git-commit-writer
Writes conventional commit messages by analyzing your staged git changes. Detects commit type, scope, and breaking changes automatically.
Skills that help AI agents manage CI/CD pipelines, Docker containers, infrastructure-as-code, and cloud deployments. Automate your deployment workflows and reduce operational overhead.
📖 Related guide: Best DevOps & Deployment Skills for Claude Code →
190 skills
Writes conventional commit messages by analyzing your staged git changes. Detects commit type, scope, and breaking changes automatically.
Diagnoses why your project will not start. Checks runtime versions, dependencies, environment variables, databases, ports, and build artifacts systematically.
Clone any webpage into fully editable native Elementor Pro widgets with pixel-perfect accuracy.
Eliminate hallucinations with an evidence-first verification framework for system state, configs, and file contents.
Audit AI agent skills for security risks, packaging errors, and marketplace readiness with professional reports.
A risk-aware, evidence-based engineering lifecycle protocol for robust agentic task execution and safety.
Transform Claude Code into a coordinated multi-agent system. Battle-tested tmux orchestration patterns, YAML task queues, event-driven communication, and parallel worker management for 8+ agents.

Generate high-fidelity, structured handoff packets for seamless multi-agent collaboration and session persistence.
Systematic runtime bug detection and automated patching for Firebase, Next.js, and Vercel stacks.
Advanced engineering intelligence for building scalable, reliable, and secure distributed backend systems.
Audit and auto-fix agent skills to remove platform lock-in and ensure cross-platform compatibility.
Monitor and analyze real-time context window usage with visual bars and detailed token breakdowns.
Turn any basic business URL into a high-end cinematic landing page with AI-generated 4K assets and GSAP animations.
Full-featured Gitea API integration for managing Codeberg repositories, releases, and multi-file commits.
Eliminate the "finish barrier" with instant, copy-pasteable commands to commit, push, and deploy your work.
Senior-level DevOps automation for CI/CD, IaC, Kubernetes, and production-ready GitOps pipelines.
Audit your codebase for technical debt and generate a prioritized, actionable remediation report.

Automate the setup and optimization of Semgrep, SonarQube, and CodeQL for high-signal security testing.
Automated security audit and health check for software dependencies across polyglot projects.
A 5-gate pre-flight audit to ensure your AI agent has the context, scope, and safety boundaries needed to code successfully.

Generate a README from your actual repo, not a hallucinated guess. Scans your manifests (package.json, pyproject.toml, go.mod, Cargo.toml) for real install steps, scripts, and dependencies across Node, Python, Go, Rust, and Java. Documentation that matches the code instead of drifting from it.
Professional IGDB v4 API specialist for advanced game data fetching, Apicalypse queries, and image URL construction.
Design and evaluate production-grade observability systems using the 12-layer Full Stack Observatory reference model.

Transforms vague coding requests into precise, scoped, testable, AI-ready prompts for Cursor, Claude Code, Codex CLI, Replit, and other coding agents.
Reliable, health-gated autonomous operations for agents in restricted or sandboxed terminal environments.
Turn any business URL into a high-converting, agency-grade landing page with AI-generated 4K cinematic visuals, GSAP scroll animations, and one-command Cloudflare Pages deployment.
Turn your AI agent into a coordinator that manages parallel subagents for complex coding and research tasks.
A structured framework for planning, reviewing, and evolving complex software systems with explicit trade-offs.
Track GitHub repository growth trends, star velocity, and commit activity with historical digests and benchmarking.
Catches dangerous database migrations before they hit production. Reviews schema changes for locking hazards, data loss, missing rollbacks, and index issues across PostgreSQL, MySQL, and SQLite.
Operational SOP for debugging, repairing, and maintaining Telegram-to-OpenCode bridge bots and persisted sessions.
Turn AWS billing mysteries into 10-minute root cause reports by correlating cost spikes with engineering events.
Transform raw incident logs and Slack threads into blameless, structured postmortems and 5-Whys RCA reports.

Creates safe modernization roadmaps for old, messy, undocumented, or fragile codebases, including risk audits, refactor phases, dependency reviews, testing plans, migration steps, and AI coding prompts.
High-precision test gap analysis that prioritizes untested code by risk and identifies missing edge cases.

