Skip to main content
kalshamsi
ملف منشئ GitHub

kalshamsi

عرض على مستوى المستودعات لـ ٢٧ skills مجمعة عبر ٣ مستودعات GitHub.

skills مجمعة
٢٧
مستودعات
٣
محدث
٧ يوليو ٢٠٢٦
مستكشف المستودعات

المستودعات و skills الممثلة

premortem-plan-check
متخصصو إدارة المشاريع

Before finalizing any plan, run a premortem — assume the plan has already failed, list the likeliest causes, and reshape the plan with mitigations before presenting it. Use this whenever producing something that will be executed later: project plans,…

٧ يوليو ٢٠٢٦
reversibility-check
متخصصو إدارة المشاريع

Before executing any hard-to-reverse or destructive step, classify it as a one-way or two-way door; for one-way doors, substitute a reversible alternative or get explicit confirmation, and order work so mistakes can be undone. Use this whenever a plan or…

٧ يوليو ٢٠٢٦
stop-and-reassess
مطوّرو البرمجيات

After two failed attempts at the same problem, stop and diagnose before trying again — never make a third attempt built on the same assumption. Use this whenever an approach has failed twice in a row, whenever you notice yourself making similar edits,…

٧ يوليو ٢٠٢٦
answer-first-structure
متخصصو إدارة المشاريع

Decide the bottom line before writing and put it in the first sentence, with only decision-relevant support after it. Use this whenever producing anything a reader will consume to decide or act — reports, emails, summaries, memos, recommendations, status…

٧ يوليو ٢٠٢٦
assess-before-acting
مطوّرو البرمجيات

Classify the user's intent before producing anything. When a message describes a problem, shares something that "seems off" or "doesn't look right", asks "what do you think", "does this make sense", "why is this happening", or thinks out loud without…

٧ يوليو ٢٠٢٦
assumption-audit
متخصصو إدارة المشاريع

Before finalizing any analysis, recommendation, or decision made under incomplete information, surface the load-bearing assumptions, tag each as supported or unsupported by the given evidence, and stress-test the conclusion against the weakest one. Use this…

٧ يوليو ٢٠٢٦
calibrated-claims
متخصصو إدارة المشاريع

Attach explicit, evidence-tied confidence to every load-bearing judgment instead of asserting flatly or retreating into "it depends". Use this whenever the task involves a forecast, an estimate, a feasibility or go/no-go call, a deadline or risk question, or…

٧ يوليو ٢٠٢٦
finish-the-turn
مطوّرو البرمجيات

Audit the final section of a response before ending the turn - if it promises work, lists next steps the assistant could do itself, or defers with "let me know if...", do that work now instead of ending. Use this on every long, tedious, or multi-part task…

٧ يوليو ٢٠٢٦
عرض 8 من أصل ١٤ skills مجمعة.
pci-dss-audit
محللو أمن المعلومات

Use when auditing code for PCI-DSS v4.0 compliance, reviewing cardholder data handling, checking credit-card storage and transmission, hunting PAN logging, or answering "is this code PCI-compliant?".

١٦ أبريل ٢٠٢٦
docker-scout-scanner
محللو أمن المعلومات

Use when scanning Docker images for CVEs, auditing Dockerfiles for misconfigurations, reviewing base image choices, generating container SBOMs, hardening docker-compose configurations, or any container/OCI security concern.

١٦ أبريل ٢٠٢٦
bandit-sast
محللو أمن المعلومات

Use when scanning Python code for security vulnerabilities, running Bandit, performing Python SAST, auditing Python security bugs, or reviewing Python source for injection, weak crypto, or insecure deserialization.

١٦ أبريل ٢٠٢٦
mobile-security
محللو أمن المعلومات

Use when auditing an Android or iOS application for security issues, reviewing React Native or Flutter code, checking mobile authentication or insecure data storage, or covering the OWASP Mobile Top 10:2024.

١٥ أبريل ٢٠٢٦
security-headers-audit
محللو أمن المعلومات

Use when reviewing HTTP security headers, checking a Content-Security-Policy, auditing CORS or HSTS configuration, evaluating X-Frame-Options or Permissions-Policy, inspecting header middleware, or hardening a web application's response headers.

١٥ أبريل ٢٠٢٦
security-test-generator
محللو ضمان جودة البرمجيات والمختبرون

Use when writing security tests for a web application, building a vulnerability regression suite, creating pentest-style automated tests, generating runnable injection/XSS/auth test code, or adding security coverage to an existing test suite.

١٥ أبريل ٢٠٢٦
api-security-tester
محللو أمن المعلومات

Use when auditing REST or GraphQL API endpoints, checking API authentication and authorization, hunting BOLA or broken access control, reviewing rate limiting, or covering the OWASP API Security Top 10.

١٥ أبريل ٢٠٢٦
socket-sca
محللو أمن المعلومات

Use when scanning project dependencies for supply-chain risk, running Socket SCA on npm/pip/pypi packages, hunting typosquats or malicious packages, or auditing third-party dependency health before a release.

١٥ أبريل ٢٠٢٦
عرض 8 من أصل ١١ skills مجمعة.
عرض ٣ من أصل ٣ مستودعات
تم تحميل كل المستودعات