这个仓库中的 skills
AI image generation for blog posts, presentations, and content creation. USE WHEN user mentions generate image, create artwork, blog image, header image, presentation visual, AI art, Replicate, DALL-E, Midjourney, OR wants visual content for publications and marketing materials.
Security-first multi-agent development team with PM, developers, QA, security audit, and code review. USE WHEN user mentions dev team, development team, multi-agent development, orchestrate coding agents, parallel development, coordinate developers, build feature, implement code, carbeneai, cyberdefensetactics, purpleteamops, OR wants autonomous software development with security gates.
Expert CMMC 2.0 (Cybersecurity Maturity Model Certification) advisor for US defense contractors and subcontractors in the Defense Industrial Base (DIB). Use this skill whenever a user asks about CMMC 2.0, CMMC Level 1, Level 2, or Level 3, DoD cybersecurity compliance, NIST SP 800-171, CUI (Controlled Unclassified Information) protection, System Security Plan (SSP), Plan of Action & Milestones (POA&M), C3PAO assessments, DIBCAC audits, self-assessment, SPRS score, or any requirement under DFARS 252.204-7012 or 7021. Also trigger for: "CMMC gap analysis", "CMMC readiness", "FCI protection", "CUI scoping", "CMMC practices", "DoD contract cybersecurity", "defense supply chain security", or "prime contractor flow-down requirements".
Expert DORA (Regulation (EU) 2022/2554 — Digital Operational Resilience Act) compliance advisor for EU financial entities. Use this skill whenever a user asks about DORA compliance, ICT risk management frameworks, ICT incident classification or reporting, threat-led penetration testing (TLPT), ICT third-party risk management, Register of Information, contractual provisions with ICT providers, ICT concentration risk, oversight of critical ICT third-party service providers (CTPPs), or any DORA RTS/ITS obligation. Also trigger for: "DORA gap analysis", "DORA readiness", "Art. 6 ICT risk framework", "Art. 17 incident reporting", "Art. 26 TLPT", "Art. 28 third-party policy", "Art. 30 contractual provisions", "Register of Information CIR 2024/2956", "critical TPSP designation", "DORA vs NIS2", "DORA simplified framework", or EBA/ESMA/EIOPA digital resilience guidance.
Expert India Digital Personal Data Protection Act, 2023 (DPDPA) compliance advisor. Use this skill whenever a user asks about the DPDPA, DPDP Act, DPDP Rules 2025, India data privacy law, Data Fiduciary obligations, Data Principal rights, Significant Data Fiduciary, Data Protection Board of India, consent under DPDPA, notice requirements, breach notification India, children's data India, cross-border data transfer India, India privacy compliance, DPDPA gap analysis, DPDPA vs GDPR, or any obligation under India's personal data protection framework. Also trigger for: "Section 6 consent", "Section 7 legitimate uses", "Section 9 children's data", "Section 10 SDF", "Section 16 cross-border", "Rule 6 breach notification", "Rule 13 SDF obligations", "Data Protection Board complaint", "verifiable parental consent India", "DPDPA compliance roadmap", or "India privacy law global company".
Expert guidance for FedRAMP certification and compliance. Use this skill whenever a user asks about FedRAMP authorization, ATO (Authority to Operate), cloud security for federal government, NIST SP 800-53 controls, CSP compliance, or any of the core FedRAMP document types: SSP, SAP, SAR, POA&M, CIS/CRM workbooks. Also trigger for questions about FedRAMP impact levels (Low, Moderate, High, LI-SaaS), FedRAMP 20x, OSCAL, 3PAO assessments, continuous monitoring (ConMon), gap assessments, system boundary definition, FedRAMP readiness, or architecture reviews for federal cloud. When in doubt, use this skill — it covers the full FedRAMP lifecycle from readiness through continuous monitoring.
Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing Agreements (DPAs), and consent notices, (3) answering GDPR compliance questions with authoritative article citations, and (4) reviewing data flows and PII handling practices. Use this skill whenever the user mentions GDPR, data protection, privacy compliance, lawful basis, data subject rights, DPA, privacy notices, consent management, data breaches, DPIAs, controller/ processor relationships, cross-border data transfers, or any EU/UK data privacy topic. Also trigger for questions like "is this GDPR compliant?", "how do I handle personal data?", "what does a privacy policy need?", or any request involving PII, personal data, or data retention in a regulatory context.
Expert HIPAA compliance assistant for healthcare and software contexts. Use this skill whenever the user mentions HIPAA, PHI (Protected Health Information), ePHI, covered entities, business associates, healthcare data privacy, medical records, health information security, BAA (Business Associate Agreements), or any compliance review involving patient data. Also trigger for requests to draft privacy notices, HIPAA policies, consent forms, security risk assessments, or breach notification letters. Use for developers building healthcare software who need technical safeguard guidance (encryption, access controls, audit logs), compliance officers reviewing documents or procedures, and anyone asking "is this HIPAA compliant?" or "what does HIPAA require for X?". When in doubt about whether a healthcare or data privacy question falls under this skill — use it.
