All authors

Claude Skills by chrishuffman5
github.com/chrishuffman5446 skills0 installs53 views
- OverviewTop-level entry point for all networking technologies -- routing/switching, firewalls, DNS, VPN, SD-WAN, wireless, DC fabric, cloud networking, IPAM, automation, and monitoring -- for cross-platform or architectural questions. Use for \"network architecture\", \"firewall rule\", \"routing protocol\", \"VLAN design\", \"BGP peering\", \"OSPF area\", \"VPN tunnel\", \"DNS resolution\", \"load balancer\", \"SD-WAN\", \"network segmentation\", \"EVPN-VXLAN\", \"ACL\", \"NAT\" when no specific tec...Votes: 0GitHub stars: 4
- PanosExpert coverage of Palo Alto Networks PAN-OS across all versions: SP3 architecture, App-ID, Content-ID, User-ID, security policy design, Panorama management, WildFire, decryption, zone design, HA, and CLI troubleshooting. Use for \"PAN-OS\", \"Palo Alto\", \"App-ID\", \"Panorama\", \"WildFire\", \"Content-ID\", \"User-ID\", \"GlobalProtect\", \"PA-\", \"security profile\", \"IronSkillet\". Do NOT use for cross-vendor comparison, platform selection, or category-wide architecture -- use the `fi...Votes: 0GitHub stars: 4
- PfsenseExpert coverage of pfSense (Plus and CE) across all versions: FreeBSD pf packet filter, CARP high availability, OpenVPN/WireGuard/IPsec, pfBlockerNG, Suricata/Snort IDS/IPS, ALTQ/limiters traffic shaping, Netgate hardware, package system, and WebGUI administration. Use for \"pfSense\", \"Netgate\", \"pfBlockerNG\", \"CARP HA\", \"pfsync\", \"ALTQ\", \"pfSense Plus\", \"pfSense CE\", \"Netgate 4100\", \"Netgate 6100\". Do NOT use for cross-vendor comparison, platform selection, or category-wid...Votes: 0GitHub stars: 4
- PowerdnsExpert coverage of the PowerDNS suite (Authoritative Server 5.0, Recursor 5.4, and DNSdist 2.0): pluggable backends (MySQL/PostgreSQL/LDAP), DNSSEC auto-signing, REST API, Lua scripting, views, RPZ threat blocking, YAML configuration, DoH/DoT termination, and DNS load balancing. Use for \"PowerDNS\", \"pdns\", \"pdnsutil\", \"Recursor\", \"DNSdist\", \"PowerDNS API\", \"PowerDNS backend\", \"PowerDNS DNSSEC\". Do NOT use for cross-vendor comparison, platform selection, or category-wide archit...Votes: 0GitHub stars: 4
- PrtgExpert coverage of PRTG Network Monitor by Paessler: sensor-based monitoring model, auto-discovery, SNMP/WMI/flow/packet sensors, maps and dashboards, notification and escalation, PRTG Hosted Monitor SaaS, remote probes, and REST API automation. Use for \"PRTG\", \"Paessler\", \"PRTG sensor\", \"PRTG Hosted Monitor\", \"remote probe\", \"PRTG map\", \"PRTG auto-discovery\". Do NOT use for cross-vendor comparison, platform selection, or category-wide architecture -- use the `network-monitoring...Votes: 0GitHub stars: 4
- Route53Expert coverage of AWS Route 53: hosted zones, alias records, routing policies (weighted/latency/failover/geolocation/geoproximity/IP-based), health checks, DNSSEC, Route 53 Resolver, DNS Firewall, and Application Recovery Controller. Use for \"Route 53\", \"AWS DNS\", \"hosted zone\", \"alias record\", \"latency routing\", \"failover routing\", \"Route 53 health check\", \"DNS Firewall\", \"Route 53 Resolver\". Do NOT use for cross-vendor comparison, platform selection, or category-wide arch...Votes: 0GitHub stars: 4
