Porter's Five Forces, SWOT analysis, and competitive positioning matrix for strategic market analysis. Identifies threats, opportunities, and recommends positioning strategy.
Build durable competitive advantage using Hamilton Helmer's \"7 Powers\" framework—the complete, mutually exclusive enumeration of all possible sources of sustainable business…
Research competitors and produce a positioning + messaging comparison with content gaps, opportunities, threats, and a sales battlecard.
Analyze competitors using Porter's Five Forces, positioning maps, and competitive response frameworks. Use when assessing market position or strategic threats.
Scrape competitor ads from Meta Ad Library and Google Ads Transparency Center, analyze creative patterns (hooks, formats, CTAs), reverse-engineer landing page funnels, and produce…
Synthesize multiple per-competitor research files (produced by /competitor-research) into a single canonical threat matrix.
Analyze competitive landscape to identify strengths, weaknesses, opportunities, and threats. Inform product strategy and positioning based on market insights.
Analyze competitors with strengths, weaknesses, and differentiation opportunities. Identifies direct competitors and maps the competitive landscape.
Run a structured competitive teardown in 20 minutes. Covers positioning, ICP, offer analysis, moat assessment, vulnerability mapping, and a direct attack brief.
Analyse competitor moves and translate them into strategic implications for your product roadmap. Use when a competitor announces a new feature, pricing change, partnership, or…
Estimate issue complexity before implementation to prevent timeouts. Uses cheap estimation to save expensive implementation tokens. — from majiayu000/claude-skill-registry
Two niche audit specialists not covered by existing operations/finance/ecc skills — smart contract security audit (Solidity / EVM / DeFi) and business automation governance (n8n…
Automated compliance auditing for SOC2, HIPAA, GDPR, and PCI-DSS. Activates for compliance checks, security audits, regulatory requirements, and compliance automation.
Provides a checklist framework for surfacing potentially applicable application-compliance obligations across declared jurisdictions (Japan / EU / US-CA / platform stores).
Use when setting up or auditing how compliance documentation is structured, collected, and preserved for regulatory audit in Salesforce FSC — covering KYC data collection…
SOC2, HIPAA, GDPR, PCI-DSS, FedRAMP compliance implementation in code. Audit logging, data encryption, access controls, privacy by design, and regulatory requirement mapping.
Aggregates audit findings mapped to framework controls, classifies each as compliant / partially compliant / non-compliant / not tested, identifies blind spots, prioritizes gaps…
Runs a 4-phase compliance pipeline: security scan, GDPR audit, dependency vulnerability check, and penetration test, producing a unified pass/fail compliance report.
Provides compliance, governance, and supply chain security guidance for cloud-native systems. Covers OPA Rego policies, Kyverno cluster policies, SBOM generation, SLSA provenance,…
Prüft Pflichtschulungen, Compliance-Regeln, Security Policies, Zugangsbeschränkungen und Statusgewicht im Sozialversicherungsstatus Prüfer.
Runs a 5-phase enterprise compliance and security hardening pipeline: regulatory review, GDPR audit, SOC 2 evaluation, dependency scan, and penetration test with cross-framework…
Validate compliance during migration with rule checking, audit trails, and security control validation
Wirtschaftsprüfer: component auditor koordination - Rechtsprechungscheck, stärkste Gegenansicht und Red-Team-Korrektur; mit Live-Normencheck, Kammerlogik, Verhältnismäßigkeit,…
Create and manage OSCAL component definitions for reusable security control implementations. Inspired by CivicActions components and community patterns.
Composer dependency management playbook for safe, systematic package updates. Use when the user asks to update Composer dependencies, audit packages for security vulnerabilities,…
Composio OAuth integration for external service connections. CSRF-protected flow with state management, connection lifecycle transitions (pending→initiated→active), dynamic tool…
Coinbase Automation: list and manage cryptocurrency wallets, accounts, and portfolio data via Coinbase CDP SDK — from phamlongh230-lgtm/yamtam-engine
Automate Google Drive tasks via Rube MCP (Composio). Always search tools first for current schemas. — from phamlongh230-lgtm/yamtam-engine
Automate Securitytrails tasks via Rube MCP (Composio). Always search tools first for current schemas. — from phamlongh230-lgtm/yamtam-engine
SharePoint Automation: manage sites, lists, documents, folders, pages, and search content across SharePoint and OneDrive — from phamlongh230-lgtm/yamtam-engine
Exhaustive multi-dimensional project auditor covering code, runtime, infrastructure, security, performance, business logic, and human processes across 12 dimensions with — from…
Exhaustive multi-dimensional project auditor covering code, runtime, infrastructure, security, performance, business logic, and human processes across 12 dimensions with — from…
Ability to plan, direct, and oversee the development, operation, and governance of information systems to meet organisational objectives.
Use when a task needs the judgment of a Computer and Information Systems Manager (IT Manager/Director/CIO-adjacent) — planning IT infrastructure and systems strategy, evaluating a…
Analyzes events through computer science lens using computational complexity, algorithms, data structures, systems architecture, information theory, and software engineer — from…
Analyzes events through computer science lens using computational complexity, algorithms, data structures, systems architecture, information theory, and software engineer — from…
Build AI agents that interact with computers like humans do - viewing screens, moving cursors, clicking buttons, and typing text.
Build AI agents that interact with computers like humans do - viewing screens, moving cursors, clicking buttons, and typing text.
Build production computer vision pipelines for object detection, tracking, and video analysis. Handles drone footage, wildlife monitoring, and real-time detection.
Computerbetrug/Phishing anzeigen: Zahlungsdaten, TAN, Social Engineering, Bankkommunikation, Logs und Sofortmaßnahmen im Strafanzeige-Vorbereitung.
Framework for surfacing and tracking tech debt, known bugs, and security gaps in software codebases.
TOCTOU prevention, distributed locking, idempotency keys, race condition detection for Node.js and serverless environments.
Conducts security testing of REST, GraphQL, and gRPC APIs to identify vulnerabilities in authentication, authorization,
Responds to security incidents in cloud environments (AWS, Azure, GCP) by performing identity-based containment,
Conduct a defensible cybersecurity risk assessment using the NIST SP 800-30 Rev 1 methodology: prepare scope and a risk model, identify threat sources and threat events, identify…
Perform DCSync attacks to replicate Active Directory credentials and establish domain persistence by extracting
Identifies fulcrum securities in distressed capital structures with enterprise value allocation and recovery sensitivity analysis.
Plan and execute a comprehensive red team engagement covering reconnaissance through post-exploitation using
Execute an internal network penetration test simulating an insider threat or post-breach attacker to identify
Conduct internal Active Directory reconnaissance using BloodHound Community Edition to map attack paths, identify
Responds to malware infections across enterprise endpoints by identifying the malware family, determining infection
Simulates man-in-the-middle attacks using Ettercap, mitmproxy, and Bettercap in authorized environments to intercept,
Performs memory forensics analysis using Volatility 3 to extract evidence of malware execution, process injection,
Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security
Pass-the-Ticket (PtT) is a lateral movement technique that uses stolen Kerberos tickets (TGT or TGS) to authenticate
Responds to phishing incidents by analyzing reported emails, extracting indicators, assessing credential compromise,
Spearphishing simulation is a targeted social engineering attack vector used by red teams to gain initial access.
Conducts authorized wireless network penetration tests to assess the security of WiFi infrastructure by testing
Build a personalized preference profile from a small number of well-chosen, cluster-grounded questions instead of a long survey.
Produces structured legal conference summaries capturing session substance, speaker credentials, cited authorities, and practical takeaways.