Use when planning, coordinating, or reviewing evidence-first security code audits, vulnerability hunting, scanner triage, exploitability review, or report verification across a…
Comprehensive security audit with evidence-based findings. Combines deep pattern knowledge with contextual reasoning to eliminate false positives.
US stocks analysis by an adversarial investment committee. Legendary-investor personas independently research a thesis, attack each other's cases against a shared evidence ledger…
Use when turning internal/external situation analysis into strategic options with SWOT and TOWS: strengths, weaknesses, opportunities, threats, evidence quality, SO/WO/ST/WT…
Provider-neutral onboarding protocol for a new, rebuilt, or replacement workstation. It establishes the operating-system prerequisites, agent runtimes, shared rule surfaces,…
Manage Tencent Cloud EdgeOne (CDN + edge security). Use when the user asks to: list zones, purge CDN cache (URL / prefix / hostname / all), prefetch URLs to warm edges, check…
Use any time someone asks for a thermonuclear review or a thorough/intense code review of a PR or some changes.
Search and retrieve clinical practice guidelines across 12+ authoritative sources including NICE, WHO, ADA, AHA/ACC, NCCN, SIGN, CPIC, CMA, CTFPHC, GIN, MAGICapp, PubMed,…
Draft a professional Hebrew letter for an Israeli traffic-ticket appeal — בקשה לביטול דו"ח or בקשה להישפט. Respectful tone, factual claims only, evidence list, requested remedy.
Guide live digital-forensics and incident-response work with human approval gates when the job is evidence review and triage, not general MCP setup.
Drafts Evidence of UCC Lien Release documents proving termination of security interests perfected under the Uniform Commercial Code.
FINRA Broker-Dealer Cybersecurity Guidance expert. Stub-depth framework plugin that routes to the SCF crosswalk.
Prüft Software als Trade Secret nach US-Recht: secrecy measures, misappropriation, employee mobility und repository evidence im Softwarerecht De Eu Us.
Use installed Objective-See macOS security tools as thin evidence adapters. Use for KnockKnock persistence inventory, BlockBlock persistence alerts, LuLu network decisions,…
Use when targeting USENIX Security Symposium (USENIX Security) or deciding whether a computer-science manuscript fits this venue.
Use when deciding whether a project belongs at the USENIX Security Symposium or a sibling venue — routing among USENIX Security, IEEE S&P, ACM CCS, NDSS, and specialty venues…
15-agent hierarchical mesh coordination for v3 implementation. Orchestrates parallel execution across security, core, and integration domains following 10 ADRs with 14-week…
Run a third-party / vendor security review and assign a risk tier with required controls. Use when asked to assess a vendor's security, run a third-party risk assessment, complete…
Гейты качества перед delivery: тесты, lint (ruff/ESLint v9/Biome), types (pyright), LSP, browser/security/design.
Verify whether an online bounty, freelance task, agent marketplace job, hackathon prize, or crypto work offer is actually open, accessible, and credibly funded.
Use when the user asks VibePro to check UI, security, performance, architecture, PR readiness, launch readiness, or performance improvement evidence.
Builds a deterministic, reproducible proof-of-concept for a suspected vulnerability before writing a finding — eliminating false positives and producing airtight evidence.
Prepare an evidence-bound vulnerability publication and publish the exact approved advisory through Runx Connect with independent provider readback.
Turn one confirmed security finding into a disclosure-ready GitHub advisory with root cause, proof of concept, impact, and source evidence.
Evaluate delegated-wallet, embedded-wallet, or agent-signer policy evidence without sharing credentials or raw provider payloads.
3-wave parallel audit — Wave 1 discovery (4 agents), Wave 2 verification (4 agents), Wave 3 cross-optimization (1 synthesizer). Each wave runs agents in parallel.
