github.com/alirezarezvani/claude-skills
| Skill | Added | Review |
|---|---|---|
iso42001-specialist .gemini/skills/skills-iso42001-specialist/SKILL.md ISO/IEC 42001:2023 AI Management System (AIMS) specialist for compliance teams running internal audits. Three decisions: (1) Where are the gaps against Clauses 4-10 and what do we close first? (2) What goes in the AI risk register and which Annex A controls treat each risk? (3) What's the 12-month internal audit plan that satisfies Clause 9.2? Use when preparing for certification, scoping internal audit cycles, or onboarding AI systems into an existing ISMS (27001) / QMS (13485) program. NOT an executive AI strategy skill (see chief-ai-officer-advisor). NOT EU AI Act compliance (see compliance-team-eu-ai-act). | 64 64 Impact — No eval scenarios have been run Securityby — The risk profile of this skill Version: 19392f7 | |
handoff .gemini/skills/skills-handoff/SKILL.md Compact the current conversation into a handoff document for another agent to pick up. References existing artifacts (PRDs, plans, ADRs, issues, commits, diffs) by path or URL instead of duplicating them. Use when user wants to hand off the conversation to a fresh agent or starts a new session that picks up prior work. | 68 68 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 19392f7 | |
general-counsel-advisor .gemini/skills/skills-general-counsel-advisor/SKILL.md General Counsel advisory for startups: contract review (MSA, SaaS, NDA, DPA, employment), IP strategy, term sheet decoding, and regulatory landscape mapping. Use when reviewing any contract or term sheet, deciding when to engage outside counsel, defining IP strategy, evaluating regulatory exposure (HIPAA, GDPR, FDA, fintech), or when user mentions general counsel, GC, legal review, contract risk, term sheet, IP assignment, or regulatory exposure. NOT a substitute for licensed counsel — surfaces questions to bring to qualified attorneys. | 62 62 Impact — No eval scenarios have been run Securityby — The risk profile of this skill Version: 19392f7 | |
feature-flags-architect .gemini/skills/skills-feature-flags-architect/SKILL.md Use when adding, retiring, or auditing feature flags. Triggers on "add a flag", "ship behind a flag", "rollout plan", "kill switch", "stale flags", "flag debt", "LaunchDarkly", "GrowthBook", "Statsig", "Unleash", "Flipt", or any progressive-delivery question. Ships flag debt scanner, rollout planner, and kill-switch auditor (all stdlib Python), 4 references on flag taxonomy + provider trade-offs + rollout strategies + lifecycle, plus a /flag-cleanup slash command. | 70 70 Impact — No eval scenarios have been run Securityby — The risk profile of this skill Version: 19392f7 | |
eu-ai-act-specialist .gemini/skills/skills-eu-ai-act-specialist/SKILL.md EU AI Act (Regulation (EU) 2024/1689) operational compliance for compliance teams. Three Article-level decisions: (1) What's the risk tier of this AI system — prohibited (Art. 5), high-risk (Art. 6 + Annex III), limited-risk (Art. 50), or minimal-risk? (2) For high-risk systems, what's the Article 43 conformity assessment route (Module A internal control vs Module H full QMS + notified body) and what goes in the Annex IV technical documentation? (3) Per organizational role (provider / deployer / importer / distributor / authorized representative), what are the active obligations and deadlines? Use during AI system intake review, when planning conformity assessment, or when scoping deployer obligations. Cites Articles + Annexes for every output. NOT executive AI strategy (see chief-ai-officer-advisor). NOT a legal substitute. | 68 68 Impact — No eval scenarios have been run Securityby — The risk profile of this skill Version: 19392f7 | |
chief-data-officer-advisor .gemini/skills/skills-chief-data-officer-advisor/SKILL.md Chief Data Officer advisory for startups: AI training data rights and consent provenance, data product strategy (warehouse vs lakehouse vs mesh, build-vs-buy), B2B customer-data-as-asset valuation and M&A readiness, data team org evolution. Use when deciding whether to train models on customer data, choosing data architecture, valuing data for fundraising or M&A, sequencing data hires, or when user mentions CDO, chief data officer, data strategy, data mesh, lakehouse, training data, data product, data monetization, or customer data asset. NOT a tactical data engineering skill — strategic decisions only. | 69 69 Impact — No eval scenarios have been run Securityby — The risk profile of this skill Version: 19392f7 | |
chief-customer-officer-advisor .gemini/skills/skills-chief-customer-officer-advisor/SKILL.md Chief Customer Officer advisory for startups: retention decomposition (gross retention vs NRR honesty, churn root-cause taxonomy), customer segmentation strategy (differential investment across tiers + ICP fit scoring), CS team coverage model (pooled vs named CSM thresholds + ratio math), and CS team org evolution (CS vs Support vs AM distinctions). Use when designing retention strategy, segmenting customers for differential investment, sizing CS team, or sequencing CS hires. Strategic only — does not duplicate engineering/business-growth tactical skills. | 68 68 Impact — No eval scenarios have been run Securityby — The risk profile of this skill Version: 19392f7 | |