Design rigorous chaos engineering experiments and resilience audits to verify production system reliability.
Automated pipeline to scrape, filter, score, and deliver high-quality VLESS proxies via Telegram bot.

Automated security and compatibility firewall for installing AI agent skills and Codex/OpenClaw packages.
Battle-tested orchestration framework for running 3+ Claude Code agents in parallel. Covers task routing, denbun handoff protocol, exponential-backoff retry, rate-limit guards, structured JSON logging, and automated self-healing — patterns from real production deployments.

Supercharge repo exploration and refactoring with semantic call-graph tracing and structural AST pattern matching.
Audit dependencies for security, licenses, and health while generating a phased, low-risk upgrade and migration plan.
Transform AI claims into verified, risk-assessed technical reports for production, DevOps, and enterprise governance.

Designs and upgrades business automation systems into modular, reliable, observable, secure, low-maintenance, enterprise-grade workflows.
Select the smallest honest verification set for a change, including targeted tests, manual checks, missing-test recommendations, a broader fallback, and named remaining risk.
Automate real Chrome profiles with a professional CLI, SDK, and MCP-ready automation stack for AI agents.

Generate beautiful release notes and changelogs automatically from commits, pull requests, and deployments.

Fix the 'it works on my machine' problem before you touch the code. Diagnoses local setup failures across Node, Python, Go, and Docker: missing dependencies, broken env vars, port conflicts, stale installs, and 'why won't this run?' sludge, then hands you copy-paste bash fixes.

Generate Conventional Commit messages from your staged git diff: auto-detects type and scope from the changed files, flags breaking changes, and keeps work-in-progress out of the message. Clean, searchable history that plays nicely with automated changelog tools.

Audit, score, and improve your AI agent skills for higher quality, lower token costs, better reliability, and marketplace success. Get actionable recommendations for prompts, instructions, tool usage, error handling, and user experience.

Security review of Kandji agent configurations, library items, and automation for compliance and safety
Simple HTTP health checker that monitors your endpoints and sends Telegram alerts when they go down or recover.
Canonical Next.js bridge for secure, real-time communication between browser UIs and local agent gateways.

Scaffold and audit secure MCP servers with input schemas, confirmation gates, and safety-first tool definitions.
Audit applications against 12-Factor methodology to identify architectural risks and generate cloud-native fix plans.
Generate production-ready, commented Nginx configurations from plain English descriptions.
Replace fragile prompt-chains with a strict, artifact-driven DAG orchestration system for reliable agent workflows.

Review Jamf and Kandji scripts for safer user context, prompts, logging, and rollout readiness.
A production-ready Python integration for Gemini using a unified AIProvider interface for easy model swapping.

Catch the dangerous migration before it locks or wrecks your production database. Scans SQL migration files for destructive and risky operations: DROP and TRUNCATE, drops without IF EXISTS, lossy column-type changes, NOT NULL added without a default, DELETE or UPDATE with no WHERE, non-concurrent index builds, dropped constraints, renames, and data backfills mixed into schema changes. Each finding is ranked by severity with a safer rewrite. Postgres, MySQL, and SQLite.
Secure, battle-tested patterns for user detection and credential prompting in Jamf and Kandji scripts
Evaluates AI coding agent platforms across five structural dimensions that determine real-world performance independently of model quality, so teams select on architectural fit rather than benchmark scores.
Fast, free image classification using ResNet-50 on Cloudflare Workers AI with 1,000+ object categories.
Free summarization of articles, files, and URLs using BART Large CNN on Cloudflare Workers AI.

Enforce small, verified, and rollback-safe code increments to prevent AI scope creep and broken builds.

Flag the destructive operations in a shell command or script before anyone runs it. Catches recursive force deletes, force pushes and history rewrites, database drops and truncates, disk-wipe commands (mkfs, dd to a device), permission blowouts (chmod 777), remote content piped into a shell, broad wildcard deletes, and prod-targeting or disabled-safety flags. Each finding comes with a severity and a safer alternative.
The ultimate pre-commit checklist agent for cleaning code, updating docs, and validating repository state.
Instantly deploy text, JSON, files, or full static sites to brewpage.app with zero configuration.

