Install
$ agentstack add mcp-kerberosclaw-kc-ai-skills ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
AI Skills That Actually Do Things
[](LICENSE)
[正體中文](README_zh.md)
A collection of AI agent skills that solve real problems — not "summarize this PDF" kind of skills, but "scan my repo for leaked API keys before I push" kind of skills. Works with any LLM client that supports skill/prompt loading, cloud or local.
> Skills follow the Claude Code skill convention (SKILL.md + scripts/), but the concepts are framework-agnostic. Think of them as reusable checklists your AI actually follows.
> Security Notice: These skills are designed for local development and trusted LAN environments. Skills that interact with external services (e.g., searxng) default to secure settings (TLS verification enabled), but do not implement additional authentication layers. Review each skill's configuration before deploying in sensitive environments.
Skills
Grouped by what you're trying to get done — every skill is still a self-contained top-level folder, the grouping is just a map.
Generate & create
| Skill | What It Actually Does | |-------|----------------------| | [gpt-image-gen](gpt-image-gen/) | Talk Codex into drawing it for you. Drafts a tight bilingual prompt, iterates until you give an explicit go, then fires Codex CLI for text-to-image — the hard confirmation gate exists because "looks good" is not "yes" and every generation costs real quota. Does text-to-image and img2img (drop an on-disk reference image to lock a face/character via Codex -i), hands you a jpg, and pointedly refuses to shove a preview window in your face | | [character-lora](character-lora/) | Take an original character from "an idea + one reference look" to a trained LoRA that holds its identity across every angle and scene. Orchestrates the whole pipeline — define → multi-angle dataset (delegating image-gen to gpt-image-gen) → caption → base-specific homework → train on a local GPU → verify — and gates every expensive step. The hard rule: read the base model's own training docs before you train, because improvising the settings is how characters come out "rolling the dice" on every generation | | [rewrite-tone](rewrite-tone/) | Turn your dry technical docs into something people actually want to read. War stories > whitepapers |
Docs & decks
| Skill | What It Actually Does | |-------|----------------------| | [md2pdf](md2pdf/) | Turn your Markdown into a PDF that doesn't look like it was generated by a computer from 2003. Handles Mermaid diagrams, CJK fonts, and ASCII art conversion — because we already mass-debugged all the cursed edge cases so you don't have to | | [md2ppt](md2ppt/) | md2pdf's louder sibling. Turn your Markdown report into a presentation-quality .pptx via interactive design dialogue + a reusable Python build script. Generic markdown→pptx tools (Marp, pandoc) produce slides that are syntactically correct but visually broken — md2ppt walks per-slide layout decisions with you, then emits a hand-coded script you can re-run in 5 seconds after content edits. Optional self-check via LibreOffice. Brand template integration via ad-hoc helpers — we tried prescribing a workflow, pulled it back after 5 rounds of "wait that's not the cover layout" | | [conference-report](conference-report/) | You went to a conference, recorded the talks, photographed the slides, and came home with a pile of audio, blurry photos, and a vague promise to "write it up someday". This rebuilds faithful per-session notes (slide visuals + speaker transcript, with Whisper hallucinations flagged so you do not quote a robot daydream), then actually asks what report you need -- one talk, a full day, or a multi-day synthesis -- before writing a single word |
Spec & project
| Skill | What It Actually Does | |-------|----------------------| | [prd-create](prd-create/) | Turn a pile of meeting notes, scattered chat messages, and hand-waved feature requests into a structured PRD that follows your org's guideline — it quizzes you for the gaps instead of fabricating them, surfaces stakeholder conflicts instead of silently picking a side, then sanitizes and publishes to ADO Wiki. Pure prompt-driven, no Python. First half of the prd-create → prd-breakdown → ADO chain | | [prd-breakdown](prd-breakdown/) | Take a finished PRD and slice it into Azure DevOps work items along vertical slices (HITL/AFK tags + blocked_by dependencies), then push them via the az CLI — idempotent re-runs via fingerprint markers, so re-running won't duplicate items. Second half of the prd-create → prd-breakdown → ADO chain | | [spec](spec/) | Spec-driven development workflow — from fuzzy idea to verified deliverable. One command, auto-detects project state, walks you through: requirements → review → implement → verify → report. Because "just start coding" is how you end up rewriting everything | | [goal-engineer](goal-engineer/) | For when you want an agent to grind on something overnight without you hovering over it. Interview-style, it pins down a goal-driven evaluator-optimizer loop of the generate-and-select kind (generate candidates -> grade against a rubric -> iterate by reason-code -> you pick the winner), then emits a self-contained dispatch doc a fresh session runs blind while you just watch the green/yellow/red pings roll in. It is the upstream spec author, not the engine -- hand the dispatch to Claude Code's built-in /goal, a headless claude -p, or any unattended agent. NOT /goal itself, NOT a build-to-spec PRD writer (that's prd-create), NOT a cron timer. Channel-agnostic notifications (Telegram/Discord/Slack/iMessage), and it bakes in a "want an adversarial review before we ship?" gate -- because we got tired of remembering to ask ourselves |
Research & security
| Skill | What It Actually Does | |-------|----------------------| | [searxng](searxng/) | Give your local LLM the ability to search the web without sending your queries to Google | | [repo-scan](repo-scan/) | Security scan a GitHub repo before you install it. Static analysis, dependency audit, supply chain risks, issue-reported vulnerabilities, maintainer health — because npm install random-package shouldn't require a leap of faith | | [ctf-kit](ctf-kit/) | Battle-tested playbook for bypassing Windows app authentication — VMProtect, Themida, network verification, you name it. Born from 67+ failed attempts so you don't have to repeat them. Includes ready-to-use Frida recon scripts and a zero-dependency PE analyzer. Pairs well with ljagiello/ctf-skills for broader CTF coverage | | [job-scout](job-scout/) | Research a company before you waste time applying. Salary, reviews, red flags, financials — the due diligence you should've done before that last interview |
AI knowledge hygiene
| Skill | What It Actually Does | |-------|----------------------| | [memory-lint](memory-lint/) | Your AI's memory directory accumulates duplicate rules, stale "active" projects, and orphan files over time. This skill scans for all of that and reports before Claude confidently quotes the wrong rule back at you. Read-only — finds problems, you decide what to fix | | [llm-wiki-lint](llm-wiki-lint/) | Karpathy's LLM Wiki pattern has a blind spot — past ~15 pages, stale claims, orphan cross-refs, and missing topics silently rot your knowledge base. This skill is the lint pass: contradictions, source traceability, data gaps, frontmatter completeness, index drift. For three-tier raw/ + wiki/ + schema repos. Read-only. Pair with [memory-lint](memory-lint/) for full-stack AI knowledge hygiene | | [llm-benchmark](llm-benchmark/) | Find out which Ollama model actually fits in your GPU — before you waste 30 minutes downloading one that doesn't |
Automation & watch
| Skill | What It Actually Does | |-------|----------------------| | [skill-cron](skill-cron/) | One manager to schedule them all. Register any skill for crontab execution + Telegram push — because claude -p doesn't support /skill syntax, so somebody had to build the bridge. Config in ~/.claude/configs/, logs auto-rotate, crontab entries self-managed | | [banini](banini/) | Track Taiwan's most famous "reverse indicator" investor on Threads, let Claude do the contrarian analysis on the spot. Zero API cost — Playwright scrapes locally, Claude IS the LLM. Rewritten from cablate/banini-tracker to eliminate $11/mo in Apify + LLM API fees. Pair with [skill-cron](skill-cron/) for scheduled runs + Telegram push — [setup guide](banini/docs/SETUP.md) | | [job-radar](job-radar/) | Your job-hunting autopilot's remote control. Tell your AI "write cover letters" in Telegram and it reads JDs, writes 25 tailored letters, zips them, and sends them back before you finish your coffee. Pairs with kcjobradar — Docker required, sanity optional | | [prep-repo](prep-repo/) | The "did I forget anything?" checklist before pushing to GitHub. README, commits, secrets, broken links — the stuff you always forget at 2 AM |
Installation
Grab what you need, leave what you don't:
git clone https://github.com/KerberosClaw/kc_ai_skills.git
# Example: install for Claude Code (user-level)
cp -r kc_ai_skills/prep-repo ~/.claude/skills/
# Example: install for OpenClaw (workspace-level)
cp -r kc_ai_skills/searxng ~/.openclaw/workspace/skills/
> Naming tip: Feel free to rename the skill folder with your own prefix when copying (e.g. my_prep-repo). It won't break anything. Probably.
> Other clients: Each SKILL.md is a self-contained markdown instruction file. You can paste its content into any AI chat, system prompt, or custom instruction field. No SDK required, no API key needed — just copy and paste.
Skill Structure
Every skill follows a dead-simple convention. If you can write markdown, you can write a skill:
skill-name/
├── SKILL.md # Frontmatter (name, description, version) + instructions
└── scripts/ # Executable scripts (optional)
└── script.py
Related Projects
- kctradfri_mcp — "Turn on the living room lights" — yes, we made an AI do that
- kcopenclawlocal_llm — We tested 13 local LLMs. Only 2 could reliably call tools. Here's the full report.
Source & license
This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: KerberosClaw
- Source: KerberosClaw/kcai_skills
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.