Skill Claude CodeCodex
Review drafts for clarity, structure, evidence quality, and reader usefulness against the project's writing rules. Use when a draft needs a structured review pass before publishing.
Spec-driven development framework — AI agents that think before they type
This repository also configures its own agents. See what paqad-ai tells them →
Skill Claude CodeCodex
Review drafts for clarity, structure, evidence quality, and reader usefulness against the project's writing rules. Use when a draft needs a structured review pass before publishing.
Skill Claude CodeCodex
Produce reader-ready drafts for docs, briefs, landing pages, and internal writing deliverables, starting from a brief and ending in style-compliant prose. Use when an approved brief needs to become a publishable draft.
Skill Claude CodeCodex
Write concise spoken-word scripts and narrative sequences optimized for pacing, transitions, and spoken clarity. Use when the deliverable will be performed aloud (video, podcast, demo).
Skill Claude CodeCodex
Revise drafts for search visibility — keyword placement, heading hierarchy, meta fields, internal links — without sacrificing readability. Use after the draft is reader-ready and before publishing.
Skill Claude CodeCodex
Normalize drafts to the project's explicit writing style and formatting rules at docs/instructions/rules/writing-style.md. Use as the last pass before publish.
Skill Codex
Reason about authentication weaknesses including JWT vulnerabilities, session security, OAuth/OIDC flaws, brute-force surfaces, and password storage from code and docs evidence.
Skill Codex
Derive abuse cases from module docs and validate them against tests and runtime evidence.
Skill Codex
Identify cryptographic failures including weak hashing, insecure encryption modes, hardcoded keys, weak PRNG usage, and disabled TLS verification from code evidence.
Skill Codex
Normalize dependency advisories across native audits and OSV evidence.
Skill Codex
Reason about SSRF, IDOR, mass assignment, injection vectors, file upload abuse, prototype pollution, and ReDoS from code and docs evidence.
Skill Codex
Assess security logging and monitoring gaps including missing audit trails, log injection surfaces, sensitive data in logs, and alerting coverage.
Skill Codex
Review authorization, tenant isolation, and privileged route boundaries.
Skill Codex
Identify missing rate limiting and denial-of-service surfaces on authentication endpoints, bulk operations, expensive queries, and WebSocket handlers.
Skill Codex
Re-evaluate prior pentest findings against fresh local evidence.
Skill Codex
Plan and interpret safe runtime checks against a locally running application.
Skill Codex
Enumerate threats systematically using STRIDE before scripted checks run so all downstream findings map to a threat category.
Skill Codex
Decide, from the request and the S0 grounding, which domain experts (db, security, ui, ...) the spec pipeline needs — the one model call that replaces a deterministic signal-scorer, because no script can reliably tell which expert a request needs without emitting false signals. Emits a roster-constrained JSON need…
Skill Codex
Read one expert's brief and, through that expert's lens, write short request-time notes for the spec pipeline — what this request must do, must never break, and still leaves undecided — as findings plus plain-language questions. One runner skill with a lens per expert (db, security, ui, ...), so the procedure is…
Skill Codex
The chief architect for the spec pipeline. Read the request, the grounding, every expert note and the script's merge, then accept or decline each finding with a reason, recommend a resolution for each conflict (never apply it), list the gaps nobody covered, and give a readiness verdict. It is never picked by the…
Skill Codex
When no script can classify how a project's test runner parallelizes, read the manifests and lockfiles, decide whether a parallel mode exists and its prerequisite is installed, and emit a validated JSON record for paqad-ai checks record-runner. Issue.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: