All authors

Claude Skills by coco-research
github.com/coco-research228 skills0 installs18 views
- Gsd Ui ReviewUse when the user asks for a visual or UI quality review of frontend code that already shipped, or passes a phase number. Produces {phase_num}-UI-REVIEW.md with a graded 1-4 assessment across six pillars.Votes: 0GitHub stars: 434
- Gsd UndoUse when the user wants to roll back GSD commits: the last N, a whole phase, or one plan. Reverts through the phase manifest with dependency checks and a confirmation gate before anything is undone.Votes: 0GitHub stars: 434
- Gsd UpdateUse when the user asks whether GSD is up to date or wants to upgrade it. Checks the local and global install against npm, shows the changelog, warns before a clean install, then clears the cache.Votes: 0GitHub stars: 434
- Gsd Validate PhaseUse when validation or test coverage is missing on a phase that already shipped. Audits or reconstructs VALIDATION.md, fills the gaps and generates the missing test files.Votes: 0GitHub stars: 434
- Gsd Verify WorkUse after a phase executes, when the user wants to test the built features themselves. Runs one conversational UAT test at a time into {phase}-UAT.md and, when something fails, diagnoses it and queues fix plans for /gsd-execute-phase.Votes: 0GitHub stars: 434
- Gsd WorkstreamsUse when the user runs /gsd-workstreams or asks to list, create, switch, status, progress, complete, or resume parallel workstreams for concurrent milestone work. The active one is tracked in the GSD_WS variable.Votes: 0GitHub stars: 434
- Embedded CaptionsAdd captions or subtitles to an existing single-subject talking-head video without editing the footage. Use for plain verbatim captions, cinematic captions embedded behind the subject, VFX captions, “炸/特效/酷炫字幕,” or a named identity from the 35-style catalog. Route by visual identity, not by backend engine. The quiet `anchor` rail is the default; embed every word only when the user explicitly wants a fully cinematic treatment. The workflow runs locally end to end, including transcription and s...Votes: 0GitHub stars: 434
- Faceless ExplainerTurn arbitrary text — an article, notes, a topic, a brief — into a faceless explainer video: there is no site or footage to capture, so the visuals are invented per scene (typography, abstract graphics, diagrams, data-viz). Use for topic explainers, concept breakdowns, how-tos, listicles. Not a video built from a website (/product-launch-video — promo or tour). Unclear → /hyperframes.Votes: 0GitHub stars: 434
- FigmaImport Figma content into a HyperFrames composition — rendered assets, brand tokens, components, storyboard sections → reconstructed motion (frames read as states, not slides) (REST/CLI), connector-assisted motion when available, and shaders from a connector or native export. Use when the user pastes a figma.com link or asks to bring a Figma design, frame, logo, brand, or animation into a video/composition.Votes: 0GitHub stars: 434
- General VideoAuthor or edit a custom HyperFrames composition when no specialized workflow fits, or when BRIEF.md sets flow: companion. Use for longer or multi-scene pieces, brand and sizzle reels, montages, static loops, static title cards, footage remixes, and freeform builds. Use motion-graphics instead for a short unnarrated motion-first unit, including an animated title. Route fresh creation through hyperframes before using this skill.Votes: 0GitHub stars: 434
- Hyperframes AnimationAll animation knowledge for HyperFrames — atomic motion rules, multi-phase scene blueprints, scene transitions, broader motion-design techniques, AND the seven runtime adapters (GSAP default, plus Lottie, Three.js, Anime.js, CSS keyframes, Web Animations API, TypeGPU). Use for any motion or animation task: pick 2-4 rules and compose, or load a blueprint, or look up runtime-specific API (e.g. GSAP eases / Lottie player / Three.js mixer). Also covers auditing an existing composition's choreogra...Votes: 0GitHub stars: 434
- Hyperframes CliUse the HyperFrames CLI development loop: init, add, catalog, capture, lint, check, snapshot, compare, grade-compare, preview, play, present, beats, keyframes, single or batch render, publish, cloud, cloudrun, feedback, lambda, doctor, browser, info, upgrade, skills, compositions, docs, benchmark, telemetry, transcribe, auth, tts, and remove-background. Also use when diagnosing build or render failures. validate, inspect, and layout are deprecated aliases; use check. Covers local, HeyGen-host...Votes: 0GitHub stars: 434
- Hyperframes CoreThe HyperFrames composition contract — build one renderable project. Use for composition structure, the `data-*` timing attributes, `class="clip"`, tracks, sub-compositions, variables, framework-owned media playback, deterministic-render rules, and validation. Also covers Tailwind projects and the STORYBOARD.md / SCRIPT.md plan formats. Read before writing composition HTML.Votes: 0GitHub stars: 434
- Hyperframes CreativeNon-animation creative direction for HyperFrames videos. Use for design spec (frame.md / design.md) handling, palettes, typography, narration, beat planning, audio-reactive visuals, composition patterns, and brand / style decisions. For atomic motion patterns and scene blueprints, use `hyperframes-animation`.Votes: 0GitHub stars: 434
- Hyperframes KeyframesUse when a HyperFrames composition needs seek-safe 2D/3D keyframes, GSAP timelines, CSS keyframes, Anime.js, WAAPI, FLIP, paths, masks, SVG morph/draw, text trails, 3D depth, or `hyperframes keyframes` diagnostics. Don't use for broad scene strategy, brand design, media sourcing, captions, or general video planning.Votes: 0GitHub stars: 434
- Hyperframes RegistryInstall, discover, and wire registry blocks and components into HyperFrames compositions. Use when running hyperframes add or hyperframes catalog, installing one item or every block matching a tag, wiring an installed item into index.html, or working with hyperframes.json. Covers discovery, install locations, block sub-composition wiring, component snippet merging, and authoring a new block or component to contribute upstream (idea → scaffold → validate → PR).Votes: 0GitHub stars: 434
- HyperframesMandatory entry point: read this first for any request to make, create, edit, animate, or render a video, animation, or motion graphic, including a promo, explainer, captioned clip, title card, overlay, slideshow or interactive deck, Remotion port, or any HyperFrames HTML composition. Also use it to inspect, diagnose, validate, preview, publish, or batch-render an existing HyperFrames project. Inputs may be a website URL, GitHub PR, Figma design or URL, text or brief, existing footage, or mus...Votes: 0GitHub stars: 434
- Motion GraphicsUse when the user wants a short, design-led, unnarrated motion graphic: kinetic type, stat count-up, chart hit, logo sting, lower-third, animated map, or UI animation. Longer or narrated: /general-video. Unclear: /hyperframes.Votes: 0GitHub stars: 434
- Music To VideoUse when the user supplies a music track, a video to pull audio from, or a mood brief, and wants a beat-synced video: lyric video, slideshow, or kinetic promo. The music drives pacing; zero assets are required.Votes: 0GitHub stars: 434
- Pr To VideoUse when the user wants a GitHub PR (URL, owner/repo#N, or 'this PR') made into a code-change explainer video from its diff and commits: changelog, feature reveal, fix, or refactor. Not a product promo; unclear goes to /hyperframes.Votes: 0GitHub stars: 434
- Product Launch VideoTurn a product or marketing URL, pasted script, or brief into a product launch / promo video — SaaS promos, feature reveals, product demos, app and company launches. Use when the user wants to market, launch, promote, or reveal a product; the default for any commercial URL. Site tours / showcases of a website route here too — the brief carries the show-it-as-is intent. Unclear → /hyperframes.Votes: 0GitHub stars: 434
- Remotion To HyperframesUse when the user explicitly asks to port, convert or migrate a Remotion source to HyperFrames HTML: one-way, Remotion-only. A passing mention or a lookalike request is a fresh build (/general-video); unclear intent goes to /hyperframes.Votes: 0GitHub stars: 434
- SlideshowUse when the user asks for a slideshow, presentation, pitch deck, or interactive deck, or to convert an existing page into a deck. Authors a HyperFrames deck with fragments, branching and presenter mode; unclear -> /hyperframes.Votes: 0GitHub stars: 434
- Talking Head RecutPackage an existing talking-head / interview / podcast video with timed, designed GRAPHIC OVERLAY cards — kinetic titles, lower-thirds, data callouts, quotes, side panels, picture-in-picture — synced to the transcript, on a 16:9 / 9:16 / 4:5 canvas of your choice; the clip plays untouched underneath. Trigger on "graphic overlays", "on-screen graphics", "package / dress up my video". Not plain subtitles (/embedded-captions). Unclear → /hyperframes.Votes: 0GitHub stars: 434
- Website To VideoUse when the user wants a video of a website (site tour, portfolio, docs or landing-page showcase) captured from a URL. Deprecated upstream since v0.7.59: folded into /product-launch-video, which owns URL promo work.Votes: 0GitHub stars: 434
- M0 HandoffUse when the user says m0 handoff, before I compact, end of session, save session state, resume where we left off, or continue in Cursor or Claude Code. Writes or reads a compact_checkpoint so a cold start becomes a continuation.Votes: 0GitHub stars: 434
- M0 RecallUse when the user asks m0 recall, where were we, what did we do last time, catch me up, what is next, or to resume context from another tool. Reads the recent M0 operational thread per project, newest first, from local SQLite.Votes: 0GitHub stars: 434
- M0 RememberUse when the user says 'm0 remember', 'record what we did', 'note for next session' or 'write a checkpoint', or after finishing a step worth handing to the next session. Appends one idempotent entry to the M0 thread.Votes: 0GitHub stars: 434
- M0Use when the user says 'm0', 'm0 status', 'start m0', 'cross-tool memory', 'operational thread', or 'where is my memory stored', or when the M0 server, store, spool, or MCP wiring needs attention.Votes: 0GitHub stars: 434
- Api SecurityUse for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including discovery, authentication, authorization, rate-limit, and CI/CD testing.Votes: 0GitHub stars: 434
- Apk Reverse在 CLI 环境下做 Android APK 逆向时使用。适用于 APK 解包、Java 反编译、smali 修改、重打包、Frida 动态 Hook,以及按需切换到 so/native 分析。优先使用本机已安装的 jadx、apktool、frida、adb、ida-reverse、radare2。Votes: 0GitHub stars: 434
- Binary Diff跨版本符号迁移与二进制差分。当你有旧版本的符号/逆向结果,需要快速迁移到新版本时使用。 适用场景:内核缺 PDB 用旧版符号推导、程序更新后批量迁移函数名、应用更新后快速定位新偏移。 核心方法:用 LLM 做结构化差异比对,程序化输入输出,成本极低(200 函数 ~1 元)。 触发关键词:符号迁移、bindiff、跨版本、PDB 缺失、函数偏移迁移、symbol migration、binary diff、版本对比。Votes: 0GitHub stars: 434
- Browser Automation统一自动化入口。覆盖浏览器自动化(Playwright)和 Windows 桌面应用自动化(OpenReverse)。 浏览器场景:打开网页、点击、填表、爬取、截图、自动化登录、渗透页面交互。 桌面场景:操作 IDA/x64dbg 等 GUI 工具、Windows UI Automation、视觉驱动交互、桌面应用网络抓包。 触发关键词:浏览器自动化、桌面自动化、打开网页、填表、爬取、截图、自动化登录、Playwright、agent-browser、headless、OpenReverse、UIA、CUA、桌面操作、Windows 自动化。Votes: 0GitHub stars: 434
- Browser Extension ReverseUse for authorized reverse engineering of browser extensions (Chrome/Firefox) including manifest analysis, background workers, and extension-based credential or traffic logic recovery.Votes: 0GitHub stars: 434
- Cloud K8sUse for authorized cloud, container, and Kubernetes security assessment including metadata SSRF, IAM misconfig, container escape paths, and cluster RBAC review.Votes: 0GitHub stars: 434
- Code AuditUse for authorized source-code security review and SAST workflows including Semgrep, CodeQL patterns, dangerous API hunting, and fix verification.Votes: 0GitHub stars: 434
- Database SecurityUse for authorized database security assessment covering PostgreSQL/MySQL/MSSQL/Mongo/Redis exposure, authz, UDF/command paths, and misconfiguration review.Votes: 0GitHub stars: 434
- Digital ForensicsUse for authorized digital forensics including memory dumps, disk timelines, PCAP investigation, artifact triage, and IR evidence preservation.Votes: 0GitHub stars: 434
- Docs GeneratorCreates task-oriented technical documentation with progressive disclosure. Use when writing READMEs, API docs, architecture docs, or markdown documentation. Also use this skill at the END of any completed reverse engineering, penetration testing, CTF, or security analysis task to generate a formal report in the user's project directory. Trigger keywords: 写报告, 写文档, 出报告, writeup, 技术文档, report, documentation.Votes: 0GitHub stars: 434
- Dotnet Reverse.NET / C# 二进制逆向。当目标是 .NET assembly(PE 头含 CLR、.exe/.dll 托管程序)、C# 编译产物(含 NativeAOT)、红队 Sharp* 工具(Rubeus / SharpHound / SharpHound 等)、.NET 混淆程序(ConfuserEx / SmartAssembly / Babel / Eazfuscator)、.NET loader / info-stealer / 套壳 malware 时使用。优先用 dnSpyEx + de4dot,需要 AI 直接操作时联动 dnSpy MCP。不用于纯 native 二进制(走 reverse-engineering / ida-reverse)。Votes: 0GitHub stars: 434
- Email SecurityUse for authorized email security review including phishing analysis, header authentication (SPF/DKIM/DMARC), BEC patterns, and mailbox token abuse research.Votes: 0GitHub stars: 434
- Firmware Pentest固件 / IoT 渗透链。从拿到一坨 .bin / .img 开始,闭环走完逆向 → 提取 → 模拟 → 利用。 方法论遵循 OWASP FSTM 九阶段;工具链以 binwalk v3、unblob、EMBA、Firmadyne、AFL++ 为主。 适用场景:路由器/摄像头/智能家居固件审计、固件升级包逆向、IoT CVE 复现、嵌入式 0day 挖掘。 触发关键词:固件、firmware、IoT、binwalk、unblob、UART、JTAG、squashfs、UBI、JFFS2、Firmadyne、QEMU 全系统仿真、EMBA、固件渗透、路由器固件、嵌入式漏洞利用、bootloader、NVRAM、FAT、firmware analysis toolkit。Votes: 0GitHub stars: 434
- Ghidra ReverseUse for free/open reverse engineering with Ghidra (headless or GUI), including decompile, cross-refs, and optional Ghidra MCP workflows when IDA is unavailable.Votes: 0GitHub stars: 434
- Go Rust ReverseUse for reverse engineering stripped Go and Rust binaries including runtime recognition, pclntab/moduel data recovery, panic strings, and idiomatic decompilation recovery.Votes: 0GitHub stars: 434
- Hardware SecurityUse for authorized hardware and embedded interface security research including UART/JTAG discovery, debug pad triage, secure boot overview, and offline firmware extraction support.Votes: 0GitHub stars: 434
- Identity FederationUse for authorized assessment of federated identity systems including SAML, OIDC, OAuth2 flows, SSO misconfiguration, and token confusion issues.Votes: 0GitHub stars: 434
- Js Reverse在使用 js-reverse-mcp 做前端 JavaScript 逆向时使用,适用于签名链路定位、页面观察取证、运行时采样、本地补环境复现与证据化输出。优先适配当前环境里的 js-reverse_* 工具,需要更强的浏览器/CDP/Hook 面时联动 jshookmcp。Votes: 0GitHub stars: 434
- Llm SecurityUse for authorized security assessment of LLM applications and AI agents, including prompt injection, tool abuse, RAG exposure, memory poisoning, and model supply-chain risks.Votes: 0GitHub stars: 434
- Macos ReverseUse for authorized macOS and Mach-O reverse engineering including codesign, Objective-C/Swift recovery, endpoint security surfaces, and Apple platform malware analysis.Votes: 0GitHub stars: 434
- Malware AnalysisUse when analyzing suspected malware through static, dynamic, and behavioral techniques, including IOC extraction, YARA or Sigma rules, sandboxing, and anti-analysis behavior.Votes: 0GitHub stars: 434