# Claude Code skills > 87 Claude Code skills in 13 plugins by Muhammad Basit Ali, in one repository (https://github.com/basitalisandhu/claude-skills) that is also a Claude Code plugin marketplace named `claude-skills`. Install with `/plugin marketplace add basitalisandhu/claude-skills` then `/plugin install @claude-skills`, or clone the repository and run `python3 install.py --user` to copy every skill into `~/.claude/skills/`. Each skill is a SKILL.md file with optional standard-library scripts. Skills are edited in their source repositories and synced here daily. ## agent-security Security skills for LLM agents: threat model a codebase, audit agent configuration, review MCP servers, trace prompt injection to tool calls, look up incident precedents, run security evals, and scan with Semgrep. Includes guard hooks for Bash and an optional incident-database MCP server. Source: https://github.com/basitalisandhu/agent-security-skills - [agent-config-audit](https://basitalisandhu.github.io/claude-skills/plugins/agent-security/agent-config-audit/): Audit AI-agent configuration for risky permissions, leaked secrets, unpinned MCP servers and prompt-injection in instruction files. - [agent-eval-harness](https://basitalisandhu.github.io/claude-skills/plugins/agent-security/agent-eval-harness/): Set up AgentDojo-style security evaluations for an agent: benign user tasks, injection tasks planted in tool results, utility and attack-success-rate metrics, and a policy hook (provenance, approval) in the tool executor. - [agent-threat-model](https://basitalisandhu.github.io/claude-skills/plugins/agent-security/agent-threat-model/): Write a system description of an LLM-agent codebase in the agent-threat-model YAML format (principals, agents, channels, tools, data stores, controls), validate it with atm validate, run atm analyse for a STRIDE and OWASP threat model with residual risk scoring, then interpret and summarise the result with incident precedents. - [incident-lookup](https://basitalisandhu.github.io/claude-skills/plugins/agent-security/incident-lookup/): Look up real AI agent security incidents, vulnerability disclosures and threat reports (80 coded events, 2023 to 2026, mapped to OWASP Agentic Top 10, OWASP LLM Top 10 and MITRE ATLAS) and summarise precedents for a design. - [mcp-server-review](https://basitalisandhu.github.io/claude-skills/plugins/agent-security/mcp-server-review/): Checklist-driven security review of an MCP server implementation (TypeScript or Python) covering authentication, transport binding and origin checks, input validation, tool description poisoning, resource and path handling, SSRF, rate limits and secret-free logging, with a Semgrep pass. - [prompt-injection-review](https://basitalisandhu.github.io/claude-skills/plugins/agent-security/prompt-injection-review/): Trace untrusted inputs (web pages, emails, documents, tickets, repo issues, tool results, retrieved memory) to consequential tool calls in an agent codebase and judge each flow with deterministic provenance and approval rules. - [secure-agent-checklist](https://basitalisandhu.github.io/claude-skills/plugins/agent-security/secure-agent-checklist/): Pre-ship security checklist for an LLM agent covering identity, least privilege, approvals, sandboxing, audit, kill switch, supply chain and evals, producing a markdown report with pass, fail or n.a. per item and the evidence behind each verdict. - [semgrep-agentic](https://basitalisandhu.github.io/claude-skills/plugins/agent-security/semgrep-agentic/): Run the agentic-semgrep-rules pack (36 rules for Python, JavaScript and TypeScript agent code: model output reaching exec, shells, SQL, URLs, file paths and HTML; user input in system prompts; tool parameters reaching shells and paths; MCP servers without auth or bound to every interface; leaked provider keys; unsafe model and config loading) against a repository, fall back to the bundled offline rules, and triage the results. ## aws-security AWS security skills for Claude Code: read-only account audit, SCP guardrail builder and linter, landing zone blast-radius design, IAM least-privilege review, Security Hub and GuardDuty triage, least-privilege access for AI agents with a kill switch, incident response runbooks, spend guardrails and a sandbox OU guardrail pack. Scripts are standard-library Python and work offline on specs and saved aws CLI output. Source: https://github.com/basitalisandhu/aws-security-skills - [agent-safe-aws-access](https://basitalisandhu.github.io/claude-skills/plugins/aws-security/agent-safe-aws-access/): Set up least-privilege, auditable AWS access for an AI coding agent, or review an existing agent role. - [aws-account-audit](https://basitalisandhu.github.io/claude-skills/plugins/aws-security/aws-account-audit/): Read-only security audit of one AWS