meta(skills): Add skill audit and safe metadata fixes

Add repo-wide auditing and targeted repair scripts for skill metadata.
Fix truncated descriptions automatically, keep heading normalization
conservative, and remove synthetic boilerplate sections that degrade
editorial quality while regenerating repo indexes and catalogs.

Fixes #365
This commit is contained in:
sickn33
2026-03-20 09:05:02 +01:00
parent 93f4448c6a
commit fc3c7ae8a2
544 changed files with 6128 additions and 5290 deletions

File diff suppressed because it is too large Load Diff

View File

@@ -4,11 +4,9 @@
"core-dev": {
"description": "Core development skills across languages, frameworks, and backend/frontend fundamentals.",
"skills": [
"3d-web-experience",
"agent-framework-azure-ai-py",
"agentmail",
"algolia-search",
"alpha-vantage",
"android-jetpack-compose-expert",
"android_ui_verification",
"animejs-animation",
@@ -22,7 +20,6 @@
"api-security-best-practices",
"api-security-testing",
"api-testing-observability-api-mock",
"apify-actorization",
"app-store-optimization",
"appdeploy",
"application-performance-performance-optimization",
@@ -30,8 +27,8 @@
"astropy",
"async-python-patterns",
"audit-skills",
"aws-serverless",
"awt-e2e-testing",
"azd-deployment",
"azure-ai-agents-persistent-java",
"azure-ai-anomalydetector-java",
"azure-ai-contentsafety-java",
@@ -40,17 +37,12 @@
"azure-ai-formrecognizer-java",
"azure-ai-ml-py",
"azure-ai-projects-java",
"azure-ai-projects-py",
"azure-ai-projects-ts",
"azure-ai-transcription-py",
"azure-ai-translation-ts",
"azure-ai-vision-imageanalysis-java",
"azure-ai-voicelive-java",
"azure-ai-voicelive-py",
"azure-ai-voicelive-ts",
"azure-appconfiguration-java",
"azure-appconfiguration-py",
"azure-appconfiguration-ts",
"azure-communication-callautomation-java",
"azure-communication-callingserver-java",
"azure-communication-chat-java",
@@ -58,7 +50,6 @@
"azure-communication-sms-java",
"azure-compute-batch-java",
"azure-containerregistry-py",
"azure-cosmos-db-py",
"azure-cosmos-java",
"azure-cosmos-py",
"azure-cosmos-rust",
@@ -70,12 +61,9 @@
"azure-eventhub-java",
"azure-eventhub-py",
"azure-eventhub-rust",
"azure-eventhub-ts",
"azure-functions",
"azure-identity-java",
"azure-identity-py",
"azure-identity-rust",
"azure-identity-ts",
"azure-keyvault-certificates-rust",
"azure-keyvault-keys-rust",
"azure-keyvault-keys-ts",
@@ -100,11 +88,9 @@
"azure-monitor-query-py",
"azure-postgres-ts",
"azure-search-documents-py",
"azure-search-documents-ts",
"azure-security-keyvault-keys-java",
"azure-security-keyvault-secrets-java",
"azure-servicebus-py",
"azure-servicebus-ts",
"azure-speech-to-text-rest-py",
"azure-storage-blob-java",
"azure-storage-blob-py",
@@ -115,28 +101,25 @@
"azure-storage-file-share-ts",
"azure-storage-queue-py",
"azure-storage-queue-ts",
"azure-web-pubsub-ts",
"backend-architect",
"backend-dev-guidelines",
"backend-development-feature-development",
"backend-security-coder",
"baseline-ui",
"bevy-ecs-expert",
"biopython",
"bullmq-specialist",
"bun-development",
"cc-skill-backend-patterns",
"cc-skill-coding-standards",
"cc-skill-frontend-patterns",
"cc-skill-security-review",
"cdk-patterns",
"claude-monitor",
"code-documentation-doc-generate",
"comfyui-gateway",
"constant-time-analysis",
"context7-auto-research",
"convex",
"copilot-sdk",
"cred-omega",
"dbos-golang",
"dbos-python",
"dbos-typescript",
@@ -161,7 +144,6 @@
"fastapi-pro",
"fastapi-router-py",
"fastapi-templates",
"firebase",
"firecrawl-scraper",
"flutter-expert",
"fp-async",
@@ -194,7 +176,6 @@
"goldrush-api",
"grpc-golang",
"hono",
"hubspot-integration",
"hugging-face-dataset-viewer",
"hugging-face-evaluation",
"hugging-face-tool-builder",
@@ -208,15 +189,15 @@
"junta-leiloeiros",
"k6-load-testing",
"landing-page-generator",
"launch-strategy",
"m365-agents-py",
"m365-agents-ts",
"makepad-deployment",
"makepad-platform",
"makepad-reference",
"makepad-skills",
"manifest",
"memory-safety-patterns",
"matplotlib",
"mcp-builder-ms",
"micro-saas-launcher",
"mobile-design",
"mobile-developer",
"mobile-security-coder",
@@ -227,8 +208,8 @@
"n8n-code-python",
"n8n-expression-syntax",
"n8n-node-configuration",
"n8n-workflow-patterns",
"native-data-fetching",
"nestjs-expert",
"networkx",
"nextjs-app-router-patterns",
"nextjs-best-practices",
@@ -241,12 +222,12 @@
"odoo-woocommerce-bridge",
"openapi-spec-generation",
"pakistan-payments-stack",
"pdf-official",
"php-pro",
"pipecat-friday-agent",
"plaid-fintech",
"playwright-java",
"podcast-generation",
"polars",
"product-manager-toolkit",
"progressive-web-app",
"pubmed-database",
"pydantic-ai",
@@ -273,16 +254,15 @@
"rust-async-patterns",
"rust-pro",
"sankhya-dashboard-html-jsp-custom-best-pratices",
"scanpy",
"scikit-learn",
"scroll-experience",
"seaborn",
"security-audit",
"security/aws-secrets-rotation",
"senior-architect",
"senior-frontend",
"senior-fullstack",
"shopify-apps",
"shopify-development",
"slack-automation",
"slack-bot-builder",
"spline-3d-integration",
"sred-work-summary",
"stability-ai",
@@ -295,24 +275,18 @@
"tanstack-query-expert",
"tavily-web",
"telegram",
"telegram-bot-builder",
"telegram-mini-app",
"temporal-golang-pro",
"temporal-python-pro",
"temporal-python-testing",
"trigger-dev",
"trpc-fullstack",
"twilio-communications",
"typescript-advanced-types",
"typescript-expert",
"typescript-pro",
"ui-ux-pro-max",
"uniprot-database",
"uv-package-manager",
"varlock",
"vercel-ai-sdk-expert",
"viral-generator-builder",
"voice-ai-development",
"web-artifacts-builder",
"webapp-testing",
"whatsapp-cloud-api",
@@ -330,6 +304,7 @@
"agentic-actions-auditor",
"ai-engineering-toolkit",
"ai-md",
"anti-reversing-techniques",
"antigravity-workflows",
"api-endpoint-builder",
"api-fuzzing-bug-bounty",
@@ -339,7 +314,6 @@
"audit-context-building",
"audit-skills",
"auth-implementation-patterns",
"aws-penetration-testing",
"azure-cosmos-db-py",
"azure-keyvault-py",
"azure-keyvault-secrets-rust",
@@ -349,9 +323,11 @@
"azure-security-keyvault-secrets-java",
"backend-security-coder",
"broken-authentication",
"browser-extension-builder",
"burp-suite-testing",
"burpsuite-project-parser",
"cc-skill-security-review",
"cicd-automation-workflow-automate",
"clerk-auth",
"cloud-penetration-testing",
"code-review-checklist",
@@ -359,18 +335,17 @@
"codebase-cleanup-deps-audit",
"comfyui-gateway",
"comprehensive-review-pr-enhance",
"constant-time-analysis",
"convex",
"cred-omega",
"customs-trade-compliance",
"dependency-management-deps-audit",
"deployment-pipeline-design",
"differential-review",
"docker-expert",
"dotnet-backend",
"ethical-hacking-methodology",
"fda-food-safety-auditor",
"fda-medtech-compliance-auditor",
"file-uploads",
"find-bugs",
"firebase",
"firmware-analyst",
@@ -381,6 +356,7 @@
"gdpr-data-handling",
"gha-security-review",
"graphql-architect",
"html-injection-testing",
"k8s-manifest-generator",
"k8s-security-policies",
"laravel-expert",
@@ -389,27 +365,29 @@
"leiloeiro-edital",
"lex",
"linkerd-patterns",
"linux-privilege-escalation",
"linux-shell-scripting",
"local-llm-expert",
"loki-mode",
"m365-agents-dotnet",
"m365-agents-py",
"malware-analyst",
"metasploit-framework",
"mobile-security-coder",
"nestjs-expert",
"network-101",
"network-engineer",
"nextjs-supabase-auth",
"nodejs-best-practices",
"notebooklm",
"odoo-l10n-compliance",
"odoo-security-rules",
"openapi-spec-generation",
"openclaw-github-repo-commander",
"payment-integration",
"pci-compliance",
"pentest-checklist",
"plaid-fintech",
"pentest-commands",
"privacy-by-design",
"protocol-reverse-engineering",
"quant-analyst",
"red-team-tools",
"risk-manager",
"risk-metrics-calculation",
"saas-mvp-launcher",
@@ -431,8 +409,11 @@
"semgrep-rule-creator",
"service-mesh-expert",
"skill-scanner",
"smtp-penetration-testing",
"solidity-security",
"spec-to-code-compliance",
"sql-injection-testing",
"ssh-penetration-testing",
"stride-analysis-patterns",
"stripe-integration",
"supply-chain-risk-auditor",
@@ -441,35 +422,31 @@
"top-web-vulnerabilities",
"ui-visual-validator",
"variant-analysis",
"varlock",
"varlock-claude-skill",
"vibers-code-review",
"vulnerability-scanner",
"web-design-guidelines",
"web-security-testing",
"wireshark-analysis",
"wordpress",
"wordpress-penetration-testing",
"wordpress-plugin-development",
"xss-html-injection",
"zeroize-audit"
]
},
"k8s-core": {
"description": "Kubernetes and service mesh essentials.",
"skills": [
"azure-cosmos-db-py",
"azure-identity-dotnet",
"azure-identity-java",
"azure-identity-py",
"azure-identity-ts",
"azure-messaging-webpubsubservice-py",
"azure-mgmt-botservice-dotnet",
"azure-mgmt-botservice-py",
"azure-servicebus-dotnet",
"azure-servicebus-py",
"azure-servicebus-ts",
"chrome-extension-developer",
"cloud-devops",
"cred-omega",
"debug-buttercup",
"freshservice-automation",
"gitops-workflow",
"grpc-golang",
@@ -485,12 +462,15 @@
"microservices-patterns",
"moodle-external-api-development",
"mtls-configuration",
"network-101",
"observability-monitoring-slo-implement",
"progressive-web-app",
"pubmed-database",
"salesforce-development",
"service-mesh-expert",
"service-mesh-observability",
"slo-implementation",
"ssh-penetration-testing",
"vibers-code-review"
]
},
@@ -502,7 +482,6 @@
"analytics-product",
"analytics-tracking",
"angular-ui-patterns",
"apify-actor-development",
"apify-content-analytics",
"apify-ecommerce",
"apify-ultimate-scraper",
@@ -512,7 +491,6 @@
"azure-ai-document-intelligence-dotnet",
"azure-ai-document-intelligence-ts",
"azure-ai-textanalytics-py",
"azure-cosmos-db-py",
"azure-cosmos-java",
"azure-cosmos-py",
