Skip to main content
alpha-omega-security
GitHub creator profile

alpha-omega-security

Repository-level view of 56 collected skills across 3 GitHub repositories.

skills collected
56
repositories
3
updated
Aug 28, 2026
repository explorer

Repositories and representative skills

verify
unclassified

Re-run a finding's reproduction against current HEAD, test its attack tree, grade five fixed evidence criteria, and account for every matched design control.

Aug 28, 2026
critic
unclassified

Judge whether a validated finding can affect a real release build, and record the attacker position, preconditions, impact, counterevidence, and facts that could change that conclusion. Finding-scoped and read-only.

Aug 28, 2026
disclose
unclassified

Draft the disclosure content for a finding in GitHub Security Advisory shape. Produces a title, markdown description, affected package block, CVSS vector, CWE list, references, and a suggested-recipients list from CODEOWNERS or git history, then writes them…

Aug 28, 2026
public-issue
unclassified

File a low-severity finding as an ordinary public GitHub issue after explicit analyst confirmation. Use for hardening gaps, defence-in-depth misses, and other bugs that do not warrant coordinated private disclosure.

Aug 28, 2026
report-upstream
unclassified

File a finding on the upstream repository through GitHub's private vulnerability reporting, request the temporary private fork, and push the proposed patch to it when available. Use after disclose has produced a draft and (optionally) patch has produced a…

Aug 28, 2026
security-deep-dive
unclassified

Audit first-party source for security vulnerabilities using an inventory-first, six-step per-sink methodology. Use when you want a thorough scan that distinguishes real findings from pattern matches and records both in a machine-readable report. The target is…

Aug 28, 2026
audit-memory
unclassified

Focused static audit for reachable memory corruption in first-party C, C++, unsafe Rust, native extensions, and FFI boundaries.

Aug 27, 2026
embedded-native
unclassified

Map native languages, extension bridges, build tools, manifests, and dependencies after shallow Git submodules have been initialized. Runs when triage finds native-extension, submodule, or mixed native-language signals.

Aug 27, 2026
Showing 8 of 44 collected skills.
threat-model-authoring
information-security-analysts

Draft phase 3.5 of a threat model from the orientation brief, surface analysis, and maintainer answers. USE WHEN writing threat-model.md to the canonical §1.1–§1.19 structure. Combines concise prose with the §1.7 trust table and contract matrix, §1.8 output…

Aug 11, 2026
threat-model-backtest
information-security-analysts

Backtest phase 3.6 of threat-model production against historical findings before sign-off. USE WHEN a draft model must prove it can uniquely route real reports. Builds a stratified producer-side corpus across components and contract dimensions, clusters large…

Aug 11, 2026
threat-model-sidecar
information-security-analysts

Emit and validate the §1.19 machine-readable companions: threat-model.yaml using schema threat-model-sidecar/v2, and the flat threat-model.json export conforming to schema.json. USE WHEN an orchestrated threat model is ready for publication, automated or…

Aug 11, 2026
threat-model
information-security-analysts

Produce a threat model for a targeted open-source repository or package: its implicit security contract (assumptions, guarantees, disclaimed properties, and known misuses), not an audit, pentest, CVE list, or build-hygiene review. USE WHEN asked to produce,…

Aug 11, 2026
threat-model-triage
information-security-analysts

Triage one inbound vulnerability report, scanner hit, fuzzer artifact, or AI finding against a finished threat model. USE WHEN asked whether a finding is valid or in scope. Applies the §1.1 routing algorithm and §1.17 precedence to assign exactly one closed…

Aug 10, 2026
threat-model-interview
information-security-analysts

Run phase 3.4 maintainer question waves for threat-model production. USE WHEN inferred claims need ratification or interview-first versus draft-first mode must be chosen. Asks 3–7 prioritized proposed-answer questions per wave; wave 1 always covers scope,…

Aug 10, 2026
threat-model-recon
information-security-analysts

Orient and mine an open-source repository for threat-model production phases 3.1–3.2. USE WHEN starting a threat model or surveying security posture before modeling. Reads README, top-level docs, SECURITY/THREAT docs, maintainer issue rulings, and changelog…

Aug 10, 2026
threat-model-surface
information-security-analysts

Perform phase 3.3 deep analysis of an in-scope attack surface for a threat model. USE WHEN the orientation brief is ready and code must be read to derive the §1.7 per-input trust table and contract-dimension matrix, §1.5 no-surprise side-effects inventory,…

Aug 10, 2026
Showing 3 of 3 repositories
All repositories loaded