全部收录

相关性达标的全量 Skills(含未精选长尾)· 共 6259

campaign

对现有 PR 执行分级审查并在满足条件时自动把关合并的管道

▸ 推荐理由把复杂的 PR 审查与合并流程自动化、适合 CI 密集仓库
▸ 风险提示需要 GitHub 写入权限与令牌,合并操作有安全风险
开发编程PR 审核自动合并GateClaude CodeSkill.md ↗

skill-radar

测评一个 AI skill(SKILL.md 那种技能包)并生成一份简约的单页长滚动 HTML。指向一个 skill 文件夹,自动读 SKILL.md 及配套文件,讲解它是什么、适合谁、怎么装、结构架构、工作流程,并做六维打分。产出一个可直接在浏览器打开、可分享的单文件 HTML。触发词:测评这个skill、skill测评、讲清楚这个skill、给这个skill做个介绍页、skill radar、评估一下这个技能包。

Skill.md ↗

skill-doctor

Statically audit Agent Skill directories for invalid SKILL.md structure, weak metadata, broken local references, packaging problems, and risky script or instruction patterns. Use when reviewing, validating, publishing, installing, or CI-checking a Codex, Claude Code, or compatible Agent Skill, especially before trusting a third-party Skill.

Skill.md ↗

workspace-init

Sets up a multi-repo workspace so one session can see a whole system — sibling repos plus the cross-cutting folders no single repo owns — and generates the root CLAUDE.md map by reading each repo rather than being told. Use when starting work across several related repos, onboarding onto an unfamiliar system, or when Claude keeps missing context that lives in a sibling repo. Trigger: "set up the workspace", "map this project", "I have several repos", "onboard me onto this", "create the root CLAUDE.md".

Skill.md ↗

user-manual

Builds a print-quality PDF user manual for an application — learns the product by reading the codebase, drives the real UI with Playwright to capture screenshots, writes the prose against what was actually captured, and renders a paginated PDF with cover, table of contents, figures and callouts. Use when asked for a user manual, operator guide, onboarding handbook, client handover documentation, or training material. Trigger: "make a user manual", "write documentation for this app", "operator guide", "client handover doc", "PDF manual", "training guide".

Skill.md ↗

server-connect

Gives Claude Code non-interactive SSH access to a server and then writes a server-info folder by interrogating the machine — services, ports, deploy paths, logs, databases — rather than being told. Use when adding a dev or production server to a workspace, onboarding onto infrastructure nobody documented, or when Claude cannot reach a machine it needs. Trigger: "connect to the server", "set up ssh", "document this server", "add the dev server", "why can't you reach the box".

Skill.md ↗

reviewer

Validates work completed by /executor agents. Reviews contract compliance, test quality, edge cases, security, performance, and integration correctness in a fresh context, refutes its own findings before reporting them, and gates the verdict on recorded exit codes. Runs after a phase or the full plan is implemented. Trigger: "review phase", "validate the work", "check what was implemented", "run review", "quality check".

Skill.md ↗

resume-work

Restores working context after a /clear or /compact by reading the most recent session handoff plus current git state, then reports where things stand and what the next step is. Use at the start of a session, after clearing or compacting, when picking up work from a previous day, or when taking over someone else's branch. Trigger: "resume", "pick up where we left off", "what was I doing", "restore context", "continue from the handoff", "catch me up".

Skill.md ↗

investigate

Deep multi-perspective codebase investigation. Use when: analyzing feasibility of a new feature, auditing code for issues, investigating bugs, evaluating technical debt, or assessing any change before planning. Dispatches investigations across the dimensions that matter for the question asked, refutes every finding before reporting it, and synthesizes into one actionable report. Trigger: "investigate this", "is this feasible", "analyze my codebase", "audit this", "what would it take to", "assess this", "can we do this", "deep dive", "research this before we start".

Skill.md ↗

handoff

Writes a session handoff to disk before a context reset — what's done, what changed, what was decided, what was ruled out, and the single next step — then tells you whether to /clear or /compact. Use when a session is getting long or slow, before compacting, at the end of a work block, or when handing work to another person or session. Trigger: "write a handoff", "save progress", "save state", "session is getting slow", "before I compact", "wrap up", "I'm stopping here".

Skill.md ↗

frontend-verify

Verifies frontend changes in a real browser — screenshots at multiple viewports, console errors, accessibility snapshot — then fixes what it finds and re-verifies. Scopes to routes touched by the current diff when no URL is given. Use after changing UI code, before shipping a frontend change, when a page "looks wrong", or when asked whether something actually works in the browser. Trigger: "check the UI", "does this look right", "screenshot the page", "verify the frontend", "review the design", "test it in the browser".

Skill.md ↗

executor

Implements a plan created by /architect. Reads the plan, claims a phase, works one task at a time in an isolated branch or worktree, verifies externally, commits, and records state in its own single-writer file. Designed for multi-agent parallel execution. Trigger: "execute the plan", "implement phase", "continue the plan", "work on next task", "pick up where we left off".

Skill.md ↗

driver

Orchestrates the full plan-execute-review pipeline. Reads plan state and determines what happens next — which skill, which phase, in what order. Runs advisory by default, or autonomously behind explicit guardrails. Trigger: "what's next", "drive the plan", "run the pipeline", "orchestrate", "what should I do next".

Skill.md ↗

decision-log

Records durable technical decisions with their reasoning, and searches them before a settled question gets re-opened. Use when an architectural, scope, tooling or vendor choice is made or reversed, when someone asks "why is it like this", or before proposing an approach that may already have been rejected. Trigger: "log this decision", "why did we choose", "did we try", "have we decided", "record that we're not doing", "was this considered".

