GLAW Assignment & Receivables-Transfer seat — determines whether a claim, account receivable, contract right, or cause of action is assignable (FL or DE law), drafts the…
Package an engagement's findings, scan outputs, evidence, and signed ROE into a timestamped archive with a SHA-256 manifest covering every file.
User-invoked skill to run a comprehensive pre-ship review using all review agents relevant to the project's tech stack, with rad-code-review as the final gate.
SAP Analytics Cloud (SAC) Custom Widget development. Use when building custom visualizations, extending SAC with Web Components, or creating Widget Add-Ons.
Packages and runs a local SAST pipeline scan to identify source code vulnerabilities.
Scan a source-code tree for hardcoded credentials embedded in source files: AWS access keys, GitHub tokens, Stripe keys, Slack tokens, Anthropic API keys, OpenAI keys, JWT signing…
Audits Solidity codebases for smart contract vulnerabilities using a four-phase workflow (cheatsheet loading, codebase sweep, deep validation, reporting) covering 36 vulnerability…
Developer security training and assessment for secure coding practices and vulnerability prevention
Retroactively verify threat mitigations for a completed phase — from produtoramaxvision/maxvision
Map pentest reports and CVEs to real code. Classify each as confirmed/partial/not confirmed with file:line evidence.
Teaches agents to recognize and avoid security threats during normal activity. Covers phishing detection, credential protection, domain verification, and social engineering…
Apply security awareness during code review and implementation. Catches common vulnerabilities without requiring full security audit.
Security controls and structured logging implementation. Use when security logging guidance is required.
Auditoría de seguridad OWASP Top 10. Usar para revisar código en busca de vulnerabilidades, validar autenticación/autorización, analizar input sanitization, detectar SQL…
Run Semgrep static analysis scan on a codebase using parallel subagents. Supports two scan modes — "run all" (full ruleset coverage) and "important only" (high-confidence security…
Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. Use when writing Semgrep rules or building custom static analysis detections.
Identifies error-prone APIs, dangerous configurations, and footgun designs that enable security mistakes.
Use when implementing SIP authentication, security mechanisms, and encryption. Use when securing SIP servers, clients, or proxies.
Build flawless Claude Code skills. Studies existing skills as reference, ensures correct format, and pushes for genuine intelligence — skills that exploit something specific about…
Use when the user mentions a skill/plugin by name, asks "should I install X", asks for skill recommendations, wants a security check on a skill, asks about duplicates or…
MANUAL TRIGGER ONLY: invoke only when user types /specforge. Full SpecForge workflow: Act 1 (Sprint Planning) → Act 2 (Spec Generation) → Handoff.
Guides the agent through migrating SQLite and SQL-style Capacitor plugins to @capgo/capacitor-fast-sql.
Fan-out review adapter. Routes a high-blast-radius artifact (plan or PR) through multiple heterogeneous review passes and gates on consensus.
Identifies dependencies at heightened risk of exploitation or takeover. Use when assessing supply chain attack surface, evaluating dependency health, or scoping security…
SysQL query language reference for Sysdig Secure. Use when writing, debugging, or explaining SysQL graph queries against the Sysdig security datastore.
Automated technical architecture review, security assessment, scalability analysis
Scans and analyses third-party dependencies and IaC configurations for security vulnerabilities.
Build a dependency-tree map of a project (npm or Python) and trace the path from each known-vulnerable transitive package back to one or more direct dependencies.
Performs graph-assisted triage of a single security finding, SARIF result, weAudit annotation, suspicious function, or report excerpt using Trailmark reachability, entrypoint…
Runs a Trailmark structural review gate over a branch, pull request, fix commit, release diff, or git ref range to detect new entrypoints, new tainted paths, removed validation or…
Expands one confirmed or suspected vulnerability into a Trailmark graph neighborhood of variant candidates by finding sibling functions, shared callers and callees, common…
Is this change safe, security implications of this PR, did we break any security. Security-focused differential code review for PRs, commits, and diffs — blast radius calculation,…
Manage agent memory with Membase - a decentralized, encrypted memory backup and restore system. Provides backup, restore, list, diff, status, and cleanup operations for agent…
GLAW alter-ego / veil-piercing analyst — the factor engine that decides whether the corporate shield holds.
Continuous vendor security monitoring for security ratings, breach notifications, and risk change detection
Automated vendor security assessment through questionnaire generation, response parsing, and risk scoring
Vulnerability assessment is the process of systematically identifying and quantifying security weaknesses in information systems through automated scanning, CVE analysis, and risk…
Trusted domains, security assessment patterns, and domain research standards for WebFetch permissions
Provides web vulnerability testing methodology distilled from 88,636 real-world cases from the WooYun vulnerability database (2010-2016).
Write and test YARA rules for malware detection and threat hunting. Use when creating YARA signatures, detecting malware families, scanning files or memory for indicators of…
Helpt bij het integreren met ZGW API-standaarden (Zaakgericht Werken) en Haal Centraal API's voor Nederlandse overheidsorganisaties.
Query historical crypto market data from 0xArchive across Hyperliquid, Lighter.xyz, and HIP-3. Covers orderbooks, trades, candles, funding rates, open interest, liquidations, and…
Every Abnormal Security threat, case, vendor, employee, and dashboard operation, plus a local threat store, ranked SOC triage, and one-shot client reporting.
Use when the user asks to check Action1 patch status, triage vulnerabilities, find stale or offline agents, score endpoint risk, or report patch posture across one or many client…
Active Directory security audit using the MITRE ATT&CK framework. Full domain enumeration, trust mapping, GPO analysis, ACL abuse paths, ADCS attacks (ESC1-ESC8), delegation abuse…
Integrates Power Pages generative-AI summarization APIs (PREVIEW) into a Single Page Application (SPA) site — the Search Summary API and the Data Summarization API — on any…
Adiciona uma regra/risco novo ao docs/security-guidelines.md, para que Dev e DPO passem a considerá-lo desde o começo nas próximas demandas.
Maquina autonoma de seguranca (wrapper SENTINEL). Security + load testing + LGPD compliance. 6 dimensoes, modo hybrid, convergencia SSS >= 80. Security Certificate.
Debate multi-agente: 2-4 perspectivas (PM, Arquiteto, QA, Security) debatem decisao tecnica. Output: decisao + rationale + dissenting opinions → ADR.
5 expert personas debate proposed changes before implementation. Catches architectural, security, performance, and UX issues early.
Maquina autonoma de seguranca, load testing e LGPD. 6 dimensoes, modo hybrid, convergencia SSS >= 80. Security Certificate + Load Report + Fix PR.
Auditoria de seguranca, qualidade e conformidade. OWASP Top 10, secrets scan, dependency audit. Use antes de deploy.
End-to-end database connection for agami: sets up credentials on first run (DB-type picker → writes ~/.agami/credentials.example for the user to fill in), then introspects the…
Answers natural-language questions about the user's database. Loads the agami semantic model (subject areas, tables, columns, relationships with join cardinality, entities,…
Run the OWASP-aligned agentic security review path — covers goal hijacking, tool misuse, excessive agency, memory poisoning, secrets exposure, handoff failures, and observability.
Delete a secret. Requires authentication. Use for Agentuity cloud platform operations
Get a secret value. Requires authentication. Use for Agentuity cloud platform operations
Import secrets from a file to cloud and local .env. Requires authentication. Use for Agentuity cloud platform operations
Set a secret. Requires authentication. Use for Agentuity cloud platform operations
**DEFAULT for AI agent safety reviews — dispatches security-auditor + risk-and-controls-reviewer with AI/agent safety focus.**