- Routing SwitchingCross-platform comparison and architecture guidance for all routing and switching technologies: L2/L3 design, BGP, OSPF, STP, VLAN architecture, VXLAN/EVPN, and campus/DC fabric design. Use for \"routing protocol\", \"switching\", \"BGP vs OSPF\", \"VLAN design\", \"STP\", \"spine-leaf\", \"campus network\", \"EVPN-VXLAN\", \"ECMP\", \"VRF\". Do NOT use for cisco-ios-xe-, cisco-nxos-, arista-eos-, juniper-junos-, aruba-aoscx-, or meraki-specific configuration -- use that technology's own skill.Votes: 0GitHub stars: 4
- Sd WanCross-platform comparison and architecture guidance for SD-WAN technologies: overlay/underlay architecture, application-aware routing, SLA-driven path selection, ZTP, orchestration, and when to use SD-WAN vs MPLS. Use for \"SD-WAN comparison\", \"SD-WAN architecture\", \"SD-WAN selection\", \"overlay vs underlay\", \"application-aware routing\", \"SD-WAN migration\", \"MPLS replacement\", \"WAN optimization\". Do NOT use for cisco-sdwan- or fortinet-sdwan-specific configuration -- use that te...Votes: 0GitHub stars: 4
- Solarwinds NpmExpert coverage of SolarWinds Network Performance Monitor on the Orion platform: SNMP/WMI/ICMP polling, Orion architecture, polling engines, NetPath, PerfStack, NTA flow analysis, NCM config management, custom alerts, SWQL queries, and Orion SDK automation. Use for \"SolarWinds\", \"NPM\", \"Orion\", \"NetPath\", \"PerfStack\", \"SWQL\", \"NTA\", \"NCM\", \"SAM\", \"Orion SDK\", \"polling engine\". Do NOT use for cross-vendor comparison, platform selection, or category-wide architecture -- us...Votes: 0GitHub stars: 4
- SonicExpert coverage of SONiC (Software for Open Networking in the Cloud): Redis database architecture, SAI abstraction layer, SwSS orchestration, syncd, FRRouting BGP/OSPF, ConfigDB/YANG, KLISH CLI, DASH SmartNIC offload, whitebox hardware, and enterprise SONiC deployments. Use for \"SONiC\", \"SAI\", \"SwSS\", \"syncd\", \"ConfigDB\", \"ASIC_DB\", \"SONiC CLI\", \"whitebox switch\", \"SONiC DASH\", \"SONiC BGP\". Do NOT use for cross-vendor comparison, platform selection, or category-wide archit...Votes: 0GitHub stars: 4
- Sophos FirewallExpert coverage of Sophos Firewall (XGS/XGV) across all versions: Xstream architecture, three-lane processing, Synchronized Security heartbeat, TLS inspection, Sophos Central management, ZTNA gateway, SD-WAN, CIS health checks, and v22 containerized services. Use for \"Sophos Firewall\", \"XGS\", \"Xstream\", \"Synchronized Security\", \"Security Heartbeat\", \"Sophos Central\", \"Sophos ZTNA\", \"Sophos WAF\", \"Sophos SD-WAN\". Do NOT use for cross-vendor comparison, platform selection, or ...Votes: 0GitHub stars: 4
- Terraform NetworkExpert coverage of Terraform network infrastructure automation: network providers (ACI, Meraki, PAN-OS, FortiOS, F5 BIG-IP), state management, plan/apply workflow, modules, remote state, and CI/CD integration for network IaC. Use for \"Terraform network\", \"Terraform ACI\", \"Terraform Meraki\", \"Terraform PAN-OS\", \"Terraform FortiOS\", \"Terraform F5\", \"Terraform provider network\", \"HCL network\", \"terraform plan network\". Do NOT use for cross-vendor comparison, platform selection,...Votes: 0GitHub stars: 4
- ThousandeyesExpert coverage of Cisco ThousandEyes synthetic monitoring and internet intelligence platform: Cloud/Enterprise/Endpoint agent types, test types, path visualization, Internet Insights outage detection, Cisco SD-WAN integration, BGP monitoring, and API automation. Use for \"ThousandEyes\", \"path visualization\", \"Internet Insights\", \"Cloud Agent\", \"Enterprise Agent\", \"Endpoint Agent\", \"synthetic monitoring\", \"ThousandEyes test\". Do NOT use for cross-vendor comparison, platform sel...Votes: 0GitHub stars: 4
- UnboundExpert coverage of Unbound recursive resolver: unbound.conf tuning, DNSSEC validation, DoT/DoH encrypted DNS, module architecture (validator, iterator, cachedb, python), local zones, pfSense/OPNsense integration, Pi-hole upstream configuration, and qname minimisation. Use for \"Unbound\", \"unbound.conf\", \"recursive resolver\", \"pfSense DNS\", \"OPNsense DNS\", \"Pi-hole upstream\", \"qname minimisation\", \"Unbound DNSSEC\". Do NOT use for cross-vendor comparison, platform selection, or c...Votes: 0GitHub stars: 4
- Vmware NsxExpert coverage of VMware NSX across all versions: NSX Manager, transport nodes, Distributed Firewall (DFW), T0/T1 gateways, Geneve overlay, Federation, NSX ALB, and vDefend security. Use for \"VMware NSX\", \"NSX Manager\", \"DFW\", \"distributed firewall\", \"T0 gateway\", \"T1 gateway\", \"Geneve\", \"NSX Federation\", \"vDefend\", \"NSX ALB\". Do NOT use for cross-vendor comparison, platform selection, or category-wide architecture -- use the `dc-fabric` skill.Votes: 0GitHub stars: 4
- VpnCross-platform comparison and architecture guidance for all VPN technologies: IPsec/IKEv2, WireGuard, SSL VPN, remote access VPN, site-to-site VPN, crypto algorithm selection, and VPN architecture design. Use for \"VPN comparison\", \"VPN architecture\", \"site-to-site VPN\", \"remote access VPN\", \"IPsec vs SSL\", \"VPN selection\", \"crypto algorithms\", \"VPN tunnel\", \"VPN troubleshooting\". Do NOT use for ipsec-, wireguard-, or cisco-secure-client-specific configuration -- use that tec...Votes: 0GitHub stars: 4
- Windows DnsExpert coverage of Windows DNS Server across all versions: AD-integrated zones, replication scopes, DNS policies, zone scopes, DNSSEC, aging/scavenging, and PowerShell DNS management. Use for \"Windows DNS\", \"AD-integrated zones\", \"DNS policy\", \"zone scope\", \"DnsServer PowerShell\", \"dnscmd\", \"scavenging\", \"DNS Server role\". Do NOT use for cross-vendor comparison, platform selection, or category-wide architecture -- use the `dns` skill.Votes: 0GitHub stars: 4
- WireguardExpert coverage of WireGuard VPN: Noise protocol framework, Cryptokey Routing, wg-quick configuration, AllowedIPs routing, PSK post-quantum protection, kernel vs userspace implementations, deployment patterns (hub-spoke, site-to-site, mesh), Tailscale/Headscale/Netmaker orchestration, and container networking. Use for \"WireGuard\", \"wg-quick\", \"AllowedIPs\", \"Cryptokey Routing\", \"wg genkey\", \"Tailscale\", \"Headscale\", \"Netmaker\", \"wireguard-go\", \"PersistentKeepalive\". Do NOT ...Votes: 0GitHub stars: 4
- WirelessCross-platform comparison and architecture guidance for all enterprise wireless technologies: Wi-Fi standards (6/6E/7), RF design, deployment architecture, site surveys, roaming, and platform selection. Use for \"wireless comparison\", \"Wi-Fi architecture\", \"Wi-Fi 6\", \"Wi-Fi 6E\", \"Wi-Fi 7\", \"WLAN design\", \"wireless migration\", \"site survey\", \"RF design\", \"wireless platform selection\". Do NOT use for cisco-wireless-, aruba-wireless-, or juniper-mist-specific configuration -- ...Votes: 0GitHub stars: 4
- ApparmorAppArmor on Ubuntu across versions 20.04-26.04: Mandatory Access Control via path-based profile enforcement, profile modes, profile structure and syntax, abstractions, snap integration, unprivileged user namespace restrictions, and denial troubleshooting. Use when: \"AppArmor\", \"apparmor\", \"aa-status\", \"aa-genprof\", \"aa-logprof\", \"aa-enforce\", \"aa-complain\", \"apparmor profile\", \"apparmor denial\", \"DENIED apparmor\", \"snap confinement\", \"unprivileged user namespace\". Do N...Votes: 0GitHub stars: 4
- Btrfs SnapperBtrfs filesystem and Snapper snapshot management on SUSE Linux Enterprise Server: Copy-on-Write architecture, subvolume management, RAID profiles, snapshot creation and rollback, compression (zstd/lzo/zlib), quota groups (qgroups), Snapper retention policies, GRUB snapshot integration, btrfs send/receive, maintenance (scrub, balance, defragment), and ENOSPC/fragmentation/qgroup troubleshooting. Use when: \"Btrfs\", \"btrfs\", \"Snapper\", \"snapper\", \"snapshot\", \"rollback\", \"subvolume\"...Votes: 0GitHub stars: 4
- DebianDebian across supported releases (11 Bullseye, 12 Bookworm, 13 Trixie): Debian philosophy (DFSG, Social Contract), the three-suite release pipeline (unstable/testing/stable), dpkg/apt package management with pinning and backports, preseed automated installation, Debian Security Advisories (DSA), AppArmor, debsecan CVE tracking, reportbug, and the Debian BTS. Use when: \"Debian\", \"debian\", \"Bullseye\", \"Bookworm\", \"Trixie\", \"dpkg\", \"apt-get\", \"backports\", \"preseed\", \"reportbug...Votes: 0GitHub stars: 4
- Failover ClusteringWindows Server Failover Clustering (WSFC) across Windows Server 2016-2025: cluster architecture, quorum models, Cluster Shared Volumes, Cluster-Aware Updating, cluster networking, resource groups, and high availability patterns. Use when: \"failover cluster\", \"WSFC\", \"quorum\", \"CSV\", \"cluster shared volume\", \"CAU\", \"cluster-aware updating\", \"cluster validation\", \"Windows cluster\", \"cluster node\", \"cluster resource\", \"stretch cluster\", \"cluster sets\", \"split-brain\", ...Votes: 0GitHub stars: 4
- Hyper VHyper-V on Windows Server across versions 2016-2025: hypervisor architecture, VM generations, memory management, virtual networking, virtual storage, integration services, checkpoints, live migration, replication, and GPU partitioning. Use when: \"Hyper-V\", \"virtual machine\", \"VM\", \"live migration\", \"virtual switch\", \"VHDX\", \"VHD\", \"Hyper-V Replica\", \"checkpoint\", \"nested virtualization\", \"GPU-P\", \"GPU partitioning\", \"vSwitch\", \"SET teaming\", \"SR-IOV\", \"dynamic m...Votes: 0GitHub stars: 4
