A curated set of Claude Code skills extracted from a decade of running FinTech infrastructure, trading platforms, and broker-side systems in production.
Each skill is a single Markdown file with a YAML front-matter that Claude Code (and other agentic environments) can auto-discover. Drop them into your ~/.claude/commands/ (global) or .claude/commands/ (per project) and Claude will use them whenever the context matches.
Generic LLM advice on financial markets, network gear, or broker-grade infra is rarely good enough. These skills capture the things that:
- only show up in production (the third WebSocket trap, the third Wednesday rule, the BPIPE-vs-BLPAPI cost cliff)
- are obvious once you've been burned but invisible from any tutorial
- get reused across multiple projects and would be tedious to re-explain to a fresh assistant context
| Skill | What it covers |
|---|---|
financial-dates |
IMM dates, FRA tenors, forward-forward swaps, business calendar, spread combinatorics |
bloomberg-data |
BDP / BDS / BLPAPI / BPIPE / add-in, ZAR IRS tickers, DV01 nominal conversion |
imm-date-rolling |
IMM convention parsing (Sept vs Sep), resolved-to-relative mapping, rotation pitfalls |
zar-irs-finance |
Spreads in basis points, DV01 / PV01, USD-to-ZAR nominal, ZARONIA OIS, butterflies |
bloomberg-fix-mpf |
FIX 5.0 SP2 contributor (Logon, Heartbeat, SetupMonitorRequest, MarketDataIncrementalRefresh), TLS mutual auth, dual-DC failover, seven recurrent pitfalls |
| Skill | What it covers |
|---|---|
proxmox-ct-setup |
LXC container sizing by workload, base setup, runtime install, systemd hardening |
lxc-troubleshoot |
The nine recurrent LXC pitfalls and their fixes (gateway, DNS, apt sandbox, venv AppArmor, PostgreSQL, systemd-in-LXC) |
ssh-ct-patches |
Safe patterns for patching code on remote LXC via ssh + pct exec without bash eating template literals |
samba-share-setup |
Samba / CIFS share for external file ingestion (vendor add-ins, Windows workstations), AD Kerberos + local fallback auth, seven pitfalls |
pve-cluster-join |
Join a new node to a Proxmox VE cluster: the four traps (TFA on root, SSH keys, /etc/hosts, SSH config) |
| Skill | What it covers |
|---|---|
nginx-websocket |
The three classic WebSocket reverse-proxy traps (HTTP/2, hardcoded Connection header, default timeouts) and a tested vhost template |
cisco-port-trace-device |
Identify the device behind a switch port: MAC + CDP / LLDP + ARP + DHCP |
vpn-debug |
Systematic debugging of an IPsec / IKEv2 tunnel on Palo Alto (proxy-IDs, SAs, routes, security rules, IKE logs) |
ssl-setup |
HTTPS setup with Let's Encrypt / self-signed / commercial, Caddy + nginx templates, expiry monitoring |
| Skill | What it covers |
|---|---|
auth-token-decode |
Decode a JWT by hand (base64 + json), diagnose aud / iss / exp / scopes, distinguish Entra ID ID token vs access token vs Graph token |
msal-entra-patterns |
MSAL.js v4 + React + FastAPI patterns for Microsoft Entra ID (JWT validation server-side, role-based access, WebSocket auth) |
gap-analysis-response-pattern |
Strategic playbook for responding to a loaded external gap analysis or audit: refuse the framing, separate the axes, require an external legal opinion |
| Skill | What it covers |
|---|---|
prometheus-add-target |
Add a host to Prometheus + Grafana with node_exporter, ICMP blackbox probe, dashboard host-count update, hot reload via SIGHUP |
wazuh-agent-enroll |
Enrol a Wazuh agent with password authentication, version pinning, group assignment, six recurrent enrolment pitfalls |
| Skill | What it covers |
|---|---|
jitsi-post-upgrade |
Fix the five recurring bugs that break Jitsi Meet after apt upgrade jitsi-meet |
yealink-provisioning |
Provision Yealink phones (T87W, W70B DECT) against FreePBX / Asterisk: manual + EPM, DECT pairing, eight registration pitfalls |
| Skill | What it covers |
|---|---|
react-hooks-discipline |
Hooks before early returns, defensive rendering for async data, stable list keys, useEffect cleanup, Map / Set state instances |
| Skill | What it covers |
|---|---|
kafka-integration |
Cluster shape, SCRAM-SHA-512 auth, topic naming, Python consumer / producer, audit feeds, monitoring |
database-design |
Tech choice cheat sheet, naming conventions, reference DDL for a matching platform, audit trail trigger, migration discipline |
redis-integration |
LXC deployment, ACL auth, key layout, versioned caching, pub-sub fan-out, webhook dedup, distributed locks, rate limits, seven pitfalls |
Pick the skills you want and copy them to your skills directory:
git clone https://github.com/angieruiz17/claude-fintech-skills.git
cp claude-fintech-skills/trading/financial-dates.md ~/.claude/commands/
cp claude-fintech-skills/network/nginx-websocket.md ~/.claude/commands/Or symlink the whole directory:
ln -s "$PWD/claude-fintech-skills" ~/.claude/skills-fintech-opsClaude Code (and compatible agents) read the YAML front-matter (name, description) to decide when a skill is relevant.
Every file is also readable on its own. Browse the directories above for production-grade notes on the matching topics.
Issues and pull requests are welcome, especially if you spot a production caveat that should be flagged in one of the skills.
Skill format:
- Markdown with YAML front-matter (
name,description) - Self-contained, no cross-skill imports
- "When to use" section near the top, so Claude can match context fast
- Code blocks tagged with their language for highlighting
- No company-specific IPs, hostnames, or credentials
MIT. See LICENSE.
Curated by Farid Said, Head of IT at an institutional broker. Builds trading infrastructure, network and security, and FinTech tooling for over a decade.