account. - [aws-incident-response-runbook](https://basitalisandhu.github.io/claude-skills/plugins/aws-security/aws-incident-response-runbook/): Produce a step-by-step AWS incident response runbook in Markdown for one of six scenarios (leaked access key, compromised EC2 instance, public S3 bucket exposure, suspicious IAM activity, ransomware against S3 or EBS, crypto-mining), filled in with the account, region and resource identifiers. - [aws-spend-guardrails](https://basitalisandhu.github.io/claude-skills/plugins/aws-security/aws-spend-guardrails/): Generate AWS spend guardrails and check exported cost data against them. - [iam-least-privilege-review](https://basitalisandhu.github.io/claude-skills/plugins/aws-security/iam-least-privilege-review/): Review AWS IAM policy documents offline for over-broad permissions and privilege-escalation paths. - [landing-zone-blast-radius](https://basitalisandhu.github.io/claude-skills/plugins/aws-security/landing-zone-blast-radius/): Design an AWS Organizations landing zone with one account per workload and environment, and show the blast radius of each account. - [sandbox-account-guardrail-pack](https://basitalisandhu.github.io/claude-skills/plugins/aws-security/sandbox-account-guardrail-pack/): Generate a complete guardrail pack for an AWS sandbox OU where engineers and AI agents experiment. - [scp-guardrails](https://basitalisandhu.github.io/claude-skills/plugins/aws-security/scp-guardrails/): Generate and lint AWS Organizations service control policies (SCPs). - [security-hub-triage](https://basitalisandhu.github.io/claude-skills/plugins/aws-security/security-hub-triage/): Triage exported AWS Security Hub (ASFF) and GuardDuty findings offline into an owner-assigned next-actions list. ## code-quality Eight skills for keeping a codebase healthy: a review checklist, refactor planning, dead code and complexity reports, naming and error-handling audits, type coverage for Python and TypeScript, and a test gap finder. Source: https://github.com/basitalisandhu/claude-dev-skills - [complexity-report](https://basitalisandhu.github.io/claude-skills/plugins/code-quality/complexity-report/): Rank the functions in a Python or JavaScript/TypeScript tree by cyclomatic complexity, length and nesting depth with a bundled script, then explain which ones to simplify and how. - [dead-code-finder](https://basitalisandhu.github.io/claude-skills/plugins/code-quality/dead-code-finder/): Find probably-unused functions, classes, methods and exports in a Python or JavaScript/TypeScript tree with a bundled script, confirm each candidate by searching for dynamic use, and propose a safe deletion order. - [error-handling-review](https://basitalisandhu.github.io/claude-skills/plugins/code-quality/error-handling-review/): Review how a codebase or change handles failures: swallowed exceptions, missing timeouts and retries, errors without context, leaking internals to users, and inconsistent error types across layers; then propose a consistent policy with code examples. - [naming-audit](https://basitalisandhu.github.io/claude-skills/plugins/code-quality/naming-audit/): Audit the names in a module or diff (variables, functions, classes, files, database columns, API fields) for clarity, consistency with the project's conventions, and lies (names that no longer match behaviour), then propose renames with a migration path for public ones. - [refactor-plan](https://basitalisandhu.github.io/claude-skills/plugins/code-quality/refactor-plan/): Produce a step-by-step refactoring plan for a module, package or feature, with a behaviour-preserving sequence of small commits, the tests that guard each step, and a rollback point. - [review-checklist](https://basitalisandhu.github.io/claude-skills/plugins/code-quality/review-checklist/): Review a pull request, diff or branch against a fixed checklist (correctness, tests, error handling, security, performance, readability, compatibility) and produce findings with file and line references and a verdict. - [test-gap-finder](https://basitalisandhu.github.io/claude-skills/plugins/code-quality/test-gap-finder/): Map source modules to their test files by naming convention and imports with a bundled script, list the modules that have no test, and prioritise which to cover first by risk. - [type-coverage](https://basitalisandhu.github.io/claude-skills/plugins/code-quality/type-coverage/): Measure how much of a Python or TypeScript codebase is type-annotated with a bundled script (parameters and return values per function, explicit any counts), find the least-typed files, and plan a gradual typing rollout with a CI threshold. ## compliance-evidence Compliance evidence skills for Claude Code: build integrity-checked evidence packs from GitHub, AWS and Microsoft 365 exports, map them to ISO 27001 and SOC 2 control identifiers, and draft auditor narratives that cite evidence or say not assessable. Standard-library