Skip to main content
kalshamsi
GitHub 创作者资料

kalshamsi

按仓库查看 3 个 GitHub 仓库中的 27 个已收集 skills。

已收集 skills
27
仓库
3
更新
2026年7月7日
仓库浏览

仓库与代表性 skills

premortem-plan-check
项目管理专家

Before finalizing any plan, run a premortem — assume the plan has already failed, list the likeliest causes, and reshape the plan with mitigations before presenting it. Use this whenever producing something that will be executed later: project plans,…

2026年7月7日
reversibility-check
项目管理专家

Before executing any hard-to-reverse or destructive step, classify it as a one-way or two-way door; for one-way doors, substitute a reversible alternative or get explicit confirmation, and order work so mistakes can be undone. Use this whenever a plan or…

2026年7月7日
stop-and-reassess
软件开发工程师

After two failed attempts at the same problem, stop and diagnose before trying again — never make a third attempt built on the same assumption. Use this whenever an approach has failed twice in a row, whenever you notice yourself making similar edits,…

2026年7月7日
answer-first-structure
项目管理专家

Decide the bottom line before writing and put it in the first sentence, with only decision-relevant support after it. Use this whenever producing anything a reader will consume to decide or act — reports, emails, summaries, memos, recommendations, status…

2026年7月7日
assess-before-acting
软件开发工程师

Classify the user's intent before producing anything. When a message describes a problem, shares something that "seems off" or "doesn't look right", asks "what do you think", "does this make sense", "why is this happening", or thinks out loud without…

2026年7月7日
assumption-audit
项目管理专家

Before finalizing any analysis, recommendation, or decision made under incomplete information, surface the load-bearing assumptions, tag each as supported or unsupported by the given evidence, and stress-test the conclusion against the weakest one. Use this…

2026年7月7日
calibrated-claims
项目管理专家

Attach explicit, evidence-tied confidence to every load-bearing judgment instead of asserting flatly or retreating into "it depends". Use this whenever the task involves a forecast, an estimate, a feasibility or go/no-go call, a deadline or risk question, or…

2026年7月7日
finish-the-turn
软件开发工程师

Audit the final section of a response before ending the turn - if it promises work, lists next steps the assistant could do itself, or defers with "let me know if...", do that work now instead of ending. Use this on every long, tedious, or multi-part task…

2026年7月7日
已展示 8 / 14 个已收集 Skill。
pci-dss-audit
信息安全分析师

Use when auditing code for PCI-DSS v4.0 compliance, reviewing cardholder data handling, checking credit-card storage and transmission, hunting PAN logging, or answering "is this code PCI-compliant?".

2026年4月16日
docker-scout-scanner
信息安全分析师

Use when scanning Docker images for CVEs, auditing Dockerfiles for misconfigurations, reviewing base image choices, generating container SBOMs, hardening docker-compose configurations, or any container/OCI security concern.

2026年4月16日
bandit-sast
信息安全分析师

Use when scanning Python code for security vulnerabilities, running Bandit, performing Python SAST, auditing Python security bugs, or reviewing Python source for injection, weak crypto, or insecure deserialization.

2026年4月16日
mobile-security
信息安全分析师

Use when auditing an Android or iOS application for security issues, reviewing React Native or Flutter code, checking mobile authentication or insecure data storage, or covering the OWASP Mobile Top 10:2024.

2026年4月15日
security-headers-audit
信息安全分析师

Use when reviewing HTTP security headers, checking a Content-Security-Policy, auditing CORS or HSTS configuration, evaluating X-Frame-Options or Permissions-Policy, inspecting header middleware, or hardening a web application's response headers.

2026年4月15日
security-test-generator
软件质量保证分析师与测试员

Use when writing security tests for a web application, building a vulnerability regression suite, creating pentest-style automated tests, generating runnable injection/XSS/auth test code, or adding security coverage to an existing test suite.

2026年4月15日
api-security-tester
信息安全分析师

Use when auditing REST or GraphQL API endpoints, checking API authentication and authorization, hunting BOLA or broken access control, reviewing rate limiting, or covering the OWASP API Security Top 10.

2026年4月15日
socket-sca
信息安全分析师

Use when scanning project dependencies for supply-chain risk, running Socket SCA on npm/pip/pypi packages, hunting typosquats or malicious packages, or auditing third-party dependency health before a release.

2026年4月15日
已展示 8 / 11 个已收集 Skill。
已展示 3 / 3 个仓库
已展示全部仓库