con un clic
dmarc.mx
dmarc.mx contiene 5 skills recopiladas de schmug, con cobertura ocupacional por repositorio y páginas de detalle dentro del sitio.
Skills en este repositorio
Build a threat model for a target codebase and write THREAT_MODEL.md. Two modes: "bootstrap" derives a threat model from the code plus past vulnerabilities (git history, CVEs, issue tracker) with no owner present; "interview" walks an application owner through the four-question framework. Both write THREAT_MODEL.md in the shared schema (schema.md). Use when asked to "threat model", "build a threat model", "map the attack surface", or "what should we be worried about in this codebase". Read-only — never builds, runs, or fetches the target's live deployment. Adapted for dmarcheck (a TypeScript Cloudflare Worker) from anthropics/defending-code-reference-harness.
Static source-code vulnerability scan for the dmarcheck TypeScript Cloudflare Worker. Reads a target directory (and THREAT_MODEL.md if present), spawns parallel review subagents per focus area, and writes VULN-FINDINGS.json + .md for /vuln-triage to consume. Read-only — no building, running, or network. Category menu is tuned for web/Worker bugs (SSRF, authz/IDOR, auth bypass, injection, XSS, signature verification, secrets, redirect posture), not C/C++ memory corruption. Use when asked to "scan for vulns", "review this code for security issues", "find bugs in <dir>", or as the step between /threat-model and /vuln-triage.
Adversarially triage a batch of raw security-scanner findings (e.g. from /vuln-scan's VULN-FINDINGS.json). Verify each is real, collapse duplicates, re-rank by derived exploitability rather than the scanner's claimed severity, and route each to a component owner. Writes TRIAGE.json + TRIAGE.md sorted by what actually needs attention. Read-only — never executes target code or reaches the network. Named vuln-triage to avoid colliding with the repo's issue/PR /triage skill. Use when asked to "triage findings", "validate scanner output", "prioritize vulns", or "review the security backlog". Adapted for dmarcheck from anthropics/defending-code-reference-harness.
Invariants and conventions for DMarcus, the dmarcheck mascot (the @ creature with three legs). Use when editing src/views/components.ts, src/views/styles.ts, src/views/scripts.ts, or any view that renders the creature — to ensure sizes, moods, party-hat rules, grade-to-mood mapping, and the reduced-motion contract stay consistent.
Scaffold a new protocol analyzer for dmarcheck. Creates the analyzer module, types, orchestrator wiring, scoring hook-in, HTML component, and a test file — all matching the existing shape of src/analyzers/spf.ts and test/spf.test.ts. Use when adding support for a new DNS/email-security protocol (e.g. ARC, TLS-RPT, DANE).