一键导入
SunLitOrchestra
SunLitOrchestra 收录了来自 kerberosmansour 的 51 个 skills,并提供仓库级职业覆盖和站内 skill 详情页。
这个仓库中的 skills
Use this skill after /slo-spike has filled §7, to fill §8 Curation Decision — decide honestly. Mode is convergent. Classify confidence as exploratory, confirmatory, or engineering_ready from the evidence; require ablation and failure analysis before an engineering route; and give every candidate exactly one frozen disposition citing evidence. No vague maybes survive; dead ends route to §11 compost. Hands off a RecommendationPacket readiness block to /slo-demo.
Use this skill after /slo-curate has filled §8, to fill §9 Demo Pack + §10 Handoff Contract — make the discovery communicable and emit a method-complete RecommendationPacket. Mode is communication. Preserve confidence, ablation, failures, replication, limitations, and the exact next question, then fill the ONE promotion-seed table matching the disposition. Promotion is a SUGGESTION the human accepts — never an auto-invocation. Closes the Innovation Sandbox loop.
Use this skill after /slo-pattern has filled §5, to fill §6 Precision Model — make the invisible measurable. Mode is measurement. Convert each promising pattern into a falsifiable claim with a measurement handle, an accept threshold AND a kill threshold, resource bounds, security invariants, and a versioned Protocol Freeze before confirmatory work. Do NOT accept "feels better" without a handle. This is the OK-Go "math" move for engineering. Hands off to /slo-spike.
Use this skill after /slo-precision has filled §6, to fill §7 with a bounded DiscoveryRecord and/or ValidationRecord. Discovery is exploratory and may refine a mechanism; validation cites one complete active ProtocolFreeze, uses held-out frozen arms with no tuning, and records exact commands, environment, repetitions, stability, deviations, and per-arm results. This is the ONLY phase that may run code, scratch-only under experiments/<slug>/<spike-id>/. Every spike has a finite budget and delete-or-promote decision. NOTHING becomes production without the normal SLO Sprint or Ticket loop. Hands off to /slo-curate.
Use this skill to drive one milestone of a v3 runbook. Invoke with the milestone number or identifier, e.g. "/slo-execute M3" or "execute milestone 3 of the runbook". Restates milestone constraints, writes BDD tests first, implements the smallest safe change, fills the evidence log. REFUSES to touch files outside the milestone's allow-list without pausing and surfacing the conflict. Replaces the inner loop of the legacy sldo-run binary.
Use this skill when a product repo needs graph-backed codebase understanding, fast troubleshooting, or security triage. It combines Graphify knowledge graphs with semantic-provider facts from rust-analyzer / TypeScript language service and analysis-provider findings from OpenGrep or Semgrep-compatible rule packs. It is designed for private repos: raw evidence stays out of git; only anonymized summaries may be committed.
Use this skill to wire threat-model-driven SAST scanning into a target product repo. Reads docs/slo/design/<slug>-threat-model.md for CWE references, picks tuned Semgrep rule packs for the detected stack, emits a safe GitHub Actions workflow plus a baselined config plus an audit-defense manifest, and re-derives the ruleset on threat-model edit. Pure Markdown skill; no Rust binary dependency. Pair with /slo-rulegen for project-specific rules.
Use this skill when the user wants to pull or claim a bite-sized ticket from GitHub Issues before implementation. It normalizes issue context, applies the ticket sizing gate, creates or updates one persistent issue workpad comment, and hands off to /slo-ticket-plan. It does not write code.
Use this skill after /slo-ticket-pick, when one GitHub issue should become a bite-sized SLO ticket contract. It writes docs/slo/tickets/ticket-<issue>-<slug>.md from a v4-derived template, keeps the v4 Contract Block rigor, and escalates to /slo-plan when the issue is too large for one ticket.
Use this skill after /slo-execute finishes a milestone, before /slo-retro closes it. Invoke with the milestone number — "/slo-verify M3". Exercises BDD scenarios at runtime, including UI paths via Playwright if the milestone has a UI surface. For every bug found, writes a regression test FIRST, then hands the fix back to /slo-execute, then re-verifies. Do not use for static code review — that is /slo-critique.
Use this skill after /slo-plan produces a runbook, BEFORE /slo-execute runs any milestone. Orchestrates four adversarial review passes (CEO, eng-lead, security, design) against the plan. Auto-fixes mechanical issues, surfaces scope concerns for user approval, rejects vague findings. Every finding must include a concrete exploit or failure scenario — theoretical risks are not accepted. Skip the design pass automatically if the runbook has no UI surface.
Use this skill after /slo-architect (and /slo-tla if tla_required), when the user says "write the runbook", "plan the milestones", "turn this into tasks". Authors a full v4 runbook INTERACTIVELY, one milestone at a time, confirming each contract before moving on. Maximum 5 milestones per runbook — if scope needs more, suggest splitting. Refuses to generate the whole runbook in one shot; this is deliberate discipline, not a limitation.
