All authors

Claude Skills by HermeticOrmus
github.com/HermeticOrmus180 skills3 installs188 views
- Meta Prompt IterateRecursively improve LLM outputs through quality-driven iteration with automatic complexity routing, context extraction, and quality assessment.Votes: 0GitHub stars: 65
- Nexus Tui Generator> **Version**: 1.0.0 > **Purpose**: Generate production-ready TUI applications from natural language using iterative meta-prompting > **Theme**: Gold (#D4AF37) and Navy Blue (#1B365D) ---Votes: 0GitHub stars: 65
- Verify Claude Code Game DevelopmentInstall the claude-code-game-development plugin pack the way a user does, into a clean Claude Code config and a clean Grok Build home, prove every plugin validates, installs and loads its components, and keep the transcripts. Use when proving a claude-code-game-development PR's Done-when, checking that a plugin change still installs in both CLIs, or reproducing an install bug.Votes: 0GitHub stars: 65
- Cortex M PatternsCortex-M code patterns for SysTick, NVIC priority grouping, FPU enable, MPU regions, AAPCS inline assembly, DWT cycle counting, vector table relocation, and WFI sleep entry. Use when writing core-level Cortex-M code or checking it against a known-good pattern.Votes: 0GitHub stars: 50
- Bare Metal PatternsRegister-level C patterns for Cortex-M without a HAL: bit manipulation macros, GPIO and polled UART setup, SysTick timebase, interrupt-driven UART ring buffer, linker sections and map files, and weak default ISR handlers. Use when writing or reviewing HAL-free drivers and startup code.Votes: 0GitHub stars: 50
- Bootloader PatternsBootloader patterns for STM32, nRF52, and SAM parts: boot decision tree, RTC backup register boot flags, dual-bank flash layout, YMODEM receive over UART, post-flash verification, and watchdog handling during boot. Use when building or reviewing the boot path of a device that updates in the field.Votes: 0GitHub stars: 50
- Communication BusesBus reference for I2C, SPI, UART, CAN, and USB: addressing, pull-up sizing, bus recovery, SPI mode card, DMA cache rules, ring buffers, CAN bit timing and error states, USB descriptors, and STM32 HAL code for each bus. Use when writing or reviewing a bus driver or diagnosing a misbehaving bus.Votes: 0GitHub stars: 50
- Debug Trace PatternsCortex-M debug patterns: CFSR decoding after a HardFault, addr2line from fault PC to source line, GDB commands for live faults, stack canaries, ITM printf, and DWT data watchpoints. Use when chasing a crash, a hang, or memory corruption on target.Votes: 0GitHub stars: 50
- Embedded Linux PatternsEmbedded Linux patterns: Yocto layer and recipe hierarchy, kernel config fragments, device tree GPIO and interrupt properties, out-of-tree module Makefiles, sysfs attributes, and QEMU testing before hardware. Use when customizing a Linux image or writing a driver for an ARM board.Votes: 0GitHub stars: 50
- Embedded Testing PatternsFirmware test patterns with Unity, CMock, Ceedling, and QEMU: project layout, testable HAL interfaces, CMock expect chaining, error-path tests, and an on-target test runner over ITM. Use when making embedded C testable or writing tests for it.Votes: 0GitHub stars: 50
- Firmware Update PatternsOTA update patterns: MCUboot image headers, update progress over MQTT, version comparison, boot counters with automatic rollback, and aligned chunk writes. Use when implementing the device side of a firmware update.Votes: 0GitHub stars: 50
- Fpga PatternsSynthesizable Verilog patterns for MCU-FPGA designs on Artix-7 and Cyclone V: register bank with strobes, two-flop clock domain crossing, PWM generator, Vivado block design Tcl, and ILA or SignalTap capture. Use when writing FPGA logic that an MCU drives or debugging it in hardware.Votes: 0GitHub stars: 50
