Browse Secure Claude Skills
Search verified agent skills and review security grades before installing · full A–Z index
- GradersNo description providedVotes: 0GitHub stars: 7
- GradersNo description providedVotes: 0GitHub stars: 7
- GradersNo description providedVotes: 0GitHub stars: 7
- Contract TestingConsumer-Driven Contract Testing (CDC) using Pact framework and OpenAPI-based contract validation. Covers microservice-to-microservice contract verification, provider contract testing, consumer contract testing, contract publishing pipelines, and contract breaking-change detection. USE WHEN: designing microservice APIs, establishing service boundaries, verifying service-to-service contract compatibility, integrating with Pact framework, preventing contract-breaking changes, or setting up a c...Votes: 0GitHub stars: 2
- CompensationOffers, compensation framing, and negotiation planning. Use when evaluating offers or raises.Votes: 0GitHub stars: 2
- Security AuditSecurity guidance and vulnerability review for codebases, APIs, services, CLI tools, libraries, and daemons. Use for security questions, focused security reviews, vulnerability research, security audits, or pen tests. Run the complete workflow only for explicit codebase audit or pen-test requests, full/comprehensive/end-to-end reviews, or requested report artifacts. Not for general code or PR review; use code-review.Votes: 0GitHub stars: 2
- Map ModuleCreate, fully refresh, or incrementally maintain a source-verified subsystem architecture map under `.claude/maps/`. Use when the user says "/map-module", "map this module", "map the <subsystem> architecture", asks to document how a subsystem works today, or when project instructions (the Knowledge Loop Conventions in CLAUDE.md) require a targeted refresh after implementation changes invalidate mapped facts. Do not use for ad hoc code explanation, a single-file question, or changes that leave...Votes: 0GitHub stars: 19
- ReviewTrusted read-only methodology for independent Omnix code reviewers.Votes: 0GitHub stars: 2
- Nix For DevUse this when setting up Nix for a development project (devShell + package build) and you care about `nix develop` being fast. Covers the zero-inputs flake.nix + npins + default.nix/shell.nix layout, sub-flakes for non-user-facing Nix, and language-specific recommendations.Votes: 0GitHub stars: 11
- Nix CiUse this when setting up CI for a GitHub repository — offers GitHub Actions or Vira depending on the projectVotes: 0GitHub stars: 11
- Plans> **For agentic workers:** REQUIRED SUB-SKILL: Use superpowers:subagent-driven-development (recommended) or superpowers:executing-plans to implement this plan task-by-task. Steps use checkbox (`- [ ]`) syntax for tracking. **Goal:** Add a `qa-report` skill that turns any finished run (`/qa-test`, `/qa-test-fast`, `/qa-verify-fix`, `/qa-regression`, `/qa-smoke`) into **one** brief, char-budgeted tracker comment and **one** human-readable HTML page. Every template lives in one folder, and the f...Votes: 0GitHub stars: 2
- Test Tenant ProvisionerMANUAL-ONLY; never auto-invoke. Provision and verify repeatable test tenants and users in a named NON-PRODUCTION environment for auth, row-level-security (RLS), integration and end-to-end (E2E) runs. Every created row carries a test marker and unmarked rows are never mutated; validate-only mode (the default) reports drift against the persona catalog, apply mode creates or repairs only marked tenants, users and memberships; credentials are referenced by environment-variable NAME only; capabili...Votes: 0GitHub stars: 4
- Ci Failure ClassifierClassify a CI run''s failures and hidden problems from its logs and reports: each failed or suspicious job gets exactly one class (product bug, test bug, missing secret or config, timeout-only, infrastructure, skipped-runtime where a skip hides the real result, or indeterminate), with duration as first-class evidence and timeouts never conflated with regressions; GREEN runs are scanned for hidden runtime markers (console errors, unhandled rejections, unexpected skips, auth failures). Reads lo...Votes: 0GitHub stars: 4
- Formulating Atomic Decision QuestionsTurn each fork in an agent into a typed question with a fixed answer space and a written rubric, so a decision model answers and code branches.Votes: 0GitHub stars: 2
- Enforcing Deterministic Execution BoundariesMake code the only path to side effects: gate permissions, validate arguments, run tools, and verify and log real outcomes.Votes: 0GitHub stars: 2
- Designing Technical Environments For FocusSet up shared version control, unattended automated tests, frequent integration and protected focus time for developers.Votes: 0GitHub stars: 2
- Benchmarking And Observing Agent LoopsMeasure a full agent loop end to end, run new decision layers in shadow mode, and log versioned decisions so every change can be attributed.Votes: 0GitHub stars: 2
- Upgrade DepsUpgrade a Node repo's dependencies in three rounds (patch → minor → major) using npm-check-updates, respecting the project's release-age cooldown. Researches each update's changelog in parallel, bumps the uneventful ones silently, runs the tests, commits, and surfaces only the packages that need a human decision -- a few at a time, most severe first. Works in monorepos (--workspaces, syncpack). Use when the user runs /upgrade-deps, or asks to "upgrade deps", "bump dependencies", "update packa...Votes: 0GitHub stars: 3
- Translate Arabic FinanceTranslate supplied finance analysis to Saudi institutional Arabic (ar-SA), keeping RTL text intact. For Parallax reports, use the analysis skill's lang=. NOT for new analysis or non-finance text.Votes: 0GitHub stars: 5
- JavaModern Java practices: design, errors, concurrency, security, testing, tooling. Targets Java 21 LTS baseline; Java 25 LTS features called out explicitly. Use when writing or reviewing Java code.Votes: 0GitHub stars: 54