Progressive-disclosure instructions an agent loads on demand. Cheap until invoked, which is why the per-session figure on each card is usually two digits.
Audit any repo for security holes — a web/app project, a Claude skill, a Claude Code plugin, an MCP server, or an agent. Catches the glaring stuff (exposed servicerole keys, RLS off, committed .env, secrets in the client bundle, allow read,write: if true) and the subtle stuff (IDOR, SSRF, prompt injection in a…
This skill provides comprehensive WordPress development expertise including self-hosted setup with Docker and Nginx, theme development (block and classic), plugin development with security best practices, performance optimization, and security hardening. Use this skill when setting up WordPress environments…
Adds reactive and declarative behavior to HTML with minimal JavaScript using Alpine.js directives. Use when adding lightweight interactivity to server-rendered pages, building interactive components without a build step, or when user mentions Alpine.js, x-data, or Tailwind-style reactivity.
Creates an interactive, self-contained HTML recap dashboard after a longer absence (vacation, sabbatical, sick leave). Surfaces missed emails, meetings, Teams messages, files, pending decisions, deadlines, and top priorities — with checkboxes, dark mode, filters, and browser-persisted state. Works fully autonomously…
Execute an existing plan step-by-step on a dedicated git branch, with fast ralph loops per step and a deep final ralph loop that includes self-review and adversarial testing. Writes a timestamped journal with commit hashes and loop results. Supports both new multi-file story format (plan.md + design.md + prd.md) and…
Create production-ready FastAPI projects with async patterns, dependency injection, and comprehensive error handling. Use when building new FastAPI applications or setting up backend API projects.
You are the Pilot Group orchestrator. You generate diverse persona cohorts, simulate their experience with content, and produce comparative satisfaction reports.
Frontend design skill that generates, restyles, and guides UI development in mager's actual design taste — concept-led interfaces that feel authored, tactile, expressive, and highly usable, spanning editorial warmth, bright modern product design, and high-contrast neon systems. Use this skill when building or…
Execute tasks from the project task manager. Uses task-cli.sh to read tasks and update status. Performs the work described in task instructions with a structured workflow.
WordPress theme and plugin review skill. Detects whether a target path is a theme or plugin, runs security and standards checks, scores the findings, and writes a markdown report. Use when the user wants to review a WordPress theme or plugin directory, generate a code review report, inspect WordPress security posture…
A security-auditing skill for inspecting AI skills and plugins with static code analysis. Static analysis examines code without running it, while an abstract syntax tree represents its structure.
TLAE (Tech Lead Agentic Engineering) . use this skill when working on software projects. It turns Claude into a disciplined Tech Lead that adapts to YOUR stack, YOUR risk profile, and YOUR domain. Auto-detects language, framework, package manager, and tests on first use; asks 3 short questions about team size, domain…
SEO audit and implementation specialist for Next.js, Remix, and React SPAs. Use this skill whenever the user mentions SEO, meta tags, structured data, sitemaps, robots.txt, Open Graph, Twitter cards, JSON-LD, hreflang, image alt attributes, or crawlability. Also trigger when the user says their site doesn't rank…
Bumps the plugin version across manifest files, commits, and creates a local git tag for rai-agent-skills. Pushing and publishing the GitHub release happen separately, under human review. Use when cutting a release.
Review Claude/Cursor Skills for security issues (prompt injection, agentic/tool injection, data exfiltration, unsafe automation). Use when evaluating a Skill package/folder or SKILL.md + bundled scripts for risks like hidden instructions, tool misuse, credential theft, network exfil, destructive commands, and policy…
Metaculus is a forecasting platform where users predict outcomes of real-world events. Use this skill to interact with the Metaculus API for browsing questions, submitting forecasts, reading community predictions, managing comments, and downloading forecast data.
Use when building or reviewing Arab/MENA payment or BNPL flows, including Paymob, FawryPay, Geidea, PayTabs, Tap Payments, MyFatoorah, HyperPay, Moyasar, Amazon Payment Services, EasyKash, Kashier, PaySky, Tabby, Tamara, valU, Souhoola, webhooks, signatures, redirects, captures, refunds, or payment secret boundaries.
A ruthless, no-sugarcoating mentor persona that evaluates everything the user presents. This skill MUST activate on EVERY user prompt when enabled — it is an always-on communication and evaluation framework, not a task-specific tool. Trigger this skill for ANY user message including code, ideas, plans, architecture…
Use when the user wants to create any new Backstage package — plugin, module, processor, provider, scaffolder action, or library. Drives yarn new to scaffold the right template and optionally pre-wires common patterns (catalog access, identity, etc.) based on user intent. Triggers on phrases like "create a new…
Pre-install security advisor. Activate when the user mentions installing a Claude Code plugin, MCP server, or any third-party agent tool. Offer to run an Assay scan against the target before they install.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: