github.com/santosomar/general-secure-coding-agent-skills
| Skill | Added | Review |
|---|---|---|
requirement-summary skills/requirements/requirement-summary/SKILL.md Alias for requirement-summarizer. Produces a structured summary of a requirements document — the key obligations, grouped by actor and concern, with the MUST/SHOULD/MAY breakdown. Use when onboarding to a large spec, when deciding what to implement first, or when the user asks what a standard actually requires. | 70 70 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
requirement-to-tlaplus-property-generator skills/verification/requirement-to-tlaplus-property-generator/SKILL.md Translates natural-language requirements into TLA+ properties — invariants for safety, temporal formulas for liveness — checkable with TLC. Use when writing the PROPERTY and INVARIANT sections of a TLA+ spec, when formalizing acceptance criteria, or when the user has a requirement and a model but no property. | 80 80 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
rollback-strategy-advisor skills/devops/rollback-strategy-advisor/SKILL.md Advises on rollback strategies by analyzing what a deploy changes — recommending revert, roll-forward, feature-flag kill, or data repair depending on reversibility. Use during an incident when a deploy went bad, when designing a deploy pipeline and the user asks how to make it reversible, or when a migration needs an undo plan. | 77 77 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
runtime-error-explainer skills/debugging/runtime-error-explainer/SKILL.md Translates cryptic runtime error messages and stack traces into understandable explanations, pointing to the concrete line at fault and the most likely fix. Use when a user pastes an error they don't understand, when a stack trace is deep and the user doesn't know where to start, or when an error message misleads about the real cause. | 80 80 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 47d56bb | |
scenario-generator skills/requirements/scenario-generator/SKILL.md Generates concrete scenarios from a requirement — happy paths, edge cases, and error conditions — expressed as Given/When/Then or equivalent structured narratives. Use when turning a requirement into acceptance tests, when exploring what could go wrong, or when the requirement is abstract and needs grounding. | 80 80 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
semantic-bug-detector skills/debugging/semantic-bug-detector/SKILL.md Detects logical and semantic bugs by understanding program intent — catches issues that syntax-only tools miss. Use when static analysis has already run and found nothing, when the user reports incorrect behavior but no crash, or when reviewing algorithmic code for correctness. | 76 76 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
semantic-equivalence-verifier skills/code-quality/semantic-equivalence-verifier/SKILL.md Proves two program fragments semantically equivalent using symbolic reasoning — stronger than testing, applicable when differential testing is insufficient or impossible. Use when behavior preservation must be proven rather than sampled, when the input space is too large to enumerate, or when a transformation needs a correctness argument. | 75 75 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
semantic-szz-analyzer skills/debugging/semantic-szz-analyzer/SKILL.md Extends classic SZZ with semantic code understanding to reduce false positives and improve accuracy of bug-introducing commit identification. Use after classic SZZ has produced candidates, when SZZ precision is too low for the task, or when the user needs high-confidence bug-introduction data. | 68 68 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
smart-mutation-operator-generator skills/testing/smart-mutation-operator-generator/SKILL.md Generates domain-specific mutation operators beyond the standard arithmetic/relational set — mutations tailored to your codebase's idioms, APIs, and bug history that standard tools don't try. Use when generic mutation testing plateaus, when your domain has specific failure modes, or when mining bug history reveals patterns standard operators miss. | 72 72 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
smv-model-extractor skills/verification/smv-model-extractor/SKILL.md Extracts an SMV (NuSMV/nuXmv) finite-state model from code or state-machine descriptions, for CTL/LTL model checking of reactive systems. Use when verifying hardware-adjacent or embedded logic, when the state space is naturally finite and small, or when CTL branching-time properties are needed. | 71 71 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
specification-to-temporal-logic-generator skills/verification/specification-to-temporal-logic-generator/SKILL.md Translates specifications into temporal logic formulas (LTL, CTL, or TLA) by matching the specification's shape to the right logic and operators. Use when formalizing requirements for any model checker, when choosing between LTL and CTL for a property, or when the user has a temporal claim and doesn't know which operators express it. | 80 80 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
spring-mvc-to-boot-migrator skills/code-analysis/spring-mvc-to-boot-migrator/SKILL.md Migrates a Spring MVC application to Spring Boot, converting XML config to auto-configuration, restructuring the project, and replacing container deployment with embedded. Use when modernizing a legacy Spring app, when moving off a standalone servlet container, or when the user has web.xml and wants application.yml. | 84 84 1.22x Agent success vs baseline Impact 92% 1.22xAverage score across 1 eval scenario Securityby Passed No findings from the security scan Reviewed: Version: 47d56bb | |
static-bug-detector skills/debugging/static-bug-detector/SKILL.md Identifies bugs through static code analysis (null dereferences, type mismatches, control flow issues) without executing the program. Use when scanning code for defects before running tests, when the user asks for static analysis, or when integrating with CI for defect detection. | 80 80 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
static-vulnerability-detector skills/security/static-vulnerability-detector/SKILL.md Scans source code for security vulnerabilities by applying Project CodeGuard rules — injection, unsafe deserialization, XSS, path traversal, broken access control. Use when performing a security audit, when reviewing a PR that touches request handlers or database queries, when the user asks for a vulnerability scan, or when wiring security checks into CI. | 71 71 Impact — No eval scenarios have been run Securityby High Do not use without reviewing Version: 47d56bb | |
szz-bug-identifier skills/debugging/szz-bug-identifier/SKILL.md Applies the SZZ algorithm to VCS history to identify which commits introduced bugs by correlating bug-fix commits with earlier changes. Use when mining a repository for bug-introducing commits, when building a defect-prediction dataset, or when the user asks which commit introduced a given fixed bug. | 77 77 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
taint-instrumentation-assistant skills/security/taint-instrumentation-assistant/SKILL.md Sets up taint tracking by defining sources, sinks, and sanitizers from Project CodeGuard's input-validation taxonomy, then configures the target tool (CodeQL, Semgrep, custom instrumentation). Use when wiring taint analysis into CI, when the user asks for taint tracking, or when you need a source/sink catalog for a specific language. | 75 75 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 47d56bb | |
technical-debt-analyzer skills/code-quality/technical-debt-analyzer/SKILL.md Analyzes a codebase to quantify and locate technical debt — where it lives, what it costs, and what order to pay it down in. Use when planning a refactoring sprint, when justifying engineering time to stakeholders, when the user asks where the codebase hurts most, or when onboarding to a legacy system. | 80 80 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
test-case-documentation skills/testing/test-case-documentation/SKILL.md Writes documentation for test cases — names, docstrings, and comments that explain what behavior is being tested and why, so a failing test tells you what broke without reading the assertion. Use when test names are test_1 through test_47, when tests fail and nobody knows what they mean, or when onboarding needs a readable test suite. | 80 80 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
test-case-reducer skills/testing/test-case-reducer/SKILL.md Shrinks a failing test input to its minimal form while preserving the failure — delta debugging and structured shrinking to find the smallest input that still triggers the bug. Use when a fuzzer or property test finds a failure with a huge input, when a bug report has an unwieldy reproduction, or when you need a minimal test case for a regression suite. | 80 80 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
test-deduplicator skills/testing/test-deduplicator/SKILL.md Finds and removes redundant tests — tests that cover the same code, kill the same mutants, or assert the same behavior — to shrink suite runtime without losing coverage. Use when the test suite is slow, when tests have accumulated over years of copy-paste, or when CI costs are too high. | 77 77 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb |