Adding/upgrading/removing dependencies — justification bar, changelog + pinned-constraint archaeology, matching package-manager/lockfile hygiene, one bump at a time, gates after.
Audit dependencies — npm audit, govulncheck, pip-audit, cargo-audit, outdated packages, update plan
Detect and resolve package dependency conflicts before installation across npm/yarn/pnpm, pip/poetry, cargo, and composer. Auto-trigger when installing/upgrading packages.
Audit locked npm dependencies against OSV advisories and emit exact-version CVE evidence.
Diagnose and heal dependency issues in ANY package manager, ANY language. Use when facing version conflicts, security vulnerabilities, or dependency bloat.
Automated dependency management with security scanning, update orchestration, and compatibility validation
Security-first dependency management methodology with batch remediation, policy-driven compliance, and automated enforcement.
Python dependency and environment management for multi-service or monorepo python backends. Use when: (1) adding, upgrading, or removing a Python package, (2) responding to…
You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security.
Use when the Integrator is managing project dependencies, updating packages, resolving version conflicts, auditing for vulnerabilities, or maintaining lock files.
Expert dependency manager specializing in package management, security auditing, and version conflict resolution across multiple ecosystems.
Expert at package management and supply chain security. Use when managing dependencies, updating packages, resolving version conflicts, ensuring supply chain security, or auditing…
Dependency and supply-chain security - lockfiles and reproducible installs, version pinning, vulnerability auditing, minimizing and vetting third-party packages, vendoring obscure…
Audit dependencies for licensing, security, and maintenance risk. Use when a senior developer needs risk assessment.
Scan project dependencies for known vulnerabilities (CVEs), auto-fix safe patches, and generate SBOM.
Scan project dependencies for known vulnerabilities, generate software bills of materials, and enforce license compliance across the software supply chain.
Configure automated dependency and vulnerability scanning at a cadence people will actually act on. Use when dependencies drift or vulnerabilities go unnoticed.
Audits a JS/TS codebase for hand-rolled boilerplate that a secure, well-maintained, widely-used npm package could replace, and vets each candidate for security advisories,…
Enforce dependency security scanning and SBOM generation. Use when adding dependencies, reviewing package.json, or during security audits.
Audit dependency CVEs across Node, Python, Flutter/Dart, and mixed repos; design OSV/native audit hooks for pre-push and CI.
Comprehensive guide for Dependency-Track - Software Composition Analysis (SCA) and SBOM management platform.
Scan package manifests and lockfiles for outdated and vulnerable dependencies. Classify by severity and update type.
Scans your project for outdated npm, pip, Cargo, Go, or Ruby packages. Runs a CVE security audit. Fetches changelogs, summarizes breaking changes with Gemini, and opens one PR per…
Analyze a specific dependency upgrade using manifests, lockfiles, repository usage, and verified official release evidence, including breaking changes, runtime requirements,…
Plan and de-risk a major dependency, framework, or runtime upgrade — map the full version path, read every intermediate migration guide, and pin the breaking changes to your…
Vet new package dependencies before installation. Triggers when adding packages via pip, npm, yarn, or similar package managers.
Use when the user names one or a few specific dependencies (with version) — not a whole project — and asks "does io.ktor:ktor-server-core 3.1.0 have any known vulnerabilities",…
Dependency Vulnerability Checker - Auto-activating skill for Security Fundamentals. Triggers on: dependency vulnerability checker, dependency vulnerability checker Part of the…
Scans project dependencies using OSV.dev API and Snyk CLI for known CVEs across npm, PyPI, Maven, and Go modules. Generates SBOM in CycloneDX format via syft.
Turns npm audit/Snyk results into prioritized patch plans with severity assessment, safe upgrade paths, breaking change analysis, and rollback strategies.
