github.com/santosomar/general-secure-coding-agent-skills
| Skill | Added | Review |
|---|---|---|
abstract-invariant-generator skills/verification/abstract-invariant-generator/SKILL.md Generates abstract invariants using domain abstraction — intervals, octagons, polyhedra, sign domains — to find invariants that concrete reasoning misses. Use when standard invariant inference fails, when the invariant involves relationships between multiple variables, or when verifying numerical code. | 75 75 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
ambiguity-detector skills/requirements/ambiguity-detector/SKILL.md Detects ambiguity in natural-language requirements — weak words, dangling references, underspecified quantities, conflicting interpretations — before they become implementation bugs. Use when reviewing requirements, when a spec uses words like "appropriate" or "fast", or when two engineers read the same requirement and built different things. | 80 80 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
api-design-assistant skills/code-quality/api-design-assistant/SKILL.md Reviews and designs API contracts — function signatures, REST endpoints, library interfaces — for usability, evolvability, and the principle of least surprise. Use when designing a new public interface, when reviewing an API PR, when the user asks whether a signature is well-designed, or when planning a breaking change. | 80 80 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
behavior-preservation-checker skills/code-quality/behavior-preservation-checker/SKILL.md Verifies that a refactoring or transformation preserved observable behavior by comparing before and after execution, differential testing, or I/O capture. Use after a refactoring, after automated code transformation, before merging a structural PR, or whenever the claim is that two code versions do the same thing. | 77 77 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
bug-localization skills/debugging/bug-localization/SKILL.md Pinpoints the exact file, function, or line in a codebase responsible for a reported bug using static and dynamic analysis signals. Use when a bug is reported but the fault location is unknown, when narrowing down a failure to a specific code region, when triaging an issue tracker ticket, or when the user asks to locate where a bug originates. | 80 80 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
bug-reproduction-test-generator skills/debugging/bug-reproduction-test-generator/SKILL.md Creates minimal, reproducible test cases from bug reports to confirm the defect before and after a fix. Use when a bug is reported without a failing test, when the user needs a regression test for a fix, or when the user asks to reproduce a bug as a test. | 80 80 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
bug-to-patch-generator skills/debugging/bug-to-patch-generator/SKILL.md Automatically synthesizes code patches to fix identified bugs, leveraging the bug location and surrounding context. Use when a bug has been localized and the user wants an automated fix, when generating candidate patches for review, or when the user asks to fix a specific bug. | 74 74 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
build-ci-migration-assistant skills/devops/build-ci-migration-assistant/SKILL.md Assists migrating a build or CI pipeline from one system to another — Jenkins to GitHub Actions, Travis to GitLab CI, Makefile to Bazel — preserving semantics and surfacing untranslatable constructs. Use when switching CI providers, when modernizing a legacy build, or when the user pastes a Jenkinsfile and asks for the GitHub Actions equivalent. | 80 80 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
c-cpp-to-lean4-translator skills/verification/c-cpp-to-lean4-translator/SKILL.md Translates C/C++ into Lean 4 for interactive theorem proving — deep verification where automated tools fail. Use when Dafny's automation isn't enough, when proving mathematical properties of an algorithm, or when building a machine-checked proof for publication or certification. | 74 74 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
cd-pipeline-generator skills/devops/cd-pipeline-generator/SKILL.md Generates deployment pipelines with environment promotion, approval gates, and rollback triggers based on target infrastructure. Use when wiring automated deployments from CI to staging/production, when the user asks for a release pipeline, or when adding promotion gates to an existing deploy workflow. | 77 77 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
change-log-generator skills/devops/change-log-generator/SKILL.md Generates a structured CHANGELOG.md from VCS history and PR/issue references, categorized by change type. Use when cutting a release, when the user asks to update CHANGELOG.md, or when backfilling a changelog from git history. | 80 80 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
ci-pipeline-synthesizer skills/devops/ci-pipeline-synthesizer/SKILL.md Generates CI pipeline configs by analyzing a repo's structure, language, and build needs — GitHub Actions, GitLab CI, or other platforms. Use when bootstrapping CI for a new repo, when porting from one CI to another, when the user asks for a pipeline that builds and tests their project, or when wiring in security gates. | 80 80 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
code-comment-generator skills/code-analysis/code-comment-generator/SKILL.md Generates code comments that explain non-obvious intent, constraints, and tradeoffs — not what the code already says. Use when code is correct but opaque, when documenting for future maintainers, or when a function's why is harder to see than its what. | 75 75 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
code-optimizer skills/code-quality/code-optimizer/SKILL.md Optimizes code for performance by identifying the actual bottleneck, choosing the right optimization lever, and measuring the result. Use when a specific operation is too slow, when a profiler has pointed at a hot path, or when the user asks to make something faster. | 80 80 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
code-pattern-extractor skills/code-analysis/code-pattern-extractor/SKILL.md Identifies recurring structural patterns in a codebase — idioms, copy-paste clones, homegrown abstractions — and characterizes each as a reusable template. Use when learning a codebase's conventions, when hunting for copy-paste that should be a function, or when documenting how this team does things. | 80 80 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
code-refactoring-assistant skills/code-quality/code-refactoring-assistant/SKILL.md Executes refactorings — extract method, inline, rename, move — in small, behavior-preserving steps with a test between each. Use when the user wants to restructure working code, when cleaning up after a feature lands, or when a smell has been identified and needs fixing. | 77 77 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
code-review-assistant skills/code-quality/code-review-assistant/SKILL.md Performs structured code review on a diff or file set, producing inline comments with severity levels and a summary. Checks correctness, error handling, security, and maintainability — in that priority order. Use when reviewing a pull request, when the user asks for a code review, when preparing code for merge, or when a second opinion is needed on a change. | 72 72 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
code-search-assistant skills/code-analysis/code-search-assistant/SKILL.md Finds code by meaning, structure, or text across large codebases — picks the right search strategy (grep, AST query, call graph walk, semantic search) for the question being asked. Use when the user asks where something is implemented, when navigating unfamiliar code, or when a simple grep isn't enough. | 80 80 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
code-smell-detector skills/code-quality/code-smell-detector/SKILL.md Identifies code smells — structural patterns that correlate with maintainability problems — and explains why each matters in context. Use when reviewing a PR for structural quality, when the user asks what's wrong with a piece of code that isn't buggy, or when prioritizing refactoring targets. | 80 80 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
code-summarizer skills/code-analysis/code-summarizer/SKILL.md Produces natural-language summaries of what code does at the function, class, module, or subsystem level, with length and abstraction scaled to the scope. Explains purpose, side effects, and non-obvious behavior rather than restating syntax. Use when onboarding to unfamiliar code, when the user asks what something does, when generating docstrings or architecture notes, or when preparing a handoff document. | 80 80 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb |