1391 Commits

Author SHA1 Message Date
sickn33
4883b0dbb4 fix(security): Harden skill activation and loading flows
Harden batch activation, dev refresh gating, Microsoft sync path
handling, and Jetski skill loading against command injection,
symlink traversal, and client-side star tampering.

Add regression coverage for the security-sensitive paths and
update the internal triage addendum for the Jetski loader fix.
2026-03-18 18:49:15 +01:00
sickn33
55033462ff ci(codeql): Retrigger default setup analysis 2026-03-18 18:45:33 +01:00
sickn33
365bc590ff fix(codeql): Stop scanning C# template assets
Rename the dotnet backend example assets out of the C# source path so CodeQL no longer performs low-quality C# extraction on standalone template files with no project build context. Update the implementation playbook links to the new template filenames.
2026-03-18 18:36:27 +01:00
sickn33
955d35b8c6 fix(codeql): Rename invalid TSX template asset
Keep the Radix component boilerplate as a template asset, but rename it out of the TSX parser path so CodeQL does not treat placeholder syntax as executable source. Update the example README link to the new template filename.
2026-03-18 18:30:51 +01:00
sickn33
051cb3e189 docs: Clarify code of conduct reporting (#351)
Co-authored-by: sickn33 <sickn33@users.noreply.github.com>
2026-03-18 18:25:01 +01:00
sickn33
c2fcfb4ec0 docs: Add code of conduct (#350)
Co-authored-by: sickn33 <sickn33@users.noreply.github.com>
2026-03-18 18:22:02 +01:00
sickn33
344854e9e5 fix(security): Address remaining scanning alerts
Tighten the remaining high-signal security findings by switching the todo example to a standard Express rate limiter, removing sensitive metadata from boilerplate logging, and replacing fragile HTML tag filtering with parser-based conversion.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-03-18 18:15:49 +01:00
github-actions[bot]
6114c38cda chore: sync generated registry files [ci skip] 2026-03-18 17:08:53 +00:00
sickn33
3b6ef3add8 fix(security): Remediate scanning and dependency alerts
Harden template and example code paths, redact sensitive output, and pin safe transitive npm packages. Consolidate the todo backend on better-sqlite3 so the example no longer pulls the vulnerable sqlite3 chain and still passes build and CRUD smoke checks.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-03-18 18:05:45 +01:00
sickn33
d2c593e719 feat(community): add discussion templates and routing (#349)
Co-authored-by: sickn33 <sickn33@users.noreply.github.com>
2026-03-18 17:30:40 +01:00
sickn33
c003127367 docs(release): Note PR 341 for next cut
Record that the merged landing-page-generator skill from PR #341
must be included in the next release because v8.2.0 was already
published before the PR landed.
2026-03-18 13:06:38 +01:00
github-actions[bot]
80dbbcc4e3 chore: sync generated registry files [ci skip] 2026-03-18 12:04:32 +00:00
Mohamed Halith
61c054adaa feat: add landing-page-generator skill for high-converting web pages (#341)
* feat: add landing-page-generator skill for high-converting web pages

* fix: restore missing sections and fix corruption in SKILL.md
2026-03-18 13:04:07 +01:00
sickn33
dc31e86d5e docs(release): Record 8.2.0 publication
Update the maintainer and user walkthroughs so they reflect the
completed 8.2.0 release publication instead of the pre-release ready
state.

Capture the final PR merge set, issue closure state, and the exact
release commands that were executed on main.
2026-03-18 12:58:39 +01:00
sickn33
6d7d98d5d2 chore: release v8.2.0 2026-03-18 12:57:58 +01:00
sickn33
afab2e262f meta(release): Sync preflight metadata
Accept the deterministic metadata updates produced by the release
preflight so the tracked tree matches the current package version and
skill count before the automated 8.2.0 release commit runs.