Expert ISO 27001 compliance assistant for security and compliance teams. Use this skill whenever a user asks about ISO 27001 or ISO/IEC 27001, including any of the following: gap analysis, auditing, compliance assessments, control checklists, policy writing, document generation, Statement of Applicability (SoA), risk assessment, risk registers, risk treatment plans, Annex A controls, ISMS implementation, clause requirements, certification readiness, transitioning from 2013 to 2022, control implementation guidance, incident response policies, access control policies, supplier security, or any information security management system (ISMS) topic. Trigger even if the user doesn't say "skill" — any ISO 27001 or ISMS question should use this skill.
Expert ISO 27701 Privacy Information Management System (PIMS) compliance advisor. Use this skill whenever a user asks about ISO/IEC 27701:2025, ISO/IEC 27701:2019, privacy information management, PIMS certification, PII controller or processor obligations, privacy risk assessment, Statement of Applicability for privacy, privacy by design, data subject rights, DPIA, records of processing activities, transitioning from ISO 27701:2019, GDPR alignment with ISO 27701, or any privacy management system topic. Also trigger for questions about Annex A.1 (controller controls), A.2 (processor controls), A.3 (shared security controls), or implementing a standalone PIMS without ISO 27001. When in doubt, use this skill — it covers the full ISO 27701 lifecycle from gap assessment through certification.
Expert ISO 42001 AI Management System (AIMS) compliance advisor. Use this skill whenever a user asks about ISO/IEC 42001:2023, AI governance, AI management systems, AI risk assessment, AI system impact assessment, Annex A controls for AI, Statement of Applicability for AI systems, AI policy, responsible AI, AI lifecycle management, AI incident management, AI transparency, AI bias, AI certification readiness, or any topic related to implementing or auditing an AI Management System. Also trigger for questions like "how do I become ISO 42001 certified?", "what controls does ISO 42001 require?", "how do I assess AI risk under 42001?", "what is an AIMS?", or any request involving organisational governance of AI systems, responsible AI frameworks, or AI regulatory compliance aligned to an ISO standard.
Expert NIST AI Risk Management Framework (AI RMF 1.0) advisor covering all four functions: GOVERN, MAP, MEASURE, MANAGE. Use this skill whenever a user asks about NIST AI RMF, AI risk management, AI trustworthiness, GOVERN function, MAP function, MEASURE function, MANAGE function, AI RMF Playbook, AI risk profiles, responsible AI, AI bias management, AI transparency, AI explainability, AI reliability, AI safety, NIST AI 100-1, AI risk assessment, AI incident response, or alignment to EU AI Act, ISO 42001, or NIST CSF via AI RMF. Trigger even if the user doesn't say "skill" — any NIST AI RMF or AI governance risk question should use this skill.
Expert NIST Cybersecurity Framework (CSF) advisor covering CSF 2.0 and CSF 1.1. Use this skill whenever a user asks about NIST CSF, cybersecurity risk management, the six CSF functions (Govern, Identify, Protect, Detect, Respond, Recover), CSF profiles, implementation tiers, gap assessments, organizational profiles, community profiles, CSF core subcategories, informative references, or mapping to other frameworks (NIST SP 800-53, ISO 27001, CIS Controls, COBIT). Also trigger for questions like "how do I implement NIST CSF?", "what does CSF 2.0 change?", "help me build a CSF profile", "how do I assess my cybersecurity posture?", or any request involving organizational cybersecurity risk strategy or framework alignment.
PAI security audit — scans Claude Code config (settings, MCP servers, skills, agents, hooks) for risky configurations, supply-chain drift, and weekly deltas. USE WHEN user mentions audit PAI, security audit, PAI security check, supply chain audit, skill audit, MCP audit, OR wants weekly security report. Inspired by HarmonicSecurity/claudit-sec but built for Claude Code (not Claude Desktop).
Expert PCI DSS compliance advisor covering PCI DSS v4.0.1 (current) and v4.0. Use this skill whenever a user asks about PCI DSS, payment card security, cardholder data protection, CDE scoping, SAQ types (A, A-EP, B, B-IP, C, C-VT, P2PE, D), ROC, AOC, QSA assessments, ASV scans, merchant levels, service provider levels, network segmentation, penetration testing, tokenisation, encryption of PAN data, or any of the 12 PCI DSS requirements. Also trigger for questions like "are we PCI compliant?", "how do I scope my CDE?", "which SAQ applies to us?", "what changed in PCI DSS v4.0?", "how do I prepare for a QSA audit?", or any request involving payment data security, cardholder data environment, or PCI certification readiness.