Skill.md ↗

clickup-connect

Connects Claude Code to a ClickUp workspace and writes its own reference notes — workspace, spaces, folders, list IDs, assignee IDs, and the API quirks it hits — so future sessions can read and update tasks without rediscovering the workspace every time. Use when wiring a task tracker into a workspace or when task IDs keep getting looked up by hand. Trigger: "connect clickup", "set up the task board", "read my tasks", "sync tasks", "what's assigned to me".

Skill.md ↗

architect

Analyzes a problem and generates a phased execution plan with progress tracking, shared contracts, dependency graphs, per-phase isolation, and task-level detail. Use when tackling any large feature, refactor, migration, or complex fix. Trigger: "plan this", "break this down", "architect this", "create a plan".

Skill.md ↗

story-handdrawn-studio

Produce, creatively direct, revise, review, recover, and machine-check complete hand-drawn videos from Chinese stories, scripts, diary entries, comic pages, or ordered images. Use for narrative-arc selection, style bake-offs, multi-shot planning, deterministic hand-drawn motion, resumable image providers, continuity, scene retakes, multi-ratio rendering, page flips, automatic local sound design or narration, semantic and pixel QA, visual review, snapshots, and final MP4 delivery.

Skill.md ↗

getbijiex

将 biji.com/得到大脑订阅博主的笔记导出为 Markdown。

▸ 推荐理由便于备份与离线阅读,针对使用 GetbijiEx 的用户。
▸ 风险提示依赖本机安装并可能需登录或抓取第三方站点,注意凭据与隐私。
垂直行业笔记导出BijiCLI通用Skill.md ↗

convertkit-automation

通过 Rube MCP(Composio)自动化管理 ConvertKit 的订阅者、标签与广播。

▸ 推荐理由对使用 ConvertKit 的营销团队能自动化日常邮件与受众管理任务。
▸ 风险提示需要连接 ConvertKit 账号与 MCP,涉及账号权限与数据访问风险。
自动化集成邮件自动化ConvertKit订阅者管理通用Skill.md ↗

confluence-automation

通过 Composio/Rube MCP 自动化创建、搜索与管理 Confluence 页面与空间。

▸ 推荐理由对使用 Confluence 的团队可显著加速文档维护与结构管理流程。
▸ 风险提示需连接外部 MCP 并授予 Confluence 访问权限,注意凭据与权限控制。
自动化集成Confluence页面自动化空间管理通用Skill.md ↗

pentest-commands

提供 nmap、metasploit、hydra 等渗透测试常用命令参考。

▸ 推荐理由适合实战成员快速查命令及参数,便于现场测试。
▸ 风险提示含可执行攻击命令,可能被滥用或违法,需限制用途与权限。
垂直行业渗透命令渗透测试命令参考工具通用Skill.md ↗

pentest-checklist

用于规划与执行渗透测试的全面检查表与方法论。

▸ 推荐理由帮助安全团队规范化测试流程与验收标准。
▸ 风险提示可能被用于未授权的入侵测试,应确保合法合规。
垂直行业渗透测试安全评估检查表合规通用Skill.md ↗

network-101

配置与测试常见网络服务(HTTP/HTTPS/SNMP/SMB)以搭建渗透测试实验环境。

▸ 推荐理由面向实验室的实操指南,便于安全学习与环境构建。
▸ 风险提示搭建或测试网络服务可能被用于恶意目的,注意合规与授权。
开发编程网络配置服务测试实验室通用Skill.md ↗

metasploit-framework

指导使用 Metasploit 进行漏洞利用、载荷生成与后渗透操作。

▸ 推荐理由整合 msfconsole/msfvenom 常用流程,适合红队与渗透测试。
▸ 风险提示涉及攻击与后渗透技术,存在被滥用风险,必须在授权范围内使用。
垂直行业Metasploit利用载荷渗透测试通用Skill.md ↗

idor-testing

系统化检测与利用 Insecure Direct Object Reference(IDOR)漏洞的方法论。

▸ 推荐理由为红队与安全评估提供对象枚举与参数篡改流程参考。
▸ 风险提示含可用于未授权访问的利用方法,务必在授权范围内使用。
垂直行业IDOR漏洞检测权限绕过通用Skill.md ↗

http-load-profiler

按步增加并发对 HTTP 服务压测,收集 p50/p90/p99 并检测性能拐点。

▸ 推荐理由自动化发现最优并发,辅助容量规划与性能回归验证。
▸ 风险提示会对目标施加高负载,需获得授权并注意流量成本。
开发编程负载测试性能分析并发p99通用Skill.md ↗

html-injection-testing

检测与利用 HTML 注入漏洞,评估内容注入与页面篡改风险(授权测试)。

▸ 推荐理由能生成测试用例并评估注入风险,适合前后端安全审计人员。
▸ 风险提示含利用方法,可能被滥用;仅限授权环境并遵守法律。
垂直行业HTML 注入内容注入安全测试篡改检测通用Skill.md ↗

file-path-traversal

识别与利用路径遍历漏洞以读取服务端任意文件(用于授权测试)。

▸ 推荐理由帮助发现可能导致敏感信息泄露的路径遍历缺陷,便于修复。
▸ 风险提示含主动利用步骤,易被滥用;仅限授权测试并遵守法律。
垂直行业路径遍历LFI安全测试漏洞检测通用Skill.md ↗