All authors

Claude Skills by jiayaoqijia
github.com/jiayaoqijia2,216 skills3 installs4,789 views
- Chaingpt Org Official UpdateCheck for and apply updates to the ChainGPT skill. Use when: update chaingpt, update skill, check for updates, latest version, outdated docs, new api features.Votes: 0GitHub stars: 76
- Ianalloway Bet JournalTrack your sports bets in a local CSV journal. Calculate ROI, CLV, win rate by sport/bet-type, and identify where you're actually making money.Votes: 0GitHub stars: 76
- Ianalloway Crypto PriceGet real-time cryptocurrency prices, market data, and portfolio trackingVotes: 0GitHub stars: 76
- Ianalloway Data VizCreate data visualizations from the command line. Generate charts, graphs, and plots from CSV/JSON data without leaving the terminal.Votes: 0GitHub stars: 76
- Ianalloway Devin IntegrationDelegate coding tasks to Devin AI agent. Create PRs, fix bugs, build features, and manage GitHub repos through Devin's API.Votes: 0GitHub stars: 76
- Ianalloway Dfs OptimizerBuild optimal Daily Fantasy Sports lineups for DraftKings and FanDuel. Maximize projected points under salary cap constraints for NBA, NFL, and MLB slates.Votes: 0GitHub stars: 76
- Ianalloway Git HelperCommon git commands, workflows, and troubleshooting for everyday developmentVotes: 0GitHub stars: 76
- Ianalloway Judge AuditAudit an LLM-as-judge with juryrig — position bias, verbosity bias, prompt injection, consistency, and calibration via CLI or HttpJudge.Votes: 0GitHub stars: 76
- Ianalloway Kelly CriterionCalculate optimal bet sizes using the Kelly Criterion formula. Maximize long-term bankroll growth while managing risk.Votes: 0GitHub stars: 76
- Ianalloway Market SentimentAnalyze market sentiment for stocks and crypto using Reddit, news headlines, and fear/greed indicators. Get a quick read on crowd psychology before trading.Votes: 0GitHub stars: 76
- Ianalloway Nft TrackerTrack NFT collection prices, floor prices, and sales data. Supports Ethereum collections including BAYC, MAYC, CryptoPunks, and more.Votes: 0GitHub stars: 76
- Ianalloway Portfolio RebalancerCalculate portfolio rebalancing trades to hit target allocations. Supports stocks, crypto, and mixed portfolios.Votes: 0GitHub stars: 76
- Ianalloway Screenshot AnnotatorCapture, annotate, and share screenshots with AI-powered descriptions using Peekaboo.Votes: 0GitHub stars: 76
- Ianalloway Security ScannerScan code and dependencies for security vulnerabilities. Check npm audit, pip safety, and common security issues.Votes: 0GitHub stars: 76
- Ianalloway Sports OddsGet live sports betting odds and compare lines across sportsbooks. Supports NFL, NBA, MLB, NHL, and more.Votes: 0GitHub stars: 76
- Ianalloway Streak TrackerTrack hot and cold streaks for sports teams and players. Identify momentum patterns, ATS performance trends, and regression-to-mean signals.Votes: 0GitHub stars: 76
- Ianalloway Weather ForecastGet current weather conditions and forecasts for any locationVotes: 0GitHub stars: 76
- ArbitrumAssist with Arbitrum One transactions, bridging, gas optimization, and L2 ecosystem navigation.Votes: 0GitHub stars: 76
- Ashrafiucse Auth ReviewReviews authentication and authorization in any codebase — login flows, password storage, session/cookie handling, JWT pitfalls, OAuth/OIDC misconfigurations, IDOR/broken access control, privilege escalation, CSRF protection, route census for unguarded endpoints, trusted-header identity spoofing, check-then-act race conditions (TOCTOU), and WebSocket/SSE authorization. Use when auditing how users log in, how permissions are enforced, how internal services trust each other, or when reviewing a...Votes: 0GitHub stars: 76
- Ashrafiucse Config HardeningAudits configuration security in any project — HTTP security headers, CORS policy, cookie flags, TLS settings, debug modes in production configs, default credentials, exposed admin/debug endpoints, CI/CD pipeline risks (GitHub Actions, GitLab CI), and exposed sensitive files. Use when auditing web server, framework, reverse proxy, or CI configuration files.Votes: 0GitHub stars: 76
- Ashrafiucse Container Iac SecurityAudits container and infrastructure-as-code security — Dockerfiles, docker-compose, Kubernetes manifests/helm charts, Terraform, CloudFormation, Pulumi. Finds root containers, untagged images, secrets baked into layers, privileged containers, host mounts, overly open security groups, unencrypted storage, and IAM over-privilege. Use when auditing Docker, Kubernetes, Terraform, or cloud infrastructure definitions.Votes: 0GitHub stars: 76