- Macos Developer ToolchainmacOS developer toolchain management: Xcode versions and lifecycle, Swift migration (5.9 to 6.0 to 6.2), code signing, notarization, Command Line Tools, Foundation Models, CI/CD pipelines, and Homebrew. Covers Xcode 15 through Xcode 26 and macOS 14 Sonoma through macOS 26 Tahoe. Use when: \"Xcode\", \"xcode\", \"Swift\", \"swift\", \"codesign\", \"notarize\", \"notarytool\", \"stapler\", \"Developer ID\", \"code signing\", \"provisioning profile\", \"xcode-select\", \"Command Line Tools\", \"...Votes: 0GitHub stars: 4
- Macos Mdm DeploymentmacOS MDM deployment: Declarative Device Management (DDM), Apple Business Manager (ABM), Automated Device Enrollment (ADE), configuration profiles, restrictions, supervised mode, MDM migration, and Recovery Lock. Covers macOS 14 Sonoma through macOS 26 Tahoe. Use when: \"MDM\", \"Apple Business Manager\", \"ABM\", \"DEP\", \"ADE\", \"Automated Device Enrollment\", \"configuration profile\", \"mobileconfig\", \"DDM\", \"Declarative Device Management\", \"MDM migration\", \"Jamf\", \"Intune\", ...Votes: 0GitHub stars: 4
- Macos Platform SsomacOS Platform SSO (PSSO): enterprise IdP integration (Okta, Microsoft Entra ID, Jamf Connect), authentication policies, ADE simplified setup, NFC Tap-to-Login, and token management. Covers macOS 13 Ventura through macOS 26 Tahoe. Use when: \"Platform SSO\", \"PSSO\", \"Okta macOS\", \"Entra ID macOS\", \"macOS SSO\", \"login window SSO\", \"FileVaultPolicy\", \"LoginPolicy\", \"UnlockPolicy\", \"Tap to Login\", \"NFC login\", \"IdP macOS\". Do NOT use for Entra ID/Okta tenant-side IdP config...Votes: 0GitHub stars: 4
- MacosmacOS across all supported versions (14 Sonoma, 15 Sequoia, 26 Tahoe): XNU kernel, launchd, APFS, Apple Silicon vs Intel, Rosetta 2, SIP, Gatekeeper, code signing, notarization, FileVault, Homebrew, Time Machine, zsh, networksetup/scutil, and MDM/configuration profiles. Use when: \"macOS\", \"Mac\", \"Apple Silicon\", \"Rosetta\", \"Homebrew\", \"brew\", \"launchd\", \"APFS\", \"FileVault\", \"SIP\", \"Gatekeeper\", \"Time Machine\", \"networksetup\", \"defaults write\", \"diskutil\", \"sw_ve...Votes: 0GitHub stars: 4
- OverviewCross-platform operating systems expertise for service management, packaging/patching, security frameworks, filesystems, and OS selection across Windows Server, Windows Client, RHEL, Rocky Linux/AlmaLinux, Ubuntu, Debian, SLES, and macOS. Use when the question is OS-agnostic: \"operating system\", \"which Linux distribution\", \"systemd fundamentals\", \"SELinux vs AppArmor\", \"Group Policy vs MDM\", \"kernel tuning\", \"sysctl\", \"patching cadence\", \"package management strategy\", \"OS h...Votes: 0GitHub stars: 4
- Rhel PodmanPodman and the container ecosystem on Red Hat Enterprise Linux across RHEL 8, 9, 10: daemonless container architecture, rootless containers, pods, networking (CNI/Netavark), storage, Quadlet systemd integration, Buildah, Skopeo, auto-update, container security, and troubleshooting. Use when: \"Podman\", \"podman\", \"container\", \"Buildah\", \"buildah\", \"Skopeo\", \"skopeo\", \"rootless container\", \"quadlet\", \"container image\", \"OCI\", \"Containerfile\", \"pod\". Do NOT use for Podma...Votes: 0GitHub stars: 4
