Detects and prevents code injection attacks targeting serverless functions (AWS Lambda, Azure Functions, Google
Spearphishing targets specific individuals using personalized, researched content that bypasses generic spam
Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned
Detects suspicious use of assertions for security checks that can be disabled in production builds. Use when analyzing assertion usage, security checks, or investigating…
Detect abuse of elevation control mechanisms including UAC bypass, sudo exploitation, and setuid/setgid manipulation
Detects type confusion vulnerabilities by identifying unsafe type casts, vtable corruption, and polymorphism issues.
Detects use-after-free vulnerabilities by identifying pointer dereferences after memory deallocation.
Generic detection rule creation and management using Sigma, the universal SIEM rule format. Sigma provides vendor-agnostic detection logic for log analysis across multiple SIEM…
Expert-level guide to dev threat modeling continuous. Comprehensive coverage of advanced concepts, production implementation, and optimization strategies.
综合生成工具专业版,面向专业团队的全模态AI生成平台。核心能力: - 40+ 模型全覆盖(图片、视频、音频三大模态) - 高质量图片生成(seedream-4。Use when 需要视频处理、音频编辑、媒体转换、配音生成时使用。不适用于版权受保护的媒体内容处理. — from thcjp/hermes-skills
综合生成工具专业版,面向专业团队的全模态AI生成平台。核心能力: - 40+ 模型全覆盖(图片、视频、音频三大模态) - 高质量图片生成(seedream-4。Use when 需要视频处理、音频编辑、媒体转换、配音生成时使用。不适用于版权受保护的媒体内容处理。适用于独立开发者、企业团队和自动化工作流场景。 — from…
Atualização INCREMENTAL da documentação project-doc — mapeia o diff do trabalho recente pros docs afetados (via scope inverso) e re-projeta SÓ eles, sem re-mineração completa.
Analiza la jerarquía de archivos de un repositorio técnico de fabricante de componentes electrónicos, construye un grafo semántico de relaciones entre documentos, y define el…
Escribe tutoriales completos en lenguaje natural para proyectos de domótica, contextualizados en escenarios reales de automatización del hogar con integración Home Assistant.
Erkennt Fristen und Eile-Signale in Mandantenanfragen: Hauptverhandlung naechste Woche, Kuendigungsfrist laeuft, Haftungsfalle, Zwangsvollstreckung, Insolvenzantrag.
Risikoanalyse im Rahmen der DSFA: Eintrittswahrscheinlichkeit mal Schadenschwere für Bedrohungsszenarien systematisch ermitteln.
Risikoanalyse im Rahmen der DSFA: Eintrittswahrscheinlichkeit mal Schadenschwere fuer Bedrohungsszenarien systematisch ermitteln.
Legal Due Diligence für M&A-Transaktionen: Prüft Corporate, Vertragswerk, HR, IP, Litigation und Compliance im Datenraum. Normen: §§ 311 Abs.
逆向防御方实现 → 红队针对性绕过。把 EDR / Defender / AV 的 hook 表、ETW provider、AMSI 实现先逆向出来, 再写针对性的 unhook / 间接 syscall / ETW patch / call stack spoof。对照 MITRE ATT&CK T1562 防御规避。 触发关键词:EDR 绕过、AV…
Use when bypassing EDR/AV to run a payload — hook unhooking, direct/indirect syscalls, PPID spoofing, process injection, AMSI bypass, ETW patching, memory/sleep encryption,…
Generate diagrams from natural language using EdrawMax AI APIs. Supports four diagram types: flowchart (流程图), infographic (信息图), Gantt chart (甘特图), and mind map (思维导图).
Edrone integration. Manage data, records, and automate workflows. Use when the user wants to interact with Edrone data.
Elastic Stack を用いた Active Directory ログ分析・脅威検知支援スキル。Elasticsearch クエリ、Logstash パイプライン、Kibana 可視化を通じて、Windows イベントログおよび Sysmon ログの多角的な脅威検知を実現します。Active Directory…
Live endpoint threat hunting skill. Systematically scans a system for malicious activity across all categories (Process, File, Network, Persistence, User Account, Registry, etc.)…
Audit environmental software for EPA reporting (CEDRI, NetDMR, RCRAInfo), Clean Air Act (Title V, NESHAP, CEMS, TRI), Clean Water Act (NPDES, SWPPP, SPCC), RCRA hazardous waste…
Escribe o mejora prosa técnica que se lee y se acepta — ADRs, READMEs, PR bodies, devlogs, guías, explicaciones y secciones de docs.
多源文献聚合检索:PubMed + PMC + 预印本(bioRxiv / medRxiv / ChemRxiv / Research Square)+ NCBI Bookshelf + 专利 一次调用,自动 PMID/PMCID/DOI 三级去重。用于医学 RAG 知识库广召回、全文 OA 链接发现、资助信息检索。返回完整元数据(OA…
Evaluates and selects Threat Intelligence Platform (TIP) products based on organizational requirements including
Animate a named or official mascot using the exact user-supplied SVG while preserving its identity. Use when the mascot asset must not be redrawn, substituted, approximated, or…
Sessione interattiva su canvas Excalidraw bidirezionale. Usa questa skill quando l'utente vuole discutere visivamente di un'idea, fare brainstorming su un canvas, disegnare…
Read and write Excel files via Microsoft Graph API. Manage workbooks, worksheets, and cells in OneDrive/SharePoint.