AI red-teaming framework for testing LLMs and generative AI systems for jailbreaks, prompt injection, harmful content, data leakage, and multi-turn attacks. USE WHEN user mentions AI red team, LLM jailbreak, prompt injection test, AI risk assessment, AI security testing, GenAI red teaming, NIST AI RMF MEASURE, ISO 42001 testing evidence, or wants to stress-test an AI system. Wraps Microsoft's open-source PyRIT (Python Risk Identification Tool) v0.13+.
Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P). Use this skill whenever a user mentions SOC 2, Trust Services Criteria, SOC 2 Type 1 or Type 2, audit readiness, compliance gaps, control documentation, evidence collection, vendor risk questionnaires, or anything related to AICPA service organization controls. Trigger even for adjacent topics like "we need to get audited", "a customer asked for our security report", "writing an information security policy", or "preparing for an audit". Covers gap analysis, policy writing, control documentation, audit evidence preparation, and vendor risk reviews for organizations at any maturity level — from first-time startups to seasoned compliance teams.
Expert SWIFT Customer Security Programme (CSP) advisor covering the Customer Security Controls Framework (CSCF v2025). Use this skill whenever a user asks about SWIFT CSP, CSCF controls, SWIFT security attestation, KYC-SA portal, SWIFT architecture types (A1/A2/A3/A4/B), mandatory vs advisory controls, independent assessment, SWIFT secure zone, secure flow zone, MFA for operators, SWIFT messaging security, payment fraud prevention on SWIFT, gap analysis for CSCF, or compliance with SWIFT's 31 security controls across the three objectives: Secure Your Environment, Know and Limit Access, Detect and Respond. Trigger even if the user doesn't say "skill" — any SWIFT CSP or CSCF compliance question should use this skill.
Expert TSA cybersecurity compliance advisor for critical infrastructure owners and operators. Use this skill whenever a user asks about TSA Security Directives for pipelines, freight railroads, passenger rail, public transit, or bus operators; the TSA Cyber Risk Management Program (CRMP); Cybersecurity Implementation Plan (CIP); Cybersecurity Operational Implementation Plan (COIP); Cybersecurity Assessment Plan (CAP); incident reporting to CISA; designation of a Cybersecurity Coordinator; Critical Cyber Systems (CCS); OT/IT network segmentation; the TSA November 2024 NPRM; or any directive in the SD Pipeline-2021 series, SD 1580-21-01 (freight rail), or SD 1582-21-01 (public transit/passenger rail). Also trigger for questions like "are we covered by TSA directives?", "what does the TSA require for pipeline cybersecurity?", "how do I build a CIP?", "what must I report to CISA?", or any request involving transportation critical infrastructure cybersecurity compliance.
PAI (Personal AI Infrastructure) - Your AI system core. AUTO-LOADS at session start. USE WHEN any session begins OR user asks about PAI identity, response format, stack preferences, security protocols, or delegation patterns.
24 ATT&CK-mapped offensive security playbooks for penetration testing, red teaming, and security assessments. USE WHEN user mentions kerberoasting, bloodhound, active directory attacks, nmap scanning, SQL injection, privilege escalation, lateral movement, C2 infrastructure, metasploit, credential access, SSRF, SMB exploitation, memory forensics, or any specific offensive security technique. Provides step-by-step operator-grade playbooks with actual tool commands, detection indicators, and MITRE ATT&CK mappings. Designed for use with Talon (Kali Linux MCP) and Ehud (penetration testing agent).
Discord server administration and community management. USE WHEN user mentions discord admin, server management, discord moderation, community management, discord announcements, member management, role management, OR wants to manage the Cyber Defense Tactics Discord server.
Intelligent email management for Gmail accounts with spam filtering and Telegram notifications. USE WHEN user mentions email monitoring, check emails, email spam, email digest, email notifications, OR wants to manage Gmail accounts, filter spam, or get email alerts via Telegram.
Organizational governance for PAI agent infrastructure — budget controls, approval gates, goal ancestry, org chart visualization, standing orders, config portability, workspaces, and task locking. USE WHEN user mentions budget, spending, approval, governance, org chart, goals, standing orders, heartbeat, export config, import config, workspace, task lock, OR organizational management.
Persistent project knowledge and context management. USE WHEN learning new facts about projects, user preferences, or environment details OR when needing to recall previously learned information. Auto-captures learnings to prevent repetition.
Real-time n8n workflow status dashboard. USE WHEN user mentions n8n dashboard, n8n status, workflow status, automation status, OR wants to monitor n8n workflows.