- RhelRed Hat Enterprise Linux across all supported versions (8, 9, 10): systemd, dnf/rpm, Application Streams, firewalld, NetworkManager, storage (LVM, XFS, Stratis), subscription management, Cockpit, SELinux basics, crypto policies, audit, and performance tuning. Use when: \"RHEL\", \"Red Hat\", \"Red Hat Enterprise Linux\", \"dnf\", \"systemd\", \"subscription-manager\", \"Application Streams\", \"firewalld\", \"tuned\", \"SELinux\", \"rpm-ostree\", \"bootc\", \"Cockpit\", \"nmcli\", \"journalct...Votes: 0GitHub stars: 4
- Rocky AlmaRocky Linux and AlmaLinux — RHEL-compatible enterprise Linux distributions — across versions 8, 9, 10: the rebuild process, Rocky vs Alma differences (binary clone vs ABI compatible), CentOS migration (migrate2rocky, almalinux-deploy, ELevate), repo management (EPEL, CRB, SIGs, Synergy), Secure Boot, GPG keys, and distro selection. Use when: \"Rocky Linux\", \"Rocky\", \"AlmaLinux\", \"Alma\", \"CentOS migration\", \"ELevate\", \"RHEL compatible\", \"RHEL clone\", \"migrate2rocky\". Do NOT us...Votes: 0GitHub stars: 4
- SelinuxSELinux on Red Hat Enterprise Linux across RHEL 8, 9, 10: Mandatory Access Control, type enforcement, security contexts, booleans, file and port context management, custom policy modules, container SELinux integration, and AVC troubleshooting. Use when: \"SELinux\", \"selinux\", \"AVC\", \"audit2why\", \"sealert\", \"semanage\", \"restorecon\", \"security context\", \"type enforcement\", \"boolean\", \"selinux denial\", \"selinux troubleshoot\". Do NOT use for general RHEL administration — us...Votes: 0GitHub stars: 4
- Sles Ha ExtensionSUSE Linux Enterprise High Availability Extension: Corosync cluster communication (Totem protocol, transport modes, knet), Pacemaker resource management (CIB, Policy Engine, CRMd), resource types, fencing/STONITH/SBD, quorum configuration, SAP HANA HA, HAWK console, crm shell, and cluster diagnostics. Use when: \"Pacemaker\", \"Corosync\", \"HAWK\", \"SBD\", \"STONITH\", \"HA cluster\", \"high availability\", \"crm_mon\", \"crm configure\", \"resource agent\", \"fencing\", \"cluster resource\...Votes: 0GitHub stars: 4
- SlesSUSE Linux Enterprise Server across supported service packs (15 SP5, 15 SP6): module/extension system, YaST, zypper, Btrfs default filesystem, Snapper basics, Wicked networking, transactional updates, RMT mirroring, supportconfig, saptune, AppArmor, and SUSE-specific hardening. Use when: \"SLES\", \"SUSE\", \"SUSE Linux Enterprise\", \"zypper\", \"YaST\", \"Btrfs\", \"Snapper\", \"SUSEConnect\", \"Wicked\", \"SUSE Manager\", \"supportconfig\", \"transactional-update\", \"SLE Micro\". Do NOT u...Votes: 0GitHub stars: 4
- UbuntuUbuntu across all supported LTS versions (20.04, 22.04, 24.04, 26.04): apt/dpkg/snap package management, Netplan declarative networking, cloud-init, UFW firewall, AppArmor, Ubuntu Pro/ESM/Livepatch, Subiquity/autoinstall, ZFS root, LXD/Incus, and MicroK8s. Use when: \"Ubuntu\", \"ubuntu\", \"apt\", \"dpkg\", \"snap\", \"Netplan\", \"cloud-init\", \"UFW\", \"Livepatch\", \"Ubuntu Pro\", \"ESM\", \"Subiquity\", \"autoinstall\", \"LXD\". Do NOT use for AppArmor profile syntax/troubleshooting dep...Votes: 0GitHub stars: 4