Explore an authorized URL with headless Chrome DevTools/CDP, build a bounded SPA state-and-action graph, capture and classify browser traffic, optionally harvest browser-loaded…
Gather security intelligence for Proteus hypotheses: expected behavior, public-known status, advisories, changelogs, issues, PRs, docs, tests, affected-version timeline, duplicate…
Use for cold-start, time-boxed, multi-axis audits of unfamiliar codebases — take-home assessments, post-acquisition or due-diligence reviews, inherited-service onboarding,…
Use when results may be sensitive — to specification, sample, measurement, or inference for quantitative work, or to interpretation and triangulation for qualitative work — in a…
Triages WordPress availability, integrity, performance, and suspected-security incidents while stabilizing service, preserving evidence, controlling changes, restoring safely, and…
Use this skill when investigating events in the ThreatLocker Action Log (the API name is "audit") — building incident timelines, tracing a file's history across endpoints,…
Read-only audit of a project's third-party dependencies — lockfile discipline, hallucinated and typosquatted package names (slopsquatting), dependency confusion, install-script…
Knowledge engine over the Colombian Truth Commission (CEV) final report "Hay Futuro Si Hay Verdad" (2022) — the findings, statistics, armed-actor responsibilities, differential…
Translate technical threat scenarios into standardized controls and regulatory requirements, covering NIST 800-53, MITRE ATT&CK, SOC 2, and automated control-gap analysis.
A Cursor Canvas is a live React app (.canvas.tsx) that the user can open beside the chat. Use a canvas when the agent produces a standalone analytical artifact — quantitative…
Reconstruct attack timelines through deep data recovery and log correlation, covering deleted-file recovery, memory-dump analysis, registry and shellbag forensics, and…
Check whether the claims in public-facing documentation (README, release notes, install/usage docs) are supported by the evidence the user provides — files, manifests, logs, and…
Analyzes SQL Server ERRORLOG files for operational issues, availability group failures, memory pressure, I/O subsystem warnings, and security events.
Apply structured critical thinking — identifying claims, evidence, reasoning chains, hidden assumptions, and logical fallacies — to evaluate or construct specific written…
Run a structured check on whether an image or video is AI-generated, digitally manipulated, or authentic-but-miscaptioned, and produce a sourced verdict with a confidence level.
Use this skill when converting Kujo audit findings, drift reports, release blockers, DocGen gaps, Dependabot/security triage, or recurring automation output into fix-ready backlog…
Use this skill when working with SentinelOne XSPM misconfigurations - cloud security posture management across AWS, Azure, GCP, Kubernetes, identity, and infrastructure-as-code.
Analyze source for vulnerabilities and non-conformance to MISRA and AUTOSAR safety coding standards. Use this skill whenever the user mentions misra, autosar, coding standard,…
> Use this skill whenever asked about Netherlands cryptocurrency or digital asset taxation. Trigger on phrases like \"crypto tax Netherlands\", \"Bitcoin Netherlands\", \"crypto…
A skill that runs a GAP ANALYSIS & feedback review of an existing project through a multi-agent harness instead of a single review pass.
A skill that runs a GAP ANALYSIS & feedback review of an existing project through a multi-agent harness (enhanced variant: GPT-5.5 cross-model adversarial confirmation) — from…
Use this skill to rate, audit, grade, stress-test, red-team, or issue a ship/no-ship verdict on a vibe-coded, AI-built, prototype, or MVP app, repository, or live deployment.
Use this skill to rate, audit, stress-test, red-team, or issue a ship/no-ship verdict on a concrete API, worker, realtime service, data pipeline, backend repository, or server…
Score a documentation package against the ten-dimension weighted rubric in `references/scorecard-rubric.md` with a cited justification per dimension, then evaluate the eighteen…
Special Court for Sierra Leone (SCSL, 2002-2013) and the Residual Special Court for Sierra Leone (RSCSL, 2013-) research, drafting, and analysis.
This skill designs and runs the security awareness training programme for all employees. Use when asked to create security training, run phishing simulations, or track training…
Assess and govern security-sensitive changes by identifying trust boundaries, secrets, privileges, untrusted execution, dependency/provenance risk, network/data exposure, insecure…
Extends Capability Evolver with verification, rollback, and promotion gating. Use when an agent logs a learning, proposes a self-improvement, or wants to promote a learning to…
Special Tribunal for Lebanon (STL / TSL — Tribunal Spécial pour le Liban) research, drafting, and analysis.