Coding & Development
semgrep/code-security
Security guidelines for writing secure code. Use when writing code, reviewing code for vulnerabilities, or asking about secure coding practices like 'check for SQL injection' or 'review security'. IMPORTANT: Always consult this skill when writing or reviewing any code that handles user input, authentication, file operations, database queries, network requests, cryptography, or infrastructure configuration (Terraform, Kubernetes, Docker, GitHub Actions) — even if the user doesn't explicitly mention security. Also use when users ask to 'review my code', 'check this for bugs', or 'is this safe'.
$ npx skills add semgrep/skillsserpdownloaders/vectorstock-downloader
Extract VectorStock vectors and illustrations in original formats
$ npx skills add serpdownloaders/skillsccheney/postgres-drizzle
Proactively apply when creating APIs, backends, or data models. Triggers on PostgreSQL, Postgres, Drizzle, database, schema, tables, columns, indexes, queries, migrations, ORM, relations, joins, transactions, SQL, drizzle-kit, connection pooling, N+1, JSONB, RLS. Use when writing database schemas, queries, migrations, or any database-related code. PostgreSQL and Drizzle ORM best practices.
$ npx skills add ccheney/robust-skillsgiuseppe-trisciuoglio/react-code-review
Provides comprehensive code review capability for React applications, validates component architecture, hooks usage, React 19 patterns, state management, performance optimization, accessibility compliance, and TypeScript integration. Use when reviewing React code changes, before merging pull requests, after implementing new features, or for component architecture validation. Triggers on "review React code", "React code review", "check my React components".
$ npx skills add giuseppe-trisciuoglio/developer-kitriba2534/feishu-cli-toolkit
飞书轻量工具箱与分诊入口。仅在没有更专用 skill 时使用,主要覆盖普通电子表格、 日历/日程、任务/任务清单、基础文件/素材/评论、知识库、用户和部门查询、审批查询。 文档读写导入导出、云盘增强、多维表格、画板、消息/群聊、邮箱、搜索、权限、OAuth、 视频会议/妙记均优先使用对应 feishu-cli-* 专用技能。 sheet filter-view/dropdown 优先用 `feishu-cli-sheet`;calendar suggestion/room-find/rsvp 优先用 `feishu-cli-calendar`。
$ npx skills add riba2534/feishu-cliphuryn/draft-nda
Draft a detailed Non-Disclosure Agreement between two parties covering information types, jurisdiction, and clauses needing legal review. Use when creating confidentiality agreements or preparing an NDA for a partnership.
$ npx skills add phuryn/pm-skillsserpdownloaders/internet-archive-downloader
Access and download books
$ npx skills add serpdownloaders/skillsactionbook/m10-performance
CRITICAL: Use for performance optimization. Triggers: performance, optimization, benchmark, profiling, flamegraph, criterion, slow, fast, allocation, cache, SIMD, make it faster, 性能优化, 基准测试
$ npx skills add actionbook/rust-skillsserpdownloaders/upornia-downloader
Upornia Downloader Browser Extension (Chrome, Firefox, Edge, Opera, Brave)
$ npx skills add serpdownloaders/skillsopenai/cli-creator
Build a composable CLI for Codex from API docs, an OpenAPI spec, existing curl examples, an SDK, a web app, an admin tool, or a local script. Use when the user wants Codex to create a command-line tool that can run from any repo, expose composable read/write commands, return stable JSON, manage auth, and pair with a companion skill.
$ npx skills add openai/skillsserpdownloaders/txxx-downloader
TXXX Downloader Browser Extension (Chrome, Firefox, Edge, Opera, Brave)
$ npx skills add serpdownloaders/skillsleezythu/mao-zedong-perspective
毛泽东思维框架:以《毛泽东选集》五卷为核心,提炼毛泽东分析问题、制定战略、组织行动的认知操作系统。 核心来源:《矛盾论》《实践论》《论持久战》《中国社会各阶级的分析》《星星之火可以燎原》《论联合政府》《关于正确处理人民内部矛盾的问题》等。 核心模型:7个。决策启发式:10条。 触发词:「毛泽东」「毛选」「教员」「用毛泽东的方式分析」「从毛选的角度」「教员怎么看」 局限:本Skill聚焦于毛泽东的分析方法论和战略思维框架,适用于战略分析、组织管理、竞争策略、问题诊断等场景。不涉及具体政治立场的评判。 素材来源:《毛泽东选集》一至五卷、公开演讲与书信、诗词作品。
$ npx skills add leezythu/maoxuan-skill404kidwiz/project-manager
Project management expert specializing in planning, execution, monitoring, and closure of projects. Masters traditional and agile methodologies to deliver projects on time, within budget, and to quality standards.