- Ashrafiucse Course Platform SecurityAudits course-selling / e-learning platforms for domain-specific security — catalog gating truth (draft/unpublished/private course exposure to public), preview-vs-full-content leaks, enrollment state machines (free enrollment without paid order), cohort/multi-cohort access control (student of cohort A reading cohort B), and persona-driven route checks (admin-only surfaces reachable by public/student). Use when the project sells or gates digital courses/content — look for courses, lessons, enr...Votes: 0GitHub stars: 76
- Ashrafiucse Crypto ReviewFinds cryptographic weaknesses in code — weak ciphers (DES, RC4, ECB mode), weak hashes (MD5, SHA-1) used for security purposes, hardcoded keys/IVs/salts, predictable randomness (Math.random, random, time-based tokens), disabled certificate verification, and undersized key lengths. Use when auditing anything involving encryption, hashing, tokens, certificates, or random number generation.Votes: 0GitHub stars: 76
- Ashrafiucse Cve ResearchResearches current, publicly known vulnerabilities (CVEs) affecting a project's exact stack and versions — queries OSV.dev and the CISA Known Exploited Vulnerabilities catalog live, and reads the bundled, versioned vuln knowledge base for detection guidance. Use when checking whether a project is affected by newly disclosed CVEs, or when maintaining/updating the security-skills knowledge base.Votes: 0GitHub stars: 76
- Ashrafiucse Data ExposureFinds sensitive data exposure risks — PII/secrets written to logs, over-returning API responses, data at rest without encryption, sensitive data in URLs, test fixtures with real data, secrets in git history, and temporary/backup file leaks. Use when auditing how a project handles, stores, logs, or transmits sensitive data.Votes: 0GitHub stars: 76
- Ashrafiucse Dependency VulnsChecks project dependencies for known vulnerabilities (CVEs, GHSAs, PYSA, RUSTSEC, etc.) against the OSV.dev database. Finds lockfiles/manifests across npm, pip, Poetry, Bundler, Cargo, Composer, Go modules, Maven, NuGet, and Pub, queries live advisories for the exact installed versions, and also flags absent lockfiles, deprecated packages, and unpinned installs. Use when auditing dependencies or investigating a specific package's vulnerabilities.Votes: 0GitHub stars: 76
- Ashrafiucse Django SecurityAudits Django (Python) applications for framework-specific vulnerabilities — raw()/extra() SQL injection, mark_safe and |safe filter XSS, SSTI via Template() with user strings, ModelForm fields='__all__' mass assignment, settings misconfigurations (DEBUG=True, ALLOWED_HOSTS=['*'], insecure cookie flags, hardcoded SECRET_KEY), missing login_required/permission checks (IDOR), weak password hashers, and django-cors-headers wildcards. Use when the project has manage.py, settings.py, or Django in ...Votes: 0GitHub stars: 76
- Ashrafiucse Flow SecurityAudits multi-step business flows for vulnerabilities that are invisible when endpoints are checked in isolation — order/payment/invoice state-machine violations, cross-step data provenance (stale or client-supplied totals at terminal steps), chained/association IDOR (ownership through entity joins), replay and duplication across steps, step-skipping via direct access, post-payment mutation, amount drift, and privilege transitions between hops. Use when the app has stateful workflows (checkout...Votes: 0GitHub stars: 76
- Ashrafiucse Graphql SecurityAudits GraphQL APIs for security misconfiguration and abuse — introspection/GraphiQL/playground exposed in production, missing query depth and complexity limits, resolver-level authorization gaps and IDOR, error/stacktrace/field-suggestion leakage, query-batching abuse, CSRF with cookie auth, and unbounded custom scalars. Covers Apollo, graphql-yoga, express-graphql, graphql-js, graphene/strawberry/ariadne, gqlgen, Hasura. Use when the project has a GraphQL server, .graphql schema files, or G...Votes: 0GitHub stars: 76
- Ashrafiucse Injection FlawsDetects injection vulnerabilities in code — SQL/NoSQL injection (including NoSQL operator injection), OS command injection, cross-site scripting (XSS), path traversal, SSRF, insecure deserialization, template injection (SSTI), XXE, prototype pollution, ReDoS, open redirect, and unsafe file upload handling. Covers Node/JS, Python, Java, Go, PHP, Ruby, C# with per-language grep patterns and context-review rules. Use when auditing input handling, query construction, file operations, subprocess c...Votes: 0GitHub stars: 76
