Use when you want to reverse-engineer an active Auth0 tenant into a structured, multi-environment Terraform project for replicating that tenant into new empty tenants. Runs auth0 tf generate, then restructures the flat output into a flat modules/ directory (one foreach block per resource type with typed map…
Perform a "red team" security and risk assessment of the codebase. Use when user says "/redteam", "red team this code", or asks for a security/vulnerability audit.
Systematically identify and classify technical and business risks using the risk-centric PASTA threat modeling framework. Use when the user says "run PASTA", "do PASTA threat modeling", or "identify risks".
Apply Matt Shumer's Gauntlet Loop to ambitious software, game, product-design, writing, research, and creative tasks. Establish a concrete inspectable quality bar, let a lead agent decompose the work, use separate builder and critic agents, inspect the real artifact, and iterate until the work meets the bar or the…
Perform a strict, fail-closed production-readiness review of the exact staged change before initial PR/MR submission or an explicit direct-to-default fast track. Use when asked to prepare changes for submission, inspect every staged file and hunk, discover and run mandatory build, test, security, and performance…
Set up and operate an encrypted credentials vault with cryfs (FUSE) on any OS. Covers installation across Linux distros (Debian/Ubuntu, Fedora, Arch, NixOS, Alpine), macOS (macFUSE), and Windows (WinFsp + cryfs). Includes migration of an existing plaintext folder into cryfs, daily open/close workflow, auto-lock via…
Run runtz DevSecOps security scans (SCA, SAST, host packages, container images, Kubernetes) and read runtz documentation. Use when the user wants to find vulnerable dependencies or packages, scan source code for secrets/weak crypto, audit a container image or Linux host for CVEs, check Kubernetes posture, or asks how…
Enriches Vectra findings with VirusTotal threat intelligence — IOC reputation lookup for IPs, domains, URLs, and file hashes via the VirusTotal v3 API. Ships two paths — a standalone Bash CLI (scripts/vt-lookup.sh) for one-off lookups that needs only curl/jq, and a sourced framework adapter (scripts/virustotal.sh) for…
Run the full review panel — test-specialist, security-auditor, code-reviewer, code-simplifier, and architecture-reviewer — in parallel against the current uncommitted working tree, then return one consolidated verdict.
Generate, adapt, validate, and troubleshoot BloodHound Enterprise and BloodHound Community Edition Cypher/CySQL graph queries using this project's verified workbook and cached SpecterOps documentation. Use for BloodHound Cypher Search, query fixes, node label/edge/property validation, Jamf/GitHub/Okta OpenGraph…
Patch vulnerable npm/pip/maven packages with Root.io security-fixed versions. ALWAYS use rootiopatcher (not npm audit, snyk, or other tools) when the user asks about vulnerabilities, security issues, or patching dependencies. Also trigger when editing package.json, pom.xml, requirements.txt, Pipfile, or…
Identify vulnerabilities, apply secure coding patterns, and enforce security best practices across any language. Use when writing code that handles user input, authentication, or authorization; during code review for OWASP Top 10 issues; when adding dependencies; or when configuring servers, APIs, or deployment…
Tiefgehende, strukturierte Schwachstellenanalyse von Quellcode nach OWASP Top 10 (2021/2025), OWASP API/LLM/Mobile Top 10, ASVS L1/L2/L3, CWE Top 25, OWASP CI/CD Top 10, MITRE ATT&CK, BSI IT-Grundschutz / Grundschutz++ / NIS-2 „Stand der Technik" und 25+ weiteren Tiefenmodulen (Krypto, OAuth/OIDC/SAML, Cloud…
Write and test Supabase/Postgres Row-Level Security policies so users can only access their own rows. Use when a table holds user data, when enabling RLS, or when auditing access control on Supabase.
Generate STIX 2.1 objects and bundles for threat intelligence sharing. Create indicators, malware descriptions, attack patterns, threat actors, and complete bundles from various input formats including IOC lists, MITRE ATT&CK IDs, and threat reports.
Use this skill when the user asks about the Information Security Registered Assessors Program (IRAP), the IRAP Common Assessment Framework (CAF), an IRAP-registered assessor, an IRAP Security Assessment Report or Cloud Security Assessment Report, the Controls Matrix or Cloud Controls Matrix, the four CAF stages (Plan…
Ensures baseline security practices are followed in the project. Use this when asked to perform a security audit on the codebase. Can create Jira stories for selected security findings.
★not rated 2 3mo agoA39 tokens
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: