All authors

Claude Skills by Amey-Thakur
github.com/Amey-Thakur1,001 skills16 installs1,473 views
- Autocomplete DesignSuggest queries as the user types, fast enough to feel instant and relevant enough to be worth reading. Use when adding a search box that should guide rather than merely accept input.Votes: 0GitHub stars: 7
- Faceted SearchProvide filters that narrow results honestly, with counts that reflect what is actually available and a clear way back out. Use when a result set is large enough that browsing needs structure.Votes: 0GitHub stars: 7
- Full Text Search DesignDesign a text search feature with the right analyzer, fields, and matching model so results are relevant rather than merely returned. Use when adding search to a product or replacing a LIKE query that no longer works.Votes: 0GitHub stars: 7
- Hybrid SearchCombine keyword and vector retrieval so exact terms and semantic meaning both work, and fuse the two rankings sensibly. Use when keyword search misses paraphrases or vector search misses exact identifiers.Votes: 0GitHub stars: 7
- Query UnderstandingInterpret what a user meant before matching, through normalisation, intent detection, and entity extraction. Use when queries are short, ambiguous, or full of product-specific language.Votes: 0GitHub stars: 7
- Relevance TuningImprove ranking with a judged evaluation set and measured changes rather than intuition. Use when search feels wrong and every proposed fix is someone's opinion.Votes: 0GitHub stars: 7
- Search AnalyticsInstrument search so queries, clicks, and abandonment tell you what to fix. Use when improving relevance without evidence, or when nobody can say whether search works.Votes: 0GitHub stars: 7
- Search Indexing PipelineGet data into a search index reliably and keep it current, with reindexing, partial updates, and a defined staleness budget. Use when search results lag reality or a schema change requires a full rebuild.Votes: 0GitHub stars: 7
- Search Result PresentationPresent results so a user can judge relevance without opening each one, with useful snippets, clear grouping, and honest metadata. Use when results are correct but users still cannot find what they need.Votes: 0GitHub stars: 7
- Synonyms And StemmingMatch words to their variants and equivalents without collapsing distinctions that matter. Use when searches miss obvious results, or when unrelated results appear because two words were merged.Votes: 0GitHub stars: 7
- Typo ToleranceCorrect or forgive misspelled queries without turning precise searches into fuzzy guesses. Use when users mistype and get nothing, or when fuzzy matching returns irrelevant results.Votes: 0GitHub stars: 7
- Zero Results HandlingTurn an empty result set into a useful next step instead of a dead end, and treat the query as a signal worth acting on. Use when searches return nothing and users leave.Votes: 0GitHub stars: 7
- Api SecuritySecure an API by enforcing per-object authorization, per-caller quota, and schema-validated input on every endpoint. Use when building or reviewing an HTTP or GraphQL API that serves authenticated users, machine clients, or partner integrations.Votes: 0GitHub stars: 7
- Audit LoggingRecord security-relevant events in a tamper-evident, append-only log that answers who did what and when. Use when building or reviewing logging for authentication, authorization, privilege changes, or access to sensitive data.Votes: 0GitHub stars: 7
- Authn DesignDesign sign-in so credentials are hashed with a slow algorithm, guessing is rate limited, and sessions rotate on login to defeat fixation. Use when building or reviewing registration, login, or password-reset flows.Votes: 0GitHub stars: 7
- Authz DesignEnforce authorization so access is denied by default and every request re-checks that the caller owns the specific resource, closing IDOR gaps. Use when building endpoints that read or modify data belonging to a particular user or tenant.Votes: 0GitHub stars: 7
- Browser Storage SafetyDecide where a web app keeps tokens and state by reasoning about the XSS blast radius of each store, not by convenience. Use when choosing how to persist session tokens, auth state, or any value an attacker on your origin would want to read.Votes: 0GitHub stars: 7
- Bug BountyHunt vulnerabilities in bug bounty programs effectively and within the rules: scope, methodology, safe proof, and reports that get accepted. Use when participating in a bug bounty or coordinated disclosure program.Votes: 0GitHub stars: 7
