# Kc Ai Skills

> AI Skills That Actually Do Things — reusable skills for any LLM workflow

- **Type:** MCP server
- **Install:** `agentstack add mcp-kerberosclaw-kc-ai-skills`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [KerberosClaw](https://agentstack.voostack.com/s/kerberosclaw)
- **Installs:** 0
- **Category:** [AI & ML](https://agentstack.voostack.com/c/ai-and-ml)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [KerberosClaw](https://github.com/KerberosClaw)
- **Source:** https://github.com/KerberosClaw/kc_ai_skills

## Install

```sh
agentstack add mcp-kerberosclaw-kc-ai-skills
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# AI Skills That Actually Do Things

[](LICENSE)

[正體中文](README_zh.md)

A collection of AI agent skills that solve real problems — not "summarize this PDF" kind of skills, but "scan my repo for leaked API keys before I push" kind of skills. Works with any LLM client that supports skill/prompt loading, cloud or local.

> Skills follow the [Claude Code skill convention](https://code.claude.com/docs/en/skills) (SKILL.md + scripts/), but the concepts are framework-agnostic. Think of them as reusable checklists your AI actually follows.

> **Security Notice:** These skills are designed for local development and trusted LAN environments. Skills that interact with external services (e.g., `searxng`) default to secure settings (TLS verification enabled), but do not implement additional authentication layers. Review each skill's configuration before deploying in sensitive environments.

## Skills

Grouped by what you're trying to get done — every skill is still a self-contained top-level folder, the grouping is just a map.

### Generate & create

| Skill | What It Actually Does |
|-------|----------------------|
| [gpt-image-gen](gpt-image-gen/) | Talk Codex into drawing it for you. Drafts a tight bilingual prompt, iterates until you give an explicit go, *then* fires Codex CLI for text-to-image — the hard confirmation gate exists because "looks good" is not "yes" and every generation costs real quota. Does text-to-image *and* img2img (drop an on-disk reference image to lock a face/character via Codex `-i`), hands you a jpg, and pointedly refuses to shove a preview window in your face |
| [character-lora](character-lora/) | Take an original character from "an idea + one reference look" to a trained LoRA that holds its identity across every angle and scene. Orchestrates the whole pipeline — define → multi-angle dataset (delegating image-gen to gpt-image-gen) → caption → base-specific homework → train on a local GPU → verify — and gates every expensive step. The hard rule: read the base model's own training docs *before* you train, because improvising the settings is how characters come out "rolling the dice" on every generation |
| [rewrite-tone](rewrite-tone/) | Turn your dry technical docs into something people actually want to read. War stories > whitepapers |

### Docs & decks

| Skill | What It Actually Does |
|-------|----------------------|
| [md2pdf](md2pdf/) | Turn your Markdown into a PDF that doesn't look like it was generated by a computer from 2003. Handles Mermaid diagrams, CJK fonts, and ASCII art conversion — because we already mass-debugged all the cursed edge cases so you don't have to |
| [md2ppt](md2ppt/) | md2pdf's louder sibling. Turn your Markdown report into a presentation-quality .pptx via interactive design dialogue + a reusable Python build script. Generic markdown→pptx tools (Marp, pandoc) produce slides that are syntactically correct but visually broken — md2ppt walks per-slide layout decisions with you, then emits a hand-coded script you can re-run in 5 seconds after content edits. Optional self-check via LibreOffice. Brand template integration via ad-hoc helpers — we tried prescribing a workflow, pulled it back after 5 rounds of "wait that's not the cover layout" |
| [conference-report](conference-report/) | You went to a conference, recorded the talks, photographed the slides, and came home with a pile of audio, blurry photos, and a vague promise to "write it up someday". This rebuilds faithful per-session notes (slide visuals + speaker transcript, with Whisper hallucinations flagged so you do not quote a robot daydream), then actually asks what report you need -- one talk, a full day, or a multi-day synthesis -- before writing a single word |

### Spec & project

| Skill | What It Actually Does |
|-------|----------------------|
| [prd-create](prd-create/) | Turn a pile of meeting notes, scattered chat messages, and hand-waved feature requests into a structured PRD that follows your org's guideline — it quizzes you for the gaps instead of fabricating them, surfaces stakeholder conflicts instead of silently picking a side, then sanitizes and publishes to ADO Wiki. Pure prompt-driven, no Python. First half of the prd-create → prd-breakdown → ADO chain |
| [prd-breakdown](prd-breakdown/) | Take a finished PRD and slice it into Azure DevOps work items along vertical slices (HITL/AFK tags + blocked_by dependencies), then push them via the az CLI — idempotent re-runs via fingerprint markers, so re-running won't duplicate items. Second half of the prd-create → prd-breakdown → ADO chain |
| [spec](spec/) | Spec-driven development workflow — from fuzzy idea to verified deliverable. One command, auto-detects project state, walks you through: requirements → review → implement → verify → report. Because "just start coding" is how you end up rewriting everything |
| [goal-engineer](goal-engineer/) | For when you want an agent to grind on something overnight without you hovering over it. Interview-style, it pins down a goal-driven evaluator-optimizer loop of the generate-and-select kind (generate candidates -> grade against a rubric -> iterate by reason-code -> you pick the winner), then emits a self-contained dispatch doc a fresh session runs blind while you just watch the green/yellow/red pings roll in. It is the upstream *spec author*, not the engine -- hand the dispatch to Claude Code's built-in `/goal`, a headless `claude -p`, or any unattended agent. NOT `/goal` itself, NOT a build-to-spec PRD writer (that's prd-create), NOT a cron timer. Channel-agnostic notifications (Telegram/Discord/Slack/iMessage), and it bakes in a "want an adversarial review before we ship?" gate -- because we got tired of remembering to ask ourselves |

### Research & security

| Skill | What It Actually Does |
|-------|----------------------|
| [searxng](searxng/) | Give your local LLM the ability to search the web without sending your queries to Google |
| [repo-scan](repo-scan/) | Security scan a GitHub repo before you install it. Static analysis, dependency audit, supply chain risks, issue-reported vulnerabilities, maintainer health — because `npm install random-package` shouldn't require a leap of faith |
| [ctf-kit](ctf-kit/) | Battle-tested playbook for bypassing Windows app authentication — VMProtect, Themida, network verification, you name it. Born from 67+ failed attempts so you don't have to repeat them. Includes ready-to-use Frida recon scripts and a zero-dependency PE analyzer. Pairs well with [ljagiello/ctf-skills](https://github.com/ljagiello/ctf-skills) for broader CTF coverage |
| [job-scout](job-scout/) | Research a company before you waste time applying. Salary, reviews, red flags, financials — the due diligence you should've done before that last interview |

### AI knowledge hygiene

| Skill | What It Actually Does |
|-------|----------------------|
| [memory-lint](memory-lint/) | Your AI's memory directory accumulates duplicate rules, stale "active" projects, and orphan files over time. This skill scans for all of that and reports before Claude confidently quotes the wrong rule back at you. Read-only — finds problems, you decide what to fix |
| [llm-wiki-lint](llm-wiki-lint/) | Karpathy's LLM Wiki pattern has a blind spot — past ~15 pages, stale claims, orphan cross-refs, and missing topics silently rot your knowledge base. This skill is the lint pass: contradictions, source traceability, data gaps, frontmatter completeness, index drift. For three-tier `raw/` + `wiki/` + `schema` repos. Read-only. Pair with [memory-lint](memory-lint/) for full-stack AI knowledge hygiene |
| [llm-benchmark](llm-benchmark/) | Find out which Ollama model actually fits in your GPU — before you waste 30 minutes downloading one that doesn't |

### Automation & watch

| Skill | What It Actually Does |
|-------|----------------------|
| [skill-cron](skill-cron/) | One manager to schedule them all. Register any skill for crontab execution + Telegram push — because `claude -p` doesn't support `/skill` syntax, so somebody had to build the bridge. Config in `~/.claude/configs/`, logs auto-rotate, crontab entries self-managed |
| [banini](banini/) | Track Taiwan's most famous "reverse indicator" investor on Threads, let Claude do the contrarian analysis on the spot. Zero API cost — Playwright scrapes locally, Claude IS the LLM. Rewritten from [cablate/banini-tracker](https://github.com/cablate/banini-tracker) to eliminate $11/mo in Apify + LLM API fees. Pair with [skill-cron](skill-cron/) for scheduled runs + Telegram push — [setup guide](banini/docs/SETUP.md) |
| [job-radar](job-radar/) | Your job-hunting autopilot's remote control. Tell your AI "write cover letters" in Telegram and it reads JDs, writes 25 tailored letters, zips them, and sends them back before you finish your coffee. Pairs with [kc_job_radar](https://github.com/KerberosClaw/kc_job_radar) — Docker required, sanity optional |
| [prep-repo](prep-repo/) | The "did I forget anything?" checklist before pushing to GitHub. README, commits, secrets, broken links — the stuff you always forget at 2 AM |

## Installation

Grab what you need, leave what you don't:

