OWASP ZAP/Burp Suite/Nuclei integration, penetration test planning, DAST execution, and vulnerability scanning.
Assess a Kubernetes cluster from the attacker viewpoint when an agent needs exposure-focused findings instead of a general cluster scanner listing.
Run automated red-team and failure scans against an LLM or RAG app before users find the breakage.
Run a thorough TLS preflight against a host before launch, certificate renewal, or incident review.
Work with Probo SOC-2 compliance platform via MCP tools. Manage risks, documents (policies), controls, vendors, and evidence.
Handles full PDF lifecycle — extracts text/tables, merges/splits, rotates, watermarks, fills forms, encrypts/decrypts, and OCRs scanned pages.
Processes STIX 2.1 threat intelligence bundles delivered via TAXII 2.1 servers, normalizing objects into platform-native
Procore security basics — construction management platform integration. Use when working with Procore API for project management, RFIs, or submittals.
Audit procurement and procure-to-pay systems for spend analytics (Pareto analysis, tail spend visibility), supplier consolidation opportunities, Kraljic matrix category…
Grounded procurement research for any real-world need. Turn a problem ("reduce bedroom noise from the avenue", "add air conditioning", "hire an accountant", "buy a TV mount",…
Scans repository controls and scripts, not user journeys: access control on request handlers, CI/CD pipeline, structured logging, error tracking, secrets management,…
Route cross-domain production evidence (readiness, migration, recovery, capacity/cost, incident-learning) into a launch or operational decision — go, no-go, defer, exception, or…
Comprehensive pre-deployment validation ensuring code is production-ready. Runs complete audit pipeline, performance benchmarks, security scan, documentation check, and generates…
Ring-standards-aligned production readiness audit across Structure, Security, Operations, Quality, and Infrastructure — 43 base dimensions + 1 conditional (multi-tenant) = up to…
Ultimate production readiness skill that orchestrates all relevant skills (frontend, backend, security, performance, SEO, testing, DevOps) to harden applications before deployment…
Comprehensive system audit methodology for production web applications. Use when auditing systems before launch, identifying technical debt, troubleshooting systematic issues,…
API de Produtos da Tray. Utilize quando o desenvolvedor precisar listar, consultar, cadastrar, atualizar ou excluir produtos no catálogo de uma loja Tray.
6 个专业 Agent:security-reviewer(安全审计)、build-error-resolver(构建修复)、planner(实施规划)、code-reviewer(代码审查)、refactor-cleaner(死代码清理)、doc-updater(文档同步)。源自 everything-claude-code 的专业 Agent…
Professional Review Sheet mit Rollen-, Daten- und Dokumentenperspektive: führt schnell durch Sachverhalt, Rechtsgrundlagen, Belege, Risiken und erzeugt einen verwertbaren — from…
Build a comprehensive competitor profile using Porter's four-component framework. Use when asked to analyze a competitor, predict competitor moves, or assess competitive threats.
Use when authoring or modifying any claude-team-toolkit skill that loads credentials, switches between accounts/orgs/environments, or needs confirmation for destructive…
Develops comprehensive threat actor profiles for APT groups, criminal organizations, and hacktivist collectives
Use for deep Symfony project analysis: kernel/bootstrap, container wiring, routing/request flow, Doctrine, security, Messenger, and Symfony-specific failure patterns.
Run a comprehensive audit on any Claude Code project. Scores 10 categories from 0-10 (total /100), identifies gaps, and generates a prioritized fix kit with copy-pasteable…
Audit an entire software repository for broken code, security vulnerabilities, secrets, dependency risk, architecture problems, backend/API issues, frontend issues, database…
Existing project health scan — audits Infrastructure, Security, Quality, and Harness setup. Read-only.
Turn a design, idea, sketch, brief, or product concept into the simplest feasible project plan spanning design, deployment, security, operations, finance, tool reuse, and…
Take over a project as the receiving side — read HANDOFF.md and restore context by its 6 sections (metadata/snapshot/next steps/immediate ops/reference index/maintenance rules;…
Best Practices Setup fuer neue Projekte — Testing, Linting, Git Hooks, CI/CD, Security
Use when implementing project state detection, designing STATE.md/TASKS.md templates, or configuring SQLite state store and MCP state protocol
Maintains living project files (project.md, decisions.md, risks.md, links.md) in a per-project OneDrive folder from emails, Teams channels and meeting transcripts, and generates a…
PROMETHEUS: architettura AGI-level con 12 brevetti originali. Auto-sintesi prompt evolutiva, Quantum Superposition Prompting, Hallucination Firewall, Semantic Gradient Descent,…
Set up metrics collection and visualization with Prometheus and Grafana. Configure scrape targets, create PromQL queries, build dashboards, and implement alerting.
