Reliably diff a single macOS kext between two macOS versions (e.g. 26.4.1 vs 26.5) when both kexts ship inside the kernelcache. Use when: (1) you need to confirm whether a kext was actually changed across a point release (kext CFBundleVersion is unreliable in macOS 26+: bumps with no code change, AND code changes with…
When the user wants to analyze automotive requirements, check INCOSE/EARS compliance, review MISRA-C code, assess ADAS levels, or verify ISO 26262/AUTOSAR/SOTIF conformance. Also use when the user says 'check requirements', 'EARS check', 'INCOSE analysis', 'MISRA check', 'ASIL assessment', 'V-model check'…
Operate the Rhombus physical-security platform (cameras, access control, sensors, alerts, footage) from the terminal using the official rhombus CLI. Use when a task involves checking camera or device status, pulling alerts or events, reviewing or stitching footage, managing access control, or automating anything in a…
Comprehensive GitHub repo analysis covering architecture, OWASP Top 10 security scanning (with file path + line number + fix), 4-dimension strategic value assessment (cost savings, efficiency, startup opportunities, community impact), auto-competitor discovery, and optional Traditional Chinese audio review via…
Pre-push gate for the current branch's diff. Runs review-plan-v2's deterministic analyzers (gitleaks, markdownlint, actionlint, shellcheck, ruff, structural) with --static-only, then the CodeRabbit CLI for the actual review. No API keys, nothing billed to you, and no diff leaves the machine on the first leg. The…
Whole-codebase code quality audit system with 9 specialized sub-skills covering security, SOLID principles, architecture, error handling, performance, test quality, code smells, design patterns, and framework best practices. Produces a scored health dashboard (0-100 per category), severity-rated findings (P0-P3) with…
Cortex XSOAR content pack development lifecycle - create packs, integrations, scripts, playbooks, run demisto-sdk lint/validate/pre-commit, build zip packs, manage versions and release notes, run unit tests, deploy to XSOAR instances, manage git branches/tags, handle marketplace vs local pack workflows. Use when the…
Use when the user says something like "add login", "users need to sign in", "I want auth", "gate this behind a user account". The auth surface (login / signup / OAuth / sessions) is NOT something you build. Read this whole page before touching auth code.
Audit AI agent skills for security vulnerabilities. Use when scanning installed skills against the OWASP Agentic Skills Top 10, checking skills before running them, gating CI/CD on skill safety, or generating audit reports (text, JSON, SARIF, HTML) for stakeholders.
A security review method for an external coding-agent skill file. It looks for prompt injection, credential theft, unsafe code execution, misleading names, and social-engineering tactics before installation.
CTF pwn solving workflow for Codex with tmux-CLI-driven persistent-GDB live debugging: protection checks, libc/loader matching, IDA or idalib reverse engineering, pwntools wrappers, mandatory GDB-pwndbg inferior-tty step debugging, heap/stack/libc state inspection, and exploit strategy selection by primitive, glibc…
Vet ClawHub skills before installation. Use when the user asks about evaluating, auditing, or safely installing OpenClaw/ClawHub skills, or when a skill’s trustworthiness is in question.
Collect natural-language environment context and generate evidence collection guidance for Mandate 2.2.3 Secure Training and Fine-Tuning. Use when code is insufficient and operational proof is required for final compliance evaluation.
Business logic vulnerability playbook. Use when reasoning about workflows, race conditions, price manipulation, coupon abuse, state machines, and multi-step authorization gaps.
KENSHO (検証) — industry-grade playbook for offensive Web3 security assessment and responsible disclosure, covering EVM smart contracts / DeFi and Rust/Solana consensus & validator code. Usable by individual researchers, audit teams, and security firms. Invoke when a target is named (project, handle, repo, or website)…
Full-spectrum security audit for any project — SAST, DAST, SCA, secret scanning, IaC security, container hardening, IAM/RBAC review, threat modeling, and API security. Step-by-step investigation with context-gathering questions before scanning. Produces triage findings, autofix patches, and a structured report.
Reverse engineering meta-cognitive activation engine. Manages attention allocation, noise suppression, task-mode routing, object typing, hypothesis branching, mental model switching, and analysis boundary judgment at a meta level. Use when performing reverse engineering, binary analysis, malware analysis, obfuscation…
★not rated 5 1mo agoA136 tokens
originalMIT
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: