Browse Secure Claude Skills
Search verified agent skills and review security grades before installing · full A–Z index
- Workspace ScopeRecord a WORKSPACE outcome and its authority: ideas, decisions, work, deliveries, criteria, grants and recommendations, accepting a decision or recording a grant from a committed mandate note. Use for workspace-scope on cross-repository outcomes. NOT for a native repository plan/todo item (use new-plan), dispatching, syncing, setup or a read-only briefing.Votes: 0GitHub stars: 13
- Workspace DispatchDispatch an already scoped WORKSPACE outcome: check current grants, native claims, dependencies and resources, write a bounded brief and hand it to a native host. Use for workspace-dispatch or handing off an authorised assignment. NOT for reconciling a return, maintenance observation, planning scope, native agent waves, setup or read-only briefing.Votes: 0GitHub stars: 13
- Jev RulesUse when a written rule should become a Jev rule check, or an existing one misbehaves — "turn this rule into a Jev rule", "add a rule check", "make this a Jev check", "calibrate this rule", "why does my rule not separate", "my rule fires on accepted work", "my rule never blocks", "the violating case scores 0.6", "park this rule", "wire this rule", "unwire it", "add a rule set for <workflow>", "add a real case for this rule". Use proactively whenever a reviewer or lens keeps re-judging the sam...Votes: 0GitHub stars: 22
- Translate Vietnamese FinanceTranslate supplied finance analysis to Vietnamese (vi-VN), Vietnamese number style in prose. For Parallax reports, use the analysis skill's lang=. NOT for new analysis or non-finance text.Votes: 0GitHub stars: 5
- Barba JsPage transitions library for creating fluid, smooth transitions between website pages. Use this skill when implementing page transitions, creating SPA-like experiences, adding animated route changes, or building websites with smooth navigation. Triggers on tasks involving Barba.js, page transitions, routing, view management, transition hooks, GSAP integration, or smooth page navigation. Works with gsap-scrolltrigger for transition animations.Votes: 0GitHub stars: 2
- T4 Engineering RecordsUse when working in a T4-team repo (T4 Labs / Slow-Inc) and something notable just happened that a future agent will need the "why" of — you fixed and validated a bug, made a hard-to-reverse architectural decision, shipped a system-affecting change, or hit a bug whose lesson is worth keeping. Helps pick the right record (post-mortem vs ADR vs system-impact entry vs bug-case-catalog) and write it so it stays a reliable index (file:line, commit SHAs, validated-only). Triggers include "write a p...Votes: 0GitHub stars: 2
- Cortex Platform Xdm AuthorAuthor Cortex XSIAM Data Model Rules in Cortex Query Language (XQL). Turns a raw vendor log sample into a production-ready rule with a MAPPED-header comment block.Votes: 0GitHub stars: 4
- Technical WriterExpert technical documentation specialist for developer docs, API references, and runbooks. Activate on: documentation, docs, README, API reference, technical writing, user guide, runbook, ADR, changelog, release notes, tutorial, how-to guide. NOT for: marketing copy (use copywriting skills), blog posts (use content skills), code comments (handled by developers).Votes: 0GitHub stars: 2
- Firebase CrashlyticsComprehensive guide for Firebase Crashlytics, includingVotes: 0GitHub stars: 16
- RecallTest your understanding of code the agent wrote. Run /recall after a slice you did not write, or when onboarding into an area. The agent asks, you answer; it never explains first.Votes: 0GitHub stars: 10
- Migrate Workflow TypescriptThis skill migrates an existing TypeScript/Node.js application to Dapr incrementally. It scans the existing codebase for service-call, messaging, scheduling, secrets, state, and saga patterns, maps each onto the matching Dapr building block, presents a plan for approval, and applies confirmed changes one at a time with verification between each. Use this skill when the user asks to "migrate this app to Dapr", "add Dapr to my existing Node.js app", "convert this TypeScript service to use Dapr"...Votes: 0GitHub stars: 12