- Windows ClientWindows desktop operating systems (Windows 10 and Windows 11): desktop app model (Win32/UWP/MSIX/winget), editions and licensing, Intune/MDM management, Windows Update for Business, BitLocker, Windows Hello, desktop security (Defender, SmartScreen, ASR), desktop diagnostics (SFC, DISM, Reliability Monitor), and migration planning. Use when: \"Windows 10\", \"Windows 11\", \"Win10\", \"Win11\", \"Windows desktop\", \"Windows client\", \"BitLocker\", \"Intune\", \"Windows Update\", \"winget\", ...Votes: 0GitHub stars: 4
- Windows ServerMicrosoft Windows Server across all versions (2016-2025): server roles/features, PowerShell administration, Active Directory, storage (NTFS/ReFS/Storage Spaces), networking (SMB/NIC Teaming/SET), security hardening, performance monitoring, and diagnostics. Use when: \"Windows Server\", \"Server Core\", \"PowerShell remoting\", \"Active Directory\", \"Group Policy\", \"Storage Spaces Direct\", \"S2D\", \"SMB\", \"NIC Teaming\", \"NTFS\", \"ReFS\", \"WSUS\", \"Windows Admin Center\", \"WAC\", \...Votes: 0GitHub stars: 4
- WslWindows Subsystem for Linux (WSL) on Windows 10 and Windows 11: WSL1 vs WSL2 architecture, filesystem performance (ext4 VHD, 9P protocol), networking (NAT/mirrored mode, DNS tunneling, VPN compatibility), GPU passthrough, WSLg, systemd support, .wslconfig/wsl.conf, distro management, memory management (Vmmem), development workflows (VS Code Remote, Docker Desktop, Dev Containers), and enterprise deployment. Use when: \"WSL\", \"WSL2\", \"WSL1\", \"Windows Subsystem for Linux\", \"wsl.conf\", ...Votes: 0GitHub stars: 4
- 1password SecretsExpert agent for 1Password Secrets Automation. Covers service accounts, Connect Server (self-hosted bridge), SDKs (Node.js, Python, Go), CLI (op), GitHub Actions integration, Terraform provider, and Kubernetes operator. WHEN: \"1Password\", \"1Password Connect\", \"1Password service account\", \"op CLI\", \"1Password SDK\", \"1Password Kubernetes\", \"1Password Terraform\", \"1Password GitHub Actions\".Votes: 0GitHub stars: 4
- AbnormalExpert agent for Abnormal Security. Covers API-based behavioral AI email protection, BEC detection, vendor email compromise, account takeover, and native M365/Google Workspace integration without MX changes. WHEN: \"Abnormal Security\", \"Abnormal AI\", \"behavioral email security\", \"BEC detection\", \"vendor email compromise\", \"VEC\", \"API email security\", \"account takeover email\", \"Abnormal SIEM\".Votes: 0GitHub stars: 4
- Ad CsExpert agent for Active Directory Certificate Services. Provides deep expertise in enterprise PKI, certificate templates, enrollment, CRL/OCSP, and ESC1-ESC16 vulnerability detection and remediation. WHEN: \"AD CS\", \"ADCS\", \"PKI\", \"certificate template\", \"auto-enrollment\", \"CRL\", \"OCSP\", \"ESC1\", \"ESC8\", \"Certify\", \"Certipy\", \"certificate authority\", \"enterprise CA\", \"certificate vulnerability\".Votes: 0GitHub stars: 4
- Ad DsExpert agent for Active Directory Domain Services across all versions. Provides deep expertise in AD architecture, replication, FSMO roles, Group Policy, Kerberos, LDAP, tiered administration, and AD hardening. WHEN: \"Active Directory\", \"AD DS\", \"domain controller\", \"FSMO\", \"Group Policy\", \"GPO\", \"replication\", \"dcdiag\", \"repadmin\", \"NTDS\", \"Kerberos\", \"LDAP\", \"trust\", \"LAPS\", \"gMSA\", \"AD hardening\".Votes: 0GitHub stars: 4
- Ad FsExpert agent for Active Directory Federation Services. Provides deep expertise in claims-based authentication, SAML/OIDC federation, WAP, claims rules, relying party trusts, and migration to Entra ID. WHEN: \"AD FS\", \"ADFS\", \"federation services\", \"claims rules\", \"relying party trust\", \"WAP\", \"Web Application Proxy\", \"SAML federation AD\", \"AD FS migration\", \"token signing certificate\".Votes: 0GitHub stars: 4
- Akamai WafExpert agent for Akamai App & API Protector (WAAP). Covers adaptive security engine, WAF policies, DDoS protection, bot management, API security, reputation scoring, Kona Site Defender, and Akamai Security Center. WHEN: \"Akamai WAF\", \"App and API Protector\", \"Akamai WAAP\", \"Kona Site Defender\", \"Akamai bot manager\", \"Akamai adaptive security\", \"Akamai reputation\", \"Akamai API Security\", \"Akamai Security Center\".Votes: 0GitHub stars: 4
- AppsecExpert routing agent for Application Security (AppSec). Covers OWASP Top 10, secure SDLC, DevSecOps pipelines, threat modeling, and ASVS. Routes to SAST, DAST, SCA, and WAF technology agents. WHEN: \"application security\", \"AppSec\", \"OWASP\", \"secure SDLC\", \"DevSecOps\", \"shift-left\", \"threat modeling\", \"ASVS\", \"vulnerability scanning\", \"security pipeline\". Do NOT use for tool-specific questions -- use the `sast`, `dast`, `sca`, or `waf` skill.Votes: 0GitHub stars: 4
- AquaExpert agent for Aqua Security platform. Covers full container lifecycle security — image scanning, KSPM, runtime protection with Aqua Enforcer, Dynamic Threat Analysis (DTA), vShield virtual patching, Trivy OSS integration, and Kubernetes-native deployment. WHEN: \"Aqua Security\", \"Aqua platform\", \"Aqua Enforcer\", \"Aqua image scanning\", \"vShield\", \"DTA\", \"Dynamic Threat Analysis\", \"Aqua KSPM\", \"Aqua runtime\", \"Aqua supply chain\", \"kube-bench Aqua\", \"Trivy Aqua\".Votes: 0GitHub stars: 4
- ArcherExpert agent for RSA Archer GRC. Covers quantitative risk management, regulatory and corporate compliance, audit management, IT and security risk, operational risk, third-party governance, business resiliency, custom data model configuration, and on-premises or SaaS deployment. WHEN: \"Archer\", \"RSA Archer\", \"Archer GRC\", \"Archer risk\", \"Archer compliance\", \"Archer audit\", \"Archer TPRM\", \"Archer configuration\".Votes: 0GitHub stars: 4
- AsmRouting agent for External Attack Surface Management (EASM). Covers internet asset discovery, shadow IT, exposure identification, and routes to platform-specific agents for Falcon Surface, Xpanse, Defender EASM, and Censys. WHEN: \"attack surface management\", \"EASM\", \"external attack surface\", \"internet-exposed assets\", \"shadow IT discovery\", \"unknown assets\", \"ASM\". Do NOT use for platform-specific questions -- use the `falcon-surface`, `xpanse`, `defender-easm`, or `censys` skill.Votes: 0GitHub stars: 4
- Auth0Expert agent for Auth0 customer identity platform. Provides deep expertise in Universal Login, Actions, Organizations, Connections, RBAC, Attack Protection, and machine-to-machine authentication for CIAM scenarios. WHEN: \"Auth0\", \"Universal Login\", \"Auth0 Actions\", \"Auth0 Organizations\", \"CIAM\", \"Auth0 connections\", \"Auth0 rules\", \"Auth0 hooks\", \"Auth0 tenant\", \"Auth0 attack protection\", \"Auth0 FGA\".Votes: 0GitHub stars: 4