chief-ai-officer-advisor .gemini/skills/skills-chief-ai-officer-advisor/SKILL.md Chief AI Officer advisory for startups: model build-vs-buy decisions (API vs fine-tune vs in-house), AI risk classification under EU AI Act + US state patchwork, AI cost economics (API-to-self-hosted breakeven), and AI team org evolution. Use when deciding whether to call an API or fine-tune, classifying AI use cases for regulatory risk, calculating when self-hosting pays off, sequencing AI hires, or when user mentions CAIO, AI strategy, model selection, foundation model, fine-tuning, EU AI Act, NIST AI RMF, AI governance, model risk, or AI economics. Strategic only — does not duplicate engineering AI/ML skills. | 68 68 Impact — No eval scenarios have been run Securityby — The risk profile of this skill Version: 19392f7 | |
chaos-engineering .gemini/skills/skills-chaos-engineering/SKILL.md Use when planning, running, or learning from chaos engineering experiments. Triggers on "chaos experiment", "fault injection", "gameday", "resilience test", "blast radius", "steady state", "abort criteria", "Chaos Toolkit", "Chaos Mesh", "Litmus", "Gremlin", "AWS FIS", or any deliberate failure-injection question. Ships experiment designer, blast-radius calculator, and postmortem generator (all stdlib Python), 4 references on chaos principles + experiment design + attack taxonomy + tooling landscape, and a /chaos-experiment slash command. Composes with feature-flags-architect (kill switches as abort triggers) and kubernetes-operator (common chaos targets). | 72 72 Impact — No eval scenarios have been run Securityby — The risk profile of this skill Version: 19392f7 | |
arquiteto-de-empresa .gemini/skills/skills-arquiteto-de-empresa/SKILL.md Company Architect: builds a business from scratch as an OKF (Open Knowledge Format) bundle — a tree of version-controllable .md files with frontmatter type, links forming a graph, and reserved index.md/log.md, readable by humans and agents. Guides the founder through a 12-phase interview (foundation, strategy, market, financial, sales, marketing, product, operations, tech, people, legal, governance), one phase at a time, few questions per block, and generates the concepts as conformant markdown. Trigger when the user wants to create, structure, or document an entire company in folders and .md files; when they mention build my company from scratch, company as code, company knowledge base for AI to read, company wiki for agents, OKF, or knowledge bundle. In English. | 72 72 Impact — No eval scenarios have been run Securityby — The risk profile of this skill Version: 19392f7 | |
skillopt-sleep .gemini/skills/skillopt-sleep/SKILL.md Use when the user wants their Claude agent to self-improve from past usage, asks about a nightly/offline 'sleep' or 'dream' cycle, memory/skill consolidation, or says things like 'make my agent better the more I use it', 'review my past sessions', 'learn my preferences', 'consolidate what you learned', 'run the sleep cycle', or wants to schedule offline self-optimization. Drives the skillopt_sleep engine: harvest past sessions -> mine recurring tasks -> replay offline -> consolidate validated CLAUDE.md and SKILL.md behind a held-out gate. | 76 76 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 19392f7 | |
skill-tester .gemini/skills/skill-tester/SKILL.md Validate, test, and score the quality of skills within the claude-skills ecosystem. Comprehensive meta-skill: structure validation, Python script testing (syntax + imports + runtime + output format), multi-dimensional quality scoring with letter grades and tier classification (BASIC/STANDARD/POWERFUL). Use when authoring a new skill, auditing existing skills for tier promotion, setting up pre-commit hooks for skill quality, or integrating skill QA into CI. | 72 72 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 19392f7 | |
skill-security-auditor .gemini/skills/skill-security-auditor/SKILL.md Security audit and vulnerability scanner for AI agent skills before installation. Use when: (1) evaluating a skill from an untrusted source, (2) auditing a skill directory or git repo URL for malicious code, (3) pre-install security gate for Claude Code plugins, OpenClaw skills, or Codex skills, (4) scanning Python scripts for dangerous patterns like os.system, eval, subprocess, network exfiltration, (5) detecting prompt injection in SKILL.md files, (6) checking dependency supply chain risks, (7) verifying file system access stays within skill boundaries. Triggers: "audit this skill", "is this skill safe", "scan skill for security", "check skill before install", "skill security check", "skill vulnerability scan". | 70 70 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 19392f7 | |
skill-doctor .gemini/skills/skill-doctor/SKILL.md Use when the user wants their agent setup graded from real conversation history, asks which installed skills are actually working, or wants evidence-backed skill edits — scores recent local Claude Code / Codex sessions against efficiency and code-quality rubrics, then drafts skill changes gated by a deterministic aggregator and renders one local shareable report. | 76 76 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 19392f7 | |
site-architecture .gemini/skills/site-architecture/SKILL.md When the user wants to audit, redesign, or plan their website's structure, URL hierarchy, navigation design, or internal linking strategy. Use when the user mentions 'site architecture,' 'URL structure,' 'internal links,' 'site navigation,' 'breadcrumbs,' 'topic clusters,' 'hub pages,' 'orphan pages,' 'silo structure,' 'information architecture,' or 'website reorganization.' Also use when someone has SEO problems and the root cause is structural (not content or schema). NOT for content strategy decisions about what to write (use content-strategy) or for schema markup (use schema-markup). | 68 68 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 19392f7 | |
