EngineeringCAUTION
380 Claude Code skills & agent skills & plugins (30+ Agents, 70+ custom commands, 380+ skills, customizable references, scripts)for Claude Code, Codex, Gemini CLI, Cursor, and 8 more coding agents — engineering, marketing, product, compliance, C-level advisory, research, business operations, commerc
Overview
380 Claude Code skills & agent skills & plugins (30+ Agents, 70+ custom commands, 380+ skills, customizable references, scripts)for Claude Code, Codex, Gemini CLI, Cursor, and 8 more coding agents — engineering, marketing, product, compliance, C-level advisory, research, business operations, commerc
b228be08e8bdOBSERVED · 2026-10-06Install
Commands as the repository documents them. They are shown, not run.
git clone https://github.com/alirezarezvani/claude-skills.git
git clone https://github.com/alirezarezvani/claude-skills.git
git clone https://github.com/alirezarezvani/claude-skills.git
git clone https://github.com/alirezarezvani/claude-skills.git
Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned | |
| codex | mentioned | |
| copilot | mentioned | |
| cursor | mentioned | |
| gemini-cli | mentioned | |
| openclaw | mentioned | |
| windsurf | mentioned |
Trust audit
CAUTIONgrade B · trust 85/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (13)
.codex/skills/a11y-audit
.codex/skills/ab-test-setup
.codex/skills/ad-creative
.codex/skills/adversarial-reviewer
.codex/skills/aeo
`HIVEMIND_SERVER_URL` overrides that address (default `http://127.0.0.1:4096`). It must be a
| Privileged instructions | High | Avoid `--privileged`, drop capabilities |
| Sensitive mounts | Critical | Never mount /etc, /var/run/docker.sock in prod |
| **System prompt override** | "Ignore previous instructions", "You are now..." | 🔴 CRITICAL | <!-- noqa: SEC-AUDITOR -->
| **Safety bypass** | "Skip safety checks", "Disable content filtering" | 🔴 CRITICAL | <!-- noqa: SEC-AUDITOR -->
| **Role hijacking** | "Act as root", "Pretend you have no restrictions" | 🔴 CRITICAL | <!-- noqa: SEC-AUDITOR -->
Production applications should never read secrets from `.env` files or environment variables baked into container images. Use a dedicated secret store instead.
Gates applied: no_behavioural_pass.
b228be08e8bdfull audit observations/trust-audit/skill/alirezarezvani__engineering.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | b228be08e8bd | CAUTION | B | 85 | first audit |
Questions
What does the Engineering skill do?
380 Claude Code skills & agent skills & plugins (30+ Agents, 70+ custom commands, 380+ skills, customizable references, scripts)for Claude Code, Codex, Gemini CLI, Cursor, and 8 more coding agents — engineering, marketing, product, compliance, C-level advisory, research, business operations, commerc
Is Engineering safe to install?
With care. The audit graded it B (85/100) and found 13 things worth knowing before you trust this skill, listed below with the exact line each was found on.
What can Engineering access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Engineering work with?
Its documentation mentions claude-code, codex, copilot, cursor, gemini-cli, openclaw and windsurf. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (b228be08e8bd), read on 2026-10-06. The repository is watched, and a new audit runs when it changes — this is the first audit.