Apply AI SAFE2 v3.1 to design, build, audit, test, and govern AI agents, multi-agent systems, RAG, MCP/tool integrations, and AI infrastructure. Use the 161-control core taxonomy plus applicable profile overlays such as CP.5.MCP MCP-1 through MCP-19. Classify autonomy with ACT tiers, enforce HEAR and replication…
Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities by correlating components against the NVD CVE database via the NVD 2.0 API. Builds dependency graphs, calculates risk scores, identifies transitive vulnerability paths, and generates compliance reports.…
Analyze public equities and sectors using the Serenity-style AI supply-chain chokepoint investing framework. Best for AI infrastructure, semiconductors, optical communications, data center power, storage, cooling, robotics, and industrial supply-chain bottleneck research.
A set of instructions for researching investment opportunities using bottleneck theory. The method looks for lower-level suppliers that larger technology companies cannot easily replace.
Formats a friendly greeting for the name the user provides. Use when the user asks for a demo greeting. A test fixture for skanna: contains nothing suspicious.
Security-scan a Claude Code skill, plugin, or MCP server BEFORE installing or trusting it: reads the SKILL.md, scripts, hooks, and manifests and returns a SAFE / CAUTION / DANGEROUS verdict with file:line reasons. Read-only, zero cost, never executes the target. Use when the user says /skanna, pastes a marketplace or…
Creating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems. Create original algorithmic art rather than copying existing artists' work to avoid copyright…
Build, debug, and optimize Claude API / Anthropic SDK apps. Apps built with this skill should include prompt caching. Also handles migrating existing Claude API code between Claude model versions (4.5 → 4.6, 4.6 → 4.7, retired-model replacements). TRIGGER when: code imports anthropic/@anthropic-ai/sdk; user asks for…
Create new skills, modify and improve existing skills, and measure skill performance. Use when users want to create a skill from scratch, edit, or optimize an existing skill, run evals to test a skill, benchmark skill performance with variance analysis, or optimize a skill's description for better triggering accuracy.
Run TaskBounty's local GitHub Actions / CI maintenance-hygiene check, interpret the findings, and draft a fix plan. Use when a user wants to review a repo's GitHub Actions workflows for third-party action pinning, workflow token permissions, or update-automation gaps before shipping. Scope is CI/workflow hygiene only…
Run a labeled fixture set through the bundled deterministic subject and report catch rate and false-refusal rate without converting synthetic performance into production proof.