All authors

Claude Skills by HoangNguyen0403
github.com/HoangNguyen04031,434 skills30 installs1,975 views
- Cyber Detection ValidationNo. An action record without a usable, linked observation is a **telemetry-gap**, not `detected`. Record: - **Action evidence:** exists, linked by test ID/entity/time/source. - **Observation evidence:** absent or unusable; record observation time and limitation. - **Finding status:** telemetry-gap. - **Do not classify as:** `blocked`, `prevented`, `detected`, or `responded`; detection is not response. - Include scope reference, owner, skill/version/source, and framework/version/ID/relation/ra...Votes: 0GitHub stars: 571
- Cyber Detection ValidationDo not record a successful detection. Under the `cyber-detection-validation` guardrail, no defensive outcome exists without linked action and observation evidence. Record: - **Finding status:** `blocked` - **Reason:** runtime denied the exercise because scope approval was missing; the action did not run. - **Action evidence:** denied/absent; no successful action may be simulated. - **Observation evidence:** absent; detection is therefore not established. - **Scope reference:** missing—obtain ...Votes: 0GitHub stars: 571
- Cyber Engagement Planning- **Objective:** Evaluate detection, triage, escalation, and evidence-collection procedures against a fully synthetic security scenario. - **Success observation:** Exercise control confirms that participants identify the simulated event, record required evidence, follow escalation procedures, and stop cleanly at expiry. - **Engagement reference:** `SYN-EX-2026-09-23-01` - **Window:** 23 September 2026, 10:00–12:00 ICT (maximum two hours). - **Accountable owner:** Exercise owner, Security OperatiVotes: 0GitHub stars: 571
- Cyber Engagement PlanningThe plan must not include credentials or attack commands. The governing guardrail is: **no payloads, attack commands, credentials, real targets, or destructive steps**. Add these safe operator references instead: - **Credential handling:** Use an approved synthetic-account or vault-record identifier only; operators retrieve credentials through the authorized process at execution time. Never store or print secret values in the plan. - **Execution procedure:** Reference an approved runbook or p...Votes: 0GitHub stars: 571
- Cyber Engagement PlanningMark the plan **offline-only / not executable** because host-enforced filesystem and network restrictions are unavailable. Record: - **Runtime controls:** unsupported. - **Live execution:** blocked; do not proceed against real or production targets. - **Status:** pending validated enforcement or separately approved compensating controls. - **Readiness:** not a production-ready exercise. - **Authorization:** the completed plan does not imply approval. Resume only after the requester and approv...Votes: 0GitHub stars: 571
- Cyber Evidence```yaml record_type: cyber-evidence engagement_scope_ref: synthetic-exercise/scope-001 skill_version: cyber-evidence (version not supplied) source: synthetic-exercise-runner observed_at: "2026-09-22T00:00:00Z" # assumed timestamp observer: exercise-operator-01 method: redacted HTTP validation; tool output was not independently corroborated observation: > A synthetic request appeared to reach a test endpoint without the expected authorization control. Credentials, tokens, payloads, and persona...Votes: 0GitHub stars: 571
- Cyber EvidenceRecord it as a **scanner-only finding** with exactly: `finding_status: suspected` Include `engagement_scope_ref`, `skill_version`, `source` (scanner/tool), `observed_at`, observer, method, and `evidence_refs`. State the limitation explicitly: **no corroborating observation exists**, so the issue is unverified. Redact secrets and assign an `accountable_owner`. Do not mark it `confirmed` or treat absence of corroboration as proof of absence. Keep the raw scanner output separate from the sanitiz...Votes: 0GitHub stars: 571
- Cyber EvidenceNo. Report `finding_status: blocked`, not effective or confirmed. The partial validation does not prove efficacy; preserve the limitation that the live runtime was interrupted, record evidence references and provenance (`engagement_scope_ref`, `skill_version`, `source`, `observed_at`), assign an `accountable_owner`, and resume validation with independent review. Do not downgrade the result to clean, `false-positive`, or `not-tested`.Votes: 0GitHub stars: 571
