Browse Secure Claude Skills
Search verified agent skills and review security grades before installing · full A–Z index
- Feat ReviewUse when the user wants a code review of an explicit range or set of files — correctness, security, performance, conventions, tests — with stable findings (CR-nnn, BLOCKER..INFO) and rule citations — 'revisar os últimos commits', 'code review da feature X', 'review base..HEAD'. Plans a REPORT-mode review (no code changes, no commit). Do NOT use to fix code (feat-feature / feat-quick), to write tests (feat-test) or for UI/UX design critique.Votes: 0GitHub stars: 3
- Requesting Code ReviewUse when completing tasks, implementing major features, or before merging to verify work meets requirementsVotes: 0GitHub stars: 144
- Adr AdoptionHow to adopt an architecture decision (ADR) into ProvenMap and measure the estate against it — the /adopt-adr arc. Use when the org has made a decision, standard, or policy that boards should be governed by and checked against. Key capabilities: ADR normalization, blast-radius sweep per aspect family, the decision grill, the durable decision board, compliance insight batches, federated per-app remediation work items.Votes: 0GitHub stars: 3
- Actions Billing UsageMeasure GitHub Actions cost with the billing-usage API — per repo, month and SKU; net vs gross; per-job rounding. Use when optimizing CI cost or speed, or before removing a workflow as expensive.Votes: 0GitHub stars: 58
- Dbt Coredbt Core skill for SQL-based data transformation in warehouses. Deep expertise in project structure, materializations (view, table, incremental, microbatch), Jinja templating, testing framework, macros, packages, MetricFlow, dbt Mesh, and CI/CD workflows. WHEN: \"dbt\", \"dbt Core\", \"dbt run\", \"dbt build\", \"dbt test\", \"ref()\", \"source()\", \"incremental model\", \"dbt macro\", \"dbt snapshot\", \"dbt seed\", \"Jinja SQL\", \"dbt materialization\", \"dbt package\", \"dbt_utils\", \"d...Votes: 0GitHub stars: 4
- GithubCovers GitHub repository management and Git workflow governance: branching strategies (trunk-based, GitHub Flow, GitFlow), pull request and code review process, branch protection rulesets, CODEOWNERS, merge strategies, semantic versioning, conventional commits, Git tags, and GitHub Releases. WHEN: \"branch management\", \"branching strategy\", \"trunk-based\", \"GitHub Flow\", \"GitFlow\", \"pull request process\", \"PR review\", \"code review\", \"branch protection\", \"ruleset\", \"CODEOWNE...Votes: 0GitHub stars: 4
- CloudformationCovers AWS CloudFormation: templates (JSON/YAML), stacks, change sets, nested stacks, StackSets, intrinsic functions, custom resources, drift detection, and CDK integration. WHEN: \"CloudFormation\", \"CFN\", \"CloudFormation template\", \"CFN stack\", \"StackSet\", \"change set\", \"CloudFormation drift\", \"cfn-lint\", \"AWS CDK\", \"SAM template\".Votes: 0GitHub stars: 4
- BicepCovers Azure Bicep and ARM templates: Bicep DSL, modules, parameters, resource declarations, deployment scopes, template specs, and migration from ARM JSON. WHEN: \"Bicep\", \".bicep\", \"ARM template\", \"Azure Resource Manager\", \"az deployment\", \"Bicep module\", \"deployment stack\", \"template spec\", \"Azure IaC\".Votes: 0GitHub stars: 4
- AnsibleCovers Ansible across all versions: playbooks, roles, inventory, modules, collections, AWX/Tower, and configuration management. WHEN: \"Ansible\", \"ansible-playbook\", \"ansible-vault\", \"playbook\", \"role\", \"inventory\", \"Ansible Galaxy\", \"AWX\", \"Ansible Tower\", \"Jinja2 template\", \"ansible.cfg\", \"ansible-lint\". Do NOT use for Ansible against network devices (IOS/NX-OS/Junos/EOS modules, network_cli) — that's the `ansible-network` skill (in the `networking` plugin).Votes: 0GitHub stars: 4
- OdataOData 4.x covering Entity Data Model, system query options ($filter, $select, $expand, $orderby, $apply), CSDL metadata, batch requests, functions/actions, and Microsoft/SAP ecosystem integration. Use for \"OData\", \"$filter\", \"$select\", \"$expand\", \"$orderby\", \"$apply\", \"$count\", \"$search\", \"$batch\", \"EDM\", \"CSDL\", \"$metadata\", \"OData query\", \"lambda operator\", \"any\", \"all\", \"navigation property\", \"deep insert\", \"Power BI OData\", \"SAP OData\", \"OData acti...Votes: 0GitHub stars: 4
