Use this skill when validating a backend API or WebSocket endpoint end-to-end, including acquiring an OIDC bearer token for authenticated calls. Trigger whenever the user asks to test/validate/smoke-check a backend, write a Hurl test, hit a WebSocket, acquire…
Skills in this repository
aibot88/sec_skill_store - Page 9
SkillsMP has collected 2,449 skills from aibot88/sec_skill_store. Open a skill to review its source and details.
aibot88/sec_skill_storeShowing 40 of 2,449 collected skills.
Champion prioritization of discovered opportunities. Advocates for the most impactful, actionable items based on team velocity, business value, and technical feasibility.
Consulta a documentação completa do Backstage (Spotify's developer portal, CNCF) em 489 markdown pages locais offline. Use SEMPRE que o usuário perguntar sobre Backstage — instalação, plugins, frontend system (alpha), backend system, software catalog,…
Source text: Portuguese
Plan and run backups, set recovery objectives, and run disaster recovery drills. Use this skill when defining RPO/RTO targets, designing backup architecture, deciding what to back up and how often, planning for full-region or platform outages, or running a…
Implement backup strategies, disaster recovery plans, and data restoration procedures for protecting critical infrastructure and data.
Summarizes WeChat group chat highlights into a structured digest using the local wx-cli binary (https://github.com/jackwener/wx-cli). Generates a normal digest by default; a roast (毒舌) version is opt-in. Maintains per-group history (history.json +…
Authentication scaffolding Laravel — Breeze (Blade+Alpine ou React/Vue), Jetstream (Livewire ou Inertia, Teams, 2FA) e Fortify (headless). Usar quando configurar login, registo, passwords, guards ou middleware de autenticação. Requer 01-base-laravel.md como…
Source text: Portuguese
Excelência em contentores Docker — Dockerfile, Docker Compose (Compose Specification), BuildKit, redes, volumes, secrets, healthchecks, multi-stage builds, segurança de imagens, CI com buildx e boas práticas oficiais. Ativar para: criar ou rever Dockerfiles,…
Source text: Portuguese
Use for writing JavaScript/TypeScript code with the Base44 SDK in EXISTING projects. Triggers: user wants to implement features, build functionality, or write code using Base44; code uses '@base44/sdk' imports; user mentions SDK methods like base44.entities,…
Use this skill to drive a batch of suspected bugs in microsoft/apm from raw issue list to mergeable PR queue. Fan out one triage subagent per issue (LEGIT / UNCLEAR / FIXED-AT-HEAD), cross-reference legit issues against open PRs, then branch: in-flight…
Red vs Blue team security competition orchestrator. Runs long-running overnight battles with 1000s of interactions, scoring, and insight generation.
Detect whether a beads installation needs migration from classic format (SQLite/JSONL) to Dolt.
Migrate a beads installation from classic format (SQLite/JSONL on beads-sync worktree branch) to the new Dolt-based format.
Multi-language code quality standards for TypeScript, Python, Go, and Rust. Enforces type safety, security, performance, and maintainability with progressive enforcement. Use when writing, reviewing, or refactoring code across any of these languages.
