Use when an AI agent has been compromised, behaved unexpectedly, executed unauthorized actions, or may have had credentials exposed. Use when CLAUDE.md was modified without authorization, a skill executed a malicious payload, an agent accessed files outside its scope, or suspicious tool calls were detected. Triggers: "agent compromised", "agent behaved unexpectedly", "suspicious agent behavior", "CLAUDE.md modified", "skill executed payload", "agent accessed credentials", "unauthorized tool calls", "agent incident", "agent compromise response", "agent forensics", "credential exposed by agent", "agent wrote unexpected files", "memory poisoned", "hook fired", "agent anomaly".
Use when auditing AI/LLM systems for security vulnerabilities, reviewing prompt injection risks, auditing MCP server tool integrations, assessing AI agent behavioral drift, reviewing credential scoping for agents, or designing safe agentic systems. Triggers: "AI security", "LLM security", "prompt injection", "tool abuse", "MCP security", "agent security", "behavioral drift", "AI agent audit", "insecure plugin", "agentic threat", "LLM threat", "indirect injection", "credential exposure", "excessive agency".
Use when implementing animations, transitions, hover effects, page transitions, exit animations, scroll-linked animations, drag interactions, or motion design in React/Next.js. Triggers: "animation", "animate", "framer motion", "motion", "transition", "hover effect", "page transition", "AnimatePresence", "spring physics", "micro-interaction", "scroll animation", "exit animation", "layout animation", "shared element transition", "gesture".
Use when designing APIs, defining interfaces, choosing between REST and alternatives, applying Hyrum's Law, designing resilience patterns (circuit breaker, retry with backoff, health checks), writing API contracts, or reviewing API design for consistency and correctness. Triggers: "design an API", "API design", "REST API", "interface design", "HTTP endpoints", "contract-first", "Hyrum's Law", "circuit breaker", "retry logic", "health check endpoint".
Use when diagnosing slow API responses, fixing N+1 query problems, optimizing database queries, adding indexes, debugging memory leaks, profiling server-side code, setting API latency budgets, or detecting performance regressions. Triggers: "slow API", "slow query", "N+1", "database performance", "N+1 queries", "memory leak", "backend performance", "profiling", "API latency", "EXPLAIN plan", "missing index", "unbounded fetch".
Use when transcribing video audio, generating visual descriptions from video frames, or creating rough cut edit sequences from video footage. A three-phase AI-assisted video editing workflow: transcribe audio with WhisperX, analyze frames with FFmpeg, create rough cut YAML for Buttercut. Triggers: "Buttercut", "rough cut", "video rough cut", "video transcription", "WhisperX", "video analysis", "visual transcript", "video sequence", "video scene", "Final Cut Pro XML", "video editing workflow", "video footage".
Use when reviewing code, giving feedback on a PR, auditing a codebase for quality problems, or evaluating code before submitting. Triggers: "review this", "code review", "review this PR", "give me feedback on this code", "audit this code", "what's wrong with this", "is this implementation good", "critique this", "check this for issues".
Use when evaluating whether code meets quality standards, checking naming conventions, assessing complexity thresholds, identifying anti-patterns, understanding what good code looks like, or applying quality standards to your own code before submitting. Triggers: "is this code good", "code quality", "does this follow best practices", "naming conventions", "is this too complex", "code standards", "what makes good code", "anti-patterns".