- Ashrafiucse Laravel SecurityAudits Laravel (PHP) applications for framework-specific vulnerabilities — mass assignment via missing fillable/guarded, SQL injection through DB::raw/whereRaw/orderByRaw concatenation, Blade raw output XSS, CSRF middleware exclusions, committed APP_KEY enabling cookie-forgery RCE chains, APP_DEBUG in production, routes without auth middleware, path traversal in file downloads, and dev tools (debugbar/telescope) in production dependencies. Use when the project has composer.json with laravel/f...Votes: 0GitHub stars: 76
- Ashrafiucse Llm SecurityAudits LLM/AI application security — prompt injection and data exfiltration via tools, unsafe model/artifact deserialization (pickle, torch.load, LangChain unsafe_deserialization), hardcoded LLM API keys (OpenAI, Anthropic, Google, Groq, Hugging Face), over-powered agent tools (shell/REPL), prompt/PII logging, and telemetry capturing prompts (LangSmith, W&B). Use when auditing LangChain/LlamaIndex/AutoGen apps, OpenAI/Anthropic integrations, RAG pipelines, chatbots, or repos containing model ...Votes: 0GitHub stars: 76
- Ashrafiucse Mobile SecurityAudits mobile app security — Android (AndroidManifest.xml: exported components, allowBackup, debuggable, cleartext traffic, network security config; WebView misconfigurations; hardcoded keys), iOS (Info.plist ATS exceptions, secrets in UserDefaults, keychain accessibility), and React Native/Flutter storage pitfalls. Use when the project contains AndroidManifest.xml, Info.plist, or Kotlin/Java/Swift/Dart/RN code.Votes: 0GitHub stars: 76
- Ashrafiucse Rails SecurityAudits Ruby on Rails applications for framework-specific vulnerabilities — SQL injection via interpolated where/order/find_by_sql, mass assignment through params.permit!, XSS via raw/html_safe/<%==, CSRF skips (protect_from_forgery absent, skip_before_action), missing authenticate/authorize before_actions, send_file/IO path traversal, open redirects via redirect_to(params), Marshal/Oj unsafe deserialization, send/public_send with params, committed secret_key_base, and force_ssl disabled. Use ...Votes: 0GitHub stars: 76
- Ashrafiucse Secrets DetectionFinds hardcoded secrets in any project — API keys (AWS, GitHub, Google, Stripe, Slack), passwords, tokens, private keys, JWTs, database URLs with credentials. Runs a fast regex scan, then triages matches to remove false positives and checks .env/git hygiene. Use when auditing a codebase for leaked credentials or before committing/publishing a repo.Votes: 0GitHub stars: 76
- Ashrafiucse Security AuditComprehensive security audit of any codebase. Maps the project's stack, scans for hardcoded secrets, vulnerable dependencies, injection flaws, auth/authz bugs, weak crypto, misconfigurations, container/IaC risks, and data exposure, then writes a prioritized SECURITY-AUDIT.md report with file:line evidence, CWE mapping, and fix recommendations. Use when the user asks for a security audit, security review, vulnerability scan, pentest prep, or project hardening.Votes: 0GitHub stars: 76
- Ashrafiucse Skill ForgeAuthors NEW custom security skills for this repo — design method, scaffold, fixture+ground-truth rules, self-test wiring, and the hard-won authoring laws from LEARNINGS. Use when creating a skill for a stack, product class, or business domain these skills don't cover (e.g. an internal platform, a niche framework), or when converting a repeated miss/FP into a first-class skill.Votes: 0GitHub stars: 76
- Ashrafiucse Spring SecurityAudits Spring Boot / Spring (Java) applications for framework-specific vulnerabilities — JPQL/native query concatenation, JdbcTemplate string-concat SQL injection, MyBatis ${} substitution, Thymeleaf th:utext and JSP scriplet XSS, Spring Security misconfigurations (csrf().disable(), permitAll() on sensitive matchers), Actuator endpoint over-exposure (env/heapdump leak credentials), hardcoded datasource/JWT secrets in properties, Jackson enableDefaultTyping deserialization, SpEL injection, ses...Votes: 0GitHub stars: 76