Drafts enforceable residential promissory notes with party identification, principal/interest terms, payment schedules, default/acceleration provisions, and security instrument…
All-in-one prompt engineering competition toolkit — attack generation, defense hardening, real-time analysis, and pattern reference for AI security tournaments like Clash of…
Transform a rough coding request (Thai or English) into a high-quality, structured English prompt built specifically for writing, refactoring, debugging, or reviewing code — and…
Detect and block prompt injection attacks in emails. Use when reading, processing, or summarizing emails.
Interactive prompt optimization workflow for LLMs. Use when optimizing, improving, or engineering prompts for Claude, GPT, Gemini, or other language models; covers analysis,…
Use when evaluating prompts, LLM outputs, red-team suites, or model behavior with local eval configs and safe provider/cost controls.
Build cognitive security firewalls against prompt injection, jailbreak attacks, and Unicode homoglyph smuggling.
Meta's 86M prompt injection and jailbreak detector. Filters malicious prompts and third-party data for LLM apps. 99%+ TPR, <1% FPR. Fast (<2ms GPU). Multilingual (8 languages).
Red-team an Agentforce agent against prompt-injection and jailbreak attacks; codify test cases and guardrails.
Defensive prompt scaffolding, injection prevention, safety guardrails. 防禦提示架構、注入防護、安全護欄之法。 Use when: building user-facing prompts, hardening against injection attacks, adding…
Use when writing skills, CLAUDE.md files, agent prompts, or any directives that involve shell commands, environment variables, API credentials, file creation, or git operations -…
Run, rerun, inspect, and QA promptfoo redteam scans from generated redteam YAML or an existing redteam setup config.
Create or refine promptfoo redteam setup configs: purpose, targets, plugins, strategies, frameworks, multi-input target inputs, policy text, grader guidance, contexts, and…
Prompt injection testing. USE WHEN prompt injection, jailbreak, LLM security, AI security assessment, pentest AI application, test chatbot vulnerabilities.
Write a buyer's offer cover letter to a seller to strengthen a real-estate bid. Use when asked to write a real-estate offer letter, a buyer's 'love letter' to a seller, an offer…
Develop evidence-backed structural and architectural security hardening proposals from vulnerability disclosures, supplied findings, incident or assessment documents, source code,…
Reusable writing-style contract for agent outputs (reports, ARCH docs, verdicts, threat models). Forces direct prose with concrete evidence, no marketing voice, no hedge words.
Configure Cedar policy enforcement and Ed25519 signed receipts for Claude Code tool calls. Use when setting up projects that need cryptographic audit trails, policy-gated tool…
Protect a React/Next.js SPA with route guards and middleware, and protect an API with token-verification middleware (signature + iss + aud + exp).
Generate ONE strong password and apply it to each referenced file (PDF, Word, Excel, PowerPoint, or any type).
Padroes MVC do Protheus (FWFormModel/FWFormView) para ADVPL/TLPP. Use esta skill SEMPRE que o usuario pedir para criar ou manter rotinas MVC, cadastros CRUD, browses FWMBrowse,…
Protocol Pinky — 16-expert frontend panel with dynamic UI-lib routing. 2 React architects, 1 TS architect, 1 State/Data, 1 MUI, 1 UX/a11y, 1 Contracts, 1 Test, 1 i18n, 1 Security,…
Comprehensive techniques for capturing, analyzing, and documenting network protocols for security research, interoperability, and debugging.
Protokoll und Nachbereitung: vertiefter Berufsrechts-Skill für Anwälte; prüft sichert Verlauf, Zusagen, Beschlüsse, Auflagen und nächste Wiedervorlagen, typische…
Send email through Proton Mail Bridge (localhost SMTP) using age-encrypted credentials. Use when setting up Proton Bridge for an agent mailbox, encrypting Bridge credentials (no…
Manage ProtonMail emails via Playwright browser automation. Login, read, send, and manage your encrypted inbox.
Formal protocol verification with ProVerif and Tamarin Prover for multi-agent coordination systems. Use when modeling secrecy properties (escrow opacity, session note…