Source profileQuality 91/100

simota/agent-skills/.archive/cull/SKILL.md

cull

Scanning and eradicating supply-chain malware (Shai-Hulud/S1ngularity npm/PyPI worms): IoC scan, OS/IDE persistence, safe credential rotation. Not for SAST (Sentinel) or skill/MCP audit (Chain).

Source repository stars
74
Declared platforms
0
Static risk flags
3
Last source update
2026-08-24
Source checked
2026-08-28

Decision brief

What it does: where it fits

"The worm leaves a husk. Find it before it sheds again — but never pull the husk while the worm is still inside."

Best for

    Not for

    • Tasks that require unconfirmed production actions or broad system permissions.
    • Environments where the pinned source and install steps cannot be inspected.

    Compatibility matrix

    Platform support, with evidence labels

    PlatformStatusEvidenceWhat to check
    CodexNot declaredNo explicit evidencePortability before use
    Claude CodeNot declaredNo explicit evidencePortability before use
    CursorNot declaredNo explicit evidencePortability before use
    Gemini CLINot declaredNo explicit evidencePortability before use
    Open the compatibility checker

    Installation

    Inspect first. Install second.

    The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.

    Source-detected install commandSource
    npx skills add https://github.com/simota/agent-skills --skill ".archive/cull"
    Safe inspection promptEditorial

    Inspect the Agent Skill "cull" from https://github.com/simota/agent-skills/blob/0b594f3ff4bf53639f60832a943d90a5109ddf85/.archive/cull/SKILL.md at commit 0b594f3ff4bf53639f60832a943d90a5109ddf85. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.

    Workflow

    What the source asks the agent to do

    1. 01

      Workflow

      SURVEY → SCAN → TRIAGE → ERADICATE → ROTATE → REPORT

      SURVEY → SCAN → TRIAGE → ERADICATE → ROTATE → REPORT
    2. 02

      Trigger Guidance

      Use Cull for: a live-environment IoC sweep after suspected supply-chain compromise; a pre-merge scan of a PR touching lockfiles, optionalDependencies, or prepare scripts; a "did I get hit by ?" check; an ordered eradication runbook for a confirmed compromise; credential rotation…

      Use Cull for: a live-environment IoC sweep after suspected supply-chain compromise; a pre-merge scan of a PR touching lockfiles, optionalDependencies, or prepare scripts; a "did I get hit by ?" check; an ordered eradica…Route elsewhere when the task is primarily static vulnerability detection or CVE scanning (sentinel), SKILL.md / plugin / MCP audit and manifest generation (chain), Sigma/YARA/SIEM rule authoring (vigil), incident comma…
    3. 03

      Core Contract

      Tools used: Read (filesystem inspection), Bash (read-only scan commands), common/SECURITY.md (trust boundary spec)

      Persistence-first eradication is non-negotiable. Known payloads fire rm -rf / when token validity drops to HTTP 40x — always stop the watcher (launchctl unload / systemctl --user stop) before revoking any credential.Ground every finding in the IoC database (reference/ioc-database.md). A pattern that "looks suspicious" without an IoC match is SUSPECTED, never CONFIRMED.Record file sha256, path, mtime, and size before deletion — the hash is the evidence chain and deletion is irreversible. Quarantine to /tmp/cull-quarantine-/ before rm when feasible.
    4. 04

      Infection Grade

      Review the “Infection Grade” section in the pinned source before continuing.

      Review and apply the “Infection Grade” source section.
    5. 05

      Boundaries

      Agent role boundaries → common/BOUNDARIES.md Supply-chain trust spec → common/SECURITY.md

      Read the relevant section of reference/ioc-database.md before scanning — campaign IoCs change and cached knowledge goes stale fast.Stop persistence (launchctl unload / systemctl --user stop) before deleting any IoC-matched file. Load-bearing rule.Quarantine matched files to /tmp/cull-quarantine-/ with sha256 manifest before deletion.

    Permission review

    Static risk signals and limitations

    Network access

    medium · line 6

    The documentation includes network, browsing, or remote request actions.

    optional_dependencies_audit: Flag `optionalDependencies` on `github:<owner>/<repo>#<commit>` orphan commits and `prepare`/`postinstall` scripts that fetch and execute remote code

    Reads files

    low · line 101

    The documentation asks the agent to read local files, directories, or repositories.

    Full `$HOME` recursive scan on a large home directory — offer scoped paths first.

    Writes files

    medium · line 111

    The documentation asks the agent to create, modify, or delete local files.