Python scripts read exports already on disk and make no network calls. Source: https://github.com/basitalisandhu/compliance-evidence-skills - [auditor-narrative-drafter](https://basitalisandhu.github.io/claude-skills/plugins/compliance-evidence/auditor-narrative-drafter/): Draft short control narratives for an ISO 27001 or SOC 2 assessment strictly from a control map, with an inline citation [evidence: file#field] on every sentence that reports evidence, and lint any narrative (drafted or hand-edited) before it reaches the assessor. - [aws-identity-and-logging-evidence](https://basitalisandhu.github.io/claude-skills/plugins/compliance-evidence/aws-identity-and-logging-evidence/): Turn saved aws CLI output from one AWS account into evidence rows for logging, access control and backup controls (ISO/IEC 27001:2022 A.8.15, A.8.16, A.8.5, A.8.2, A.5.17, A.8.9, A.5.15, A.8.13 and SOC 2 CC7.2, CC6.1, CC7.1, CC6.6, A1.2 by identifier). - [control-map-from-exports](https://basitalisandhu.github.io/claude-skills/plugins/compliance-evidence/control-map-from-exports/): Map the exports inside an evidence pack to ISO/IEC 27001:2022 Annex A or SOC 2 control identifiers with a mapping file, and report per control one of three states (supported, contradicted, not assessable) with citations to the exact file, field and value, plus the gaps. - [evidence-pack-builder](https://basitalisandhu.github.io/claude-skills/plugins/compliance-evidence/evidence-pack-builder/): Turn a folder of exports already on disk (GitHub, AWS, Microsoft 365 JSON, CSV or text) into an integrity-checked evidence pack for an ISO 27001 or SOC 2 assessment. - [github-change-control-evidence](https://basitalisandhu.github.io/claude-skills/plugins/compliance-evidence/github-change-control-evidence/): Turn saved gh api and gh pr list exports of one GitHub repository into evidence rows for change management and vulnerability management controls (ISO/IEC 27001:2022 A.8.32, A.8.8, A.8.12 and SOC 2 CC8.1, CC7.1, CC6.1 by identifier). ## data Six skills for data and API work: SQL query review, schema migration planning, CSV profiling, JSON Schema inference from samples, regex building with test cases, and OpenAPI 3 contract review. Source: https://github.com/basitalisandhu/claude-dev-skills - [api-contract-review](https://basitalisandhu.github.io/claude-skills/plugins/data/api-contract-review/): Lint an OpenAPI 3.x document (YAML or JSON) with a bundled script for missing operationIds, undeclared path parameters, responses without schemas or error cases, servers over http, missing security schemes, unused or dangling components and naming inconsistencies; then review the contract for consistency, versioning and client friendliness. - [csv-profiler](https://basitalisandhu.github.io/claude-skills/plugins/data/csv-profiler/): Profile a CSV or TSV file with a bundled script (column types, nulls, distinct counts, ranges and statistics, candidate keys, ragged and duplicate rows, mixed types, whitespace) and turn the profile into import decisions: column types for a table or schema, cleaning steps and validation rules. - [json-schema-author](https://basitalisandhu.github.io/claude-skills/plugins/data/json-schema-author/): Write a JSON Schema (draft 2020-12) for an API payload, configuration file or event by inferring a draft from sample documents with a bundled script (types, required fields, nullability, formats, enums, bounds) and then hand-finishing it: tightening constraints, adding descriptions and examples, and deciding additionalProperties and versioning. - [regex-builder](https://basitalisandhu.github.io/claude-skills/plugins/data/regex-builder/): Build, explain and test regular expressions against labelled cases with a bundled script that reports which cases match, the captured groups, and warnings for patterns that can backtrack catastrophically, with timing on adversarial inputs. - [schema-migration-plan](https://basitalisandhu.github.io/claude-skills/plugins/data/schema-migration-plan/): Plan a database schema change as a sequence of backwards-compatible, reversible migration steps (expand, migrate data, contract) that work with the running application version, with lock and downtime analysis per step, a batched backfill for large tables, and a rollback plan. - [sql-query-review](https://basitalisandhu.github.io/claude-skills/plugins/data/sql-query-review/): Review SQL queries, ORM-generated SQL and query plans for correctness and performance: injection, implicit casts, NULL logic, non-sargable predicates, missing indexes, N+1 patterns, unbounded result sets, lock contention and transaction scope, using a fixed checklist and EXPLAIN reading notes for PostgreSQL, MySQL and SQLite. ## debugging Six skills for finding the cause of a failure: minimise a bug reproduction, cluster log lines, find flaky tests in JUnit XML, explain a stack trace, summarise a py-spy, pprof or cProfile profile, and work a memory leak checklist. Source: https://github.com/basitalisandhu/claude-dev-skills - [bug-repro-minimiser](https://basitalisandhu.github.io/claude-skills/plugins/debugging/bug-repro-minimiser/): Turn a vague bug report into the smallest reliable reproduction: a single command or test that fails every time, with the environment, input and expected versus actual result pinned down. - [flaky-test-hunter](https://basitalisandhu.github.io/claude-skills/plugins/debugging/flaky-test-hunter/): Find tests that pass and fail without code changes by comparing JUnit XML reports from several runs with a bundled script, then classify each flaky test by cause (ordering, timing, shared state, resources, environment) and prescribe the fix. - [log-triage](https://basitalisandhu.github.io/claude-skills/plugins/debugging/log-triage/): Reduce a large log file to its distinct message templates with counts, levels, first and last occurrence and attached stack traces using a bundled clustering script, then rank what to investigate. - [memory-leak-checklist](https://basitalisandhu.github.io/claude-skills/plugins/debugging/memory-leak-checklist/): Diagnose a process whose memory grows over time with a fixed checklist: confirm it is a leak and not a cache or fragmentation, measure with the runtime's heap tools (tracemalloc, objgraph, Node heap snapshots, Go pprof heap, JVM histograms), find the retaining path, and fix the usual suspects (unbounded caches, listeners, closures, global registries, connection pools, large buffers). - [perf-profile-reader](https://basitalisandhu.github.io/claude-skills/plugins/debugging/perf-profile-reader/): Summarise a captured CPU profile (py-spy collapsed stacks or dump, Go pprof text, Python cProfile output) into the few functions that hold the time, separate busy from waiting, and name the optimisation to try first, using a bundled script. - [stack-trace-explainer](https://basitalisandhu.github.io/claude-skills/plugins/debugging/stack-trace-explainer/): Read a stack trace or crash report from any mainstream runtime (Python, JavaScript and Node, Java and JVM, Go, Rust, .NET, Ruby, PHP), identify the frame where the fault lives versus where it surfaced, explain the error type, and propose the next diagnostic step. ## devops Eight skills for shipping and operating software: Dockerfile hardening, GitHub Actions workflow authoring and validation, Kubernetes manifest review, Terraform review, crontab diagnosis, .env key diffs, release notes from git history and a semver advisor. Source: https://github.com/basitalisandhu/claude-dev-skills - [cron-doctor](https://basitalisandhu.github.io/claude-skills/plugins/devops/cron-doctor/): Diagnose a crontab with a bundled script that validates every schedule, explains it in words, computes the next runs, and flags jobs with no output redirection, unescaped percent signs, PATH assumptions, day-of-month plus day-of-week confusion, DST-sensitive hours, overlapping frequent jobs and duplicates; then fix the entries and add locking and logging. - [dockerfile-hardening](https://basitalisandhu.github.io/claude-skills/plugins/devops/dockerfile-hardening/): Lint a Dockerfile with a bundled script for images that run as root, unpinned or latest base images, secrets in ENV or ARG, remote scripts piped to a shell, unclean apt layers, world-writable permissions and missing HEALTHCHECK, then rewrite it as a smaller, pinned, non-root multi-stage build. - [env-diff](https://basitalisandhu.github.io/claude-skills/plugins/devops/env-diff/): Compare the keys of a .env.example (or any template) against real .env files with a bundled script, listing missing, extra, empty and duplicated keys and template values that look like real credentials, without ever printing a value. - [github-actions-author](https://basitalisandhu.github.io/claude-skills/plugins/devops/github-actions-author/): Write or review GitHub Actions workflows with least-privilege permissions, SHA-pinned actions, timeouts, concurrency and caching, and validate them with a bundled linter that catches missing permissions, pull_request_target checkout of fork code, expression injection in run steps, unpinned actions and literal secrets. - [k8s-manifest-review](https://basitalisandhu.github.io/claude-skills/plugins/devops/k8s-manifest-review/): Review Kubernetes manifests (Deployments, StatefulSets, DaemonSets, Jobs, CronJobs, Pods, Services, Secrets) with a bundled script for missing resource limits and probes, privileged or root containers, mutable image tags, host namespaces and hostPath mounts, inline secrets and missing seccomp, then produce the corrected YAML. - [release-notes](https://basitalisandhu.github.io/claude-skills/plugins/devops/release-notes/): Generate release notes from a git commit range with a bundled script that