Decentralized git for AI agents and humans. Use when the user wants to create repositories, push code, open pull requests, review and merge PRs, manage issues, create or claim…
Plan, create, and configure production-ready Google Kubernetes Engine (GKE) clusters using the golden path Autopilot configuration.
Plans, configures, and hardens platform-level Google Kubernetes Engine (GKE) cluster security. Covers cluster add-ons (Secret Manager enablement), RBAC hardening (disabling…
Plans, configures, and hardens Google Kubernetes Engine (GKE) security. Covers Workload Identity Federation, Secret Manager integration, RBAC hardening, Binary Authorization,…
Audits, configures, and hardens workload-level security controls for Google Kubernetes Engine (GKE) applications and namespaces.
Gmail Inbox Zero Triage - Interactive inbox management using gog CLI with Telegram buttons. Use when the user wants to achieve inbox zero, triage their Gmail inbox interactively,…
GOAD (Game of Active Directory) lab environment — AWS-based Active Directory pentest lab with 1 Ubuntu jumpbox and 5 Windows Server VMs (2 forests, 3 domains).
Step-by-step guide for setting up Google Calendar MCP server in Claude Code CLI. Use when users want to (1) connect Google Calendar to Claude Code, (2) set up the…
Deploys a baseline landing zone foundation for a Google Cloud Organization, establishing security guardrails using Organization Policies, resource hierarchy folders and projects,…
Connect to Google Workspace services (Gmail, Docs, Sheets, Calendar, Drive, Tasks, Slides). Load when user mentions 'connect google', 'setup google', 'configure google', 'google…
Complete Google OAuth integration architecture including token storage and debugging
Export Google Workspace Admin Reports and customer usage evidence with the gws CLI for security reviews, shadow AI detection, OAuth investigation, Drive sharing analysis, login…
Verify Google Workspace OAuth app permissions and scopes with gws, confirm apps are not effectively allow-all, review app access control and domain-wide delegation risk, and…
Build concise weekly Google Workspace security reports from exported Admin Reports and customer usage evidence, including shadow AI OAuth activity, Gemini Workspace usage, Drive…
Review Google Workspace Admin Reports for daily security triage. Use when analyzing Drive sharing, external downloads, risky logins, OAuth/token activity, admin lifecycle changes,…
Receive and authenticate Green Dot Embedded Finance (BaaS) webhooks. Use when setting up a Green Dot partner webhook endpoint, validating the OAuth client_credentials Bearer token…
Implement Guidewire RBAC: API roles, user permissions, and security policies. Trigger: "guidewire enterprise rbac", "enterprise-rbac".
Lock down a Guidewire Cloud API integration so it survives a SOC 2 audit, an NAIC Model Audit Rule review, and a real-world incident — least-privilege role design, encrypted…
Implement Guidewire security: OAuth2 JWT, API roles, Gosu secure coding, and data protection. Trigger: "guidewire security basics", "security-basics".
Harden a Kubernetes cluster's data plane and control plane. Covers Pod Security Standards (Restricted, Baseline, Privileged), RBAC with least privilege, NetworkPolicy…
Quick install of the Google Workspace CLI (gws) on an additional machine using existing OAuth credentials. Requires client_secret.json from a previous gws-setup.
Set up the Google Workspace CLI (gws) from scratch. Guides through GCP project creation, OAuth credentials, authentication, and installing 90+ agent skills for Claude Code.
Manage secrets and PKI with HashiCorp Vault. Configure secret engines, authentication methods, and policies.
BrightTALK weekly-rec process steal: interest-ranked digest of hidden agent-tool-call entry points (PreToolUse unwired, dynamic tools, missing identity).
Hippius decentralized storage on Bittensor Subnet 75 — upload files, query storage, manage buckets via S3-compatible API.
Hongkong-Risikoszenario: National Security Law HK 2020 Auswirkungen auf Geschäft, Rechtsstaatlichkeits-Degradierung HK-Gerichte, Common Law-Restbestand, HKIAC-Schiedsstandort…
Elimina las "señales" estilísticas que hacen que un texto en español parezca escrito por IA (ChatGPT/Claude/Gemini), para que los borradores suenen a una persona concreta con una…
Hunting skill for auth bypass vulnerabilities. Built from 12 public bug bounty reports across SAML XSW / parser-differential (GitHub Enterprise CVE-2025-25291/25292), SAML…
Hunt MFA / 2FA bypass — 7 distinct patterns. (1) MFA not enforced on sensitive endpoints (password change, email change accept without MFA challenge), (2) MFA-step skip via direct…
Hunt NTLM/Negotiate information disclosure on internet-reachable IIS/SharePoint/Exchange. Anonymous NTLM Type-2 challenge capture leaks NetBIOS domain, internal DNS forest,…
Hunting skill for oauth vulnerabilities. Built from 19 public bug bounty reports. Use when hunting oauth on any target.
