发现 Skills
为真实工作流程挑选经过整理的 Skill,连接、安装并开始使用。
gcp-vulnerable-components
Use this skill when users need to audit, detect, or remediate Vulnerable and Outdated Components (OWASP A06:2021) on Google Cloud Platform. This includes auditing Binary Authorization enforcement on GKE clusters, scanning container images in Artifact Registry for known CVEs, reviewing Security Command Center findings for container threats (malicious scripts, reverse shells, cryptomining, malware) and vulnerability detections (outdated libraries), configuring Cloud Armor WAF rules to block exploitation of vulnerable endpoints (RCE, file inclusion), and monitoring GCP security bulletins. Activate for container scanning, Binary Authorization policy checks, CVE remediation, or OWASP A06 compliance.
context-engineering-collection
A comprehensive collection of Agent Skills for context engineering, multi-agent architectures, and production agent systems. Use when building, optimizing, or debugging agent systems that require effective context management.
contract-comparison
Side-by-side comparison of two contract versions or two different contracts with change tracking, favorability analysis, and risk assessment
paperclip-ceo-autonomous-loop
Paperclip CEO autonomous loop — reviews all company KPIs, assigns tasks to agents, self-improves every 6 hours
lcu-api
League of Legends LCU (League Client Update) API reference. Use when working with LCU endpoints, champ select, skin selection, gameflow phases, ownership checks, lobby, matchmaking, store, collections, or any fetch/PATCH calls to the local client API.
RSpec Testing
This skill should be used when the user asks to "write specs", "create spec", "add RSpec tests", "fix failing spec", or mentions RSpec, describe blocks, it blocks, expect syntax, test doubles, or matchers. Should also be used when editing *_spec.rb files, working in spec/ directory, planning implementation phases that include tests (TDD/RGRC workflow), writing Testing Strategy or Success Criteria sections, discussing unit or integration tests, or reviewing spec output and test failures. Comprehensive RSpec and FactoryBot reference with best practices, ready-to-use patterns, and examples.
api-vuln-analyst-planner
Lead for API security vulnerabilities. Coordinates the triage of Nuclei findings against the OWASP API Security Top 10 (2023) — leads the Plan phase or contributes as an analyst when another skill is leading.
clause-negotiator
Proposes concrete alternative formulations for problematic clauses
input-abuser
Tests input handling: missing validation constraints, malformed payloads, wrong MIME types, oversized inputs, injection entry points
pcc-refresh
Refresh Project Context Cache (PCC) based on repo changes (minimal updates).
planning-with-files
Implements Manus-style file-based planning for complex tasks. Creates task_plan.md, findings.md, and progress.md. Use when starting complex multi-step tasks, research projects, or any task requiring >5 tool calls.
ui-ux-pro-max
UI/UX design intelligence. 50 styles, 21 palettes, 50 font pairings, 20 charts, 9 stacks (React, Next.js, Vue, Svelte, SwiftUI, React Native, Flutter, Tailwind, shadcn/ui). Actions: plan, build, create, design, implement, review, fix, improve, optimize, enhance, refactor, check UI/UX code. Projects: website, landing page, dashboard, admin panel, e-commerce, SaaS, portfolio, blog, mobile app, .html, .tsx, .vue, .svelte. Elements: button, modal, navbar, sidebar, card, table, form, chart. Styles: glassmorphism, claymorphism, minimalism, brutalism, neumorphism, bento grid, dark mode, responsive, skeuomorphism, flat design. Topics: color palette, accessibility, animation, layout, typography, font pairing, spacing, hover, shadow, gradient. Integrations: shadcn/ui MCP for component search and examples.
performance-budget-enforcer
Monitors Lighthouse scores and JavaScript bundle sizes across deployments with automated alerts when performance thresholds are exceeded. This skill should be used when setting up performance monitoring, enforcing bundle size limits, tracking Lighthouse metrics, or adding performance regression detection. Use for performance budgets, bundle size, Lighthouse CI, performance monitoring, regression detection, or web vitals tracking.
claw-pilot
PM/QA skill that manages Claude Code as a background engineer. Plan → Approve → Execute → Validate with git worktree isolation.
react-google-maps
Expert implementation of @vis.gl/react-google-maps library for Google Maps in React. Use when building maps, markers, pins, info windows, places autocomplete, geocoding, draggable markers, polygons, circles, polylines, drawing tools, or any Google Maps JavaScript API integration in React/Next.js applications.
blog-research
Research legal technology topics for blog posts on alt-counsel (Ang Hou Fu's blog). Use this Skill when the user asks to research topics, find sources, fact-check claims, gather statistics, or locate expert opinions for blog content. It prioritizes Singapore and ASEAN perspectives and flags US/EU-centric information. Outputs research findings to research.md in the post folder with proper citations.
fully-kiosk
Comprehensive Fully Kiosk Browser management for Android tablets and kiosk devices. Control screen state, brightness, URLs, screensavers, TTS, and media playback. Manage device fleets via REST API, MQTT, and Fully Cloud. Integrate with Home Assistant. Configure kiosk mode, motion detection, and remote administration. Supports Amazon Fire tablets, Android tablets, and wall-mounted panels. Ideal for dashboards, digital signage, and locked kiosks.
github-repo-management
Clone/create/fork repos; manage remotes, releases.
deployment-validator
Validates application readiness for Render/production deployment. Auto-runs when a user mentions deployment. Prevents “works locally, fails in production” issues. Always run this BEFORE any deployment.
Comprehensive PDF manipulation toolkit for extracting text and tables, creating PDFs, merging and splitting documents, and handling forms.
subagent-driven-development
Use when executing implementation plans made of independent tasks in the current session, or when facing three or more independent issues that can be investigated without shared state or dependencies. This approach dispatches a fresh subagent for each task and inserts automated code-review gates between tasks, enabling fast iteration with quality controls.
create-prd
Create a Product Requirements Document using a comprehensive 8-section template covering problem, objectives, segments, value propositions, solution, and release planning. Use when writing a PRD, documenting product requirements, preparing a feature spec, or reviewing an existing PRD.
huggingface-best
Use when the user asks about finding the best, top, or recommended model for a task, wants to know what AI model to use, or wants to compare models by benchmark scores. Triggers on: "best model for X", "what model should I use for", "top models for [task]", "which model runs on my laptop/machine/device", "recommend a model for", "what LLM should I use for", "compare models for", "what's state of the art for", or any question about choosing an AI model for a specific use case. Always use this skill when the user wants model recommendations or comparisons, even if they don't explicitly mention Hugging Face or benchmarks.
competitor-alternatives
[PMC] When the user wants to create competitor comparison or alternative pages for SEO and sales enablement. Also use when the user mentions 'alternative page,' 'vs page,' 'competitor comparison,' 'comparison page,' '[Product] vs [Product],' '[Product] alternative,' 'competitive landing pages,' 'how do we compare to X,' 'battle card,' or 'competitor teardown.' Use this for any content that positions your product against competitors. Covers four formats: singular alternative, plural alternatives, you vs competitor, and competitor vs competitor. For sales-specific competitor docs, see sales-enablement.