groups commits by Conventional Commits type (breaking, features, fixes, performance, docs, build), links commits and issues, and lists contributors; then edit them into notes a user can read. - [semver-advisor](https://basitalisandhu.github.io/claude-skills/plugins/devops/semver-advisor/): Decide the next version number (major, minor or patch, or a pre-release) for a library, service, API, CLI or schema from the actual changes, using a decision table for what counts as breaking in each kind of artefact, and explain the decision with evidence. - [terraform-review](https://basitalisandhu.github.io/claude-skills/plugins/devops/terraform-review/): Review Terraform or OpenTofu code against a fixed checklist: state and backend safety, provider and module version pinning, variables with types and validation, secrets handling, public exposure (open security groups, public buckets, 0.0.0.0/0), encryption and logging defaults, lifecycle and destroy protection, and plan hygiene. ## docs Six skills for writing documentation that stays accurate: README author, ADR writer, changelog keeper, onboarding doc, API docs extracted from docstrings and JSDoc, and a postmortem writer. Source: https://github.com/basitalisandhu/claude-dev-skills - [adr-writer](https://basitalisandhu.github.io/claude-skills/plugins/docs/adr-writer/): Write an Architecture Decision Record for a technical choice, with context, the options considered and their trade-offs, the decision and its consequences, in a fixed format with a status lifecycle (proposed, accepted, superseded), numbered and stored in the repository. - [api-docs-from-code](https://basitalisandhu.github.io/claude-skills/plugins/docs/api-docs-from-code/): Generate an API reference from source with a bundled script that extracts Python docstrings (Google, NumPy and reST styles) and JavaScript/TypeScript JSDoc blocks into Markdown or JSON, lists undocumented public symbols, and measures documentation coverage; then fill the gaps and wire the extraction into the docs build. - [changelog-keeper](https://basitalisandhu.github.io/claude-skills/plugins/docs/changelog-keeper/): Maintain CHANGELOG.md in the Keep a Changelog format with a bundled script that validates the structure, adds entries under Unreleased in the right category, cuts a release (version, date, compare links) and prints a version's section. - [onboarding-doc](https://basitalisandhu.github.io/claude-skills/plugins/docs/onboarding-doc/): Write a developer onboarding document for a repository or service that gets a new team member from a clean machine to a merged change: environment setup verified step by step, how the code is organised, how to run and test it, the configuration it needs, the deployment path, who owns what, and the first tasks. - [postmortem-writer](https://basitalisandhu.github.io/claude-skills/plugins/docs/postmortem-writer/): Write a blameless incident postmortem from the timeline, logs, chat transcript and metrics: impact with numbers, a minute-by-minute timeline, contributing causes found with a structured analysis rather than a single root cause, what went well and what did not, and action items with owners, deadlines and a check that they would have prevented or shortened the incident. - [readme-author](https://basitalisandhu.github.io/claude-skills/plugins/docs/readme-author/): Write or rewrite a README that answers what the project is, who it is for, how to install and use it in under five minutes, and where everything else lives, using a fixed section order and a quality checklist (first screen, copy-pasteable commands verified to work, no stale claims). ## github-manager Engineering manager skills that compute from exported GitHub data: a stuck-PR and review-queue digest with next actions, an iteration report with shipped, carried-over and newly opened work plus cycle time and review turnaround, and a blameless incident postmortem timeline. Every number and row cites the PR, issue, comment or event it came from; team level only, no per-person scoring. Source: https://github.com/basitalisandhu/github-manager-skills - [incident-postmortem-timeline](https://basitalisandhu.github.io/claude-skills/plugins/github-manager/incident-postmortem-timeline/): Build a blameless postmortem timeline and document skeleton from a saved incident issue export (gh issue view with comments, the issue timeline, and the PRs it references), with a bundled script that orders every label change, assignment, comment, cross-reference, PR merge and close by time, derives detected, acknowledged, mitigated and resolved from those records, reports where two signals for one phase disagree, lists people as roles, and writes contributing factors as questions for the review, citing each row to its comment id, event id or PR. - [iteration-report](https://basitalisandhu.github.io/claude-skills/plugins/github-manager/iteration-report/): Write