- 429 skills
- 0 followers
- 14k repo stars
- 188 verified
- last week last updated
- ▌
- ▌
- ▌
- ▌ Dev CI · googleCI triage and red-gate discipline. Use when an Actions run is red, pr-gate blocks a PR, you are deciding whether to rerun, or you are editing .github/workflows/.
- ▌ Citadel · googleThe Citadel guard suite. Use when adding a guard, a linter, or a source surface, or when a citadel test fails and you need to know what it is protecting.
- ▌
- ▌ Dev Gate · googleHow capsem-gate works and how to add or change a gate command. Use when touching build, test, or release logic, or when a boundary/primitive/recursion/purity guard fails.
- ▌ Dev Just · googleCapsem's small Just surface and its boundary with the Python gate. Use when adding or changing a recipe, or deciding whether logic belongs in Just or in a gate plan.
- ▌ Ironbank · googleUse when Capsem VM, network, model, MCP, credential broker, security, package-manager, doctor, benchmark, or release-gate behavior needs black-box acceptance proof
- ▌ Dev Cache · googleCapsem's unified cache control plane. Use for cache inventory, retention, cleanup, test reuse, or disk, Docker/Colima, Tart, Cargo, Python, Node, BuildKit, and VM asset cache work.
- ▌ Dev Setup · googleSetting up a Capsem dev environment from scratch. Use when onboarding, provisioning a machine, or troubleshooting environment and container-runtime issues.
- ▌ Dev Start · googleQuick start for new Capsem developers. Use for "how do I get started" or "first time setup"; for environment troubleshooting use dev-setup instead.
- ▌
- ▌
- ▌ Dev Sprint · googleRun multi-step Capsem development in Sprinty. Use for features, refactors, migrations, release preparation, or any work spanning several commits and verification gates.
- ▌ Site Infra · google bundleThe documentation site, docs.capsem.org. Use when writing or editing docs, adding pages, or working with Astro Starlight.
- ▌ Dev Testing · google bundleCapsem testing policy and workflow. Use whenever running or writing tests. For VM, hypervisor, frontend, or Python specifics see the dev-testing-* skills.
- ▌ Build Images · googleBuilding Capsem VM images from profile-owned inputs. Use when working on profile package files, Dockerfile templates, kernel or rootfs builds, or the capsem-builder backend.
- ▌ Build Initrd · googleInitrd repack and guest binary management. Use when adding or changing a guest binary, modifying capsem-init, or iterating on the initrd without a full rebuild.
- ▌ Dev Benchmark · google bundleMeasuring Capsem with capsem-bench. Use when running benchmarks, adding a dimension or a collector, reading the store, or judging whether a slowdown is real.
- ▌
- ▌ Asset Pipeline · google bundleAsset manifests, hash verification, and boot-time resolution for Capsem VM images. Use when debugging boot failures, manifest issues, or hash mismatches.
- ▌
- ▌ Dev Mitm Proxy · google bundleThe air-gapped network intercept layer. Use when working on TLS termination, HTTP inspection, cert minting, SSE parsing, or debugging network behaviour.
- ▌ Dev Testing Vm · googleIn-VM diagnostics and test fixtures. Use when adding in-VM tests, debugging failures inside the guest, or updating the test fixture.
- ▌ Site Marketing · googleThe marketing website, capsem.org. Use when editing copy, adding sections, or changing the site theme.
- ▌ Frontend Design · google bundleCapsem frontend design system. Use when building UI components, styling views, choosing colors, or working with Svelte 5 runes and the component library.
- ▌
- ▌
- ▌ Dev Capsem Doctor · googleThe capsem-doctor in-VM diagnostic suite. Use when writing, running, or extending doctor tests, or debugging VM sandbox issues.
- ▌
- ▌ Dev Session Debug · googleDebugging session.db and the telemetry pipeline. Use when inspecting a session ledger, diagnosing missing telemetry, or correlating events across tables.
- ▌
- ▌ Dev Testing Python · googlePython test infrastructure for capsem-builder. Use when running Python tests, checking coverage, or working with golden fixtures and generated schemas.
- ▌ Meta Skill Creation · googleCreate, improve, and evaluate skills. Use when writing a new skill, editing an existing one, or tuning a description for better triggering.
- ▌ Dev Testing Frontend · google bundleTesting the Capsem frontend. Use when writing frontend tests, running type checks, or doing visual verification with Chrome DevTools MCP.
- ▌ Meta Organize Skills · googleConventions for the skills/ directory. Use when creating, reorganizing, or maintaining skill layout, symlinks, and discovery across agents.
