All authors

Claude Skills by matthews-wong
github.com/matthews-wong62 skills0 installs14 views
- Access Review GuidanceUse when the user asks to review IAM, RBAC, or permission changes — auditing a diff for over-broad grants, wildcards (`*`), or privilege escalation. Delegates to the access-reviewer subagent via /access-review. Triggers on "review access", "check permissions", "IAM change", "RBAC", "least privilege", "who can do what".Votes: 0GitHub stars: 2
- Accessibility AuditUse when auditing or fixing UI for accessibility — triggers on "accessibility", "a11y", "WCAG", "screen reader", "keyboard navigation", "alt text", "color contrast", "ARIA", "focus order", "accessible form", or when HTML/JSX/Vue/component markup is shown and the user wants it usable by everyone. Reports issues mapped to WCAG 2.2 AA success criteria with concrete fixes.Votes: 0GitHub stars: 2
- Adr AuthoringMADR-style Architecture Decision Record conventions. Use when creating, updating, or listing ADRs to apply the standard template, numbering, and status lifecycle.Votes: 0GitHub stars: 2
- Agent OrchestrationUse when a task is large enough to split across multiple subagents. Explains how to decompose a task into independent subtasks, kick off a subagent per subtask (agent-to-agent orchestration), synthesize the results, and — critically — when parallel subagents help versus when they hurt. Triggers on "orchestrate", "fan out", "parallel agents", "split this across agents", "kick off subagents".Votes: 0GitHub stars: 2
- Api CompatibilityUse when evaluating whether an API change is backward compatible — diffing OpenAPI/Swagger or JSON Schema, deciding breaking vs non-breaking, or picking a SemVer bump for an API. Triggers: "breaking change", "backward compatible", "API compat", "OpenAPI diff", "schema diff", "will this break clients", "oasdiff", "deprecate endpoint", "version bump for API".Votes: 0GitHub stars: 2
- Auto Mode SetupUse when a user wants to enable or understand Claude Code''s auto permission mode. Explains permissions.defaultMode "auto" honestly (a safety classifier approves routine actions and falls back to default mode if unavailable), and helps configure ~/.claude/settings.json with a vetted allow set and a deny floor.Votes: 0GitHub stars: 2
- Changelog MaintenanceKeep a Changelog maintenance rules. Use when writing or updating CHANGELOG.md to map Conventional Commits into Added/Changed/Deprecated/Removed/Fixed/Security sections under an Unreleased heading.Votes: 0GitHub stars: 2
- Claude Md StandardsUse when creating, reviewing, or editing a CLAUDE.md (or nested CLAUDE.md) file. Defines what belongs in project memory versus what is derivable bloat — high-value build/test commands, conventions, gotchas, and safety rules — and how to keep it lean and skimmable.Votes: 0GitHub stars: 2
- Code Review GuidanceUse when the user asks to review code, a diff, or a PR for bugs, edge cases, and quality — delegates to the code-reviewer subagent via /code-review. Triggers on "review my code", "review this diff", "check before I commit", "look over my changes", "code review".Votes: 0GitHub stars: 2
- Simplification GuidanceUse when the user wants to simplify or clean up recently-written code without changing behavior — remove dead code, reduce indirection, prefer deleting lines over adding. Delegates to the code-simplifier subagent via /simplify. Triggers on "simplify", "clean this up", "reduce indirection", "remove dead code", "make it simpler".Votes: 0GitHub stars: 2
- Codeowners ManagerScaffold and validate GitHub CODEOWNERS files — map path patterns to owning teams and ensure critical paths are covered. Use when creating, editing, or reviewing a CODEOWNERS file, setting up code-review ownership, or checking that sensitive paths have required reviewers. Triggers on "CODEOWNERS", "code owners", "who owns this path", "required reviewers", "ownership rules".Votes: 0GitHub stars: 2
- Compliance ChecklistPre-release security & compliance control checklist mapped to SOC 2 and ISO 27001. Use when preparing a release, doing a go/no-go review, an audit-readiness pass, or when the user mentions SOC 2, ISO 27001, access control, change management, audit logging, encryption, or incident response. Triggers on "compliance check", "pre-release review", "SOC 2", "ISO 27001", "audit readiness", "control gap".Votes: 0GitHub stars: 2
- Context BudgetAudit and slim CLAUDE.md and skills for token bloat, and restructure guidance via progressive disclosure. Use when a CLAUDE.md or memory file feels long, when writing or reviewing SKILL.md files, when the user asks to reduce context, cut bloat, improve routing, or apply progressive disclosure. Triggers on "CLAUDE.md too long", "context bloat", "trim context", "token budget", "progressive disclosure", "lean context", "skill not triggering".Votes: 0GitHub stars: 2
- Context HygieneUse when a Claude Code session is bloated, stuck, or drifting — repeated failed corrections, mixing unrelated tasks in one session, exploration that never converges, or deciding between /clear, /compact, and subagents. Helps recognize the failure pattern and re-prompt with a clean context that incorporates what was learned.Votes: 0GitHub stars: 2
- Context PullUse before starting a non-trivial coding task to gather the relevant repository context (README, docs, ADRs, related modules, recent git history) and distill it into a short working brief so the agent starts grounded instead of guessing. Triggers on "pull context", "get me up to speed", "brief before I start", "gather context".Votes: 0GitHub stars: 2
- Conventional CommitsThe Conventional Commits v1.0.0 grammar. Use when writing, formatting, or validating a git commit message so it declares type, optional scope, description, body, and breaking-change footer correctly.Votes: 0GitHub stars: 2
- Cost ControllerUse when deciding which model to run for a task or how to cut Claude Code spend — a cost policy that routes bulk, mechanical work to cheaper/faster models (Haiku-class) and reserves frontier models (Opus-class) for judgment and review. Covers the cost/quality tradeoff, a decision matrix, how to switch models per task and per subagent, and orchestration patterns that minimize total cost to a correct result. Triggers on choosing between Haiku/Sonnet/Opus, reducing token cost, picking a cheaper ...Votes: 0GitHub stars: 2
- Css ResponsiveUse when writing or reviewing CSS/SCSS styling and layout — in .css, .scss, .sass, .less, styled-components, or Tailwind/@apply files — especially for "responsive" design, "mobile-first", "flexbox" vs "grid", "media query", breakpoints, "dark mode", theming with CSS variables / design tokens, "container queries", relative units (rem/em/%/vw/ch/clamp), or fixing layouts that break on small screens. Provides opinionated best practices for adaptive, token-driven, accessible styling.Votes: 0GitHub stars: 2
- Data ClassificationClassify data fields into public/internal/confidential/PII tiers and recommend handling controls. Use when reviewing schemas, database models, migrations, API payloads, config, or log statements for sensitive data; when the user asks to classify data, find or flag PII, or decide encryption/retention/minimization for a field. Triggers on "classify data", "is this PII", "sensitive fields", "data handling", "should we log this".Votes: 0GitHub stars: 2
- Db Migration SafetyUse when reviewing or writing a "database migration" or "schema change" — triggers on "ALTER TABLE", "zero-downtime migration", "add column", "drop column", "rename column", "add index", "backfill", "expand-contract", or when a migration file (Rails/Alembic/Flyway/Liquibase/Prisma/Django/golang-migrate) is shown. Flags locking, downtime, and compatibility risks and rewrites the migration into safe phased steps.Votes: 0GitHub stars: 2
- Dependency AuditRun and triage dependency vulnerability audits across Node.js, Python, Rust, and Go using native tools (npm audit, pip-audit, cargo audit, govulncheck). Use when auditing dependencies for known CVEs or prioritizing remediation.Votes: 0GitHub stars: 2
- Dockerfile HardeningUse when reviewing, writing, or hardening a "Dockerfile" or "container image" — triggers on "harden image", "Docker security", "non-root container", "distroless", "multi-stage build", "pin base image", or when a Dockerfile is shown and the user wants it production/enterprise-ready. Produces a hardened Dockerfile and a findings list mapped to concrete fixes.Votes: 0GitHub stars: 2
- Docs DriftUse when code changes may have made documentation stale, or the user asks to check/update docs after editing source. Triggers: "docs out of date", "stale docs", "update the README", "docs drift", "did I miss a doc", "keep docs in sync", "changelog", "document this change". Not for writing new docs from scratch — for detecting and fixing drift caused by code changes.Votes: 0GitHub stars: 2
- E2e VerificationUse when a code change needs end-to-end verification before handing it to a human — reproduce the change through the real running system, confirm the happy path plus at least one edge case, capture concrete evidence, and only then declare it ready.Votes: 0GitHub stars: 2
- Fan Out MigrationUse when a repetitive, mechanical change must be applied across many files — a bulk migration, codemod, rename, or API/import update spanning a whole codebase. Covers generating a task list to a file and looping a scoped headless `claude -p` per file, testing on a few files before running at scale.Votes: 0GitHub stars: 2
- Incident ResponseUse during or after a production incident/outage: triaging severity, running the response, drafting status comms, deciding mitigation, or writing a postmortem. Triggers: "incident", "outage", "we're down", "SEV1/SEV2", "on-call", "declare an incident", "status update for customers", "postmortem", "root cause analysis", "RCA", "action items". For live production impact and the retrospective that follows.Votes: 0GitHub stars: 2
