--- name: solana-dev description: Routing hub for Solana development. Maps a task to the one reference to read first in the ext/ skill submodules or the kit's local skills. user-invocable: true --- # Solana skill hub Follow further links only as needed. Paths are relative to this file. Every install carries the core packs: solana-dev, auditor-skill, colosseum and anthropic-skills. The first three sit under `ext/`, which Claude Code does not auto-discover, so they cost nothing until a row here sends you into one; anthropic-skills installs top-level in `skills//` and is listed every session, for about 102 tokens. The other `ext/` packs are extensions: the kit pins them, and a project installs one when a task needs it. A row that links into an extension gives its install command; run it when the linked folder is missing (`/update` keeps what you install). The Extensions table at the end lists each one with when to use it. The tables below answer "what do I read for this task". When the task instead suggests a pack this project has not installed — formal verification for program code, a design or animation pack for a landing page — [skill-packs](skill-packs/SKILL.md) maps work to packs, add-ons included, and gives the rules for offering one. When sources overlap: the program-code house rules in the project instruction file (`CLAUDE.md`, or `AGENTS.md` in `--agents` installs) win; a protocol's official skill wins for its own SDK (Jupiter, Metaplex, Helius, MagicBlock, Alchemy); [ext/solana-dev](ext/solana-dev/skills/solana-dev/SKILL.md) wins for general Solana work; sendai and community skills fill gaps only. ## Programs | Task | Read | |------|------| | Any program, client or test work (entry point) | [solana-dev SKILL.md](ext/solana-dev/skills/solana-dev/SKILL.md) | | Anchor | [programs/anchor.md](ext/solana-dev/skills/solana-dev/references/programs/anchor.md); upgrading to 1.x: [migrating-v0.32-to-v1.md](ext/solana-dev/skills/solana-dev/references/anchor/migrating-v0.32-to-v1.md) | | Pinocchio, CU optimization | [programs/pinocchio.md](ext/solana-dev/skills/solana-dev/references/programs/pinocchio.md) | | Account and PDA design | [programs/design-patterns.md](ext/solana-dev/skills/solana-dev/references/programs/design-patterns.md) | | Tests: LiteSVM, Mollusk, Surfpool | [testing.md](ext/solana-dev/skills/solana-dev/references/testing.md), [surfpool/overview.md](ext/solana-dev/skills/solana-dev/references/surfpool/overview.md) | | Fuzzing a program with Trident (harness API, invariants) | [solana-fuzz](ext/solana-fuzz/solana-fuzz/SKILL.md) from [belumume](ext/solana-fuzz/); run it as `trident fuzz run fuzz_0 --with-exit-code` -- without that flag a failing invariant is swallowed and the run exits 0 (install: `bash .claude/bin/skills.sh add solana-fuzz`) | | Error codes, failing transactions | [common-errors.md](ext/solana-dev/skills/solana-dev/references/common-errors.md) | | Toolchain version pairing | [compatibility-matrix.md](ext/solana-dev/skills/solana-dev/references/compatibility-matrix.md) | | Security review | [security.md](ext/solana-dev/skills/solana-dev/references/security.md), then [auditor-skill](ext/auditor-skill/SKILL.md) for the audit itself (scope-gated checklists, 1,424 items; see Security tooling below) | | Formal verification (Lean 4) | [qedgen](ext/qedgen/skills/qedgen/SKILL.md) from [QEDGen](ext/qedgen/); needs the `qedgen` CLI, plus `MISTRAL_API_KEY` or `ARISTOTLE_API_KEY` depending on the command (install: `bash .claude/bin/skills.sh add qedgen`) | | Port from Solidity/EVM | concept map: [solana-vs-evm.md](ext/solana-new/skills/idea/solana-beginner/references/solana-vs-evm.md) (install: `bash .claude/bin/skills.sh add solana-new`). The Solana Foundation's eth-to-sol skill carries the full type, pattern and stdlib mappings; the kit catalogues it as an add-on pointer in [skill-registry.json](skill-registry.json) rather than pinning it | Anchor 1.x defaults this kit uses (not all spelled out upstream): SPL transfers through `token_interface::transfer_checked`, account space `T::DISCRIMINATOR.len() + T::INIT_SPACE`, Rust LiteSVM tests under `programs//tests/` (`anchor test` runs Surfpool). ## Clients and frontend | Task | Read | |------|------| | Wallet connection, React hooks, `@solana/kit` UI | [frontend.md](ext/solana-dev/skills/solana-dev/references/frontend.md) | | Transactions, Kit and web3.js boundary | [kit-web3-interop.md](ext/solana-dev/skills/solana-dev/references/kit-web3-interop.md) | | web3.js to Kit migration | [solana-kit-migration/](ext/sendai/skills/solana-kit-migration/), [solana-kit/](ext/sendai/skills/solana-kit/) (install: `bash .claude/bin/skills.sh add sendai`) | | Clients generated from an IDL (Codama, Shank) | [idl-codegen.md](ext/solana-dev/skills/solana-dev/references/idl-codegen.md) | | Payments, Solana Pay, Kora | [payments.md](ext/solana-dev/skills/solana-dev/references/payments.md) | | Official doc links | [resources.md](ext/solana-dev/skills/solana-dev/references/resources.md) | | Vercel, Next.js, AI SDK, v0 | [ext/vercel/skills/](ext/vercel/skills/) from [Vercel](ext/vercel/) (install: `bash .claude/bin/skills.sh add vercel`) | | Brand identity and a design system for the client: shadcn theme, design tokens, UI critique, WCAG audit | [get-shit-pretty](ext/get-shit-pretty/gsp/skills/) (install: `bash .claude/bin/skills.sh add get-shit-pretty`) — designs the client, not the program; wire none of its own `hooks.json` or `.mcp.json` (see its registry `safety`) | | UI design direction; Playwright tests of a local dApp | Anthropic's `frontend-design/SKILL.md` and `webapp-testing/SKILL.md`, core, so every install has them and loads them by description | | Animation and motion on a landing page: timelines, scroll-driven effects, reduced-motion | [gsap-core](ext/gsap-skills/skills/gsap-core/SKILL.md) (official; install: `bash .claude/bin/skills.sh add gsap-skills`); also [gsap-timeline](ext/gsap-skills/skills/gsap-timeline/SKILL.md), [gsap-scrolltrigger](ext/gsap-skills/skills/gsap-scrolltrigger/SKILL.md), [gsap-react](ext/gsap-skills/skills/gsap-react/SKILL.md) (useGSAP), [gsap-frameworks](ext/gsap-skills/skills/gsap-frameworks/SKILL.md) (Vue, Nuxt), [gsap-plugins](ext/gsap-skills/skills/gsap-plugins/SKILL.md), [gsap-utils](ext/gsap-skills/skills/gsap-utils/SKILL.md), [gsap-performance](ext/gsap-skills/skills/gsap-performance/SKILL.md). Last moved 2026-04, so check its API against the current GSAP release | | A real end-to-end browser suite: persistent sessions, multiple contexts, CI | [playwright-skill](ext/playwright-skill/skills/playwright-skill/SKILL.md) (install: `bash .claude/bin/skills.sh add playwright-skill`). Use core `webapp-testing` for a one-off check; reach here when the suite has to live. Its `run.js` launches a real browser against whatever URL you give it, so a test pointed at production acts on production | ## Tokens and NFTs | Task | Read | |------|------| | Token-2022 extensions: pick, combine and create them (CLI, Kit, Anchor); fees, hooks, metadata, pausable, soulbound | [token-extensions](token-extensions/SKILL.md) | | Confidential transfers | [confidential-transfers.md](ext/solana-dev/skills/solana-dev/references/confidential-transfers.md) | | NFTs: Core, Token Metadata, Bubblegum, Candy Machine, Umi | [metaplex](ext/metaplex/skills/metaplex/SKILL.md) (official; install: `bash .claude/bin/skills.sh add metaplex`) | ## DeFi, RPC and data | Task | Read | |------|------| | Jupiter swap, lend, perps, trigger, recurring | [integrating-jupiter](ext/jupiter/skills/integrating-jupiter/SKILL.md) (official); also [jupiter-lend](ext/jupiter/skills/jupiter-lend/SKILL.md), [jupiter-swap-migration](ext/jupiter/skills/jupiter-swap-migration/SKILL.md), [jupiter-vrfd](ext/jupiter/skills/jupiter-vrfd/SKILL.md) (install: `bash .claude/bin/skills.sh add jupiter`) | | Helius RPC, DAS, webhooks, Sender, priority fees | [helius](ext/helius/helius-skills/helius/SKILL.md) (official; install: `bash .claude/bin/skills.sh add helius`) | | SVM internals, consensus, validators, SIMDs | [svm](ext/helius/helius-skills/svm/SKILL.md) (install: `bash .claude/bin/skills.sh add helius`) | | Alchemy RPC, DAS, Yellowstone gRPC; keyless x402 access | [alchemy-api](ext/alchemy/skills/alchemy-api/SKILL.md) (official), [agentic-gateway](ext/alchemy/skills/agentic-gateway/SKILL.md) (install: `bash .claude/bin/skills.sh add alchemy`) | | MagicBlock Ephemeral Rollups: delegated state, real-time apps and games, private payments, VRF, cranks | [magicblock](ext/magicblock/skill/SKILL.md) (official; install: `bash .claude/bin/skills.sh add magicblock`) | | Concentrated-liquidity LP: track positions and fees, out-of-range alerts, IL-vs-HODL backtests, cross-DEX yield, confirm-gated rebalancing, tax lots | [position-manager](ext/position-manager-skill/skill/SKILL.md) (Orca, Raydium, Meteora, Kamino; open one [reference leaf](ext/position-manager-skill/skill/references/) per task; install: `bash .claude/bin/skills.sh add position-manager-skill`) | | Meteora DBC launches, DAMM v1/v2 and DLMM pools, alpha and presale vaults, locks and vesting, M3M3 staking, zaps | [meteora](ext/meteora-invent/skills/meteora/SKILL.md) (official; install: `bash .claude/bin/skills.sh add meteora-invent`). Deeper than the sendai `meteora` folder below; its on-chain writes need a funded keypair and it asks for owner confirmation first | | ZK compression: compressed PDAs and compressed tokens, and the cost model that makes them worth it | [compressed-pda](ext/light-protocol/skills/compressed-pda/SKILL.md), [compressed-token](ext/light-protocol/skills/compressed-token/SKILL.md), [zk](ext/light-protocol/skills/zk/SKILL.md), [testing](ext/light-protocol/skills/testing/SKILL.md) (official; install: `bash .claude/bin/skills.sh add light-protocol`). Last moved 2026-06, so check its SDK versions against the current crate | | Historical or cross-chain analytics in DuneSQL: dashboards, decoded-table queries, Trino's departures from Postgres | [dune](ext/dune/skills/dune/SKILL.md) (official; install: `bash .claude/bin/skills.sh add dune`). Answers questions over data someone else already decoded; an indexer is still the answer for your own program's state | | USDC and stablecoin payments: agent wallets, CCTP bridging, Gateway, Arc, swaps, accepting payments | [circle](ext/circle/plugins/circle/skills/) (official; install: `bash .claude/bin/skills.sh add circle`) — 18 skills. It moves real money: 11 of them describe fund movement, it reads `CIRCLE_API_KEY`/`CIRCLE_ENTITY_SECRET` and several private-key variables, and `recover-eco-funds` ships two Node scripts that simulate by default and sign only behind explicit flags. Point it at a testnet before anything else, and read [agent-wallet-policy](ext/circle/plugins/circle/skills/agent-wallet-policy/SKILL.md) before granting an allowance | | Memecoin research and due diligence: holder and wallet analysis, smart-money tracking, dev score, heat rank, narrative | [gmgn](ext/gmgn/skills/) (install: `bash .claude/bin/skills.sh add gmgn`) — 17 skills. Two of them **submit trades**: [gmgn-token-buy](ext/gmgn/skills/gmgn-token-buy/SKILL.md) vets and sizes a buy, then [gmgn-swap](ext/gmgn/skills/gmgn-swap/SKILL.md) executes it (buys, sells, limit orders, stop loss, take profit, multi-wallet batches). Use the research skills freely; treat the two execution skills as spending real funds, and note that `gmgn-swap` resolves no token names — only contract addresses — so a same-name copycat is a loss it cannot catch. A personal-account repo, not an organisation | Other protocols from [SendAI](ext/sendai/skills/) (install: `bash .claude/bin/skills.sh add sendai`): perps [phoenix](ext/sendai/skills/phoenix/) and leverage [lavarage](ext/sendai/skills/lavarage/); AMMs [raydium](ext/sendai/skills/raydium/), [meteora](ext/sendai/skills/meteora/), [orca](ext/sendai/skills/orca/); lending [kamino](ext/sendai/skills/kamino/), [marginfi](ext/sendai/skills/marginfi/); LSTs [sanctum](ext/sendai/skills/sanctum/); launches [pumpfun](ext/sendai/skills/pumpfun/); oracles [pyth](ext/sendai/skills/pyth/), [switchboard](ext/sendai/skills/switchboard/); multisig [squads](ext/sendai/skills/squads/); bridging [debridge](ext/sendai/skills/debridge/), [lifi](ext/sendai/skills/lifi/); encrypted compute [arcium](ext/sendai/skills/arcium/); ZK compression [light-protocol](ext/sendai/skills/light-protocol/); data [birdeye](ext/sendai/skills/birdeye/), [wallet-analysis](ext/sendai/skills/wallet-analysis/); RPC [carbium](ext/sendai/skills/carbium/), [quicknode](ext/sendai/skills/quicknode/); order book [manifest](ext/sendai/skills/manifest/); order flow [dflow](ext/sendai/skills/dflow/); account cleanup [sol-incinerator](ext/sendai/skills/sol-incinerator/); agents [solana-agent-kit](ext/sendai/skills/solana-agent-kit/); wallets [phantom-connect](ext/sendai/skills/phantom-connect/); scanning [vulnhunter](ext/sendai/skills/vulnhunter/). SendAI's own jupiter, metaplex, helius and magicblock folders are older copies; the official skills above supersede them. ## Security tooling - [safe-ai-skill](https://github.com/solanabr/safe-ai-skill), core (the `safe-ai-skill@stbr` plugin): hooks gate mainnet, value-moving and authority actions and secret reads. At session start it pins skills and `ext/` submodules and moves any that drift or look unsafe into quarantine, so a missing `ext/` path may be quarantined rather than uninitialized. Its ask or deny is the user's policy, so don't retry the action another way. CLI (on PATH while the plugin is enabled, else `npx @stbr/safe-ai-skill`): `status`, `verify check `, `registry list`. - [auditor-skill](ext/auditor-skill/SKILL.md), core: the kit's audit pack, scope-gated so it loads only the checklists a repo needs. Programs — [account validation](ext/auditor-skill/checklists/01-program-account-validation.md), [access control](ext/auditor-skill/checklists/02-program-access-control.md), [arithmetic](ext/auditor-skill/checklists/03-program-arithmetic-safety.md), [CPI and PDA](ext/auditor-skill/checklists/04-program-cpi-pda.md), [state machines](ext/auditor-skill/checklists/05-program-state-machine.md), [economics](ext/auditor-skill/checklists/06-program-economic-logic.md), [opsec and governance](ext/auditor-skill/checklists/07-program-opsec-governance.md); the code around them — [TypeScript](ext/auditor-skill/checklists/08-typescript-safety.md), [backend](ext/auditor-skill/checklists/09-backend-security.md), [frontend](ext/auditor-skill/checklists/10-frontend-security.md), [supply chain](ext/auditor-skill/checklists/11-supply-chain.md), [secrets](ext/auditor-skill/checklists/12-secrets-opsec.md), [deployment](ext/auditor-skill/checklists/13-deployment-infrastructure.md), [testing and formal verification](ext/auditor-skill/checklists/16-formal-verification-testing.md), [logging and incident response](ext/auditor-skill/checklists/17-logging-monitoring-incident-response.md), [privacy and change management](ext/auditor-skill/checklists/18-privacy-compliance-change-management.md), [AI-agent surface](ext/auditor-skill/checklists/19-ai-agent-security.md), [Rust services](ext/auditor-skill/checklists/20-rust-offchain-services.md). Also [known-vectors](ext/auditor-skill/known-vectors/) (138 worked attacks), [framework idioms](ext/auditor-skill/references/framework-idioms/), [invariant catalog](ext/auditor-skill/references/invariant-catalog.md), [false positives](ext/auditor-skill/references/false-positives.md), [report format](ext/auditor-skill/references/report-format.md), and [FULL-AUDIT.md](ext/auditor-skill/FULL-AUDIT.md) for the whole-repo run. It supersedes the trailofbits, ghostsecurity, defending-code and safe-solana-builder packs the kit used to pin. Its tool-execution layer wraps Trail of Bits at `vendor/trailofbits`, which the installers do not fetch: the pack tests for the directory and falls back to its own grep-based discovery when it is absent, so treat that layer as absent unless you checked it. Installed packs are plain copies with no git metadata, so opting in means cloning it yourself at the commit [skill-registry.json](skill-registry.json) records in the entry's `vendored` field — and `/update` removes it again. - [sign-safe](ext/sign-safe/skill/SKILL.md), extension: review a transaction at signing time rather than the program behind it. Decodes an opaque base64 transaction or message (legacy and v0 with ALTs), classifies instructions, screens recipients, and emits a SIGN / HOLD / REJECT verdict plus a `verdict.json` an agent can gate on. Offline and deterministic by default; `--rpc` adds ALT resolution, Squads v4 proposal decoding and Token-2022 extension screening. Also [danger-catalog](ext/sign-safe/skill/references/danger-catalog.md), [decode-notes](ext/sign-safe/skill/references/decode-notes.md), [verdict-contract](ext/sign-safe/skill/references/verdict-contract.md) (install: `bash .claude/bin/skills.sh add sign-safe`) - [counterparty-gate](ext/counterparty-gate/skill/SKILL.md), extension: who *operates* a program, oracle, keeper or multisig you are about to CPI into or compose with — the serial-rug question a bytecode audit cannot answer. Also [interpreting-scores](ext/counterparty-gate/skill/interpreting-scores.md), [counterparty](ext/counterparty-gate/skill/counterparty.md), [tx-preview](ext/counterparty-gate/skill/tx-preview.md). It calls SolSentry's hosted API, so the addresses you ask about leave the machine and an outage means no answer rather than a wrong one (install: `bash .claude/bin/skills.sh add counterparty-gate`) The three cover different questions: `auditor-skill` the program's source, `sign-safe` the transaction in front of you, `counterparty-gate` the people behind it. ## Deploy, infra, backend - [deployment.md](deployment.md): devnet and mainnet flow, verifiable builds, Squads multisig upgrades, rollback - [backend-async.md](backend-async.md): Rust services and indexers that talk to Solana - MCP server for a program or API: Anthropic's `mcp-builder`, no longer in core. `/plugin marketplace add anthropics/skills` then `/plugin install example-skills@anthropic-agent-skills` — per-user, so it costs a project nothing - [Cloudflare](ext/cloudflare/skills/) (install: `bash .claude/bin/skills.sh add cloudflare`): [workers-best-practices](ext/cloudflare/skills/workers-best-practices/), [agents-sdk](ext/cloudflare/skills/agents-sdk/), [sandbox-stable](ext/cloudflare/skills/sandbox-stable/), [durable-objects](ext/cloudflare/skills/durable-objects/), [wrangler](ext/cloudflare/skills/wrangler/) - [supabase](ext/supabase/skills/supabase/SKILL.md) (official; install: `bash .claude/bin/skills.sh add supabase`): the off-chain data layer — Postgres, Auth, Edge Functions, Realtime, Storage, the CLI, migrations and declarative schemas. For the database an indexer or webhook consumer writes into, [supabase-postgres-best-practices](ext/supabase/skills/supabase-postgres-best-practices/SKILL.md) is the one to open: query plans, connection pooling and exhaustion, partitioning, RLS policy performance, missing foreign-key indexes, `SKIP LOCKED` queues. Two things it does on its own: its SKILL.md fetches `https://supabase.com/changelog.md` whenever it loads, plus vendor docs at decision points, so a Supabase task always calls out to supabase.com; and [skill-feedback.md](ext/supabase/skills/supabase/references/skill-feedback.md) can open a public GitHub issue on `supabase/agent-skills` built from the conversation. That step asks permission first; let the user answer it, since the issue body is their session. - [huggingface-skills](ext/huggingface-skills/skills/) (official; install: `bash .claude/bin/skills.sh add huggingface-skills`): 25 skills for the AI/LLM side of a project — the `hf` CLI and Hub operations, [Gradio](ext/huggingface-skills/skills/huggingface-gradio/) and [Spaces](ext/huggingface-skills/skills/huggingface-spaces/) apps, [ZeroGPU](ext/huggingface-skills/skills/huggingface-zerogpu/), fine-tuning ([LLM](ext/huggingface-skills/skills/huggingface-llm-trainer/), [vision](ext/huggingface-skills/skills/huggingface-vision-trainer/), [TRL](ext/huggingface-skills/skills/trl-training/), [sentence-transformers](ext/huggingface-skills/skills/train-sentence-transformers/)), [evals](ext/huggingface-skills/skills/huggingface-community-evals/) and [transformers.js](ext/huggingface-skills/skills/transformers-js/). Machinery rather than prose — executables, a pipe-to-shell CLI installer, AWS IAM creation: read its registry `safety` before letting it near a cloud account, and wire none of its own `.mcp.json`. - [mongodb](ext/mongodb/skills/) (official; install: `bash .claude/bin/skills.sh add mongodb`), extension: the document store under an indexer — [mongodb-schema-design](ext/mongodb/skills/mongodb-schema-design/SKILL.md), [mongodb-query-optimizer](ext/mongodb/skills/mongodb-query-optimizer/SKILL.md), [mongodb-connection](ext/mongodb/skills/mongodb-connection/SKILL.md), [mongodb-search-and-ai](ext/mongodb/skills/mongodb-search-and-ai/SKILL.md) (Atlas Search and vector search), [mongodb-atlas-stream-processing](ext/mongodb/skills/mongodb-atlas-stream-processing/SKILL.md). Pick it over `supabase` when the shape is documents rather than relations; `duckdb` stays the answer for files with no database at all. Its `mongodb-mcp-setup` skill points at `mongodb-mcp-server@<3`, which talks to whichever cluster its connection string names - [redis](ext/redis/skills/) (official; install: `bash .claude/bin/skills.sh add redis`), extension: the cache and queue on an RPC fan-out's hot path — [redis-core](ext/redis/skills/redis-core/SKILL.md), [redis-connections](ext/redis/skills/redis-connections/SKILL.md) (pooling and exhaustion), [redis-clustering](ext/redis/skills/redis-clustering/SKILL.md), [redis-search](ext/redis/skills/redis-search/SKILL.md), [redis-semantic-cache](ext/redis/skills/redis-semantic-cache/SKILL.md) (for LLM calls), [redis-security](ext/redis/skills/redis-security/SKILL.md), [redis-observability](ext/redis/skills/redis-observability/SKILL.md) - [pulumi](ext/pulumi/pulumi/skills/) (official; install: `bash .claude/bin/skills.sh add pulumi`), extension: infrastructure-as-code in a real language, where the kit's own devops lane stops at CI and Cloudflare — [pulumi-overview](ext/pulumi/pulumi/skills/pulumi-overview/SKILL.md), [pulumi-best-practices](ext/pulumi/pulumi/skills/pulumi-best-practices/SKILL.md), [pulumi-automation-api](ext/pulumi/pulumi/skills/pulumi-automation-api/SKILL.md), [pulumi-esc](ext/pulumi/pulumi/skills/pulumi-esc/SKILL.md) (secrets and config), [pulumi-debug-failed-operation](ext/pulumi/pulumi/skills/pulumi-debug-failed-operation/SKILL.md); migration lives under [migration/skills](ext/pulumi/migration/skills/) (Terraform, CDK, ARM, CloudFormation). It drives the `pulumi` CLI against whatever cloud credentials the shell already holds, so `pulumi up` from here changes real infrastructure - [resend](ext/resend/skills/) (official; install: `bash .claude/bin/skills.sh add resend`), extension: transactional email a dApp needs for alerts, receipts and waitlists — [resend](ext/resend/skills/resend/SKILL.md), [resend-cli](ext/resend/skills/resend-cli/SKILL.md), [react-email](ext/resend/skills/react-email/SKILL.md), [email-best-practices](ext/resend/skills/email-best-practices/SKILL.md) (deliverability), [agent-email-inbox](ext/resend/skills/agent-email-inbox/SKILL.md). `RESEND_API_KEY` sends as your domain, so a mistake lands in real inboxes under your own sending reputation — and `agent-email-inbox` has an agent read and reply to mail - [google](ext/google/plugins/cloud/) (official; install: `bash .claude/bin/skills.sh add google`), extension: 155 Google Cloud skills for the infrastructure under an indexer or RPC fleet — GKE autoscaling, compute classes and workload security, BigQuery (BigFrames, AI/ML functions, vector search), IAM troubleshooting and privileged access, Cloud Monitoring PromQL, Agent Platform deploy and tuning. Nothing on-chain. About 20 of its skills ship shell and Python under `scripts/` that call `gcloud`, `kubectl` and `bq` against whichever project your ambient login points at — some read state, some change it, so check the active project before running one - [duckdb](ext/duckdb/skills/) (official; install: `bash .claude/bin/skills.sh add duckdb`), extension: SQL over files with no database to run — [read-file](ext/duckdb/skills/read-file/SKILL.md) (Parquet, CSV, JSON, Avro, Excel, Iceberg, Delta), [query](ext/duckdb/skills/query/SKILL.md), [attach-db](ext/duckdb/skills/attach-db/SKILL.md), [convert-file](ext/duckdb/skills/convert-file/SKILL.md), [s3-explore](ext/duckdb/skills/s3-explore/SKILL.md) (S3, R2, GCS, Azure), [spatial](ext/duckdb/skills/spatial/SKILL.md), [duckdb-docs](ext/duckdb/skills/duckdb-docs/SKILL.md). Reach for it on an indexer's Parquet exports, an airdrop snapshot or a one-off aggregate over transaction dumps — `supabase` stays the answer when the data needs to live somewhere. Two notes: [install-duckdb](ext/duckdb/skills/install-duckdb/SKILL.md) tells the user to pipe `install.duckdb.org` into a shell, which is their call and not the only route (Homebrew has it), and `read-memories` searches past Claude session logs on disk. ## Games and mobile - [solana-game](ext/solana-game/skill/) (install: `bash .claude/bin/skills.sh add solana-game`): [SKILL.md](ext/solana-game/skill/SKILL.md), [unity-sdk.md](ext/solana-game/skill/unity-sdk.md), [playsolana.md](ext/solana-game/skill/playsolana.md) (PSG1, PlayDex, PlayID), [game-architecture.md](ext/solana-game/skill/game-architecture.md), [mobile.md](ext/solana-game/skill/mobile.md), [csharp-patterns.md](ext/solana-game/skill/csharp-patterns.md) - [solana-mobile](ext/solana-mobile/skills/) (install: `bash .claude/bin/skills.sh add solana-mobile`): [solana-mobile-wallet](ext/solana-mobile/skills/solana-mobile-wallet/) (MWA 2.0), [seeker-genesis-token](ext/solana-mobile/skills/seeker-genesis-token/), [seeker-domains](ext/solana-mobile/skills/seeker-domains/) - [expo](ext/expo/plugins/expo/skills/) (install: `bash .claude/bin/skills.sh add expo`), extension: Expo's own 23 skills for everything solana-mobile does not cover — [expo-overview](ext/expo/plugins/expo/skills/expo-overview/SKILL.md) routes them. Build and release: [eas-workflows](ext/expo/plugins/expo/skills/eas-workflows/SKILL.md) (CI), [eas-app-stores](ext/expo/plugins/expo/skills/eas-app-stores/SKILL.md), [eas-update](ext/expo/plugins/expo/skills/eas-update/SKILL.md) (OTA), [eas-simulator](ext/expo/plugins/expo/skills/eas-simulator/SKILL.md), [eas-hosting](ext/expo/plugins/expo/skills/eas-hosting/SKILL.md), [eas-observe](ext/expo/plugins/expo/skills/eas-observe/SKILL.md). Native and UI: [expo-module](ext/expo/plugins/expo/skills/expo-module/SKILL.md) (config plugins, native modules), [expo-dev-client](ext/expo/plugins/expo/skills/expo-dev-client/SKILL.md), [expo-router](ext/expo/plugins/expo/skills/expo-router/SKILL.md), [expo-ui](ext/expo/plugins/expo/skills/expo-ui/SKILL.md), [expo-brownfield](ext/expo/plugins/expo/skills/expo-brownfield/SKILL.md), [expo-upgrade](ext/expo/plugins/expo/skills/expo-upgrade/SKILL.md). Use it with solana-mobile, not instead of it: MWA and Seeker live there, the build and release pipeline here. Wire none of its own `hooks.json` or `.mcp.json` — a pin leaves both inert, and its telemetry is opt-in and off by default only on the paths the registry `safety` records. ## Ideas, pitch, go-to-market - [Colosseum copilot](ext/colosseum/skills/colosseum-copilot/SKILL.md) ([dir](ext/colosseum/skills/colosseum-copilot/)), core: idea validation, competitive research, hackathon archives, feedback on the user's own submission. It signs in through a helper rather than an env var, so on a fresh machine run `npx @colosseum-org/copilot-connect status` and, if that reports no connection, `npx @colosseum-org/copilot-connect login` (`--device` where no browser can open). Needs Node 20+. `COLOSSEUM_COPILOT_PAT` is a leftover from the retired v1 auth — don't read it or ask for one. - [community-moderation](ext/community-moderation/skills/community-moderation/SKILL.md), extension: running the community once it exists — moderating a Telegram or Discord group (spam, drainer links, raids, admin impersonation, mass pings) and member support (trust states, roles, triage, ticketing), with confusable, invisible-character and bidi normalization so evasion in ten languages still matches. Its platform examples are bots the operator runs and tokens the operator supplies (install: `bash .claude/bin/skills.sh add community-moderation`) - [frontend-slides](ext/frontend-slides/plugins/frontend-slides/skills/frontend-slides/SKILL.md) (install: `bash .claude/bin/skills.sh add frontend-slides`), extension: the house format for decks, graphics and marketing material is HTML, and this is what builds it — 36 templates each with a `design.md` and `preview.md`, a [selection index](ext/frontend-slides/bold-template-pack/selection-index.json) that