- ▌ Dev Testing Hypervisor · google bundleTesting the hypervisor layer, Apple VZ and KVM. Use when testing VM configuration, VirtioFS, vsock, serial console, or the backend abstraction.
- ▌ Secops Triage · googleExpert guidance for security alert triage. Use this when the user asks to "triage" an alert or case.
- ▌ Secops Setup Gemini · googleHelps the user configure the Google SecOps Remote MCP Server for Gemini CLI. Use this when the user asks to "set up" or "configure" the security tools for Gemini CLI.
- ▌ Find Skills · googleDiscover/install NEW agent skills from external sources (skills.sh). Use for capabilities you lack, e.g. "find a skill for X". Do NOT use to list skills you already have; see `<available_skills>`.
- ▌ Google Workspace · googleRead/write Google Drive, Docs, Sheets, Gmail, Calendar, Chat, Tasks, Slides via the `gws` CLI. Needs an OAuth client or service account configured first. Use for any Google Workspace task.
- ▌ Bootstrap Google Tools · googleInstall/auth CLIs the sandbox lacks - `gws` (Drive, Gmail, Sheets, Calendar), `gcloud`, `agents-cli`, `mcp-cli` (MCP servers). Use on "command not found" or before GCP/Workspace/MCP work.
- ▌ Retail Product Search · google bundleCreates product search agents with semantic search and RAG on Google Cloud (Vertex AI Vector Search, BigQuery, embeddings). Use when the user wants to "build a product search agent", "create an e-commerce search", "make a shopping assistant", "set up semantic catalog discovery", "ingest products into Vector Search", or "deploy a retail RAG agent". Handles the full pipeline: catalog data ingestion to BigQuery, Vertex AI Vector Search collection setup, ADK agent scaffolding, evaluation, and Cloud Run deployment.
- ▌ Make Python Recipe Deployable · google bundleMakes an existing Python recipe deployable: generates the serving files a container needs (Dockerfile, .dockerignore, fast_api_app.py, app_utils/a2a.py, app_utils/services.py, app_utils/reasoning_engine_adapter.py) and configures the recipe to match (required serving dependencies, the App object in agent.py, the hatch wheel package, manifest.deployable). Interactive by design — it asks the recipe owner about runtime data directories and stops for a human decision when a recipe needs an ADK migration or carries a legacy app_utils generation. When docker is available it offers to PROVE the claim: it builds the generated Dockerfile, runs it, probes it, and refuses to flag a recipe deployable if the container does not come up. Does NOT deploy or write terraform. Use when the user wants to "make this recipe deployable", "add a Dockerfile to a recipe", "add the serving files", "containerize a recipe", "verify the container builds", or prepare a recipe for Cloud Build / Artifact Registry.
- ▌ Policy · googleInspect the per-workspace tool-policy overlay (.lha/policies.jsonl) that gates destructive or sensitive tool calls, and tell the user what to change if they want a rule added or removed.
- ▌ Routines · googleUse for a recurring unattended task (cron; pull data, open a PR, post a digest), or to test/dry-run a routine first. Explains authoring and testing via the routine tool.
- ▌ Repo Oracle · google bundleAnswer questions about how the adk-samples repo itself is governed — CI and workflow behavior, the limits and thresholds in .github/policy.yml and the reasoning behind them, CODEOWNERS routing, what the bots (stale sweep, Dependabot, recipe canary, AI review) do, how the repo is organised (core vs contrib vs skills verticals), what the repo skills and validators cover, when a rule last changed and which PR changed it, what a label means, and the admin runbooks for changing any of it. Also answers generic contribution-process questions from docs/ — how a recipe is prepared and validated, what a field in manifest.yaml means, what a runnability test is, what a README must contain, what a named CI error means. On explicit request it also traces which files consume a config key, and audits whether the repo still obeys its own policy. STRICTLY READ-ONLY — it never edits, commits, comments, labels, or performs a task on the caller's behalf, even when asked directly; it cites the source file and describes the change
- ▌ Retail Virtual Tryon · google bundleCreates virtual try-on agents supporting image and video (catwalk animation) try-ons on Google Cloud (Gemini image models and Veo on Gemini Enterprise Agent Platform). Handles resource setup, user photo uploading, image/video generation pipelines, local testing, and evaluation.
- ▌ A2ui Implement Feature From Blueprint · googleProvides instructions on implementing feature specs or module blueprint commit diffs in a specific codebase.
