Adversarial verification for AI-generated legal content with systematic fact-checking, source validation, and quality control.
Usar siempre que el usuario escriba, redacte, revise o traduzca texto científico/académico en ESPAÑOL — artículos, papers, tesis, abstracts, introducciones, metodologías,…
AI pressure redirection — handling conflicting demands, tool failures, and competing constraints by blending with incoming force then reframing.
Redis security guidance covering authentication (requirepass and ACL users), TLS, ACL-based least-privilege access control, restricting network exposure via bind and…
Spawn a one-shot red-team subagent to challenge a milestone result. Calibrated to return "nothing substantive" when the work is sound — does not invent issues to seem thorough.
Detailed Active Directory attack-path pack for kerberos, ACL, ADCS, and NTLM relay routes.
Detailed code-audit pack for entrypoint tracing, trust boundaries, exploit proofs, and sink selection.
Red-Team-Gate für alle Commercial-Court-Outputs: Zuständigkeit, Sprache, Fristen, Beweise, Übersetzungen, Geheimnisschutz, Kosten, Rechtsmittel.
Detailed cryptography pack for RSA, hash, symmetric-cipher, lattice, stego, and classical-cipher attack paths.
Adversarial analysis with 32 agents. USE WHEN red team, attack idea, counterarguments, critique, stress test. SkillSearch('redteam') for docs.
Detailed evasion pack for AV/EDR, WAF, 403/CSP bypass, and sandbox-oriented analysis.
Detailed injection pack for SSRF, SQLi, XSS, SSTI, deserialization, XML, command, and expression injection paths.
Red-team operator discipline — the mindset corrections that separate offensive testing from defensive WAPT.
Standards for creating redteam plugins and graders. Use when creating new plugins, writing graders, or modifying attack templates.
Detailed post-exploitation pack for foothold triage, privesc, credentials, lateral movement, and tunneling.
Detailed reconnaissance pack for attack-surface discovery, docs review, and pre-exploitation signal gathering.
Client-facing red-team deliverable format — codifies the Subject / Observations / Description / Impact / Recommendation / PoC structure used for external red-team engagements (not…
Detailed reverse-engineering pack for binaries, loaders, anti-analysis, deobfuscation, and exploitability clues.
Adversarial security review fleet for the Port Daddy whitepapers (Bonded Commons, Anchor Protocol). Use when a paper version is being prepared, when a coordination/cryptographic…
Detailed web/API/auth/injection/file/logic testing pack for hook-routed red-team mode.
Systematically detects all reentrancy vulnerability variants in smart contracts — classic, cross-function, cross-contract, and read-only reentrancy.
Advanced Regle form validation patterns — collection validation with `$each`, async rules and `$pending`, server/`externalErrors`, `$reset` options, global config with…
Audit codebases for cross-industry regulatory compliance across SOX, GDPR, HIPAA, PCI-DSS, CCPA/CPRA, FedRAMP, FISMA, COPPA, and FERPA.
Track legislation, regulatory actions, and legal developments affecting prediction markets, crypto, and AI agents — triaged by stage × impact for decision-ready output
Use when validating code, a SPEC or an Intent against the 4 Tier 1 governance agents (AI-ACT, RGPD, RGAA, RGESN). Emits PASS / WARN / VETO with structured remediation.
Deep operational guide for 20 relational/SQL databases. PostgreSQL tuning (VACUUM, WAL, partitioning, extensions, PgBouncer), MySQL/MariaDB (InnoDB, Vitess, Galera, ProxySQL),…
Audit an existing CI/CD pipeline for slowness, security issues, and reliability gaps. Use when asked to "audit pipeline", "why is CI slow", "pipeline review", or "deployment…
Pre-release verification checklist. Validates features, tests, docs, security, and quality gates before shipping. Delegates to the Centinela (QA) agent.
Sequential release gate validating build success, test suite, security checks, type checking, manifest counts consistency, and changelog presence.
Senior developer-level release review for macOS/iOS apps. Identifies security, privacy, UX, and distribution issues with actionable fixes.
Manages release preparation including validation, version bumping, documentation verification, and security checks.
Define deployment reliability, availability zones, failover, degradation, backup, restore, RPO, RTO, disaster recovery, resilience testing, and recovery ownership.
Track vulnerability remediation performance, SLA compliance, and trending direction. Identifies areas falling behind, blindspots with runtime risk but no CVE tracking, and…
RemoFirst security basics — global HR, EOR, and payroll platform integration. Use when working with RemoFirst for global employment, payroll, or compliance.
Use when working with the REMORA system — calling MCP tools for document analysis, legal verification, or security research, OR developing/deploying REMORA workers and benchmarks,…
Use when configuring Remote Site Settings to allow Apex callouts to external URLs, or when distinguishing Remote Site Settings from CSP Trusted Sites for Lightning component…
Baseline guidance for the reopt CLI — authentication, login, global flags, security rules, and exit codes.
Use when designing how a database keeps multiple copies of its data in agreement across nodes for availability, read scaling, and disaster recovery: the three foundational…
Implement secure data handling on Replit: PostgreSQL, KV Database, Object Storage, and data security patterns.
Configure Replit Teams roles, SSO/SAML, custom groups, and organization-level access control. Use when setting up team permissions, configuring SSO, managing deployment access, or…
Enforce security and resource policies for Replit-hosted apps: secrets exposure prevention, resource limits, deployment visibility, and database access controls.
Apply Replit security best practices: Secrets management, REPL_IDENTITY tokens, Auth headers, and public Repl safety.
Dual-lens repo analysis: Creator View (knowledge, insights, home-repo comparison) + Engineer View (health, security, process).
Deep analysis of Git history: identify frequently changed hotspot files, analyze code ownership by contributor, and scan for leaked secrets.
Multi-dimensional codebase evaluation with verified scoring. Launches parallel explore agents, cross-checks findings with direct verification, produces calibrated 1-10 scorecard…
Auditoría defensiva para repositorios AI-native. Usar SIEMPRE que el usuario quiera revisar un repo antes de lanzar, mergear, actualizar dependencias, migrar package manager,…
Pre-clone security scanner — detect malicious hooks, poisoned MCP configs, credential-harvesting patterns before Claude Code processes repos
Repo/monorepo—dep modernize, vuln fix, framework-aware upgrade, hard-cut, dep-native refactors.
Repo/monorepo modernization: dependency upgrades, security fixes, deprecation cleanup, framework migrations, dependency-native refactors, and verified hard-cut simplification.
Analisa e classifica um repositório GitHub via repo-radar CLI (SQLite + LLM), registrando o veredito em PROJECT_EVALUATIONS.md
Security audit for GitHub repositories before installation. Use when user wants to check if a repo/app is safe to install, review install scripts for malicious code, verify an…
Full security audit for public repositories across 12 attack surfaces: git history, secrets, CI/CD, containers, dependencies, licenses.
Package entire code repositories into single AI-friendly files using Repomix. Capabilities include pack codebases with customizable include/exclude patterns, generate multiple…
Repomix packs an entire code repository into a single AI-friendly file optimized for LLM consumption.
Pack repositories into AI-friendly files with Repomix (XML, Markdown, plain text). Use for codebase snapshots, LLM context preparation, security audits, third-party library…
Safely package codebases with repomix by automatically detecting and removing hardcoded credentials before packing.
Identify and report potentially malicious software repositories masquerading as legitimate security tools
Take a suspected injectable request, replay it on an authorized target, confirm the finding, and enumerate reachable database actions before manual follow-up.
CI/CD pipelines as merge gates. Tests, security scans, and linting must pass before code reaches production. Automated validation that satisfies auditors.
Drafts jurisdictionally compliant U.S. residential lease agreements with required disclosures, security deposit compliance, and Fair Housing Act conformance.