Use this skill at the END of every milestone, after /slo-execute and /slo-verify have finished. Writes the milestone's lessons-learned file, completion summary, and updates the runbook's Milestone Tracker. Requires a filled-in Evidence Log. Refuses to run on milestones whose Evidence Log has blank "Actual Result" cells. Also usable standalone to close out a milestone that was executed by hand.
Use this skill to open or resume a creative experiment — when the user says "what if", "could we explore", "maybe there's something here", "can we play with", or "I have a weird technical hunch" but does NOT yet have a feature. Creates docs/slo/experiments/<slug>/EXPERIMENT.md from the Experiment Book v1 template (the experimentation peer of the v4 runbook — Definition of Learned, not Done) and seeds §0-§2 + the tracker. It is the umbrella of the Innovation Sandbox loop; the phase skills (/slo-sandbox, /slo-play, /slo-pattern, /slo-precision, /slo-spike, /slo-curate, /slo-demo) fill §3-§10 afterward. Do NOT use it for a roughly-formed feature where /slo-ideate is the right start — this loop FEEDS /slo-ideate, it does not replace it.
Use this skill after /slo-play has filled §4, to fill §5 Pattern Catalog — turn raw play into named reusable mechanisms (a vocabulary of tricks). Mode is convergent. Cite probe IDs for every pattern, run the next-curve check and the DICEE check, and narrow to at most five serious candidates. Do NOT promote everything. Hands off to /slo-precision.
Use this skill after /slo-sandbox has filled §3, to fill §4 Play Log — generate many raw probes from the sandbox's probe seeds WITHOUT premature judgment. Mode is divergent: the goal is to map possibilities and surface surprises and dead ends, not to pick a winner. This is the joy-preserving phase. Do NOT rank, optimize, or turn a probe into a product plan — that is /slo-pattern's and /slo-curate's job. Hands off to /slo-pattern.
Use this skill after /slo-experiment has opened an Experiment Book, to fill §3 Sandbox Charter — choose the MATERIAL, not the feature. Mode is framing: name what we are playing with, why it is rich, the boundaries, the safety rails, the weirdness budget, at least three probe seeds, and kill criteria. It is the first phase of the Innovation Sandbox loop after the umbrella. Do NOT ask "what feature are we building?" — that collapses the play; ask "what material are we exploring?" Hands off to /slo-play.
Use this skill to pick up an interrupted runbook. Invoke as "/slo-resume" (no args) and it reads the current runbook's Milestone Tracker to identify the first non-done milestone, then suggests the next skill to run for that milestone. Does not modify state — it only orients. Good for "I stepped away yesterday, where was I" scenarios.
Use this skill when a runbook's milestones are all done and you're ready to open a PR — "ship this", "open the PR", "push and PR". Syncs main, runs the full non-parked test suite, confirms git state is clean-ish, pushes the branch, opens a PR with a runbook-aware description summarizing completed milestones (not line counts). Does NOT merge. Does NOT skip hooks.
Use this skill when a UK seed-stage founder needs PM-side artifacts: a product roadmap with RICE / Kano prioritisation, a product-metrics dashboard defining north-star + activation funnel + retention curves + feature adoption, OR a quarterly OKR set tied to the north-star metric. Generator with a mode arg `mode_arg: roadmap | metrics | okrs`. Output path differs per mode under `docs/biz-public/product/`. Distinct from `/slo-metrics` (Runbook B2 — financial / business KPIs like CAC / LTV / NDR / MoM growth / burn multiple, NOT product KPIs).
Use this skill at the start of any new product or feature idea — when the user says "I want to build X", "I have an idea for", "let's design", "what if we", or hands you a rough pitch. Interrogates the idea YC-office-hours style with six forcing questions, reframes the pain, generates three implementation approaches, and writes a shareable idea doc. Trigger BEFORE any research, architecture, or planning. Do not run this on a well-specified feature where the user already knows the what and the how.
Use this skill when /slo-architect has set tla_required=true, or when the user asks to "verify the design", "model check", "prove this is correct", "add TLA+ to this plan", or whenever a design involves concurrent actors, distributed state, ordering guarantees, resource ownership, or failure recovery. Produces a TLA+ spec, runs TLC, translates counterexamples to plain English, iterates with the user on fixes, and writes a verified-design doc with explicit model bounds. Skip for simple CRUD systems with no real concurrency risk.