- Clickjacking DefenseStop UI redress attacks by declaring who may frame your pages, using frame-ancestors as the primary control and X-Frame-Options as the fallback. Use when hardening any page that performs sensitive actions on a click, especially authenticated dashboards and confirmation flows.Votes: 0GitHub stars: 7
- Command Injection DefenseRun external programs without ever building a shell string from untrusted input, using argument arrays that bypass the shell entirely. Use when a program shells out to another binary, especially with any value that came from a user, a file, or the network.Votes: 0GitHub stars: 7
- Container SecurityHarden container images and runtime specs with minimal bases, non-root users, read-only filesystems, and dropped capabilities. Use when writing image or Kubernetes security settings or reviewing a container for privilege risk.Votes: 0GitHub stars: 7
- Crypto UsageUse cryptography by calling vetted libraries with authenticated defaults and storing keys in a KMS, never by designing a scheme. Use when adding encryption, choosing a cipher or mode, or reviewing code that handles keys or ciphertext.Votes: 0GitHub stars: 7
- Csrf DefenseBlock cross-site request forgery with SameSite cookies, per-session anti-CSRF tokens, and strict HTTP method discipline so a forged cross-origin request cannot act as the user. Use when building state-changing endpoints authenticated by cookies.Votes: 0GitHub stars: 7
- Data EncryptionEncrypt data at rest and in transit with vetted primitives and a managed key service that rotates on schedule. Use when handling sensitive data on disk or over the network, or when reviewing how a system stores and moves it.Votes: 0GitHub stars: 7
- Dependency AuditingAudit third-party packages by pinning resolved versions, scanning against advisory databases, and catching malicious lookalikes before install. Use when adding a dependency, wiring a vulnerability gate into CI, or reviewing what a project actually pulls in.Votes: 0GitHub stars: 7
- Deserialization SafetyTreat any serialized bytes from outside the program as hostile, parsing them through schema-validated formats instead of native object reconstructors. Use when reading pickles, Java or PHP serialized objects, YAML, or any encoded structure that arrives from a user, a queue, or a cache.Votes: 0GitHub stars: 7
- File Upload SafetyAccept user file uploads without letting them become code execution, storage exhaustion, or a path into other users' data. Use when building an upload endpoint, an avatar or document feature, or any handler that writes client-supplied bytes to disk or object storage.Votes: 0GitHub stars: 7
- Input ValidationValidate untrusted input at every trust boundary with allowlists, canonicalization, and hard limits so malformed data never reaches logic. Use when accepting data from requests, files, uploads, or third-party APIs.Votes: 0GitHub stars: 7
- Jwt HandlingUse JSON Web Tokens safely by pinning the algorithm, keeping lifetimes short, and pairing them with a revocation path. Use when issuing or validating JWTs, designing a session scheme around them, or reviewing token-based auth.Votes: 0GitHub stars: 7
- Least PrivilegeScope every credential to the minimum actions it uses, with per-workload identities and expiry so a leak has a small blast radius. Use when writing an IAM policy, provisioning a service account, or reviewing an access grant.Votes: 0GitHub stars: 7
- Mobile App SecurityProtect a mobile app by storing secrets in the platform keystore, pinning certificates only where rotation is controlled, and treating obfuscation as delay rather than defense. Use when building or reviewing an iOS or Android app that holds tokens, keys, or user data on device.Votes: 0GitHub stars: 7
- Oauth FlowsImplement OAuth 2.0 and OpenID Connect flows that bind the request end to end with PKCE, state, and exact redirect allowlists. Use when adding "sign in with" a provider, integrating a third-party API on a user's behalf, or reviewing an OAuth client.Votes: 0GitHub stars: 7
- Open Redirect DefenseValidate every redirect destination against a server-side allowlist so a user-controlled target cannot bounce victims onto an attacker's site. Use when an endpoint reads a next, return_to, or callback parameter and sends the browser there.Votes: 0GitHub stars: 7
- Password StorageStore passwords with a slow, salted, memory-hard hash and a plan to raise the cost over time. Use when building signup or login, migrating off a weak hash, or reviewing how a system persists user passwords.Votes: 0GitHub stars: 7
