Coding & Development

yaklang/network-protocol-attacks

github.com

Network protocol attack playbook. Use when exploiting layer 2/3 protocols including ARP spoofing, LLMNR/NBT-NS/mDNS poisoning, WPAD abuse, DHCPv6 attacks, VLAN hopping, STP manipulation, DNS spoofing, IPv6 attacks, and IDS/IPS evasion.

$ npx skills add yaklang/hack-skills
Skill anzeigen→

nomadamas/foresttrip-vacancy

★ 6.3kgithub.com

Look up available Korean national forest recreation lodging or camping slots on foresttrip.go.kr. Use when the user asks for 숲나들e or 자연휴양림 빈 객실/빈자리 조회, not for booking.

$ npx skills add nomadamas/k-skill
Skill anzeigen→

yaklang/smart-contract-vulnerabilities

github.com

Smart contract vulnerability playbook. Use when auditing Solidity/EVM contracts for reentrancy, integer overflow, access control, delegatecall, flash loan, signature replay, and MEV-related attack patterns.

$ npx skills add yaklang/hack-skills
Skill anzeigen→

yaklang/xslt-injection

github.com

XSLT injection testing: processor fingerprinting, XXE and document() SSRF, EXSLT write primitives, PHP/Java/.NET extension RCE surfaces. Use when user-controlled XSLT/stylesheet input or transform endpoints are in scope.

$ npx skills add yaklang/hack-skills
Skill anzeigen→

yaklang/nosql-injection

github.com

NoSQL injection playbook. Use when MongoDB-style operators, JSON query objects, flexible search filters, or backend query DSLs may allow data or logic abuse.

$ npx skills add yaklang/hack-skills
Skill anzeigen→

phuryn/identify-assumptions-existing

★ 23.9kgithub.com

Identify risky assumptions for a feature idea in an existing product across Value, Usability, Viability, and Feasibility. Uses multi-perspective devil's advocate thinking. Use when stress-testing a feature idea, doing risk assessment, or preparing for assumption mapping.

$ npx skills add phuryn/pm-skills
Skill anzeigen→

yaklang/tunneling-and-pivoting

github.com

Tunneling and pivoting playbook. Use when establishing network tunnels through compromised hosts including SSH tunneling, Chisel, Ligolo-ng, socat, DNS/ICMP/HTTP tunneling, ProxyChains, and multi-layer pivoting strategies.

$ npx skills add yaklang/hack-skills
Skill anzeigen→

flutter/flutter-platform-views

★ 2.7kgithub.com

Add a native view into your Flutter app

$ npx skills add flutter/skills
Skill anzeigen→

yaklang/upload-insecure-files

github.com

Insecure file upload playbook. Use when testing upload validation, storage paths, processing pipelines, preview behavior, overwrite risks, and upload-to-RCE chains.

$ npx skills add yaklang/hack-skills
Skill anzeigen→

yaklang/kubernetes-pentesting

github.com

Kubernetes penetration testing playbook. Use when targeting Kubernetes clusters via API server, RBAC enumeration, service account abuse, etcd access, Kubelet API, pod escape, cloud-specific metadata, admission webhook bypass, and registry secrets.

$ npx skills add yaklang/hack-skills
Skill anzeigen→

yaklang/windows-av-evasion

github.com

AV/EDR evasion playbook for Windows. Use when bypassing AMSI, ETW, .NET assembly detection, shellcode execution, process injection, API hooking, and signature-based detection on Windows endpoints.

$ npx skills add yaklang/hack-skills
Skill anzeigen→

tradermonty/backtest-expert

github.com

Expert guidance for systematic backtesting of trading strategies. Use when developing, testing, stress-testing, or validating quantitative trading strategies. Covers "beating ideas to death" methodology, parameter robustness testing, slippage modeling, bias prevention, and interpreting backtest results. Applicable when user asks about backtesting, strategy validation, robustness testing, avoiding overfitting, or systematic trading development.

$ npx skills add tradermonty/claude-trading-skills
Skill anzeigen→

rudrankriyam/asc-xcode-build

github.com

Build, archive, export, upload, and manage Xcode version/build numbers with the current asc xcode helpers before App Store Connect upload or submission. Use when creating an IPA or PKG for upload.