- GrpcgRPC 1.x covering Protocol Buffers, service definitions, streaming patterns, channels, interceptors, metadata, deadlines, error model, load balancing, health checking, retry policies, and performance tuning. Use for \"gRPC\", \"protobuf\", \"Protocol Buffers\", \"proto3\", \"protoc\", \"Buf\", \"gRPC streaming\", \"bidirectional streaming\", \"gRPC interceptor\", \"gRPC metadata\", \"gRPC deadline\", \"gRPC health check\", \"gRPC load balancing\", \"gRPC-Web\", \"Connect protocol\", \"grpc-ga...Votes: 0GitHub stars: 4
- ReviewOpen a GitHub-style review UI for local git changes and stay in the loop: the user comments on a line in the browser, you answer in that thread and fix the code. Use when the user says /marj:review or /marj, asks to review local changes together, or wants to talk about a diff line by line.Votes: 0GitHub stars: 10
- GithubLoad before any git or GitHub work in a chat: committing model changes, pushing a branch, opening a pull request, updating a pull request, or commenting on one. Covers the sandbox git checkout, the signalpilot/ branch rule, and the open_pull_request, update_pull_request, and comment_on_pull_request tools.Votes: 0GitHub stars: 485
- Arch InspectArchitecture and code quality audit protocol for Rust projects. Activates expert knowledge across type safety, modularity, testability, readability, DRY, async concurrency, error-handling design, API stability, observability, and lint/manifest hygiene. Called by rust-arch-analyst at startup via Skill(...); invoked directly as /arch-inspect [focus] it delegates the audit to a background rust-arch-analyst.Votes: 0GitHub stars: 11
- Harness Branch Buster> Sync a branch from its base with interactive conflict resolution, run the > project's exact CI gate set locally, delegate review to `harness-code-review`, > then classify every finding by **origin** — introduced by this branch, or > pre-existing on the base — into a dated report, and auto-fix only the in-scope > ones after a single approval.Votes: 0GitHub stars: 21
- PhpLanguage-specific super-code guidelines for php.Votes: 0GitHub stars: 7
- Review SwarmAdversarial code review of a diff or pull request by seven independent reviewer subagents with distinct mandates (security and secrets handling; correctness and concurrency; data loss, migration and backward compatibility; documentation-vs-reality truthfulness; regressions against the project's git and pull-request history; the project's own written rules in AGENTS.md/CLAUDE.md and directive comments; performance), each forbidden from reporting anything it cannot quote verbatim from the code,...Votes: 0GitHub stars: 2
- Project PlanPlan project work by creating or updating a detailed design document (approved by the user before planning), then deriving an implementation plan with cohesive, session-sized milestones and mandatory testing and review gates, then executing one milestone per session with recorded evidence and a handoff. Use for "plan this project", "design doc", "turn this design into an implementation plan", "break this work into milestones", or "what's next on this project"; also use when the project alread...Votes: 0GitHub stars: 2
- Sdd ReviewIndependent, traceable code review of one SDD Composy task in review_required against its approved PRD, stories, TechSpec, evidence, and project rules, with stable findings and severities. Use when a task passed QA and evidence — 'revisar a TASK-003', 'code review da task', 'review this task's diff'. Do NOT use for code review outside an SDD workspace (use the host code review), for QA (sdd-qa), or for verification (sdd-verify).Votes: 0GitHub stars: 3
- Sdd MapProduce a deterministic, read-only evidence map of the repository for SDD Composy (languages, manifests, commands, modules, boundaries, staleness) and publish the context bundle only on request. Use before a PRD or TechSpec, or when the map is stale — 'mapear o repositório', 'atualizar o contexto do código', 'what does this codebase look like for SDD'. Do NOT use for architecture decisions, code review, or repository exploration without an SDD workspace.Votes: 0GitHub stars: 3