Drive a federal system through the NIST Risk Management Framework (SP 800-37 Rev 2) to an Authorization to Operate (ATO): Prepare, Categorize (FIPS 199), Select a control baseline…
Crea extensiones de FacturaScripts delegando al agente especializado `extension-developer`. ACTIVAR SIEMPRE que el usuario pida modificar el comportamiento de modelos,…
Bewertung von Grundvermoegen fuer Zwecke der Erbschaft- und Schenkungsteuer — Vergleichswertverfahren Ertragswertverfahren Sachwertverfahren nach §§ 176 ff.
Off-Label-Use bei Long-COVID und ME/CFS Erstattung durch gesetzliche Krankenversicherung GKV. § 35c SGB V Off-Label-Liste § 92 Abs. 1 SGB V Richtlinie Methodenbewertung.
GEAS-Reform EU-Asyl- und Migrationsmanagementverordnung 2024/1351 EU-Asylverfahrensverordnung 2024/1348 EU-Grenzverfahrensverordnung 2024/1349 ab 12.6.2026 anwendbar.
Generate images via fal.ai and BytePlus Seedream APIs. Supports single image, batch parallel, and reference-guided generation.
Triage a Falco security-event notification on Hop — classify false-positive vs real, then fix by image-bake or rule exception
Assess FedRAMP/StateRAMP readiness — impact levels, control baselines, 3PAO requirements
FedRAMP 20X modernization expert. Provides guidance on Key Security Indicators (KSIs), continuous monitoring automation, machine-readable policies, and the new automated…
Validates FedRAMP Plan of Action and Milestones (POAM) files for structural integrity, naming conventions, deduplication, and cross-sheet consistency
FedRAMP Rev 5 authorization expert. Provides guidance on traditional authorization paths, SSP/SAP/SAR/POA&M documentation, NIST 800-53 Rev 5 control implementation, and 3PAO…
Expertise on FedRAMP SSP authoring — what the DOCX templates contain, what OSCAL 1.2.0 SSP looks like for FedRAMP, how this plugin fits alongside Compliance Trestle and oscal-cli.
Fetch live per-token, per-image, and per-GPU-hour prices for foundation models across Anthropic, OpenAI, Google, AWS Bedrock, Azure OpenAI, OCI Generative AI, and Vertex AI.
「Box にあったあの資料」「先週共有された PDF」「<キーワード>含むファイル」「あの議事録どこ」「あの Google Doc」「Sheets の 」「Google Slides で説明したやつ」「あの Gmail」「Gmail に来てた件」「Google Calendar の予定」と頼まれたら、opshub MCP の search…
Break any problem down to fundamental truths, then rebuild solutions from atoms up. Use when user says "firstp", "first principles", "from scratch", "what are we assuming", "break…
Descompone un fix grande en porciones atomicas cuando el cambio es demasiado amplio para resolverse de una sola vez.
Resuelve bugs, ajustes visuales, refactors y mejoras de comportamiento en el proyecto. Usa esta skill SIEMPRE que el usuario mencione fix, bug, error, no funciona, arreglar,…
Procesa las herramientas e instrucciones de flasheo de un repositorio de fabricante y crea guías interactivas paso a paso para flashear firmware en microcontroladores ESP32 sin…
How DevSecOps thinks about threats — STRIDE categories, attack surface mapping, trust boundaries, and producing actionable security requirements (not "be secure")
Redrafts user-provided text into formal, binding legal language for contracts, policies, or codes of ethics.
Pure mathematical structure. Sets, groups, rings, fields, topology — the formal bedrock everything else rests on.
> French tax audit procedures, penalties, and taxpayer rights (contrôle fiscal). Trigger on phrases like \"contrôle fiscal\", \"vérification de comptabilité\", \"redressement…
Analyzes FedRAMP FRMR documents to extract control mappings, KSI entries, and version changes. Use when the user asks about FedRAMP requirements, control mappings, compliance…
Import any CSV stream into a Fulcra account as annotations — body weight, mood scores, expenses, sleep, media plays, anything timestamped.
Internal fetcher module for Google Docs and Sheets. Fetches content via MCP (preferred, when available), Google API with bearer token or public URL export (fallback), or browser…
Generate AI images using ByteDance's Seedream 4.0 API. Use when user wants to create, generate, or make images from text descriptions, especially for professional graphics,…
Migrate AI image generation from Google Gemini 2.5 Flash to BytePlus SeeDream v4.5. Use when: (1) User wants to switch from Gemini to SeeDream/BytePlus for image generation, (2)…
Generates structured cyber threat intelligence reports at strategic, operational, and tactical levels tailored
Genere un fichier Zoom SQL (.dhsp) complet avec les 27 procedures obligatoires du cycle de vie ecran CRUD (creation, modification, suppression, consultation).