All authors

Claude Skills by ModernNomad-98
github.com/ModernNomad-98212 skills1 installs122 views
- TemplateTEMPLATE ONLY — not a real skill and never invoked. Copy this directory to .claude/skills/<your-skill-name>/, rename it, set `name` to match the new directory, and rewrite every section against docs/skill-generation-standard.md. Write the real description to the Portability contract: front-load what the skill DOES in the first ~90 characters, keep it ONE strict-YAML-valid line (single-quote it like this one and double internal apostrophes, ''like this''), parsed value under 1024 characters.Votes: 0GitHub stars: 4
- Ab Test DesignerDesign AND read A/B and controlled experiments honestly — a falsifiable hypothesis, ONE primary metric plus guardrails, the randomization unit (sticky, non-contaminating), a sample-size/power calculation from a minimum detectable effect, and a pre-set duration that respects weekly cycles and forbids peeking-to-significance; then the READOUT — statistical vs practical significance with confidence intervals, the peeking/early-stopping trap, multiple-comparison and segment-fishing caveats, sampl...Votes: 0GitHub stars: 4
- Accessibility Test HarnessDesign the accessibility verification harness — WCAG-oriented coverage of keyboard operability (tab order, visible focus, no traps), accessible names/labels/roles, focus management in dialogs and route changes, color contrast, and screen-reader expectations (announcements, landmarks, live regions) — as BOTH automated tooling (axe-style scans in component and E2E layers, contrast checks in CI) AND a manual checklist for what automation cannot judge. Findings map to WCAG criteria with severity ...Votes: 0GitHub stars: 4
- Admin Console ArchitectDesign the internal ops/support/superadmin CONSOLE for a multi-tenant SaaS — the surface operators act THROUGH: cross-tenant read/write with MANDATORY audit on every action, impersonation/support-mode with hard boundaries + consent + audit, least-privilege admin tiers (view-ops / write-ops / superadmin), break-glass elevation (time-boxed, approved, auto-expiring, logged), and the operator control-plane (health, manual failover/retry, data-repair). Produces the console architecture, admin-tier...Votes: 0GitHub stars: 4
- Adr SequencerManage a CORPUS of Architecture Decision Records over time — the longitudinal discipline atop adr-writer (which authors ONE ADR): numbering and the ADR index/log, the status lifecycle (proposed → accepted → deprecated → superseded), bidirectional superseding links so a new decision points at the one it replaces and vice versa, detecting and resolving contradictions between ADRs, deciding when a change is a NEW ADR vs an amendment, and keeping the decision history navigable and trustworthy as ...Votes: 0GitHub stars: 4
- Adr WriterWrite an Architecture Decision Record for a significant technical choice — context, the decision itself, alternatives genuinely considered, consequences (good and bad), operational impact, a rollback/reversal plan, and a review date. Use when a decision has just been made and needs durable recording, when asked to "write an ADR" or "document why we chose X", or when architecture-designer hands over an ADR draft for completion. Also use to record a rejected option or a superseded decision. Do ...Votes: 0GitHub stars: 4
- Agent Authorization MatrixMANUAL-ONLY; never auto-invoke. Define a deny-by-default authorization matrix for AI agents across actions and contexts. Protected-branch merge requires an explicit human decision, which may be a still-active, scoped standing grant; green checks alone are never approval. Arming auto-merge is forbidden to agents by default and is a separate action from merging. Deploys, releases, production data, secrets, and history rewrites require their own decisions. Invoke explicitly to design or revise a...Votes: 0GitHub stars: 4
- Agent Containment ReviewerReview whether a multi-agent system contains failure and drift. Covers the Open Worldwide Application Security Project (OWASP) agentic failure-cascade identifier ASI08 and rogue-agent identifier ASI10: blast-radius isolation, bounded trust, circuit breakers, checkpoints, retry and fan-out limits, drift detection, inventory, and kill switches that sever authority. Inputs are agent topology, autonomy boundaries, and kill/rollback paths. Composes ai-cost-guardrail-designer for spend bounds and i...Votes: 0GitHub stars: 4
- Agent Failure RecoveryMANUAL-ONLY; never auto-invoke. Recover from a broken working state — failed or interrupted runs, dirty or conflicted trees, partial or wrong commits, broken branches, blocked permissions — without losing work. Invoke explicitly when an agent session ended badly or git state looks wrong. Diagnoses read-only first, inventories ignored as well as untracked files, and verifies a rescue ref, stash or safe copy covers every valuable path before changing anything. A normal stash with -u does not in...Votes: 0GitHub stars: 4
- Agent Goal Hijack DefenderMANUAL-ONLY; never auto-invoke. Defend an artificial intelligence (AI) agent''s goal and plan against hijack, the Open Worldwide Application Security Project (OWASP) agentic identifier ASI01. Pin the authorized goal in a record only the authorizing principal can change, trace each planned step to it, detect scope or objective deviation, and re-ground or halt. Covers injected content, tool outputs, peer messages, and memory. Builds on prompt-injection-defender, which handles the prompt-injecti...Votes: 0GitHub stars: 4
- Agent Governance AuditAudit whether an artificial-intelligence-assisted change followed governance rules: classification, scope, human approvals, merge/deploy authority, validation, security review, closeout, and memory or documentation updates. Each control receives a PASS, FAIL, or UNVERIFIABLE verdict citing primary evidence; missing evidence never passes. Use for retrospective review of a change or pull request (PR), post-incident review, autonomy spot checks, or closeout verification. Read-only; changes nothi...Votes: 0GitHub stars: 4
- Agent Harness ArchitectDesign the governed operating environment an AI agent runs inside — the harness: ONE server-side mediation point every model/tool call crosses; identity from credentials (never from model-supplied payload), propagated; a deny-by-default pre-flight ladder (authenticate → authorize → entitlement → budget → input policy) BEFORE the model runs, each rung fail-closed; a CLOSED tool/provider registry (unknown capability fails, never improvised); instructions as server-side versioned artifacts no un...Votes: 0GitHub stars: 4
- Agent Identity Privilege ReviewerReview agent identities and privilege paths under the Open Worldwide Application Security Project (OWASP) agentic identity identifier ASI03. Check distinct least-privilege identities, scoped credentials, delegation that only reduces authority, confused-deputy paths, and attribution to both human and agent. Complements secrets-identity-hardener for custody and rotation. Use for agent identity and delegation design or privilege-escalation review. Do NOT use for secret storage, per-tool enforcem...Votes: 0GitHub stars: 4
- Agent Instruction ConsolidatorMANUAL-ONLY; never auto-invoke. Audit and align agent instruction files across tools — CLAUDE.md (root, nested, local), AGENTS.md, Cursor rules, GitHub Copilot instructions, Windsurf and Cline rules, and similar — into one consistent source of truth. Invoke explicitly when instruction files conflict, duplicate each other, or have drifted, or after adopting a new AI tool. Produces an inventory, a conflict and duplication matrix, and a consolidation proposal with a rule-preservation diff; edits...Votes: 0GitHub stars: 4
- Agent Memory GovernanceMANUAL-ONLY; never auto-invoke. Govern persistent agent memory as a curated, verified artifact. Keep only confirmed durable facts with provenance and dates; never keep secrets or personally identifiable information (PII). Recheck remembered repository, pull request (PR), and branch state against live evidence; deduplicate and correct stale entries. Invoke explicitly to establish memory rules, audit a memory store, or recover from a stale-memory mistake. Memory edits require separate approval....Votes: 0GitHub stars: 4
- Agent Startup Context GateRun at the start of any repository or coding task, before reading or writing code. Verifies the working directory and workspace role from available evidence, reads project instructions and status docs, and separates verified facts from assumptions and missing information. A fresh product repository may have no remote, commits, application files, or project-state document. Use when starting work in a repo, when told to cd into a path and build something there, or when resuming a session whose ...Votes: 0GitHub stars: 4
- Agent Tool Safety GuardDesign or review least-privilege tool and function access for a large language model (LLM) agent, containing excessive agency and tool misuse. Covers Open Worldwide Application Security Project (OWASP) identifiers LLM03 (excessive agency), ASI02 (tool misuse), and the tool-enabled ASI05 code-execution slice. Build a per-tool permission matrix, validate arguments before execution, use the calling user's authority, gate high-impact actions behind human approval, and map tool-chain abuse. Code-e...Votes: 0GitHub stars: 4
- Agentic Loop DesignerDesign an agentic loop's shape and bounds — decide explicitly whether a loop is needed; clamp iteration ceilings; classify failures before retrying; stop on policy denials and permanent errors; retry a transient failure at most once on identical input only when the operation is safe to repeat; distinguish retry exhaustion and unknown outcomes from proven permanent failures; report empty results honestly. Consumes cost caps from ai-cost-guardrail-designer, gives recovery checkpoints to agent-f...Votes: 0GitHub stars: 4
- Ai Closeout ReporterProduce the end-of-task closeout report — what changed, what was intentionally NOT done or was omitted (always a dedicated section, "None" written explicitly when empty), files touched, tests and validation actually run with real results, a per-deliverable trace from request item to files, checks and evidence (commit SHA, CI run, logs, known skips), risks, skipped checks, and the recommended next action. Use when finishing a task, handing off work, opening or closing a pull request (PR), or w...Votes: 0GitHub stars: 4
- Ai Cost Guardrail DesignerDesign cost and consumption guardrails for a large language model (LLM) feature, covering spend and unbounded-consumption abuse (Open Worldwide Application Security Project identifier LLM06). Specify token caps, per-user/tenant/plan budgets, cost-aware rate limits, task-aware model choice, concurrency and queue bounds, agent loop limits, input limits, a fail-closed spend kill switch, degraded fallback, and telemetry. Compose saas-cost-architect for unit economics and observability-operator fo...Votes: 0GitHub stars: 4
- Ai Evaluation HarnessMANUAL-ONLY; never auto-invoke. Design and run the evaluation harness for a large language model (LLM) feature: a versioned dataset, quality and safety graders, pass/fail thresholds, and a continuous integration (CI) gate that blocks regressions. Include representative, adversarial, and regression cases; measure schema, refusal, grounding, injection resistance, latency, and cost. Running the harness can spend tokens and money, so it is manual-only. Use for evaluation datasets, regression gate...Votes: 0GitHub stars: 4
- Ai Governance Risk ReviewerReview the governance and risk posture of an artificial intelligence (AI) feature: classify impact, assign a human owner, match human oversight to risk, check disclosure, consent, data use, retention, and a feature card, then map applicable European Union (EU) AI Act obligations and voluntary National Institute of Standards and Technology (NIST) AI Risk Management Framework (RMF) functions to controls. Composes ai-sdlc-operating-model, agent-governance-audit, and human-approval-boundary. Use ...Votes: 0GitHub stars: 4
- Ai Lifecycle Risk ManagerOperationalize the National Institute of Standards and Technology (NIST) Artificial Intelligence (AI) Risk Management Framework (RMF) as an organization risk program across design, development, deployment, operation, and decommissioning. Its GOVERN, MAP, MEASURE, and MANAGE functions form a voluntary risk method, not a certification. Compose ai-governance-risk-reviewer for feature tiering, ai-threat-modeler, ai-evaluation-harness, and incident-response-runbook for procedure authoring. Use whe...Votes: 0GitHub stars: 4
- Ai Misinformation GuardDesign controls against misinformation and overreliance in a large language model (LLM) feature, the Open Worldwide Application Security Project (OWASP) LLM07 category. Require authoritative grounding, checked citations, calibrated uncertainty and refusal, validation before consequential action, and a user experience that shows limits. Cover invented software packages or application programming interfaces (APIs) and human oversight for high-impact outputs. Compose rag-security-architect for r...Votes: 0GitHub stars: 4
- Ai Router ArchitectMANUAL-ONLY; never auto-invoke. Design the centralized model-routing layer all AI calls flow through: one internal interface in front of every provider/model; per-provider adapters mapping requests, responses, tool calls, streaming and errors onto it so no provider-specific type leaks past it; a capability matrix so routing and fallback never pick a model lacking a needed feature; adapter conformance tests. Credentials stay server-side; routing picks the model by task/cost/availability; per-c...Votes: 0GitHub stars: 4
- Ai Sdlc Operating ModelDefine the end-to-end software development lifecycle (SDLC) operating model for artificial-intelligence-assisted work: context, classify, plan, implement, validate, review, merge, close, and learn. Name the human or agent authority holder, entry and exit gates, and owning skill at each stage. Compose agent-authorization-matrix, agent-memory-governance, and agent-governance-audit. Use when designing how humans and agents build together, adopting agents on a team, correcting skipped review or s...Votes: 0GitHub stars: 4
- Ai Threat ModelerBuild an artificial-intelligence-specific threat model for a large language model (LLM) feature, retrieval-augmented generation (RAG) pipeline, or agent before release. Inventory prompts, models, stores, tools, credentials and trust boundaries; enumerate Open Worldwide Application Security Project (OWASP) LLM Top 10 threats; write attacker abuse cases; rank concrete exploit paths; and map mitigations to owning skills and evaluation cases. Compose threat-modeler for conventional application th...Votes: 0GitHub stars: 4
- Api Contract Test DesignerDesign contract tests that verify application programming interface (API), command, provider, webhook, and edge-function shapes without user-interface (UI) tests. Specify provider- and consumer-side schema checks, version coverage, and compatibility gates in continuous integration (CI); additive changes still need consumer checks. Use for API/webhook or remote-procedure-call contract verification and schema-drift gates. Do NOT use to design the contract (api-event-architect), test internal bu...Votes: 0GitHub stars: 4
- Api Doc Generator DesignerDesign generated application programming interface (API) reference documentation from a verified schema or code source, with a check that the source matches the implementation. Split exhaustive generated reference from authored guides and examples; enrich the source, choose a generation toolchain, and version the reference with the API. Use when API docs drift or a reference generator is needed. Do NOT use to design the API contract (api-event-architect), the general docs pipeline (docs-as-co...Votes: 0GitHub stars: 4
- Api Event ArchitectDesign external application programming interface (API) and event contracts for multi-tenant software as a service (SaaS). Tenant context comes from credentials by default; an explicitly authorized partner or aggregator may select only tenants allowed by its credential. Define routes, versioning, idempotency, rate limits, and signed tenant-scoped webhook delivery. Produce contract conventions, event schemas, delivery policy, and migration plan. Use for public API or webhook design and partner...Votes: 0GitHub stars: 4
- Appsec ImplementerMANUAL-ONLY; never auto-invoke. Implement a named, already-decided application security (AppSec) control in code, such as input validation, output encoding, parameterized queries, authorization, safe sessions/files, or server-side request forgery (SSRF) and redirect allowlists. Prove it test-first with a failing-then-passing negative test and no scope creep. Use when the user or an approved review has named the exact control to build. Side-effecting and manual-only. Do NOT use to choose contr...Votes: 0GitHub stars: 4
- Architecture AdvisorAdvise on the architecture STYLE/paradigm for what someone is building — monolith, modular monolith, microservices, event-driven, serverless, service-oriented, or a hybrid — with honest, case-specific tradeoffs and a reasoned recommendation. Interview the need FIRST (domain, load, team size and operational maturity, constraints, scaling/change, consistency/latency) before advising; lay out only the genuinely relevant candidates for THIS situation (not a textbook dump); give case-specific pros...Votes: 0GitHub stars: 4
- Architecture DesignerDesign or redesign system structure from an inspection of the current code and architecture. Produce component, dependency, and data-ownership maps, tradeoffs, an architecture decision record (ADR) draft, and an incremental migration plan. Use for structural feature or system decisions. Do NOT use to choose the architecture style (architecture-advisor), design tenancy (saas-platform-architect), model domain concepts (domain-modeler), or record an already-made decision (adr-writer).Votes: 0GitHub stars: 4
