发现 Skills
为真实工作流程挑选经过整理的 Skill,连接、安装并开始使用。
penetration-testing
Perform basic penetration testing and security assessments. Use reconnaissance, vulnerability discovery, and exploitation techniques. Use when validating security controls or assessing system security.
systemd-services
Create and manage systemd services and timers. Configure service dependencies and resource limits. Use when managing system services.
windows-hardening
Harden Windows servers according to security baselines and CIS benchmarks. Configure Group Policy, Windows Defender, and other security features. Use when securing Windows Server environments.
zot-skills
When a user inside Claude Code, Codex, or a similar agent wants to directly query, extract, organize, or safely update locally available Zotero content, this skill must be used. The focus is on Zotero metadata, notes, tags, attachments, PDF full text, outlines, annotations, collections, saved searches, feeds, and reading workspaces—not on teaching CLI usage. The Rust `zot` CLI is only the execution layer. Applicable scenarios include in-library search, citation-key lookup, annotation and PDF extraction, workspace creation and retrieval, saved-search management, attachment downloads, semantic indexing/search, Scite checks, configuration troubleshooting, and Zotero Web API write operations that have explicit authorization. Do not use it for broad paper discovery, general summarization, citation-format tutorials, or PDF processing that does not result in Zotero/workspace artifacts.
ai-content-discovery
Fixes AI content discovery issues — creates and optimizes robots.txt, AI crawler directives, XML sitemaps, llms.txt, and meta robots tags so AI systems can find, crawl, and understand website content. Use when asked to "fix robots.txt", "add llms.txt", "create a sitemap", "allow AI crawlers", "fix AI discoverability", "improve AI content discovery score", "make site crawlable by AI", or any robots.txt, sitemap, or llms.txt task.
data-assessment
Assesses whether a business question can be answered with data available in a Bauplan lakehouse. Maps business concepts to tables and columns, checks data quality on the relevant subset, validates semantic fit, and renders a verdict: answerable, partially answerable, or not answerable. Produces a structured feasibility report. Use when a user brings a business question, asks 'can we answer this', wants to know if the data supports an analysis, or before building a one-off analysis or pipeline.
validating-database-integrity
Use when you need to ensure database integrity through comprehensive data validation. This skill validates data types, ranges, formats, referential integrity, and business rules. Trigger with phrases like "validate database data", "implement data validation rules", "enforce data integrity constraints", or "validate data formats".
x-callback-url:xcall
Call x-callback-url schemes from the CLI and receive responses synchronously. Use when invoking macOS app URL schemes that have no CLI but support x-callback-url (Things, Bear, OmniFocus, etc.) and you need to capture the result.
code-review
Performs an architectural and quality code review on a specified file or set of files. Checks for coding standard compliance, architectural pattern adherence, SOLID principles, testability, and performance concerns.
map-systems
Decompose a game concept into individual systems, map dependencies, prioritize design order, and create the systems index.
security-audit
Comprehensive security scanning and vulnerability detection. Includes input validation, path traversal prevention, CVE detection, and secure coding pattern enforcement. Use when: authentication implementation, authorization logic, payment processing, user data handling, API endpoint creation, file upload handling, database queries, external API integration. Skip when: read-only operations on public data, internal development tooling, static documentation, styling changes.
Story Coaching
Coach the author through building a narrative structure using the Amuse-Bouche framework. Work through each component one at a time — propose, get the author's reaction, confirm, then move on.
biome
Fast linting/formatting for TypeScript/React. Use when setting up linter, migrating from ESLint/Prettier, or running code quality checks.
write-docs
Create or revise documentation for the simple-stack repository, especially MDX guides and API reference content under www/src/content/docs/. Use when asked to write docs, restructure guides, add examples, or enforce documentation tone, structure, and code highlighting conventions.
predictable-revenue
Outbound sales methodology based on Aaron Ross' "Predictable Revenue". Use when you need to: (1) build a scalable outbound sales process, (2) implement Cold Calling 2.0, (3) structure sales team roles (SDR/AE/CSM), (4) design lead generation and qualification frameworks, (5) scale B2B SaaS sales predictably, (6) create prospecting email sequences, (7) build sales development pipeline, (8) separate prospecting from closing.
Handoff Document Generator
Generate a HANDOFF.md documenting session progress for seamless continuation in a new session
multi-plan
Multi-agent orchestration skill that spawns parallel specialist agents to analyze a feature from architecture, testing, and security perspectives, then synthesizes a unified implementation plan. Example usage: ``` /multi-plan Add user authentication with OAuth2 and role-based access control ``` ``` /multi-plan Redesign the payment processing pipeline to support subscriptions ``` ``` /multi-plan Migrate the monolithic API to microservices with event-driven communication ```
qa-fix
Systematically QA test a web application and fix bugs. Finds issues via browser automation, fixes source code, commits atomically, and re-verifies. Use when asked to "QA this", "test and fix", "find and fix bugs", or "qa the app".
dealradar-query
Conversational dealradar search from a natural-language description. Launches a targeted scrape and returns the top 3–5 analyzed results.
eightctl
Control Eight Sleep pods (status, temperature, alarms, schedules).
openhue
Control Philips Hue lights and scenes via the OpenHue CLI.
self-improvement-pipeline
Nightly self-improvement pipeline for field agents. Agent reviews transcripts, identifies mistakes, auto-applies safe fixes, and sends proposals for risky changes to founders for approval. One job, no morning phase needed.
vulkn-software-manager
HQ skill for provisioning full-stack infrastructure for new VULKN field agents. Creates GitHub repos, Supabase project, Vercel deploy, and Railway service — all via API. Sends individual keys to field agents via A2A.
vf-rtl
Use this skill to start or resume the VeriFlow RTL hardware design pipeline (architect to synth). Trigger this when the user asks to "run the RTL flow", "design hardware", or "start the pipeline". Pass the project directory path as the argument.