github.com/modu-ai/moai-adk
| Skill | Added | Review |
|---|---|---|
moai-foundation-context .moai/archive/skills/v3.0/moai-foundation-context/SKILL.md Manages context window optimization, session state persistence, and token budget allocation for multi-agent workflows. Use for token budget management, context limits, or session handoff across agents. | 55 55 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 2213871 | |
moai-foundation-core .claude/skills/moai-foundation-core/SKILL.md Provides MoAI-ADK foundational principles including TRUST 5 quality framework, SPEC-First DDD methodology, delegation patterns, progressive disclosure, agent catalog reference, and token budget management (absorbed from moai-foundation-context). Use when referencing TRUST 5 gates, SPEC workflow, or context window optimization. | 59 59 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 2213871 | |
moai-foundation-philosopher .moai/archive/skills/v3.0/moai-foundation-philosopher/SKILL.md Strategic thinking framework integrating First Principles Analysis, Stanford Design Thinking, and MIT Systems Engineering for deeper problem-solving. Use for architecture decisions or root cause analysis. | 56 56 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 2213871 | |
moai-foundation-quality .claude/skills/moai-foundation-quality/SKILL.md TRUST 5 quality principles and how MoAI enforces them through agents, the 3-level harness, /moai gate, and sync-auditor scoring. Use for code review, quality gate checks, coverage targets, or TRUST 5 compliance. | 60 60 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 2213871 | |
moai-foundation-thinking .claude/skills/moai-foundation-thinking/SKILL.md Unified thinking toolkit: Creative frameworks (Critical Evaluation, Diverge-Converge, Deep Questioning), First Principles reasoning (absorbed from moai-foundation-philosopher), and Adaptive Thinking via the `ultrathink` keyword. Use for ideation, strategic analysis, architecture decisions, and deep reasoning on complex problems. | 59 59 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 2213871 | |
moai-harness-learner .claude/skills/moai-harness-learner/SKILL.md Harness learning subsystem coordinator. Produces Tier 4 auto-update proposal payloads consumed by the orchestrator (which surfaces them via AskUserQuestion) and orchestrates Apply/Rollback flows. Triggers when harness learning proposals are pending or learning lifecycle management is needed. | 57 57 Impact — No eval scenarios have been run Securityby High Do not use without reviewing Version: 2213871 | |
moai-kanban-foreman .claude/skills/moai-kanban-foreman/SKILL.md One unattended kanban foreman iteration: watch the backlog queue, dispatch the next operator-picked card to an isolated worker, collect completion evidence on read (not on claims), and report. This is the body the project's loop.md driver invokes each iteration of a bare /loop; it can also be invoked directly to test one cycle by hand. | 64 64 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 2213871 | |
moai-meta-harness .claude/skills/moai-meta-harness/SKILL.md DEPRECATED — legacy 7-Phase meta-harness. Redirects to the v4 harness Builder (/moai:harness <natural-language request>) which replaces the static 7-Phase workflow with an orchestrator-direct 4-phase Builder (ANALYZE / PLAN / GENERATE / ACTIVATE) + a manifest-driven dynamic-workflow Runner. Retained as the redirect source for backward-compat invocation paths; the 7-Phase body below is preserved as historical reference, NOT for new harness creation. | 49 49 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 2213871 | |
moai-platform-auth .moai/archive/skills/v2.16/moai-platform-auth/SKILL.md Authentication and authorization specialist covering Auth0, Clerk, and Firebase Auth. Use when implementing authentication, MFA, SSO, passkeys, WebAuthn, social login, or security features. | 55 55 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 2213871 | |
moai-platform-database-cloud .moai/archive/skills/v3.0/moai-platform-database-cloud/SKILL.md Cloud database platform specialist covering Neon (serverless PostgreSQL), Supabase (PostgreSQL 16 with real-time), and Firebase Firestore (NoSQL with offline sync). Use when choosing or setting up cloud databases. | 49 49 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 2213871 | |
moai-ref-api-patterns .claude/skills/moai-ref-api-patterns/SKILL.md REST/GraphQL API design patterns, error handling conventions, and input validation reference for backend development. Agent-extending skill that amplifies backend domain work (spawned via Agent(general-purpose) with backend instructions) with production-grade API patterns. Use when designing APIs, implementing endpoints, or reviewing backend code. NOT for: frontend development, DevOps, database schema design, security audits. | 69 69 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 2213871 | |
moai-ref-cross-model-audit .claude/skills/moai-ref-cross-model-audit/SKILL.md Cross-model audit convergence reference for the plan-auditor and sync-auditor agents. Documents how to invoke the `audit_multi` MCP tool to fan a code review out across the codex and GLM (z.ai) backends in parallel, converge their verdicts with the in-session Claude verdict, and fold the resulting per-backend verdicts + disagreement flag into the audit output. The single skill both audit entry points load — no duplication. | 64 64 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 2213871 | |
