Audit client bundles and applications for exposed secrets and security gaps
Project overview
client-secret-exposure audits web, mobile, and backend projects for secrets exposed in client bundles, insecure storage, broken access control, XSS, weak authentication, sensitive logs, dependency issues, headers, rate limits, business-logic flaws, and CI secrets. It is useful for Next.js and other app stacks, but the checks only identify findings; developers still need to remediate and retest the application.
Closes post-deploy web-app readiness gaps across security, operations, legal, and recovery.
Project overview
webapp-last-90 detects a web app’s stack, scores an 11-dimension readiness baseline, and gates launch on ten binary blockers such as real auth, tenant isolation, rate limits, legal pages, production monitoring, CI/CD, health checks, and a rehearsed backup restore. It separates autonomous work from items needing account access or a decision, then returns SHIP-SAFE or NOT-YET with evidence.
Interviews you into a narrow, evidence-backed Ideal Customer Profile for sales, ads, and copy.
Project overview
SuperICP turns a vague “we sell to everyone” position into a focused Ideal Customer Profile through a short, structured interview. It forces facts, guesses, buying context, and disqualifiers into the open, then returns an operational profile, lead scorecard, and validation plan for sales, advertising, and copy. It runs in any prompt-capable agent with no install or API key, across B2B, B2C, creator, and nonprofit contexts.
Writes platform-adapted TikTok, Reels, and Shorts scripts with hooks, re-hooks, and CTAs.
Project overview
short-form-video-script-writer generates a topic and angle, calibrates the presenter’s voice, selects one of six frameworks, and builds hooks, a 5–7 second re-hook, open-loop body copy, and a CTA. Its default is one 45–60 second script adapted across TikTok, Instagram Reels, and YouTube Shorts, followed by a ten-point revision checklist and an optional performance-feedback loop.
Cleans up orphaned AI-tool processes and handles background agents that respawn.
Project overview
bg-janitor targets macOS leftovers after AI tools close: orphaned children, sandbox-protected processes, port-holding gateways, and KeepAlive LaunchAgents. Its playbook distinguishes unsandboxed signal delivery, safe multi-PID handling in zsh, and launchctl unload -w for agents that immediately return after kill. Because the commands can terminate processes or disable startup services, confirm the target before applying them.
Collection or directoryProductivity and officeClaude Code
meta-skills↗
@opelpleple
Adds 17 model-agnostic thinking skills for clarification, critique, context control, and verification.
Project overview
meta-skills is a collection of 17 standalone process skills for Claude, including rubber-duck questioning, steelmanning, pre-mortems, first-principles analysis, red-teaming, scope cutting, context budgeting, distillation, handoffs, and teach-back. Each skill is designed to challenge assumptions or verify work before trust. Install the collection globally, per project, or copy a single folder when you need only one method.
Builds embedded, demo-safe product walkthroughs with real components, highlights, and guided interactions.
Project overview
embedded-uiux-walkthrough guides an agent to add tutorial routes or embedded tours to a web app using real components rather than screenshots. It covers demo-only data, no-write flows, fake cursors, target highlights, click and typing animations, iframe scroll or input locking, and mobile-aware targeting through stable data-tutorial hooks. Use it for onboarding, customer demos, or in-app training.
Builds evidence-based, citation-checked medical literature reviews, including POCUS.
Project overview
revisao-literatura-medica is for medical professionals and supports literature reviews across clinical topics, with POCUS as one use case. It searches PubMed, Europe PMC, and OpenAlex, verifies PMIDs and DOIs, resolves open-access copies through Unpaywall, and reads PDF or EPUB documents TOC-first, using OCR for scans. Outputs follow evidence-grading and guideline or study structures, and the skill only states claims retrieved from a real source in the current session. It requires Python dependencies; Telegram-library access stays in private configuration.
Renders HTML, CSS, and JavaScript animations into deterministic MP4 video frames.
Project overview
html-animation-to-mp4 captures HTML/CSS/JS animations in a headless browser and encodes the frames with ffmpeg. Claude Design .dc.html bundles can expose their own frame-seek hook, while --virtual freezes clocks and advances ordinary canvas, WebGL, or CSS animation frame by frame. It supports multiple aspect ratios and frame rates; capture is silent by default, and Playwright, Node, and ffmpeg are required for the CLI.