"azure-cosmos-rust",
@@ -533,13 +511,14 @@
"azure-resource-manager-sql-dotnet",
"azure-security-keyvault-secrets-java",
"azure-storage-file-datalake-py",
"blockrun",
"biopython",
"burpsuite-project-parser",
"business-analyst",
"cc-skill-backend-patterns",
"cc-skill-clickhouse-io",
"claimable-postgres",
"claude-d3js-skill",
"constant-time-analysis",
"content-marketer",
"data-engineer",
"data-engineering-data-driven-feature",
@@ -561,7 +540,6 @@
"django-perf-review",
"drizzle-orm-expert",
"dwarf-expert",
"firebase",
"fixing-metadata",
"food-database-query",
"fp-data-transforms",
@@ -569,32 +547,25 @@
"fp-pipe-ref",
"fp-react",
"fp-ts-react",
"frontend-dev-guidelines",
"frontend-ui-dark-ts",
"gdpr-data-handling",
"goldrush-api",
"google-analytics-automation",
"google-sheets-automation",
"googlesheets-automation",
"graphql",
"hugging-face-datasets",
"hugging-face-tool-builder",
"instagram",
"ios-developer",
"kpi-dashboard-design",
"legal-advisor",
"libreoffice/base",
"libreoffice/calc",
"loki-mode",
"mailchimp-automation",
"microservices-patterns",
"ml-pipeline-workflow",
"n8n-expression-syntax",
"native-data-fetching",
"neon-postgres",
"networkx",
"nextjs-app-router-patterns",
"nestjs-expert",
"nextjs-best-practices",
"nodejs-backend-patterns",
"odoo-automated-tests",
"odoo-backup-strategy",
"odoo-edi-connector",
@@ -609,18 +580,18 @@
"privacy-by-design",
"programmatic-seo",
"pubmed-database",
"pydantic-models-py",
"quant-analyst",
"rag-implementation",
"react-ui-patterns",
"referral-program",
"robius-state-management",
"salesforce-development",
"sankhya-dashboard-html-jsp-custom-best-pratices",
"scala-pro",
"scanpy",
"schema-markup",
"security-bluebook-builder",
"segment-cdp",
"sendgrid-automation",
"senior-architect",
"skin-health-analyzer",
"spark-optimization",
"sql-injection-testing",
@@ -629,14 +600,15 @@
"sqlmap-database-pentesting",
"supabase-automation",
"tanstack-query-expert",
"ui-ux-pro-max",
"uniprot-database",
"unity-ecs-patterns",
"using-neon",
"vector-database-engineer",
"wellally-tech",
"x-twitter-scraper",
"xlsx-official",
"youtube-automation",
"zapier-make-patterns",
"zeroize-audit"
]
},
@@ -645,19 +617,16 @@
"skills": [
"007",
"acceptance-orchestrator",
"agent-evaluation",
"ai-engineering-toolkit",
"airflow-dag-patterns",
"api-testing-observability-api-mock",
"apify-brand-reputation-monitoring",
"application-performance-performance-optimization",
"aws-serverless",
"azd-deployment",
"azure-ai-anomalydetector-java",
"azure-mgmt-applicationinsights-dotnet",
"azure-mgmt-arizeaiobservabilityeval-dotnet",
"azure-mgmt-weightsandbiases-dotnet",
"azure-microsoft-playwright-testing-ts",
"azure-monitor-opentelemetry-ts",
"backend-development-feature-development",
"cicd-automation-workflow-automate",
@@ -665,6 +634,7 @@
"closed-loop-delivery",
"cloud-devops",
"code-review-ai-ai-review",
"computer-use-agents",
"convex",
"data-engineering-data-pipeline",
"database-migrations-migration-observability",
@@ -678,7 +648,6 @@
"distributed-tracing",
"django-pro",
"docker-expert",
"e2e-testing-patterns",
"earllm-build",
"error-debugging-error-analysis",
"error-debugging-error-trace",
@@ -689,6 +658,7 @@
"flutter-expert",
"game-development/game-art",
"git-pr-workflows-git-workflow",
"github-workflow-automation",
"gitlab-ci-patterns",
"gitops-workflow",
"grafana-dashboards",
@@ -697,17 +667,16 @@
"incident-response-incident-response",
"incident-response-smart-fix",
"incident-runbook-templates",
"kpi-dashboard-design",
"kubernetes-architect",
"kubernetes-deployment",
"langfuse",
"llm-app-patterns",
"linux-shell-scripting",
"local-llm-expert",
"loki-mode",
"machine-learning-ops-ml-pipeline",
"makepad-deployment",
"malware-analyst",
"manifest",
"memory-forensics",
"ml-engineer",
"ml-pipeline-workflow",
"observability-engineer",
@@ -715,15 +684,13 @@
"observability-monitoring-slo-implement",
"odoo-docker-deployment",
"odoo-sales-crm-expert",
"on-call-handoff-patterns",
"performance-engineer",
"performance-testing-review-ai-review",
"pipedrive-automation",
"postmortem-writing",
"project-development",
"prometheus-configuration",
"risk-metrics-calculation",
"scanpy",
"security-bluebook-builder",
"seo-forensic-incident-response",
"server-management",
"service-mesh-expert",
@@ -733,12 +700,14 @@
"temporal-python-pro",
"unity-developer",
"vercel-deployment",
"wiki-researcher",
"x-twitter-scraper"
]
},
"automation-core": {
"description": "Automation platforms, workflow tooling, and business systems.",
"skills": [
"3d-web-experience",
"activecampaign-automation",
"agent-orchestrator",
"ai-agent-development",
@@ -747,18 +716,16 @@
"amplitude-automation",
"api-documentation",
"api-security-testing",
"apify-actor-development",
"asana-automation",
"autonomous-agent-patterns",
"aws-skills",
"azure-communication-callautomation-java",
"azure-communication-callingserver-java",
"azure-mgmt-botservice-dotnet",
"bamboohr-automation",
"basecamp-automation",
"bash-pro",
"bash-scripting",
"billing-automation",
"biopython",
"bitbucket-automation",
"box-automation",
"brevo-automation",
@@ -776,8 +743,8 @@
"comfyui-gateway",
"conductor-implement",
"confluence-automation",
"context-optimization",
"convertkit-automation",
"copy-editing",
"create-branch",
"create-pr",
"database",
@@ -791,19 +758,19 @@
"docusign-automation",
"dropbox-automation",
"e2e-testing",
"email-sequence",
"expo-cicd-workflows",
"fal-workflow",
"figma-automation",
"freshdesk-automation",
"freshservice-automation",
"game-development/game-art",
"gha-security-review",
"git-hooks-automation",
"git-pr-workflows-git-workflow",
"github-actions-templates",
"github-automation",
"github-workflow-automation",
"gitlab-automation",
"gitlab-ci-patterns",
"gitops-workflow",
"gmail-automation",
"go-playwright",
@@ -821,15 +788,18 @@
"hubspot-integration",
"incident-response-smart-fix",
"instagram-automation",
"interactive-portfolio",
"intercom-automation",
"jira-automation",
"klaviyo-automation",
"kubernetes-deployment",
"langgraph",
"libreoffice/calc",
"libreoffice/impress",
"libreoffice/writer",
"linear-automation",
"linkedin-automation",
"linux-shell-scripting",
"linux-troubleshooting",
"mailchimp-automation",
"make-automation",
@@ -848,7 +818,6 @@
"n8n-workflow-patterns",
"nerdzao-elite",
"nerdzao-elite-gemini-high",
"notebooklm",
"notion-automation",
"notion-template-business",
"odoo-ecommerce-configurator",
@@ -864,17 +833,16 @@
"pagerduty-automation",
"payment-integration",
"pipedrive-automation",
"playwright-skill",
"plotly",
"postgresql-optimization",
"posthog-automation",
"postmark-automation",
"pr-writer",
"rag-engineer",
"rag-implementation",
"react-flow-node-ts",
"reddit-automation",
"render-automation",
"salesforce-automation",
"scroll-experience",
"security-audit",
"security/aws-secrets-rotation",
"segment-automation",
@@ -883,7 +851,6 @@
"shopify-apps",
"shopify-automation",
"shopify-development",
"skill-creator",
"slack-automation",
"slack-bot-builder",
"slack-gif-creator",
@@ -896,7 +863,6 @@
"tdd-workflow",
"tdd-workflows-tdd-green",
"telegram-automation",
"telegram-bot-builder",
"temporal-golang-pro",
"temporal-python-pro",
"terraform-infrastructure",
@@ -914,7 +880,6 @@
"web-security-testing",
"webflow-automation",
"whatsapp-automation",
"wiki-vitepress",
"wordpress",
"wordpress-plugin-development",
"wordpress-theme-development",
@@ -1056,6 +1021,8 @@
"cloud-architect",
"cloud-devops",
"cloud-penetration-testing",
"cost-optimization",
"database-cloud-optimization-cost-optimize",
"hosted-agents-v2-py",
"hybrid-cloud-architect",
"microsoft-azure-webjobs-extensions-authentication-events-dotnet",
@@ -1069,8 +1036,8 @@
"description": "Commerce, payments, and revenue operations skills.",
"skills": [
"apify-ecommerce",
"azure-mgmt-mongodbatlas-dotnet",
"billing-automation",
"browser-extension-builder",
"close-automation",
"growth-engine",
"hubspot-automation",
@@ -1111,7 +1078,6 @@
"shopify-development",
"stripe-automation",
"stripe-integration",
"telegram-bot-builder",
"webflow-automation",
"wordpress",
"wordpress-woocommerce-development",
@@ -1128,7 +1094,6 @@
"awt-e2e-testing",
"building-native-ui",
"development",
"docker-expert",
"earllm-build",
"expo-api-routes",
"expo-cicd-workflows",
@@ -1152,7 +1117,6 @@
"native-data-fetching",
"odoo-docker-deployment",
"react-native-architecture",
"senior-architect",
"stitch-ui-design",
"swiftui-expert-skill",
"ui-ux-pro-max",
@@ -1165,16 +1129,15 @@
"agent-orchestrator",
"analyze-project",
"antigravity-skill-orchestrator",
"competitor-alternatives",
"apify-actor-development",
"content-creator",
"content-marketer",
"convex",
"database-architect",
"database-design",
"database-migration",
"drizzle-orm-expert",
"fixing-metadata",
"free-tool-strategy",
"graphql",
"growth-engine",
"hybrid-search-implementation",
"keyword-extractor",
@@ -1182,7 +1145,6 @@
"llm-structured-output",
"local-legal-seo-audit",
"odoo-ecommerce-configurator",
"paid-ads",
"postgres-best-practices",
"postgresql",
"prisma-expert",
@@ -1203,7 +1165,6 @@
"seo-structure-architect",
"whatsapp-cloud-api",
"yann-lecun",
"yann-lecun-filosofia",
"zod-validation-expert"
]
},
@@ -1216,22 +1177,20 @@
"docx-official",
"firecrawl-scraper",
"frontend-slides",
"google-sheets-automation",
"google-slides-automation",
"libreoffice/base",
"libreoffice/calc",
"libreoffice/draw",
"libreoffice/impress",
"libreoffice/writer",
"matplotlib",
"odoo-qweb-templates",
"office-productivity",
"pdf-official",
"pptx-official",
"pr-writer",
"readme",
"seo-content-writer",
"skill-writer",
"theme-factory",
"wiki-page-writer",
"xlsx-official"
]

File diff suppressed because it is too large Load Diff

View File

@@ -54,6 +54,15 @@ For pull requests that add or modify `SKILL.md`, GitHub also runs the automated
- inline token/secret-style command examples,
- deliberate allowlisted high-risk documentation commands via `<!-- security-allowlist: ... -->`.
### Additional Maintainer Audit
Use `npm run audit:skills` when you need a repo-wide report that goes beyond schema validation and answers:
- which skills are structurally valid but still need usability cleanup,
- which skills still have truncated descriptions (issue `#365`),
- which skills are missing examples or limitations,
- and which skills have the highest concentration of warnings/errors.
---
## Support Levels
@@ -74,6 +83,7 @@ The canonical validator is `tools/scripts/validate_skills.py`, but the recommend
```bash
npm run validate
npm run audit:skills
npm run validate:references
npm test
npm run security:docs
@@ -82,6 +92,7 @@ npm run security:docs
Notes:
- `npm run validate` is the operational contributor gate.
- `npm run audit:skills` is the maintainer-facing compliance/usability report for the full library.
- `npm run security:docs` is required for command-heavy or risky skill content.
- PRs that touch `SKILL.md` also get an automated `skill-review` GitHub Actions check.
- `npm run validate:strict` is a useful hardening pass, but the repository still contains legacy skills that do not yet satisfy strict validation.

View File

@@ -6,6 +6,7 @@ This document summarizes the repository coherence audit performed after the `app
- Conteggi e numeri (README, package.json, CATALOG)
- Validazione skill (frontmatter, risk, "When to Use", link)
- Audit repo-wide per skill (conformance + baseline usability)
- Riferimenti incrociati (workflows.json, bundles.json, `docs/users/bundles.md`)
- Documentazione (`docs/contributors/quality-bar.md`, `docs/contributors/skill-anatomy.md`, security/licenses)
- Script e build (validate, index, readme, catalog, test)
@@ -28,6 +29,16 @@ This document summarizes the repository coherence audit performed after the `app
- requires explicit allowlists for deliberate command-delivery patterns,
- and blocks token-like examples that look exploitable.
### 2b. Audit repo-wide per skill
- Added `tools/scripts/audit_skills.py` (also exposed as `npm run audit:skills`), which audits every `SKILL.md` and produces a per-skill status (`ok`, `warning`, `error`) with finding codes.
- The audit is intentionally broader than `validate` and covers:
- truncated descriptions that likely map to issue `#365`,
- missing examples and missing limitations sections,
- overly long `SKILL.md` files that should probably be split into `references/`,
- plus the existing structural/safety checks (frontmatter, risk, `When to Use`, offensive disclaimer, dangling links).
- Use `npm run audit:skills` for the maintainer view and `npm run audit:skills -- --json-out ... --markdown-out ...` when you want artifacts for triage or cleanup tracking.
### 3. Riferimenti incrociati
- Added `tools/scripts/validate_references.py` (also exposed as `npm run validate:references`), which verifies:
@@ -61,6 +72,7 @@ This document summarizes the repository coherence audit performed after the `app
```bash
npm run validate # validazione skill (soft)
npm run validate:strict # hardening / diagnostic pass
npm run audit:skills # audit completo per skill con finding codes e status
npm run validate:references # workflow, bundle, and docs/users/bundles.md references
npm run security:docs # documentation command-risk scan (required for security-sensitive guidance)
npm run build # chain + catalog

