A principal-level, 16-division multi-agent Council for Claude Code. Drop-in ~/.claude/ config: 15 Floor + 160 Library rules, 121 skills, 32 agents, 33 commands, 14 hook-enforced quality gates. Runs on any machine, any project, every IDE. MIT.
Principal-level organisational design — team topologies, span of control, reporting structures, decision rights (DACI / RACI), Conway's Law, coordination cost, scaling from 10 to 1000, the difference between functional / divisional / matrix / network structures, and the discipline that aligns the org chart to the…
OWASP Application Security Verification Standard 4.0.3 — the canonical control catalogue for application security, mapped per L1 / L2 / L3 with implementation patterns and verification commands.
PCI-DSS v4.0 implementation patterns for systems that store, process, or transmit cardholder data — scope reduction via tokenization, SAQ selection, segmentation, encryption requirements, and the 12 PCI-DSS requirements mapped to concrete engineering controls.
Principal-level performance management — feedback systems, calibration, ratings (or no ratings), career frameworks, performance improvement plans, and the operational discipline that turns reviews from anxiety-inducing theatre into a real engine of growth, retention, and accountability.
Principal-level portfolio construction — Markowitz mean-variance optimisation, CAPM, factor models, risk budgeting, rebalancing discipline, drawdown and tail-risk management. Diversification is the only free lunch; respect transaction costs and behavioural traps.
Template for authoring a project-specific skill in /.claude/skills/. Demonstrates the canonical shape — Architecture / File Structure / Code Patterns / Testing Requirements / Deployment Workflow / Critical Rules — that workspace skills follow when they extend global guidance with project-specific specifics. Use this…
Principal-level prompt engineering — task decomposition, role + context + instructions + examples + output-format structure, few-shot patterns, chain-of-thought, tool-use prompts, evaluation, prompt versioning, and the discipline that separates "works once on the demo" from "production-grade prompt that survives model…
Transforms vague or under-specified prompts into actionable, research-grounded requests through systematic codebase + workspace + open-source + online research. Wires the user's directive flow into the Council Protocol Phase 0 and the global task-intake-due-diligence.md questionnaire. Invoked by the UserPromptSubmit…
Read and cite primary-source provider documentation BEFORE writing any integration code against an external API. Enforces the official-docs-first rule across calendar, identity, payment, mail, push, ML, and observability providers.
Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns. Also lazy-loads the security.md / security-controls-org-wide.md / secrets-management.md content migrated from…
Scan a Claude Code configuration surface (.claude/ directory, CLAUDE.md, settings.json, MCP servers, hooks, agent definitions) for security vulnerabilities, misconfigurations, and prompt-injection risks using AgentShield (ecc-agentshield). Sister to security-review (broader OWASP / source-code audit). Use this skill…
SOC 2 Type I and Type II readiness patterns — Trust Service Criteria (Security / Availability / Processing Integrity / Confidentiality / Privacy), control-to-evidence mapping, and the operational evidence collection patterns that survive a continuous-period audit.
★not rated 9 5d agoA51 tokens
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: