github.com/zebbern/claude-code-guide
| Skill | Added | Review |
|---|---|---|
data-viz-renderer skills/data-viz-renderer/SKILL.md Generate self-contained HTML/SVG infographics from JSON data, including stat cards, bar charts, flow diagrams, and mixed dashboards. Offers 8 color palettes and built-in icons with no external dependencies. Triggered when users request data visualization, infographics, charts, or dashboards. | 71 71 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a2e6ee3 | |
deep-module-refactor skills/deep-module-refactor/SKILL.md Explore a codebase to find opportunities for architectural improvement, focusing on making the codebase more testable by deepening shallow modules. Use when user wants to improve architecture, find refactoring opportunities, consolidate tightly-coupled modules, or make a codebase more AI-navigable. | 64 64 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a2e6ee3 | |
design-system-builder skills/design-system-builder/SKILL.md Extract design systems from reference UI images and generate implementation-ready UI design prompts. Use when users provide UI screenshots/mockups and want to create consistent designs, generate design systems, or build MVP UIs matching reference aesthetics. | 61 61 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a2e6ee3 | |
dev-guide-generator skills/dev-guide-generator/SKILL.md Generates complete technical tutorials from prerequisites and environment setup to core steps, troubleshooting, and a final cheatsheet. Trigger on requests to write a tutorial, create a setup guide, organize steps for beginners, or keywords like step-by-step, quickstart, or how-to guide. | 66 66 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a2e6ee3 | |
ethical-hacking-methodology skills/ethical-hacking-methodology/SKILL.md This skill should be used when the user asks to "learn ethical hacking", "understand penetration testing lifecycle", "perform reconnaissance", "conduct security scanning", "exploit vulnerabilities", or "write penetration test reports". It provides comprehensive ethical hacking methodology and techniques. | 54 54 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a2e6ee3 | |
file-path-traversal skills/file-path-traversal/SKILL.md This skill should be used when the user asks to "test for directory traversal", "exploit path traversal vulnerabilities", "read arbitrary files through web applications", "find LFI vulnerabilities", or "access files outside web root". It provides comprehensive file path traversal attack and testing methodologies. | 58 58 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a2e6ee3 | |
html-injection-testing skills/html-injection-testing/SKILL.md This skill should be used when the user asks to "test for HTML injection", "inject HTML into web pages", "perform HTML injection attacks", "deface web applications", or "test content injection vulnerabilities". It provides comprehensive HTML injection attack techniques and testing methodologies. | 60 60 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a2e6ee3 | |
http-load-profiler skills/http-load-profiler/SKILL.md Run stepped HTTP load tests with ab/wrk, ramping concurrency levels to collect p50/p90/p99 latency, detect performance inflection points, and recommend optimal concurrency. Triggered by requests like 'load test this URL', 'benchmark my API', 'find the max concurrency', or mentions of p99 latency, throughput saturation, or capacity planning. | 66 66 Impact — No eval scenarios have been run Securityby Medium Suggest reviewing before use Version: a2e6ee3 | |
idor-testing skills/idor-testing/SKILL.md This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references," or "bypass authorization to access other users' data." It provides comprehensive guidance for detecting, exploiting, and remediating IDOR vulnerabilities in web applications. | 64 64 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a2e6ee3 | |
linux-privilege-escalation skills/linux-privilege-escalation/SKILL.md This skill should be used when the user asks to "escalate privileges on Linux", "find privesc vectors on Linux systems", "exploit sudo misconfigurations", "abuse SUID binaries", "exploit cron jobs for root access", "enumerate Linux systems for privilege escalation", or "gain root access from low-privilege shell". It provides comprehensive techniques for identifying and exploiting privilege escalation paths on Linux systems. | 61 61 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a2e6ee3 | |
linux-shell-scripting skills/linux-shell-scripting/SKILL.md This skill should be used when the user asks to "create bash scripts", "automate Linux tasks", "monitor system resources", "backup files", "manage users", or "write production shell scripts". It provides ready-to-use shell script templates for system administration. | 57 57 Impact — No eval scenarios have been run Securityby High Do not use without reviewing Version: a2e6ee3 | |
localization-toolkit skills/localization-toolkit/SKILL.md This skill should be used when setting up, auditing, or enforcing internationalization/localization in UI codebases (React/TS, i18next or similar, JSON locales), including installing/configuring the i18n framework, replacing hard-coded strings, ensuring en-US/zh-CN coverage, mapping error codes to localized messages, and validating key parity, pluralization, and formatting. | 72 72 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a2e6ee3 | |
log-error-digest skills/log-error-digest/SKILL.md Analyze log files to troubleshoot errors, identify peak error periods, and produce error clustering, frequency statistics, and time distribution reports. Supports JSON, syslog, and Nginx formats with automatic detection. Use when a user uploads a .log file and asks to analyze errors, find patterns, debug issues, or get distribution stats. | 74 74 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: a2e6ee3 | |
metasploit-framework skills/metasploit-framework/SKILL.md This skill should be used when the user asks to "use Metasploit for penetration testing", "exploit vulnerabilities with msfconsole", "create payloads with msfvenom", "perform post-exploitation", "use auxiliary modules for scanning", or "develop custom exploits". It provides comprehensive guidance for leveraging the Metasploit Framework in security assessments. | 64 64 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a2e6ee3 | |
network-101 skills/network-101/SKILL.md This skill should be used when the user asks to "set up a web server", "configure HTTP or HTTPS", "perform SNMP enumeration", "configure SMB shares", "test network services", or needs guidance on configuring and testing network services for penetration testing labs. | 60 60 Impact — No eval scenarios have been run Securityby Medium Suggest reviewing before use Version: a2e6ee3 | |
nextjs-developer skills/nextjs-developer/SKILL.md Use when building Next.js 14+ applications with App Router, server components, or server actions. Invoke for full-stack features, performance optimization, SEO implementation, production deployment. | 58 58 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a2e6ee3 | |
pdf skills/pdf/SKILL.md Use this skill whenever the user wants to do anything with PDF files. This includes reading or extracting text/tables from PDFs, combining or merging multiple PDFs into one, splitting PDFs apart, rotating pages, adding watermarks, creating new PDFs, filling PDF forms, encrypting/decrypting PDFs, extracting images, and OCR on scanned PDFs to make them searchable. If the user mentions a .pdf file or asks to produce one, use this skill. | 68 68 Impact — No eval scenarios have been run Securityby High Do not use without reviewing Version: a2e6ee3 | |
pentest-checklist skills/pentest-checklist/SKILL.md This skill should be used when the user asks to "plan a penetration test", "create a security assessment checklist", "prepare for penetration testing", "define pentest scope", "follow security testing best practices", or needs a structured methodology for penetration testing engagements. | 56 56 Impact — No eval scenarios have been run Securityby Medium Suggest reviewing before use Version: a2e6ee3 | |
pentest-commands skills/pentest-commands/SKILL.md This skill should be used when the user asks to "run pentest commands", "scan with nmap", "use metasploit exploits", "crack passwords with hydra or john", "scan web vulnerabilities with nikto", "enumerate networks", or needs essential penetration testing command references. | 62 62 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a2e6ee3 | |
pipeline-blueprint skills/pipeline-blueprint/SKILL.md Provide CI/CD best practices and pipeline templates for GitHub Actions and GitLab CI, recommending configurations based on project type (frontend, backend, fullstack, library, monorepo, mobile). Trigger when users ask about setting up CI/CD, automating builds, improving pipelines, or mention keywords like GitHub Actions, GitLab CI, pipeline templates, or deployment automation. | 63 63 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: a2e6ee3 |