Coding & Development

yaklang/smart-contract-vulnerabilities

github.com

Smart contract vulnerability playbook. Use when auditing Solidity/EVM contracts for reentrancy, integer overflow, access control, delegatecall, flash loan, signature replay, and MEV-related attack patterns.

$ npx skills add yaklang/hack-skills
Ver habilidad

phuryn/beachhead-segment

23.9kgithub.com

Identify the first beachhead market segment for a product launch. Evaluates segments against burning pain, willingness to pay, winnable market share, and referral potential. Use when choosing a first market, targeting an initial customer segment, or planning market entry strategy.

$ npx skills add phuryn/pm-skills
Ver habilidad

yaklang/xslt-injection

github.com

XSLT injection testing: processor fingerprinting, XXE and document() SSRF, EXSLT write primitives, PHP/Java/.NET extension RCE surfaces. Use when user-controlled XSLT/stylesheet input or transform endpoints are in scope.

$ npx skills add yaklang/hack-skills
Ver habilidad

yaklang/nosql-injection

github.com

NoSQL injection playbook. Use when MongoDB-style operators, JSON query objects, flexible search filters, or backend query DSLs may allow data or logic abuse.

$ npx skills add yaklang/hack-skills
Ver habilidad

phuryn/identify-assumptions-existing

23.9kgithub.com

Identify risky assumptions for a feature idea in an existing product across Value, Usability, Viability, and Feasibility. Uses multi-perspective devil's advocate thinking. Use when stress-testing a feature idea, doing risk assessment, or preparing for assumption mapping.

$ npx skills add phuryn/pm-skills
Ver habilidad

yaklang/tunneling-and-pivoting

github.com

Tunneling and pivoting playbook. Use when establishing network tunnels through compromised hosts including SSH tunneling, Chisel, Ligolo-ng, socat, DNS/ICMP/HTTP tunneling, ProxyChains, and multi-layer pivoting strategies.

$ npx skills add yaklang/hack-skills
Ver habilidad

flutter/flutter-platform-views

2.7kgithub.com

Add a native view into your Flutter app

$ npx skills add flutter/skills
Ver habilidad

yaklang/upload-insecure-files

github.com

Insecure file upload playbook. Use when testing upload validation, storage paths, processing pipelines, preview behavior, overwrite risks, and upload-to-RCE chains.

$ npx skills add yaklang/hack-skills
Ver habilidad

yaklang/kubernetes-pentesting

github.com

Kubernetes penetration testing playbook. Use when targeting Kubernetes clusters via API server, RBAC enumeration, service account abuse, etcd access, Kubelet API, pod escape, cloud-specific metadata, admission webhook bypass, and registry secrets.

$ npx skills add yaklang/hack-skills
Ver habilidad

yaklang/windows-av-evasion

github.com

AV/EDR evasion playbook for Windows. Use when bypassing AMSI, ETW, .NET assembly detection, shellcode execution, process injection, API hooking, and signature-based detection on Windows endpoints.

$ npx skills add yaklang/hack-skills
Ver habilidad

tradermonty/backtest-expert

github.com

Expert guidance for systematic backtesting of trading strategies. Use when developing, testing, stress-testing, or validating quantitative trading strategies. Covers "beating ideas to death" methodology, parameter robustness testing, slippage modeling, bias prevention, and interpreting backtest results. Applicable when user asks about backtesting, strategy validation, robustness testing, avoiding overfitting, or systematic trading development.

$ npx skills add tradermonty/claude-trading-skills
Ver habilidad

rudrankriyam/asc-xcode-build

github.com

Build, archive, export, upload, and manage Xcode version/build numbers with the current asc xcode helpers before App Store Connect upload or submission. Use when creating an IPA or PKG for upload.

$ npx skills add rudrankriyam/asc-skills
Ver habilidad

phuryn/wwas

23.9kgithub.com

Create product backlog items in Why-What-Acceptance format — independent, valuable, testable items with strategic context. Use when writing structured backlog items, breaking features into work items, or using the WWA format.

$ npx skills add phuryn/pm-skills
Ver habilidad

giuseppe-trisciuoglio/nestjs-code-review

306github.com

Provides comprehensive code review capability for NestJS applications, analyzing controllers, services, modules, guards, interceptors, pipes, dependency injection, and database integration patterns. Use when reviewing NestJS code changes, before merging pull requests, after implementing new features, or for architecture validation. Triggers on "review NestJS code", "NestJS code review", "check my NestJS controller/service".

$ npx skills add giuseppe-trisciuoglio/developer-kit
Ver habilidad

mcollina/documentation

1.9kgithub.com

Creates, structures, and reviews technical documentation following the Diátaxis framework (tutorials, how-to guides, reference, and explanation pages). Use when a user needs to write or reorganize docs, structure a tutorial vs. a how-to guide, build reference docs or API documentation, create explanation pages, choose between Diátaxis documentation types, or improve existing documentation structure. Trigger terms include: documentation structure, Diátaxis, tutorials vs how-to guides, organize docs, user guide, reference docs, technical writing.

$ npx skills add mcollina/skills
Ver habilidad

giuseppe-trisciuoglio/better-auth

306github.com

Provides Better Auth integration patterns for NestJS backend and Next.js frontend with Drizzle ORM and PostgreSQL. Use when setting up Better Auth with NestJS backend, integrating Next.js App Router frontend, configuring Drizzle ORM schema, implementing social login (GitHub, Google), adding plugins (2FA, Organization, SSO, Magic Link, Passkey), implementing email/password authentication with session management, or creating protected routes and middleware.

$ npx skills add giuseppe-trisciuoglio/developer-kit
Ver habilidad

rudrankriyam/asc-signing-setup

github.com

Set up bundle IDs, capabilities, signing certificates, provisioning profiles, and encrypted signing sync with the asc cli. Use when onboarding a new app, rotating signing assets, or sharing them across a team.

$ npx skills add rudrankriyam/asc-skills
Ver habilidad

qianwen-ai/qianwen-model-selector

github.com

[QianWen] Recommend the best Qwen model and parameters. TRIGGER when: choosing between Qwen models, comparing Qwen model pricing, understanding Qwen model capabilities, checking usage or billing, viewing cost history, when an execution skill needs model selection advice, or user explicitly invokes this skill by name (e.g. use qianwen-model-selector). DO NOT TRIGGER when: non-Qwen model discussions (OpenAI, Gemini, etc.), general AI questions unrelated to Qwen.

$ npx skills add qianwen-ai/qianwen-ai
Ver habilidad

yaklang/vm-and-bytecode-reverse

github.com

Custom VM and bytecode reverse engineering playbook. Use when CTF challenges or protected software implement custom virtual machines with proprietary bytecode, dispatcher loops, or maze-style challenges.

$ npx skills add yaklang/hack-skills
Ver habilidad

flutter/flutter-plugins

2.7kgithub.com

Build a Flutter plugin that provides native interop for other Flutter apps to use

$ npx skills add flutter/skills
Ver habilidad

yaklang/anti-debugging-techniques

github.com

Anti-debugging detection and bypass playbook. Use when reversing protected binaries that detect debuggers via ptrace, PEB flags, timing checks, or signal/exception handlers on Linux and Windows.

$ npx skills add yaklang/hack-skills
Ver habilidad

yaklang/saml-sso-assertion-attacks

github.com

SAML SSO assertion attack playbook. Use when testing signature validation, assertion wrapping, audience restrictions, ACS handling, XML trust boundaries, and enterprise SSO flaws.

$ npx skills add yaklang/hack-skills
Ver habilidad

yaklang/hash-attack-techniques

github.com

Hash attack playbook. Use when exploiting length extension, MD5/SHA1 collisions, HMAC timing leaks, birthday attacks, or hash-based proof of work in CTF and authorized testing scenarios.

$ npx skills add yaklang/hack-skills
Ver habilidad

yaklang/active-directory-certificate-services

github.com

AD Certificate Services attack playbook. Use when targeting misconfigured AD CS for privilege escalation via ESC1-ESC13 template abuse, NTLM relay to enrollment, CA officer abuse, and certificate-based persistence.

$ npx skills add yaklang/hack-skills
Ver habilidad