a team-level iteration or sprint report from saved gh pr list, gh issue list and milestone exports, with a bundled script that lists what shipped (merged PRs with the issues they close), what carried over, what was newly opened, what was closed as not planned and which PRs merged outside the window, and computes cycle time (median and p90, from first commit or from PR creation, stated) and review turnaround (median), every number followed by the PR or issue rows it came from. - [pr-queue-digest](https://basitalisandhu.github.io/claude-skills/plugins/github-manager/pr-queue-digest/): Build a stuck-PR and review-queue digest from a saved gh pr list export, with a bundled script that flags PRs waiting on review longer than a threshold, PRs blocked on one overloaded reviewer, changes requested with no new commits, new commits with no re-request, failing checks, merge conflicts, approved but unmerged PRs, PRs with no reviewer and stale drafts, then prints a review-queue table per reviewer (counts only) and one next action per PR (nudge, re-request, rebase, fix checks, merge, close as stale), each citing the PR. ## m365-governance Microsoft 365 governance skills for Claude Code: Graph permission preflight for apps and connectors, Entra ID posture review, Conditional Access gap analysis, privileged access review, guest and external sharing review, licence and service plan audit, Intune baseline check, Teams and group sprawl report, and a quarterly access review pack. Scripts are standard-library Python and evaluate exported Microsoft Graph JSON offline. Source: https://github.com/basitalisandhu/m365-governance-skills - [access-review-pack](https://basitalisandhu.github.io/claude-skills/plugins/m365-governance/access-review-pack/): Build a quarterly Microsoft 365 access review package from read-only Graph exports. - [conditional-access-gap-analysis](https://basitalisandhu.github.io/claude-skills/plugins/m365-governance/conditional-access-gap-analysis/): Find gaps, overlaps and exclusion problems in Microsoft Entra Conditional Access from read-only Graph exports. - [entra-posture-review](https://basitalisandhu.github.io/claude-skills/plugins/m365-governance/entra-posture-review/): Review a Microsoft Entra ID tenant's identity posture from read-only Graph exports. - [graph-permission-preflight](https://basitalisandhu.github.io/claude-skills/plugins/m365-governance/graph-permission-preflight/): Preflight the Microsoft Graph permissions an app registration, enterprise application or third-party connector requests or already holds, before it touches a Microsoft 365 tenant. - [guest-and-external-sharing-review](https://basitalisandhu.github.io/claude-skills/plugins/m365-governance/guest-and-external-sharing-review/): Review guest accounts and external sharing in Microsoft 365 from read-only exports. - [intune-baseline-check](https://basitalisandhu.github.io/claude-skills/plugins/m365-governance/intune-baseline-check/): Check a Microsoft Intune estate against a device baseline from read-only Graph exports. - [license-and-service-plan-audit](https://basitalisandhu.github.io/claude-skills/plugins/m365-governance/license-and-service-plan-audit/): Audit Microsoft 365 licence assignments from read-only Graph exports and draft a reclaim list. - [privileged-access-review](https://basitalisandhu.github.io/claude-skills/plugins/m365-governance/privileged-access-review/): Review privileged Microsoft Entra ID role holders from read-only Graph exports and score each admin account. - [teams-and-groups-sprawl](https://basitalisandhu.github.io/claude-skills/plugins/m365-governance/teams-and-groups-sprawl/): Report Microsoft Teams and Microsoft 365 group sprawl from read-only Graph exports and draft a cleanup list. ## mac-maintenance Mac cleanup skills: survey what takes space and memory without changing anything, remove only the caches and leftovers that programs recreate, find byte-identical duplicate files and park the obvious copies in the Trash, and find data, login items and launch agents left by uninstalled apps. Every deletion of user data is a decision the user makes from a written list. Source: https://github.com/basitalisandhu/mac-maintenance-skills - [mac-app-leftovers](https://basitalisandhu.github.io/claude-skills/plugins/mac-maintenance/mac-app-leftovers/): Find what uninstalled applications left behind on a Mac with a bundled script: Application Support and container folders, caches, preferences, saved state, WebKit and HTTP storage, logs, login items whose app is gone, and launch agents or daemons whose program no longer exists. - [mac-cleanup](https://basitalisandhu.github.io/claude-skills/plugins/mac-maintenance/mac-cleanup/): Clean up and speed up a Mac in three tiers with two bundled scripts. - [mac-duplicate-finder](https://basitalisandhu.github.io/claude-skills/plugins/mac-maintenance/mac-duplicate-finder/): Find