github.com/zebbern/claude-code-guide
| Skill | Added | Review |
|---|---|---|
playwright-ci skills/playwright/ci/SKILL.md Production-ready CI/CD configurations for Playwright — GitHub Actions, GitLab CI, CircleCI, Azure DevOps, Jenkins, Docker, parallel sharding, reporting, code coverage, and global setup/teardown. | 62 62 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: a2e6ee3 | |
playwright-cli skills/playwright/playwright-cli/SKILL.md Automates browser interactions for web testing, form filling, screenshots, and data extraction using playwright-cli. Use when the user needs to navigate websites, interact with web pages, fill forms, take screenshots, test web applications, extract information from web pages, mock network requests, manage browser sessions, or generate test code. | 69 69 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a2e6ee3 | |
playwright-core skills/playwright/core/SKILL.md Battle-tested Playwright patterns for E2E, API, component, visual, accessibility, and security testing. Covers locators, assertions, fixtures, network mocking, auth flows, debugging, and framework recipes for React, Next.js, Vue, and Angular. TypeScript and JavaScript. | 62 62 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a2e6ee3 | |
playwright-migration skills/playwright/migration/SKILL.md Step-by-step migration guides for moving to Playwright from Cypress or Selenium/WebDriver — command mappings, architecture changes, and incremental adoption strategies. | 69 69 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a2e6ee3 | |
playwright-pom skills/playwright/pom/SKILL.md Page Object Model patterns for Playwright — when to use POM, how to structure page objects, and when fixtures or helpers are a better fit. | 52 52 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a2e6ee3 | |
playwright-skill skills/playwright/SKILL.md Battle-tested Playwright patterns for E2E, API, component, visual, accessibility, and security testing. Covers locators, fixtures, POM, network mocking, auth flows, debugging, CI/CD (GitHub Actions, GitLab, CircleCI, Azure, Jenkins), framework recipes (React, Next.js, Vue, Angular), and migration guides from Cypress/Selenium. TypeScript and JavaScript. | 57 57 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: a2e6ee3 | |
privilege-escalation-methods skills/privilege-escalation-methods/SKILL.md This skill should be used when the user asks to "escalate privileges", "get root access", "become administrator", "privesc techniques", "abuse sudo", "exploit SUID binaries", "Kerberoasting", "pass-the-ticket", "token impersonation", or needs guidance on post-exploitation privilege escalation for Linux or Windows systems. | 61 61 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a2e6ee3 | |
project-sizing-guide skills/project-sizing-guide/SKILL.md Software project effort estimation assistant. Outputs three-point estimates (optimistic/most-likely/pessimistic values with confidence intervals), T-shirt sizes, or Function Point Analysis (FPA) counts. Triggered when users ask 'how long will this feature take,' need to assess project workload, perform PERT estimation, T-shirt sizing, FPA, sprint planning, or quote-based effort breakdowns. | 70 70 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a2e6ee3 | |
r2-upload skills/r2-upload/SKILL.md Upload files to Cloudflare R2, AWS S3, or any S3-compatible storage (like MinIO) and generate secure, time-limited presigned download links with configurable expiration, typically set to 5 minutes. Use when the user needs to upload a file to cloud storage and get a shareable link, or mentions R2, S3, presigned URLs, temporary links, or file uploads with expiration. | 69 69 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a2e6ee3 | |
r3f-animation skills/r3f-animation/SKILL.md React Three Fiber animation - useFrame, useAnimations, spring physics, keyframes. Use when animating objects, playing GLTF animations, creating procedural motion, or implementing physics-based movement. | 62 62 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a2e6ee3 | |
r3f-best-practices skills/r3f-best-practices/SKILL.md React Three Fiber (R3F) and Poimandres ecosystem best practices. Use when writing, reviewing, or optimizing R3F code. Triggers on tasks involving @react-three/fiber, @react-three/drei, zustand, @react-three/postprocessing, @react-three/rapier, or leva. | 60 60 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a2e6ee3 | |