- Path Traversal DefenseStop user-supplied path components from escaping the directory you meant to confine them to. Use when a filename, path segment, or archive entry from outside the program is joined into a filesystem path for reading, writing, or serving.Votes: 0GitHub stars: 7
- Penetration Test PrepPrepare for a penetration test by fixing scope, rules, and access up front, then turn its findings into tracked, verified remediation. Use when commissioning an external pentest or acting on the report one delivered.Votes: 0GitHub stars: 7
- Phishing ResistanceDesign authentication whose credentials cannot be relayed to a look-alike site, using origin-bound passkeys and hardware keys over phishable codes. Use when choosing MFA factors, building a passkey flow, or reviewing account recovery.Votes: 0GitHub stars: 7
- Pii HandlingMinimize, classify, mask, and expire personal data so any leak or legal request reaches as little of it as possible. Use when designing storage, logging, or analytics that touch names, contacts, identifiers, or other personal data.Votes: 0GitHub stars: 7
- Rate LimitingLimit requests by the cost they impose and the identity behind them, using token buckets, deliberate keys, and tiered responses to abuse. Use when protecting an API, a login flow, or any expensive endpoint from brute force, scraping, and accidental overload.Votes: 0GitHub stars: 7
- Sast IntegrationWire a static analysis scanner into CI so it blocks real security bugs while staying under a defined noise budget. Use when adding a SAST tool to a pipeline or when an existing one is being ignored.Votes: 0GitHub stars: 7
- Sbom ManagementProduce signed software bills of materials from real artifacts and consume them to answer "are we affected" fast. Use when setting up build output, responding to a new advisory, or fielding a customer SBOM request.Votes: 0GitHub stars: 7
- Secrets ManagementKeep credentials out of source by loading them from a controlled store, scanning for leaks, and rotating on a schedule. Use when adding a secret to an app, cleaning one out of a repository, or setting up how a service reads credentials at runtime.Votes: 0GitHub stars: 7
- Secrets ScanningScan commit history and CI for leaked credentials and rotate on every hit, because a pushed secret is already compromised. Use when hardening a repo against committed keys or responding to a suspected leak.Votes: 0GitHub stars: 7
- Security Code ReviewRead a diff for security by tracing attacker-controlled input to dangerous operations and checking every trust boundary it crosses. Use when reviewing code that handles input, queries, files, output rendering, or authorization.Votes: 0GitHub stars: 7
- Security HeadersSet the HTTP response headers that constrain what a browser will execute, embed, and leak on behalf of your origin. Use when hardening a web app against cross-site scripting, clickjacking, or referrer leakage, or when a security scan flags missing headers.Votes: 0GitHub stars: 7
- Security Incident ResponseRun a security breach through containment, evidence preservation, and notification duties in the right order, under time pressure, without destroying the record you will need. Use when you suspect or confirm a compromise: leaked credentials, unauthorized access, malware, or exfiltrated data.Votes: 0GitHub stars: 7
- Security ReviewReview code for the vulnerabilities that actually get exploited, ranked by real risk with concrete attack scenarios. Use when reviewing changes that touch input handling, auth, secrets, files, queries, or network calls.Votes: 0GitHub stars: 7
- Session ManagementHandle sessions so identifiers rotate on privilege change, expire on inactivity, can be revoked server-side, and ride only on hardened cookies. Use when issuing, storing, or validating session tokens after a user signs in.Votes: 0GitHub stars: 7
- Sql Injection DefenseEliminate SQL injection by sending data as bound parameters instead of concatenated query text, and auditing every raw-SQL escape hatch. Use when writing or reviewing code that builds database queries from variables.Votes: 0GitHub stars: 7
- Ssrf DefensePrevent server-side request forgery by constraining where a user-influenced URL can make the server connect. Use when the server fetches a URL that came from a user: webhooks, link previews, image proxies, PDF renderers, or import-from-URL features.Votes: 0GitHub stars: 7