- Create Workflow TypescriptThis skill creates a Dapr application in TypeScript that demonstrates the core Dapr building blocks — Workflow, service invocation, pub/sub, bindings, jobs, state management, and secrets. Use this skill when the user asks to "create a workflow in TypeScript", "create a Dapr app in Node.js", "write a TypeScript Dapr workflow application", "build a Dapr building blocks demo in TypeScript/JavaScript", or similar.Votes: 0GitHub stars: 12
- Concise DocsWrite, rewrite, or review human-facing Markdown documentation so it reads at a glance — short sections each anchored by a diagram, table, or code block, with content ordered by dependency; a bundled script verifies the limits. Use this skill whenever the user asks to write, rewrite, restructure, or review a README, anything under docs/, an architecture or design document, a guide, or any other Markdown meant for people to read — even if they never mention length, format, or style. 撰寫、改寫、整理或審閱...Votes: 0GitHub stars: 9
- DocxUse this skill whenever the user wants to create, read, edit, or manipulate Word documents (.docx files) or Word templates (.dotx files). Triggers include: any mention of 'Word doc', 'word document', '.docx', '.dotx', or requests to produce professional documents with formatting like tables of contents, headings, page numbers, or letterheads. Also use when extracting or reorganizing content from .docx or .dotx files, inserting or replacing images in documents, performing find-and-replace in W...Votes: 0GitHub stars: 179,886
- Trailmark Finding TriagePerforms graph-assisted triage of a single security finding, SARIF result, weAudit annotation, suspicious function, or report excerpt using Trailmark reachability, entrypoint paths, taint, privilege-boundary, blast-radius, caller/callee, and neighborhood evidence. Use when deciding whether one candidate issue is reachable, prioritizing a finding before PoC work, preparing evidence for exploit validation, or checking whether a static-analysis result is actionable.Votes: 0GitHub stars: 7,287
- Mermaid To ProverifTranslates Mermaid sequenceDiagrams describing cryptographic protocols into ProVerif formal verification models (.pv files). Use when generating a ProVerif model, formally verifying a protocol, converting a Mermaid diagram to ProVerif, verifying protocol security properties (secrecy, authentication, forward secrecy), checking for replay attacks, or producing a .pv file from a sequence diagram.Votes: 0GitHub stars: 7,287
- Crypto Protocol DiagramExtracts protocol message flow from source code, RFCs, academic papers, pseudocode, informal prose, ProVerif (.pv), or Tamarin (.spthy) models and generates Mermaid sequenceDiagrams with cryptographic annotations. Use when diagramming a crypto protocol, visualizing a handshake or key exchange flow, extracting message flow from a spec or RFC, diagramming a ProVerif or Tamarin model, or drawing sequence diagrams for TLS, Noise, Signal, X3DH, Double Ratchet, FROST, DH, or ECDH protocols.Votes: 0GitHub stars: 7,287
- Audit AugmentationAugments Trailmark code graphs with external audit findings from SARIF static analysis results, weAudit annotation files, and version-gated Trailmark 0.4.x binary-analysis graph exports. Maps findings to graph nodes by file and line overlap, creates severity-based subgraphs, and enables cross-referencing findings with pre-analysis data (blast radius, taint, etc.). Use when projecting SARIF results onto a code graph, overlaying weAudit annotations, importing binary graph findings, cross-refere...Votes: 0GitHub stars: 7,287
- TemplatesUse this template for static analysis tools (Semgrep, CodeQL) and similar standalone CLI tools.Votes: 0GitHub stars: 7,287
- Harness WritingDesigns and improves fuzzing harnesses for C/C++ and Rust. Covers mapping raw bytes onto a target API, generating structured inputs, avoiding non-determinism and false crashes, and deciding what to fuzz together. Use when writing a first LLVMFuzzerTestOneInput or fuzz_target! harness, when a campaign finds nothing or reports crashes that will not reproduce, or when the target API needs structured rather than raw input.Votes: 0GitHub stars: 7,287