Audit local git history to identify commits that likely fixed vulnerabilities, infer the underlying bug from the diff, turn those patches into a reusable bug-fix reference set,…
Investigate GitHub security incidents using tamper-proof GitHub Archive data via BigQuery. Use when verifying repository activity claims, recovering deleted…
Generate, export, load, and verify forensic evidence from GitHub sources. Use when creating verifiable evidence objects from GitHub API, GH Archive, Wayback Machine, local git…
Agent skill for safe, dry-run-first, deduplicated, root-cause-consolidated, evidence-validated, and secret-redacted logging of repository execution friction into GitHub Issues.
A multifaceted OSINT and forensics tool for GitHub repositories that detects fake stargazers, tampered commits, infected releases, leaked PGP keys, and suspicious contributor…
Elite U.S. corporate + commercial-litigation lawyer persona with a Florida specialty. Use for: reviewing/ drafting loan, financing, secured-lending, M&A and entity-governance…
Elite FBI/forensic-investigator + financial-crimes (Fintech) division case-builder. Connects dots across large evidence sets (chats, bank records, PDFs, contracts), uncovers…
GPAI Code of Practice und Evidence-Logik: Copyright-Policy, Safety/Security, systemisches Risiko, Modellinformationen für Downstream-Anbieter, Standards-Uebergang und Nac — from…
GPAI Code of Practice und Evidence-Logik: Copyright-Policy, Safety/Security, systemisches Risiko, Modellinformationen für Downstream-Anbieter, Standards-Uebergang und Nac — from…
Use when creating a draw.io diagram for audit planning, request lists, evidence, testing, exceptions, remediation, and reporting in a GRC, security, audit, compliance, privacy,…
Use when creating a draw.io diagram for controls mapped across frameworks, systems, owners, risks, and evidence sources in a GRC, security, audit, compliance, privacy, cloud, or…
Use when creating a draw.io diagram for evidence collection, evidence lifecycle, audit evidence pipelines, and systems of record in a GRC, security, audit, compliance, privacy,…
Use when creating a draw.io diagram for cloud/SaaS shared responsibility, inherited controls, provider controls, customer controls, and evidence ownership in a GRC, security,…
Audit distributed systems where the highest-impact findings live between the components, not inside any one of them.
Use when a vulnerability is reported from OUTSIDE the team (a security researcher, a user, a bug bounty, an embargoed upstream CVE) — triage it without shooting the messenger,…
Audit the health of an AI-coding harness — the CLAUDE.md / AGENTS.md files, rules, skills, agents, hooks, and commands that steer an agent in a repository — across four questions…
Govern Huawei Cloud SWR (Software Repository for Container) — image retention policy, vulnerability scanning via VSS (Vulnerability Scan Service) integration, namespace permission…
Use when targeting IACR Conference on Cryptographic Hardware and Embedded Systems (CHES) or deciding whether a computer-science manuscript fits this venue.
Use when revising an IEEE ICSME paper for a maintenance/evolution contribution stated on the first page, research-question contracts, a threats-to-validity section that argues…
Use when targeting IEEE Symposium on Security and Privacy (IEEE S&P) or deciding whether a computer-science manuscript fits this venue.
Use when hardening the reproducibility of an IEEE S&P (Oakland) paper's evidence before submission, including environment pinning for exploits and side channels, seed and trial…
Internationales Handelsrecht und Lex Mercatoria: Arbitration Evidence. Geführter Spezialskill mit Quellenlogik, Prüfroutine, Red-Team-Fragen und verwertbarem Output.
Internationales Handelsrecht und Lex Mercatoria: Trade Custom Evidence. Geführter Spezialskill mit Quellenlogik, Prüfroutine, Red-Team-Fragen und verwertbarem Output.
Use when handoff details could create delivery, security, integration, data, timeline, or expectation risk for implementation.
Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.
Configure AIDE (Advanced Intrusion Detection Environment) for file integrity monitoring including baseline creation,
Structure and record a cybersecurity incident materiality determination, and run the disclosure clocks that follow from it.
Use when user needs security incident response, operational incident management, evidence collection, forensic analysis, or coordinated response for outages and breaches.