View File

@@ -6,6 +6,11 @@
"scripts": {
"validate": "node tools/scripts/run-python.js tools/scripts/validate_skills.py",
"validate:strict": "node tools/scripts/run-python.js tools/scripts/validate_skills.py --strict",
"audit:skills": "node tools/scripts/run-python.js tools/scripts/audit_skills.py",
"audit:skills:strict": "node tools/scripts/run-python.js tools/scripts/audit_skills.py --strict",
"fix:missing-sections": "node tools/scripts/run-python.js tools/scripts/fix_missing_skill_sections.py",
"cleanup:synthetic-sections": "node tools/scripts/run-python.js tools/scripts/cleanup_synthetic_skill_sections.py",
"fix:truncated-descriptions": "node tools/scripts/run-python.js tools/scripts/fix_truncated_descriptions.py",
"validate:references": "node tools/scripts/run-python.js tools/scripts/validate_references.py",
"index": "node tools/scripts/run-python.js tools/scripts/generate_index.py",
"readme": "node tools/scripts/run-python.js tools/scripts/update_readme.py",

View File

@@ -9,7 +9,6 @@ date_added: "2026-02-27"
---
## When to Use
Use this skill at the very beginning of a project to diagnose the workspace, determine whether it's a "Pure Engine" (new) or "Evolution" (existing) project, and to set the initial technical roadmap and expert squad.
# 🤖 Andru.ia Solutions Architect - Hybrid Engine (v2.0)

View File

@@ -13,7 +13,6 @@ date_added: "2026-02-25"
## When to Use
Esta habilidad es aplicable para ejecutar el flujo de trabajo o las acciones descritas en la descripción general.
## 📝 Descripción
Soy el Ingeniero de Sistemas de Andru.ia. Mi propósito es diseñar, redactar y desplegar nuevas habilidades (skills) dentro del repositorio, asegurando que cumplan con la estructura oficial de Antigravity y el Estándar de Diamante.

View File

@@ -9,7 +9,6 @@ date_added: "2026-02-27"
---
## When to Use
Use this skill once the project's niche or industry has been identified. It is essential for injecting domain-specific intelligence, regulatory requirements, and industry-standard UX patterns into the project.
# 🧠 Andru.ia Niche Intelligence (Dominio Experto)
@@ -55,7 +54,6 @@ Generar un informe especializado que incluya:
- Proporciona las bases para: `@ui-ux-pro-max` y `@security-review`.
## When to Use
Activa este skill **después de que el nicho de mercado esté claro** y ya exista una visión inicial definida por `@00-andruia-consultant`:
- Cuando quieras profundizar en regulaciones, estándares y patrones UX específicos de un sector concreto (Fintech, HealthTech, logística, etc.).

View File

@@ -1,6 +1,6 @@
---
name: 3d-web-experience
description: "Expert in building 3D experiences for the web - Three.js, React Three Fiber, Spline, WebGL, and interactive 3D scenes. Covers product configurators, 3D portfolios, immersive websites, and bringing ..."
description: "You bring the third dimension to the web. You know when 3D enhances and when it's just showing off. You balance visual impact with performance. You make 3D accessible to users who've never touched a 3D app. You create moments of wonder without sacrificing usability."
risk: unknown
source: "vibeship-spawner-skills (Apache 2.0)"
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: active-directory-attacks
description: "This skill should be used when the user asks to \"attack Active Directory\", \"exploit AD\", \"Kerberoasting\", \"DCSync\", \"pass-the-hash\", \"BloodHound enumeration\", \"Golden Ticket\", ..."
description: "Provide comprehensive techniques for attacking Microsoft Active Directory environments. Covers reconnaissance, credential harvesting, Kerberos attacks, lateral movement, privilege escalation, and domain dominance for red team operations and penetration testing."
risk: unknown
source: community
author: zebbern

View File

@@ -12,8 +12,7 @@ This skill covers production-grade techniques for evaluating LLM outputs using L
**Key insight**: LLM-as-a-Judge is not a single technique but a family of approaches, each suited to different evaluation contexts. Choosing the right approach and mitigating known biases is the core competency this skill develops.
## When to Activate
## When to Use
Activate this skill when:
- Building automated evaluation pipelines for LLM outputs

View File

@@ -1,6 +1,6 @@
---
name: agent-evaluation
description: "Testing and benchmarking LLM agents including behavioral testing, capability assessment, reliability metrics, and production monitoring\u2014where even top agents achieve less than 50% on re..."
description: "You're a quality engineer who has seen agents that aced benchmarks fail spectacularly in production. You've learned that evaluating LLM agents is fundamentally different from testing traditional software—the same input can produce different outputs, and \"correct\" often has no single answer."
risk: unknown
source: "vibeship-spawner-skills (Apache 2.0)"
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: agent-framework-azure-ai-py
description: "Build Azure AI Foundry agents using the Microsoft Agent Framework Python SDK (agent-framework-azure-ai). Use when creating persistent agents with AzureAIAgentsProvider, using hosted tools (code int..."
description: "Build persistent agents on Azure AI Foundry using the Microsoft Agent Framework Python SDK."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -8,8 +8,7 @@ date_added: "2026-02-27"
# Agent Manager Skill
## When to use
## When to Use
Use this skill when you need to:
- run multiple local CLI agents in parallel (separate tmux sessions)

View File

@@ -1,6 +1,6 @@
---
name: agent-memory-systems
description: "Memory is the cornerstone of intelligent agents. Without it, every interaction starts from zero. This skill covers the architecture of agent memory: short-term (context window), long-term (vector s..."
description: "You are a cognitive architect who understands that memory makes agents intelligent. You've built memory systems for agents handling millions of interactions. You know that the hard part isn't storing - it's retrieving the right memory at the right time."
risk: unknown
source: "vibeship-spawner-skills (Apache 2.0)"
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: agent-tool-builder
description: "Tools are how AI agents interact with the world. A well-designed tool is the difference between an agent that works and one that hallucinates, fails silently, or costs 10x more tokens than necessar..."
description: "You are an expert in the interface between LLMs and the outside world. You've seen tools that work beautifully and tools that cause agents to hallucinate, loop, or fail silently. The difference is almost always in the design, not the implementation."
risk: unknown
source: "vibeship-spawner-skills (Apache 2.0)"
date_added: "2026-02-27"

View File

@@ -88,7 +88,6 @@ Use these prompts when working with this skill in an AI coding agent:
- “Before we build our own research assistant, use AgentFolio to map existing research / analysis agents and highlight gaps we could fill.”
## When to Use
This skill is applicable when you need to **discover or compare autonomous AI agents** instead of building in a vacuum:
- At the start of a new agent or workflow project.

