zotero-mcp-code
Search Zotero library using code execution for efficient multi-strategy searches without crash risks. Use this skill when the user needs comprehensive Zotero searches with automatic deduplication and ranking.
Yieldoracle
DeFi Yield Intelligence MCP — 8 tools: 19K+ pools, risk-adjusted APY, RWA yields.
app-store-preflight-compliance
Pre-submission compliance scanner workflow for Apple App Store apps. Use when reviewing iOS, macOS, tvOS, watchOS, or visionOS projects (Swift, Objective-C, React Native, Expo) for App Store rejection risks, submission readiness, privacy compliance, or guideline violations.
FeedOracle Stablecoin Risk
7-signal stablecoin risk scoring. 13 tools, 28+ tokens, SAFE/CAUTION/AVOID verdicts.
requirements-test-coverage-mapper
Map requirements (PRD/user stories/AC) to comprehensive test coverage using a traceability matrix (RTM). Outputs coverage gaps, risks, test levels, prioritization, automation candidates, and change-impact notes. Designed for QA/Test Architect workflows.
Project Management AI Analysis
AI-powered project analysis with risk identification, forecasting, and mitigation generation
System R Risk Intelligence
Pre-trade risk validation and position sizing for AI trading agents via G-formula and Iron Fist.
AutoTS
Automated time series forecasting with model search, anomaly detection, and event risk analysis
Bitsbound Contract Automation
AI contract automation with partner-level redlines, OOXML Track Changes, and risk analysis.
change-reaudit
Re-audit code changes to identify side effects, regression risks, and unhandled edge cases before merging or deploying.
schematic
Reverse engineer a detailed product and technical specification document from a git branch's implementation. Use when: (1) a branch has shipped or is in-progress and needs documentation, (2) you need to understand what a branch does at product and architecture level, (3) onboarding to someone else's feature branch, (4) creating PR descriptions or design docs after the fact, (5) user asks to "analyze this branch", "write a spec from the code", or "document what this branch does". Produces a structured markdown spec covering problem statement, product requirements, architecture, technical design, file inventories, testing strategy, rollout plan, and risks.
cycle-plan
Plan Linear cycles using velocity analytics. Suggests scope based on historical capacity, identifies dependency risks, balances workload.
pr-risk-scoring
Score all open PRs by risk level and generate a CSV report. Use when asked to rescore, rate, or triage open PRs.
Decompose
Decompose text into classified semantic units. Authority, risk, attention. No LLM.
Rug Munch Mcp
Crypto risk intelligence: 19 tools for rug pull detection, AI forensics, and token analysis.
analysing-attack
Analyse Mitre ATT&CK tactics, techniques and sub-techniques. Use when performing analysis of threat detections, threat models, security risks or cyber threat intelligence
Io.Github.SPIRY RO/Slush Meme Mcp
AI-native meme coin launchpad on Avalanche. Deploy tokens, simulate trades, query risk.
coding-agent-standards
Defines practical standards for implementation-focused coding agents. Use when creating or editing code, especially when reliability, clarity, and low-risk delivery are required.
ac-verify
Lightweight single-pass AC verification before Archive â run implementation against each AC, produce pass/fail evidence. FAIL blocks Archive and rolls back to Phase 4. Mutually exclusive with ultraqa: choose ac-verify when AC count ⤠3 AND risk â HIGH; otherwise use ultraqa. See .claude/rules/skill-precedence.md Zone C.
agent-estimation
Accurately estimate AI agent work effort using the agent's own operational units (tool-call rounds) instead of human time. Use when asked to estimate, scope, plan, or evaluate how long a coding task will take. Prevents the common failure mode where agents anchor to human developer timelines and massively overestimate. Outputs a structured breakdown with round counts, risk factors, and a final wallclock conversion.
IncomeBot Trading Intelligence
Options trading — regime detection, momentum scanning, income screening, and risk simulation.
Io.Github.Lordbasilaiassistant Sudo/Contract Scanner
Smart contract security scanner — vulnerabilities, risk scores, and calldata decoding
analyze-feature-requests
Analyze and prioritize a list of feature requests by theme, strategic alignment, impact, effort, and risk. Use when reviewing customer feature requests, triaging a backlog, or making prioritization decisions.
CRAP Analyzer
CRAP (Change Risk Anti-Patterns) flags functions that are both **complex** and **poorly tested** â the worst-risk code to ship.
Threat Modeling Skill v3.1.0 (20260313a)
AI-native automated software risk analysis skill. LLM-driven, Code-First approach for comprehensive security risk assessment, threat modeling, security testing, penetration testing, and compliance checking.
backend-mvp-guardrails
Use when designing or reviewing a backend MVP with tight budget, evolving schema, and reliance on third-party backends where idempotency, replay, and responsibility attribution are high-risk.
create-a-plan
Conduct a focused technical planning interview to produce an implementable, parallelizable plan or spec with clear dependencies, risks, and open questions.
Philidor DeFi Vault Risk Analytics
Search 700+ DeFi vaults, compare risk scores, analyze protocols. No API key needed.
architectural-analysis
Performs deep architectural analysis of a specified module, directory, or feature area by examining structural coupling, data flow, concurrency patterns, risk, and SOLID alignment. Use when the user wants to assess, evaluate, or review the architecture, design quality, dependency structure, coupling, cohesion, or technical debt of an existing part of the codebase â including requests to audit module boundaries, check for architectural smells, or inform refactoring decisions. Requires a specific focus area (module, directory, or component) to analyze. Not for creating new project structures, scaffolding, or boilerplates. Not for investigating specific bugs, runtime errors, or failures â use investigate. Not for test planning â use test-planning. Not for file-level code review â use code-review. Not for writing documentation or architectural decision records.
auditing
Use when reviewing a bundle-plugin for structural issues, version drift, skill quality, workflow integration, or security risks â before releasing, after changes, or after adding skills. Auto-detects scope (full project vs skill vs workflow)
Credential Exfiltration Detection
Determine whether stolen credentials were actually used by attackers after a security incident. This skill walks through a four-phase investigation: scoping what was at risk, checking audit trails, identifying lateral movement, and verifying that rotation was complete.
code-change-verification
Verify code changes by identifying correctness, regression, security, and performance risks from diffs or patches, then produce prioritized findings with file/line evidence and concrete fixes. Use when reviewing commits, PRs, and merged patches before/after release.
account-health
Score a customer's health, start the renewal motion, and flag churn or expansion early. Trigger when the user asks "how's this account doing", "health check", "are we at risk of churn", "is this account ready to expand", or before a renewal or QBR.
attend
Route upstream epistemic deficits and evaluate execution-time risks during AI operations. Scans for unresolved upstream protocol needs, materializes intent into tasks, classifies each for risk signals, delegates low-risk tasks to executor, and surfaces elevated-risk findings for user judgment. Type: (ExecutionBlind, User, EVALUATE, ExecutionContext) â SituatedExecution. Alias: Prosoche(ÏÏοÏοÏή).
SupplyMaven Supply Chain Intelligence
Real-time supply chain risk scores, manufacturing index, commodities, and port data.
analyzing-dtc-stores
Use when the user provides a DTC or ecommerce store URL and asks for a teardown, breakdown, brand analysis, competitor teardown, investor memo, store audit, deep dive, or 'what's going on with [brand]'. Produces an investor-grade markdown teardown report covering brand, market, unit economics, supply chain, channel mix, marketing, reviews, agentic-commerce readiness, risks, and a falsifiable verdict. Triggers: 'dtc teardown', 'brand teardown', 'store teardown', 'competitor teardown', 'analyze this store', 'investor memo on [brand]', 'break down [store url]'. Do NOT use for SEO-only audits, design-system extraction, lead-gen scraping, or general web scraping with no brand/investor focus.
ai-adoption-rollout
The tool is chosen; the risk now is **people**. This plans the human rollout: who gets it when, what they're taught, who they ask, what they're told, and the observable that must hold before the next cohort opens.
Io.Github.Ark Forge/Mcp Eu Ai Act
EU AI Act compliance MCP server. Scans AI codebases, classifies risk, provides remediation guidance.
-21risk-automation
Automate 21risk tasks via Rube MCP (Composio). Always search tools first for current schemas.
code-review-expert
Expert code review of current git changes with a senior engineer lens. Detects SOLID violations, security risks, and proposes actionable improvements.
precoil-emt
Use this skill when the user wants to test a business idea, strategy, or initiative against real-world risk. Triggers include: 'test my idea', 'what are the riskiest assumptions', 'help me validate this', 'run EMT on this', 'extract assumptions', 'assumption mapping', 'what could go wrong with this plan', 'pressure test this', 'validate this plan', 'what could go wrong with this strategy', 'identify hidden risk in this idea', or any request to pressure-test a business decision before committing resources. Runs a guided Extract â Map â Test system based on David J. Bland's Precoil methodology.
Policycheck
AI seller verification and policy risk analysis for any online store.
roadmap-safety-execution
Plans and executes roadmap work in one-by-one low-risk change-sets with mandatory gates (feature flags, tests, rollback path, and acceptance checks). Use for multi-phase delivery where regressions must be minimized.
auto-frame
Bound and de-risk a request into SPEC.md. Use when the objective is clear but scope needs constraining.
Implementation Plan Generator
> **Quick Ref:** Mode detect â ingest or analyze â interactive input â understand â size â impact â phased plan â risk â test â rollback â write â proceed.
DeepMap AI
Multi-hazard geophysical risk scoring, prediction, weather, insurance, and climate tools
code-confidence-map
Assesses code comprehensibility and maintainability risk. Use when the user asks about code confidence, risk, maintainability, tech debt, code health, or whether code is safe to change. Also use when the user asks to analyze code quality, scan for risks, check if code is messy or complex, audit code, do a code checkup, find weak spots, assess what needs refactoring, or asks about code trust, hidden risks, gotchas, or onboarding to a codebase.
Clawdfolio
Quantitative portfolio toolkit for professional investors. Multi-broker aggregation (Longport, Moomoo/Futu, demo), institutional risk analytics, options strategy lifecycle management, 20+ automated finance workflows, and CSV/JSON data export.
kraken-autonomy-levels
Progress from manual trading to full agent autonomy with controlled risk at each level.
StressZero MCP - Burnout Risk Scoring
Burnout risk scoring across 3 dimensions (physical, emotional, effectiveness)