Browse Secure Claude Skills
Search verified agent skills and review security grades before installing · full A–Z index
- Review Requested PrsOrchestrate full PR reviews (assess-pr-risk in parallel with analyze-test-coverage, validate-pr, verify-pr, review-pr) across all PRs where you are a requested reviewer (including PRs where a team request was later dropped), or on a specific PR by URL. Fans out one independent review-pr-full session per PR so a slow step on one PR never blocks another. Never posts anything to GitHub directly; each sub-skill posts its own report.Votes: 0GitHub stars: 10
- Threat ModelSTRIDE threat modeling with CAPEC drill-down and DREAD-lite scoring. Builds a DFD from lode/ domain knowledge, identifies threats per trust boundary, maps to concrete attack patterns, and produces a prioritized threat register.Votes: 0GitHub stars: 2
- Tech Debt AuditTech debt and architecture audit for .NET repos. Produces plans/TECH_DEBT_AUDIT.md with file-cited findings, severity, and effort estimates. Supports module scoping and focused-mode shortcuts (crap, dead-code, duplicates, suppressions, solid) for single-dimension audits. Does not auto-invoke. Triggers on: tech debt audit, debt audit, codebase health check, architecture review, code quality assessment, audit tech debt, tech debt scan, code health, crap analysis, crap score, dead code audit, fi...Votes: 0GitHub stars: 2
- Strategy AuditStrategic alignment audit for codebases. Applies Roger Martin's strategy framework directly to code, analyzing what the code reveals about its strategic choices, investment levels, and capability reinforcement. Produces a prioritized findings report and feeds actionable refactorings into dev-planning. Use for code review through a strategy lens, feature gap analysis, investment mismatch detection, or surfacing undocumented strategic choices. Triggers on: strategy audit, strategic audit, strat...Votes: 0GitHub stars: 2
- ReviewUnified code review: --local (diff review), --pr (adversarial PR review), --apply (batch fixes from last review).Votes: 0GitHub stars: 2
- Review LocalOrchestrated code review of git diff using parallel agents. Standard mode (diff-scoped) or full mode (adds Roslyn semantic analysis). Produces severity-grouped plan.Votes: 0GitHub stars: 2
- Readme CheckAudits all README.md files in the repo for staleness after significant code changes and auto-fixes drifted tables. Discovers READMEs dynamically. Skips automatically when fewer than 50 C# files changed in recent history. Triggers on: check readme, readme stale, is readme up to date, readme check, readme accuracy, readme outdated, update readme.Votes: 0GitHub stars: 2
- Lode AuditAudits lode/ documentation for content accuracy, checks whether each doc correctly describes the current codebase. Distinct from lode-sync (which only checks timestamps). Produces a staleness table with git-verified findings, then makes targeted updates only on the sections you approve. Use after large refactors, renames, or when the lode feels out of sync with the code. Triggers on: audit lode, lode out of date, lode accuracy check, is the lode correct, lode stale, lode content review, audit...Votes: 0GitHub stars: 2
- FixFix build errors in batch. Parses pasted CI/build output, classifies errors, applies minimal fixes, validates. For test investigation or CI divergence, use /fix-investigate instead.Votes: 0GitHub stars: 2
- Fix InvestigateInvestigate failing tests or CI divergence. Deep single-test root-cause analysis, or local-vs-CI pattern matching.Votes: 0GitHub stars: 2
- Error AuditWeekly error triage skill. Runs scripts/session-health.sh errors --json to get error counts by category, surfaces the top-3 recurring patterns with ranked fix suggestions, and identifies actionable root causes (flag errors, write-before-read, parallel cascade failures, hook-denied patterns, etc.). When permission errors are in the top 3, runs a settings.json gap analysis inline (formerly allowed-tools-maintainer). Triggers on: error audit, what's breaking, error report, session health, what e...Votes: 0GitHub stars: 2
- Bash PatternsWrite, review, and fix Bash (.sh) scripts using project conventions and best practices. Always use this skill when writing any .sh file, creating a new shell script, fixing a bash error or runtime error, reviewing shell code, adding a new script to scripts/, or when the user asks about bash style, naming, formatting, or patterns. This skill combines official style rules with project-specific patterns to produce correct, portable scripts on the first try. Trigger on: write bash, create .sh, ba...Votes: 0GitHub stars: 2
- Review ProjectReview the project context files (.sdlc/context/) for completeness, consistency, clarity, and actionability. Use when the user says /review-project, after /create-project, or before relying on project context to drive feature work.Votes: 0GitHub stars: 10
- Review PrConduct the code-craft review of a GitHub pull request (approach and simplicity, quality, architecture, security, tests, operational concerns). Static only: does not build or run the code (verify-pr's conformance role) or judge whether the target is the right product (validate-pr's validation role).Votes: 0GitHub stars: 10
- Review Pr FullOrchestrate a full PR review for a single PR, running assess-pr-risk in parallel with the analyze-test-coverage -> validate-pr -> verify-pr -> review-pr chain. Skips steps already completed for the current commit. Accepts a PR URL or a PR number with optional repository.Votes: 0GitHub stars: 10
- Prune Merged WorktreesRemove local git worktrees (and their branches) whose associated pull request was merged, verifying merge state against GitHub instead of git ancestry. Use when the user says /prune-merged-worktrees, "prune worktrees", "clean up merged worktrees", "remove worktrees for merged PRs", or wants stale worktree cleanup after merges.Votes: 0GitHub stars: 10
- Learn From Code ReviewsCollect the code review feedback you received on your own pull requests and distill it into durable, cited rules to consult before design and implementation work so the same mistakes stop recurring. Use when the user says /learn-from-code-reviews, "learn from my code reviews", "learn from my PR reviews", "what do reviewers keep telling me", "turn review feedback into rules", "why do I keep getting the same review comments", "review my feedback history", or wants a review-rules checklist to ap...Votes: 0GitHub stars: 10
- Handle Failing Pr CiList your open pull requests and their CI status, then fix failing CI across all of them in parallel by fanning out one handle-pr-ci session per failing PR. Use when the user says /handle-failing-pr-ci, "fix my failing CI", "my PRs have failing checks", "get my PRs green", "check my PRs CI", or wants to bulk-fix CI on their own pull requests.Votes: 0GitHub stars: 10
- GhxUse ghx as an extended GitHub CLI. It browses issues and pull requests with local disk caching, and performs PR/issue comment operations the standard `gh` CLI does not support: inline PR review comments, line-range comments, thread replies, pending reviews, local comment stashes, and edit/delete of comments. Trigger when the user wants to list/search/view issues or PRs, pre-populate the cache, comment on a PR (especially inline / on a specific file or line), reply to a review thread, manage a...Votes: 0GitHub stars: 10
- Devils AdvocateChallenge an idea, plan, decision, or argument by constructing the strongest case against it. Use when the user says /devils-advocate, "challenge me", "play devil's advocate", "what am I missing", "steelman the other side", "poke holes in this", or wants stress-testing before committing.Votes: 0GitHub stars: 10