Assemble the grab-and-go document and information kit for a disaster — the IDs, insurance, medical, financial, and property records (physical copies + secure digital backups)…
Use when a task needs the judgment of an Emergency Management Director — activating and staffing an EOC for a developing hazard, sequencing a disaster declaration and FEMA Public…
Recover from developer disasters. Use when someone force-pushed to main, leaked credentials in git, ran out of disk space, killed the wrong process, corrupted a database, broke a…
Audit an emergency resource management system for crisis readiness. Evaluates inventory tracking accuracy, deployment request-to-arrival pipeline, logistics and route…
API de Emissores de Etiqueta da Tray. Utilize quando o desenvolvedor precisar integrar geração de etiquetas de envio, cadastrando URLs de etiqueta e vinculando-as a pedidos.
API de Endereços de Clientes da Tray. Utilize quando o desenvolvedor precisar gerenciar os endereços cadastrados dos clientes, incluindo listagem, consulta individual, criação e…
Install guardrails-as-code into a repo so AI/vibe-coding can't keep reintroducing the same classes of problems (leaked secrets, injection, off-system styles, untested code,…
Env Secret Detector - Auto-activating skill for Security Fundamentals. Triggers on: env secret detector, env secret detector Part of the Security Fundamentals skill category.
Security-focused pull request and diff review skill for finding newly introduced vulnerabilities, risky regressions, and missing security tests in changed code.
Security remediation skill for fixing confirmed or likely SAST findings in source code. Trigger when the user asks to: "fix a vulnerability", "patch this security bug", "remediate…
General-purpose Static Application Security Testing (SAST) skill for code vulnerability analysis. Trigger when the user asks to: "analyze code for vulnerabilities", "review code…
Threat modeling skill for new features, services, endpoints, or repositories. Trigger when the user asks to: "threat model this", "analyze attack surface", "find abuse cases",…
Audit exact npm dependency versions against OSV and emit a reproducible evidence packet with zero unverified findings.
Guide the design and management of trading venue connectivity and market data infrastructure. Owns the FIX session layer (logon, heartbeats, sequence number gaps, resend and gap…
Create Harness STO security exemptions (waivers) for vulnerabilities found by SAST, SCA, DAST, secret, container, or IaC scanners.
Set up an active-passive failover gateway for OpenClaw. Deploy a standby node that auto-promotes when your primary goes down and auto-demotes when it recovers.
Comprehensive family emergency preparedness planning. Use when someone wants to create a household emergency plan, prepare for natural disasters, build a go-bag, or ensure their…
Fix all guardrail findings (make lint, make test, make sast) across repositories. Use when the user asks to fix linting errors, test failures, SAST findings, or run the full…
Fast high-dimensional fixed effects in R: feols/fepois/feglm/fenegbin with multi-way FE; IV estimation; DiD (TWFE, Sun-Abraham via sunab); clustered/ heteroskedasticity-robust…
Mapa canônico do fluxo de uma cotação até a ativação do associado neste projeto (Praticcar). Use ao mexer em qualquer etapa entre criação da cotação e ativação — link público,…
Advanced fuzzing techniques for finding zero-days and hidden vulnerabilities. Use when automated scanners miss
Essential fuzzing payloads: SQL injection, command injection, special characters. Curated essentials for vulnerability testing.
Configure perform API fuzzing to discover edge cases, crashes, and security vulnerabilities. Use when performing specialized testing.
Configure perform API fuzzing to discover edge cases, crashes, and security vulnerabilities. Use when performing specialized testing.
Building effective fuzzing harnesses to maximize code coverage and vulnerability discovery through automated input generation
Generate a CVE 5.x JSON document from an tracking issue, ready to paste into the Vulnogram `#source` tab of the ASF CVE tool at…
[FREE — public data, free API key required] Environmental disaster and hazard data -- GDACS disaster alerts, USGS earthquakes, NASA FIRMS fire detection, NASA EONET natural events
Gitleaks is an open-source SAST tool for detecting hardcoded secrets like passwords, API keys, and tokens in Git repositories, files, and directories.
Configures GKE Backup Plans and restore workflows. Use for backup policies, disaster recovery, or GKE cluster restores. Don't use for database backups.
Improves GKE workload reliability, using PDBs, health probes, and topology spread constraints. Use when configuring GKE workload reliability, setting up PDBs, or configuring GKE…
Apply Go project conventions — Go 1.25.x toolchain pinned via toolchain directive and GOTOOLCHAIN=local, vendored deps via go mod vendor, golangci-lint v2 strict (~50 enabled…
Scan container images, filesystems, and SBOMs for known vulnerabilities using Anchore Grype. Supports major OS package ecosystems and language-specific packages with EPSS risk…
Design backups that actually work when they are needed. Covers RPO and RTO definition, the 3-2-1 rule, encryption before leaving the host, ransomware-resistant immutable storage,…
Draft and file a security vulnerability report to a HackerOne bug-bounty program through the browser, and prepare its PoC package + a concise copy-paste README for a user-filmed…
Runs the HawkScan DAST security loop — configure, scan, fix all reported vulnerabilities (not just your changes), rescan to verify.
Figure out which disasters and emergencies your specific location actually faces — and the concrete prep each one demands — so your readiness targets real risks instead of generic…
Help HR and business leaders plan for and respond to workforce crises — layoffs handled poorly, safety incidents, natural disasters, leadership scandals, or sudden business…
Hunt CI/CD pipeline vulnerabilities — GitHub Actions workflow injection (pull_request_target Pwnrequest + ${{ }}-into-shell), self-hosted runner poisoning, OIDC trust-policy…
Hunt gRPC vulnerabilities — server reflection enabled (enumerate all services/methods), missing authentication / metadata-stripping on internal endpoints, plaintext gRPC over…
Hunt Spring Boot specific vulnerabilities — Actuator endpoints (heapdump, env, loggers, mappings, shutdown), Spring Expression Language (SpEL) injection → RCE, H2 console RCE,…
Infrastructure as Code (IaC) security scanning using Checkov with 750+ built-in policies for Terraform, CloudFormation, Kubernetes, Dockerfile, and ARM templates.
Terraform / Pulumi / CloudFormation review — state management, module contract, plan output, drift detection, security scan (tfsec/checkov/OPA), cost diff (Infracost).
Scans Infrastructure as Code for security misconfigurations. Wraps tfsec for Terraform and Checkov for multi-cloud IaC.
Provides comprehensive IBM Mainframe administration, development, and modernization guidance including z/OS operations, JCL scripting, COBOL/PL/I programming, CICS/IMS…
Integrate FIRST's Exploit Prediction Scoring System (EPSS) API to prioritize vulnerability remediation based
Deploy and configure Rapid7 InsightVM Security Console and Scan Engines for authenticated and unauthenticated
Write custom Semgrep SAST rules in YAML to detect application-specific vulnerabilities, enforce coding standards,
Deploy and operate Greenbone/OpenVAS vulnerability management using the python-gvm library to create scan targets,
Vulnerability remediation SLAs define mandatory timeframes for patching or mitigating identified vulnerabilities
Build automated alerting for vulnerability remediation SLA breaches with severity-based timelines, escalation
Scan for reports that have not yet been copied into as tracking issues, present the proposed imports to the user, and — defaulting to *import un — from…
Use when the user mentions infrastructure, cloud, AWS, GCP, Terraform, deployment, DevOps, containers, Kubernetes, serverless, VPC, networking, databases, load balancers, CDN,…
Check JFrog Public Catalog and stored packages for a version, interpret catalog security signals, and download through Artifactory (JFrog Platform locations, remote cache,…
Backup, restore, and manage encrypted snapshots of OpenClaw agent data via the Keep My Claw API. Use when backing up agent configuration, workspace files, and credentials;…
KLIC & WIBON expert skill voor Nederland. Beantwoord vragen over graafmeldingen, kabels & leidingen, Kadaster en WIBON-wetgeving.
Audits project dependencies for vulnerabilities. Multi-ecosystem support (npm, .NET, Python, Go). CVSS-based severity classification.
Esta skill deve ser usada quando o usuário solicitar candidaturas automáticas em vagas do LinkedIn relacionadas a Inteligência Artificial (IA) no Brasil, priorizando vaga — from…
Esta skill deve ser usada quando o usuário solicitar candidaturas automáticas em vagas do LinkedIn relacionadas a Inteligência Artificial (IA) no Brasil, priorizando vaga — from…
Checks outdated packages, unused deps, reinvented wheels, CVE/CVSS vulnerability scan. Use when auditing dependencies. — from security/appsec-tools
Checks outdated packages, unused deps, reinvented wheels, CVE/CVSS vulnerability scan. Use when auditing dependencies. — from majiayu000/claude-skill-registry