- InstinctsDurable, learned rules the agent should follow. Auto-invoke this skill when (1) a lesson recurs during work — the same mistake, correction, or preference shows up again — to PROPOSE promoting it into a durable instinct; and (2) when STARTING a task in a repo — to APPLY the active instincts already recorded so the agent follows established rules instead of relearning them.Votes: 0GitHub stars: 2
- Javascript StandardsApply modern JavaScript/TypeScript standards when writing, reviewing, or refactoring .js/.jsx/.ts/.tsx/.mjs code. Triggers on "modern JS", "ESM", "import/export", "async/await", "callback hell", "var vs let", "==", Promises, error handling, immutability, optional chaining, or nullish coalescing. Use whenever authoring or cleaning up JavaScript modules.Votes: 0GitHub stars: 2
- K8s Security PolicyUse when reviewing Kubernetes manifests (Pod, Deployment, StatefulSet, DaemonSet, Job) for security — triggers on "kubernetes security", "securityContext", "pod security", "Pod Security Standards", "harden this manifest", "runAsNonRoot", "readOnlyRootFilesystem", or when YAML for a K8s workload is shown. Produces findings mapped to the Restricted profile plus a corrected manifest.Votes: 0GitHub stars: 2
- Knowledge LoopFolder-scoped knowledge memory for a repo. Use when you solve a tricky bug, hit a non-obvious gotcha, work around a quirk, or make a design decision worth remembering — record it as a concise learning. Also use when starting a task in a folder or picking up unfamiliar code — recall prior learnings first so you inherit what past sessions figured out. Triggers: "remember this", "record a learning", "note this gotcha", "what did we learn here", "recall prior context", "why did we decide", captur...Votes: 0GitHub stars: 2
- License ComplianceInventory dependency licenses, normalize to SPDX identifiers, and flag licenses outside an allowlist (e.g. GPL/AGPL copyleft in proprietary code). Use when checking open-source license obligations or building a license inventory.Votes: 0GitHub stars: 2
- Loop RoutinesUse when a task should repeat on a schedule or until a condition is met. Explains Claude Code''s /loop taxonomy — interval loops (fixed cadence) vs. self-paced loops (model decides when to continue) — and how to set stop conditions and avoid runaway loops. Triggers on "loop", "run this every N minutes", "keep running until", "recurring task", "poll for status".Votes: 0GitHub stars: 2
- MemoryUnified project memory + auto-learning for a repo. Use when you solve a tricky bug, hit a non-obvious gotcha, work around a quirk, or make a design decision worth keeping — record it as a concise folder-scoped learning. Also use when starting a task in a folder or picking up unfamiliar code — recall prior learnings AND apply the active learned rules (instincts) first, so you inherit what past sessions figured out instead of relearning it. Triggers: "remember this", "record a learning", "note ...Votes: 0GitHub stars: 2
- Mistake CaptureUse when turning a mistake, correction, or repeated error into a durable rule that persists across sessions. Decides whether the lesson belongs as a lean line in CLAUDE.md (one-off fact/constraint) or as a skill (repeatable procedure), and keeps CLAUDE.md lean. Triggers on "preserve this mistake", "log a lesson", "don''t repeat this", "add a rule", "when to make a skill vs CLAUDE.md".Votes: 0GitHub stars: 2
- Node Backend PatternsUse when writing or reviewing Node.js backend/server code — Express, Fastify, Koa, or plain http services, route handlers, middleware, controllers, services, or repositories in .js/.ts/.mjs files. Triggers on "Node server", "Express", "Fastify", "middleware", "route handler", "async handler", "env config / environment variables", "structured logging", "graceful shutdown", request validation, and error handling. Provides opinionated layering, boundary-validation, error, config, logging, and li...Votes: 0GitHub stars: 2
- Otel GovernanceUse when setting up team- or org-level monitoring or cost controls for Claude Code — enable OpenTelemetry (OTel/OTLP) export of usage telemetry to your own backend and configure organizational spend governance (budgets, alerts, spend caps). Team/enterprise-oriented. Covers the observability-vs-enforcement distinction, the shape of OTel configuration, and where to find authoritative specifics. Triggers on wanting usage dashboards across many seats, per-user/per-team cost attribution, budget al...Votes: 0GitHub stars: 2
- Parallel LanesUse when a large task spans several independent areas and you want to fan it out for speed — split it into parallel "lanes" run by separate subagents or git worktrees, partition the work so lanes never write the same files (avoiding merge conflicts), then merge and synthesize the results into one coherent whole. Triggers on wanting to parallelize, fan out, run multiple agents in parallel, use a worktree per task, or split a big multi-part change across agents.Votes: 0GitHub stars: 2
