Skip to main content
kalshamsi
Perfil de criador do GitHub

kalshamsi

Visão por repositório de 27 skills coletadas em 3 repositórios do GitHub.

skills coletadas
27
repositórios
3
atualizado
7 de jul. de 2026
explorador de repositórios

Repositórios e skills representativas

premortem-plan-check
Especialistas em gestão de projetos

Before finalizing any plan, run a premortem — assume the plan has already failed, list the likeliest causes, and reshape the plan with mitigations before presenting it. Use this whenever producing something that will be executed later: project plans,…

7 de jul. de 2026
reversibility-check
Especialistas em gestão de projetos

Before executing any hard-to-reverse or destructive step, classify it as a one-way or two-way door; for one-way doors, substitute a reversible alternative or get explicit confirmation, and order work so mistakes can be undone. Use this whenever a plan or…

7 de jul. de 2026
stop-and-reassess
Desenvolvedores de software

After two failed attempts at the same problem, stop and diagnose before trying again — never make a third attempt built on the same assumption. Use this whenever an approach has failed twice in a row, whenever you notice yourself making similar edits,…

7 de jul. de 2026
answer-first-structure
Especialistas em gestão de projetos

Decide the bottom line before writing and put it in the first sentence, with only decision-relevant support after it. Use this whenever producing anything a reader will consume to decide or act — reports, emails, summaries, memos, recommendations, status…

7 de jul. de 2026
assess-before-acting
Desenvolvedores de software

Classify the user's intent before producing anything. When a message describes a problem, shares something that "seems off" or "doesn't look right", asks "what do you think", "does this make sense", "why is this happening", or thinks out loud without…

7 de jul. de 2026
assumption-audit
Especialistas em gestão de projetos

Before finalizing any analysis, recommendation, or decision made under incomplete information, surface the load-bearing assumptions, tag each as supported or unsupported by the given evidence, and stress-test the conclusion against the weakest one. Use this…

7 de jul. de 2026
calibrated-claims
Especialistas em gestão de projetos

Attach explicit, evidence-tied confidence to every load-bearing judgment instead of asserting flatly or retreating into "it depends". Use this whenever the task involves a forecast, an estimate, a feasibility or go/no-go call, a deadline or risk question, or…

7 de jul. de 2026
finish-the-turn
Desenvolvedores de software

Audit the final section of a response before ending the turn - if it promises work, lists next steps the assistant could do itself, or defers with "let me know if...", do that work now instead of ending. Use this on every long, tedious, or multi-part task…

7 de jul. de 2026
Mostrando 8 de 14 skills coletadas.
pci-dss-audit
Analistas de segurança da informação

Use when auditing code for PCI-DSS v4.0 compliance, reviewing cardholder data handling, checking credit-card storage and transmission, hunting PAN logging, or answering "is this code PCI-compliant?".

16 de abr. de 2026
docker-scout-scanner
Analistas de segurança da informação

Use when scanning Docker images for CVEs, auditing Dockerfiles for misconfigurations, reviewing base image choices, generating container SBOMs, hardening docker-compose configurations, or any container/OCI security concern.

16 de abr. de 2026
bandit-sast
Analistas de segurança da informação

Use when scanning Python code for security vulnerabilities, running Bandit, performing Python SAST, auditing Python security bugs, or reviewing Python source for injection, weak crypto, or insecure deserialization.

16 de abr. de 2026
mobile-security
Analistas de segurança da informação

Use when auditing an Android or iOS application for security issues, reviewing React Native or Flutter code, checking mobile authentication or insecure data storage, or covering the OWASP Mobile Top 10:2024.

15 de abr. de 2026
security-headers-audit
Analistas de segurança da informação

Use when reviewing HTTP security headers, checking a Content-Security-Policy, auditing CORS or HSTS configuration, evaluating X-Frame-Options or Permissions-Policy, inspecting header middleware, or hardening a web application's response headers.

15 de abr. de 2026
security-test-generator
Analistas de garantia de qualidade de software e testadores

Use when writing security tests for a web application, building a vulnerability regression suite, creating pentest-style automated tests, generating runnable injection/XSS/auth test code, or adding security coverage to an existing test suite.

15 de abr. de 2026
api-security-tester
Analistas de segurança da informação

Use when auditing REST or GraphQL API endpoints, checking API authentication and authorization, hunting BOLA or broken access control, reviewing rate limiting, or covering the OWASP API Security Top 10.

15 de abr. de 2026
socket-sca
Analistas de segurança da informação

Use when scanning project dependencies for supply-chain risk, running Socket SCA on npm/pip/pypi packages, hunting typosquats or malicious packages, or auditing third-party dependency health before a release.

15 de abr. de 2026
Mostrando 8 de 11 skills coletadas.
Mostrando 3 de 3 repositórios
Todos os repositórios foram exibidos