- ▌ A2ui Implement New Sdks For Client Language · googleStep-by-step phased instructions for building new A2UI Core SDKs, Framework Adapters, and Inference SDKs from scratch in any client language.
- ▌ A2ui Audit · google bundleMain coordination skill to run the blueprint compliance, documentation synchronization, and test quality audits, posting the combined results as a labeled GitHub issue.
- ▌ Inspect AI · googleUseful when working with the Inspect AI evaluation framework (e.g., in the eval/ directory). Provides instructions on how to access Inspect AI documentation.
- ▌ Natural Writing · googleContains well-defined rules for creating natural, accurate, and readable writing. Use this skill whenever authoring longer text, including reports, PR or CL descriptions, READMEs, system designs, analysis documents, or general documentation.
- ▌ A2ui Issue Triage · google bundleAutomates the triage of GitHub issues in the A2UI repository. Helps the oncall engineer by fetching untriaged issues, generating AI-suggested priorities, assignees, and responses, launching a local review dashboard, and bulk-applying approved decisions to GitHub. Use when tasked with triaging new GitHub issues or managing the repository backlog.
- ▌ A2ui Doc Sync Check · googleAuditing codebase implementations for synchronization drift with the user documentation, readmes, and code comments.
- ▌ A2ui Remediate Problem · google bundleRemediates a specific recommendation from an A2UI compliance report issue, or resolves any general GitHub issue, by inspecting context, implementing minimal targeted fixes, verifying tests, creating a branch, and opening a developer-signed Pull Request. Use when asked to fix or remediate an A2UI compliance audit finding, recommendation, or repository issue.
- ▌ A2ui Swift Development · googleGrounding, coding standards, testing practices, and verification workflows for developing in the A2UI Swift codebase (under the swift/ directory). Use whenever implementing features, modifying state logic, creating SwiftUI views, or writing tests in Swift.
- ▌ A2ui Add Eval Datapoint · googleStep-by-step workflow for adding and verifying new evaluation data points in the A2UI evaluation suite.
- ▌ A2ui Test Quality Check · googleAuditing test suites for assertion utility, boundary cases coverage, and verification strength.
- ▌ A2ui Blueprint Navigator · googleAnalytical navigation of A2UI Spec-Driven Development module and codebase blueprints.
- ▌ A2ui Blueprint Compliance · google bundleVerification of platform codebase blueprint compliance against the latest module blueprints.
- ▌ A2ui Blueprint Maintenance · googleManage the evolution, merging, archiving, and cleanup of specifications and blueprints across the workspace.
- ▌ A2ui Create Feature Blueprint · googleProvides instructions on how to create a new language-agnostic A2UI Feature Blueprint, ensuring consistency and ease of cross-language implementation.
- ▌
- ▌ Fuzzing Jvm Expert · googleUse this skill to fuzz open source JVM projects (Java, Kotlin, Scala, etc.) using Jazzer.
- ▌
- ▌ Fuzzing Python Expert · googleUse this skill to fuzz open source Python software projects using Atheris.
- ▌
- ▌
- ▌ Adk Git · googleWrites commit messages and pull request descriptions for the adk-python repository: Conventional Commits types and scopes, subject lines that say why a change was made, and the linked-issue and testing-plan sections the PR template requires. Use when writing or rewording a commit message, squashing commits before a pull request, drafting a PR description, or checking that a change is shaped to land. Don't use for generic git mechanics such as rebasing, resolving conflicts, cherry-picking, or branch surgery; those need no skill. Don't use to judge the content of a change (use adk-review) or for code style and naming (use adk-style).
- ▌ Mantis Plan · googleFormulates a targeted defensive security reviewing plan based on the active threat model and historical learnings. Use when starting a security review campaign to map the codebase boundaries and generate a roadmap (workspace/plan.json). Don't use for executing code reviews, writing test scripts, or patching code.
- ▌ Mantis Chain · googleAnalyzes individual security findings to identify and construct complex exploit chains. Use after validation stages to see if multiple low-severity bugs can be combined into a higher impact vulnerability. Don't use for initial codebase auditing or writing patch code.
- ▌ Mantis Patch · google bundleGenerates minimal security fixes using transactional isolation (shadow directories or file backups), applies patches, and verifies them. Use when security findings are successfully reproduced and need patches applied and verified. Don't use for initial vulnerability research or reproduction payload generation.