- Iot ProtocolsIoT protocol reference: selection matrix, MQTT QoS flows and LWT, topic design, CoAP observe and block-wise transfer, LwM2M objects and firmware update, BLE GATT and connection tuning, LoRaWAN airtime and classes, and Paho, Zephyr, and ESP-IDF client code. Use when designing or debugging the protocol layer of a connected device.Votes: 0GitHub stars: 50
- Memory Mgmt PatternsDeterministic memory patterns: static FreeRTOS objects, pools for variable-rate messages, heap statistics, stack high-water mark audits, and placing arrays in specific SRAM regions. Use when removing malloc from firmware or tracking down memory exhaustion.Votes: 0GitHub stars: 50
- Power Mgmt PatternsLow-power patterns: sleep entry checklist, RTC alarm wake-up, GPIO leakage prevention, a power budget format, and FreeRTOS tickless idle on LPTIM. Use when cutting sleep current or estimating battery life.Votes: 0GitHub stars: 50
- Rtos PatternsFreeRTOS and Zephyr reference: priority inversion taxonomy, deferred interrupt processing, watchdog kick patterns, mutex vs. semaphore choice, stack sizing, FreeRTOSConfig.h settings, the stack overflow hook, and rate monotonic analysis. Use when designing, reviewing, or debugging RTOS firmware.Votes: 0GitHub stars: 50
- Safety Critical PatternsSafety-critical C patterns: MISRA-compliant fixed-width types, single-exit functions (Rule 15.5), suppression comments, a March-C RAM test, and CRC protection of critical data. Use when writing or reviewing firmware under a functional safety standard.Votes: 0GitHub stars: 50
- Sensor PatternsSensor patterns in embedded C: SPI register protocol, NTC thermistor conversion, multi-point calibration tables, median filters for spike rejection, and temperature compensation. Use when writing a sensor driver or cleaning up noisy readings.Votes: 0GitHub stars: 50
- Verify Libre EmbedInstall the LibreEmbed-Claude-Code plugin pack the way a user does, into a clean Claude Code config and a clean Grok Build home, prove every plugin validates, installs and loads its components, and keep the transcripts. Use when proving a LibreEmbed-Claude-Code PR's Done-when, checking that a plugin change still installs in both CLIs, or reproducing an install bug.Votes: 0GitHub stars: 50
- Verify Design MasteryInstall the design-mastery-claude-code plugin pack the way a user does, into a clean Claude Code config and a clean Grok Build home, prove every plugin validates, installs and loads its components, and keep the transcripts. Use when proving a design-mastery-claude-code PR's Done-when, checking that a plugin change still installs in both CLIs, or reproducing an install bug.Votes: 0GitHub stars: 18
- Example SkillA fill-in template that shows the SKILL.md layout: frontmatter, when to use it, a step-by-step procedure, output templates, and notes. Use when writing a new skill and you want a starting structure to copy and adapt.Votes: 0GitHub stars: 8
- Verify Claude Code GuideInstall the claude-code-guide plugin pack the way a user does, into a clean Claude Code config and a clean Grok Build home, prove every plugin validates, installs and loads its components, and keep the transcripts. Use when proving a claude-code-guide PR's Done-when, checking that a plugin change still installs in both CLIs, or reproducing an install bug.Votes: 0GitHub stars: 8
- Api Auth PatternsSecure implementation patterns for API authentication and authorization: OAuth 2.0 flows, JWT best practices, API key handling with constant-time comparison, mTLS, session management, authorization middleware, token refresh, and rate limiting. Use when building or reviewing API auth code.Votes: 0GitHub stars: 4
- Detection EngineeringDetection engineering reference: the detection lifecycle and quality metrics, Sigma rule syntax and modifiers, YARA rule writing, a detection-as-code CI pipeline, and essential Windows detections. Use when writing, testing, or maintaining detection rules.Votes: 0GitHub stars: 4