signup-flow-cro .gemini/skills/signup-flow-cro/SKILL.md When the user wants to optimize signup, registration, account creation, or trial activation flows. Also use when the user mentions "signup conversions," "registration friction," "signup form optimization," "free trial signup," "reduce signup dropoff," or "account creation flow." For post-signup onboarding, see onboarding-cro. For lead capture forms (not account creation), see form-cro. | 65 65 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 19392f7 | |
ship-gate .gemini/skills/ship-gate/SKILL.md Pre-production audit that scans a codebase for security, database, deployment, code quality, AI/LLM, dependency, frontend, and observability issues. Intercepts deploy commands and blocks until critical items pass. Stack-agnostic. Use for "run ship gate", "am I ready to ship", "pre-launch audit", "can I deploy", "push to production", "go live checklist", "preflight check". Not for CI/CD setup or infra provisioning. | 68 68 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 19392f7 | |
setup .gemini/skills/setup/SKILL.md Set up a new autoresearch experiment interactively. Collects domain, target file, eval command, metric, direction, and evaluator. Use when the user runs /ar:setup or asks to start optimizing a file with the autoresearch loop. | 67 67 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 19392f7 | |
seo-auditor .gemini/skills/seo-auditor/SKILL.md Scan and optimize documentation files for SEO. Audits README.md files and docs/ pages for meta tags, headings, keywords, readability, duplicate content, and broken links. Applies fixes, updates sitemap.xml, and generates a report. Usage: /seo-auditor [path] | 60 60 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 19392f7 | |
seo-audit .gemini/skills/seo-audit/SKILL.md When the user wants to audit, review, or diagnose SEO issues on their site. Also use when the user mentions "SEO audit," "technical SEO," "why am I not ranking," "SEO issues," "on-page SEO," "meta tags review," or "SEO health check." For building pages at scale to target keywords, see programmatic-seo. For adding structured data, see schema-markup. | 57 57 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 19392f7 | |
senior-security .gemini/skills/senior-security/SKILL.md Use when the user asks for STRIDE threat modeling, DREAD risk scoring, data-flow-diagram threat analysis, or a quick secret scan — or when a security request needs routing to the right specialist skill (pen-testing, incident response, cloud posture, red team, AI security, threat hunting, secure code review). This skill owns threat modeling; everything else routes to a sibling. | 76 76 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 19392f7 | |
senior-secops .gemini/skills/senior-secops/SKILL.md Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. Runs SAST/DAST scans, generates CVE remediation plans, checks dependency vulnerabilities, creates security policies, enforces secure coding patterns, and automates compliance checks against SOC2, PCI-DSS, HIPAA, and GDPR. Use when conducting a security review or audit, responding to a CVE or security incident, hardening infrastructure, implementing authentication or secrets management, running penetration test prep, checking OWASP Top 10 exposure, or enforcing security controls in CI/CD pipelines. | 72 72 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 19392f7 | |
senior-qa .gemini/skills/senior-qa/SKILL.md Generates unit tests, integration tests, and E2E tests for React/Next.js applications. Scans components to create Jest + React Testing Library test stubs, analyzes Istanbul/LCOV coverage reports to surface gaps, scaffolds Playwright test files from Next.js routes, mocks API calls with MSW, creates test fixtures, and configures test runners. Use when the user asks to "generate tests", "write unit tests", "analyze test coverage", "scaffold E2E tests", "set up Playwright", "configure Jest", "implement testing patterns", or "improve test quality". | 68 68 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 19392f7 | |
senior-prompt-engineer .gemini/skills/senior-prompt-engineer/SKILL.md Use when the user asks to optimize prompts, design prompt templates, evaluate LLM outputs with an eval set, measure RAG retrieval quality, validate agent/tool configurations, analyze token usage, or design structured-output contracts. Covers eval-driven prompt iteration, RAG metrics (relevance, faithfulness, coverage), agent workflow validation, and token/cost budgeting — all model-agnostic, with three stdlib Python tools. | 72 72 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 19392f7 | |
senior-pm .gemini/skills/senior-pm/SKILL.md Senior Project Manager for enterprise software, SaaS, and digital transformation projects. Specializes in portfolio management, quantitative risk analysis, resource optimization, stakeholder alignment, and executive reporting. Uses advanced methodologies including EMV analysis, Monte Carlo simulation, WSJF prioritization, and multi-dimensional health scoring. Use when a user needs help with project plans, project status reports, risk assessments, resource allocation, project roadmaps, milestone tracking, team capacity planning, portfolio health reviews, program management, or executive-level project reporting — especially for enterprise-scale initiatives with multiple workstreams, complex dependencies, or multi-million dollar budgets. | 62 62 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 19392f7 |