This keeps the README registry sync comment aligned with the current
package state while preserving the manual 8.2.0 release messaging.
2026-03-18 12:57:02 +01:00
sickn33
cceefcce0f docs(release): Prepare 8.2.0 documentation
Add the 8.2.0 changelog entry and align the release-facing user docs
with the current maintenance sweep so the release workflow has the
required notes and public version references in place.

Refresh README release messaging and contributor acknowledgements ahead
of the automated release commit and tag creation.
2026-03-18 12:56:27 +01:00
sickn33
d2ad123c81 fix(plugin): Correct Claude marketplace source path
Update the Claude marketplace entry to use a schema-valid relative source path and add a regression test so invalid marketplace sources fail in the local suite. Also document the maintainer workflow used for stale PR metadata and fork-gated Actions runs.

Fixes #344
2026-03-18 12:48:45 +01:00
Wolfe-James
2f8a52e26c Update README with new project links (#345)
## Add faf-skills to Community Contributors
                                                                                 
  17 Claude Code skills for AI-context management, built on the IANA-registered  
  .faf format (`application/vnd.faf+yaml`).                                      
                                                                                 
  **Skills include:** project DNA creation, AI-readiness scoring (0-100%),       
  bi-sync with CLAUDE.md/AGENTS.md, MCP server building, and championship-grade
  testing.                                                                       
                                                            
  - **Repo:** https://github.com/Wolfe-Jam/faf-skills
  - **License:** MIT
  - **Skills:** 17
2026-03-18 12:44:41 +01:00
github-actions[bot]
1bcb135b45 chore: sync generated registry files [ci skip] 2026-03-18 11:40:28 +00:00
Jayen
19e42bb67a feat: add goldrush-api skill for blockchain data across 100+ chains (#334) 2026-03-18 12:40:00 +01:00
Da Wei
61ba6d689f feat: add openclaw-github-repo-commander for GitHub repo audit and cleanup (#340) 2026-03-18 12:39:44 +01:00
Champbreed
fdd496da08 docs: add missing metadata labels to devcontainer-setup skill (#343)
* fix: resolve OOM crash by balancing markdown syntax (#339)

Corrected unbalanced backticks in browser-extension-builder/SKILL.md
(19 -> 18) to prevent infinite loops during indexing.

Signed-off-by: Simon Essien <champbreed1@gmail.com>

* Update SKILL.md

---------

Signed-off-by: Simon Essien <champbreed1@gmail.com>
2026-03-18 12:39:27 +01:00
github-actions[bot]
eade42da9a chore: sync generated registry files [ci skip] 2026-03-18 11:33:12 +00:00
Suhaib Janjua
ae306ce015 feat: add sveltekit, astro, hono, and pydantic-ai skills (#336) 2026-03-18 12:32:48 +01:00
Suhaib Janjua
1336e8d455 fix(skills): remove malformed nested code fences in browser-extension-builder (#338) 2026-03-18 12:32:20 +01:00
Suhaib Janjua
e2879ab560 docs: fix missing required frontmatter fields in skill-anatomy and ad… (#333)
* docs: fix missing required frontmatter fields in skill-anatomy and add missing tools to FAQ

* ci: retrigger checks after PR body update
2026-03-18 12:32:03 +01:00
github-actions[bot]
33cd7bbda5 chore: update star history chart 2026-03-18 06:25:40 +00:00
sickn33
5cccc7a7ba chore: release v8.1.0 2026-03-17 12:32:54 +01:00
sickn33
428432a789 docs: sync walkthrough for release 8.1.0 2026-03-17 12:32:20 +01:00
sickn33
e8a0250687 chore: sync package metadata 2026-03-17 12:32:05 +01:00
sickn33
99e1ad1be7 docs: prepare release 8.1.0 2026-03-17 12:30:23 +01:00
github-actions[bot]
a9d77c9d42 chore: sync generated registry files [ci skip] 2026-03-17 11:23:28 +00:00
Suhaib Janjua
d45edcb674 feat: add trpc-fullstack skill for end-to-end type-safe API development (#329)
* feat: add trpc-fullstack skill for end-to-end type-safe API development

