Claude Code Skills · page 13
Individual Claude Code skills mined from every repository in the directory: each SKILL.md, installable with one command, with its full definition and the repository's trust signals.
- us-etf-flow33.2k
US ETF fund flow analysis, sector rotation breadth, and style factor flows — track institutional capital movement via ETF creation/redemption, sector breadth signals, and thematic momentum.
HKUDS/Vibe-TradingInstall - valuation-model33.2k
Valuation methodology — absolute valuation with DCF / DDM / SOTP, relative valuation with PE-Band / PB-ROE / EV-EBITDA, sensitivity analysis, and valuation-trap detection.
HKUDS/Vibe-TradingInstall - vnpy-export33.2k
Export a Vibe-Trading backtest strategy to a runnable vnpy CtaTemplate Python class — supports A-share equities, futures, and crypto via BarGenerator + ArrayManager.
HKUDS/Vibe-TradingInstall - volatility33.2k
Volatility strategy. Trades mean reversion based on percentile ranking of historical volatility (HV). Suitable for any OHLCV data.
HKUDS/Vibe-TradingInstall - web-reader33.2k
Read web pages, articles, and document links by converting URLs into Markdown text. Use the `read_url` tool directly, without bash. Sends the full URL to the third-party Jina Reader (r.jina.ai).
HKUDS/Vibe-TradingInstall - yfinance33.2k
yfinance global market data interface — retrieve OHLCV, financials, insider transactions, and institutional holdings for US stocks, HK stocks, ETFs, and indices via Yahoo Finance. Free, no API key required.
HKUDS/Vibe-TradingInstall - eastmoney33.2k
东方财富(Eastmoney)免费免鉴权数据接口,覆盖资金流向、龙虎榜、融资融券、大宗交易、股东户数、限售解禁、行业概念板块、券商研报、财经新闻、A股/港股三大报表+主要指标、全市场选股与代码搜索;美股财报由 get_financial_statements 转 SEC EDGAR。东财请求经共享 IP 限速层节流(东财按源 IP 限流并临时封禁突发请求),通过 Vibe-Trading 工具直接调用,无需 token。
HKUDS/Vibe-TradingInstall - sec-edgar33.2k
U.S. SEC EDGAR fetch interface — resolve a ticker to its CIK, list recent filings (10-K / 10-Q / 8-K and friends) with primary-document URLs, and pull XBRL companyfacts financial series. Free, no API key; rate-limited by IP so every request is throttled and carries a contact User-Agent. United States only.
HKUDS/Vibe-TradingInstall - bottleneck-hunter33.2k
Supply-chain bottleneck arbitrage. Given a super-trend (AI infra, energy transition, defense, semiconductor reshoring, space economy), decompose its physical supply chain down to Layer 2/3 choke points (optics, lasers, InP/SOI substrates, IC substrates, probe cards, specialty fiberglass...) and surface under-the-radar listed companies sitting on each bottleneck. Scores each link on 6 scarcity criteria, applies mandatory valuation gates (PS/PE/safety-margin) via the financial_rigor tool, and Munger-style reverse-validates. Outputs a ranked bottleneck opportunity board. Use when the user wants hidden beneficiaries of a structural trend rather than already-priced leaders.
HKUDS/Vibe-TradingInstall - correlation-regime33.2k
Correlation-regime detection and crisis attribution — edge-density regime states with hysteresis, causal (no look-ahead) smoothing, regime-aware exposure context, first-mover crisis attribution with honest NAME / MACRO / AMBIGUOUS / ABSTAIN verdicts, and a correlation-rewiring leaderboard that catches slow bleed-outs
HKUDS/Vibe-TradingInstall - deep-company-series33.2k
Write a publication-grade 8-part deep-dive series on a single company (~120k words total): cognitive reset / moat / profit engine / hidden assets / era variable (e.g. AI) / financials Buffett-style / management / valuation+redlines. The core IP is NOT writing but REVISING — a strict fact-check checklist catches pseudo-precision (probability-weighted expectations, third-party MAU discrepancies, linear extrapolation), absolute language, and cross-article number inconsistencies that most finance long-forms violate. Each piece stands alone but shares one valuation/management/price framework. Use when the user wants textbook-level depth on one company for public publishing (a single research report or earnings note is NOT this — use investment-research / earnings-review instead).
