ขั้นตอนการติดตั้งและตั้งค่า Provider ID OAuth (ผ่าน Health ID / moph.id.th) ด้วย Auth.js (next-auth v5) ใน Next.js App Router — ครอบคลุม: การติดตั้ง package, การสร้างปุ่ม Login,…
Create Microsoft Entra Agent Identity blueprints, principals, and agent identities with the right beta Graph permissions, sponsor rules, and sidecar-based auth patterns.
Proxmox VE administration for single-node and clustered environments. Use when Codex needs to operate or troubleshoot Proxmox hosts, VMs, LXCs, storage, networking, backups,…
Römisches Recht: Prozess Legisaktionen. Geführter Fachmodul mit Quellenlogik, Prüfroutine, Red-Team-Fragen und verwertbarem Output.
Podiva se na posledni screenshoty z OneDrive Screenshots slozky a precte jejich obsah pomoci token-free OCR (Windows OCR API nebo Tesseract).
Prüft Phishing-Vorfall im Online-Banking oder Zahlungsverkehr auf Erstattungsansprüche gegen Zahlungsdienstleister.
Schnuert das vollstaendige Pruefer-Paket nach Abschluss eines Wuerfellaufs — Excel-Wuerfel-Datei aus Skill `excel-multi-sheet-export` PDF-Bericht aus `pdf-bericht-erzeugen`…
Wirtschaftsprüfer: prüfungsplanung und dokumentationsluecke - Rechtsprechungscheck, stärkste Gegenansicht und Red-Team-Korrektur; mit Live-Normencheck, Kammerlogik,…
pschool (個人プログラミングスクール) の Q&A 教師エージェント。ユーザーが pschool コース (Udemy 1 コース粒度の座学 + ハンズオン演習) を受講中に詰まったときに起動し、答えを絶対に教えずに 3 段階のヒント (Lv 1 Conceptual / Lv 2 Directional / Lv 3 Specific)…
Aggregates crypto news from multiple sources and generates curated daily markdown reports with automated scoring and deduplication.
Verify Python packages, CLIs, MCP servers, and Agent plugins through the exact installed artifact and real runtime contract.
Prüft BSI-Anforderungen für öffentliche Auftraggeber und Lieferanten im Nis2 Cybersecurity Compliance.
Audit a government or public services system for compliance, fraud risk, and security — chains benefits processing review, fraud detection analysis, regulatory compliance check…
TspoonBase — a TypeScript backend-as-a-service with SQLite, auth, realtime, file storage, AI tools, vector search, and Admin UI.
Use when stellar-forge release publishing touches GitHub Actions permissions, secrets, protected environments, token scope, signing keys, provenance, OIDC, registry credentials,…
The GRU953-Studio protocol for publishing a finished MVP privately to the user's OWN GitHub account, with an explicit separate step to make it public later.
Publish agent skills AND MCP servers to every marketplace, plugin directory, and registry — security-scan for private data, validate with `gh skill`, cut a release, wire the…
Guidance for working with Pulumi ESC (Environments, Secrets, and Configuration). Use when users ask about managing secrets, configuration, environments, short-term credentials,…
Defense-in-depth security across Rust, TypeScript, and Bash for the Pump SDK — cryptographic key handling, memory zeroization, secure file I/O, input validation, privilege…
Launch tokens on pump.fun directly from your agent. Zero middleware fees — direct on-chain via pumpdotfun-sdk.
Purificar agua de fuentes silvestres usando ebullición, filtración, desinfección química y destilación solar.
Synthesize red team findings and blue team fixes into a structured security report. Use when the user wants a consolidated security report after red-team-check and blue-team-fix…
Pwn/Binary kategorisi SKILL.md — BOF, ROP, kernel exploit araçları kurma rehberi
从逆向走到可用利用 (Working Exploit) 的全链路工程化方法。 适用场景:拿到了二进制 + 漏洞点 + 目标环境,需要写出一个能稳定打通的 exploit(不是只能本地复现一下、远程一打就崩的脚本)。 覆盖三大方向:栈溢出 / 堆利用 / 内核 pwn。强调"CTF 本地通 → 真实远程稳定打通"的工程差距:libc…
Test your AI agent for security vulnerabilities using PwnClaw. Runs 50+ attacks (prompt injection, jailbreaks, social engineering, MCP poisoning, and more) and provides fix…
Use when running pynchy locally — running the app, tests, linting, formatting, pre-commit hooks, or rebuilding the agent container.
LOCAL-ONLY PyPI publishing with Doppler credentials. TRIGGERS - publish to PyPI, pypi upload, local publish. NEVER use in CI/CD.
Queries the PyPI JSON API and the libraries.io API to analyze Python package metadata, dependency trees, and version histories.