* fix: separate App Router and server-side context factories per review feedback

- Replace createContext({ req } as any) in App Router handler with
  createTRPCContext(opts: FetchCreateContextFnOptions) — the correct fetch adapter shape
- Add createServerContext() for Server Component callers so auth() is called
  directly without an empty or synthetic request object cast
- Update SSR example to use createServerContext() instead of createContext({} as any)
- Add two new pitfall entries covering both auth failure scenarios
2026-03-17 12:23:03 +01:00
github-actions[bot]
a170f94aae chore: sync generated registry files [ci skip] 2026-03-17 11:22:52 +00:00
marsiandeployer
2f39fc3851 feat: add vibers-code-review for human review of AI-generated code (#325)
* feat: add vibers-code-review for human review of AI-generated code

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: add valid metadata to vibers-code-review skill

---------

Co-authored-by: buildbot <bot@swaponline.io>
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: sickn33 <sickn33@users.noreply.github.com>
2026-03-17 12:22:23 +01:00
github-actions[bot]
7561a602c6 chore: sync generated registry files [ci skip] 2026-03-17 11:20:45 +00:00
Jaskirat Anand
85990937bd feat: add progressive-web-app skill (#324)
* feat: add progressive-web-app skill

* fix: addressed Codex Review fixes
2026-03-17 12:20:21 +01:00
github-actions[bot]
f72f03f7cb chore: sync generated registry files [ci skip] 2026-03-17 11:20:10 +00:00
benz1
0575998307 fix(skills): Repair invalid YAML frontmatter (#326)
Replace malformed frontmatter lines that start with an extra YAML document separator with proper metadata fields. This keeps the skill metadata parseable by strict loaders that only accept a single YAML document in SKILL.md frontmatter.

Co-authored-by: Claude <noreply@anthropic.com>
2026-03-17 12:19:42 +01:00
Suhaib Janjua
3a3fb6cbe2 docs: align FAQ risk labels with frontmatter values and add skill-review guidance (#330) 2026-03-17 12:19:08 +01:00
Suhaib Janjua
03a28b06d7 fix: remove broken reference to missing implementation-playbook.md (#331)
The data-scientist SKILL.md referenced resources/implementation-playbook.md which does not exist in the repository, causing a dead link.

Fixes #327
2026-03-17 12:18:30 +01:00
sickn33
883c81609a Update README for release version 8.0.0 2026-03-16 16:14:40 +01:00
sck_0
ad296a3527 docs: document skill-review workflow 2026-03-16 16:12:51 +01:00
sck_0
9511ab07e2 chore: release v8.0.0 2026-03-16 16:03:26 +01:00
sck_0
965d16353e docs: prepare 8.0.0 release notes and contributors 2026-03-16 16:03:05 +01:00
sck_0
4cebc8672f docs: record maintenance merge batch 2026-03-16 15:57:48 +01:00
github-actions[bot]
e76fbb6405 chore: sync generated registry files [ci skip] 2026-03-16 14:57:23 +00:00
Bap
469c9f45af improve comprehensive-review-pr-enhance skill structure + add skill-review CI (#322)
* improve comprehensive-review-pr-enhance skill structure + add skill-review CI

- rewrite description with concrete capabilities + trigger terms
- replace vague instructions with numbered workflow + PR description template
- add conditional review checklist rules table and large-PR splitting guidance
- add .github/workflows/skill-review.yml for automated skill review on PRs

* chore: refresh branch for ci

---------

Co-authored-by: sck_0 <samujackson1337@gmail.com>
2026-03-16 15:56:59 +01:00
Gizzant
1a5c4059bd Update SKILL.md to final version (#305)
* Update SKILL.md to final version

* fix: restore analyze-project frontmatter

---------

Co-authored-by: sck_0 <samujackson1337@gmail.com>
2026-03-16 15:56:50 +01:00