Real-time monitoring dashboard for PAI multi-agent activity. USE WHEN user says 'start observability', 'stop dashboard', 'restart observability', 'monitor agents', 'show agent activity', or needs to debug multi-agent workflows.
Penetration testing methodology guide for reconnaissance, enumeration, exploitation, and reporting. Use when the user needs help with network/port scanning, web application testing, privilege escalation, writing pentest reports, CTF challenges, OSCP-style boxes, or creating attack playbooks and checklists. Integrates with Kali MCP for automated pentesting workflows.
Presentation creation, editing, and analysis. USE WHEN user mentions create presentation, make slides, build deck, PowerPoint, pptx, slide deck, pitch deck, board presentation, OR any presentation tasks. Supports Markdown-to-PPTX workflow with dual branding (CarbeneAI/Professional) and dual engines (python-pptx/Gamma.app).
Generate performance review documents from evidence sources. USE WHEN user mentions review brief, performance review, self-review, team assessment, OR brag doc compilation. Produces manager-ready or peer-style review documents.
Semantic search, temporal knowledge graph, layered context loading, and cross-project tunnels across PAI history, learnings, research, and Obsidian notes. USE WHEN user asks about past work, previous sessions, what they've done before, OR user wants to recall, remember, find, or search history OR user mentions semantic search, memory search, knowledge recall, knowledge graph, entity relations, timeline, tunnels, or cross-project connections.
Bidirectional Telegram bot for full PAI access. USE WHEN user mentions telegram bot, start telegram, stop telegram, telegram access, remote PAI, mobile PAI, OR wants to manage the telegram bot service (start/stop/restart), OR needs to save telegram results to obsidian.
Send PAI system status updates to Telegram with on-demand or scheduled delivery. USE WHEN user says 'send status to telegram', 'telegram update', 'schedule daily telegram', 'setup telegram cron', or requests PAI status notifications via Telegram. Includes system health checks, formatted messages with timestamps, and automated 7 AM daily updates.
UI/UX design intelligence. 50 styles, 21 palettes, 50 font pairings, 20 charts, 9 stacks (React, Next.js, Vue, Svelte, SwiftUI, React Native, Flutter, Tailwind, shadcn/ui). Actions: plan, build, create, design, implement, review, fix, improve, optimize, enhance, refactor, check UI/UX code. Projects: website, landing page, dashboard, admin panel, e-commerce, SaaS, portfolio, blog, mobile app, .html, .tsx, .vue, .svelte. Elements: button, modal, navbar, sidebar, card, table, form, chart. Styles: glassmorphism, claymorphism, minimalism, brutalism, neumorphism, bento grid, dark mode, responsive, skeuomorphism, flat design. Topics: color palette, accessibility, animation, layout, typography, font pairing, spacing, hover, shadow, gradient. Integrations: shadcn/ui MCP for component search and examples.
Real-time Wazuh SIEM security dashboard with PAI chat integration. USE WHEN user mentions wazuh dashboard, security alerts, SIEM monitoring, alert analysis, OR wants to view security events with AI assistance.
Autonomous iterative research loop. Takes a topic, runs web searches, fetches sources, synthesizes findings, and files everything into the wiki as structured pages. Based on Karpathy's autoresearch pattern: program.md configures objectives and constraints, the loop runs until depth is reached, output goes directly into the knowledge base. Triggers on: "/autoresearch", "autoresearch", "research [topic]", "deep dive into [topic]", "investigate [topic]", "find everything about [topic]", "research and file", "go research", "build a wiki on".
Ingest sources into the Obsidian wiki vault. Reads a source, extracts entities and concepts, creates or updates wiki pages, cross-references, and logs the operation. Supports files, URLs, and batch mode. Triggers on: ingest, process this source, add this to the wiki, read and file this, batch ingest, ingest all of these, ingest this url.
Health check the Obsidian wiki vault. Finds orphan pages, dead wikilinks, stale claims, missing cross-references, frontmatter gaps, and empty sections. Creates or updates Dataview dashboards. Generates canvas maps. Triggers on: "lint", "health check", "clean up wiki", "check the wiki", "wiki maintenance", "find orphans", "wiki audit".
Port scanner for finding open ports and services on hosts. USE WHEN user mentions port scanning, open ports, service discovery, network reconnaissance, or host enumeration. Wraps ProjectDiscovery's naabu binary as a local MCP server.
AI-powered source code vulnerability discovery, exploitation, and patching pipeline. Inspired by Praetorian Constantine's 6-stage architecture. USE WHEN user mentions bug bounty, source code audit, vulnerability scanning, code security review, CVE hunting, exploit generation, proof of vulnerability, patch validation, security-relevant file scoring, SAST, static analysis, or wants to find exploitable bugs in a codebase. Integrates with Ehud (pentest agent) and Nehemiah (security auditor) for comprehensive assessments.