Use this skill when /slo-architect has set kani_required=true, or when the user asks to "verify this Rust code", "model-check this function", "prove this can't panic / overflow / go out of bounds", "add Kani to this", or whenever Rust code has unsafe blocks, raw pointers, arithmetic/boundary logic, parsers, state machines, or representation invariants worth a bounded proof. Drives the Kani Rust model checker as a code-level peer to /slo-tla: scores candidates, writes #[cfg(kani)] proof harnesses, runs `cargo kani`, triages results, remediates, and writes a verified-scope report. A green run means "proved within the stated harness, assumptions, and bounds" — never "whole system proved." Concurrency is out of scope for Kani — pair with /slo-tla for interleavings. Skip for non-Rust targets or Rust with no unsafe/arithmetic/invariant kernels.
Use this skill after /slo-research, when the user is ready to commit to architecture and stack decisions — "design the system", "pick the stack", "write the architecture". Produces ARCHITECTURE.md plus stack decision and interface-lock-in docs. Sets tla_required true/false on the design so /slo-tla knows whether to run. Do not use for feature additions to an already-designed system — in that case jump straight to /slo-plan.
Use this skill to produce a scenario-driven AWS, GitHub, or Cloudflare cloud / platform threat model. Given one prebuilt scenario ID it writes a structured Markdown threat-model document plus a machine-readable companion, citing framework control identifiers (CSA CCM, CIS, NIST 800-53 / SSDF, MITRE ATT&CK / ATLAS, OpenSSF Scorecard, OWASP ASVS, ISO 27001) and Hulumi policy rule IDs by identifier only — never verbatim licensed control prose. It is the SLO-native, modernized port of Hulumi's `hulumi-threat-model` skill, refreshed for the Hulumi v1.3.2 Edge Platform (Cloudflare + cross-provider patterns). Distinct from `/slo-threat-model` (issue #67): this is a prebuilt-scenario catalog, not the architect/plan/critique provider contract.
Use this skill to wire and tune DAST for an authorized web app or web service through zaprun only. Operates OWASP ZAP via the latest approved digest-pinned ghcr.io/kerberosmansour/zaprun image, reads threat models, OpenAPI/routes/auth context, and SAST SARIF, then tunes generic DAST policy while keeping app-specific custom rules in the target repo or run artifacts.
Use this skill to implement one docs/slo/tickets/ticket-*.md contract. It is the ticket-sized analogue of /slo-execute: BDD tests first, exact file allow-list enforcement, smallest safe change, v4 evidence log discipline, and no scope widening without user approval.
Use this skill after /slo-ticket-execute. It performs ticket-sized runtime QA and security/static evidence checks against docs/slo/tickets/ticket-*.md, writes regression tests before fixes for any bug found, and updates the issue workpad. It does not implement unrelated fixes.
Use this skill for authorized OWASP Nettacker vulnerability assessments, recon-to-active scanning plans, safe Nettacker CLI/API/Web UI usage, scan result triage, CI drift monitoring, and writing or reviewing custom Nettacker YAML modules ("rules") for company-owned systems. Hard-gates on target authorization, scope, rate limits, and credential-testing permission.
Use this skill to read CycloneDX 1.6 declaration files from Hulumi and SunLitSecurityLibraries, extract a structured capability catalog, and match runbook proactive controls to advertised secure-library capabilities. M1-M2 are read-only; M3 files user-confirmed SLO-intake capability gaps; M4 adds explicit upstream filing with a per-session cap.
Use this skill when a UK seed-stage founder needs a brief-the-accountant memo (R&D claim narrative, VAT registration timing, MTD readiness check), needs an HMRC letter or accountant communication translated to plain English, needs to triage whether an accountant is genuinely required for an accounting matter, or needs to prepare for an accountant call. Operates as an advisor with the same four modes as `/slo-legal`: `draft`, `translate`, `triage`, `prepare`. Hard-blocks `draft` for regulated-domain matters above the £5,000 threshold with counterparty representation, and ALL GDPR-related documents — routing to `triage`. UK only in v1; non-UK jurisdictions emit the canonical "v1 supports UK only" error. Default professional routing for HMRC matters is the accountant (overrides the gate-1-regulated default of `lawyer` per the per-skill override pattern documented in `references/biz/jurisdiction-uk.md`).
Use this skill when a UK seed-stage founder needs first-cut equity artifacts (cofounder split rationale, vesting schedule with 4-year/1-year-cliff, cap-table snapshot), needs a vesting agreement / option grant translated to plain English, needs to triage whether a lawyer + accountant are required for an equity matter, or needs to prepare for an equity-related professional call. Same four-mode advisor pattern as `/slo-legal` and `/slo-accounting`: `draft`, `translate`, `triage`, `prepare`. Hard-blocks `draft` for regulated / >£5k / counterparty-with-lawyer / GDPR matters. Cites HMRC VCM index for SEIS / EIS qualifying-rights checks. Routes preferential-rights matters to lawyer; tax matters to accountant; complex cap-table changes to lawyer + accountant.
