Startup crisis management operating system covering 14 crisis types with severity scoring, escalation matrices, war room protocols, stakeholder communication playbooks, runway…
Designs cloud architectures, creates migration plans, generates cost optimization recommendations, and produces disaster recovery strategies across AWS, Azure, and GCP.
Identifies security vulnerabilities, generates structured audit reports with severity ratings, and provides actionable remediation guidance.
Expert methodology for identifying, assessing, and mitigating technical and operational risks including security, incidents, compliance, and disaster recovery.
Audit exact npm dependency versions against OSV through Runx native HTTP and emit replay-verified evidence with no unverified findings.
CVE research, standalone PoC script and report generation. Given a CVE ID, researches NVD and advisories, generates a safe Python PoC, and writes a detailed vulnerability report.
Remediate dependency vulnerability scanner failures by verifying live package registry data and upgrading instead of suppressing.
Searches the NIST NVD database for CVE vulnerabilities using API 2.0. Returns CVE details, CVSS scores, affected software, and references.
Эксперт CVE tracking. Используй для vulnerability management, security advisories и patch prioritization.
Look up CVE vulnerability details by ID via MITRE CVE API with NVD fallback — severity, CVSS score, affected products, and references
Score a vulnerability with CVSS v3.1: derive the base metric vector, compute the score and severity rating, and explain each metric choice.
Computes an exact CVSS v3.1 base score and vector from a vulnerability description. Infers metrics from context, picks the most accurate score when info is sufficient, and asks…
Fast web fuzzer for DAST testing with directory enumeration, parameter fuzzing, and virtual host discovery.
Fast, template-based vulnerability scanning using ProjectDiscovery's Nuclei with extensive community templates covering CVEs, OWASP Top 10, misconfigurations, and security issues…
Dynamic Application Security Testing with two tiers: Nuclei (fast, template-based) and ZAP (deep, active scanning via Docker).
Dynamic Application Security Testing execution and management. Configure and execute OWASP ZAP and Nuclei scans, run authenticated scanning, manage scan policies and scope,…
Dynamic application security testing (DAST) using OWASP ZAP (Zed Attack Proxy) with passive and active scanning, API testing, and OWASP Top 10 vulnerability detection.
Implement reliable data backup and recovery strategies with automated scheduling, encryption, rotation policies, and disaster recovery testing.
Set up database replication for high availability and disaster recovery. Use when configuring master-slave replication, multi-master setups, or replication monitoring.
Expert database administrator specializing in modern cloud databases, automation, and reliability engineering.
Implement backup and restore strategies for disaster recovery. Use when creating backup plans, testing restore procedures, or setting up automated backups.
Audit locked npm dependencies against OSV advisories and emit exact-version CVE evidence.
Dependency Vulnerability Checker - Auto-activating skill for Security Fundamentals. Triggers on: dependency vulnerability checker, dependency vulnerability checker Part of the…
Scans project dependencies using OSV.dev API and Snyk CLI for known CVEs across npm, PyPI, Maven, and Go modules. Generates SBOM in CycloneDX format via syft.
Turns npm audit/Snyk results into prioritized patch plans with severity assessment, safe upgrade paths, breaking change analysis, and rollback strategies.
Dependency-upgrade campaign — outdated scan, batch-by-severity, breaking-change remediation, lockfile audit.
Designs and validates backup, point-in-time-recovery, and disaster-recovery strategy for datastores — sets RPO/RTO targets, configures snapshot plus continuous WAL/binlog/oplog…
Use when analyzing user journeys, auditing UX quality, prototyping flows, or designing new pages/features from a product perspective.
Analyse et évalue les vulnérabilités d'un système ou d'une application. À utiliser pour comprendre et prioriser les vulnérabilités.
Analyze disaster prediction and early warning systems — model accuracy for flood, earthquake, wildfire, hurricane, and tsunami hazards, data pipeline reliability from sensor…
Implement disaster recovery and backup strategies for Proxmox. Create and manage backups, test recovery procedures, and ensure business continuity for your infrastructure.