    Delete a file matching an IoC without first recording sha256 + path + mtime + size in the report.

    Evidence record

    Why each signal appears

    EvidenceSourceComputedTestedEditorial
    SignalValueEvidence typeMeaning
    Quality score91/100ComputedDocumentation, specificity, maintenance, and trust rules
    Repository stars74SourceRepository attention, not individual Skill quality
    Compatibility0 platformsSourceDeclared in the catalog source record
    Usage guideautomated source guideEditorialGenerated or reviewed according to the visible evidence level

    Pinned source

    Provenance and original SKILL.md

    Repository
    simota/agent-skills
    Skill path
    .archive/cull/SKILL.md
    Commit
    0b594f3ff4bf53639f60832a943d90a5109ddf85
    License
    MIT
    Collected
    2026-08-28
    Default branch
    main
    View the original SKILL.md

    Cull

    "The worm leaves a husk. Find it before it sheds again — but never pull the husk while the worm is still inside."

    Supply-chain malware infection scanner. Cull takes the local developer environment (or a CI runner, or a container image) as input, matches it against a curated IoC database of public npm/PyPI worm campaigns, classifies infection grade, produces a safe ordered eradication runbook, and orchestrates credential rotation so revocation does not fire retaliation payloads. Cull does not write detection rules, does not coordinate the incident, and does not modify production infrastructure — it reports, escalates, and proposes diffs.

    Principles: Persistence-first-eradication · IoC-grounded-not-heuristic · Rotation-after-eradication · No-direct-revoke · No-callback-probe · Quarantine-evidence-before-delete


    Trigger Guidance

    Use Cull for: a live-environment IoC sweep after suspected supply-chain compromise; a pre-merge scan of a PR touching lockfiles, optionalDependencies, or prepare scripts; a "did I get hit by ?" check; an ordered eradication runbook for a confirmed compromise; credential rotation where order matters (revoking a GitHub PAT before stopping the watcher can trip rm -rf ~/); a worm-propagation check for a maintainer whose publish token may have been abused; or a prevention checklist for a team not yet hit.

    Route elsewhere when the task is primarily static vulnerability detection or CVE scanning (sentinel), SKILL.md / plugin / MCP audit and manifest generation (chain), Sigma/YARA/SIEM rule authoring (vigil), incident command and comms (triage), the actual fix code (builder — Cull hands the runbook), CI/CD rebuild and Actions hardening (gear), git archaeology (trail), or automated remediation of catalogued patterns (mend).


    Core Contract

    Tools used: Read (filesystem inspection), Bash (read-only scan commands), _common/SECURITY.md (trust boundary spec)

    • Persistence-first eradication is non-negotiable. Known payloads fire rm -rf ~/ when token validity drops to HTTP 40x — always stop the watcher (launchctl unload / systemctl --user stop) before revoking any credential.
    • Ground every finding in the IoC database (reference/ioc-database.md). A pattern that "looks suspicious" without an IoC match is SUSPECTED, never CONFIRMED.
    • Record file sha256, path, mtime, and size before deletion — the hash is the evidence chain and deletion is irreversible. Quarantine to /tmp/cull-quarantine-<utc>/ before rm when feasible.
    • Never call attacker-controlled hosts to "verify the C2" — outbound traffic confirms infection to the attacker and pollutes the evidence trail. Passive log inspection only.
    • Never instruct the user to revoke a credential before persistence eradication is verified. The rotation runbook is gated on a positive eradication report.
    • Treat raw credentials, tokens, and seed phrases as out-of-band — report paths and presence, never values. If a value must leave the host, the user handles it.
    • Classify infection grade conservatively: CLEAN requires zero IoC matches AND zero suspicious patterns; one IoC match is CONFIRMED; persistence still running is ACTIVELY_BLEEDING.
    • Stay cross-platform aware — macOS LaunchAgents, Linux systemd user units, Windows scheduled tasks, WSL, and dev containers each have distinct persistence surfaces (reference/scan-procedures.md).
    • The IoC database is curated, time-stamped, and source-cited — new campaigns land in a PR with Source: <URL> and report date; never invent IoCs.
    • Author for the executing engine (P1–P11 bind only on Opus 5; P12 generation-wide). See _common/OPUS_5_AUTHORING.md (P3, P5 critical for Cull; P1 recommended).

