Use when the user asks to reconcile Sherweb billing, compute net margin per customer (receivable minus payable), find orphaned or under-billed subscriptions, catch metered usage…
Power-user shortcut to list WP Umbrella sites with an optional filter. Invoke as /umbrella:sites [filter].
Syncs skills across AI CLI tools (Claude, Cursor, Windsurf, etc.) from a single source of truth. Global mode (~/.config/skillshare/) and project mode (.skillshare/ per-repo).
Use when the user asks to audit SkyKick Cloud Backup across customers - which Microsoft 365 tenants have a backup gap, which mailboxes silently stopped snapshotting, what's…
SOC daily-pull triage feed — Vulnetix''s score-driven queue cross-referenced with installed dependencies.
Run Socket.dev supply chain security audit on npm dependencies for malicious packages and typosquatting
Final code review and quality gate — run tests, check coverage, audit security, verify acceptance criteria from spec, and generate ship-ready report.
Soroban smart contract development on Stellar (Rust SDK). Covers project setup, contract structure, storage types, authorization, cross-contract calls, events, error handling,…
Analyze a CycloneDX/SPDX SBOM file using sbomr. Use when asked to inspect, summarize, or query an SBOM file — e.g.
Use when: performing code review, pull request review, security review, designing, implementing, or testing SSRF fixes, outbound HTTP requests, outbound fetch helpers,…
Take a system from "merged" to reliably serving users in production, and keep it there: deployment & release strategy, infrastructure-as-code & config, observability, monitoring &…
Plan een klus als een reeks kleine, toetsbare stappen voor attended uitvoering met /fwd:steps-run — de lichte tegenhanger van fwd:mission-plan.
Scaffold and build AI agents using the Strands Agents SDK with Bedrock AgentCore. Use when creating new agent projects, building greenfield AgentCore applications, prototyping…
Use when analyzing a subscription or recurring-revenue business (news site, paywall publisher, SaaS-light, membership platform, e-commerce with subscription tier) for monetization…
Use when the user asks to triage a SuperOps queue, see who's about to breach SLA, pull a client 360 before a QBR, find at-risk assets (unpatched and actively alerting), check…
Reviews AI/ML model supply chains for security risks including model provenance verification, training data lineage, fine-tuning pipeline integrity, inference dependency review,…
Expert SurrealDB 3 skill. Use when working with SurrealDB, SurrealQL queries, multi-model data modeling (document, graph, vector, time-series, geospatial), schema design, graph…
Use this skill when investigating a runtime threat detected by Sysdig end-to-end. Surfaces the highest-priority threat, scores vulnerability vs runtime correlations on a 1-5…
Use when the user asks to check Tactical RMM fleet health, triage the agents that need attention first, sweep patch posture across every client, find agents that have gone dark,…
Orchestrate the polish team: coordinates performance-analyst, security-engineer, accessibility-specialist, and qa-tester to optimize, harden, and polish a feature for release…
Launches pre-configured multi-agent teams for code review, debugging, feature development, security audits, and database migrations.
Inspects the OrchestKit telemetry pipeline for the current project — lists all known telemetry files with write counts, sizes, schema status, growth trend, and orphan detection.
Knowledge router AND interactive teacher across every book-derived skill in this project. Two modes — (1) **ask**: auto-discovers all domain skills (finance, vuln hunting, AI…
Daily threat-intel digest — AI-discovered vulnerabilities, AI-in-the-wild exploitation observations, AI-authored malware families, exploit-trends rollup, vendor-trends…
Use when the user asks to triage ThreatLocker application approvals across tenants, approve a file hash everywhere it's pending, export or check retention on the Unified Audit…
Analyze a PR for TNF (Two-Node Fencing) security threats with STRIDE/DFD analysis, MITRE ATT&CK and OWASP mapping
Allowlist/denylist for AI agent tool calls with approval gates for destructive operations. Define which tools the agent can use freely, which require confirmation, and which are…
Host-agnostic, multi-agent code review of the current branch: delegates independent tech-lead, security/correctness/test, and optional UI perspectives, then synthesizes one…
Typosquat and malicious-package detection across installed dependencies (or a single prospective addition) — cross-checks AI-malware family intelligence, package-name similarity…
Drafts a second-line UDAAP review memo for a product, feature, fee, disclosure or customer-experience flow, marketing motion, complaint pattern, or enforcement theme.
Use when: reviewing, designing, implementing, or testing security-sensitive Unicode text handling, UTF-8 decoding, invalid byte sequences, overlong encodings, surrogate handling,…
5 expert personas debate proposed changes before implementation. Catches architectural, security, performance, and UX issues early.
Use when you need to pack a local or remote repository into an AI-friendly reference artifact for research, audits, feature-porting prep, context review, or security-oriented repo…
STRIDE + OWASP-based security audit with optional auto-fix. Scans code for vulnerabilities, categorizes by severity, and can iteratively fix findings using vc:autoresearch pattern.
Use when the user asks to check Veeam backup health across customers, find failing or stale backup jobs, surface workloads past their RPO, triage VSPC alarms, or report per-tenant…
Verify code-review or security-review findings for false positives using deep codebase tracing, framework-aware analysis, and web research.
Post-fix verification — re-scan the repo, gate on `--exploits weaponized --severity high`, recheck the specific CVE against the new installed version, write the verdict to…
Inspect and validate Vertex AI Agent Engine deployments including Code Execution Sandbox, Memory Bank, A2A protocol compliance, and security posture.
Generate OpenVEX / CycloneDX VEX attestations from `.vulnetix/memory.yaml` triage decisions, optionally sign with cosign, optionally upload to Vulnetix and post to a GitHub PR.
End-to-end VPS provisioning — select provider → plan → provision → harden → verify (ssh-check + firewall-diff hard-gate) → handoff.
Use this skill whenever the user needs to manage VMware NSX networking — segments, gateways, NAT, routing, and IP pools.
Use this skill whenever the user needs to manage VMware NSX security — distributed firewall (DFW) policies, security groups, microsegmentation, and IDS/IPS.
Use this skill whenever the user needs to operate a VMware/Omnissa Horizon VDI environment via its Connection Server: list and manage desktop pools, RDS farms and published apps,…
Use when: performing defensive web application security review, web-app vulnerability triage, web-app threat-model review, or validation of web-app security fixes.
Full end-to-end browser testing for local web apps with a persistent logged-in session. Log in once into a named Chrome profile, then drive real flows with trace evidence against…
Launch a comprehensive website audit. Specify a URL or audit the current codebase. Optionally specify categories: seo, accessibility, performance, security, mobile, content,…
Sovereign-grade safety OS for AI coding agents. 45 hooks, 3,440 skills, L1 memory, circuit breakers, and cross-engine enforcement — blocks rm -rf, force push, pipe-to-she — from…
Sovereign-grade safety OS for AI coding agents. 45 hooks, 3,440 skills, L1 memory, circuit breakers, and cross-engine enforcement — blocks rm -rf, force push, pipe-to-she — from…
Run the AI-DLC workflow with the security-patch scope baked in — no scope detection. CVE response. Packaging over `/amadeus --scope security-patch`, which works without this skill.
Verifies financial data against source documents, bank statements, contracts
Vehicle cybersecurity engineering per ISO/SAE 21434
Advanced binary exploitation and mitigation bypass
Web application security testing with Burp Suite integration
This skill should be used when the user says "configure hooks", "set up quality gates", "add PostToolUse hook", "set up permission hooks", "create hook configuration", "add…
**DEFAULT for cost analysis spanning LLM tokens, cloud spend, and database query cost — produces a ranked findings list with monthly $-cost estimate, severity, and remediation…
Chief Security Officer mode. Infrastructure-first security audit: secrets archaeology, dependency supply chain, CI/CD pipeline security, LLM/AI security, skill supply cha — from…
CVE and CWE database querying and management
Advanced debugging integration for vulnerability research
quality gates | code review debug audit security eval ui
This skill should be used when the user explicitly invokes `/oracle:mcp-fleet` to set up, extend, or wire multi-workspace MCP server access from Claude Code.