Secure authentication and account resolution for Mailtrap Email Sending, Sandbox, and Account APIs.
Build, patch, and fix Jira Cloud automation JSON files for advanced rules, unique lookup variables, and HTML emails.

An adversarial reviewer for AGENTS.md and agent instruction files. It flags ambiguous or contradictory rules, missing guardrails, vague tool and scope definitions, and untestable instructions, then returns a PASS / REVISE / BLOCK verdict — before the config drives your agent.

Transform chaotic support into structured operations with playbooks, triage rules, and automated QA rubrics.
Turn Apple endpoint work into clean change tickets.

Professional DevOps diagnostics for AI agents to solve failed deployments, Docker crashes, and CI/CD pipeline errors.
Free, direct translation across 100+ languages using Meta M2M-100 on Cloudflare Workers AI.
Deploy production-grade, AI-powered Telegram bots to Raspberry Pi with automated server hardening and scheduled jobs.
Automatically generate and update a professional CHANGELOG.md from your git history and Conventional Commits.
Orchestrate a production-grade, multi-tenant SaaS stack on a single Raspberry Pi or budget VPS.
Avoid context bloat and high costs with a 3-line verdict on expensive AI operations before you run them.

Stop guessing and start solving with hypothesis-driven debugging for complex, intermittent, and production-only bugs.
The production-ready deployment engineer for Next.js, Firebase, Supabase, and Stripe stacks.

Architect safe, staged code migrations with zero-downtime patterns and automated rollback gates.

Architect, scaffold, and audit enterprise-grade Playwright test suites with professional CI and auth patterns.
A safe, expert-level database troubleshooter for fixing migrations, performance issues, and schema drift.
Intelligently delegate tasks to Claude, Codex, or Gemini based on cost, model strengths, and rate limits.

Design and analyze industrial control system anomaly detection logic for safe, protocol-aware OT security monitoring.
Expert AWS architecture guidance for building secure, scalable, and cost-optimized production environments.

Diagnose why your Docker Compose stack won't come up: port conflicts, bad or missing env vars, absent healthchecks, volume and permission issues, depends_on that doesn't wait for readiness, networking gaps, platform mismatches, and databases that aren't ready. Reads your docker-compose.yml and logs and ranks the blockers with fixes.
A professional systematic framework for AI agents to analyze, resolve, and verify complex git merge conflicts.
The security auditor for AI agents. Detect prompt injection, secret leaks, and unsafe tool access in SKILL.md files.
Optimize task execution by intelligently dispatching work to parallel subagents with ready-to-paste prompts.
Automated open-source license audit and risk assessment based on your project's specific distribution model.

Scan a SKILL.md package for prompt injection and secret exfiltration before you install or publish an agent skill. Flags env-variable-to-URL exfiltration wording, conditional triggers with hidden side effects, imperative instructions buried in HTML comments, zero-width characters, base64 and long-token blobs, remote content treated as instructions, pipe-to-shell and recursive force-delete references, and overbroad tool requests (network plus browser plus file-write with no scope).
Automatically detect your tech stack and generate a production-ready GitHub Actions CI/CD workflow.

Generate a deep, evidence-based Software Quality Strategy grounded in your repository's actual code and maturity level.

Generate a ready-to-use LICENSE file for your repo. Pick from MIT, Apache-2.0, GPL-3.0, MPL-2.0, BSD-2-Clause, BSD-3-Clause, or The Unlicense, fill in your name and year, and get the canonical license text. Prints to the screen by default and writes a LICENSE file only when you ask.

Design, validate, and orchestrate A2A-compliant multi-agent systems using artifact-driven Mesh Flow DAGs.

Designs robust Windows desktop automation workflows using pywinauto, UI Automation, hotkeys, image matching, OCR, retries, logging, screenshots, and safety controls.

