Loading...
Loading...
Found 2,044 Skills
Regulatory compliance auditing across GDPR, HIPAA, PCI DSS, SOC 2, and ISO frameworks with automated evidence collection and gap analysis. Use when conducting compliance assessments, preparing for certifications, or implementing regulatory controls.
Migrate an application with hardcoded LLM prompts to a full LaunchDarkly AgentControl implementation in five stages: audit the code, wrap the call, move the tools, add tracking, attach evaluators. Use when the user wants to externalize model/prompt configuration, move from direct provider calls (OpenAI, Anthropic, Bedrock, Gemini, Strands) to a managed config, or stage a full hardcoded-to-LaunchDarkly migration.
Security & compliance skill suite providing OWASP scanning, CVE detection, GDPR/SOC2 audits, threat modeling, and incident response workflows for AI coding agents
Design HTTP APIs for Bun + Hono backends using Clean Architecture, Zod contracts in a shared package, OpenAPI generation from Zod, and thin controllers. Supports two selectable conventions — standard REST (resource paths with GET/POST/PATCH/PUT/DELETE) and POST-only action-based paths — picking one per project. Use when defining new endpoints, auditing or refactoring existing routes, shaping request/response contracts and envelopes, establishing API standards, or mapping typed application errors to HTTP status codes. Do not use for GraphQL, tRPC, non-Hono runtimes, or frontend-only concerns.
Build and maintain a Karpathy-style LLM knowledge base — a self-compiling Obsidian markdown wiki where an Agent ingests raw sources, compiles cross-linked concept/entity/summary pages, answers queries against the corpus, lints the graph for health, and audits in-context human feedback filed from Obsidian or the local web viewer. Use when (1) scaffolding a new knowledge base for any research topic, (2) ingesting articles/papers/PDFs/web pages into raw/, (3) compiling or restructuring wiki articles from existing raw material, (4) answering questions against the wiki and filing durable answers back, (5) running lint passes for dead links / orphan pages / coverage gaps / audit shape, (6) processing human feedback from the audit/ directory and applying corrections. Not for general note-taking, daily journals, or non-wiki Obsidian use.
Server-side tracking pipeline audit covering server-side Google Tag Manager (sGTM), Meta CAPI Gateway, Conversions API health, event deduplication via event_id, server-side hit ratio targets, pixel debugging, and PII hashing discipline. Use when user says server-side tracking, sGTM, server-side GTM, server-side tagging, CAPI, Conversions API, CAPI Gateway, Meta Conversions API, event deduplication, event_id, pixel debug, pixel health, Pixel/CAPI audit, first-party tracking, iOS 14.5 recovery, or server-side hit ratio.
Administer the CARTO org — users, roles, quotas, activity audit, and bulk resource operations.
Guide for (a) auditing an existing whistleblower system or (b) drafting a compliant reporting policy from a provided template. Covers EU Directive 2019/1937, the amended Sapin II law (Waserman 2022), Decree 2022-1284, CNIL guidelines, public sector requirements, and duty of vigilance.
Use this skill to manage Google Cloud Workload Manager evaluations, rules, scanned resources, and validation results by using public client libraries and the REST API. Use when you need to inspect workload best-practice rules, create and run evaluations for Google Cloud general best practices, SAP, SQL Server, or custom organizational rules, review violations, export results to BigQuery, or automate Workload Manager through client libraries because no service-specific public CLI or MCP server is available. Don't use for general Google Compute Engine instance management, VPC configuration, or standard IAM auditing.
HertzFlow on-chain trade-decision intelligence. Currently covers Binance Alpha forensic across all surf-SQL EVM chains (BSC / Ethereum / Arbitrum / Base / Polygon / Optimism) — insider distribution, 真实派发 confirmed sell-out, 筹码三分法 (operator / CEX pool / verifiable retail), anomaly waves, monitoring exports. Solana runs in HOLDER_SNAPSHOT mode. Auto-trigger whenever the user pastes a raw 0x-prefixed 40-hex EVM CA, a Solana base58 CA, mentions a Binance Alpha token by ticker, or asks about 链上 forensic / 内幕出货 / 派发 / chip structure / quiet insider / Alpha distribution / on-chain dump — even if they don't say "hertzflow" explicitly. Pipeline runs deterministically (~2-10 min per CA depending on activity + surf cache state); LLM only fills narrative slots, never picks the verdict or writes SQL. Perp metrics, bridge audits, and HertzFlow core contract analysis sub-domains are coming — when those ship, this skill will dispatch to them based on input pattern (perp symbol, bridge protocol name, etc.) using the router table below. REQUIRES a Surf account + SURF_API_KEY. New users get 2000 free credits (~6-8 reports) via the HertzFlow private invite. Full forensic costs ~$1.5-3 USD per CA in Surf credits after the free tier runs out.
SEO & Content Marketing command suite for keyword research, content audits, technical SEO, competitor analysis, and content strategy workflows
AI SDLC commit preparation workflow. Use when an AI assistant is asked to commit repository changes, prepare an auditable commit message, stage files safely, include SDD traceability, verify branch/spec alignment, or verify the working tree before committing. Supports `--quick-flow` for fast assumption-driven execution and `--full-flow` for question-driven verified execution.