HKUDS/Vibe-TradingInstall - investor-lenses33.2k
Named investor reasoning frameworks packaged as reusable analytical lenses — 12 lenses (deep value, quality franchise, inversion, scuttlebutt growth, GARP, cycle positioning, debt cycle, forensic short, cost drag, right-business, weak-system contrarian, three questions) that stack on top of evidence already gathered, each with ordered priority signals, hard disqualifiers, and documented failure modes.
HKUDS/Vibe-TradingInstall - management-deep-dive33.2k
Deep management assessment — the 'buying a stock is buying a person' layer. For a company or a named executive, evaluate integrity (promise-vs-delivery tracking, crisis behavior, stakeholder treatment), ability (strategic foresight, execution, capital-allocation record) and governance (equity structure, compensation, related-party deals). Outputs a weighted score across integrity / ability / capital-allocation / governance plus Duan Yongping's 3-question verdict ('would you hand this person your money for 10 years'). Use when standard research leaves management quality uncertain, or when management IS the investment thesis.
HKUDS/Vibe-TradingInstall Deep research framework for pre-IPO / private companies (Ant Group, SpaceX, Stripe, ByteDance...). Six analyst lenses — business model, financial forensics, competitive landscape, risk & governance, tech & IP, alternative-data signals — run in parallel via run_swarm, then cross-validated for signal consistency before any verdict. Built around the core challenge of private-company work: information is scarce, so every data point carries a confidence label (high / medium / low), inference is shown separately from fact, and 'I don't know' is a valid output. Outputs a fair-value range, exit-path analysis, and an information-gap map. Use for any unlisted company where you need to judge what the business is actually worth.
HKUDS/Vibe-TradingInstall- qveris33.2k
Paid capability marketplace for global multi-asset data; use it when free Vibe-Trading sources lack coverage, depth, or provider quality, and keep free sources as the default for routine OHLCV.
HKUDS/Vibe-TradingInstall - research-discipline33.2k
A short self-bias checklist to run at the START of any investment research task (stock screen / sector study / company deep-dive). Four biases that systematically warp AI research — leader-bias (only big caps), English-bias (miss JP/KR/TW players), narrative-bias (chase concept labels), confirmation-bias (only bullish evidence) — plus recency-bias. Load this first, then research with the corrections in mind. Not a workflow, just a 60-second attitude reset that materially improves coverage and honesty.
HKUDS/Vibe-TradingInstall - strategy-dev-manager33.2k
Strategy Development Manager: convert academic papers and research reports into validated factors and strategies with automated backtesting, persistent storage, and decay monitoring.
HKUDS/Vibe-TradingInstall - strategy-discovery33.2k
Strategy Discovery: evidence-gated facade over Alpha Zoo + the SDM strategy store — answers what strategies exist and what state they are in, with per-regime evidence instead of scenario tags; reports evidence freshness on every returned row and rebuilds the disposable evidence cache from local backtest runs.
HKUDS/Vibe-TradingInstall - architecture32.7k
|
iOfficeAI/AionUiInstall - bump-version32.7k
Use when bumping the AionUi version: query AionCore release, verify artifacts, update package.json, generate CHANGELOG, branch, commit, push, create PR, auto-merge, tag release.
iOfficeAI/AionUiInstall - fix-issues32.7k
|
iOfficeAI/AionUiInstall - fix-sentry32.7k
|
iOfficeAI/AionUiInstall - i18n32.7k
|
iOfficeAI/AionUiInstall - oss-pr32.7k
Use when creating a pull request, after committing changes, or when user invokes /oss-pr. Covers branch management, quality checks, commit, push, and PR creation.
iOfficeAI/AionUiInstall - pr-automation32.7k
|
iOfficeAI/AionUiInstall - pr-fix32.7k
|
iOfficeAI/AionUiInstall - pr-review32.7k
|
iOfficeAI/AionUiInstall - pr-ship32.7k
|
iOfficeAI/AionUiInstall - pr-verify32.7k
|
iOfficeAI/AionUiInstall - testing32.7k
|
iOfficeAI/AionUiInstall - skills32.7kiOfficeAI/AionUiInstall
- Add new skill32.6k
Create forensically sound bit-for-bit disk images with dd or dcfldd on a Linux forensic workstation, preserving evidence integrity through hash verification (MD5/SHA) during acquisition. Use when imaging a suspect drive, USB device, or memory card for investigation, preserving volatile disk evidence during incident response, or producing a verified copy for legal or law-enforcement proceedings before any destructive analysis.
