ワンクリックで
project-raven-d3fend
project-raven-d3fend には daemon-blockint-tech から収集した 10 個の skills があり、リポジトリ単位の職業カバレッジとサイト内 skill 詳細ページを表示します。
このリポジトリの skills
Mythos-class source-code reasoning for DevSec — pre-merge, pre-deploy, pre-release. Use when the user says "review this PR for security", "audit this diff", "block bad merges", "secure code review", "DevSec gate", "shift-left security", "pre-deploy security scan", "release security gate", or asks Raven to act as a Mythos-grade auditor inside the CI/CD pipeline. Every finding terminates at a tool oracle (𝒯), classical-ML detector (𝓜), or scored hypothesis (𝓛) with a falsification test — never raw LLM speculation — and ships with the D3FEND Harden technique id it implements. Defender-only: emits findings + remediation candidates, never exploit payloads.
Orchestrate 100+ specialized AI agents across an ensemble of frontier and distilled models to discover, debate, validate, prove, enrich, and triage exploitable bugs end-to-end. Use when the user wants to run the full MDASH pipeline with multi-model ensemble, dynamic agent spawning, or production-scale vulnerability discovery. Every finding terminates at a tool oracle (𝒯), classical-ML detector (𝓜), or scored hypothesis (𝓛), and ships with D3FEND defensive techniques, ATT&CK offensive context, exposure scoring, and DevSecOps routing.
Scaffold a research-grade experiment that tests whether a Looped / Recurrent-Depth Transformer (RDT) is better than a parameter-matched vanilla transformer at vulnerability discovery, when both are continued-pretrained on a security corpus. Use when the user says "test the looped-transformer hypothesis", "run the OpenMythos RDT experiment", "compare loop count to trial budget", "does inference-time loops help security reasoning", or asks for a reproducible research pipeline around the Mythos architecture hypothesis. The skill scaffolds the experiment — it does NOT make claims about Mythos itself, and it explicitly bins OpenMythos as a community speculative reconstruction, not Anthropic's actual model.
Run Project Raven's MDASH (Multi-Model Agentic Security Harness) pipeline against a target codebase or runtime. Use when the user says "hunt 0-days", "look for zero-days", "ARES scan", "variant analysis", "memory corruption hunt", "kernel/driver hunt", "smart-contract 0-day", or asks Raven to anticipate kill chains, generate exploit hypotheses, or validate LLM-claimed vulnerabilities. Every finding ends in a tool-oracle (𝒯), classical-ML detector (𝓜), or scored hypothesis (𝓛) — never raw LLM speculation — and ships with D3FEND defensive techniques, ATT&CK offensive context, and real-world exposure scoring.
Automatically enforce defensive policy against an in-progress 0-day signal, end-to-end, with strict approval gating. Use when the user says "auto-prevent", "auto-block", "auto-quarantine", "policy-driven response", "stop this 0-day now without me clicking through", or asks Raven to execute the Defend plan automatically when criteria are met. Every automatic action terminates at a tool oracle (𝒯) with mandatory approval-gate verification, references a real D3FEND Isolate / Evict / Harden technique id, and emits a tamper-evident audit trail.
Stand up Raven's defensive posture against an in-the-wild 0-day campaign. Use when the user says "defend against `<CVE>` / `<campaign>`", "harden us against this 0-day", "deploy mitigations for the new exploit", "isolate exposure", or asks to compose D3FEND Harden + Isolate + Deceive techniques into an active defensive plan. Every action terminates at a tool oracle (𝒯) or approval-gated mitigation module, never raw LLM speculation, and every recommendation is bound to a real D3FEND technique id from the 271-entry MITRE catalog plus ATT&CK offensive context and exposure scoring. Built for production DevSecOps at enterprise scale.
Run Raven's online 0-day detection stack against live telemetry, files, binaries, or network flows. Use when the user says "detect 0-days", "scan for novel threats", "run anomaly detection", "screen this artifact for unknown malware", "novelty detection", or asks for a continuous monitor against unknown-bad. Every detection terminates at a classical-ML detector (𝓜) or a tool-oracle rule (𝒯) — LLM verdicts alone are never accepted — and every alert ships with a D3FEND Detect-tactic technique id, ATT&CK offensive context, and exposure scoring. Built for production DevSecOps at enterprise scale on private codebases.
Generate, verify, and apply patches for a confirmed 0-day finding. Use when the user says "fix this 0-day", "patch this CVE", "generate the fix", "virtual-patch this", "rollback unsafe change", "apply remediation", or hands over a confirmed root cause from `raven-zero-day-investigator`. Every patch terminates at a tool oracle (𝒯) — static verifier, test suite, formal check, or restore primitive — never raw LLM speculation, and every fix is tagged with a D3FEND Harden / Restore technique id.
Investigate a single 0-day alert or finding end-to-end and produce a grounded incident report. Use when the user says "investigate this alert", "triage this finding", "deep-dive this anomaly", "root-cause this 0-day candidate", "build a timeline for this incident", or hands over an alert from `raven-zero-day-detection`. Every conclusion terminates at a tool oracle (𝒯), classical-ML detector (𝓜), or scored hypothesis (𝓛) and ships with D3FEND Detect / Isolate / Evict technique ids, ATT&CK offensive context, and exposure scoring. Built for production DevSecOps: every finding has an owner, triage process, and Patch Tuesday deadline.
Curate, query, and emit Raven's catalog of 0-day threat patterns. Use when the user says "0-day pattern", "exploit pattern library", "threat fingerprint", "variant template", "bug-class taxonomy", "match this finding against known patterns", or asks to extend the YARA / Semgrep / ARES rule packs with a new 0-day archetype. Every pattern record terminates at a tool oracle (𝒯) or a classical-ML detector (𝓜) — never raw LLM speculation — and ships with the CWE plus D3FEND Harden / Detect technique ids it counters.