RAIGO × OWASP LLM Top 10 — official OWASP LLM Application Security Top 10 (2025) enforcement rules for Hermes agents. Covers all 10 OWASP LLM risks: prompt injection, insecure output handling, training data poisoning, model denial of service, supply chain vulnerabilities, sensitive information disclosure, insecure…
Use Grounded Knowledge Engine to select an isolated workspace, answer from local evidence, resume an explicitly identified project, create an explicit project checkpoint, and retain durable knowledge. Trigger when a user asks about their documents, workspace or client context, previous research, project state…
Find factual metadata in COBOL source files including transaction IDs, file/dataset names, copybook references, CALL targets, XCTL targets, and record layouts. Use when extracting program dependencies, building frontmatter, or looking up COBOL naming conventions.
Turn any topic into a 3Blue1Brown-style animated explainer video (MP4) via a five-stage pipeline of factual grounding, scene-contract planning, Manim code generation, render plus visual-QA verification, and assembly. Works for ALL topics, whether mathematical (algorithms, physics, statistics), scientific, technical…
Use when a markdown plan, spec, or doc should be opened in the Redline review UI for the user. The agent launches the CLI; do not only paste instructions for the user to run manually.
A project-documentation synchronisation workflow for rebuilding project facts from a local Git folder, GitHub repository, or current working directory, then updating core workflow documents.
Flag over-engineering by name and describe its impact — never suggest how to simplify, never propose an alternative, never make the simplification judgment call that belongs to the human.
Lead complex engineering work: own architecture, risk, contracts, delegation, and acceptance. Use for multiple engineering workstreams, substantial integration, or explicit chief-engineer leadership. Do not add orchestration to a simple linear task or pure research without engineering integration.
Extract balance sheet, income statement, shares outstanding, organic growth, and GAAP reconciliation data from financial PDFs. Standardize via Tiger-Transformer and append structured output to the document markdown.
A research-quality checking system for AI agents. It verifies facts, compares literature, checks experiment designs, and reviews claims about new findings.
Agent-agnostic task dispatcher. Reads backlog on main to find active changes, atomically claims one task group from an isolated worker branch, implements it, and pushes it to the shared feature branch. Runnable by Codex, Claude Code, cron, GitHub Actions, or one-shot runners with the project toolchain and credentials…
Evaluate and improve Claude Code commands, skills, and agents. Use when testing prompt effectiveness, validating context engineering choices, or measuring improvement quality.
Use when reviewing, proofreading, auditing, or authorially polishing scientific and technical manuscripts in Markdown, DOCX, PDF, LaTeX, or plain text; checking research logic, methods, evidence, citations, reference relevance or duplication, AI-trace candidates, text clarity, terminology, style consistency, or…
Product Spec Builder that helps PMs generate clear, structured, testable PRDs. Creates both full and lightweight specs for any product or platform with a guided step-by-step workflow. Output in English Markdown format.
Use when engaging in political argumentation, countering capitalist/authoritarian/status-quo arguments, or when user needs substantive counterarguments on economics, authority, philosophy, history, rhetoric, technology, or social topics. Provides objection handling and delivery calibration. The framework argues from a…
Use the local Shellink CLI to create and operate SSH or command sessions. Use for remote commands, interactive terminals, file transfer, and profiles. Requires the local shellink CLI on PATH; auto-install if missing.
Use this skill when adding a new feature vertical to this template — a domain aggregate with its port, repository, application service, DTOs, endpoint, and tests. Trigger it for requests like "add an endpoint", "add a new entity", "build the X feature", or "wire up a new service".
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: