Borrowing it
Nothing to install: this file belongs to Jm-Paunlagui/CATHERINE. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/Jm-Paunlagui/CATHERINE/main/.claude/skills/senior-chaos-resilience-engineer/SKILL.mdgit clone --depth 1 https://github.com/Jm-Paunlagui/CATHERINEWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/jm-paunlagui/catherine/senior-chaos-resilience-engineer)<a href="https://agentmods.dev/skills/jm-paunlagui/catherine/senior-chaos-resilience-engineer"><img src="https://agentmods.dev/badge/skills/jm-paunlagui/catherine/senior-chaos-resilience-engineer/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/jm-paunlagui/catherine/senior-chaos-resilience-engineer"><img src="https://agentmods.dev/badge/skills/jm-paunlagui/catherine/senior-chaos-resilience-engineer.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00117 | $0.01157 |
| Opus 5 | $0.00059 | $0.00579 |
| Sonnet 5 | $0.00023 | $0.00231 |
| Haiku 4.5 | $0.00012 | $0.00116 |
Grade A, and why
senior-chaos-resilience-engineer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 60 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Senior Chaos & Resilience Engineer
Chaos engineering is hypothesis-driven experimentation on a production-like system to surface latent weakness before customers do. Not random destruction. Every experiment has a hypothesis, a blast radius, a rollback plan, and a measured outcome.
Resilience patterns (enforce in design review)
- Timeouts everywhere. Every outbound call (Oracle, HTTP, cache, queue) has an explicit per-dependency timeout. Global defaults are a code smell.
- Retries with bounded budget. Exponential backoff with jitter, capped retries, and a retry budget (e.g., max 10% of traffic retrying) to avoid retry storms.
- Circuit breakers on every external dependency. Open → half-open → closed. Surface state in
/health/deps. - Bulkheads. Isolate pools per dependency — this is why the reporting Oracle pool starving must not take down the auth Oracle pool (dual-pool pattern).
- Graceful degradation. Identify which features can serve stale cache, fall back to a replica, or return a degraded response vs. which must hard-fail.
- Idempotency keys on every mutating route that may be retried (especially financial postings).
- Backpressure. Bounded queues, reject-with-429 when full. Never queue unboundedly.
Failure modes to design against
- Oracle pool exhaustion → acquisition timeout → cascading 503
- Slow dependency → thread-pool starvation → P95 collapse
- Single-row hot key → contention → row-lock waits → ORA-00060 deadlock
- Cache stampede on key expiry → thundering herd to Oracle
- DNS failure mid-request → resolver retry storm
- Clock skew → JWT
exprejection on healthy tokens - Disk full → log writes block → request thread hangs
Game day playbook
- Hypothesis: "If Oracle pool A is exhausted, auth continues from pool B with P95 < 500ms."
- Blast radius: non-prod first, single AZ, single tenant.
- Steady-state metric: P95 latency, error rate, business KPI (logins/min).
- Experiment: inject the failure (kill pool A, throttle network, fill disk).
- Abort criteria: explicit, automated. Stop when crossed.
- Outcome: validated / refuted / inconclusive. File a follow-up for any refutation.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 60 lines · 117 tokens per session scan A c8cc5a41bfae
senior-chaos-resilience-engineer is a skill published in the GitHub repository Jm-Paunlagui/CATHERINE (2 stars, last pushed 7d ago), licensed Apache-2.0. It adds 117 tokens to every session and 1,157 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-05.
Other skills, from other repositories
gke-ai-troubleshooting-jobset-interruption
Diagnoses GKE JobSet interruptions, restarts, and preemptions for AI/ML training workloads autonomously. Use when troubleshooting JobSet restart loops, spot VM preemptions, node readiness failures, host VM issues, or coordinator worker crashes. Don't use for general GKE cluster creation, basic workload deployment, or…
gke-workload-troubleshooting
Diagnoses GKE workload failures (CrashLoopBackOff, OOMKilled, ImagePullBackOff, Pending, etc.) via logs and events. Use when pods fail to start or crash repeatedly. Don't use for GKE cluster infrastructure provisioning, node pool creation, or non-Kubernetes Google Cloud services.
gke-node-notready
Diagnoses GKE nodes reporting NotReady or Unknown status by inspecting node conditions, events, kubelet/containerd logs, and node metrics, then proposing safe remediations. Use when nodes show NotReady, when the kubelet stops posting node status, or when workloads are evicted or stuck Pending due to node health. Don't…
gke-ai-troubleshooting-handle-disruption-gpu-tpu
Diagnoses, predicts, and mitigates node disruptions during Compute Engine host maintenance and hardware or software maintenance events for GPU and TPU workloads on GKE. Use when diagnosing node disruptions, predicting host maintenance events on GPU/TPU nodepools, inspecting node interruption PromQL metrics, auditing…
agentcore-investigation
Investigate Bedrock AgentCore runtime sessions via CloudWatch Logs Insights — resolve session/trace IDs, query OTEL spans, filter noise, build timelines. Use when debugging AgentCore agent sessions, tracing tool calls, or analyzing latency.
troubleshoot-sandbox
Troubleshoot OpenSandbox issues by running diagnostics (logs, inspect, events, summary) via CLI or HTTP API to diagnose sandbox failures like OOM, crash, image pull errors, network problems, etc.