- Threat Hunting MethodologyHypothesis-driven threat hunting framework with hunt categories, required data sources, worked hunts for DNS tunneling, lateral movement, and persistence, and a hunt documentation template. Use when planning, running, or documenting a threat hunt.Votes: 0GitHub stars: 4
- Recon MethodologyReconnaissance methodology for authorized bug bounty programs: passive recon (certificate transparency, search engine and code dorking, historical URLs), in-scope active recon (subdomain enumeration, live host probing, content and JavaScript analysis), and attack surface mapping. Use when scoping recon inside a program's published rules.Votes: 0GitHub stars: 4
- Vuln Report WritingGuide to vulnerability reports that get accepted and triaged: title writing, CVSS v3.1 scoring, reproduction steps, impact writing, the report lifecycle, chaining, evidence, and minimal PoC scripts. Use when drafting or reviewing a bug bounty or disclosure report.Votes: 0GitHub stars: 4
- Aws Iam PatternsAWS IAM reference: policy evaluation logic, policy types, least-privilege Lambda roles, permission boundaries, SCP guardrails, cross-account access with external ID, and IAM anti-patterns such as unconstrained PassRole. Use when writing or reviewing IAM policies.Votes: 0GitHub stars: 4
- Aws S3 SecurityS3 security reference: access control layers, encryption models, a secure bucket baseline in Terraform, TLS-only bucket policies, access points, and anti-patterns such as public buckets and ACL reliance. Use when configuring or auditing S3 buckets.Votes: 0GitHub stars: 4
- Azure Identity PatternsEntra ID security patterns: Conditional Access baseline policies, managed identities, Privileged Identity Management, certificate-based service principals, and anti-patterns such as permanent Global Administrator assignments and client secrets. Use when designing or reviewing Azure identity.Votes: 0GitHub stars: 4
- Gcp Iam PatternsGCP IAM reference: the permission model, role types, deny policies, least-privilege service accounts, Workload Identity Federation for CI, custom roles, domain-restricted sharing, and GKE Workload Identity. Use when writing or reviewing GCP IAM bindings.Votes: 0GitHub stars: 4
- Gdpr RequirementsGDPR reference for technology teams: key definitions, Article 5 principles, lawful bases, data subject rights, data protection by design, processor duties, breach notification, DPIAs, a SaaS compliance checklist, and a data deletion pattern. Use when building or reviewing systems that process EU personal data.Votes: 0GitHub stars: 4
- Soc2 ControlsSOC 2 Type II reference: the Trust Service Criteria, Common Criteria controls, evidence requirements, a readiness pattern, and common auditor requests. Use when preparing for a SOC 2 audit or designing controls to satisfy it.Votes: 0GitHub stars: 4
- Container Runtime SecurityContainer runtime isolation reference: namespaces, Linux capabilities, seccomp, AppArmor, user namespace remapping, hardened docker run and Compose examples, and anti-patterns such as --privileged, Docker socket mounts, and --pid=host. Use when configuring how containers run.Votes: 0GitHub stars: 4
- Dockerfile HardeningSecure Dockerfile patterns: base image hierarchy, multi-stage builds for Node.js and Go on distroless or scratch, BuildKit secret mounts, and non-root execution. Use when writing or reviewing a Dockerfile.Votes: 0GitHub stars: 4
- Crypto AlgorithmsAlgorithm selection guide: a decision tree for cryptographic choices, key size guidelines, modes of operation, and worked examples for authenticated encryption with libsodium, Argon2id password hashing, and Ed25519 signatures. Use when picking an algorithm, mode, or key size.Votes: 0GitHub stars: 4
- Key ManagementKey management reference: key lifecycle and types, storage security hierarchy, rotation strategy, envelope encryption, crypto-shredding, KMS access control, and anti-patterns such as keys in source code. Use when designing how keys are stored, rotated, or destroyed.Votes: 0GitHub stars: 4
- Ci Security PatternsReference pipelines for security scanning in GitHub Actions, GitLab CI, and Jenkins, plus pre-commit hooks, with stage ordering and design decisions. Use when adding or reviewing security stages in CI.Votes: 0GitHub stars: 4
- Security GatesSecurity gate reference: gate types, severity matrices, risk-based gating with CVSS, EPSS, and KEV, differential gating for new code, application-tiered gates, and an override process. Use when deciding when a finding should break the build.Votes: 0GitHub stars: 4
- Forensic MethodologyForensic methodology following NIST SP 800-86 and ISO 27037: the forensic process, order of volatility (RFC 3227), evidence integrity, KAPE triage collection, and disk imaging with dc3dd and ewfacquire. Use when collecting or preserving evidence during an investigation.Votes: 0GitHub stars: 4
- Memory ForensicsMemory forensics reference: acquisition tools (WinPMem, DumpIt, FTK Imager, LiME, AVML), Volatility 3 architecture, and triage patterns for processes, hidden processes, and injected code. Use when acquiring or analyzing a memory image during incident response.Votes: 0GitHub stars: 4
- Access Control ModelsRBAC, ABAC, and ReBAC (Zanzibar-style) reference with a decision framework, implementation patterns, a segregation-of-duties matrix, and anti-patterns such as role explosion and hard-coded authorization. Use when choosing or implementing an authorization model or fixing IDOR-style ambient authority.Votes: 0GitHub stars: 4
- Mfa ImplementationMFA reference covering factor types, NIST AAL levels, WebAuthn/FIDO2 registration, TOTP implementation, enforcement middleware with step-up auth, and bypass risks such as SMS SIM swap and prompt bombing. Use when adding or hardening multi-factor authentication.Votes: 0GitHub stars: 4
- Ir PlaybooksStep-by-step incident response playbooks (indicators, validation, containment, eradication and recovery, post-incident) for malware infection, account compromise, data breach, ransomware, DDoS, and insider threat. Use when responding to one of these incidents or writing its runbook.Votes: 0GitHub stars: 4
- K8s Rbac PatternsKubernetes RBAC reference: the Role and ClusterRole binding model, evaluation logic, escalation paths, least-privilege patterns for developers, CI/CD, monitoring, and break-glass access, plus common misconfigurations. Use when writing RBAC manifests or reviewing who can do what in a cluster.Votes: 0GitHub stars: 4
- K8s Security PoliciesPod Security Standards and Pod Security Admission, NetworkPolicy fundamentals with default-deny and service-to-service patterns, restricted-profile pod security contexts, and Kyverno examples. Use when hardening workloads or writing NetworkPolicy and admission rules.Votes: 0GitHub stars: 4
- Ioc PatternsIndicator of compromise taxonomy ranked by the Pyramid of Pain, extraction and defanging patterns, quality assessment, and structured formats such as STIX 2.1 for sharing. Use when extracting, prioritizing, or formatting IOCs from an investigation.Votes: 0GitHub stars: 4
- Malware Analysis MethodologyDefensive malware analysis workflow from safe handling in an isolated lab through triage, static analysis, dynamic analysis, and reporting with ATT&CK mapping and YARA, Snort/Suricata, or Sigma signatures. Use when planning or running an analysis of a suspected sample for incident response.Votes: 0GitHub stars: 4
- Mobile Crypto PatternsMobile cryptography patterns for Android Keystore and iOS Secure Enclave, Keychain, and CryptoKit: key storage, data-at-rest encryption, password key derivation, TLS and certificate pinning, and secure randomness. Use when implementing or reviewing crypto in a mobile app.Votes: 0GitHub stars: 4
- Owasp MasvsOWASP MASVS v2.0 reference covering every control group (storage, crypto, auth, network, platform, code, resilience) and how each maps to MASTG test cases. Use when scoping, testing, or reporting against the mobile verification standard.Votes: 0GitHub stars: 4