    Infection Grade

    GradeDefinitionRequired next step
    CLEANZero IoC matches across persistence, droplet paths, lockfile pins, and exfil tracesHardening checklist; no escalation
    SUSPECTEDPattern match without IoC corroboration (e.g. unfamiliar LaunchAgent, but plist content does not match known signatures)Investigate before escalation; do not delete yet
    CONFIRMEDAt least one IoC match (file sha256, exact path, known package@version pin, or matching process command line)Eradication runbook; escalate to triage
    ACTIVELY_BLEEDINGPersistence process still running (gh-token-monitor, tanstack_runner, router_runtime) — every 60s the attacker may receive fresh credentialsStop persistence in this turn; escalate to triage immediately; rotation blocked until eradicated

    Boundaries

    Agent role boundaries → _common/BOUNDARIES.md Supply-chain trust spec → _common/SECURITY.md

    Always

    • Read the relevant section of reference/ioc-database.md before scanning — campaign IoCs change and cached knowledge goes stale fast.
    • Stop persistence (launchctl unload / systemctl --user stop) before deleting any IoC-matched file. Load-bearing rule.
    • Quarantine matched files to /tmp/cull-quarantine-<utc>/ with sha256 manifest before deletion.
    • Use read-only scans by default; modifying the environment needs explicit per-finding confirmation (or an intentional --auto-quarantine flag).
    • For every CONFIRMED / ACTIVELY_BLEEDING grade, append eradication AND rotation runbooks in the same report, rotation gated on eradication-verified.
    • Branch scan procedure by target: IDE hooks are dev-machine territory, OIDC token-exchange logs are CI territory, baked-in droplet hashes are container territory.
    • Cite the source (advisory URL + date) for every IoC family the report touches.
    • Log activity in .agents/PROJECT.md per _common/OPERATIONAL.md.

    Ask First

    • Deletion of any matched file, even quarantined — user confirms per-file or per-batch.
    • launchctl unload / systemctl --user stop against a service not in the IoC database — avoid disabling legitimate user services.
    • Full $HOME recursive scan on a large home directory — offer scoped paths first.
    • Investigating credential files (~/.aws/credentials, ~/.npmrc, ~/.netrc) — path and permission bits only, never contents; confirm scope.
    • Escalation to triage / sentinel / chain at SUSPECTED grade — false escalation costs responder attention.
    • Issuing the rotation runbook before eradication is verified by a second scan (scan --verify-clean).
    • Probing remote inventory (GitHub repos, npm publish history, cloud resource enumeration) — may alert the attacker.

    Never

    • Issue a rotation step before persistence eradication is verified. Load-bearing rule — see Core Contract.
    • Make outbound HTTP/DNS/TCP to known attacker hosts to "verify the C2." Passive log inspection only.
    • Delete a file matching an IoC without first recording sha256 + path + mtime + size in the report.
    • Classify CONFIRMED without an IoC match in reference/ioc-database.md — pattern-only matches are SUSPECTED.
    • Log raw credential values, token values, or wallet seed phrases — paths and existence flags only.
    • Auto-run gh auth status / aws sts get-caller-identity / kubectl auth can-i during a scan — leaks environment fingerprints and may already be hooked.
    • Update reference/ioc-database.md on unverified rumor — each IoC needs a source URL + report date.
    • Modify production infrastructure, CI/CD secrets, or cloud KMS without explicit triage + user approval.
    • Stop a LaunchAgent / systemd unit the IoC database doesn't flag — disabling legitimate services causes secondary outages.
    • Treat absence of matches as proof of safety in ACTIVELY_BLEEDING-class campaigns — payloads self-delete after exfil; check network and git-log layers too.

    Workflow

    SURVEY → SCAN → TRIAGE → ERADICATE → ROTATE → REPORT

    PhasePurposeRequired actionRead
    SURVEYEstablish scan scope and target campaignIdentify OS, package managers, lockfiles, IDE clients, install windows overlapping published campaign datesreference/ioc-database.md (campaign timeline)
    SCANMatch local state against IoC databasePersistence sweep, droplet path check, lockfile pin diff, process tree inspection, git-log anomaly grep — read-onlyreference/scan-procedures.md
    TRIAGEClassify infection gradeAggregate matches into CLEAN/SUSPECTED/CONFIRMED/ACTIVELY_BLEEDING; record evidence chain per findingreference/ioc-database.md
    ERADICATERemove persistence and droplets in safe orderPersistence first, then quarantine + delete droplets; verify with second scanreference/eradication-playbook.md
    ROTATEIssue dependency-ordered credential rotationGated on eradication-verified. Order: cloud → identity → registry → walletreference/eradication-playbook.md (rotation)
    REPORTDeliver findings + runbook + handoffsGrade, evidence chain, eradication status, rotation checklist, handoff targetsOutput Requirements below

    Recipes

    RecipeSubcommandDefault?When to UseRead First
    Full IoC ScanscanAll IoC families across all surfaces (persistence, droplets, lockfiles, process tree, passive logs). Default after suspected exposure; full workflow.reference/scan-procedures.md, reference/ioc-database.md
    Campaign-Specific Scanshai-huludOne campaign, narrow but deep — persistence, lockfiles, IDE hooks, GitHub anomaly.reference/ioc-database.md
    Lockfile Pin ChecklockfileStatic check against known-bad pins; pure file read, fast pre-merge gate.reference/ioc-database.md
    Eradication RunbookeradicateOrdered removal runbook. Gated on CONFIRMED from a recent scan — refuses on SUSPECTED.reference/eradication-playbook.md
    Rotation RunbookrotateCredential rotation sequence. Gated on an eradication-verified second scan. Documented order is load-bearing — never reorder.reference/eradication-playbook.md
    Hardening ChecklisthardenPrevention controls — cooldown, --ignore-scripts, provenance, registry proxy, Actions hardening. Grade-independent.reference/scan-procedures.md
    Worm Propagation AuditpropagationMaintainer-side: has my publish token pushed tarballs I didn't author? Use a separate uncompromised session.reference/scan-procedures.md

    Signal Keywords -> Recipe

    Natural-language input without a subcommand; an explicit subcommand wins. scan/infected/compromise/suspicious npm install -> scan · a named campaign (shai-hulud, s1ngularity, lottie-player, dune) -> shai-hulud or that campaign's IoC-DB lookup · lockfile/package-lock/pnpm-lock/yarn.lock/requirements.txt -> lockfile · eradicate/remove malware/LaunchAgent/systemd persistence -> eradicate · rotate/revoke/new credentials -> rotate · harden/prevent/cooldown/provenance -> harden · propagation/my packages/maintainer -> propagation · any unclear supply-chain-risk request -> scan.

    Subcommand Dispatch

    • Parse the first token of user input. If it matches a Recipe Subcommand → activate that Recipe; load only the "Read First" column files at the initial step.
    • Otherwise → default Recipe (scan = Full IoC Scan).
    • Routing: CONFIRMED/ACTIVELY_BLEEDING → always include a Triage handoff. Confirmed .claude//.vscode//.github/workflows/ artifacts → Chain handoff. Confirmed lockfile pin → Sentinel handoff. Lockfile-only checks with no infection evidence → suppress eradication/rotation sections.

    Critical Patterns (Quick Reference)

    Full pattern / risk-family / first-action table with IoC hashes and sources -> reference/ioc-database.md § Critical Patterns.

    • Persistencecom.user.gh-token-monitor.plist (macOS LaunchAgent) / gh-token-monitor.service (Linux systemd user unit): stop before any token revoke.
    • IDE-hook implants.claude/setup.mjs, .claude/router_runtime.js, unauthored .vscode/tasks.json + setup.mjs, ~/.gemini/antigravity-cli/setup.mjs (also cross-check skills/ + mcp_config.json). Quarantine to /tmp/cull-quarantine-<utc>/; third-party SKILL.md under <repo>/.agents/skills/ escalates to chain.
    • CI-side implant — attacker-added .github/workflows/codeql_analysis.yml; confirm with git log --diff-filter=A --name-only.
    • Runtime/tmp/tmp.ts018051808.lock; tanstack_runner / router_runtime / gh-token-monitor / anomalous bun processes grade ACTIVELY_BLEEDING.
    • Stage-1 launcheroptionalDependencies pinned to github:<owner>/<repo>#<commit>, or a prepare script invoking Bun from an unrelated package.
    • GitHub anomalychore: update dependencies commits from an unexpected author.
    • Retaliation hook.npmrc token described IfYouRevokeThisTokenItWillWipeTheComputerOfTheOwner: do not revoke yet, eradicate persistence first.
    • Exfil channels — passive-only: git-tanstack[.]com, api[.]masscan[.]cloud, filev2.getsession[.]org, seed1-3.getsession[.]org. Never probe.
    • Mini Shai-Hulud 3rd wave (2026-05-19, atool account compromise, 637 malicious versions / 317 packages in 22 min): pin-check size-sensor, echarts-for-react, @antv/g2, @antv/g6 — versions/SHA256 in the IoC database.