maps a deck's intent to a template, [style presets](ext/frontend-slides/plugins/frontend-slides/skills/frontend-slides/STYLE_PRESETS.md) and [animation patterns](ext/frontend-slides/plugins/frontend-slides/skills/frontend-slides/animation-patterns.md). pitch-deck and content-gen hand it the content. Its two scripts only run if you ask: `export-pdf.sh` npm-installs Playwright into a temp dir to render a PDF, and `deploy.sh` publishes through the Vercel CLI (and will `npm install -g vercel`), which puts the deck on a public URL. - [elevenlabs](ext/elevenlabs/) (official; install: `bash .claude/bin/skills.sh add elevenlabs`), extension: the audio a launch needs — [text-to-speech](ext/elevenlabs/text-to-speech/SKILL.md) for demo-video narration, [dubbing](ext/elevenlabs/dubbing/SKILL.md) for localisation, [sound-effects](ext/elevenlabs/sound-effects/SKILL.md) and [music](ext/elevenlabs/music/SKILL.md) for a trailer, [speech-to-text](ext/elevenlabs/speech-to-text/SKILL.md) for transcripts, plus [voice-changer](ext/elevenlabs/voice-changer/SKILL.md), [voice-isolator](ext/elevenlabs/voice-isolator/SKILL.md) and [agents](ext/elevenlabs/agents/SKILL.md). Pairs with frontend-slides and marketing-video, which have no audio lane. Every call is billed to `ELEVENLABS_API_KEY` ([setup-api-key](ext/elevenlabs/setup-api-key/SKILL.md)), so a long dubbing or music job costs real money - [knowledge-work](ext/knowledge-work/) (official; install: `bash .claude/bin/skills.sh add knowledge-work`), extension: Anthropic's 252 skills across 18 role-shaped plugins for the business around the project rather than the chain — [sales](ext/knowledge-work/sales/), [marketing](ext/knowledge-work/marketing/), [finance](ext/knowledge-work/finance/), [legal](ext/knowledge-work/legal/), [product-management](ext/knowledge-work/product-management/), [design](ext/knowledge-work/design/), [data](ext/knowledge-work/data/), [engineering](ext/knowledge-work/engineering/), [operations](ext/knowledge-work/operations/), [human-resources](ext/knowledge-work/human-resources/), [customer-support](ext/knowledge-work/customer-support/), [enterprise-search](ext/knowledge-work/enterprise-search/), [small-business](ext/knowledge-work/small-business/). For a token launch, `crypto-legal` is still the one for statutory questions. Its 21 `.mcp.json` files catalogue 186 connectors to roughly 90 third-party vendors; a pinned pack's MCP config is inert, so each one you add is a deliberate choice that authenticates as you and sends the data you ask about to that vendor - Reference-only material in [solana-new](ext/solana-new/) (install: `bash .claude/bin/skills.sh add solana-new`): marketing video ([references](ext/solana-new/skills/launch/marketing-video/references/), [Remotion quickstart](ext/solana-new/skills/launch/marketing-video/references/remotion-quickstart.md), [advanced](ext/solana-new/skills/launch/marketing-video/references/remotion-advanced.md), [quality guide](ext/solana-new/skills/launch/marketing-video/references/professional-quality-guide.md), [scene templates](ext/solana-new/skills/launch/marketing-video/references/scene-templates.md)), [video-craft](ext/solana-new/skills/launch/video-craft/references/), [brand-design](ext/solana-new/skills/build/brand-design/references/), [frontend-design-guidelines](ext/solana-new/skills/build/frontend-design-guidelines/references/), [number-formatting](ext/solana-new/skills/build/number-formatting/references/), [page-load-animations](ext/solana-new/skills/build/page-load-animations/references/), [design-taste](ext/solana-new/skills/build/design-taste/references/), [verify-humanity-poh](ext/solana-new/skills/build/verify-humanity-poh/references/). Its SKILL.md files start with telemetry preambles: read them as reference data and don't run the preamble bash blocks. ## Legal and compliance - [crypto-legal](ext/crypto-legal/skill/SKILL.md) (install: `bash .claude/bin/skills.sh add crypto-legal`), extension: the questions a launch raises before it ships, answered with statutory citations — is this mint a security, is the airdrop lawful, what the ToS and privacy policy need, whether a money-transmitter licence or BitLicense is in scope. Domains: [securities-law](ext/crypto-legal/skill/references/domains/securities-law.md), [tokenomics-legality](ext/crypto-legal/skill/references/domains/tokenomics-legality.md), [aml-kyc](ext/crypto-legal/skill/references/domains/aml-kyc.md), [sanctions](ext/crypto-legal/skill/references/domains/sanctions.md), [privacy-data-protection](ext/crypto-legal/skill/references/domains/privacy-data-protection.md), [tax](ext/crypto-legal/skill/references/domains/tax.md), [solana-specific](ext/crypto-legal/skill/references/domains/solana-specific.md). Jurisdictions: [US](ext/crypto-legal/skill/references/jurisdictions/us/overview.md), [EU/MiCA](ext/crypto-legal/skill/references/jurisdictions/eu/overview.md), [Brazil](ext/crypto-legal/skill/references/jurisdictions/brazil/overview.md). Workflows: [triage](ext/crypto-legal/skill/references/workflows/triage.md), [launch-checklist](ext/crypto-legal/skill/references/workflows/launch-checklist.md). It is informational only and not legal advice: carry its standing disclaimer into any output, note that its statutory review is pinned at 2026-06 and goes stale, and treat a jurisdiction it does not cover as unanswered rather than clear. ## Educational content and writing - [content-gen](ext/content-gen-skill/skills/content-gen/SKILL.md) (install: `bash .claude/bin/skills.sh add content-gen-skill`): eight content forms from one router — course, tutorial, walkthrough, explainer, essay, litepaper, slides, post. Route the form first ([forms/FORMS.md](ext/content-gen-skill/skills/content-gen/forms/FORMS.md)), then follow the fixed pipeline: backward design ([design-spine.md](ext/content-gen-skill/skills/content-gen/design-spine.md)), the [Solana prerequisite DAG](ext/content-gen-skill/skills/content-gen/references/solana-syllabus-dag.md), grounding against live sources, draft, voice pass, visual placeholders, validators. Skipping a stage is a defect, not a shortcut. - [superseo](ext/superseo/skills/) (install: `bash .claude/bin/skills.sh add superseo`), extension: the search half of the same work — [page-audit](ext/superseo/skills/page-audit/SKILL.md), [content-brief](ext/superseo/skills/content-brief/SKILL.md), [write-content](ext/superseo/skills/write-content/SKILL.md) and [improve-content](ext/superseo/skills/improve-content/SKILL.md) for the page itself, [keyword-deep-dive](ext/superseo/skills/keyword-deep-dive/SKILL.md) and [semantic-gap-analysis](ext/superseo/skills/semantic-gap-analysis/SKILL.md) for intent, [eeat-audit](ext/superseo/skills/eeat-audit/SKILL.md) for trust signals, plus topic-cluster-planning, featured-snippet-optimizer, linkbuilding and expert-interview. Markdown only — no executables — and it works through your own search and fetch tools, so it needs no SEO subscription. - [writer-style](ext/writer-style-skill/skills/writer-style/SKILL.md) (install: `bash .claude/bin/skills.sh add writer-style-skill`): prose in a named author's voice, facts verified before styling. Ships the `kaue` and `david` [packs](ext/writer-style-skill/skills/writer-style/profiles/); content-gen hands it a brief tagged with `dominant_job` when both are installed, and writes the prose itself when it is absent. - [obsidian-skills](ext/obsidian-skills/skills/) (install: `bash .claude/bin/skills.sh add obsidian-skills`): an Obsidian vault as the project's notes and research layer — Obsidian-flavored Markdown, Bases (`.base`) query views, JSON Canvas (`.canvas`), and Defuddle for a web page into clean Markdown. Vault-write and local-exec once an agent follows it, not from the pin (see its registry `safety`). ## Extensions Pinned by the kit, installed on demand. `bash .claude/bin/skills.sh list` shows what this project has. | Extension | Install when the task involves | Install | |-----------|--------------------------------|---------| | qedgen | Formal verification with Lean 4 (needs the `qedgen` CLI, plus `MISTRAL_API_KEY` or `ARISTOTLE_API_KEY`) | `bash .claude/bin/skills.sh add qedgen` | | solana-fuzz | Trident fuzzing: the v0.12.0 harness API, invariant post-conditions, and the `--with-exit-code` flag a run needs in order to fail | `bash .claude/bin/skills.sh add solana-fuzz` | | sendai | DeFi and other protocols (Raydium, Orca, Meteora, Kamino, marginfi, Sanctum, Pyth, Switchboard, Squads, pump.fun, bridges), web3.js to Kit migration | `bash .claude/bin/skills.sh add sendai` | | jupiter | Jupiter swap, lend, perps, trigger and recurring orders | `bash .claude/bin/skills.sh add jupiter` | | metaplex | NFTs: Core, Token Metadata, Bubblegum, Candy Machine, Umi | `bash .claude/bin/skills.sh add metaplex` | | magicblock | MagicBlock Ephemeral Rollups, real-time apps and games, private payments | `bash .claude/bin/skills.sh add magicblock` | | helius | Helius RPC, DAS, webhooks, Laserstream, Sender, priority fees, SVM internals | `bash .claude/bin/skills.sh add helius` | | alchemy | Alchemy RPC, DAS, Yellowstone gRPC, x402 gateway (`ALCHEMY_API_KEY` for the API skill) | `bash .claude/bin/skills.sh add alchemy` | | position-manager-skill | Concentrated-liquidity LP: positions, out-of-range alerts, IL backtests, rebalancing, tax lots | `bash .claude/bin/skills.sh add position-manager-skill` | | solana-game | Unity, C#, games, PlaySolana, PSG1 | `bash .claude/bin/skills.sh add solana-game` | | solana-mobile | React Native, Expo, Mobile Wallet Adapter, Seeker, dApp Store | `bash .claude/bin/skills.sh add solana-mobile` | | crypto-legal | Legal and compliance before a launch: is the mint a security, is the airdrop lawful, ToS and privacy review, licensing, sanctions and KYC (US, EU/MiCA, Brazil; informational only, review pinned at 2026-06) | `bash .claude/bin/skills.sh add crypto-legal` | | duckdb | Analysing or reporting on exported data — Parquet, CSV, JSON, Excel, Iceberg, buckets — with SQL and no database to stand up (its install step is a pipe-to-shell it asks you to run; `read-memories` reads past session logs) | `bash .claude/bin/skills.sh add duckdb` | | dune | Historical or cross-chain analytics in DuneSQL — dashboards and queries over decoded tables, and Trino's departures from Postgres | `bash .claude/bin/skills.sh add dune` | | mongodb | A document store under an indexer: schema design, aggregation and query plans, Atlas Search and vector search, stream processing | `bash .claude/bin/skills.sh add mongodb` | | redis | Caching, queues and rate-limit state on a hot path: pooling and exhaustion, clustering, Redis Search, semantic caching for LLM calls | `bash .claude/bin/skills.sh add redis` | | light-protocol | ZK compression on Solana: compressed PDAs and compressed tokens, and the cost model that justifies them (last moved 2026-06 — check its SDK versions) | `bash .claude/bin/skills.sh add light-protocol` | | meteora-invent | Meteora in depth: DBC launches, DAMM v1/v2 and DLMM pools, alpha and presale vaults, locks and vesting, M3M3 staking, zaps (on-chain writes need a funded keypair) | `bash .claude/bin/skills.sh add meteora-invent` | | circle | USDC and stablecoin payments: agent wallets, CCTP bridging, Gateway, Arc, swaps, accepting payments. **Moves real money** and reads API keys and private-key variables — testnet first | `bash .claude/bin/skills.sh add circle` | | gmgn | Memecoin research and due diligence: holder and wallet analysis, smart-money tracking, dev score, narrative. **Two of its skills submit trades**; `gmgn-swap` takes contract addresses only, never names | `bash .claude/bin/skills.sh add gmgn` | | resend | Transactional email for a dApp — alerts, receipts, waitlists — with React Email and deliverability practice (sends as your domain; `agent-email-inbox` replies to mail) | `bash .claude/bin/skills.sh add resend` | | pulumi | Infrastructure-as-code in a real language, past CI and Cloudflare: Automation API, ESC secrets, stack migration (drives the `pulumi` CLI against your live cloud credentials) | `bash .claude/bin/skills.sh add pulumi` | | google | Google Cloud under an indexer or RPC fleet: GKE, BigQuery, IAM troubleshooting, PromQL, Agent Platform (about 20 skills ship scripts that call `gcloud`/`kubectl`/`bq` against your active project) | `bash .claude/bin/skills.sh add google` | | knowledge-work | The business around the project rather than the chain: 252 skills across 18 role plugins (sales, finance, legal, PM, support). Its 186 catalogued MCP connectors are inert until you add one | `bash .claude/bin/skills.sh add knowledge-work` | | elevenlabs | Audio for a launch: demo-video narration, dubbing and localisation, sound effects, music, transcripts (every call is billed to your key) | `bash .claude/bin/skills.sh add elevenlabs` | | gsap-skills | Animation and motion on a landing page or marketing site: timelines, ScrollTrigger, useGSAP, plugins, reduced-motion, performance (official GreenSock; last moved 2026-04) | `bash .claude/bin/skills.sh add gsap-skills` | | playwright-skill | Browser automation and end-to-end webapp tests when `webapp-testing` from core is not enough — persistent sessions, multiple contexts, a real CI suite (individually authored; last moved 2026-08) | `bash .claude/bin/skills.sh add playwright-skill` | | expo | The Expo build and release pipeline beside solana-mobile: EAS Build, Update and Workflows, store submission, OTA, config plugins and native modules, expo-router, SDK upgrades (don't wire its `hooks.json` or `.mcp.json`) | `bash .claude/bin/skills.sh add expo` | | cloudflare | Cloudflare Workers, wrangler, Durable Objects, Agents SDK | `bash .claude/bin/skills.sh add cloudflare` | | vercel | Vercel deploys, Next.js and React performance, web design review | `bash .claude/bin/skills.sh add vercel` | | get-shit-pretty | Brand identity, a design system, shadcn themes and design tokens, UI polish, accessibility audits (designs the client, not the program; don't wire its `hooks.json` or `.mcp.json`) | `bash .claude/bin/skills.sh add get-shit-pretty` | | frontend-slides | Any slide deck, presentation, marketing graphic or social image — the kit builds these as HTML (36 templates; `export-pdf.sh` and `deploy.sh` run only when you ask) | `bash .claude/bin/skills.sh add frontend-slides` | | superseo | Making a landing page, docs page or post rank: SEO audit, keyword and intent research, content briefs, E-E-A-T, topic clusters, link building (markdown only, no executables, no paid data source) | `bash .claude/bin/skills.sh add superseo` | | supabase | Supabase as the off-chain layer: Postgres schema, migrations and RLS, Auth, Edge Functions, Realtime, Storage; or tuning the database an indexer writes into (fetches supabase.com docs whenever it loads) | `bash .claude/bin/skills.sh add supabase` | | solana-new | Go-to-market references: marketing video, brand design, tokenomics, DefiLlama research, ecosystem catalogs | `bash .claude/bin/skills.sh add solana-new` | | sign-safe | Reviewing a transaction before it is signed: decode an opaque base64 tx, SIGN/HOLD/REJECT verdict, gating an agent's signing, Squads proposal review | `bash .claude/bin/skills.sh add sign-safe` | | counterparty-gate | Vetting who operates a program, oracle, keeper or multisig before integrating (sends the addresses you ask about to SolSentry's API) | `bash .claude/bin/skills.sh add counterparty-gate` | | community-moderation | Moderating a Telegram or Discord community and running member support: spam and drainer links, raids, impersonation, ticket triage | `bash .claude/bin/skills.sh add community-moderation` | | content-gen-skill | Writing educational content: a course or curriculum, tutorial, explainer, essay, litepaper, slide spec or thread | `bash .claude/bin/skills.sh add content-gen-skill` | | writer-style-skill | Writing prose in a named author's voice, or building a voice pack; content-gen hands it the brief | `bash .claude/bin/skills.sh add writer-style-skill` | | obsidian-skills | An Obsidian vault as the notes layer: Obsidian Markdown, Bases query views, JSON Canvas, the `obsidian` CLI, Defuddle web-to-Markdown — vault-write and local-exec (see its registry `safety`) | `bash .claude/bin/skills.sh add obsidian-skills` | | huggingface-skills | Building an AI/LLM feature beside the program: the `hf` CLI and Hub, Gradio and Spaces, ZeroGPU, fine-tuning (TRL, sentence-transformers, LoRA), evals, transformers.js, SageMaker deploys — the one machinery pack (see its registry `safety`) | `bash .claude/bin/skills.sh add huggingface-skills` | ## Add-ons [skill-registry.json](skill-registry.json) records each pack's tier, triggers, license and source. Its entries without a tier are opt-in skill packs, plugins, template repos and catalogs the kit doesn't pin; install one only when the user asks and `safe-ai-skill add skill|mcp ` returns `proceed: true`. It lists no MCP servers, because nothing here installs one: the default servers are in `.mcp.json` and the opt-in ones are commands `/setup-mcp` prints for the user to run. [skill-packs](skill-packs/SKILL.md) indexes the useful entries by the work they suit (design, animation, iOS simulator, data visualization), so you don't have to read the whole registry to find one. Wider ecosystem catalogs: [ext/solana-new/cli/data/](ext/solana-new/cli/data/) (install: `bash .claude/bin/skills.sh add solana-new`).