Browse Secure Claude Skills
Search verified agent skills and review security grades before installing · full A–Z index
- Map ModuleCreate, fully refresh, or incrementally maintain a source-verified subsystem architecture map under `.claude/maps/`. Use when the user says "/map-module", "map this module", "map the <subsystem> architecture", asks to document how a subsystem works today, or when project instructions (the Knowledge Loop Conventions in CLAUDE.md) require a targeted refresh after implementation changes invalidate mapped facts. Do not use for ad hoc code explanation, a single-file question, or changes that leave...Votes: 0GitHub stars: 19
- Plans> **For agentic workers:** REQUIRED SUB-SKILL: Use superpowers:subagent-driven-development (recommended) or superpowers:executing-plans to implement this plan task-by-task. Steps use checkbox (`- [ ]`) syntax for tracking. **Goal:** Add a `qa-report` skill that turns any finished run (`/qa-test`, `/qa-test-fast`, `/qa-verify-fix`, `/qa-regression`, `/qa-smoke`) into **one** brief, char-budgeted tracker comment and **one** human-readable HTML page. Every template lives in one folder, and the f...Votes: 0GitHub stars: 2
- Test Tenant ProvisionerMANUAL-ONLY; never auto-invoke. Provision and verify repeatable test tenants and users in a named NON-PRODUCTION environment for auth, row-level-security (RLS), integration and end-to-end (E2E) runs. Every created row carries a test marker and unmarked rows are never mutated; validate-only mode (the default) reports drift against the persona catalog, apply mode creates or repairs only marked tenants, users and memberships; credentials are referenced by environment-variable NAME only; capabili...Votes: 0GitHub stars: 4
- Formulating Atomic Decision QuestionsTurn each fork in an agent into a typed question with a fixed answer space and a written rubric, so a decision model answers and code branches.Votes: 0GitHub stars: 2
- Enforcing Deterministic Execution BoundariesMake code the only path to side effects: gate permissions, validate arguments, run tools, and verify and log real outcomes.Votes: 0GitHub stars: 2
- Designing Technical Environments For FocusSet up shared version control, unattended automated tests, frequent integration and protected focus time for developers.Votes: 0GitHub stars: 2
- Benchmarking And Observing Agent LoopsMeasure a full agent loop end to end, run new decision layers in shadow mode, and log versioned decisions so every change can be attributed.Votes: 0GitHub stars: 2
- Translate Arabic FinanceTranslate supplied finance analysis to Saudi institutional Arabic (ar-SA), keeping RTL text intact. For Parallax reports, use the analysis skill's lang=. NOT for new analysis or non-finance text.Votes: 0GitHub stars: 5
- Durable ObjectsCreate and review Cloudflare Durable Objects. Use when building stateful coordination (chat rooms, multiplayer games, booking systems), implementing RPC methods, SQLite storage, alarms, WebSockets, or reviewing DO code for best practices. Covers Workers integration, wrangler config, and testing with Vitest. Biases towards retrieval from Cloudflare docs over pre-trained knowledge.Votes: 0GitHub stars: 2
- Workflow Integration Test[Workflow] Use when writing integration tests spec-first, converting test specs into test code, adding coverage to untested code, or driving failing integration tests to green. Flag: --mode={write|green}.Votes: 0GitHub stars: 3
- Workflow Integration Test[Workflow] Use when writing integration tests spec-first, converting test specs into test code, adding coverage to untested code, or driving failing integration tests to green. Flag: --mode={write|green}.Votes: 0GitHub stars: 3
- Praxis Review PrReview a GitHub PR and produce GitHub-ready review comments with file, line, and markdown. Handles re-reviews after fixes and groups of related PRs. Use when the user asks to review a PR by number, URL, or chat link ("review pr 123", "review-pr #456", "fais une review de la pr 789", "la pr X a été corrigée, refais une review").Votes: 0GitHub stars: 3
- Infra ContextHow the system under test is built, run and deployed: its architecture and external services, the backend and frontend stacks with their run and test commands, the auth flow, the environments and their URLs, the CI/CD pipelines, and the non-functional budgets it must hold (performance, security, reliability, observability). Load it whenever a task wires the test framework to the stack, touches an environment, a deploy, a pipeline, auth in tests, test IDs, or a performance or security budget, ...Votes: 0GitHub stars: 26
- Business E2e ContextHow people actually use the system under test end to end: the personas, the user journeys first (entry point, steps, branches, where money or data changes hands, where it can fail), then the feature catalog those journeys cross and the flows that span several features. Load it whenever a task touches an E2E or UI test, a user flow, a smoke or regression scope, an exploratory session, a story's place in a bigger journey, or asks what a user can do in the product, even when nobody says 'feature...Votes: 0GitHub stars: 26
- Business Domain ContextThe vocabulary and the business of the system under test: what the product is for, who pays and why, and what every domain term means (the business meaning, the label the UI shows, the identifier the code uses, how it relates to other terms). Load it whenever a task names, labels or explains a domain concept: writing or refining acceptance criteria, authoring an ATP, naming a test case or a test file, filing a bug in business language, or asking what a term means or why a feature exists, even...Votes: 0GitHub stars: 26
- Business Data ContextWhat the system under test IS at the data level: business entities and why they exist, their relationships, state machines, automatic processes (DB triggers, cron jobs, webhooks), external integrations and the business flows that move data between them. Load it whenever a task touches the database, data validation, a SQL query, test data setup, an entity's lifecycle or status transitions, a trigger or a background job, or asks how the product works under the hood, even when nobody says 'data ...Votes: 0GitHub stars: 26
- Business Api ContextWhat the API of the system under test MEANS to the business: every endpoint group, who calls it and why, what it changes, which auth level and role it needs, the business flows that cross several endpoints, error semantics and the external integrations behind them. Load it whenever a task touches an API test, a request or response, an auth or permission question, a status code that looks wrong, contract coverage, or asks which endpoint does what, even when nobody says 'API map'. Reads its map...Votes: 0GitHub stars: 26
- Flow 4 ReviewOne wide-net review round over the whole uncommitted diff, then clean reshape fixesVotes: 0GitHub stars: 1,992
- TestingDraftForge test infrastructure for writing backend unit tests, Playwright E2E tests, and managing test data population. This skill should be used when writing new tests, adding test fixtures, creating populate functions for new features, adding Playwright E2E specs, using login/auth fixtures, creating test users/orgs/leagues/tournaments, or understanding the test data architecture. Covers backend Django tests via Docker, Playwright config (projects, workers, sharding), test auth endpoints tha...Votes: 0GitHub stars: 15
- Chrome DevtoolsBrowser automation, debugging, and performance analysis using Puppeteer CLI scripts. Use for automating browsers, taking screenshots, analyzing performance, monitoring network traffic, web scraping, form automation, and JavaScript debugging.Votes: 0GitHub stars: 15