Hunt SAML / SSO attacks. Patterns: XML Signature Wrapping (XSW) — modify Assertion while keeping Signature valid by relocating signed element, comment injection in NameID…
Hunt Session Management vulnerabilities — session fixation (no regeneration on login), insufficient invalidation on logout / password-change / email-change, predictable or…
Hunt Microsoft SharePoint Server (2013/2016/2019/Subscription Edition) on-prem farms — anonymous endpoint enumeration, version disclosure, legacy SOAP login bypass…
Hunting skill for subdomain takeover vulnerabilities. Includes modern provider fingerprints — Microsoft Azure DevOps `cloudapp.azure.com` regional-pool re-issue (1-click OAuth ATO…
Detects credential stuffing attacks by analyzing authentication logs for login velocity anomalies, ASN diversity,
Detect NTLM relay attacks by analyzing Windows Event 4624 logon type 3 with NTLMSSP authentication, identifying
Hunts for stolen-session and OAuth/PRT token replay (T1550.001) by correlating Microsoft Entra ID SigninLogs SessionId/UniqueTokenIdentifier fields and Okta System Log sso/session…
Structure cloud IAM with role-based access, short-lived credentials, and permission boundaries that hold at scale.
Fetches raw IAM recommendations and associated security insights from Google Cloud for a specified target scope (Organization, Folder, or Project).
AWS IAM(Identity and Access Management)のセキュリティ設計パターン。最小権限の原則に基づく ポリシー設計、IAMロールの構成、クロスアカウントアクセス、条件キーによるアクセス制御、 サービスリンクロール、権限境界(Permissions Boundary)を網羅する。…
Internationales Handelsrecht und Lex Mercatoria: Warentransit Und Gefahruebergang. Geführter Spezialskill mit Quellenlogik, Prüfroutine, Red-Team-Fragen und verwertbarem Output.
Image editing for agents: image-to-image edits, variations, and image-conditioned transforms through Image Skill's zero-setup hosted runtime.
Image-to-3D asset creation for agents through Image Skill's zero-setup hosted runtime. Use when an input image should become a durable hosted 3D mesh asset, such as a glb, without…
Use ImagineVid's OAuth-protected MCP and CLI tools to discover and safely run current image, video, and music generation capabilities.
Implement API threat protection using Google Apigee policies including JSON/XML threat protection, OAuth 2.0,
Implements Delinea Secret Server for privileged access management (PAM) including secret vault configuration,
Implements FIDO2/WebAuthn hardware security key authentication including registration ceremonies, authentication
Implements passwordless authentication using Microsoft Entra ID with FIDO2 security keys, Windows Hello for
Deploy FIDO2/WebAuthn passwordless authentication using security keys and platform authenticators. Covers WebAuthn
Deploy CyberArk Privileged Access Management to discover, vault, rotate, and monitor privileged credentials across
Configure rsyslog for centralized log collection with TLS encryption, custom templates, and log rotation. Generates
Perform Five Forces analysis — competitive rivalry, supplier power, buyer power, threat of substitutes, and threat of new entrants.
WHEN: Infrastructure security audit, secrets management, network policies, compliance checks WHAT: Secrets scanning + Network policies + IAM/RBAC audit + Compliance validation +…
Drafting tool-verified answers to cyber-insurance renewal, new-business, and underwriter security questionnaires: the standard recurring question set (MFA everywhere including…
Integra um banco, instituição de pagamento ou lotérica com a API do Boleto Ringer da Conta Comigo Digital (digitalbank 2.0): login OAuth2, cadastro de pessoa pagadora, webhook de…
Integrates a THIRD-PARTY identity provider via OpenID Connect — "Log in with Google/GitHub/Microsoft/Apple" or acting as an OAuth client to a third-party API.
Use when managing Connected Apps for integration purposes — configuring OAuth policies, IP restrictions, refresh token expiry, and monitoring connected app usage.
Guide for creating new OAuth-based integrations in the Orient codebase. Use when adding external service integrations (APIs like Linear, GitHub, Slack, Notion, etc.), implementing…
Use when designing a reusable integration layer in Salesforce that serves multiple external APIs through a shared callout infrastructure.