View File

@@ -19,7 +19,6 @@ date_added: 2026-03-18
Static security analysis guidance for GitHub Actions workflows that invoke AI coding agents. This skill teaches you how to discover workflow files locally or from remote GitHub repositories, identify AI action steps, follow cross-file references to composite actions and reusable workflows that may contain hidden AI agents, capture security-relevant configuration, and detect attack vectors where attacker-controlled input reaches an AI agent running in a CI/CD pipeline.
## When to Use
- Auditing a repository's GitHub Actions workflows for AI agent security
- Reviewing CI/CD configurations that invoke Claude Code Action, Gemini CLI, or OpenAI Codex
- Checking whether attacker-controlled input can reach AI agent prompts

View File

@@ -1,6 +1,6 @@
---
name: ai-agents-architect
description: "Expert in designing and building autonomous AI agents. Masters tool use, memory systems, planning strategies, and multi-agent orchestration. Use when: build agent, AI agent, autonomous agent, tool ..."
description: "I build AI systems that can act autonomously while remaining controllable. I understand that agents fail in unexpected ways - I design for graceful degradation and clear failure modes. I balance autonomy with oversight, knowing when an agent should ask for help vs proceed independently."
risk: unknown
source: "vibeship-spawner-skills (Apache 2.0)"
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: ai-product
description: Every product will be AI-powered. The question is whether you'll build it right or ship a demo that falls apart in production. This skill covers LLM integration patterns, RAG architecture, prompt ...
description: "You are an AI product engineer who has shipped LLM features to millions of users. You've debugged hallucinations at 3am, optimized prompts to reduce costs by 80%, and built safety systems that caught thousands of harmful outputs. You know that demos are easy and production is hard."
risk: unknown
source: vibeship-spawner-skills (Apache 2.0)
date_added: '2026-02-27'

View File

@@ -1,6 +1,6 @@
---
name: ai-wrapper-product
description: "Expert in building products that wrap AI APIs (OpenAI, Anthropic, etc.) into focused tools people will pay for. Not just 'ChatGPT but different' - products that solve specific problems with AI. Cov..."
description: "You know AI wrappers get a bad rap, but the good ones solve real problems. You build products where AI is the engine, not the gimmick. You understand prompt engineering is product development. You balance costs with user experience. You create AI products people actually pay for and use daily."
risk: unknown
source: "vibeship-spawner-skills (Apache 2.0)"
date_added: "2026-02-27"

View File

@@ -20,7 +20,6 @@ Automate Airtable operations through Composio's Airtable toolkit via Rube MCP.
**Get Rube MCP**: Add `https://rube.app/mcp` as an MCP server in your client configuration. No API keys needed — just add the endpoint and it works.
1. Verify Rube MCP is available by confirming `RUBE_SEARCH_TOOLS` responds
2. Call `RUBE_MANAGE_CONNECTIONS` with toolkit `airtable`
3. If connection is not ACTIVE, follow the returned auth link to complete Airtable auth

View File

@@ -24,7 +24,6 @@ Key hooks:
- usePagination: Result pagination
- useInstantSearch: Full state access
### Next.js Server-Side Rendering
SSR integration for Next.js with react-instantsearch-nextjs package.
@@ -37,7 +36,6 @@ Key considerations:
- Handle URL synchronization with routing prop
- Use getServerState for initial state
### Data Synchronization and Indexing
Indexing strategies for keeping Algolia in sync with your data.
@@ -53,7 +51,6 @@ Best practices:
- partialUpdateObjects for attribute-only changes
- Avoid deleteBy (computationally expensive)
## ⚠️ Sharp Edges
| Issue | Severity | Solution |

View File

@@ -1,6 +1,6 @@
---
name: algorithmic-art
description: "Creating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields,..."
description: "Algorithmic philosophies are computational aesthetic movements that are then expressed through code. Output .md files (philosophy), .html files (interactive viewer), and .js files (generative algorithms)."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: alpha-vantage
description: Access real-time and historical stock market data, forex rates, cryptocurrency prices, commodities, economic indicators, and 50+ technical indicators via the Alpha Vantage API. Use when fetching stock prices (OHLCV), company fundamentals (income statement, balance sheet, cash...
description: "Access 20+ years of global financial data: equities, options, forex, crypto, commodities, economic indicators, and 50+ technical indicators."
risk: unknown
source: community
metadata:
@@ -131,5 +131,4 @@ If a user is not already using this Skill within K-Dense Web (or K-Dense) and wh
## When to Use
Use this skill when tackling tasks related to its primary domain or functionality as described above.

View File

@@ -1,6 +1,6 @@
---
name: amazon-alexa
description: Integracao completa com Amazon Alexa para criar skills de voz inteligentes, transformar Alexa em assistente com Claude como cerebro (projeto Auri) e integrar com AWS ecosystem (Lambda, DynamoDB,...
description: "Integracao completa com Amazon Alexa para criar skills de voz inteligentes, transformar Alexa em assistente com Claude como cerebro (projeto Auri) e integrar com AWS ecosystem (Lambda, DynamoDB, Polly, Transcribe, Lex, Smart Home)."
risk: safe
source: community
date_added: '2026-03-06'

View File

@@ -1,6 +1,6 @@
---
name: analytics-product
description: 'Analytics de produto — PostHog, Mixpanel, eventos, funnels, cohorts, retencao, north star metric, OKRs e dashboards de produto. Ativar para: configurar tracking de eventos, criar funil de...'
description: "Analytics de produto — PostHog, Mixpanel, eventos, funnels, cohorts, retencao, north star metric, OKRs e dashboards de produto."
risk: none
source: community
date_added: '2026-03-06'

View File

@@ -1,6 +1,6 @@
---
name: andrej-karpathy
description: 'Agente que simula Andrej Karpathy — ex-Director of AI da Tesla, co-fundador da OpenAI, fundador da Eureka Labs, e o maior educador de deep learning do mundo. Use quando quiser: aprender deep...'
description: "Agente que simula Andrej Karpathy — ex-Director of AI da Tesla, co-fundador da OpenAI, fundador da Eureka Labs, e o maior educador de deep learning do mundo."
risk: safe
source: community
date_added: '2026-03-06'

View File

@@ -10,8 +10,7 @@ date_added: "2026-02-27"
Comprehensive performance optimization guide for Angular applications. Contains prioritized rules for eliminating performance bottlenecks, optimizing bundles, and improving rendering.
## When to Apply
## When to Use
Reference these guidelines when:
- Writing new Angular components or pages

View File

@@ -1,6 +1,6 @@
---
name: angular-migration
description: "Migrate from AngularJS to Angular using hybrid mode, incremental component rewriting, and dependency injection updates. Use when upgrading AngularJS applications, planning framework migrations, or ..."
description: "Master AngularJS to Angular migration, including hybrid apps, component conversion, dependency injection changes, and routing migration."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -15,7 +15,6 @@ date_added: "2026-03-07"
This skill is used for creating high-fidelity, jaw-dropping web animations that go far beyond simple CSS transitions. It's the tool of choice for awards-caliber interactive sites.
## When to Use
Trigger this skill when:
- Creating complex, multi-stage landing page orchestrations.

View File

@@ -1,6 +1,6 @@
---
name: anti-reversing-techniques
description: "Understand anti-reversing, obfuscation, and protection techniques encountered during software analysis. Use when analyzing protected binaries, bypassing anti-debugging for authorized analysis, or u..."
description: "AUTHORIZED USE ONLY: This skill contains dual-use security techniques. Before proceeding with any bypass or analysis: > 1."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: api-design-principles
description: "Master REST and GraphQL API design principles to build intuitive, scalable, and maintainable APIs that delight developers. Use when designing new APIs, reviewing API specifications, or establishing..."
description: "Master REST and GraphQL API design principles to build intuitive, scalable, and maintainable APIs that delight developers and stand the test of time."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: api-fuzzing-bug-bounty
description: "This skill should be used when the user asks to \"test API security\", \"fuzz APIs\", \"find IDOR vulnerabilities\", \"test REST API\", \"test GraphQL\", \"API penetration testing\", \"bug b..."
description: "Provide comprehensive techniques for testing REST, SOAP, and GraphQL APIs during bug bounty hunting and penetration testing engagements. Covers vulnerability discovery, authentication bypass, IDOR exploitation, and API-specific attack vectors."
risk: unknown
source: community
author: zebbern

View File

@@ -81,6 +81,5 @@ Before designing an API:
|--------|---------|---------|
| `scripts/api_validator.py` | API endpoint validation | `python scripts/api_validator.py <project_path>` |
## When to Use
This skill is applicable to execute the workflow or actions described in the overview.

