Markdown sanitization order matters — marked.js then DOMPurify then Mermaid to prevent XSS
Use when when you have mass spectrometry data stored in non-standard formats (SQLite, HDF5, custom binary) that pymzML does not natively support, and you want to enable…
Autonomous mobile security audit aligned with OWASP MASTG v2. Performs checklist-driven analysis across MASVS categories: storage, crypto, network, platform, code, resilience,…
Review a mobile app (Android/iOS) against the OWASP MASVS control groups — storage, crypto, auth, network, platform, code quality, and resilience — producing a per-control finding…
Guidance for file picker, file system helpers, bundled assets, and app data storage in .NET MAUI applications.
Add secure storage to .NET MAUI apps using SecureStorage.Default. Covers SetAsync, GetAsync, Remove, RemoveAll, platform setup (Android backup rules, iOS Keychain entitlements,…
Maven build expertise for this multi-module Java project. Use when working with pom.xml files, managing dependencies, running builds or tests for specific modules, configuring or…
OWASP MCP Top 10 vulnerability knowledge base for identifying, assessing, and remediating security risks in Model Context Protocol environments.
Full-text search across structured Markdown documentation archives using SQLite FTS5. Use when you need to search large collections of Markdown articles that are separated by \
Lokale, private Erfassung medizinischer Daten: Diagnosen, Symptomverläufe und Untersuchungspläne. Kein BACH-Origin — Eigenentwurf mit eigenem SQLite-Store.
Mema's personal brain - SQLite metadata index for documents and Redis short-term context buffer. Use for organizing workspace knowledge paths and managing ephemeral session state.
Auto-escalating multi-tier memory search that cascades from in-memory cache through SQLite, grep, and LanceDB vector search to find the best answer with minimal latency.
Move data into PostgreSQL with declarative load files, built-in type conversion, and repeatable migration runs before one-off import scripts become cutover risk.
Migrate a TinyBase table to SQLite. Use when asked to move a data domain (e.g. templates, vocabs) from the TinyBase store to the app SQLite database.
Use when creating or editing files in pkg/migration/. Covers cross-DB type safety across MySQL/PostgreSQL/SQLite, DDL error handling, time-column conventions, and path…
Use dogsheep/github-to-sqlite when an agent needs a local, queryable snapshot of GitHub activity instead of bouncing through the web UI or ad hoc API calls.
OWASP Machine Learning Top 10 vulnerability knowledge base for identifying, assessing, and remediating security risks in machine learning systems.
AI/LLM defensive security reference: prompt-injection defense, OWASP LLM Top 10 defensive mapping, MCP and agentic tool-call hardening, training-data poisoning detection,…
OWASP Top 10 security checklist, authentication patterns, input validation, and HTTP security headers reference.
DevSecOps, container, and API operational defensive security reference: CI/CD pipeline hardening, secret scanning, IaC misconfiguration detection, SAST/DAST integration, container…
Run a complete mobile app pre-launch verification — chains performance audit, QA testing, OWASP mobile security review, App Store and Play Store compliance checks, and store…
Implement offline-first mobile apps with local storage, sync strategies, and conflict resolution. Covers AsyncStorage, Realm, SQLite, and background sync patterns.
Mobile offline-first architecture with local databases, CRDT conflict resolution, and background sync.
Mobile application security skill for implementing OWASP MASVS compliance, secure storage, certificate pinning, biometric authentication, and security hardening across iOS and…
Audit mobile apps against OWASP Mobile Top 10 (M1-M10): credential hardcoding, supply chain dependencies, insecure auth/token storage (Keychain/Keystore), input validation (deep…
OWASP Mobile Top 10 vulnerability knowledge base for identifying, assessing, and remediating security risks in mobile application environments.
Comprehensive threat modeling for multi-agent systems using CSA MAESTRO 7-layer framework and OWASP Multi-Agentic System Threat Modeling Guide v1.0.
Query Midea MX / 美信 local message cache through the MX local HTTP query service from Codex. Use when the user asks to read MX sessions, search chat history, search messages…
Companion playbook for direct datastore and state inspection after actions in an AI-native workflow. Use alongside ai-native-workflow when API, worker, or UI actions should be…
Performs a comprehensive security review of code changes in a GitHub PR or issue. Checks out the branch, analyzes changed files against a 9-category security checklist, and…
Reviews NetSuite SuiteScript 2.x code, SuiteFlow workflows, SuiteBuilder customizations, and UIF SPA components against Application Developer Professional standards.
Static-review flashlight for NetSuite SuiteCloud Development Framework projects and SuiteScript 2.x code.
Configure and audit Salesforce network security controls — trusted IP ranges (org-wide Network Access), login IP ranges on profiles, CSP Trusted Sites for Lightning components,…
資安工程師 Nina — OWASP Top 10、XSS/CSRF/SQL injection、API Key、Supabase RLS、個資合規。Use when user mentions 資安/security/OWASP/XSS/CSRF/SQL injection/SQL 注入/API Key/.env/Supabase…
Enforces five non-negotiable quality pillars that counter the shortcuts an agent takes under training pressure: complete reporting (show ALL items, never filter unilaterally),…
No-nonsense task manager using SQLite. Track tasks with statuses (backlog, todo, in-progress, done), descriptions, and tags.
Use when adding authentication and authorization to a Node.js service, hardening its HTTP surface, or running an OWASP-style security review after the service scaffold exists and…
Set up RAG pipelines, vector indexing, document ingestion, ChromaDB/FAISS/SQLite-vec search, and knowledge base creation in NodeTool.
Skill para produzir uma plataforma de pesquisa NPS com PHP Slim, SQLite, HTMX, VanJS e Squeleton.dev, incluindo home showcase, admin completo, widget embed e gatilhos de exibição.
Initialise le projet Nudge de zéro avec Expo, expo-router, TypeScript, NativeWind, Drizzle ORM, expo-sqlite, et configure WebStorm pour un confort optimal.
Hardening OWASP para Nuxt 3/4/5 (SSR/SSG/híbrido): headers/CSP, cookies, SSR isolation, validação, rate limit, CORS e proteção de segredos (inclui notas para Nuxt 5/Nitro v3).
Use when building NuxtHub v0.10.6 applications - provides database (Drizzle ORM with sqlite/postgresql/mysql), KV storage, blob storage, and cache APIs.
Produces a running multi-agent observability dashboard by deploying the hook capture pipeline, SQLite WAL store, and WebSocket-streaming Vue client — then validates it with a live…
Implement secure Obsidian plugin development practices. Covers credential storage, input validation, XSS prevention, network security, URI handler safety, and Electron security.
Business logic vulnerability testing for web/mobile/API engagements. Covers workflow bypass, state machine violations, multi-step process abuse, price/quantity/discount…
Penetration test and red team report writing methodology. Covers executive summary structuring (risk-led narrative for non-technical readers), technical finding format (title,…
SQL injection testing skill for offensive security assessments and bug bounty hunting. Covers error-based, UNION-based, boolean/time-based blind, out-of-band, second-order, NoSQL,…
Karpathy 스타일 LLM 위키 스킬 oh-my-wiki(omw) 의 설치 안내. 소스를 수집(ingest)해 구조화된 위키를 만들고, 인용(citation)이 달린 답변으로 질의(query)한다.
本地向量记忆系统 - 基于 Ollama + SQLite 的 AI 助手记忆方案。\n 支持:Markdown 记录、向量搜索、本地嵌入、无 API 费用。\n 特点:本地部署、语义搜索、隐私优先。
Quality assurance specialist for security, performance, accessibility, comprehensive testing, and quality standard alignment.
Trigger system backups, restore from backup files, and manage the SQLite database lifecycle. Supports export, import, and incremental snapshot strategies.
Validate every redirect destination against a server-side allowlist so a user-controlled target cannot bounce victims onto an attacker's site.
Offline, zero-API-key search over the full OpenAlex academic corpus — 284M+ works, abstracts, authors, DOIs in a local SQLite + FTS5 index.
AI Agent Security Suite - Real-time protection against prompt injection, command injection, SSRF, path traversal, secrets exposure, and content policy violations — from…
AI Agent Security Suite - Real-time protection against prompt injection, command injection, SSRF, path traversal, secrets exposure, and content policy violations — from…
QA opencode itself, per case: verify the CLI/terminal (opencode run, db, serve, export), prove a specific plugin hook/action/event fired via the SSE event stream, smoke-test the…
Scenario-first whitebox security vulnerability research using the OpenHack methodology (Hadrian Security).
OWASP Open Source Software Top 10 vulnerability knowledge base for identifying, assessing, and remediating security risks in open source software dependencies.
Authenticates to Microsoft Graph API using MSAL with Mail.ReadWrite and Calendars.ReadWrite permissions.
Systematic audit against the OWASP 2021 Top 10 web application security risks with severity-rated, file-level findings.