action coherence, assumption exposure, falsifiability — with optional 7S, Five Forces, Balanced Scorecard, and Hoshin Kanri lenses. Triggers on: review my strategy, poke holes in this plan, what's weak here, strategy audit, red team this. Does NOT build strategy (use strategy-interview) or brainstorm project ideas (use brainstorm-beagle).
- ▌ Subfinder Recon · aibot88 bundle使用 subfinder 进行被动子域名枚举。当需要发现目标域名的子域名、扩展攻击面时使用。subfinder 是 ProjectDiscovery 出品的被动子域名发现工具,聚合 Shodan、Censys、SecurityTrails、VirusTotal 等多数据源,快速且隐蔽。任何涉及子域名枚举、攻击面发现、被动信息收集的场景都应使用此技能
- ▌ Substack Editor · aibot88 bundleTransform topics or documents into engaging, optimized Substack articles with authentic voice, storytelling, and maximum engagement. Use when user wants to create a Substack post from an idea, topic, or existing document.
- ▌ Supabase Expert · aibot88 bundleExpert guide for Supabase integration - database schemas, RLS policies, auth, Edge Functions, and real-time subscriptions. Use when working with Supabase backend features.
- ▌ Telnyx 10dlc Go · aibot88 bundle10DLC brand and campaign registration for US A2P messaging compliance. Assign phone numbers to campaigns.
- ▌ Terms Generator · aibot88 bundleGenerates comprehensive terms of service by analyzing a website or application to detect business type, data collection, and user interactions. Use when launching a website, app, or SaaS product that needs terms of service with GDPR/CCPA compliance. Trigger with "/terms-generator" or "create terms of service for my website".
- ▌ Terraform Skill · aibot88 bundleUse when writing, reviewing, or debugging Terraform/OpenTofu modules, tests, CI, scans, or state ops — diagnoses failure mode (identity churn, secrets, blast radius, CI drift, state corruption) with version-aware guards.
- ▌ Test Heuristics · aibot88 bundleUse when reviewing, designing, triaging, or rationalizing test suites — unit, integration, e2e/UI, exploratory, property-based, contract, snapshot, mutation, or performance tests. Trigger for flakiness triage, false-pass risk, brittleness on refactor, suite pruning, test-pyramid/trophy decisions, exploratory charters, and snapshot review. Routes by activity (triage / review / author / strategize / prune) and layer.
- ▌ Thinking Deeply · aibot88 bundleEngages structured analysis to explore multiple perspectives and context dependencies before responding. Use when users ask confirmation-seeking questions, make leading statements, request binary choices, or when feeling inclined to quickly agree or disagree without thorough consideration.
- ▌ Threat Advisory · aibot88 bundleGenerate a personalized threat advisory based on your tech stack — what CVEs, breaches, and supply chain attacks matter to YOU.
- ▌ Threat Modeling · aibot88 bundleProduces structured threat models for software systems using STRIDE on data flow diagrams. Generates DFDs with trust boundaries, identifies threats per element, scores risks, and defines concrete mitigations. Outputs a complete threat model Markdown document through phased, interactive delivery. Use when threat modeling a system, analyzing security threats, identifying attack surfaces, performing STRIDE analysis, assessing security risks in architecture, creating a threat model document, or when the user mentions threat model, attack surface, trust boundaries, STRIDE, or security risk analysis.
- ▌ Token Breakdown · aibot88 bundleAnalyze current Claude Code session token usage via Splunk. Shows per-model, per-tool, and subagent token breakdown with cache efficiency metrics.
- ▌ Trace Sanitizer · aibot88 bundleExport Claude Code, Codex, Gemini CLI, and OpenCode conversation history for TRACED. Use when the user asks about exporting conversations, donating to TRACED, configuring trace-sanitizer, reviewing PII/secrets in exports, or managing their dataset.