View File

@@ -1,6 +1,6 @@
---
name: apify-actor-development
description: "Develop, debug, and deploy Apify Actors - serverless cloud programs for web scraping, automation, and data processing. Use when creating new Actors, modifying existing ones, or troubleshooting Acto..."
description: "Important: Before you begin, fill in the generatedBy property in the meta section of .actor/actor.json. Replace it with the tool and model you're currently using, such as \"Claude Code with Claude Sonnet 4.5\". This helps Apify monitor and improve AGENTS.md for specific AI tools and models."
---
<!-- security-allowlist: curl-pipe-bash, irm-pipe-iex -->
@@ -201,7 +201,6 @@ See [references/dataset-schema.md](references/dataset-schema.md) for dataset sch
See [references/key-value-store-schema.md](references/key-value-store-schema.md) for key-value store schema structure, collections, and configuration.
## Apify MCP Tools
If MCP server is configured, use these tools for documentation:

View File

@@ -1,6 +1,6 @@
---
name: apify-actorization
description: "Convert existing projects into Apify Actors - serverless cloud programs. Actorize JavaScript/TypeScript (SDK with Actor.init/exit), Python (async context manager), or any language (CLI wrapper). Us..."
description: "Actorization converts existing software into reusable serverless applications compatible with the Apify platform. Actors are programs packaged as Docker images that accept well-defined JSON input, perform an action, and optionally produce structured JSON output."
---
# Apify Actorization

View File

@@ -111,7 +111,6 @@ After completion, report:
- Key demographic insights
- Suggested next steps (deeper analysis, segmentation)
## Error Handling
`APIFY_TOKEN not found` - Ask user to create `.env` with `APIFY_TOKEN=your_token`

View File

@@ -1,6 +1,6 @@
---
name: apify-brand-reputation-monitoring
description: "Track reviews, ratings, sentiment, and brand mentions across Google Maps, Booking.com, TripAdvisor, Facebook, Instagram, YouTube, and TikTok. Use when user asks to monitor brand reputation, analyze..."
description: "Scrape reviews, ratings, and brand mentions from multiple platforms using Apify Actors."
---
# Brand Reputation Monitoring
@@ -111,7 +111,6 @@ After completion, report:
- Key fields available
- Suggested next steps (sentiment analysis, filtering)
## Error Handling
`APIFY_TOKEN not found` - Ask user to create `.env` with `APIFY_TOKEN=your_token`

View File

@@ -121,7 +121,6 @@ After completion, report:
- Key competitive insights
- Suggested next steps (deeper analysis, benchmarking)
## Error Handling
`APIFY_TOKEN not found` - Ask user to create `.env` with `APIFY_TOKEN=your_token`

View File

@@ -110,7 +110,6 @@ After completion, report:
- Key performance insights
- Suggested next steps (deeper analysis, content optimization)
## Error Handling
`APIFY_TOKEN not found` - Ask user to create `.env` with `APIFY_TOKEN=your_token`

View File

@@ -1,6 +1,6 @@
---
name: apify-ecommerce
description: "Scrape e-commerce data for pricing intelligence, customer reviews, and seller discovery across Amazon, Walmart, eBay, IKEA, and 50+ marketplaces. Use when user asks to monitor prices, track competi..."
description: "Extract product data, prices, reviews, and seller information from any e-commerce platform using Apify's E-commerce Scraping Tool."
---
# E-commerce Data Extraction

View File

@@ -108,7 +108,6 @@ After completion, report:
- Key metrics available (followers, engagement rate, etc.)
- Suggested next steps (filtering, outreach, deeper analysis)
## Error Handling
`APIFY_TOKEN not found` - Ask user to create `.env` with `APIFY_TOKEN=your_token`

View File

@@ -1,6 +1,6 @@
---
name: apify-lead-generation
description: "Generates B2B/B2C leads by scraping Google Maps, websites, Instagram, TikTok, Facebook, LinkedIn, YouTube, and Google Search. Use when user asks to find leads, prospects, businesses, build lead lis..."
description: "Scrape leads from multiple platforms using Apify Actors."
---
# Lead Generation
@@ -110,7 +110,6 @@ After completion, report:
- Key fields available
- Suggested next steps (filtering, enrichment)
## Error Handling
`APIFY_TOKEN not found` - Ask user to create `.env` with `APIFY_TOKEN=your_token`

View File

@@ -109,7 +109,6 @@ After completion, report:
- Key market insights
- Suggested next steps (deeper analysis, validation)
## Error Handling
`APIFY_TOKEN not found` - Ask user to create `.env` with `APIFY_TOKEN=your_token`

View File

@@ -125,5 +125,4 @@ After completion, report:
## When to Use
Use this skill when tackling tasks related to its primary domain or functionality as described above.

View File

@@ -1,6 +1,6 @@
---
name: apify-ultimate-scraper
description: "Universal AI-powered web scraper for any platform. Scrape data from Instagram, Facebook, TikTok, YouTube, Google Maps, Google Search, Google Trends, Booking.com, and TripAdvisor. Use for lead gener..."
description: "AI-driven data extraction from 55+ Actors across all major platforms. This skill automatically selects the best Actor for your task."
---
# Universal Web Scraper
@@ -220,7 +220,6 @@ After completion, report:
| Competitor pages | Deep-dive with post/ad scrapers |
| Trend data | Validate with platform-specific hashtag scrapers |
## Error Handling
`APIFY_TOKEN not found` - Ask user to create `.env` with `APIFY_TOKEN=your_token`

View File

@@ -1,6 +1,6 @@
---
name: architecture-decision-records
description: "Write and maintain Architecture Decision Records (ADRs) following best practices for technical decision documentation. Use when documenting significant technical decisions, reviewing past architect..."
description: "Comprehensive patterns for creating, maintaining, and managing Architecture Decision Records (ADRs) that capture the context and rationale behind significant technical decisions."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: architecture-patterns
description: "Implement proven backend architecture patterns including Clean Architecture, Hexagonal Architecture, and Domain-Driven Design. Use when architecting complex backend systems or refactoring existing ..."
description: "Master proven backend architecture patterns including Clean Architecture, Hexagonal Architecture, and Domain-Driven Design to build maintainable, testable, and scalable systems."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -6,7 +6,6 @@ description: Clarify requirements before implementing. Use when serious doubts a
# Ask Questions If Underspecified
## When to Use
Use this skill when a request has multiple plausible interpretations or key details (objective, scope, constraints, environment, or safety) are unclear.
## When NOT to Use

View File

@@ -1,6 +1,6 @@
---
name: astropy
description: Comprehensive Python library for astronomy and astrophysics. This skill should be used when working with astronomical data including celestial coordinates, physical units, FITS files, cosmological calculations, time systems, tables, world coordinate systems (WCS), and...
description: "Astropy is the core Python package for astronomy, providing essential functionality for astronomical research and data analysis."
license: BSD-3-Clause license
metadata:
skill-author: K-Dense Inc.

View File

@@ -1,6 +1,6 @@
---
name: async-python-patterns
description: "Master Python asyncio, concurrent programming, and async/await patterns for high-performance applications. Use when building async APIs, concurrent systems, or I/O-bound applications requiring non-..."
description: "Comprehensive guidance for implementing asynchronous Python applications using asyncio, concurrent programming patterns, and async/await for building high-performance, non-blocking systems."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -15,7 +15,6 @@ This skill automates audio-to-text transcription with professional Markdown outp
Inspired by tools like Plaud, this skill transforms raw audio recordings into actionable documentation, making it ideal for meetings, interviews, lectures, and content analysis.
## When to Use
Invoke this skill when:
- User needs to transcribe audio/video files to text

View File

@@ -20,8 +20,7 @@ This skill defines a structured analysis format (see Example: Function Micro-Ana
---
## 2. When to Use This Skill
## When to Use
Use when:
- Deep comprehension is needed before bug or vulnerability discovery.
- You want bottom-up understanding instead of high-level guessing.