- ▌ Mantis Advise · googleProactive security advisor and guardrail assistant for secure code development. Use to query threat models, historical vulnerability lineages, verified patch patterns, triaged false positives, and learned trajectory invariants before and during code edits to prevent repeat mistakes. Don't use for automated multi-pass red-team exploitation or fuzzing.
- ▌ Mantis Critic · googleAssesses the production viability of findings, filtering out debug-only features and assertion traps. Use when findings have been validated and you need to confirm they are triggerable in production release builds (with assertions disabled). Don't use for writing reproduction scripts or patches.
- ▌ Mantis Dedupe · googleConsolidates raw security findings to eliminate redundant reports. Use when raw findings have been generated by the researcher and need consolidation before review. Don't use for initial code auditing or patch generation.
- ▌ Mantis Report · googleGenerates a human-readable security review packet compiled from confirmed findings and exploit chains. Use at the end of a review cycle to produce stakeholder-facing documentation. Don't use for auditing code or verifying patches directly.
- ▌ Mantis Review · googleIndependently reviews findings and filters out false positives. Use when consolidated findings need validation against the actual source code. Don't use for reproducing crashes or patching code.
- ▌ Mantis History · googleAnalyzes the repository's version control system (VCS) history to extract past vulnerabilities, security fixes, and vulnerability patterns. Use as an initial pre-processing step to build a historical vulnerabilities database (workspace/historical_learnings.jsonl) that informs subsequent stages about past issues and fixes. Don't use for code reviews, writing test scripts, or patching code.
- ▌ Mantis Reflect · googleExtracts learnings from execution trajectories at the end of a Mantis loop. Use to parse agent conversations, extract successes, failures, and false assumptions, and append them to workspace/learnings.jsonl. Don't use for analyzing source code or writing patches.
- ▌ Mantis Calibrate · google bundleCalculates the final risk score based on empirical evidence and architectural impact. Use when findings have been fully processed by previous stages and you need to append final risk scores to the finding files. Don't use for discovering new vulnerabilities or writing patches.
- ▌ Mantis Reproduce · googleGenerates and runs crash reproducers to verify security flaws. Use when viable findings exist and you need to write and execute a script or payload to verify the crash. Don't use for code auditing or patching.
- ▌ Mantis Summarize · googlePre-processes the repository by generating security-focused summaries (mantis-summary.md) for each directory to make planning and research more efficient. Use when starting a review campaign to map the codebase before threat modeling and planning. Don't use for executing code reviews, writing test scripts, or patching code.
- ▌ Mantis Meta Agent · googleActs as the persistent supervisor, launching and monitoring the automated review campaign. Use when running a long-running, continuous security review campaign that needs autonomous coordination. Don't use for executing individual review stages directly.
- ▌ Mantis Researcher · googleAudits production source code files based on the strategy in workspace/plan.json. Use when a review plan exists and you need to perform static analysis and deep-dive reviews of targeted files. Don't use for planning, deduplicating, or writing patches.
- ▌ Mantis Architecture · googleSynthesizes raw learnings and codebase analysis into an interlinked Markdown Knowledge Base (KB). Use at the beginning of a loop to build or update architecture.md, entities, and vulnerabilities. Don't use for generating threat models or formulating execution plans.
- ▌ Mantis Threat Model · googleSynthesizes trust boundaries, attack surfaces, and attacker profiles into a living threat model. Use as Stage B of the Knowledge Base generation process, reading architecture and entity definitions from the KB. Don't use for analyzing source code or extracting raw learnings from JSONL files.
- ▌ Mantis Pipeline Adapter · google bundleInteractively guides the design and implementation of custom deterministic orchestrator harnesses. Use when a user wants to build their own pipeline to wrap and run Mantis skills reliably. Don't use for executing the default pipeline directly.
- ▌ Mantis Structural Index · googleBuilds a content-addressed semantic-unit index from source code for structural context. Use when a pinned or live codebase is available and structural cross-reference data would improve research quality. Don't use for findings analysis, patching, or reporting.
- ▌ Mantis Launch · googleLaunches automated vulnerability review campaigns on target files or repositories. Use to initiate Mantis vulnerability review pipelines with automated preflight checks, environment auto-configuration, and runtime overrides (sandboxes, models, endpoints). Don't use for configuring settings without scanning or for manual single-stage reviews.
- ▌ Mantis Configure · googleConfigures and validates Mantis pipeline environments, sandbox mechanisms, and AI models. Use to set up workflow.json, auto-detect host capabilities, switch between sandboxes (static-only, gvisor, microsandbox, gce), select AI models, and run fast 1-2s preflight tests. Don't use for scanning source code or running attack campaigns.
