Browse Secure Claude Skills
Search verified agent skills and review security grades before installing · full A–Z index
- Codex System Plugin CreatorCreate and scaffold plugin directories for Codex with a required `.codex-plugin/plugin.json`, optional plugin folders/files, valid manifest defaults, and personal-marketplace entries by default. Use when Codex needs to create a new personal plugin, add optional plugin structure, generate or update marketplace entries for plugin ordering and availability metadata, or update an existing local plugin during development with the CLI-driven cachebuster and reinstall flow.Votes: 0GitHub stars: 389
- Migrate Workflow TypescriptThis skill migrates an existing TypeScript/Node.js application to Dapr incrementally. It scans the existing codebase for service-call, messaging, scheduling, secrets, state, and saga patterns, maps each onto the matching Dapr building block, presents a plan for approval, and applies confirmed changes one at a time with verification between each. Use this skill when the user asks to "migrate this app to Dapr", "add Dapr to my existing Node.js app", "convert this TypeScript service to use Dapr"...Votes: 0GitHub stars: 12
- Create Workflow TypescriptThis skill creates a Dapr application in TypeScript that demonstrates the core Dapr building blocks — Workflow, service invocation, pub/sub, bindings, jobs, state management, and secrets. Use this skill when the user asks to "create a workflow in TypeScript", "create a Dapr app in Node.js", "write a TypeScript Dapr workflow application", "build a Dapr building blocks demo in TypeScript/JavaScript", or similar.Votes: 0GitHub stars: 12
- Webfetch Empty Use Agent BrowserWhen webfetch returns garbled binary from a .pdf/.docx/.xlsx URL (PDF magic bytes, mojibake), do NOT pivot to agent-browser: download with curl and extract via pdftotext or pypdf/pdfplumber (see the Binary files section). Otherwise, when webfetch yields an empty body, a TOO-LARGE response, a near-empty JS-rendered shell, or fails on a dynamic page, SWITCH to agent-browser instead of retrying — 'too large' is the same signal as 'empty'. Targets: single-page apps, job boards (Workday, Greenhous...Votes: 0GitHub stars: 39
- Python Importtime OptimizationDiagnose and fix slow Python package import times. Use when: 'import pkg' or 'from pkg import X' takes seconds (CI import-time benchmarks slipping, CLI startup lag, marimo/Jupyter import latency); you suspect eager heavy imports in __init__.py; a module-level 'import lib' exists ONLY to set a side-effect flag and you need the lazy-set pattern; making imports lazy and verifying nothing still imports at load time; or dating an import-time regression from CI per-PR benchmark comments. Covers pyt...Votes: 0GitHub stars: 39
- Opencode Ollama Provider SetupAdd an Ollama-hosted model (local laptop or a remote box like the GB10) as a usable model/provider in opencode, and verify it end-to-end. Use when the user asks to 'add <model> from ollama to opencode', 'use ollama model X in opencode', 'wire up a local model in opencode', when adding an Ollama model to opencode.json, smoke-testing an Ollama OpenAI-compatible endpoint with curl, diagnosing EMPTY content from a thinking/reasoning model, or wondering why the new provider does not appear without...Votes: 0GitHub stars: 39
- Opencode Mcp Server SetupAdd or configure an MCP server in opencode's config (~/.config/opencode/opencode.json or project .opencode/) — both server types: LOCAL/stdio {"type": "local", "command": ["npx", "pkg"], "enabled": true} and REMOTE/HTTP {"type": "remote", "url": "...", "enabled": true}. Use when the user says 'add the X MCP server', 'install/configure MCP', 'connect to <service> MCP', an MCP server appears in docs but isn't wired into opencode, tools from a known MCP server are missing in a session, or a serv...Votes: 0GitHub stars: 39
- Opencode Bash Background Process SurvivalDiagnose and fix backgrounded processes (dev servers, nohup'd jobs) that get KILLED when the bash tool's command terminates, completes, or times out — even when started with nohup & disown. Use when: a backgrounded server died by the next turn or when the launching command timed out; the dev server started last turn returns connection refused / curl 000; 'shell tool terminated command after exceeding timeout' appears and the PID is gone; you need a process to survive across multiple bash-tool...Votes: 0GitHub stars: 39
- Npm Trusted Publishing Oidc SetupSet up npm package publishing via GitHub Actions using Trusted Publishing (OIDC) instead of a long-lived NPM_TOKEN secret. Use when: the user asks to publish an npm package via CI/CD, set up a publish workflow, or automate npm releases; npmjs.com shows the 'security risks with this option... use Trusted Publishing instead' warning; or you are about to recommend an npm automation token + GitHub secret. Key gotchas: Node 24 required (npm 11.5.1+); the publish step must have NO NODE_AUTH_TOKEN e...Votes: 0GitHub stars: 39
- MarimoEverything marimo notebooks: authoring and editing notebook .py files (cell params, unique-variable rules, StaleCellError, API gotchas), pairing on a LIVE notebook via marimo-pair code_mode, embedding interactive marimo cells in a blog or website (WASM/Pyodide approaches and trade-offs), migrating a docs repo so marimo .py notebooks are the single source of truth with generated artifacts gitignored, and building an awesome marimo notebook that brings a research paper or dataset to life (compe...Votes: 0GitHub stars: 39