$ npx skills add 404kidwiz/claude-supercode-skillsserpdownloaders/kick-clip-downloader
Save Kick.com clips and VODs with chat replay and emote support
$ npx skills add serpdownloaders/skillsyaklang/stack-overflow-and-rop
Stack overflow and ROP playbook. Use when exploiting buffer overflows to hijack control flow via return address overwrite, ROP chains, ret2libc, ret2csu, ret2dlresolve, or SROP on Linux userland binaries.
$ npx skills add yaklang/hack-skillsyamadashy/repomix-explorer
Analyze or explore a codebase (remote or local repository) by packing it with the Repomix CLI, then reading and searching the generated output. Use when the user wants a high-level understanding of an unfamiliar or large repo, not a targeted edit. Trigger for: - Structure/overview: "analyze this repo", "what's the structure", "explain this codebase", "what's in vercel/next.js" - Pattern discovery across many files: "find all auth code", "where are the API endpoints", "show me all React components" - Metrics: "how many files/tokens", "largest files", "TypeScript vs JavaScript ratio" - Remote repos: any github.com URL or "owner/repo" the user wants explored DO NOT trigger for: - Editing, refactoring, or writing code in the current project - Reading or searching a known file/path in the local project (use Read or grep directly) - Single-symbol lookups in the local project answerable with one grep - Git operations, running tests, builds, or installs
$ npx skills add yamadashy/repomixangular/reference-signal-forms
Explains the mental model and architecture of the code under `packages/forms/signals`. You MUST use this skill any time you plan to work with code in `packages/forms/signals`
$ npx skills add angular/angulargiuseppe-trisciuoglio/aws-lambda-php-integration
Provides AWS Lambda integration patterns for PHP with Symfony using the Bref framework. Creates Lambda handler classes, configures runtime layers, sets up SQS/SNS event triggers, implements warm-up strategies, and optimizes cold starts. Use when deploying PHP/Symfony applications to AWS Lambda, configuring API Gateway integration, implementing serverless PHP applications, or optimizing Lambda performance with Bref. Triggers include "create lambda php", "deploy symfony lambda", "bref lambda aws", "php lambda cold start", "aws lambda php performance", "symfony serverless", "php serverless framework".
$ npx skills add giuseppe-trisciuoglio/developer-kityaklang/linux-security-bypass
Linux security mechanism bypass playbook. Use when facing restricted bash/rbash, read-only or noexec filesystems, AppArmor, SELinux, seccomp filters, or audit logging that must be evaded during post-exploitation.
$ npx skills add yaklang/hack-skillsyaklang/dns-rebinding-attacks
DNS rebinding attack playbook. Use when testing applications that trust DNS resolution for origin checks, interact with internal services from browser context, or when SSRF is not possible server-side but the target has client-side fetch/XHR to attacker-controlled domains.
$ npx skills add yaklang/hack-skillsserpdownloaders/justforfans-downloader
JustForFans Downloader Browser Extension (Chrome, Firefox, Edge, Opera, Brave)
$ npx skills add serpdownloaders/skillsserpdownloaders/tokyomotion-downloader
TokyoMotion Downloader Browser Extension (Chrome, Firefox, Edge, Opera, Brave)
$ npx skills add serpdownloaders/skillsactionbook/m07-concurrency
CRITICAL: Use for concurrency/async. Triggers: E0277 Send Sync, cannot be sent between threads, thread, spawn, channel, mpsc, Mutex, RwLock, Atomic, async, await, Future, tokio, deadlock, race condition, 并发, 线程, 异步, 死锁
$ npx skills add actionbook/rust-skillsyaklang/container-escape-techniques
Container escape playbook. Use when operating inside a Docker container, LXC, or Kubernetes pod and need to escape to the host via privileged mode, capabilities, Docker socket, cgroup abuse, namespace tricks, or runtime vulnerabilities.
$ npx skills add yaklang/hack-skills