```bash
git clone https://github.com/KerberosClaw/kc_ai_skills.git

# Example: install for Claude Code (user-level)
cp -r kc_ai_skills/prep-repo ~/.claude/skills/

# Example: install for OpenClaw (workspace-level)
cp -r kc_ai_skills/searxng ~/.openclaw/workspace/skills/
```

> **Naming tip:** Feel free to rename the skill folder with your own prefix when copying (e.g. `my_prep-repo`). It won't break anything. Probably.

> **Other clients:** Each SKILL.md is a self-contained markdown instruction file. You can paste its content into any AI chat, system prompt, or custom instruction field. No SDK required, no API key needed — just copy and paste.

## Skill Structure

Every skill follows a dead-simple convention. If you can write markdown, you can write a skill:

```
skill-name/
├── SKILL.md          # Frontmatter (name, description, version) + instructions
└── scripts/          # Executable scripts (optional)
    └── script.py
```

## Related Projects

- [kc_tradfri_mcp](https://github.com/KerberosClaw/kc_tradfri_mcp) — "Turn on the living room lights" — yes, we made an AI do that
- [kc_openclaw_local_llm](https://github.com/KerberosClaw/kc_openclaw_local_llm) — We tested 13 local LLMs. Only 2 could reliably call tools. Here's the full report.

## Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [KerberosClaw](https://github.com/KerberosClaw)
- **Source:** [KerberosClaw/kc_ai_skills](https://github.com/KerberosClaw/kc_ai_skills)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/mcp-kerberosclaw-kc-ai-skills
- Seller: https://agentstack.voostack.com/s/kerberosclaw
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