- ▌ Google Agents CLI Eval · google bundleThis skill should be used when the user wants to "run an evaluation", "evaluate my agent", "evaluate my ADK agent", "write an eval dataset", "analyze eval failures", "compare eval results", "optimize agent", or needs guidance on the Agent Platform eval methodology and the Quality Flywheel. Covers eval metrics, dataset schema, LLM-as-judge scoring, and common failure causes. Applies to any agents-cli project, whatever framework the agent is written in. Do NOT use for agent API code patterns (ADK: use google-agents-cli-adk-code), deployment (use google-agents-cli-deploy), or project scaffolding (use google-agents-cli-scaffold).
- ▌ Google Agents CLI Deploy · google bundleThis skill should be used when the user wants to "deploy an agent", "deploy my ADK agent", "set up CI/CD", "configure secrets", "troubleshoot a deployment", or needs guidance on Agent Runtime, Cloud Run, or GKE deployment targets, or binding an agent to an Agent Gateway. Covers deployment workflows, service accounts, rollback, and production infrastructure. Applies to any framework agents-cli deploys (ADK, LangChain, ...). Part of the agents-cli skills suite. Do NOT use for agent API code patterns (ADK: use google-agents-cli-adk-code), evaluation (use google-agents-cli-eval), or project scaffolding (use google-agents-cli-scaffold).
- ▌ Google Agents CLI Publish · googleThis skill should be used when the user wants to "publish an agent", "publish my ADK agent", "register an agent with Gemini Enterprise", "publish to Gemini Enterprise", or needs guidance on the agents-cli publish gemini-enterprise command. Also use when the user wants to "manage agents in Agent Registry", "list/update/delete registered agents", or "register an MCP server". Covers ADK vs A2A registration modes, programmatic and interactive usage, flag reference, auto-detection from deployment metadata, Agent Registry fleet management, and troubleshooting. Part of the agents-cli skills suite. Do NOT use for deployment (use google-agents-cli-deploy).
- ▌ Google Agents CLI Adk Code · google bundleThis skill should be used when the user wants to "write agent code", "build an agent with ADK", "add a tool", "create a callback", "define an agent", "use state management", or needs ADK (Agent Development Kit) Python API patterns and code examples. Part of the Google ADK skills suite. It provides a quick reference for agent types, tool definitions, orchestration patterns, callbacks, state management, and reference recipes to study. Do NOT use for scaffolding (use google-agents-cli-scaffold) or deployment (use google-agents-cli-deploy).
- ▌ Google Agents CLI Scaffold · google bundleThis skill should be used when the user wants to "create an agent project", "start a new ADK project", "build me a new agent", "add CI/CD to my project", "add deployment", "enhance my project", or "upgrade my project". Part of the agents-cli skills suite. Covers `agents-cli scaffold create`, `scaffold enhance`, and `scaffold upgrade` commands, template options, deployment targets, and the prototype-first workflow. Do NOT use for writing agent code (ADK projects: use google-agents-cli-adk-code) or deployment operations (use google-agents-cli-deploy).
- ▌ Google Agents CLI Workflow · google bundleThis skill should be used when the user wants to "develop an agent", "build an agent using ADK", "run the agent locally", "debug agent code", "test an agent", "deploy an agent", "publish an agent", "monitor an agent", or needs the ADK (Agent Development Kit) development lifecycle and coding guidelines. Entrypoint for building ADK agents. Always active — provides the full workflow (scaffold, build, evaluate, deploy, publish, observe), code preservation rules, model selection guidance, and troubleshooting steps for ADK or any agent development.
- ▌ Google Agents CLI Observability · google bundleThis skill should be used when the user wants to "set up tracing", "monitor my agent", "configure logging", "add observability", "debug production traffic", or needs guidance on monitoring deployed agents, including ADK (Agent Development Kit) agents. Covers Cloud Trace, prompt-response logging, BigQuery Agent Analytics, third-party integrations (AgentOps, Phoenix, MLflow, etc.), and troubleshooting. Part of the agents-cli skills suite. Do NOT use for deployment setup (use google-agents-cli-deploy) or API code patterns (use google-agents-cli-adk-code).
- ▌ Agents CLI Langchain · google bundleUse when working in this project — adding tools, editing the agent, running, evaluating, serving or deploying it — or when guidance mentions ADK, LlmAgent, google.adk, adk web, or an ADK runner. This project is LangChain/LangGraph scaffolded by agents-cli, so ADK-specific instructions do not apply.