Creates structured troubleshooting runbooks for legacy banking systems with incident classification, dependency mapping, log review checklists, escalation paths, rollback guidance, and post-incident summaries.
Comprehensive security auditing for AI agents, covering prompt injection, tool permissions, and data leakage risks.
Scan multi-language codebases for unused variables, orphaned functions, and unreachable code with severity ranking.
Keep Node.js and Python services running forever with PM2 — startup, health checks, troubleshooting.

Find where knowledge is dangerously concentrated in a codebase. From your git history it flags the files only one person has ever touched, the high-churn files with a single owner, authors who own too much of the codebase, and the repo's overall truck factor. The catchy question with a real answer: what breaks if a key person leaves.

Audit your SPF, DKIM, and DMARC records for the misconfigurations that get mail rejected or sent to spam. Flags a missing DMARC record or p=none, missing rua reporting, a missing or duplicated SPF record, SPF over the 10-lookup limit, permissive +all/?all, a missing DKIM selector, and SPF/DKIM domain-alignment mismatches. Paste a DNS zone file or dig/nslookup output.
Secure, guardrail-first Render deployments and service management via MCP with mandatory approval gates.

Find and remove commented-out dead code across 8 languages (JS, TS, Python, Java, Go, Rust, HTML, CSS) while preserving TODOs, FIXMEs, license headers, disabled tests, and real documentation. Previews every change first and writes .bak backups before it touches a file.

Transform ambiguous AI tasks into auditable execution traces with verified evidence and AI-smell detection.
Design deterministic Mesh Flow guardrail topologies and verifier contracts for complex multi-agent AI systems.
Brain.co & note.com auto-publishing with quality gate & bot bypass
Expert IaC auditing for Terraform and OpenTofu to catch security holes, cost leaks, and state management risks.
Design, debug, and harden AI control loops with explicit contracts and automated verification harnesses.
Automate secret scanning with gitleaks — detect API keys, passwords, tokens before incidents.
Professional-grade Kubernetes YAML auditor for security, API deprecations, and deployment best practices.

Save, name, list, and restore git stashes without losing track of what's in them. Auto-labels each stash with its branch, timestamp, and a summary, shows them in a clean numbered list, and warns before you pop into a dirty worktree. No more digging work out of the couch cushions.
Generate a staged, phase-numbered deployment system with automated backups, migrations, and health checks.
Monitor your local Ollama server and get Telegram alerts when models crash, the GPU runs out of memory, or downloads stall.

Review macOS admin scripts for reliable current-user detection and safe session-context handling.

Penetration-test your Claude Code agent's guardrails before you deploy. Throws prompt-injection payloads, shell-chaining, and path-traversal attempts at your PreToolUse/PostToolUse hooks and sensitive-file protections, then returns a pass/fail report on 10+ attack vectors with copy-paste remediation for every gap.
Diagnose and fix Windows-specific AI coding agent failures across shells, paths, WSL, locks, ports, and CRLF diffs.

Enforce explicit context discipline, artifact-gated transitions, and verification evidence for AI agent workflows.
Drive several real Chrome profiles, each with its live Google login, at once via Kimi WebBridge — multi-profile browser automation in your real Chrome, not headless.
Diagnose and fix broken local LLM stacks, GPU issues, and stalled model downloads across Ollama, LM Studio, and more.

Audits Dockerfiles and Compose setups for production readiness, security risks, image size, build speed, health checks, secrets handling, and deployment compatibility.
A universal, multi-role AI engineering team for autonomous planning, implementation, and rigorous code review.
Automated, high-precision code reviews that detect bugs, security flaws, and performance bottlenecks in your PRs.

An evidence-first debugging workflow for agents to identify, reproduce, and surgically fix software defects.

Compress noisy chat logs and logs into durable, high-signal memory reports with built-in duplicate suppression.
Detect and assess CVE-2026-31431 "Copy Fail" vulnerability on Linux systems and Kubernetes clusters.
Create n8n credentials programmatically via REST API, including a workaround for the cryptic allOf validation bug that blocks OAuth2 credential creation.
Debug n8n workflow execution errors fast. Diagnoses common failures, checks docker dependencies, and deactivates/reactivates workflows to fix stuck states.
Benchmark your DevOps performance against DORA standards and generate a prioritized 90-day improvement roadmap.
Expert regex architect for building, auditing, and optimizing high-performance, ReDoS-safe patterns.

Debug failing GitHub Actions without scrolling 10,000 log lines. Reads the logs from the first failing step, pinpoints the root cause (missing secret, dependency mismatch, YAML syntax, permissions), and hands you a copy-paste fix, then offers to open the PR. GitHub CLI required.

You changed the prompt, tried four inputs, it looked better, you shipped — and three days later support tickets say outputs are worse for an entire class of inputs you didn't test
Async task delegation for AI agents via shared folders—perfect for cross-OS and remote worker coordination.

Find the model-version coupling that breaks when you swap LLMs. Flags hardcoded model names and versions, deprecated or renamed parameters (the max_tokens to max_completion_tokens class of change), hardcoded token and context-window limits, response-format parsing tied to one model's output, tool-schema format coupling between providers, and hardcoded per-token cost constants. The patterns load from an editable model-rules table you update as new models ship.
Generate hardened, production-ready systemd service units with auto-restart, sandboxing, and install scripts.
Turn git commit history into structured, categorized changelogs with automatic SemVer bump detection.
Run Claude Code unattended with a battle-tested safety framework, hardened deny-rules, and a 6-layer rollback ladder.

Protects API endpoints from accidental breaking changes by generating contract maps, validation rules, integration tests, documentation, and safe AI coding prompts.

Generate animated, step-by-step data flow diagrams for architectures, code paths, and user journeys.

Audits Kubernetes manifests, Helm values, deployment logs, and service configs to detect configuration errors and produce safe, reviewable fix plans.
Free speech-to-text and SRT subtitle generation using OpenAI Whisper on Cloudflare Workers AI.
Stop burning expensive model tokens on repetitive subtasks. This skill delegates mechanical work to cheaper models and writes handoff snapshots so you never lose context switching between sessions.
Diagnose Jamf app, package, and App Installer failures.
Transform brittle prompt chains into robust, artifact-driven DAG workflows with hard gates and explicit traces.
A rigorous 8-phase validation pipeline to audit environment, security, data migrations, and API stability before deploy.
Production-ready ARQ background workers for FastAPI with Redis heartbeats, cron jobs, and hardened systemd units.
Distill messy chat logs and project notes into dense, action-oriented briefs optimized for AI agents.
Protect Java desktop apps by migrating sensitive logic and API keys to a secure, Cloudflare-backed thin-client architecture.
Preflight Jamf smart group and deployment scope mistakes.
Your agent writes the code but never commits or documents what it learned. This skill handles both automatically after every task.
A production-grade 5-stage subagent dispatch chain to catch bugs and secure solo SaaS deployments.

An adversarial gate that audits cloud and infrastructure-as-code config — Terraform, Kubernetes, IAM, security groups, buckets — for the misconfigurations that cause real breaches, and returns a structured PASS/REVISE/BLOCK verdict with severities and exact fixes before anything reaches your environment.
Audit README files for broken links, missing sections, and formatting issues to ensure professional documentation.
Audit codebases for structural debt, TODOs, and dependency rot to generate prioritized remediation reports.
Establish and refine surgical CI quality gates and automated verification loops for any repository.

Standardize agent collaboration with high-density mission packets, strict authority boundaries, and return contracts.

An adversarial reviewer for Dockerfiles and container builds. It flags root users, image bloat, unpinned or cache-busting layers, leaked secrets, and missing hardening, then returns a PASS / FIX / BLOCK verdict — before you build or push the image.
Scaffold a multi-model 6-step pipeline to automatically turn prospect URLs into live, branded demo websites.
Free, high-speed SDXL Lightning text-to-image generation via Cloudflare Workers AI.

Figure out why your Vercel build or deploy failed without scrolling the whole log. Reads the build log plus your package manifest and framework config to pinpoint missing modules, Node and package-manager mismatches, missing env vars, monorepo root mistakes, and serverless/edge runtime errors, with the likely cause and a fix for each.
Bypass Cloudflare WAF, reCAPTCHA v3, and Vue.js bot detection in one skill.

