Skip to main content
leogr
GitHub creator profile

leogr

Repository-level view of 5 collected skills across 1 GitHub repositories.

skills collected
5
repositories
1
updated
2026-06-10
repository map

Where the skills live

Top repositories by collected skill count, with their share of this creator catalog and occupation spread.

repository explorer

Repositories and representative skills

falco-cli
network-and-computer-systems-administrators

Use the Falco CLI for validation, introspection, and information gathering. Supports local binary, downloaded versions from download.falco.org, and container images (Docker/Podman). Validate rules files, list available fields, inspect plugins, get version info, analyze binary dependencies (GLIBC, shared libraries), and verify Falco knowledge. This skill enables CLI-mode operations and binary analysis without requiring elevated privileges or running Falco as a daemon.

2026-06-10
falco-dev
software-developers

Develop, build, test, and debug Falco and its core components (libs, rules) using a Docker-based devcontainer. Manages multi-repo workspaces, CMake builds, unit/integration testing, and debugging with graduated privilege modes (safe, least-privilege, privileged).

2026-06-10
falco-reviewer
software-quality-assurance-analysts-and-testers

Review pull requests across falcosecurity repositories as a ghost writer for Falco maintainers. Performs code review, security review, and breaking change analysis using the falco-expert knowledge base. Generates a review report and a ready-to-run shell script that publishes a pending (draft) GitHub review with inline comments. Use this skill whenever the user asks to review a PR in any falcosecurity repository, or when terms like "review PR", "PR review", "code review" appear in the context of falcosecurity.

2026-06-10
falco-rules-author
software-developers

Author, validate, and iteratively tune Falco detection rules. Covers the complete rule language (conditions, macros, lists, priorities, output templates, overrides), the filter expression language (19 operators, 5 transformers, all field classes), rule engine optimization (event type indexing), and practical Docker-based testing workflows with structured feedback loops for false-positive reduction. Supports modern_ebpf (live), replay (.scap), nodriver (plugins-only), and plugin event sources.

2026-06-10
falco-triage
software-developers

Triage GitHub issues and pull requests across falcosecurity repositories. Fetches, categorizes, and analyzes issues/PRs using the falco-expert knowledge base for technical context, checks for duplicates and related work, evaluates PR status, and generates actionable triage reports with ready-to-run gh commands. Supports tiered (quick scan + selective deep dive) and deep-dive-all analysis modes. Read-only — never modifies issues or PRs directly.

2026-06-10
Showing 1 of 1 repositories
All repositories loaded