byte-for-byte duplicate files in a Mac's user folders with a bundled script (size grouping, then partial and full hashing), report the largest groups and which folders mirror each other, and single out "suffix copies" (IMG_1 (1).MOV next to an identical IMG_1.MOV) that can be moved to a dated Trash folder after a second hash check, with the original untouched. ## repo-engineering Repository engineering skills: verify documentation claims against the working tree, run an audit whose every finding cites a resolvable path:line, write AGENTS.md and CLAUDE.md that hold only what code cannot say, check a README's first screen, rank untested functions and entry points, write onboarding guides only from cited facts, plan restructures from the import graph, mine ADRs from git history, run offline hygiene checks with SARIF, and check release notes against the commits between two tags. Source: https://github.com/basitalisandhu/repo-engineering-skills - [adr-miner](https://basitalisandhu.github.io/claude-skills/plugins/repo-engineering/adr-miner/): Recover architecture decisions that were made but never written down, by mining git history (commit messages with decision phrases such as switch to, replace, adopt, drop, migrate, deprecate, in favour of), configuration changes (a dependency swapped in a manifest, a Dockerfile base image changed, CI files added or removed) and TODO or NOTE comments that carry a rationale, then drafting MADR stubs with status proposed that cite the commit SHA for every line; a second script lints an existing docs/adr folder for numbering gaps, duplicate numbers, missing or unknown status and broken superseded links. - [agent-context-writer](https://basitalisandhu.github.io/claude-skills/plugins/repo-engineering/agent-context-writer/): Write or refresh AGENTS.md and CLAUDE.md so they hold only what an agent cannot learn by reading the code (commands that are in no manifest, conventions, forbidden actions, environment setup, where to look first), and lint the result with a bundled script that flags lines restating package.json scripts, pyproject scripts, Makefile or justfile targets, dependency lists, pinned runtime versions or directory trees, paths that do not exist, generic advice, and length over a budget. - [cited-codebase-audit](https://basitalisandhu.github.io/claude-skills/plugins/repo-engineering/cited-codebase-audit/): Audit a whole repository against a fixed checklist (structure, entry points, dependency hygiene, dead code candidates, test coverage of entry points, secrets and config handling, CI health) where every finding must cite a path:line with a quoted snippet, and a bundled validator rejects any finding whose citation does not resolve. - [docs-truth-check](https://basitalisandhu.github.io/claude-skills/plugins/repo-engineering/docs-truth-check/): Verify that a repository's README, docs/, AGENTS.md and CLAUDE.md still match the code, using a deterministic script that checks file paths, relative links, CLI flags and their documented defaults, environment variables, function and class names, config keys, npm and make targets, and version strings against the working tree. - [readme-who-what-why](https://basitalisandhu.github.io/claude-skills/plugins/repo-engineering/readme-who-what-why/): Check whether a README answers six questions in its first screen (what it is in one sentence, who it is for, why it exists or what it replaces, how to install in one block, how to run one example, where to ask) with a bundled script that scores presence and position of each, flags hype words, and prints the gaps as a to-do list; then fix the gaps with verified text. - [release-notes-verifier](https://basitalisandhu.github.io/claude-skills/plugins/repo-engineering/release-notes-verifier/): Check a release's notes against what actually changed, with a bundled script that reads the commits between two tags (and, only when asked, pull request titles through a read-only gh call) and compares them with the CHANGELOG section or a release notes file, flagging notes that match no commit, commits with no note (chores excluded by a configurable pattern), manifest versions that disagree with the tag, and missing compare or reference links. - [repo-hygiene-bundle](https://basitalisandhu.github.io/claude-skills/plugins/repo-engineering/repo-hygiene-bundle/): Run one offline hygiene pass over a repository with a bundled script and report each finding with a severity, as a table, JSON or SARIF, with an exit code for CI. - [repo-onboarding-guide](https://basitalisandhu.github.io/claude-skills/plugins/repo-engineering/repo-onboarding-guide/): Write an onboarding guide for a repository (how to run it, how to test it, where things live, which services it needs, who owns what) only from facts a bundled script extracted with a path:line citation