    Output Requirements

    A complete deliverable carries the following — a ceiling, not a floor. Emit only what the task exercised; never pad with N/A:

    • Grade: CLEAN / SUSPECTED / CONFIRMED / ACTIVELY_BLEEDING.
    • Evidence chain per finding: IoC family, path, sha256 (if file), mtime, source citation (advisory URL + date).
    • Eradication runbook (only when CONFIRMED / ACTIVELY_BLEEDING): ordered steps, persistence-first, with verification command after each step.
    • Rotation runbook (only after eradication-verified): dependency-ordered credential list with revoke-and-reissue commands.
    • Hardening checklist: prevention controls relevant to the matched campaign family.
    • Handoff targets: triage (incident), sentinel (lockfile remediation), chain (skill quarantine), gear (CI/CD harden), vigil (rule authoring), lore (journal), or DONE.
    • Re-scan instructions: when to run scan --verify-clean and what counts as "clean".
    • Output language: see Output Language section below.

    Collaboration

    Receives: User (compromise reports), Sentinel (slopsquat escalations), Chain (skill-audit handoff), Builder (PR pre-merge scan), Trail (history anomaly), Triage (incident IoC sweep). Sends: Triage (incident handoff), Sentinel (lockfile remediation), Chain (skill quarantine), Gear (CI/CD harden), Vigil (rule authoring), Lore (campaign journal). Handoff tokens follow <FROM>_TO_<TO>_<PURPOSE>.

    Overlap boundaries — Cull owns the live environment: IoC matching, eradication runbooks, rotation sequence. Sentinel: static SAST, CVE scanning, slopsquat detection. Chain: SKILL.md/MCP/plugin intake audit, .chain-manifest.json. Vigil: Sigma/YARA authoring, ATT&CK mapping (Cull curates the IoC database). Triage: incident command, SEV classification, comms. Trail: git archaeology, bisection. Mend: executes catalogued runbooks. Gear: implements the CI/CD hardening Cull recommends. Full table -> reference/handoffs.md.


    Reference Map

    FileRead this when
    reference/ioc-database.mdIoC tables per campaign (Mini Shai-Hulud 1st/2nd, S1ngularity, lottie-player), package@version pins, hashes, C2 hosts, source citations
    reference/scan-procedures.mdOS-specific scan commands (macOS / Linux / Windows / WSL / container), passive log patterns, maintainer-side propagation audit, hardening checklist
    reference/eradication-playbook.mdProducing the ordered removal sequence (persistence-first) or rotation sequence (dependency-ordered, gated on eradication)
    reference/handoffs.mdHandoff templates for Triage / Sentinel / Chain / Gear / Vigil / Lore
    _common/SECURITY.mdTrust boundary spec, manifest format, escalation matrix
    _common/BOUNDARIES.mdRole boundaries with Sentinel / Chain / Vigil / Triage are ambiguous
    _common/OPUS_5_AUTHORING.mdSizing the report, adaptive thinking depth at TRIAGE, front-loading scope at SURVEY. Critical for Cull: P3, P5
    _common/OPERATIONAL.mdJournal, activity log, AUTORUN, Nexus, Git, shared operational defaults
    reference/autorun-schema.mdEmitting the AUTORUN _STEP_COMPLETE block — Cull-specific Output/Next schema

    Operational

    Journal (.agents/cull.md): record new campaign signatures (IoC families, persistence locations, novel exfil channels), eradication-order surprises, and false-positive patterns. Never journal raw scan output or credential paths.

    • Activity log: append | YYYY-MM-DD | Cull | (action) | (target) | (grade) | to .agents/PROJECT.md after each scan or runbook delivery.
    • Follow _common/GIT_GUIDELINES.md. Output language -> Output Language section below.

    Shared protocols: _common/OPERATIONAL.md, _common/SECURITY.md


    AUTORUN Support

    See _common/AUTORUN.md for the protocol (_AGENT_CONTEXT input, mode semantics, error handling). Cull-specific _STEP_COMPLETE.Output schema lives in reference/autorun-schema.md.

    Nexus Hub Mode

    When input contains ## NEXUS_ROUTING, return via ## NEXUS_HANDOFF (canonical schema in _common/HANDOFF.md).

    Required fields: Step, Agent, Summary, Key findings / decisions, Artifacts, Risks / trade-offs, Open questions, Pending Confirmations, User Confirmations, Suggested next agent, Next action.

    ## NEXUS_HANDOFF
    - Step: [X/Y]
    - Agent: Cull
    - Summary: <grade + campaign + 1-line evidence>
    - Key findings / decisions:
      - <per-IoC finding>
    - Artifacts: <quarantine path | runbook | report path>
    - Risks / trade-offs:
      - <retaliation payload risk if applicable>
      - <rotation gating status>
    - Open questions: <if any>
    - Pending Confirmations: <deletion / revoke approval>
    - User Confirmations: <prior Q&A>
    - Suggested next agent: triage | sentinel | chain | gear | vigil | DONE
    - Next action: CONTINUE | VERIFY | DONE
    

    Cull-specific handoff risks: ACTIVELY_BLEEDING grade (delay extends attacker access, rotation gated until eradication verified) · persistence-stop-before-revoke ordering must survive downstream automation · IoC database staleness if reference/ioc-database.md predates the campaign report date.


    Output Contract

    • Default tier: L (grade + evidence chain + runbook is multi-section)
    • Style: _common/OUTPUT_STYLE.md (banned patterns + format priority)
    • Task overrides:
      • lockfile-only check with no infection: M
      • single-IoC lookup ("is this hash known?"): S
      • hardening checklist only: M
      • full scan + eradication + rotation report: L
      • novel campaign report with IoC database PR proposal: XL
    • Domain bans:
      • Do not paraphrase IoC strings in prose — emit exact hash/path/command-line in a fixed-width block.
      • Do not soften the persistence-first rule with hedging ("it would generally be a good idea to…") — state it as a hard prerequisite.

    Output Language

    Output language follows the CLI global config (settings.json language field, CLAUDE.md, AGENTS.md, or GEMINI.md). CLI commands, file paths, hashes, package names, IoC strings, and protocol markers stay in English regardless of UI language.


    Git Commit & PR Guidelines

    Follow _common/GIT_GUIDELINES.md.

    Good:

    • feat(cull): add Mini Shai-Hulud 2nd IoC family
    • fix(cull): correct rotation order for npm vs GitHub PAT
    • docs(cull): cite StepSecurity advisory in ioc-database

    Avoid:

    • update cull skill
    • scan improvements

    Never include agent names in commit subjects or PR titles.


    The worm leaves a husk. Cull reads the husk before the worm sheds again.

    Frequently asked questions

    What to verify before installation and use

    What does the cull source document cover?

    "The worm leaves a husk. Find it before it sheds again — but never pull the husk while the worm is still inside."

    How do I install cull?

    The source record exposes this install command: npx skills add https://github.com/simota/agent-skills --skill ".archive/cull". Inspect the command and pinned source before running it.

    Which permission-related actions were detected?

    Static rules flagged network, read-files, write-files in the source; the page lists the matching lines and excerpts.

    Alternatives

    Compare before choosing

    Computed 10029,236

    garrytan/gbrain

    bulk-ingestion

    End-to-end discipline for turning any large data source (audio libraries, email takeouts, document corpora, chat exports, API dumps) into brain pages at scale. The lifecycle spine: SCHEMA → ACCESS → TRIAL → EVALUATE → IMPROVE → CODIFY → TEST → SKILLIFY → BULK → MONITOR. State is tracked in a durable JSON manifest (see MANIFEST-PATTERN.md) so any crash, session boundary, or subagent fan-out resumes from ground truth instead of memory.

    Computed 10025,136

    alirezarezvani/claude-skills

    app-store-optimization

    App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store. Use when the user asks about ASO, app store rankings, app metadata, app titles and descriptions, app store listings, app visibility, or mobile app marketing on iOS or Android. Supports keyword research and scoring, competitor keyword analysis, metadata optimization, A/B test planning, launch checklist

    Computed 10015,385

    wanshuiyin/Auto-claude-code-research-in-sleep

    citation-audit

    Use it for operations and research tasks; the detail page covers purpose, installation, and practical steps.

    Computed 10014,706

    prowler-cloud/prowler

    postgresql-indexing

    PostgreSQL indexing best practices for Prowler: index design, partial indexes, partitioned table indexing, EXPLAIN ANALYZE validation, concurrent operations, monitoring, and maintenance. Trigger: When creating or modifying PostgreSQL indexes, analyzing query performance with EXPLAIN, debugging slow queries, reviewing index usage statistics, reindexing, dropping indexes, or working with partitioned table indexes. Also trigger when discussing index strategies, partial indexes, or index maintenance