Use when a task needs the judgment of an Information Security Analyst — triaging and investigating a security alert or suspected intrusion, designing or tuning detection rules and…
Correlate suspicious macOS process, file, network, permission, and log activity. Use for unexpected processes, child execution, downloads, open files, DNS/connections, privacy…
Use when targeting International Symposium on Research in Attacks, Intrusions and Defenses (RAID) or deciding whether a computer-science manuscript fits this venue.
Grade investment claims for stocks, ETFs, crypto, and macro using a fail-closed verdict ladder. Use when the user asks whether to buy/sell/hold, wants a second opinion on a…
Produce an evidence-linked investment decision with an explicit bull case, opposing bear case, thesis invalidation conditions, bounded action, and reconciled order/FX amounts.
Audit IONOS Cloud security and compliance posture covering GDPR data residency and data sovereignty, ISO 27001 control alignment, encryption at rest and in transit, private LAN…
Endpoint visibility, digital forensics, and incident response using Velociraptor Query Language (VQL) for evidence collection and threat hunting at scale.
Verify whether an image or video is authentic, original and correctly captioned — provenance checks, error level analysis, noise and JPEG compression analysis, clone and copy-move…
Use when judging whether a research question fits the Journal of Financial and Quantitative Analysis (JFQA) — empirical and quantitative financial economics (corporate finance,…
Use when a Journal of Risk and Uncertainty (JRU) result may be sensitive to specification, incentive frame, sample, or inference.
Recover and continue after an interruption — rate limit, crash, disconnect, or gap — or when live off-thread work looks stalled and you are asked to check on it.
Use when operating or maintaining Dossier evidence ledgers: claims, sources, captured support, evidence classification, conflicts, quotations, consent, rights, freshness,…
Produce or audit one cross-domain launch admission verdict for an app, game, SaaS, desktop product, developer tool, marketplace, major release, beta, or campaign.
Use when determining the amount of alimony under Polish KRO — calculating justified needs of the entitled person vs. earning/property capacity of the obligor (art.
Incident triage skill for security-event classification, containment planning, evidence preservation, and response coordination.
Analyze system, application, and security logs for forensic investigation. Use when investigating security incidents, insider threats, system compromises, or any scenario…
Investigate Salesforce login activity using LoginHistory, IdentityVerificationHistory, and Login Forensics (Event Monitoring add-on): reconstruct per-user login timelines,…
Run adversarial review. Use for PR/diff/code/security/UX/API/performance/design review, or when behavior, records, evidence, risks, or acceptance claims need pressure-testing…
Route security-sensitive work before implementation. Use when authentication, authorization, user input, secrets, sensitive data, uploads, webhooks, external integrations,…
Build and run a third-party / vendor risk management (TPRM) program aligned to NIST SP 800-161 C-SCRM and NIST CSF 2.0 GV.SC: inventory and tier vendors by risk, send the right…
Use when administering a Synapse / Matrix homeserver — list or snapshot all rooms, rate room health (public, unencrypted, orphaned), render a Graphviz map of the room/space tree,…
Run a safe automated MCP configuration security preflight while keeping raw scanner evidence out of model-facing output. Use before installing or approving an MCP server.
Comprehensive techniques for acquiring, analyzing, and extracting artifacts from memory dumps for incident response and malware analysis.
Use when Mission Control should recommend a read-only handoff audit burst for run instructions, validation evidence, limitations, docs quality, and security caveats.
Prepare a project for release through Mission Control. Use when validation, docs, versioning, changelog, limitations, evidence, deployment readiness, and security concerns need…
Mobile device intelligence — Android/iOS app analysis, mobile forensics, emulators, messaging app reconnaissance, and device fingerprinting.
Use after Molecular Cell reviews arrive to triage the decision, prioritize the (often mechanism-completing) new experiments by impact × feasibility, and draft a point-by-point…
Use when writing an NDSS rebuttal and working the interactive discussion phase — triaging Round-2 reviews under a short window, answering adaptive-attack and ethics objections…
Use when targeting Network and Distributed System Security Symposium (NDSS) or deciding whether a computer-science manuscript fits this venue.
Analyze network traffic for defensive triage and operate the local defense-focused plugin runtime for PCAP forensics, live capture review, incident prioritization, posture…
Assess non-functional requirements across 6 quality categories (Security, Performance, Reliability, Maintainability, Scalability, Usability) with measurable criteria,…
EU NIS2 Directive (Directive (EU) 2022/2555) compliance advisor for essential and important entities — entity classification, Art. 21 risk management measures, Art.