Facebook Pyre static type analysis patterns for Python. Incremental type checking, taint tracking for data-flow security analysis, pysa rules, and integrating Pyre into CI…
AI red-teaming framework for testing LLMs and generative AI systems for jailbreaks, prompt injection, harmful content, data leakage, and multi-turn attacks.
Guidelines for building Python cybersecurity tools with secure coding practices, async scanning, and structured security testing.
Guideline for designing, implementing, and verifying secure Python applications following OWASP Top 10 best practices.
Run defensive pre-release security tests for Python web applications. Use for FastAPI, Django, Flask, and ASGI services: the common interface between Python web apps and servers.
Python-based threat modeling using pytm library for programmatic STRIDE analysis, data flow diagram generation, and automated security threat identification.
QA Developer: Stage 4c-qa post-red-team test augmentation. Write regression tests for every addressed red-team finding before Stage 5 begins.
Formal Quality Assurance Checklist before every Merge/Deploy. 6-phase validation with Build Verification, Test Suite, No-Touch Zones, Region Check, Security Review, and QA Report…
Shared QA test configuration — credentials, file paths, and scope for all QA skills
Consolidated form validation skill. Owns ALL validation testing: empty-submit, invalid-format, real-time/blur feedback, whitespace, oversize input (10K), maxlength enforcement,…
Use quando o Pedro quer revisar código num loop disciplinado que para por retornos decrescentes (qualidade vs vale a pena), não por zero erros.
ISTQB Foundation Level (CTFL) aligned QA toolkit for manual and automated testing. Use when asked to create test plans, test strategies, test conditions, test cases, bug reports,…
Design and apply QA methodology for software teams: test strategy, regression testing, CI failure triage, test automation, quality gates and metrics, risk-based testing,…
[QA Process · ISTQB CTFL v4.0] Test Plan creation — objectives, schedule, resources, entry/exit criteria, and risk mitigation. Run after qa-strategy, before test execution.
[QA Process · ISO 31000 + ISTQB CTFL v4.0] Risk-based test prioritization — builds a risk matrix (likelihood × impact), ranks test areas by priority, and flags critical paths for…
Security scanning templates and checklists for OWASP Top 10, authentication, authorization, data protection. Use when conducting security testing or vulnerability assessment.
[QA Process · ISO 25010 + ISTQB CTFL v4.0] Test Strategy document creation — defines scope, risk appetite, test approach, coverage goals, and tool selection for the project.
Systematically test web applications for functionality, security, and usability issues using browser automation.
Gestión del QA del proyecto GitHooks: ejecutar herramientas de análisis estático y tests, interpretar y corregir violaciones, y garantizar que el código está limpio antes de…
Operations, runtime configuration, security, and device-local health of QECTOR deployments. The library path uses compat_report and get_license_info; any Workbench health tools…
Use when building the robustness suite and online appendix for a Quarterly Journal of Economics (QJE) manuscript — the extensive checks QJE referees expect, exploiting the…
Integrate QPay — Mongolia's primary QR payment system — into a developer's project so they can accept MNT payments through Khan Bank, Golomt, State Bank, Xac Bank and other…
Generate QR codes for URLs, WiFi credentials, vCards, email, SMS, and plain text.
Air-gapped credential bridge using QR codes. Use when transferring credentials between networked and air-gapped devices via QR codes.
Wirtschaftsprüfer: qualitaetskontrolle und inspektion - Rechtsprechungscheck, stärkste Gegenansicht und Red-Team-Korrektur; mit Live-Normencheck, Kammerlogik, Verhältnismäßigkeit,…
Steuerberater: qualitaetsmanagement fristen - Rechtsprechungscheck, stärkste Gegenansicht und Red-Team-Korrektur; mit Live-Normencheck, Kammerlogik, Verhältnismäßigkeit, Belegplan…
Anwälte: qualitaetsmanagement fristen und vier augen - Rechtsprechungscheck, stärkste Gegenansicht und Red-Team-Korrektur; mit Live-Normencheck, Kammerlogik, Verhältnismäßigkeit,…
Notare: qualitaetsmanagement im notariat - Rechtsprechungscheck, stärkste Gegenansicht und Red-Team-Korrektur; mit Live-Normencheck, Kammerlogik, Verhältnismäßigkeit, Belegplan…
Qualitaet installierter Skills prüfen: Normaktualitaet, Description-Qualitaet, Struktur-Compliance. Normen: technisch/intern, SKILL.md-Schema.
Triage SonarQube findings by separating blockers from lower-priority issues across bugs, vulnerabilities, code smells, coverage, duplication, and security hotspots.
5-level verification pyramid: static→unit→Playwright E2E (homepage-first, 6bp)→AI visual→post-deploy. 8-check quality gate.
Page quality audits for DOM complexity, CSS architecture, security vulnerabilities, and SEO/meta tag validation.