Claude Code Guide

A Claude Code reference plus a collection of over 70 skills for development, security, data and docs, with agent configs

Skill

High risk

We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.

Why this level

  • The set includes offensive security skills: recon, vulnerability testing and exploitation tooling
  • Some skills run scripts and external tools on the host
All reasons and checks

zebbern/claude-code-guide

Install

In your terminal, with SkillFoxx CLI

npx skillfoxx add skills/claude-code-guide

Detects the agents on your machine, checks the risk and pins the version.

Other ways to install

Assembled automatically, review before installing.

Run in a terminal in the project folder

npx skills add zebbern/claude-code-guide --skill academic-paper-reviewer active-directory-attacks api-fuzzing-bug-bounty api-shape-explorer audit-flow authentication-patterns aws-penetration-testing broken-authentication burp-suite-testing caching chart-image cloud-penetration-testing code-documenter code-to-diagram code-vuln-audit composition-patterns cross-examine cv-tailor data-viz-renderer database-optimizer database-scout dataset-quality-audit deep-module-refactor design-system-builder dev-guide-generator ethical-hacking-methodology file-path-traversal html-injection-testing http-load-profiler idor-testing linux-privilege-escalation linux-shell-scripting localization-toolkit log-error-digest metasploit-framework network-101 nextjs-developer pdf pentest-checklist pentest-commands pipeline-blueprint playwright privilege-escalation-methods project-sizing-guide r2-upload r3f-animation r3f-best-practices react-best-practices red-team-tools regression-modeler regulatory-audit-generator repo-audit route-to-openapi scanning-tools scholarly-writing-refiner secure-code-review shodan-reconnaissance -a claude-code -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add zebbern/claude-code-guide --skill academic-paper-reviewer active-directory-attacks api-fuzzing-bug-bounty api-shape-explorer audit-flow authentication-patterns aws-penetration-testing broken-authentication burp-suite-testing caching chart-image cloud-penetration-testing code-documenter code-to-diagram code-vuln-audit composition-patterns cross-examine cv-tailor data-viz-renderer database-optimizer database-scout dataset-quality-audit deep-module-refactor design-system-builder dev-guide-generator ethical-hacking-methodology file-path-traversal html-injection-testing http-load-profiler idor-testing linux-privilege-escalation linux-shell-scripting localization-toolkit log-error-digest metasploit-framework network-101 nextjs-developer pdf pentest-checklist pentest-commands pipeline-blueprint playwright privilege-escalation-methods project-sizing-guide r2-upload r3f-animation r3f-best-practices react-best-practices red-team-tools regression-modeler regulatory-audit-generator repo-audit route-to-openapi scanning-tools scholarly-writing-refiner secure-code-review shodan-reconnaissance -a cursor -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add zebbern/claude-code-guide --skill academic-paper-reviewer active-directory-attacks api-fuzzing-bug-bounty api-shape-explorer audit-flow authentication-patterns aws-penetration-testing broken-authentication burp-suite-testing caching chart-image cloud-penetration-testing code-documenter code-to-diagram code-vuln-audit composition-patterns cross-examine cv-tailor data-viz-renderer database-optimizer database-scout dataset-quality-audit deep-module-refactor design-system-builder dev-guide-generator ethical-hacking-methodology file-path-traversal html-injection-testing http-load-profiler idor-testing linux-privilege-escalation linux-shell-scripting localization-toolkit log-error-digest metasploit-framework network-101 nextjs-developer pdf pentest-checklist pentest-commands pipeline-blueprint playwright privilege-escalation-methods project-sizing-guide r2-upload r3f-animation r3f-best-practices react-best-practices red-team-tools regression-modeler regulatory-audit-generator repo-audit route-to-openapi scanning-tools scholarly-writing-refiner secure-code-review shodan-reconnaissance -a github-copilot -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add zebbern/claude-code-guide --skill academic-paper-reviewer active-directory-attacks api-fuzzing-bug-bounty api-shape-explorer audit-flow authentication-patterns aws-penetration-testing broken-authentication burp-suite-testing caching chart-image cloud-penetration-testing code-documenter code-to-diagram code-vuln-audit composition-patterns cross-examine cv-tailor data-viz-renderer database-optimizer database-scout dataset-quality-audit deep-module-refactor design-system-builder dev-guide-generator ethical-hacking-methodology file-path-traversal html-injection-testing http-load-profiler idor-testing linux-privilege-escalation linux-shell-scripting localization-toolkit log-error-digest metasploit-framework network-101 nextjs-developer pdf pentest-checklist pentest-commands pipeline-blueprint playwright privilege-escalation-methods project-sizing-guide r2-upload r3f-animation r3f-best-practices react-best-practices red-team-tools regression-modeler regulatory-audit-generator repo-audit route-to-openapi scanning-tools scholarly-writing-refiner secure-code-review shodan-reconnaissance -a codex -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add zebbern/claude-code-guide --skill academic-paper-reviewer active-directory-attacks api-fuzzing-bug-bounty api-shape-explorer audit-flow authentication-patterns aws-penetration-testing broken-authentication burp-suite-testing caching chart-image cloud-penetration-testing code-documenter code-to-diagram code-vuln-audit composition-patterns cross-examine cv-tailor data-viz-renderer database-optimizer database-scout dataset-quality-audit deep-module-refactor design-system-builder dev-guide-generator ethical-hacking-methodology file-path-traversal html-injection-testing http-load-profiler idor-testing linux-privilege-escalation linux-shell-scripting localization-toolkit log-error-digest metasploit-framework network-101 nextjs-developer pdf pentest-checklist pentest-commands pipeline-blueprint playwright privilege-escalation-methods project-sizing-guide r2-upload r3f-animation r3f-best-practices react-best-practices red-team-tools regression-modeler regulatory-audit-generator repo-audit route-to-openapi scanning-tools scholarly-writing-refiner secure-code-review shodan-reconnaissance -a gemini-cli -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add zebbern/claude-code-guide --skill academic-paper-reviewer active-directory-attacks api-fuzzing-bug-bounty api-shape-explorer audit-flow authentication-patterns aws-penetration-testing broken-authentication burp-suite-testing caching chart-image cloud-penetration-testing code-documenter code-to-diagram code-vuln-audit composition-patterns cross-examine cv-tailor data-viz-renderer database-optimizer database-scout dataset-quality-audit deep-module-refactor design-system-builder dev-guide-generator ethical-hacking-methodology file-path-traversal html-injection-testing http-load-profiler idor-testing linux-privilege-escalation linux-shell-scripting localization-toolkit log-error-digest metasploit-framework network-101 nextjs-developer pdf pentest-checklist pentest-commands pipeline-blueprint playwright privilege-escalation-methods project-sizing-guide r2-upload r3f-animation r3f-best-practices react-best-practices red-team-tools regression-modeler regulatory-audit-generator repo-audit route-to-openapi scanning-tools scholarly-writing-refiner secure-code-review shodan-reconnaissance -a cline -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add zebbern/claude-code-guide --skill academic-paper-reviewer active-directory-attacks api-fuzzing-bug-bounty api-shape-explorer audit-flow authentication-patterns aws-penetration-testing broken-authentication burp-suite-testing caching chart-image cloud-penetration-testing code-documenter code-to-diagram code-vuln-audit composition-patterns cross-examine cv-tailor data-viz-renderer database-optimizer database-scout dataset-quality-audit deep-module-refactor design-system-builder dev-guide-generator ethical-hacking-methodology file-path-traversal html-injection-testing http-load-profiler idor-testing linux-privilege-escalation linux-shell-scripting localization-toolkit log-error-digest metasploit-framework network-101 nextjs-developer pdf pentest-checklist pentest-commands pipeline-blueprint playwright privilege-escalation-methods project-sizing-guide r2-upload r3f-animation r3f-best-practices react-best-practices red-team-tools regression-modeler regulatory-audit-generator repo-audit route-to-openapi scanning-tools scholarly-writing-refiner secure-code-review shodan-reconnaissance -a roo -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

A fork of Roo Code, same .roo folders.

Run in a terminal in the project folder

npx skills add zebbern/claude-code-guide --skill academic-paper-reviewer active-directory-attacks api-fuzzing-bug-bounty api-shape-explorer audit-flow authentication-patterns aws-penetration-testing broken-authentication burp-suite-testing caching chart-image cloud-penetration-testing code-documenter code-to-diagram code-vuln-audit composition-patterns cross-examine cv-tailor data-viz-renderer database-optimizer database-scout dataset-quality-audit deep-module-refactor design-system-builder dev-guide-generator ethical-hacking-methodology file-path-traversal html-injection-testing http-load-profiler idor-testing linux-privilege-escalation linux-shell-scripting localization-toolkit log-error-digest metasploit-framework network-101 nextjs-developer pdf pentest-checklist pentest-commands pipeline-blueprint playwright privilege-escalation-methods project-sizing-guide r2-upload r3f-animation r3f-best-practices react-best-practices red-team-tools regression-modeler regulatory-audit-generator repo-audit route-to-openapi scanning-tools scholarly-writing-refiner secure-code-review shodan-reconnaissance -a opencode -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

You will need: Node.js

Checked against the repository on Sep 25, 2026, commit 1d748a5.

Text for your agent

Clone https://github.com/zebbern/claude-code-guide and copy the folders you need from skills/ into ~/.claude/skills/, then run /reload-skills. Read the reference in the README on GitHub.

Other ways from the author
git clone https://github.com/zebbern/claude-code-guide.git
cp -r claude-code-guide/skills/* ~/.claude/skills/

Global install into ~/.claude/skills/. For a single project copy into the project's .claude/skills/. Copy only the folders you need, then run /reload-skills.

This is third-party code. Review the repository files before installing.

What it does

The repository bundles two things. First, a detailed Claude Code reference: install, environment variables, slash commands, modes, MCP, subagents, hooks, permissions and troubleshooting, with links to the official docs. Second, a skills folder with more than 70 ready SKILL.md skills for development, testing, security, data and documentation, plus an agents folder with configs for Claude Code and Codex. The skills cover code review and refactoring, repository audit, diagram generation, and a separate security block: recon, vulnerability testing, web and network assessment. Some skills carry helper scripts that run external tools.

Who it is for. For developers, devops and security engineers who are learning Claude Code and want a ready set of skills for their work.

Good fit when

  • You need commands, settings and Claude Code features gathered in one place
  • You need a ready skill for a task: code review, repository audit, diagram generation
  • You need methodology for authorized security testing inside the agent

Not a fit when

  • You only need the official Claude Code docs without a third-party skill set
  • You have no authorization to test a target but want the offensive skills

Example request

Audit this repository: find frequently changed files and scan the history for leaked secrets

Limitations

This is an unofficial community reference; Claude Code commands and settings change, so verify contested details against the official docs. The repository has no marketplace plugin, skills install by copying into the skills directory. The security skills are for authorized testing only, and some scripts require external tools you install separately.

How to disable. Remove the copied skill folders from ~/.claude/skills/ or the project's .claude/skills/, then run /reload-skills.

Security check

  • The set includes offensive security skills: recon, vulnerability testing and exploitation tooling
  • Some skills run scripts and external tools on the host

README in short

The README is a large map of Claude Code from quick install to advanced features: environment variables, settings and memory files, slash commands, modes, MCP, subagents, hooks, permissions and a troubleshooting section. Each part links to the official documentation, which it names as the authoritative source. Beyond the README the repository holds skills and agents folders with ready components. The skills are grouped by theme: development, testing, data, documentation and security. MIT licensed.

SKILL.md

---
name: repo-audit
description: "Deep analysis of Git history: identify frequently changed hotspot files, analyze code ownership by contributor, and scan for leaked secrets. Triggered when users ask about Git analysis, code hotspots, who owns what code, secret scanning, security audits of commit history, or optimizing code review assignments."
type: tool
license: MIT
tags:
  - git
  - security
  - analysis
  - devops
---

# Repo Audit — Deep Analysis of Git History

Perform three-dimensional analysis on a Git repository: **hotspot file detection**, **code ownership analysis**, and **secret leak scanning**.

FAQ

Is this an official Anthropic project?

No, it is a community reference with links to the official docs. Check current commands and settings against them.

Do I have to install every skill?

No. Copy only the folders you need into the skills directory, for example repository audit or code review.

Editors’ pick

Open-source personal AI assistant on your own machine: answers in Telegram, Slack, Discord and WhatsApp, extended with skills and plugins

CLIHigh risk390.7KRepository stars
Editors’ pick

A self-improving agent from Nous Research with a TUI, messaging gateway, cron jobs and skills it writes itself

CLIHigh risk249.8KRepository stars
Editors’ pick

An open source coding agent for the terminal and desktop with build and plan modes

CLIHigh risk210.6KRepository stars
Editors’ pick

Open prompt library with a Claude Code plugin, MCP server and CLI: search, fetch and improve prompts and skills from an agent

PluginMedium risk171.5KRepository stars
Foxx AIClaude Code Guide

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.