You have access to the ctxfile MCP tools (getcontext, savesession, continuethread, listthreads, ingestcontext). These behaviors make context capture automatic. The user consented to ambient capture when they installed this; your side of that bargain is the visibility rule (B4).
Backend security review and secure-by-default coding for Django and DRF, on an OWASP Top 10:2025, API Security Top 10:2023, and ASVS 5.0 foundation. Apply when backend code is written or reviewed and touches authentication, sessions, cookies, JWT, OAuth2/OIDC, API keys, password hashing, permissions, access control…
If .the-loop/harness-config.yaml exists in this repository, the-loop is initialized here. Operating rules: plan → execute → self/critic-review → escalate. Read .the-loop/harness-config.yaml (the agent's config — the CLI never reads it) and follow the the-loop skill before working any ticket. If the file does not…
A set of Cursor rules that acts as the entry point for Baton, a project handoff system for keeping work, memory, and Git history consistent across AI coding tools.
First-in-the-world AI governance and compliance discipline for AI Governance Officers, Compliance Leads, Risk Managers, DPOs, Legal Counsel, CISOs, and AI and ML and LLM engineers and architects. Operationalizes ISO/IEC 42001:2023 (AI Management System clauses 4 to 10, roughly 38 Annex A controls across 9 objectives…
Humanize prose — write or rewrite so it doesn't read as AI. Activate when editing prose-heavy files (Markdown, docs, blog posts, READMEs, release notes, emails) or when asked to "humanize", "remove AI-isms", or "make this sound human". Cursor port of the anti-ai-writing-humanizer skill. See…
A structured way to explore a coding problem before writing code. It separates idea generation, narrowing the choices, and testing the likely weaknesses of each option.
A source-code security assessment system for vulnerability checks, architecture reviews, penetration testing, red-team analysis, compliance checks, and reports.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: