Fetch a remote API and run a git command on the result.
domehahn/skcr
SkillsMP has collected 66 skills from domehahn/skcr. Open a skill to review its source and details.
- Latest recorded source activity
- SkillsMP catalog refreshed
- skills collected
- 66
- GitHub stars
- 1
- GitHub forks
- 0
Skills in this repository
Showing 40 of 66 collected skills.
Review source files without changing external state.
Review AI-assisted changes before execution for automation boundaries, human approval, affected-system criticality, and audit evidence.
Assess correlation of logs, metrics, traces, events, and incidents to reduce noise, improve root-cause analysis, and lower alert fatigue.
Review alerts for actionability, clear symptoms, runbook links, severity, ownership, SLO relation, deduplication, escalation, and remediation suitability.
Review REST, GraphQL, OpenAPI, and gRPC contracts, breaking changes, versioning, AuthN/AuthZ, error formats, and compatibility.
Create and maintain ADRs with context, decisions, alternatives, risks, security impact, compliance relation, and review points.
Review evidence, approvals, tickets, logs, test protocols, risk decisions, versioning, and accountable owners.
Link requirements, controls, implementation, tests, tickets, and evidence into an auditable trace.
Review automated repair actions for safe limits, dry runs, approval modes, rollback, audit logs, blast radius, and loop protection.
Review restore tests, RPO/RTO, data integrity, backup protection, recoverability, and disaster recovery.
Review cloud naming, tags, ownership, cost centers, allowed services, regions, data classification, policy enforcement, and audit evidence.
Review cloud accounts or subscriptions, networks, IAM, logging, policies, baselines, guardrails, encryption, tagging, and tenant separation.
Review Dockerfiles, base images, user rights, capabilities, SBOM, image signing, distroless or slim images, CVEs, and runtime hardening.
Map technical measures to DORA, VAIT or BAIT migration needs, ISO 27001, BSI, internal policies, or MaRisk review expectations.
Review setup, local development, error messages, Makefiles or scripts, onboarding, tooling consistency, and practicality for teams.
Assess maturity across plan, code, build, test, release, deploy, and operate with automation, security gates, ownership, and feedback loops.
Review documentation freshness, ownership, review cycles, approvals, versioning, validity, and traceability.
Review DORA readiness for ICT risk management, resilience testing, incidents, third-party risk, roles, policies, evidence, and auditability.
Create auditable evidence packages from tickets, pipeline results, test reports, approvals, scans, and architecture information.
Review cloud costs, budgets, rightsizing, reserved or committed usage, anomalies, showback or chargeback, and team cost transparency.
Review Argo CD or Flux setups, sync policies, drift detection, promotion, rollback, app-of-apps, secrets, cluster access, and deployment governance.
Review ICT incident classification, escalation, documentation, reportability, timelines, responsibilities, templates, and communication chains.
Review ICT risks, protection needs, criticality, controls, residual risks, treatment, and recurring reassessment.
Review cloud, SaaS, outsourcing, subcontractors, contracts, exit strategies, concentration risks, and DORA information-register readiness.
Review IAM, roles, service accounts, groups, tokens, OIDC federation, GitLab or GitHub permissions, cloud rights, and privilege-escalation paths.
Review Kubernetes clusters, namespaces, RBAC, NetworkPolicies, Pod Security, admission controllers, resource limits, secrets, ingress, tenancy, and upgrades.
Review GenAI workloads for prompt injection, tool permissions, data exfiltration, RAG sources, sensitive prompt logging, evals, guardrails, and model access.
Review database migrations, schema changes, breaking changes, rollback ability, backward compatibility, and zero-downtime deployments.
Review model versioning, training data, bias, drift, monitoring, approvals, reproducibility, model registry, and deployment gates.
Review backup and restore, failover, disaster recovery, restart procedures, crisis exercises, scenario tests, and lessons learned.
Review exit plans, data return, provider transitions, emergency operations, suboutsourcing, cloud dependencies, and business impact.
Review load behavior, bottlenecks, caching, database access, queue behavior, scaling, timeouts, and resource limits.
Design and review secure CI/CD pipelines with isolated runners, minimal rights, OIDC, signed artifacts, protected environments, and approval gates.
Create and review policies for OPA/Rego, Kyverno, GitLab Policies, Conftest, Checkov, Terraform, Kubernetes, and CI/CD gates.
Review GitLab Security Policies, OPA/Rego, Kyverno, Conftest, Sentinel, admission policies, compliance pipelines, and central guardrails.
Create and update policies, standards, procedures, and control descriptions.
Review privacy, personal data, data classification, deletion concepts, purpose limitation, GDPR risks, and sensitive-data logging.
Review timeouts, retries, circuit breakers, failover, backpressure, degraded modes, and resilience behavior.
Document and assess conscious risk decisions, impact and likelihood, expiry dates, and compensating measures.