Finds DB and API bottlenecks and proves behavior-preserving fixes with before-and-after benchmarks.
Project overview
db-route-optimizer identifies N+1 queries, missing indexes, queries in loops, unbounded reads, and other route bottlenecks through query counts or EXPLAIN ANALYZE rather than guesswork. It saves a baseline, applies one isolated behavior-preserving change, re-benchmarks under the same conditions, and records the result. Tests and a query-count guard can stay in CI to prevent regressions, and the scripts also run without Claude.
General skillSecurity and privacyAgent2Agent protocol
agentrank-skill↗
@andysalvo
Checks an x402 counterparty’s settlement-grounded AgentRank before payment.
Project overview
agentrank-verify queries an x402 counterparty’s AgentRank before settling payment. The 0–1000 score is derived from real on-chain USDC settlements and weighted by payer reputation, and the check works through MCP, A2A, or a plain HTTP GET. It helps identify counterparties with verifiable settlement history, but a reputation score is a pre-payment signal rather than a guarantee of safety or delivery.
Checks proposed dependency versions against live OSV and CVE data before the agent writes them.
Project overview
safedeps grounds dependency choices in current OSV vulnerability records instead of a model’s frozen training knowledge. When an agent is about to add a package and version, it checks for known flaws and can stop the suggestion before it enters the project. This is a narrow decision-time guard, not a replacement for npm audit, pip-audit, osv-scanner, or a broader CI security scan.
Rewrites text around 29 AI-writing patterns while preserving your voice and removing every dash variant.
Project overview
Humanize detects 29 concrete patterns associated with machine-written prose, then iterates through transformation, re-scoring, and keep-or-discard decisions for up to ten rounds. A writing sample lets it match your rhythm, vocabulary, and punctuation instead of imposing a generic voice. The final pass removes em dashes, en dashes, and double hyphens, and the plain skill runs without code dependencies.
Frisks application logs for leaked secrets and PII before a release can ship.
Project overview
logfrisk checks logging code and representative output for bearer tokens, emails, password hashes, error payloads, and other secrets or personal data. Findings include file and line locations, severity, and a suggested redaction; clear leaks can be replaced with redacted fields, while ambiguous cases are escalated for a decision. The skill keeps the work open until every leak is fixed or explicitly resolved.
Checkpoints work and distills sources into traced evidence inside a governed knowledge vault.
Project overview
vault-crystallize has two separate workflows: crystallize updates recovery state and durable knowledge in Handoff.md only when something changed, while distill converts a concrete source into traced evidence entries. AGENTS.md owns workspace and write boundaries, and the vault protocols define schemas and contradiction handling. It is deliberately not a generic document-cleanup, deep-review, memory-sync, or polished-summary tool.
Picks the best card in your wallet by capped cash earned, not advertised reward rates.
Project overview
CardRadar reads your credit-card reward rules from your Notion database and chooses among the cards you actually own. For a purchase, it ranks real cash as min(amount × reward rate, monthly cap), so a high headline percentage cannot hide a low monthly ceiling. Card profiles, spending habits, and local IDs stay on your machine; this is a wallet-specific Claude skill, not a broad card catalog or payment app.
Turn one idea into a constrained prompt for a multi-panel storyboard
Project overview
storyboard-prompter converts a one-line idea into one English prompt for an image model to render a multi-panel storyboard. It fixes the grid, aspect ratio, shared art direction, one beat per panel, and action logic so characters and style stay consistent across frames. The skill chooses common six- or nine-panel variants from natural language, but only produces prompt text; image generation happens elsewhere.
Analyze complex decisions with multi-step reasoning and self-evaluation
Project overview
deep-think applies a staged reasoning loop to complex business, strategy, and decision questions: form hypotheses, examine counterarguments, test assumptions, self-evaluate, and rethink. It scores the response across coverage, logic, support, balance, specificity, and usefulness, adjusts effort to the question, and can wait for approval of the thinking frame. It relies mainly on supplied information rather than web research.