each, then lint the guide so every sentence that names a command, path, variable, service or owner matches a fact, and run docs-truth-check on the result. - [restructure-planner](https://basitalisandhu.github.io/claude-skills/plugins/repo-engineering/restructure-planner/): Plan a repository restructure (split a package or a monorepo, merge packages, fix module boundaries) from the real import graph instead of a guess, using a bundled script that reads Python imports with ast and JS or TS imports and requires with regex, then reports the most coupled files, import cycles, files importing from many packages and god modules, and proposes a move plan as a table (file, from, to, reason, blast radius as the number of importers) with the exact git mv commands, which it prints and never runs. - [untested-entry-points](https://basitalisandhu.github.io/claude-skills/plugins/repo-engineering/untested-entry-points/): Find public functions, classes and CLI entry points that no test mentions, using a bundled script that parses Python with ast and JS or TS exports with regex, maps each unit to the test files that reference it by name, ranks the untested ones (entry points first, then by size and fan-in), and writes characterisation test stubs in the project's framework (pytest, unittest, jest, vitest, node:test). ## security-basics Six lightweight security skills for everyday development: secrets hygiene scan, npm audit and pip-audit reader, HTTP security header check, JWT inspector, CORS review and auth flow review. Agent and MCP security lives in the agent-security-skills marketplace. Source: https://github.com/basitalisandhu/claude-dev-skills - [auth-flow-review](https://basitalisandhu.github.io/claude-skills/plugins/security-basics/auth-flow-review/): Review an application's authentication and session design against a checklist covering password handling, login and logout, session cookies and tokens, OAuth and OIDC flows (authorization code with PKCE, state, redirect URI validation), multi-factor, password reset, account enumeration, rate limiting, remember-me and device trust, and logging; then produce findings with severity and the corrected flow. - [cors-review](https://basitalisandhu.github.io/claude-skills/plugins/security-basics/cors-review/): Review a web application's Cross-Origin Resource Sharing configuration (allowed origins, credentials, methods, headers, preflight caching, exposed headers) against a checklist of the mistakes that create cross-site data leaks or break legitimate clients, and produce the correct configuration for the framework or gateway in use. - [dependency-audit-reader](https://basitalisandhu.github.io/claude-skills/plugins/security-basics/dependency-audit-reader/): Read the JSON output of npm audit, yarn audit, pip-audit or cargo audit with a bundled script that ranks vulnerable packages by severity, separates fixable from unfixable and direct from transitive, and names the packages to upgrade first; then plan the upgrades, the overrides and the accepted risks with expiry dates. - [http-security-headers](https://basitalisandhu.github.io/claude-skills/plugins/security-basics/http-security-headers/): Check the security headers of a captured HTTP response (saved from curl or the browser) with a bundled script that grades HSTS, Content-Security-Policy, X-Content-Type-Options, frame protection, Referrer-Policy, Permissions-Policy, cookie flags, CORS with credentials, information disclosure and caching, then produce the header set for the web server or framework. - [jwt-inspector](https://basitalisandhu.github.io/claude-skills/plugins/security-basics/jwt-inspector/): Decode a JSON Web Token without verifying it with a bundled script that prints the header and claims with times explained, and flags unsafe settings (alg none, empty signature, missing or long expiry, jku or x5u headers, suspicious kid, symmetric algorithms, sensitive claims in the payload), then review how the application issues and verifies tokens. - [secrets-hygiene](https://basitalisandhu.github.io/claude-skills/plugins/security-basics/secrets-hygiene/): Scan a repository, a directory or the files staged for commit for leaked credentials (cloud and SaaS API keys, private keys, tokens, connection strings with passwords, high-entropy assignments) with a bundled script that redacts what it finds, check that .env files are ignored, maintain a baseline of accepted findings, and walk the rotation and history cleanup when something real is found. ## Optional - [llms-full.txt](https://basitalisandhu.github.io/claude-skills/llms-full.txt): the full text of every SKILL.md - [catalog.json](https://github.com/basitalisandhu/claude-skills/blob/main/catalog.json): machine-readable catalog - [SOURCES.json](https://github.com/basitalisandhu/claude-skills/blob/main/SOURCES.json): source repository and commit for each plugin