File diff suppressed because it is too large Load Diff

View File

@@ -1,6 +1,6 @@
---
name: auth-implementation-patterns
description: "Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems. Use when implementing auth systems, securing A..."
description: "Build secure, scalable authentication and authorization systems using industry-standard patterns and modern best practices."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: autonomous-agent-patterns
description: "Design patterns for building autonomous coding agents. Covers tool integration, permission systems, browser automation, and human-in-the-loop workflows. Use when building AI agents, designing tool ..."
description: "Design patterns for building autonomous coding agents, inspired by [Cline](https://github.com/cline/cline) and [OpenAI Codex](https://github.com/openai/codex)."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: autonomous-agents
description: "Autonomous agents are AI systems that can independently decompose goals, plan actions, execute tools, and self-correct without constant human guidance. The challenge isn't making them capable - it'..."
description: "You are an agent architect who has learned the hard lessons of autonomous AI. You've seen the gap between impressive demos and production disasters. You know that a 95% success rate per step means only 60% by step 10."
risk: unknown
source: "vibeship-spawner-skills (Apache 2.0)"
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: aws-penetration-testing
description: "This skill should be used when the user asks to \"pentest AWS\", \"test AWS security\", \"enumerate IAM\", \"exploit cloud infrastructure\", \"AWS privilege escalation\", \"S3 bucket testing..."
description: "Provide comprehensive techniques for penetration testing AWS cloud environments. Covers IAM enumeration, privilege escalation, SSRF to metadata endpoint, S3 bucket exploitation, Lambda code extraction, and persistence techniques for red team operations."
risk: unknown
source: community
author: zebbern