Turn git history into clean release notes: parses Conventional Commits across a tag range or commit window, groups them into Features, Fixes, and Breaking Changes, translates the jargon into plain English, and suggests the next SemVer bump. Markdown ready for GitHub, GitLab, or your CHANGELOG.md.
Give your AI a cheat sheet filled with all of the things that matter most to your codebase.
Generate production-ready, best-practice Docker Compose files for complex multi-service applications — with health checks, volumes, networks, and environment-specific overrides built in.
Enforce security, reliability, and deployment best practices for Docker Compose files.
Synced shared screen for a Three.js multiplayer room: a SharedScreen client (YouTube on a canvas texture, clock-based playback tracking, 3D positional audio), a screenHandlers Colyseus pattern (setUrl, play, pause, seek, volume, stop, controlled-by tracking), an optional yt-dlp plus ffmpeg proxy, and an optional Puppeteer BrowserManager. Field-verified from nex-vr-room.

Audit a Helm chart for insecure defaults before you deploy to Kubernetes. Flags privileged containers, allowPrivilegeEscalation, missing CPU/memory limits and requests, hostPath volumes, hostNetwork/hostPID/hostIPC sharing, readOnlyRootFilesystem not set, runAsNonRoot not enforced (or runAsUser 0), plaintext secrets in values.yaml, missing NetworkPolicy, and NodePort/LoadBalancer services exposed without restriction.

Review scripts and docs for safer handling of passwords, tokens, keys, and sensitive values.
Tail log files, filter by regex patterns, and send Telegram alerts when errors or warnings appear.
Deploy production-ready Discord Activities to a Raspberry Pi with Colyseus multiplayer and Cloudflare Tunneling.
Enterprise-grade WhatsApp Business Cloud API integration for Python with session window management and webhook security.
Manage multiple Postgres versions and extensions on one Linux box with a port registry and unified backups.
Audit project manifests against source code to find unused, missing, and misplaced dependencies across major languages.
Automated 8-point pre-deployment safety audit to catch breaking migrations, missing env vars, and CVEs.

Turn a .env into a safe .env.example you can commit. Keeps every key, strips every value, preserves your comments and key order, and flags the secret-looking keys so you know which ones to rotate. Prints to the screen by default and writes .env.example only when you ask.
Professional-grade git diff auditor that identifies security vulnerabilities and code smells before you merge.
Generate modular Azure Bicep IaC to deploy Metabase on Azure Container Apps with PostgreSQL.
Daily backup-and-restore for a self-hosted Postgres app or Pi: a custom-format pg_dump, app-data tar, config copy, keep-window rotation, and a low-disk Telegram alert, plus a confirm-to-proceed restore, systemd timer, and idempotent install.

Lint an exported n8n workflow before it ships: catches broken or duplicated nodes, missing error handlers, credential stubs, unhandled retries, unsafe webhooks, brittle expressions, and missing idempotency. A read-only pass over your workflow JSON that ranks production-readiness gaps with evidence and concrete fixes.
Generate a production-ready 3D virtual office for AI agents using Next.js and React Three Fiber.
A specialized security architect skill for performing deep audits, compliance checks, and DevSecOps integrations.

Orchestrate independent reviews, adversarial audits, and multimodal analysis via secondary models and external tools.
Automated governance and risk audit for AI agent tool permissions and authentication boundaries.
Transform "gut feeling" into data-driven build-vs-buy decisions with TCO estimates and risk analysis.
Auto-detect your tech stack and generate a comprehensive, organized .gitignore file instantly.
Audit Snowflake config and SQL against 2026 pricing to find waste and generate instant-fix ALTER statements.

Check your robots.txt and sitemap.xml for the mistakes that quietly block crawlers. Flags a site-wide Disallow: /, malformed directives, a missing Sitemap: line, sitemap XML that is not well-formed, <loc> URLs missing a scheme, mixed http and https, and sitemaps over the 50,000-URL or 50MB limits. Reads local files or pasted text and never touches the live site.
Apply the 5-step engineering algorithm to ruthlessly delete, simplify, and accelerate any process or codebase.

Diagnoses unreliable tests, identifies root causes, creates stabilization plans, and generates safe AI coding prompts for fixing flaky unit, integration, E2E, and CI tests.