Use when designing, scheduling, or running a disaster recovery exercise — tabletops, live drills, chaos engineering, GameDays.
Write a disaster recovery plan for a service or system — covering RPO/RTO targets, failure scenario runbooks, backup and restore procedures, DR testing cadence, and communication…
Execute comprehensive disaster recovery tests, validate recovery procedures, and document lessons learned from DR exercises.
Manage DNS records, routing policies, and failover configurations for high availability and disaster recovery.
Runs Trivy against a Docker image and produces a prioritized CVE list grouped by severity with fix availability. Filters out CVEs with no available fix.
Audits Dockerfiles for security vulnerabilities using Hadolint and Trivy container scanner. Recommends hardening steps based on CIS Docker Benchmark and Snyk container advisories.
Crie, revise e mantenha a documentação do projeto Dental System. Use quando Codex precisar atualizar README, guias de instalação, scripts de execução, documentação de API,…
Ensure architecture docs define RPO/RTO, failover paths, data consistency, and DR drillability.
Generate a Disaster Recovery plan with RTO/RPO targets. Use when someone asks to "create a DR plan", "disaster recovery", "business continuity", or "RTO RPO".
Property-based testing and fuzzing using Echidna for smart contracts. Includes invariant definition, corpus management, coverage analysis, and CI/CD integration for comprehensive…
Recover from developer disasters. Use when someone force-pushed to main, leaked credentials in git, ran out of disk space, killed the wrong process, corrupted a database, broke a…
Audit an emergency resource management system for crisis readiness. Evaluates inventory tracking accuracy, deployment request-to-arrival pipeline, logistics and route…
API de Emissores de Etiqueta da Tray. Utilize quando o desenvolvedor precisar integrar geração de etiquetas de envio, cadastrando URLs de etiqueta e vinculando-as a pedidos.
API de Endereços de Clientes da Tray. Utilize quando o desenvolvedor precisar gerenciar os endereços cadastrados dos clientes, incluindo listagem, consulta individual, criação e…
Install guardrails-as-code into a repo so AI/vibe-coding can't keep reintroducing the same classes of problems (leaked secrets, injection, off-system styles, untested code,…
Env Secret Detector - Auto-activating skill for Security Fundamentals. Triggers on: env secret detector, env secret detector Part of the Security Fundamentals skill category.
Security-focused pull request and diff review skill for finding newly introduced vulnerabilities, risky regressions, and missing security tests in changed code.
Security remediation skill for fixing confirmed or likely SAST findings in source code. Trigger when the user asks to: "fix a vulnerability", "patch this security bug", "remediate…
General-purpose Static Application Security Testing (SAST) skill for code vulnerability analysis. Trigger when the user asks to: "analyze code for vulnerabilities", "review code…
Threat modeling skill for new features, services, endpoints, or repositories. Trigger when the user asks to: "threat model this", "analyze attack surface", "find abuse cases",…
Audit exact npm dependency versions against OSV and emit a reproducible evidence packet with zero unverified findings.
Guide the design and management of trading venue connectivity and market data infrastructure. Owns the FIX session layer (logon, heartbeats, sequence number gaps, resend and gap…
Create Harness STO security exemptions (waivers) for vulnerabilities found by SAST, SCA, DAST, secret, container, or IaC scanners.
Comprehensive family emergency preparedness planning. Use when someone wants to create a household emergency plan, prepare for natural disasters, build a go-bag, or ensure their…
Fix all guardrail findings (make lint, make test, make sast) across repositories. Use when the user asks to fix linting errors, test failures, SAST findings, or run the full…
Mapa canônico do fluxo de uma cotação até a ativação do associado neste projeto (Praticcar). Use ao mexer em qualquer etapa entre criação da cotação e ativação — link público,…
Advanced fuzzing techniques for finding zero-days and hidden vulnerabilities. Use when automated scanners miss
Essential fuzzing payloads: SQL injection, command injection, special characters. Curated essentials for vulnerability testing.
Configure perform API fuzzing to discover edge cases, crashes, and security vulnerabilities. Use when performing specialized testing.