moai-ref-git-workflow .claude/skills/moai-ref-git-workflow/SKILL.md Git workflow patterns, branch strategies, conventional commits, and PR templates reference for git operations. Agent-extending skill that amplifies manager-git expertise with production-grade git workflow patterns. NOT for: code implementation, testing, architecture design, documentation content. | 64 64 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 2213871 | |
moai-ref-llm-security .claude/skills/moai-ref-llm-security/SKILL.md AI/LLM defensive security reference: prompt-injection defense, OWASP LLM Top 10 defensive mapping, MCP and agentic tool-call hardening, training-data poisoning detection, model-output validation and guardrails, MITRE ATLAS defensive correlation, and NIST AI RMF governance. Agent-extending skill that amplifies backend, security, and AI-application engineering with production-grade defensive patterns for LLM-backed systems. NOT for: offensive techniques (jailbreak authoring, attack-payload crafting, red-team exploitation), model training or fine-tuning methodology, prompt optimization for capability, web-app OWASP Top 10 (see moai-ref-owasp-checklist), or general API design (see moai-ref-api-patterns). | 69 69 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 2213871 | |
moai-ref-owasp-checklist .claude/skills/moai-ref-owasp-checklist/SKILL.md OWASP Top 10 security checklist, authentication patterns, input validation, and HTTP security headers reference. Agent-extending skill that amplifies backend-implementation and security-audit workflows with production-grade security patterns. NOT for: frontend UI, DevOps deployment, performance optimization, testing strategy. | 58 58 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 2213871 | |
moai-ref-react-patterns .claude/skills/moai-ref-react-patterns/SKILL.md React/Next.js component design patterns, state management strategies, and project structure reference for frontend development. Agent-extending skill that amplifies frontend domain work (spawned via Agent(general-purpose) with frontend instructions) with production-grade React patterns. NOT for: backend API design, database modeling, DevOps, mobile apps. | 65 65 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 2213871 | |
moai-ref-secops .claude/skills/moai-ref-secops/SKILL.md DevSecOps, container, and API operational defensive security reference: CI/CD pipeline hardening, secret scanning, IaC misconfiguration detection, SAST/DAST integration, container image scanning, Kubernetes RBAC hardening, container-escape defense, runtime threat detection, OWASP API Top 10 operational defense, WAF rule tuning, and GraphQL/REST depth and rate limiting. Agent-extending skill that amplifies backend, security, and platform-engineering work with production-grade defensive patterns for pipelines, containers, and running APIs. NOT for: offensive techniques (exploit execution, container-escape attack steps, privilege-escalation procedures, attack tooling), dev-time web-app OWASP Top 10 (see moai-ref-owasp-checklist), LLM/AI security (see moai-ref-llm-security), supply-chain provenance and signing (see moai-ref-supply-chain), or general API design (see moai-ref-api-patterns). | 57 57 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 2213871 | |
moai-ref-seo .claude/skills/moai-ref-seo/SKILL.md Search-visibility and crawlability reference for web output: canonical URL discipline, per-page title and meta description uniqueness, robots.txt and sitemap.xml as host-derived artifacts, JSON-LD structured data with entity consistency, and the document-semantics rules that decide whether a machine can read a page at all. Agent-extending skill that amplifies web-output implementation and pre-ship review with production-grade indexing and structured-data patterns. NOT for: keyboard operability, visible focus indicators, and form-control labeling (accessibility owns those; delegated to the accessibility surface); generative-engine optimization, deliberately excluded as insufficiently settled; visual polish and interface detail (see moai-ref-ui-polish); API contract design (see moai-ref-api-patterns); security headers and hardening (see moai-ref-owasp-checklist and moai-ref-secops). | 61 61 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 2213871 | |
moai-ref-supply-chain .claude/skills/moai-ref-supply-chain/SKILL.md Software supply-chain defensive security reference: SBOM generation and verification (SPDX / CycloneDX), dependency-confusion defense, malicious-package triage playbook, SLSA provenance levels, Sigstore / cosign signing and verification, package-registry hardening, typosquatting defense, and transitive-dependency auditing. Agent-extending skill that amplifies backend, security, and release-engineering work with production-grade defensive patterns for the software supply chain. NOT for: offensive techniques (dependency-confusion attack execution, malicious package authoring, registry exploitation), LLM/AI-specific security (see moai-ref-llm-security), web-app OWASP Top 10 (see moai-ref-owasp-checklist), or general API design (see moai-ref-api-patterns). | 56 56 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 2213871 | |
moai-ref-testing-pyramid .claude/skills/moai-ref-testing-pyramid/SKILL.md Test pyramid strategy, coverage targets, test patterns, and quality metrics reference. Agent-extending skill that amplifies manager-develop test-creation and quality-validation work with production-grade testing patterns. NOT for: production code implementation, architecture design, DevOps, security audits. | 56 56 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 2213871 |