Use this skill when a UK seed-stage founder needs a self-assessment artifact: 12-question check (stress / runway / cofounder / health / family / finances), worst-case-runway worksheet (cash + months + cut-cost levers + pivot options), optional YC application prep (10 standard YC application questions). Generator pattern, no mode arg. Output: `docs/biz/founder-check.md` (CONFIDENTIAL — self-assessment is highly personal data even though it's the founder writing about themselves).
Use this skill when a UK seed-stage founder needs first-cut fundraising artifacts (SAFE / cap-and-discount math worksheet, pitch narrative, investor update, term-sheet redline preparation), needs an investor-supplied legal document translated to plain English, needs to triage whether SEIS / EIS Advance Assurance / lawyer / accountant is genuinely required, or needs to prepare for an investor / lawyer / accountant call. Same four-mode advisor pattern as `/slo-legal`, `/slo-accounting`, `/slo-equity`. Hard-blocks `draft` for regulated / >£5k / counterparty-with-lawyer / GDPR matters. RUNS THE SEIS / EIS ADVANCE ASSURANCE PRE-CHECK on every fundraise interaction and refuses to draft any term-sheet-adjacent artifact without confirming AA is at least 6 weeks ahead of any signature. Cites HMRC VCM index + IR35 / CEST factors for cross-cutting status determinations.
Use this skill when a UK seed-stage founder needs an artifact for a hire: sourcing playbook, interview rubric, offer cadence, onboarding checklist. Generator with mode_arg covering role shape (`swe | ae | designer | ops` in v1; founder may extend with documented reason). Output: `docs/biz/hires/<role>-<name>.md` (confidential). MANDATORY IR35 triage gate per `references/biz/ir35-cest-factors.md` — every hire decision invokes the seven IR35 factors check before the offer is made.
Use this skill when a UK seed-stage founder needs first-cut legal documents (NDA, contractor SOW, IP assignment, T&Cs), needs a legal document received from a counterparty translated to plain English, needs to triage whether a matter requires a lawyer, or needs to prepare for a lawyer call. Operates as an advisor with four modes: `draft`, `translate`, `triage`, `prepare`. Hard-blocks `draft` for regulated domains, deal value > £5,000, counterparty with a lawyer (or being asked to sign their paper), and ALL GDPR-related documents — routing those situations to `triage` instead. UK only in v1; non-UK jurisdictions emit an explicit "v1 supports UK only" error rather than degrading silently. Cites onenda.org (CC BY-ND 4.0, verbatim render) for NDA work and JPP Law fixed-fee public pricing for ROI provenance.
Use this skill after /slo-ideate produces an idea doc, when the user says "research this", "check the market", "what's out there", "is this viable", or when a design decision depends on data the codebase cannot answer. Use host-native research tools first to produce a sourced dossier covering market, competitors, technical prior art, and regulatory constraints. An optional Claude batch backend exists for users who explicitly want it. Do not use for third-party library API reference — that is get-api-docs / chub.
Use this skill to generate or extend a Semgrep rule pack for a Rust workspace. In bootstrap mode (no flags), seeds `.semgrep/rust/` with the top-10 Rust CWE classes (CWE-755 panic-DoS, CWE-416 UAF, CWE-697 incorrect-comparison, etc.). In extend mode (`--extend`), takes an agent-found bug summary + fix diff and produces 3-5 variation rules with auto-derived corpus, appended to the existing pack ONLY after `cargo xtask sast-verify gate` passes for every new rule. Trigger when the user says "generate Rust SAST rules", "bootstrap a Semgrep pack", or hits a bug they want to compound into a regression rule. Do NOT run in CI on attacker-supplied PR diffs.
Use this skill to verify an existing Semgrep rule pack against the deterministic `cargo xtask sast-verify gate` (validate + test + check-coverage + check-clean). Read-only — never writes, never edits, never reaches the network. Reports per-rule pass/fail. Trigger when the user says "verify the SAST pack", "check rules are still passing gate", or before merging a PR that touches `.semgrep/<lang>/`.
Use this skill when a UK seed-stage founder needs to prepare for a user interview, draft an interview script, or extract structured signal from a completed interview. Generator pattern (single-mode, no four-mode contract). Output: `docs/biz/users/<date>-<name>.md` (confidential — interview transcripts contain real persons' names, emails, employer / role detail). Founder's repo `.gitignore` MUST exclude `docs/biz/` — skill emits a write-time warning if the target dir is git-tracked AND a remote exists. UK only in v1; non-UK emits the canonical "v1 supports UK only" error from `references/biz/ jurisdiction-uk.md`. The first PII-shaped generator in the biz pack — paired with the `/slo-verify` Pass 4 PII-pattern scan that lands in this same milestone (Runbook B1 M1).