- Audit Log ArchitectDesign a durable, tenant-scoped audit log system with an event taxonomy, record schema, append-only integrity, write-failure policy, retention, redaction, scoped reads, and negative tests. Include rollout and safe rollback for a live system. Use for audit logging and compliance trails such as System and Organization Controls 2 (SOC 2), International Organization for Standardization/International Electrotechnical Commission (ISO/IEC) 27001, or customer contracts. Do NOT use for external event ...Votes: 0GitHub stars: 4
- Authority Invalidation ArchitectDiagnose access changes that failed to take effect: revoked roles or memberships, logout, plan changes, or deletion. Inventory old authority in sessions, JSON Web Token (JWT) claims, client and server caches, live subscriptions, database context, search indexes, and signed links. Locate the holder with evidence, design invalidation against an owner-confirmed revocation bound, and verify denial first. Composes caching-strategy-designer, realtime-subscription-architect, plan-entitlement-archite...Votes: 0GitHub stars: 4
- Authorization Matrix DesignerDesign authorization for multi-tenant software as a service (SaaS) as an explicit roles × permissions × resources matrix. Include object-level rules, enforcement points, deny-by-default behavior, brokered support access, negative tests, and a safe migration and rollback plan. Use when roles or permissions need design or repair. Do NOT use for plan entitlements (plan-entitlement-architect), audit records (audit-log-architect), or row-level security (RLS) policy review (rls-policy-auditor).Votes: 0GitHub stars: 4
- Aws Saas ArchitectMap a decided logical architecture onto Amazon Web Services (AWS) for multi-tenant software as a service (SaaS). Design account, identity, network, data isolation, compute, messaging, observability, security, infrastructure-as-code, and cost choices tied to team maturity. Treat quotas, regional availability, instance types, and prices as current-documentation verification items. Use for AWS architecture and account layout. Do NOT use to choose the provider (cloud-architecture-decider), define...Votes: 0GitHub stars: 4
- Azure Saas ArchitectMap a DECIDED logical architecture onto provider-idiomatic Azure for a multi-tenant SaaS — subscription layout, identity (Entra ID, managed identities, OIDC federation), network (VNets, Private Link, Front Door), Key Vault, data with an explicit tenant-isolation strategy per store (Azure SQL, Cosmos DB, Blob), compute chosen by team maturity (App Service, Container Apps, AKS, Functions), messaging (Service Bus, Event Grid), Azure Monitor observability, Azure Policy + Defender for Cloud/Sentin...Votes: 0GitHub stars: 4
- Background Job Orchestration ArchitectDesign the async job/worker EXECUTION model for a multi-tenant SaaS — offload slow work off the request path: worker pools, scheduled/cron jobs, job idempotency + resumability/checkpointing, retry with backoff, a job dead-letter queue, visibility timeouts, and per-tenant fairness so one tenant''s flood cannot starve others. Produces the job catalog, the execution/retry/DLQ contract, and a fairness + scaling plan. Use when moving slow work out of the request, adding scheduled jobs, or when job...Votes: 0GitHub stars: 4
- Caching Strategy DesignerDecide what gets cached, where, and how it stays correct — candidate analysis first (read/write ratio, miss cost, staleness tolerance stated per item), layer choice (HTTP/CDN edge, in-process, distributed cache, DB materialization), invalidation designed BEFORE the cache ships (TTL, event-driven purge with backstop, write-through/behind — with the consistency envelope each buys), key design where tenant scoping is a correctness boundary (tenant-qualified keys; a NEW cache store's isolation de...Votes: 0GitHub stars: 4
- Cell Based Architecture DesignerDesign cell-based (blast-radius) partitioning for a multi-tenant SaaS — a cell is a self-contained stack subset (compute + data + cache + queue) that serves a subset of tenants end to end, so a failure, bad deploy, or noisy tenant is contained to ONE cell instead of the whole fleet: cell definition, tenant→cell mapping and placement policy, a thin cell-router, cell-by-cell deployment/canary, cross-cell/global concerns, and cell migration/rebalancing. SCALE-STAGE — most SaaS never needs it; re...Votes: 0GitHub stars: 4
- Change Classification GateClassify a requested change before starting work — docs-only, UI/style, frontend logic, backend/API, schema/migration, RLS/security, cloud/IaC, AI/agentic behavior, QA/test-only, refactor, bug fix, or release — and map the class to its required validation level and approval path. Locks scope to the approved class and file set; mid-task scope growth forces reclassification. Use when starting any non-trivial change, when a task mixes change types, or when work is drifting beyond what was asked....Votes: 0GitHub stars: 4
- Chat Backlog ReconciliationOn a cadence, extract decisions, bugs, and backlog items that exist only in ephemeral AI-chat history into dated repo docs, then AUDIT every item against PR/source evidence — classified completed / partial / active / not-active / unknown with citations; a chat "done" caps at unknown until repo evidence upgrades it. Enforces the standing rule: do not rely on stale chat history — tracked repo docs are the working record. Produces the dated extraction doc, the per-item audit table, and survivors...Votes: 0GitHub stars: 4
- Ci Pipeline ArchitectMANUAL-ONLY; never auto-invoke. Design the delivery pipeline and, on request, edit the pipeline definitions — the stage graph (lint, typecheck, build-once, unit, integration, security, E2E, artifact, deploy gates) with explicit merge-blocking semantics and a latency budget, CI secret governance (OIDC over stored credentials, job-scoped secrets, none to fork PRs), artifact provenance and cache trust, environment promotion with named-human gates, deployment strategies with rollback primitives, ...Votes: 0GitHub stars: 4
- Clickthrough Test EngineerMANUAL-ONLY; never auto-invoke. Execute a systematic interactive clickthrough of a RUNNING app — a route-by-route walkthrough plan covering navigation, forms (valid + invalid input), dialogs, permission-gated controls, empty/loading/error states, and destructive-action confirmations, then drive the UI through it, recording per-step observations with severity-rated defects and screenshot evidence at named checkpoints. One-session verification pass, not a permanent scripted suite. Use when aske...Votes: 0GitHub stars: 4
- Cloud Architecture DeciderDecide cloud platform, deployment pattern, and operational posture, teaching the choice, never picking silently — ask only for missing deciding facts, one per turn; shape a provider-neutral logical architecture; THEN compare managed platforms (frontend hosts like Vercel, Netlify, Cloudflare Pages; backend-as-a-service like Supabase, Firebase; app platforms like Render, Railway, Fly.io) side by side with hyperscalers (AWS, Azure, GCP), giving case-specific pros/cons, money/setup/upkeep costs o...Votes: 0GitHub stars: 4
- Code ReviewerReview an ACTUAL diff — a PR, branch delta, or staged/working changes obtained from git — and report findings by severity (blocker/major/minor/nit), each with file:line evidence and a concrete remediation. Covers correctness, security, performance, reliability, maintainability, test adequacy, migration safety, and agent-typical faults: scope beyond the stated intent, drift from recorded architecture decisions, tests weakened or skipped to pass. Use when asked to review a diff, PR, branch, or ...Votes: 0GitHub stars: 4
- Code SimplifierMANUAL-ONLY; never auto-invoke. Apply behavior-preserving simplifications to explicitly named code — remove dead code and needless indirection, flatten nesting, deduplicate, replace hand-rolled logic with idiomatic equivalents — with tests proving behavior unchanged (green on the same suite before AND after every move). Manual-only by design; it edits working code, so it must never auto-trigger mid-task. Use when the user explicitly asks to simplify, clean up, reduce complexity of, or make mo...Votes: 0GitHub stars: 4
- Command Gateway ArchitectDesign a single server-side-mediated write path — a command bus — for protected mutations in a multi-tenant SaaS: a command registry plus a per-command pipeline (validate payload → authenticate the actor from the token, never from client-supplied identity → derive trusted target tenant/resource scope → authorize that resolved target against policy → idempotency → execute → emit audit + domain events → safe error envelope), plus the no-direct-client-writes invariant for protected actions. Prod...Votes: 0GitHub stars: 4
- Compliance Control FoundationAuthor the framework-agnostic common control set that ISO 27001, ISO 42001, and SOC 2 work all consumes — one catalog across access control, cryptography, change management, logging/monitoring, incident response, vendor management, and risk assessment, each control written ONCE with objective, owner, verified operating mechanism or gap, and evidence hook, then projected per framework instead of rebuilt per framework. Shipped skills identify design and review routes; they do not prove that an ...Votes: 0GitHub stars: 4