- Bnb Official Bnbagent StudioThe single entry point for bnbagent-studio - a TypeScript CLI (`bag`) for building a blockchain SELLER agent that earns U/USD1/USDC/USDT stable assets on BNB Chain via ERC-8004 + ERC-8183 + an x402 or MPP B402 payment face (Pieverse LLM inside). Mainnet USD1 is EIP-3009-only and still requires live-release gates; Testnet USD1 is unavailable. Load this skill whenever the user works in a bnbagent-studio / `bag` project, or wants to create/scaffold, deploy, run, debug, operate, or monetize such ...Votes: 0GitHub stars: 76
- Dfinity Official Autoupgrade Icp CliOne-time installer that keeps a project's Internet Computer CLI toolchain current. Sets up a SessionStart hook plus a script that compares the installed `icp` and `ic-wasm` against the latest release and either reports the upgrade or applies it, using whichever channel each tool was installed from (npm, Homebrew, or the shell installer). Use when a user wants to install, bootstrap, or enable automatic icp-cli / ic-wasm updates, asks to stop running an outdated `icp`, asks how to upgrade or ch...Votes: 0GitHub stars: 76
- Sicomelure Design Generate ChangelogGenerate a structured CHANGELOG.md from git history since the last tag.Votes: 0GitHub stars: 76
- Binance Official Binance Onchain Copy TraderScaffold for assembling on-chain copy-trading strategies on Binance Agentic Wallet. Wires the existing capabilities — address monitoring, signal subscription, address scoring, token audit, order placement, on-chain take-profit/stop-loss — into one runnable pipeline, and exposes every strategy decision as a hook. Ships no strategy of its own. Trigger on: copy trade, copy trading, follow smart money, follow a wallet, mirror trades, copy-trade bot, auto-buy on signal, monitor a wallet and trade,...Votes: 0GitHub stars: 76
- Senpi Ai Quant Desk**Quant Desk** — the desk your **AI Quant** produces. Users reach it by either name, spaced or hyphenated: "run AI quant", "run ai-quant", "run quant", "run quant desk", "run quant-desk". Paste ANY Hyperliquid address (0x…) and get the desk — what the trader has actually been doing (a strategy read with a critique), a quant score with six explained dimensions, the market they are trading in right now and how they trade each regime, the live book with a protection audit, leaks priced as counte...Votes: 0GitHub stars: 76
- Senpi Ai Senpi SignalsSurface non-obvious market developments on Hyperliquid — the read you can't get from a price screen. One on-demand script (scripts/sweep.py) reads the whole HL universe once — funding, open interest, the proven cohort's positioning against the 4h crowd, the platform's momentum events and cross-asset flows — and ranks what that single reading shows through TWO lenses: a **trade** lens (actionable edge, for users building ideas) and a **news** lens (surprising, non-obvious, for market-news cont...Votes: 0GitHub stars: 76
- Alekskram Dydx GatewayUse when the user asks about anything dYdX — markets, prices, funding, OI, volumes, perps — or mentions a perp trader address to vet (equity, PnL curve, day-winrate, maxDD, farmer flag), funding/OI anomalies, liquidation cascades, leaderboards, or wants TA and ATR-based stop plans. Provides dYdX v4 perps analytics via a local read-only MCP gateway: market data, funding heatmap, verified trader PnL, leaderboards, OI and liquidation-cascade anomaly detection.Votes: 0GitHub stars: 76
- Araxis33 Aero Vote RadarDecide where to point veAERO in Aerodrome's weekly vote on Base, and check what a vote already cast actually paid. Use when someone asks where to vote, which Aerodrome pool pays best per veAERO, what their veAERO is worth, what last week's vote earned, or wants a vote they can paste into Aerodrome's UI or sign themselves. Reads live Base mainnet data; never touches keys.Votes: 0GitHub stars: 76
- Cyanheads Add App ToolScaffold an MCP App tool + UI resource pair. Use when the user asks to add a tool with interactive UI, create an MCP App, or build a visual/interactive tool.Votes: 0GitHub stars: 76
- Cyanheads Add PromptScaffold a new MCP prompt template. Use when the user asks to add a prompt, create a reusable message template, or define a prompt for LLM interactions.Votes: 0GitHub stars: 76
- Cyanheads Add ResourceScaffold a new MCP resource definition. Use when the user asks to add a resource, expose data via URI, or create a readable endpoint.Votes: 0GitHub stars: 76
- Cyanheads Add ServiceScaffold a new service integration. Use when the user asks to add a service, integrate an external API, or create a reusable domain module with its own initialization and state.Votes: 0GitHub stars: 76