a11y-ally
Use when running comprehensive WCAG accessibility audits with axe-core + pa11y + Lighthouse,…
Use when working on security-sensitive code to catch secrets, eval(), innerHTML, and other dangerous patterns before they're written. Activate with /security-watch for real-time security scanning.
$ npx -y skills add proffesor-for-testing/agentic-qe --skill security-watch --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/security-watchContext preview
The summary Claude sees to decide when to auto-load this skill.
Use when working on security-sensitive code to catch secrets, eval(), innerHTML, and other dangerous patterns before they're written. Activate with /security-watch for real-time security scanning.
name: security-watch description: "Use when working on security-sensitive code to catch secrets, eval(), innerHTML, and other dangerous patterns before they're written. Activate with /security-watch for real-time security scanning." user-invocable: true
When activated, scans every file write for common security anti-patterns and blocks dangerous code from being committed.
Flags or blocks writes containing:
/security-watch
{
"hooks": {
"PreToolUse": [
{
"matcher": "Write|Edit",
"hook": ".claude/skills/security-watch/scripts/scan-security.sh"
}
]
}
}#!/bin/bash
# scan-security.sh
CONTENT="$1"
ISSUES=0
# Secrets detection
SECRET_PATTERNS=(
'AKIA[0-9A-Z]{16}' # AWS Access Key
'sk-[a-zA-Z0-9]{48}' # OpenAI API Key
'ghp_[a-zA-Z0-9]{36}' # GitHub Personal Token
'password\s*[:=]\s*["\x27][^"\x27]+' # Hardcoded passwords
'BEGIN (RSA |EC )?PRIVATE KEY' # Private keys
'sk_live_[a-zA-Z0-9]+' # Stripe secret key
)
for pattern in "${SECRET_PATTERNS[@]}"; do
if echo "$CONTENT" | grep -qP "$pattern"; then
echo "BLOCKED: Potential secret detected matching pattern: $pattern"
ISSUES=$((ISSUES + 1))
fi
done
# Dangerous functions
DANGER_PATTERNS=(
'\beval\s*\('
'\bFunction\s*\('
'\.innerHTML\s*='
'dangerouslySetInnerHTML'
'child_process.*exec\('
'\$\{.*\}.*(?:SELECT|INSERT|UPDATE|DELETE)'
)
for pattern in "${DANGER_PATTERNS[@]}"; do
if echo "$CONTENT" | grep -qP "$pattern"; then
echo "WARNING: Dangerous pattern detected: $pattern"
ISSUES=$((ISSUES + 1))
fi
done
if [ $ISSUES -gt 0 ]; then
echo "Found $ISSUES security issues. Review before proceeding."
exit 1
fiAI-powered quality engineering agents that generate tests, find coverage gaps, detect flaky tests, and learn your codebase patterns — across 11 coding agent platforms.
Repo: proffesor-for-testing/agentic-qe
Use when running comprehensive WCAG accessibility audits with axe-core + pa11y + Lighthouse,…
WCAG 2.2 compliance testing, screen reader validation, and inclusive design verification. Use…
Master advanced AgentDB features including QUIC synchronization, multi-database management,…
Create and train AI learning plugins with AgentDB's 9 reinforcement learning algorithms.…
Implement persistent memory patterns for AI agents using AgentDB. Includes session memory,…
Optimize AgentDB performance with quantization (4-32x memory reduction), HNSW indexing (150x…