Commit Graph

27 Commits

Author SHA1 Message Date
Reza Rezvani
3622efedc0 fix: add YAML frontmatter (name + description) to all SKILL.md files
- Added frontmatter to 34 skills that were missing it entirely (0% Tessl score)
- Fixed name field format to kebab-case across all 169 skills
- Resolves #284
2026-03-06 20:35:35 +01:00
Alireza Rezvani
20c4fe823c fix: enhance 5 skills with scripts, references, and Anthropic best practices (#248)
* fix(skill): enhance git-worktree-manager with scripts, references, and Anthropic best practices

* fix(skill): enhance mcp-server-builder with scripts, references, and Anthropic best practices

* fix(skill): enhance changelog-generator with scripts, references, and Anthropic best practices

* fix(skill): enhance ci-cd-pipeline-builder with scripts, references, and Anthropic best practices

* fix(skill): enhance prompt-engineer-toolkit with scripts, references, and Anthropic best practices

* docs: update README, CHANGELOG, and plugin metadata

* fix: correct marketing plugin count, expand thin references

---------

Co-authored-by: Leo <leo@openclaw.ai>
2026-03-04 08:25:54 +01:00
Alireza Rezvani
b87662ecdf feat: add skill-security-auditor POWERFUL-tier skill (#230)
Security audit and vulnerability scanner for AI agent skills before installation.

Scans for:
- Code execution risks (eval, exec, os.system, subprocess shell injection)
- Data exfiltration (outbound HTTP, credential harvesting, env var extraction)
- Prompt injection in SKILL.md (system override, role hijack, safety bypass)
- Dependency supply chain (typosquatting, unpinned versions, runtime installs)
- File system abuse (boundary violations, binaries, symlinks, hidden files)
- Privilege escalation (sudo, SUID, cron manipulation, shell config writes)
- Obfuscation (base64, hex encoding, chr chains, codecs)

Produces clear PASS/WARN/FAIL verdict with per-finding remediation guidance.
Supports local dirs, git repo URLs, JSON output, strict mode, and CI/CD integration.

Includes:
- scripts/skill_security_auditor.py (1049 lines, zero dependencies)
- references/threat-model.md (complete attack vector documentation)
- SKILL.md with usage guide and report format

Tested against: rag-architect (PASS), agent-designer (PASS), senior-secops (FAIL - correctly flagged eval/exec patterns).

Co-authored-by: Leo <leo@openclaw.ai>
2026-03-04 02:59:45 +01:00
Gábor Lipták
5f63d23836 Refactor timestamp handling in skill_validator.py (#223)
fix: replace deprecated datetime.utcnow() with timezone-aware alternative
2026-03-03 18:01:28 +01:00
Alireza Rezvani
40df8ff9d6 feat: add 20 new practical skills (65→86 total)
20 production-ready skills for professional Claude Code users.

Engineering (12): git-worktree-manager, ci-cd-pipeline-builder, mcp-server-builder, changelog-generator, pr-review-expert, api-test-suite-builder, env-secrets-manager, database-schema-designer, codebase-onboarding, performance-profiler, runbook-generator, monorepo-navigator

Engineering Team (2): stripe-integration-expert, email-template-builder
Product (3): saas-scaffolder, landing-page-generator, competitive-teardown  
Business (1): contract-and-proposal-writer
Marketing (1): prompt-engineer-toolkit
AI Engineering (1): agent-workflow-designer

Also: README updated (badges, counts, new section), STORE.md (Stan Store + Gumroad distribution plan)
2026-03-02 04:47:47 +01:00
Leo
84ff0a23f0 feat: add Claude Code plugin manifest for engineering/ skills 2026-02-16 17:27:40 +00:00
Alireza Rezvani
d6895ddbf7 Merge pull request #210 from alirezarezvani/feature/skill-tester
feat: add skill-tester meta-skill
2026-02-16 18:17:42 +01:00
Alireza Rezvani
8d900b6194 Merge pull request #209 from alirezarezvani/feature/agent-designer
feat: add agent-designer skill
2026-02-16 18:17:39 +01:00
Alireza Rezvani
46abdc959b Merge pull request #208 from alirezarezvani/feature/rag-architect
feat: add rag-architect skill
2026-02-16 18:17:37 +01:00
Alireza Rezvani
98ccc3c8b9 Merge pull request #207 from alirezarezvani/feature/database-designer
feat: add database-designer skill
2026-02-16 18:17:35 +01:00
Alireza Rezvani
73c97d701f Merge pull request #206 from alirezarezvani/feature/release-manager
feat: add release-manager skill
2026-02-16 18:17:33 +01:00
Leo
d63685401d feat: add skill-tester POWERFUL-tier skill
- Comprehensive skill validation, testing, and quality scoring framework
- skill_validator.py: validates structure, documentation, and compliance (700+ LOC)
- script_tester.py: tests syntax, functionality, and runtime behavior (800+ LOC)
- quality_scorer.py: multi-dimensional quality assessment with scoring (1100+ LOC)
- Complete reference documentation (structure spec, tier requirements, scoring rubric)
- Sample skill with assets and expected outputs for testing
- CI/CD integration examples and pre-commit hook support
- Zero external dependencies, dual output formats (JSON + human-readable)
- Self-testing capable meta-skill for quality assurance automation
2026-02-16 16:53:49 +00:00
Leo
397b489a94 feat: add agent-designer POWERFUL-tier skill 2026-02-16 16:40:27 +00:00
Leo
effb867982 feat: add rag-architect POWERFUL-tier skill
- chunking_optimizer.py: analyzes document corpus, recommends chunking strategies
- retrieval_evaluator.py: evaluates retrieval quality with built-in TF-IDF baseline
- rag_pipeline_designer.py: designs end-to-end RAG pipelines with Mermaid diagrams
- References, sample corpus, expected outputs included
- Zero external dependencies
2026-02-16 16:22:44 +00:00
Leo
dd07924f41 feat: add database-designer POWERFUL-tier skill 2026-02-16 16:11:29 +00:00
Leo
d6f2f1df78 feat: add release-manager POWERFUL-tier skill
Complete release management toolkit including:
- changelog_generator.py: Parse conventional commits and generate structured changelogs
- version_bumper.py: Determine semantic version bumps from commit analysis
- release_planner.py: Assess release readiness and generate coordination plans
- Comprehensive documentation covering SemVer, Git workflows, hotfix procedures
- Sample data and expected outputs for testing
- Zero external dependencies, Python standard library only