- Permission OptimizerUse when a user is repeatedly prompted to approve the same safe, read-only tool calls and wants to reduce friction — phrasings like "stop asking me to approve git status / ls / rg" or "add these commands to the allowlist". Analyzes recently denied or repeatedly-prompted tool calls, isolates the read-only ones, and proposes exact-match permissions.allow rules for .claude/settings.local.json. Never allowlists write, execute, network, or destructive commands.Votes: 0GitHub stars: 2
- Plan FirstUse before any non-trivial code change — a refactor, new feature, migration, or multi-file edit. Investigate the affected code first, produce a concise implementation plan (files to change, approach, risks, test strategy), get the user's confirmation, then execute. Prevents premature edits and surprise blast radius on risky work.Votes: 0GitHub stars: 2
- Pr StandardsEnterprise pull request review standards. Use when reviewing a pull request or merge request to check description quality, linked issue/ticket, change size, test coverage, and scope discipline, and to produce a checklist verdict.Votes: 0GitHub stars: 2
- React PatternsApply modern React patterns when building or reviewing components and hooks in .jsx/.tsx files. Triggers on "component", "useState", "useEffect", "custom hook", "re-render", "props drilling", "context", "controlled input", "keys", "useMemo/useCallback", "effect cleanup", or React accessibility. Use whenever authoring React UI or debugging hook/render behavior.Votes: 0GitHub stars: 2
- Release ProcessA repeatable, honest release checklist. Use when cutting a release to decide the semver bump, promote the changelog, tag, and draft release notes without skipping governance steps.Votes: 0GitHub stars: 2
- Onboarding GuidanceUse when the user is new to an unfamiliar repository and needs to get productive fast — mapping the stack, entry points, build/test/run commands, conventions, and gotchas. Delegates to the repo-onboarder subagent via /onboard. Triggers on "onboard me", "get me up to speed on this repo", "how does this codebase work", "explore this repo", "where do I start".Votes: 0GitHub stars: 2
- Rest Api DesignUse when designing, building, or reviewing a REST API or HTTP endpoint — defining routes/paths, choosing HTTP methods and status codes, shaping request/response bodies and error responses, adding pagination, versioning an API, or handling idempotency. Triggers on "REST", "API", "endpoint", "route", "HTTP status code", "pagination", "API versioning", "error response", "idempotent", and on OpenAPI/Swagger specs and controller/router files. Provides opinionated resource-oriented design conventions.Votes: 0GitHub stars: 2
- Routine SchedulerUse when setting up recurring, unattended automation in Claude Code — a scheduled routine (cron-style cloud agent) that runs a task on a cadence like nightly or weekly without a human starting the session. Covers cadence selection, guardrails for unattended runs, self-contained task prompts, and worked examples (nightly PR triage, weekly dependency-update check). Triggers on wanting to schedule a routine, set up a cron job, run something every night/week, create a recurring agent, or automate...Votes: 0GitHub stars: 2
- Sbom GenerationGenerate a Software Bill of Materials (CycloneDX or SPDX) with standard tools (syft, cdxgen, ecosystem-native generators), pick the right format, and validate the result. Use when producing an SBOM or explaining SBOM requirements.Votes: 0GitHub stars: 2
- Secret DetectionDetect likely secrets (API keys, cloud credentials, tokens, private keys, high-entropy strings) in code and diffs, triage findings by confidence, and guide safe remediation. Use when scanning a diff for credentials or reviewing a secret-scan result.Votes: 0GitHub stars: 2
- Security Review GuidanceUse when the user asks to review changes for security vulnerabilities — injection, XSS, auth flaws, secrets, SSRF, unsafe deserialization, path traversal. Delegates to the security-reviewer subagent via /security-review. Triggers on "security review", "check for vulnerabilities", "is this safe", "audit this diff for security", "OWASP".Votes: 0GitHub stars: 2
- Senior StandardsUse while writing, changing, or reviewing code to hold to senior-developer standards. Applies three principles — make every change minimal (prefer deleting lines to adding), find and fix root causes (no band-aids or temporary hacks), and touch only what''s necessary (no side effects, don''t introduce new bugs). Triggers on "senior standards", "root cause", "minimal change", "no band-aid", "don''t break other things", "keep it simple".Votes: 0GitHub stars: 2
- Skills ConnectorUse when authoring, structuring, or debugging Claude Code skills — writing a SKILL.md, crafting the frontmatter description that drives model routing, fixing a skill that isn't triggering when it should, deciding when to split one skill into several, referencing sibling skills, or organizing a coherent agentic skills library. The reference for building skills that reliably trigger and compose.Votes: 0GitHub stars: 2