Deploy cloud-native deception across AWS, Azure, and GCP using decoy (honey) resources whose only purpose is to generate a high-fidelity alert the instant an attacker touches…
Deploys canary files (honeytokens) across file systems to detect ransomware encryption activity in real time.
Deploys and configures CrowdStrike Falcon EDR agents across enterprise endpoints to enable real-time threat
Plants Canarytokens-based decoy artifacts (honey credentials, DNS tokens, web-bug URLs, AWS keys, documents, kubeconfigs) using Thinkst's open-source Canarytokens project and…
Deploys and monitors ransomware canary files across critical directories using Python''s watchdog library for
Deploys TCP Trojan proxy nodes on Xray-core with certbot Let's Encrypt or self-signed EC P-256 + SHA-256 certificate fingerprint pinning, TCP Fast Open kernel tuning with BBR,…
Query the Cancer Dependency Map (DepMap) for cancer cell line gene dependency scores (CRISPR Chronos), drug sensitivity data, and gene effect profiles.
Use when hardening npm supply chain, pinning dependency versions, adding .npmrc security flags, or setting up Renovate and audit workflows.
Check dependencies for vulnerabilities. Use when user asks to "audit dependencies", "/deps-audit", "check for vulnerabilities", or wants to check dependency health.
Comprehensive dependency management expertise covering TypeScript (npm, yarn, pnpm, bun), Rust (cargo), and Python (pip, poetry, uv).
Dependency-upgrade campaign — outdated scan, batch-by-severity, breaking-change remediation, lockfile audit.
Use when the deliverable is a DESCRIPTION of what's in the data rather than an effect, a counterfactual, or a prediction — stylized facts, raw and indexed trends ("what's the…
Design, implement, tune, or test readable tactical action combat for web games. Use for attack timing, guard and dodge windows, hit contact, posture, lock-on, weapons, boss…
Designs and validates backup, point-in-time-recovery, and disaster-recovery strategy for datastores — sets RPO/RTO targets, configures snapshot plus continuous WAL/binlog/oplog…
Builds, redesigns, polishes, and visually reviews websites and web UIs that must feel specific, time-appropriate, non-generic, and production-quality.
Use before calling any design done, and for anything with concurrency, persistence, or external dependencies — risk-storm the design: attack it, then decide resilient vs fail-fast…
Build retention into visit burden, schedule, and engagement to lower the ~30% dropout, instead of re-recruiting. Reach for this when dropout threatens the timeline.
Design a Uniswap integration architecture. Use when user is building a project that needs to integrate Uniswap and wants recommendations on integration method (Trading API vs SDK…
Design safe n8n workflows with deterministic routing, credentials, idempotency, recovery, local-model checks, drafts, and exact approval gates.
Parallel design review by 6 specialist agents (PM, Architect, Designer, Security Design, UX, CTO) with mandatory unanimous approval.
Copilot agent that assists with systematic design review using ATAM (Architecture Tradeoff Analysis Method), SOLID principles, design patterns, coupling/cohesion analysis, error…
Premium brand-kit image generation skill for creating high-end brand-guidelines boards, logo systems, identity decks, and visual-world presentations.
Use when analyzing user journeys, auditing UX quality, prototyping flows, or designing new pages/features from a product perspective.
Designs backend API error contracts with a REST-default approach using RFC 9457 Problem Details, stable machine-readable codes, retry semantics, validation error payloads,…
Expert guide for Electron 33+ desktop application development — Electron Forge, context isolation, IPC security, native menus, auto-updates, and multi-window management / Panduan…
Electron process architecture, IPC patterns, preload security, native APIs, packaging and distribution
Electron fuses, ASAR integrity, sandbox hardening, CSP, permission handling, navigation restrictions
Tauri 2.x deny-by-default security model, capabilities, permissions, scopes, ACL
Persistent storage, SQLite databases, and credential management in Electron apps
Detect hardcoded secrets, API keys, passwords, and credentials in source code. Security audit for leaked secrets. Works across all languages.