- Marimo Notebook PatternsPitfalls for writing/editing marimo notebook .py files, and for mutating a RUNNING notebook via marimo-pair code_mode (ctx.edit_cell/create_cell/move_cell). Covers: import patterns (never alias marimo as mo), cell params (mo received as a parameter), App() init, unique-variable rules incl. the loop-variable cell-collision (namespace loop vars per cell), cross-cell symbol removal, ran-error traceback triage, import-cell return values, underscore-prefix privacy, button/toast/callout/slider/prog...Votes: 0GitHub stars: 39
- Large File Edit Truncation GuardrailDiagnose and prevent SILENT TRUNCATION when editing large files (1000+ lines, especially CJK/multibyte markdown) via Edit/StrReplace/write_file. Use when: an edit 'succeeds' but trailing content (entire sections, __main__ blocks) is silently dropped with no error; a full write_file rewrite produced a shorter file than expected; an Edit FAILED and you are considering a write_file fallback (do NOT — the #1 truncation trigger); the dedicated Grep tool finds nothing for content ripgrep finds in a...Votes: 0GitHub stars: 39
- Jupyterlab Collab Mcp SetupSet up and verify the jupyterlab-collab-mcp MCP server so an agent can read/edit/execute Jupyter notebooks with real-time collaboration. Use when the user says 'connect to the jupyter MCP server', 'check the jupyterlab collab mcp', 'jlabx extensions aren't working', 'verify the MCP server is installed', the agent has no jupyter MCP tools despite expecting them, or notebook edits via MCP fail or return connection errors. THREE-LAYER architecture (opencode <-stdio-> MCP server <-y-websocket-> J...Votes: 0GitHub stars: 39
- Git Rebase Noninteractive EditorFix 'git rebase --continue' (and 'git rebase -i') blocking or timing out in a non-interactive shell (bash tools, CI, scripts, scheduled jobs) because git opens an interactive editor (nano/vi) with no TTY that waits forever for stdin. Use when: rebase --continue hangs or the shell tool times out with no commit produced (especially after 'git add'-ing resolved conflicts); you see 'GNU nano' or a vi screen in rebase output; you are about to re-run --continue hoping it works; or you are doing ANY...Votes: 0GitHub stars: 39
- Evident ChartsMakes explanatory charts whose point is evident, using evidence-tagged dataviz rules. Use whenever you create, revise, restyle, or review a chart, plot, graph, or figure meant to show a reader something: matplotlib, seaborn, pandas .plot, ggplot2, Plotly, Altair/Vega-Lite, D3, or any PNG/SVG chart for a blog, report, paper, slide, newsletter, or social post. Starts from sound analysis of the data, picks the chart type from the takeaway and data shape, and runs deterministic checks (overlaps, ...Votes: 0GitHub stars: 39
- Dom Anchored Svg ConnectorsAnchor connector lines/arrows/edges between rendered DOM elements (gantt dependency arrows, org-chart parent-child lines, flowchart edges, annotation leader lines) on MEASURED element rects — NEVER compute connector coordinates de novo (percentage math, hardcoded px widths, or a second parallel layout math). Use when drawing connectors in vanilla JS/HTML, or when the user reports connectors 'misaligned', 'all over the place', or 'floating detached from the boxes'; trigger: any second, indepen...Votes: 0GitHub stars: 39
- Docker Offline VerificationVerify a containerized Docker app runs with ZERO network access (offline verification of demos, teaching sites, deployed containers). Use when: you must prove a containerized app serves every route without internet; a docker run combining --network none with -p fails to publish or reach ports; a --network none container's ports time out and it LOOKS like an app failure. ROOT CAUSE: port publishing (-p) requires an attached network — with --network none there is no network to publish from, so ...Votes: 0GitHub stars: 39
- Data Visualization MasterMaster skill for creating, critiquing, and improving data visualizations — charts, plots, and figures for analysis, publications, blogs, slides, and dashboards. Synthesizes the Nature Methods "Points of View" series (Bang Wong, Martin Krzywinski, and coauthors) with the evidence-tagged rules of the evident-charts skill (Cleveland & McGill graphical perception, Tufte, and modern visualization research). Load for any chart/figure/plot request in matplotlib, seaborn, plotly, ggplot2, Altair/Vega...Votes: 0GitHub stars: 39
- Codebase Study Parallel ReportersStudy an unfamiliar codebase (or audit a feature across repos) by dispatching PARALLEL READ-ONLY reporter subagents in a SINGLE tool block, NOT by reading files one-at-a-time in the main thread. Use when the user says 'study how X works', 'audit the codebase', 'understand the architecture', 'investigate the repo', 'read these files and report', hands you a file/line-range/grep list to examine, or asks to compare how two repos implement the same feature. Each reporter gets: a focused concern, ...Votes: 0GitHub stars: 39
- Blog Explainer Prose DedupTighten long-form explainer/pedagogical blog prose by auditing for facts and concepts stated 2+ times across sections and condensing each to a single mention with forward-references. Use when the user says 'less repetitive', 'more pedagogically coherent', 'too repetitive', 'this restates what was already said', 'tighten the prose', or flags a concept explained multiple times (intro re-explains, body re-derives, later section re-states). ALSO governs the INVERSE coverage problem: a takeaway/su...Votes: 0GitHub stars: 39