View File

@@ -1,6 +1,6 @@
---
name: aws-serverless
description: "Specialized skill for building production-ready serverless applications on AWS. Covers Lambda functions, API Gateway, DynamoDB, SQS/SNS event-driven patterns, SAM/CDK deployment, and cold start opt..."
description: "Proper Lambda function structure with error handling"
risk: unknown
source: "vibeship-spawner-skills (Apache 2.0)"
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: azd-deployment
description: "Deploy containerized applications to Azure Container Apps using Azure Developer CLI (azd). Use when setting up azd projects, writing azure.yaml configuration, creating Bicep infrastructure for Cont..."
description: "Deploy containerized frontend + backend applications to Azure Container Apps with remote builds, managed identity, and idempotent infrastructure."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: azure-ai-contentsafety-java
description: "Build content moderation applications with Azure AI Content Safety SDK for Java. Use when implementing text/image analysis, blocklist management, or harm detection for hate, violence, sexual conten..."
description: "Build content moderation applications using the Azure AI Content Safety SDK for Java."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: azure-ai-contentsafety-ts
description: "Analyze text and images for harmful content using Azure AI Content Safety (@azure-rest/ai-content-safety). Use when moderating user-generated content, detecting hate speech, violence, sexual conten..."
description: "Analyze text and images for harmful content with customizable blocklists."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: azure-ai-document-intelligence-ts
description: "Extract text, tables, and structured data from documents using Azure Document Intelligence (@azure-rest/ai-document-intelligence). Use when processing invoices, receipts, IDs, forms, or building cu..."
description: "Extract text, tables, and structured data from documents using prebuilt and custom models."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: azure-ai-formrecognizer-java
description: "Build document analysis applications with Azure Document Intelligence (Form Recognizer) SDK for Java. Use when extracting text, tables, key-value pairs from documents, receipts, invoices, or buildi..."
description: "Build document analysis applications using the Azure AI Document Intelligence SDK for Java."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: azure-ai-projects-py
description: "Build AI applications using the Azure AI Projects Python SDK (azure-ai-projects). Use when working with Foundry project clients, creating versioned agents with PromptAgentDefinition, running evalua..."
description: "Build AI applications on Microsoft Foundry using the azure-ai-projects SDK."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: azure-ai-projects-ts
description: "Build AI applications using Azure AI Projects SDK for JavaScript (@azure/ai-projects). Use when working with Foundry project clients, agents, connections, deployments, datasets, indexes, evaluation..."
description: "High-level SDK for Azure AI Foundry projects with agents, connections, deployments, and evaluations."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: azure-ai-translation-ts
description: "Build translation applications using Azure Translation SDKs for JavaScript (@azure-rest/ai-translation-text, @azure-rest/ai-translation-document). Use when implementing text translation, transliter..."
description: "Text and document translation with REST-style clients."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: azure-ai-voicelive-py
description: "Build real-time voice AI applications using Azure AI Voice Live SDK (azure-ai-voicelive). Use this skill when creating Python applications that need real-time bidirectional audio communication with..."
description: "Build real-time voice AI applications with bidirectional WebSocket communication."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: azure-appconfiguration-ts
description: "Build applications using Azure App Configuration SDK for JavaScript (@azure/app-configuration). Use when working with configuration settings, feature flags, Key Vault references, dynamic refresh, o..."
description: "Centralized configuration management with feature flags and dynamic refresh."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: azure-communication-callautomation-java
description: "Build call automation workflows with Azure Communication Services Call Automation Java SDK. Use when implementing IVR systems, call routing, call recording, DTMF recognition, text-to-speech, or AI-..."
description: "Build server-side call automation workflows including IVR systems, call routing, recording, and AI-powered interactions."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: azure-communication-callingserver-java
description: "Azure Communication Services CallingServer (legacy) Java SDK. Note - This SDK is deprecated. Use azure-communication-callautomation instead for new projects. Only use this skill when maintaining le..."
description: "⚠️ DEPRECATED: This SDK has been renamed to Call Automation. For new projects, use azure-communication-callautomation instead. This skill is for maintaining legacy code only."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: azure-communication-chat-java
description: "Build real-time chat applications with Azure Communication Services Chat Java SDK. Use when implementing chat threads, messaging, participants, read receipts, typing notifications, or real-time cha..."
description: "Build real-time chat applications with thread management, messaging, participants, and read receipts."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: azure-cosmos-db-py
description: "Build Azure Cosmos DB NoSQL services with Python/FastAPI following production-grade patterns. Use when implementing database client setup with dual auth (DefaultAzureCredential + emulator), service..."
description: "Build production-grade Azure Cosmos DB NoSQL services following clean code, security best practices, and TDD principles."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: azure-data-tables-java
description: "Build table storage applications with Azure Tables SDK for Java. Use when working with Azure Table Storage or Cosmos DB Table API for NoSQL key-value data, schemaless storage, or structured data at..."
description: "Build table storage applications using the Azure Tables SDK for Java. Works with both Azure Table Storage and Cosmos DB Table API."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: azure-eventhub-ts
description: "Build event streaming applications using Azure Event Hubs SDK for JavaScript (@azure/event-hubs). Use when implementing high-throughput event ingestion, real-time analytics, IoT telemetry, or event..."
description: "High-throughput event streaming and real-time data ingestion."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: azure-functions
description: "Expert patterns for Azure Functions development including isolated worker model, Durable Functions orchestration, cold start optimization, and production patterns. Covers .NET, Python, and Node.js ..."
description: "Modern .NET execution model with process isolation"
risk: unknown
source: "vibeship-spawner-skills (Apache 2.0)"
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: azure-identity-java
description: "Azure Identity Java SDK for authentication with Azure services. Use when implementing DefaultAzureCredential, managed identity, service principal, or any Azure authentication pattern in Java applic..."
description: "Authenticate Java applications with Azure services using Microsoft Entra ID (Azure AD)."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: azure-identity-ts
description: "Authenticate to Azure services using Azure Identity SDK for JavaScript (@azure/identity). Use when configuring authentication with DefaultAzureCredential, managed identity, service principals, or i..."
description: "Authenticate to Azure services with various credential types."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: azure-mgmt-mongodbatlas-dotnet
description: "Manage MongoDB Atlas Organizations as Azure ARM resources using Azure.ResourceManager.MongoDBAtlas SDK. Use when creating, updating, listing, or deleting MongoDB Atlas organizations through Azure M..."
description: "Manage MongoDB Atlas Organizations as Azure ARM resources with unified billing through Azure Marketplace."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: azure-microsoft-playwright-testing-ts
description: "Run Playwright tests at scale using Azure Playwright Workspaces (formerly Microsoft Playwright Testing). Use when scaling browser tests across cloud-hosted browsers, integrating with CI/CD pipeline..."
description: "Run Playwright tests at scale with cloud-hosted browsers and integrated Azure portal reporting."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -23,7 +23,6 @@ APPLICATIONINSIGHTS_CONNECTION_STRING=InstrumentationKey=xxx;IngestionEndpoint=h
```
## When to Use
| Scenario | Use |
|----------|-----|
| Quick setup, auto-instrumentation | `azure-monitor-opentelemetry` (distro) |

View File

@@ -1,6 +1,6 @@
---
name: azure-monitor-opentelemetry-ts
description: "Instrument applications with Azure Monitor and OpenTelemetry for JavaScript (@azure/monitor-opentelemetry). Use when adding distributed tracing, metrics, and logs to Node.js applications with Appli..."
description: "Auto-instrument Node.js applications with distributed tracing, metrics, and logs."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: azure-search-documents-ts
description: "Build search applications using Azure AI Search SDK for JavaScript (@azure/search-documents). Use when creating/managing indexes, implementing vector/hybrid search, semantic ranking, or building ag..."
description: "Build search applications with vector, hybrid, and semantic search capabilities."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: azure-servicebus-ts
description: "Build messaging applications using Azure Service Bus SDK for JavaScript (@azure/service-bus). Use when implementing queues, topics/subscriptions, message sessions, dead-letter handling, or enterpri..."
description: "Enterprise messaging with queues, topics, and subscriptions."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: azure-storage-blob-java
description: "Build blob storage applications with Azure Storage Blob SDK for Java. Use when uploading, downloading, or managing files in Azure Blob Storage, working with containers, or implementing streaming da..."
description: "Build blob storage applications using the Azure Storage Blob SDK for Java."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: azure-web-pubsub-ts
description: "Build real-time messaging applications using Azure Web PubSub SDKs for JavaScript (@azure/web-pubsub, @azure/web-pubsub-client). Use when implementing WebSocket-based real-time features, pub/sub me..."
description: "Real-time messaging with WebSocket connections and pub/sub patterns."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: backend-dev-guidelines
description: "Opinionated backend development standards for Node.js + Express + TypeScript microservices. Covers layered architecture, BaseController pattern, dependency injection, Prisma repositories, Zod valid..."
description: "(Node.js · Express · TypeScript · Microservices)"
risk: unknown
source: community
date_added: "2026-02-27"
@@ -57,8 +57,7 @@ BFRI = (Architectural Fit + Testability) (Complexity + Data Risk + Operation
---
## 2. When to Use This Skill
## When to Use
Automatically applies when working on:
* Routes, controllers, services, repositories

View File

@@ -1,6 +1,6 @@
---
name: backtesting-frameworks
description: "Build robust backtesting systems for trading strategies with proper handling of look-ahead bias, survivorship bias, and transaction costs. Use when developing trading algorithms, validating strateg..."
description: "Build robust, production-grade backtesting systems that avoid common pitfalls and produce reliable strategy performance estimates."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -20,7 +20,6 @@ Automate Basecamp operations including project management, to-do list creation,
**Get Rube MCP**: Add `https://rube.app/mcp` as an MCP server in your client configuration. No API keys needed — just add the endpoint and it works.
1. Verify Rube MCP is available by confirming `RUBE_SEARCH_TOOLS` responds
2. Call `RUBE_MANAGE_CONNECTIONS` with toolkit `basecamp`
3. If connection is not ACTIVE, follow the returned auth link to complete Basecamp OAuth

View File

@@ -7,8 +7,7 @@ description: This skill should be used when the user asks to "model agent mental
Transform external RDF context into agent mental states (beliefs, desires, intentions) using formal BDI ontology patterns. This skill enables agents to reason about context through cognitive architecture, supporting deliberative reasoning, explainability, and semantic interoperability within multi-agent systems.
## When to Activate
## When to Use
Activate this skill when:
- Processing external RDF context into agent beliefs about world states
- Modeling rational agency with perception, deliberation, and action cycles

View File

@@ -1,6 +1,6 @@
---
name: bill-gates
description: Agente que simula Bill Gates — cofundador da Microsoft, arquiteto da industria de software comercial, estrategista tecnologico global, investidor sistemico e filantropo baseado em dados. Use...
description: "Agente que simula Bill Gates — cofundador da Microsoft, arquiteto da industria de software comercial, estrategista tecnologico global, investidor sistemico e filantropo baseado em dados."
risk: safe
source: community
date_added: '2026-03-06'

View File

@@ -1,6 +1,6 @@
---
name: billing-automation
description: "Build automated billing systems for recurring payments, invoicing, subscription lifecycle, and dunning management. Use when implementing subscription billing, automating invoicing, or managing recu..."
description: "Master automated billing systems including recurring billing, invoice generation, dunning management, proration, and tax calculation."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: binary-analysis-patterns
description: "Master binary analysis patterns including disassembly, decompilation, control flow analysis, and code pattern recognition. Use when analyzing executables, understanding compiled code, or performing..."
description: "Comprehensive patterns and techniques for analyzing compiled binaries, understanding assembly code, and reconstructing program logic."
risk: unknown
source: community
date_added: "2026-02-27"

View File

@@ -1,6 +1,6 @@
---
name: biopython
description: Comprehensive molecular biology toolkit. Use for sequence manipulation, file parsing (FASTA/GenBank/PDB), phylogenetics, and programmatic NCBI/PubMed access (Bio.Entrez). Best for batch processing, custom bioinformatics pipelines, BLAST automation. For quick lookups use gget;...
description: "Biopython is a comprehensive set of freely available Python tools for biological computation. It provides functionality for sequence manipulation, file I/O, database access, structural bioinformatics, phylogenetics, and many other bioinformatics tasks."
license: Unknown
metadata:
skill-author: K-Dense Inc.

View File

@@ -20,7 +20,6 @@ Automate Bitbucket operations including repository management, pull request work
**Get Rube MCP**: Add `https://rube.app/mcp` as an MCP server in your client configuration. No API keys needed — just add the endpoint and it works.
1. Verify Rube MCP is available by confirming `RUBE_SEARCH_TOOLS` responds
2. Call `RUBE_MANAGE_CONNECTIONS` with toolkit `bitbucket`
3. If connection is not ACTIVE, follow the returned auth link to complete Bitbucket OAuth

View File

@@ -1,6 +1,6 @@
---
name: blockrun
description: "Use when user needs capabilities Claude lacks (image generation, real-time X/Twitter data) or explicitly requests external models (\\\"blockrun\\\", \\\"use grok\\\", \\\"use gpt\\\", \\\"da..."
description: "BlockRun works with Claude Code and Google Antigravity."
risk: unknown
source: community
date_added: "2026-02-27"
@@ -49,7 +49,6 @@ print(f"💰 Total spent: ${spending['total_usd']:.4f} across {spending['calls']
```
## When to Use
| Trigger | Your Action |
|---------|-------------|
| User explicitly requests ("blockrun second opinion with GPT on...", "use grok to check...", "generate image with dall-e") | Execute via BlockRun |

View File

@@ -1,6 +1,6 @@
---
name: blog-writing-guide
description: Write, review, and improve blog posts for the Sentry engineering blog following Sentry's specific writing standards, voice, and quality bar. Use this skill whenever someone asks to write a blog post, draft a technical article, review blog content, improve a draft, write a...
description: "This skill enforces Sentry's blog writing standards across every post — whether you're helping an engineer write their first blog post or a marketer draft a product announcement."
---
# Sentry Blog Writing Skill

View File

@@ -1,6 +1,6 @@
---
name: box-automation
description: "Automate Box cloud storage operations including file upload/download, search, folder management, sharing, collaborations, and metadata queries via Rube MCP (Composio). Always search tools first for..."
description: "Automate Box operations including file upload/download, content search, folder management, collaboration, metadata queries, and sign requests through Composio's Box toolkit."
risk: unknown
source: community
date_added: "2026-02-27"
@@ -20,7 +20,6 @@ Automate Box operations including file upload/download, content search, folder m
**Get Rube MCP**: Add `https://rube.app/mcp` as an MCP server in your client configuration. No API keys needed — just add the endpoint and it works.
1. Verify Rube MCP is available by confirming `RUBE_SEARCH_TOOLS` responds
2. Call `RUBE_MANAGE_CONNECTIONS` with toolkit `box`
3. If connection is not ACTIVE, follow the returned auth link to complete Box OAuth

Some files were not shown because too many files have changed in this diff Show More