Guidelines and best practices for building applications with [Beefree SDK](https://docs.beefree.io/beefree-sdk), including installation, authentication, configuration, customization, and template mana
The hacker mindset - finding vulnerabilities and breaking systems to make them stronger
Cross-cutting best practices enforcement across code, templates, skills, prompts, scripts, documentation, pages, and design. The enforcement layer that catches violations any specialist might miss. Do NOT use for deep code review methodology (use…
Scaffold and review a new BFrost worker without touching the core. Use when the user asks to "add a worker", "create a BFrost worker", "build a publisher/producer/consumer for the Item Bus", or otherwise extend BFrost with a new capability. Enforces the…
Apply David Bianco's threat hunting frameworks including the Pyramid of Pain and Threat Hunting Maturity Model. Emphasizes prioritizing detection by adversary cost and building mature hunting programs. Use when designing detection strategies or assessing…
Expert assistance for Azure Bicep infrastructure-as-code. Provides best practices for authoring Bicep templates, Azure resource type discovery with API versions, resource schema retrieval, and Azure Verified Modules (AVM) guidance. Use when writing Bicep…
GCPプロジェクト単位でBigQuery認証を設定。gcloud設定プロファイルで複数プロジェクトを安全に分離管理。「BigQueryに繋ぎたい」「{プロジェクト名}のデータを見たい」と言うだけで認証をガイド。
Source text: Japanese
Use when: billing audit, subscription lifecycle review, Stripe/Paddle integration check, webhook security, payment form CSRF, pricing centralization, webhook idempotency, billing bugs. Triggers: 'audit my billing', 'check subscription flow', 'is my checkout…
Query bioRxiv/medRxiv preprints via REST API. Search by DOI, category, or date range; retrieve metadata (title, abstract, authors, category, DOI, version history) and PDFs. No auth. For peer-reviewed biomedical use pubmed-database; broader scholarly search…
Покрывает контроллеры D7 на базе Bitrix\Main\Engine\Controller и JsonController — actions, автосвязывание параметров, фильтры ActionFilter (Authentication, Csrf, HttpMethod, Scope, CloseSession, ContentType), ошибки через addError/ErrorCollection,…
Source text: Russian
Покрывает прямую работу с базой Bitrix — Application::getConnection(), Connection, MysqliConnection, SqlHelper, SqlExpression, сырые SQL-запросы через query()/queryExecute()/queryScalar(), транзакции (startTransaction/commitTransaction/rollbackTransaction),…
Source text: Russian
Покрывает DI-контейнер Bitrix\Main\DI\ServiceLocator (PSR-11) — регистрация сервисов в секции services файла .settings.php модуля, autowire, получение зависимостей через has()/get(), constructor injection в сервисах и параметрах action-методов контроллеров,…
Source text: Russian
Business performance and context analysis for CX projects. Diagnoses a company's health across five domains — revenue, customer metrics, operational health, market position, and org capability — then surfaces key tensions and the strategic implications for…
Blockscout MCP tool reference for on-chain data queries. Covers all 16 tools: address info, transactions, token transfers, NFTs, contract ABI/source, read-only calls, ENS resolution, and block data across 8+ chains. TRIGGER when: user asks about on-chain…
Review and improve the blog post draft for clarity, engagement, and authentic voice.
Create/update Markdown blog posts and topic metadata for this Next.js static-export blog (multi-language en/tr). Use when adding/editing files under content/posts/**, updating post/topic indexes, choosing valid topic colors, and creating 1200x630 WebP…
Review blog content for authentic voice and tone. Checks if content sounds like Fabio's conversational, honest technical writing style. Trigger phrases: "voice", "voice review", "tone", "sounds like me", "authentic", "check voice", "voice check"
Plan and execute Bluesky growth strategy for audience building on the decentralized platform. Use when developing starter pack strategy, creating custom feeds, building community presence, or planning cross-platform promotion. Includes the three-feed system,…
Interact with Bluesky social media from the command line. Use this skill whenever the user wants to read or write Bluesky posts, search content or users on Bluesky, manage their Interact with Bluesky social media from the command line. Use this skill whenever…
Push the LLM to reconsider, refine, and improve its recent output. Use when user asks for deeper critique or mentions a known deeper critique method, e.g. socratic, first principles, pre-mortem, red team.
Unified story creation and enrichment engine (story-spec v2). Produces implementation-ready stories with real-data confrontation (provider/DB/cloud), external research (docs/RFC/gotchas), structured NFRs (7 categories), binary security gate, observability…
Authors and updates customization overrides for installed BMad skills. Use when the user says 'customize bmad', 'override a skill', 'change agent behavior', or 'customize a workflow'.
Assesses Non-Functional Requirements (security, performance, reliability, maintainability, observability) with evidence-based codebase analysis. Scans actual code for patterns, scores each aspect, and produces a structured assessment saved as a tracker…
Orchestriert den kompletten BMAD-Entwicklungszyklus als automatische Pipeline: bmad-create-story → bmad-testarch-atdd → bmad-dev-story → bmad-testarch-test-review → bmad-code-review → bmad-security-review (Kassandra, conditional), jeweils in frischem Kontext.…
Source text: German
Systematic PRD validation against quality standards. Validates format, information density, coverage, measurability, traceability, implementation leakage, domain compliance, project type requirements, SMART criteria, and holistic quality. Produces detailed…
Desktop application business validation gate. Executes each Validation Metier item against a real desktop app environment (test framework, local binary, logs, file system), collecting tangible proof. Binary verdict: ALL pass = Done, ANY fail = stays in…