florianbuetow

florianbuetow/claude-code

74 resources in this repository

GitHub
🎯64πŸ”Œ9πŸͺ1
9

🎯Skills64

🎯ssrf🎯Skill

Skill

ssrf
🎯spec-writer🎯Skill

Skill

spec-writer
🎯solid-principles🎯Skill

Skill

solid-principles
🎯business-logic🎯Skill

Skill

business-logic
🎯pasta-risk🎯Skill

Skill

pasta-risk
🎯file-upload🎯Skill

Skill

file-upload
🎯attack-surface🎯Skill

Skill

attack-surface
🎯pasta-attack-sim🎯Skill

Skill

pasta-attack-sim
🎯pasta🎯Skill

Skill

pasta
🎯pasta-vulns🎯Skill

Skill

pasta-vulns
🎯non-compliance🎯Skill

Skill

non-compliance
🎯mitre🎯Skill

Skill

mitre
🎯pasta-objectives🎯Skill

Skill

pasta-objectives
🎯insecure-design🎯Skill

Skill

insecure-design
🎯config🎯Skill

Skill

config
🎯report🎯Skill

Skill

report
🎯dos🎯Skill

Skill

dos
🎯spoofing🎯Skill

Skill

spoofing
🎯crypto🎯Skill

Skill

crypto
🎯verify🎯Skill

Skill

verify
🎯stride🎯Skill

Skill

stride
🎯access-control🎯Skill

Skill

access-control
🎯pasta-decompose🎯Skill

Skill

pasta-decompose
🎯auth🎯Skill

Skill

auth
🎯beyond-solid-principles🎯Skill

Skill

beyond-solid-principles
🎯api🎯Skill

Skill

api
🎯sans25🎯Skill

Skill

sans25
🎯start🎯Skill

Skill

start
🎯explain🎯Skill

Skill

explain
🎯logging🎯Skill

Skill

logging
🎯graphql🎯Skill

Skill

graphql
🎯learn🎯Skill

Skill

learn
🎯outdated-deps🎯Skill

Skill

outdated-deps
🎯race-conditions🎯Skill

Skill

race-conditions
🎯unawareness🎯Skill

Skill

unawareness
🎯fix🎯Skill

Skill

fix
🎯tampering🎯Skill

Skill

tampering
🎯identifying🎯Skill

Skill

identifying
🎯non-repudiation-privacy🎯Skill

Skill

non-repudiation-privacy
🎯privilege-escalation🎯Skill

Skill

privilege-escalation
🎯detecting🎯Skill

Skill

detecting
🎯owasp🎯Skill

Skill

owasp
🎯injection🎯Skill

Skill

injection
🎯data-disclosure🎯Skill

Skill

data-disclosure
🎯model🎯Skill

Skill

model
🎯pasta-scope🎯Skill

Skill

pasta-scope
🎯linking🎯Skill

Skill

linking
🎯linddun🎯Skill

Skill

linddun
🎯integrity🎯Skill

Skill

integrity
🎯explain-system-tradeoffs🎯Skill

Skill

explain-system-tradeoffs
🎯info-disclosure🎯Skill

Skill

info-disclosure
🎯repudiation🎯Skill

Skill

repudiation
🎯secrets🎯Skill

Skill

secrets
🎯status🎯Skill

Skill

status
🎯fuzz🎯Skill

Skill

fuzz
🎯review-plan🎯Skill

Skill

review-plan
🎯misconfig🎯Skill

Skill

misconfig
🎯full-audit🎯Skill

Skill

full-audit
🎯glossary🎯Skill

Skill

glossary
🎯serverless🎯Skill

Skill

serverless
🎯data-flows🎯Skill

Skill

data-flows
🎯harden🎯Skill

Skill

harden
🎯regression🎯Skill

Skill

regression
🎯pasta-threats🎯Skill

Skill

pasta-threats

πŸ”ŒPlugins9

πŸ”Œspec-writerπŸ”ŒPlugin

An expert-guided skill for creating layered software specification documents for greenfield projects. Produces Vision, Business Requirements, Software Requirements, Architecture & Design, and Behavioral Spec & Test Verification documents.

development
πŸ”Œbeyond-solid-principlesπŸ”ŒPlugin

Analyze code and architecture for violations of ten system-level software design principles: Separation of Concerns, Single Responsibility (system-level), DRY, Law of Demeter, Loose Coupling / High Cohesion, Evolvability, Resilience, KISS, Principle of Least Surprise, and YAGNI

development
πŸ”ŒarchibaldπŸ”ŒPlugin

Software architecture quality assessment through structural smell detection, quantitative metrics analysis, antipattern identification, dependency structure evaluation, risk/trade-off analysis, and technical debt measurement.

development
πŸ”Œspec-ddπŸ”ŒPlugin

Specification-driven development workflow skill. Orchestrates a spec-first discipline with advisory quality gates: behavioral specification, test specification, implementation specification, and alignment review.

development
πŸ”Œsolid-principlesπŸ”ŒPlugin

Analyze code for violations of the SOLID principles of object-oriented design (Single Responsibility, Open/Closed, Liskov Substitution, Interface Segregation, Dependency Inversion)

development
πŸ”ŒkissπŸ”ŒPlugin

Analyze code and architecture for unnecessary complexity, over-abstraction, and redundancy. Reports findings with severity ratings and concrete simplification suggestions.

development
πŸ”ŒretrospectiveπŸ”ŒPlugin

Analyze Claude Code session logs to identify what went well, what didn't, and how to improve developer-AI collaboration. Suggests new skills, subagents, slash commands, hooks, and workflow optimizations based on actual usage patterns.

development
πŸ”Œexplain-system-tradeoffsπŸ”ŒPlugin

Reverse-engineer distributed system tradeoffs from code, configuration, and architecture artifacts. Analyzes six axes: Consistency & Availability, Latency & Throughput, Data Distribution, Transaction Boundaries, Resilience & Failure Isolation, and Observability, Security & Cost.

development
πŸ”ŒappsecπŸ”ŒPlugin

Comprehensive application security toolbox for Claude Code. 62 skills across 8 frameworks (OWASP Top 10, OWASP API Top 10, STRIDE, PASTA, LINDDUN, MITRE ATT&CK, SANS/CWE Top 25, DREAD), red team simulation with 6 attacker personas plus consolidator, and interactive security education.

security

πŸͺMarketplaces1