Detect dangerous ACL misconfigurations in Active Directory using ldap3
Perform static analysis of Android APK malware using apktool for resource decompilation, jadx for Java source recovery, and androguard for manifest inspection, dangerous permission-combination detection, and identification of obfuscated code, dynamic code loading, and reflection-based API calls. Use to statically triage a suspicious APK without executing it or to build mobile malware detection rules.
Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect
Query ATT&CK data with attackcti, mitreattack-python, and stix2, then build MITRE ATT&CK Navigator layers and multi-layer heatmap overlays mapping one or more APT groups' TTPs for detection-gap analysis. Use to compare threat-actor technique coverage, find gaps in detection engineering, or produce Navigator visualizations for threat-intel reporting.
Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query
Analyzes bootkit and advanced rootkit malware infecting the Master
Parse Chromium-based browser databases with Hindsight to extract and correlate browsing history, downloads, cookies, cached content, autofill data, saved passwords, and extensions from Chrome, Edge, Brave, Opera, and Vivaldi into a unified timeline (XLSX, JSON, or SQLite output). Use during incident response, insider-threat investigations, or criminal cases when you need to reconstruct a user's web activity from a browser profile.
Systematically evaluate cyber-campaign evidence to attribute an operation to a threat actor, using the Diamond Model and Analysis of Competing Hypotheses (ACH) to weigh infrastructure overlaps, TTP consistency, malware code similarity, and timing/language artifacts into confidence-weighted attribution assessments. Use when an incident investigation needs a defensible attribution confidence level.
Monitor Certificate Transparency logs using crt.sh and Certstream to
Detect abnormal access in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics for after-hours bulk downloads, new-IP access, and API-call spikes (e.g. GetObject) via statistical baselines and time-series anomaly detection. Use when investigating suspected cloud data exfiltration or building related detection rules.
Extract and analyze Cobalt Strike beacon configuration from PE files
Parse and analyze Cobalt Strike Malleable C2 profiles with dissect.cobaltstrike (profiles and beacon-payload configs) and pyMalleableC2 (AST parsing) to extract HTTP/DNS transforms, URIs, headers, sleep/jitter, and injection behavior, then generate network detection signatures. Use when reverse-engineering a captured malleable profile or building detections against Cobalt Strike Beacon traffic.
Analyzes malware C2 communication over HTTP, HTTPS, DNS, and custom
Analyzes intrusion activity against the Lockheed Martin Cyber Kill Chain
Perform comprehensive forensic analysis of raw (dd), E01, or AFF disk images with Autopsy and The Sleuth Kit, recovering deleted files, examining metadata and embedded artifacts, keyword searching, and building investigation timelines with visual reports. Use for structured analysis of a forensic disk image or when stakeholders need visual reports from evidence.
Analyzes DNS query logs to detect data exfiltration via DNS tunneling,
Investigate compromised Docker containers by analyzing images, layers,
Parse and analyze email headers (Received chain, Return-Path, Message-ID)
Perform static and symbolic analysis of Solidity smart contracts using
Reverse engineer Go-compiled malware in Ghidra by parsing Go buildinfo
Detect and analyze heap spray attacks in memory dumps using Volatility3
Analyzes indicators of compromise (IOCs) including IP addresses, domains,
>-
>-
Uses the Linux Audit framework (auditd) with ausearch and aureport utilities
Analyze malicious Linux ELF binaries — botnets, cryptominers, ransomware,
Detect kernel-level rootkits in Linux memory dumps using Volatility3
Examine Linux system artifacts (auth logs, cron/systemd persistence,
Analyze Windows LNK shortcut files and Jump List artifacts with LECmd,
Analyzes malicious VBA macros embedded in Microsoft Office documents
Perform static analysis of malicious PDF documents using peepdf, pdfid,
URLScan.io is a free service for scanning and analyzing suspicious URLs.
Detonate malware samples in Cuckoo Sandbox to observe runtime behavior
Query the Malpedia API to look up malware family aliases and naming
Use Sysinternals Autoruns to systematically enumerate and analyze malware
Detect sandbox and VM evasion techniques in malware samples by analyzing
Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes,
Performs Linux memory acquisition using LiME (Linux Memory Extractor)
Analyze the NTFS Master File Table ($MFT) with MFTECmd, analyzeMFT,
Detect and analyze covert communication channels used by malware, including
Parse NetFlow v9 and IPFIX records to detect volumetric anomalies, port
Use Scapy to craft, send, sniff, and dissect TCP/UDP/ICMP/DNS packets, analyze pcap files, implement SYN scans, and detect anomalous traffic such as fragmented or malformed packets. Use when performing authorized network reconnaissance, protocol-level forensic analysis, or building traffic anomaly detection during security testing.
Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including
Analyzes network traffic generated by malware during sandbox execution
Captures and analyzes network packet data using Wireshark and tshark
Parse Office 365 Unified Audit Logs via Microsoft Graph API to detect
Parse Microsoft Outlook PST and OST files using libpff and pst-utils to extract message content, headers, attachments, deleted items, and MAPI metadata, including recovery of items from the Recoverable Items folder. Use when conducting email forensic investigations, legal e-discovery, or incident response that requires reconstructing communication patterns or tracing message routing from Outlook archives.
Identifies and unpacks UPX-packed malware samples, including binaries with modified UPX magic bytes or headers that block automated decompression, to recover the original executable for static analysis. Use when a sample shows high entropy, minimal imports, or only LoadLibrary/GetProcAddress in its import table, or when preparing a packed binary for disassembly in Ghidra or IDA.
Analyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to
Scan Linux systems for persistence mechanisms including crontab/systemd entries, LD_PRELOAD injection, shell profile modifications (.bashrc, .profile), and SSH authorized_keys backdoors, then correlate findings with auditd logs into an installation timeline. Use during incident response or threat hunting to detect or confirm how an adversary maintained access to a compromised Linux host.
Detect PowerShell Empire post-exploitation framework artifacts in Windows Script Block Logging (Event ID 4104) and Module Logging (Event ID 4103), including the default launcher string, Base64-encoded WebClient/FromBase64String payloads, known module invocations (Invoke-Mimikatz, Invoke-Kerberoast), and staging URL patterns. Use when hunting for or confirming Empire C2 activity in Windows event logs.
Parse Windows PowerShell Script Block Logs (Event ID 4104) from EVTX
Parse Windows Prefetch files (versions 17, 23, 26, 30) with tools like PECmd, WinPrefetchView, or python-prefetch to determine program execution history, including run counts, execution timestamps, and referenced files/DLLs. Use when building a timeline of program execution on a Windows system, confirming whether a suspicious binary ran, or correlating execution evidence with other forensic artifacts during an investigation.
Analyzes encryption algorithms, key management, and file encryption
Safely monitor ransomware group Tor-hosted data leak sites (DLS) to collect and extract structured victim posting data, track group activity trends over time, and produce sector- and geography-specific ransomware risk assessments. Use when performing threat intelligence gathering on active ransomware groups or building proactive defense reporting from double-extortion leak-site activity.
Identify ransomware-related network indicators, including C2 beaconing patterns, TOR exit node connections, data exfiltration flows, and encryption key exchange, by analyzing Zeek conn.log and NetFlow data. Use when threat hunting for active ransomware network activity or investigating suspected pre-encryption exfiltration during incident response.
Traces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor, WalletExplorer, and blockchain.com APIs, identifying wallet clusters and tracking fund movement through mixers and exchanges to support law enforcement attribution. Use when tracing ransomware bitcoin payments, performing cryptocurrency wallet forensics, or gathering blockchain threat intelligence on extortion payments.
Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON
Leverages Splunk Enterprise Security and SPL (Search Processing Language)
Examine NTFS slack space, MFT entries, the USN Change Journal, and Alternate Data Streams (ADS) to recover hidden or residual data, reconstruct deleted-file metadata, and reconstruct available file-system change activity from USN records. Use during deep forensic analysis of an NTFS image when standard file recovery is insufficient, such as hunting for data hidden in ADS.
Investigate supply chain attack artifacts including trojanized software
Systematically map threat actor behavior and observed IOCs to the MITRE ATT&CK framework, build technique coverage heatmaps with the ATT&CK Navigator, identify detection gaps, and produce actionable threat intelligence reports across the Enterprise, Mobile, and ICS matrices. Use when analyzing threat actor TTPs, correlating IOCs to specific ATT&CK techniques, or assessing defensive detection coverage against adversary behavior.
Map advanced persistent threat (APT) group TTPs to the MITRE ATT&CK framework using the attackcti Python library to query STIX/TAXII data for group-technique associations, then generate ATT&CK Navigator layer files to visualize and compare defensive coverage against adversary profiles. Use when profiling an APT group''s techniques, building Navigator coverage heatmaps, or assessing technique coverage gaps against a specific threat actor.
Analyzes structured and unstructured threat intelligence feeds to extract
Query a MISP (Malware Information Sharing Platform) instance via PyMISP
Queries Certificate Transparency logs via crt.sh and pycrtsh to detect