Enables automated changelog generation, version management, and release coordination
from git history using conventional commits specification.
2026-02-16 15:56:03 +00:00
Leo
4dc5ef5f19 feat: add dependency-auditor POWERFUL-tier skill 2026-02-16 15:42:19 +00:00
Alireza Rezvani
efb79e195b Merge pull request #202 from alirezarezvani/feature/observability-designer
feat: add observability-designer skill
2026-02-16 15:58:05 +01:00
Leo
52732f7e2b feat: add observability-designer POWERFUL-tier skill
- SLO Designer: generates comprehensive SLI/SLO frameworks with error budgets and burn rate alerts
- Alert Optimizer: analyzes and optimizes alert configurations to reduce noise and improve effectiveness
- Dashboard Generator: creates role-based dashboard specifications with golden signals coverage

Includes comprehensive documentation, sample data, and expected outputs for testing.
2026-02-16 14:03:12 +00:00
Alireza Rezvani
031730b814 Merge pull request #200 from alirezarezvani/feature/migration-architect
feat: add migration-architect skill
2026-02-16 14:53:27 +01:00
Alireza Rezvani
9544882b6f Merge pull request #199 from alirezarezvani/feature/interview-system-designer
feat: add interview-system-designer skill
2026-02-16 14:49:54 +01:00
Leo
e6cc0f4c6a feat: add migration-architect POWERFUL-tier skill 2026-02-16 13:48:47 +00:00
Leo
6707dd18c2 feat: add interview-system-designer skill
- Comprehensive interview system design toolkit
- Interview Loop Designer: generates calibrated loops for any role/level
- Question Bank Generator: creates competency-based questions with rubrics
- Hiring Calibrator: analyzes interview data for bias and calibration issues
- Complete reference materials: competency matrices, bias mitigation, debrief guides
- Sample data and expected outputs for testing
- Supports all major roles: SWE, PM, Designer, Data, DevOps, Leadership
- Zero external dependencies, Python standard library only
- Dual output: JSON + human-readable text formats
2026-02-16 13:30:58 +00:00
Leo
612f2a63fc merge: resolve conflict with dev, keep POWERFUL-tier SKILL.md
Kept our SKILL.md (POWERFUL-tier, 669 lines) over the codex-synced version.
Accepted all new files from dev (additional scripts, references, assets).
2026-02-16 13:13:28 +00:00
Alireza Rezvani
538582fa16 Merge pull request #196 from alirezarezvani/feature/tech-debt-tracker
feat: Add tech-debt-tracker POWERFUL-tier skill
2026-02-16 14:10:18 +01:00
Leo
b374a74290 feat: add api-design-reviewer POWERFUL-tier skill
- SKILL.md with REST conventions, OpenAPI validation, versioning strategies
- api_linter.py: OpenAPI/endpoint lint with naming, method, error format checks
- breaking_change_detector.py: compare API versions, detect breaking changes
- api_scorecard.py: grade API design (A-F) across 5 dimensions
- References, sample data, expected outputs included
- Zero external dependencies, Python stdlib only
2026-02-16 13:06:10 +00:00
Leo
91af2a883a feat: Add tech-debt-tracker POWERFUL-tier skill
Complete technical debt management system with three interconnected tools:

• debt_scanner.py - AST-based Python analysis + regex patterns for multi-language debt detection
• debt_prioritizer.py - Multiple prioritization frameworks (CoD, WSJF, RICE) with sprint planning
• debt_dashboard.py - Historical trend analysis, health scoring, and executive reporting

Features:
- 15+ debt types detected (complexity, duplicates, security, architecture, etc.)
- Business impact analysis with ROI calculations
- Health scoring (0-100) with trend forecasting
- Executive and engineering stakeholder reports
- Zero external dependencies, stdlib only
- Comprehensive documentation and sample data

Addresses: tech debt identification, prioritization, tracking, and stakeholder communication
2026-02-16 13:00:55 +00:00