red-team-tools skills/red-team-tools/SKILL.md This skill should be used when the user asks to "follow red team methodology", "perform bug bounty hunting", "automate reconnaissance", "hunt for XSS vulnerabilities", "enumerate subdomains", or needs security researcher techniques and tool configurations from top bug bounty hunters. | 60 60 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a2e6ee3 | |
regression-modeler skills/regression-modeler/SKILL.md Run regression analysis (OLS or logistic) on uploaded CSV/Excel data, generating coefficients, R², p-values, VIF, and plain-language interpretation. Triggered by requests for regression modeling, fitting data, testing significance, checking multicollinearity, or keywords like OLS, logit, coefficient, p-value, or R-squared. | 70 70 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: a2e6ee3 | |
regulatory-audit-generator skills/regulatory-audit-generator/SKILL.md Builds compliance checklists for business scenarios involving GDPR, PIPL, or advertising/data laws. Outputs a structured checklist with check items, legal basis, risk levels, and actionable recommendations. Triggered by requests like "run a compliance check," "GDPR/PIPL compliance," "pre-launch review," "privacy impact assessment (PIA/DPIA)," or asking if a feature is compliant. | 66 66 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a2e6ee3 | |
repo-audit skills/repo-audit/SKILL.md Deep analysis of Git history: identify frequently changed hotspot files, analyze code ownership by contributor, and scan for leaked secrets. Triggered when users ask about Git analysis, code hotspots, who owns what code, secret scanning, security audits of commit history, or optimizing code review assignments. | 70 70 Impact — No eval scenarios have been run Securityby High Do not use without reviewing Version: a2e6ee3 | |
route-to-openapi skills/route-to-openapi/SKILL.md Generates RESTful API documentation (OpenAPI 3.0 / Swagger spec) by scanning route definitions in code for Flask, FastAPI, Express, Gin, and other frameworks. Trigger when users ask about API documentation, OpenAPI, Swagger, endpoint docs, generating docs from code, or extracting endpoints. | 70 70 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a2e6ee3 | |
scanning-tools skills/scanning-tools/SKILL.md This skill should be used when the user asks to "perform vulnerability scanning", "scan networks for open ports", "assess web application security", "scan wireless networks", "detect malware", "check cloud security", or "evaluate system compliance". It provides comprehensive guidance on security scanning tools and methodologies. | 53 53 Impact — No eval scenarios have been run Securityby High Do not use without reviewing Version: a2e6ee3 | |
scholarly-writing-refiner skills/scholarly-writing-refiner/SKILL.md Polishes academic English paragraph by paragraph, reviewing grammar, word choice, voice, coherence, and sentence structure. Outputs revision suggestions alongside polished text. Triggered by phrases like 'polish this paragraph,' 'check the grammar,' 'rewrite in academic English,' or keywords like manuscript editing, SCI polishing, and journal submission editing. | 67 67 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a2e6ee3 | |
secure-code-review skills/secure-code-review/SKILL.md Systematically reviews code for SQL injection, XSS, SSRF, broken access control, cryptographic failures, and other common OWASP Top 10 vulnerabilities, providing vulnerable code examples and ready-to-use remediation guidance. Trigger this skill when users ask for a security review, vulnerability scan, or penetration testing assistance, or mention keywords like OWASP, SQL injection, XSS, code audit, or security checklist. | 68 68 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a2e6ee3 | |
shodan-reconnaissance skills/shodan-reconnaissance/SKILL.md This skill should be used when the user asks to "search for exposed devices on the internet," "perform Shodan reconnaissance," "find vulnerable services using Shodan," "scan IP ranges with Shodan," or "discover IoT devices and open ports." It provides comprehensive guidance for using Shodan's search engine, CLI, and API for penetration testing reconnaissance. | 61 61 Impact — No eval scenarios have been run Securityby High Do not use without reviewing Version: a2e6ee3 |