$ npx skills add rudrankriyam/asc-skills
Skill anzeigen→

phuryn/wwas

★ 23.9kgithub.com

Create product backlog items in Why-What-Acceptance format — independent, valuable, testable items with strategic context. Use when writing structured backlog items, breaking features into work items, or using the WWA format.

$ npx skills add phuryn/pm-skills
Skill anzeigen→

giuseppe-trisciuoglio/nestjs-code-review

★ 306github.com

Provides comprehensive code review capability for NestJS applications, analyzing controllers, services, modules, guards, interceptors, pipes, dependency injection, and database integration patterns. Use when reviewing NestJS code changes, before merging pull requests, after implementing new features, or for architecture validation. Triggers on "review NestJS code", "NestJS code review", "check my NestJS controller/service".

$ npx skills add giuseppe-trisciuoglio/developer-kit
Skill anzeigen→

mcollina/documentation

★ 1.9kgithub.com

Creates, structures, and reviews technical documentation following the Diátaxis framework (tutorials, how-to guides, reference, and explanation pages). Use when a user needs to write or reorganize docs, structure a tutorial vs. a how-to guide, build reference docs or API documentation, create explanation pages, choose between Diátaxis documentation types, or improve existing documentation structure. Trigger terms include: documentation structure, Diátaxis, tutorials vs how-to guides, organize docs, user guide, reference docs, technical writing.

$ npx skills add mcollina/skills
Skill anzeigen→

giuseppe-trisciuoglio/better-auth

★ 306github.com

Provides Better Auth integration patterns for NestJS backend and Next.js frontend with Drizzle ORM and PostgreSQL. Use when setting up Better Auth with NestJS backend, integrating Next.js App Router frontend, configuring Drizzle ORM schema, implementing social login (GitHub, Google), adding plugins (2FA, Organization, SSO, Magic Link, Passkey), implementing email/password authentication with session management, or creating protected routes and middleware.

$ npx skills add giuseppe-trisciuoglio/developer-kit
Skill anzeigen→

rudrankriyam/asc-signing-setup

github.com

Set up bundle IDs, capabilities, signing certificates, provisioning profiles, and encrypted signing sync with the asc cli. Use when onboarding a new app, rotating signing assets, or sharing them across a team.

$ npx skills add rudrankriyam/asc-skills
Skill anzeigen→

qianwen-ai/qianwen-model-selector

github.com

[QianWen] Recommend the best Qwen model and parameters. TRIGGER when: choosing between Qwen models, comparing Qwen model pricing, understanding Qwen model capabilities, checking usage or billing, viewing cost history, when an execution skill needs model selection advice, or user explicitly invokes this skill by name (e.g. use qianwen-model-selector). DO NOT TRIGGER when: non-Qwen model discussions (OpenAI, Gemini, etc.), general AI questions unrelated to Qwen.

$ npx skills add qianwen-ai/qianwen-ai
Skill anzeigen→

yaklang/vm-and-bytecode-reverse

github.com

Custom VM and bytecode reverse engineering playbook. Use when CTF challenges or protected software implement custom virtual machines with proprietary bytecode, dispatcher loops, or maze-style challenges.

$ npx skills add yaklang/hack-skills
Skill anzeigen→

flutter/flutter-plugins

★ 2.7kgithub.com

Build a Flutter plugin that provides native interop for other Flutter apps to use

$ npx skills add flutter/skills
Skill anzeigen→

yaklang/anti-debugging-techniques

github.com

Anti-debugging detection and bypass playbook. Use when reversing protected binaries that detect debuggers via ptrace, PEB flags, timing checks, or signal/exception handlers on Linux and Windows.

$ npx skills add yaklang/hack-skills
Skill anzeigen→

yaklang/saml-sso-assertion-attacks

github.com

SAML SSO assertion attack playbook. Use when testing signature validation, assertion wrapping, audience restrictions, ACS handling, XML trust boundaries, and enterprise SSO flaws.

$ npx skills add yaklang/hack-skills
Skill anzeigen→

yaklang/hash-attack-techniques

github.com

Hash attack playbook. Use when exploiting length extension, MD5/SHA1 collisions, HMAC timing leaks, birthday attacks, or hash-based proof of work in CTF and authorized testing scenarios.

$ npx skills add yaklang/hack-skills
Skill anzeigen→