Create and review runbooks, operating instructions, incident playbooks, escalation paths, restart procedures, and checklists.
Skills in this repository
domehahn/skcr - Page 2
SkillsMP has collected 66 skills from domehahn/skcr. Open a skill to review its source and details.
domehahn/skcrShowing 26 of 66 collected skills.
Review SBOM generation, CVE triage, VEX, exception processes, patch SLAs, and the vulnerability lifecycle.
Review code vulnerabilities such as injection, path traversal, SSRF, XSS, deserialization, crypto misuse, and race conditions.
Review secure-by-design decisions, least privilege, Zero Trust, tenant separation, secure defaults, and abuse scenarios.
Review Internal Developer Platforms for secure golden paths, self-service guardrails, templates, permission models, secrets handling, and auditability.
Review SLSA, provenance, SBOM, signatures, attestations, build integrity, artifact promotion, and trusted builders.
Assess SLOs, SLIs, error budgets, capacity, degradation, timeouts, retries, circuit breakers, load shedding, and operational risks.
Assess CVE triage, prioritization, SLAs, exploitability, asset criticality, exceptions, risk acceptance, and remediation tracking.
Review architecture, module boundaries, interfaces, coupling, scalability, data flows, and technical risks.
Review CI/CD pipelines, runners, permissions, artifacts, caches, deployment gates, and token exposure.
Review governance controls such as CODEOWNERS, branch protection, approvals, auditability, and policy compliance.
Plan coding work with minimal context, relevant file selection, risk awareness, rollback, and validation strategy.
Review dependencies, lockfiles, package managers, container images, actions, and supply-chain risks.
Create and update README files, ADRs, setup guides, API docs, runbooks, and operational documentation.
Review Terraform, Kubernetes, Helm, Kustomize, GitOps reconciliation, promotion, and environment safety.
Support incident analysis, timeline creation, root cause analysis, impact assessment, corrective actions, and follow-up issues.
Review logging, metrics, tracing, health checks, alerts, dashboards, runbooks, and operational readiness.
Assess release readiness, rollback, migrations, feature flags, monitoring, documentation, and breaking changes.
Analyze requirements, user stories, acceptance criteria, constraints, risks, and open questions before implementation.
Create or modify code, tests, configuration, and project files safely with real file changes.
Detect and prevent exposure of secrets, tokens, credentials, private keys, CI variables, and sensitive logs.
Review code, CI/CD, configuration, permissions, dependencies, input validation, and DevSecOps risks.
Design and generate unit, integration, regression, security, and end-to-end test strategies.
Identify assets, trust boundaries, abuse cases, attack paths, threats, and required security controls.
Create, adapt, validate, and optimize reusable agent skills across agentic platforms.
Review diffs, validate acceptance criteria, inspect test results, and find missed requirements.