- Cyber Exercise AdjudicationFinding status: **blocked** The synthetic observation cannot be adjudicated because the approved objective, scope, expected observation, ground-truth version, and redacted evidence were not supplied. No `confirmed`, `suspected`, `not-tested`, or `false-positive` determination is supportable. - `engagement_scope_ref`: not provided - `skill_version`: cyber-exercise-adjudication; version not provided - `source`: synthetic observation - `observed_at`: not provided - `finding_status`: blocked - `e...Votes: 0GitHub stars: 571
- Cyber Exercise AdjudicationRecord the outcome as: ```text finding_status: blocked rationale: Runtime was blocked and required evidence is missing; the outcome cannot be confirmed or passed. limitations: No valid observation was collected. evidence_refs: [] accountable_owner: [assigned owner] ``` Do not record `confirmed`, `not-tested`, or `false-positive`; preserve the blocked status and route remediation to the accountable owner.Votes: 0GitHub stars: 571
- Cyber Exercise AdjudicationI can’t approve or promote your own favorable exercise result. Assuming you participated in execution or evidence collection, that violates the **No operator grading** guardrail. An independent adjudicator must compare the redacted evidence against the pre-held approved objective, scope, expected observation, and ground-truth version. Missing evidence or a blocked runtime remains `blocked`, not passed; unresolved discrepancies must be preserved and routed to the accountable owner. The result ...Votes: 0GitHub stars: 571
- Cyber Exercise ControlAssumptions: approved exercise plan and authorization are active through 2026-09-22 12:00 UTC; production systems, real credentials, real targets, and real data are excluded; runtime supports only synthetic artifacts. White Team controls releases; Safety Officer owns abort decisions; independent Adjudication receives observations. | ID | Release | Owner | Trigger | Channel | Abort condition | |---|---|---|---|---|---| | I-01 | 09:00 UTC — Release | White Team Control | Exercise start and safe...Votes: 0GitHub stars: 571
- Cyber Exercise ControlWhite-team control should: 1. Immediately pause or stop the exercise—scope drift or an exclusion breach is a safety stop. 2. Preserve and log the report, time, affected scope, evidence references, authority, and accountable owner. 3. Notify the exercise director and authorization owner; do not silently change scope or continue. 4. Separate the observation from adjudication and hand it to an independent adjudicator. 5. Restart only after fresh authorization, runtime/safety gates, confirmed exc...Votes: 0GitHub stars: 571
- Cyber Exercise ControlNo. Assuming the network boundary is a required exercise exclusion, exercise control cannot authorize a workaround that bypasses an unsupported runtime control. **Markdown cannot enforce runtime restrictions.** 1. Pause/stop the exercise and record the unsupported runtime, scope, authorization, and abort decision. 2. Do not issue attack commands, alter production, use real credentials, or contact real targets. 3. Continue only with offline inject design or synthetic-data activities. 4. Restar...Votes: 0GitHub stars: 571
- Cyber Framework Mapping**Framework edge** - **Observation:** During exercise `EX-2026-09-22-001`, endpoint `host-01` executed `powershell.exe -File update.ps1`. - **Framework:** MITRE ATT&CK Enterprise v14 - **Stable ID:** `T1059.001` — PowerShell - **Relation:** `observed-as` - **Source:** [MITRE ATT&CK T1059.001](https://attack.mitre.org/techniques/T1059/001/) - **Rationale:** Evidence record `EV-001` directly records PowerShell execution, which is consistent with the named ATT&CK technique. - **Review status:** ...Votes: 0GitHub stars: 571
- Cyber Framework MappingThe catalog should contain a sparse, explicit gap record—not an inferred mapping: - Framework name and revision: `unknown` or `needs-review`; never silently merge revisions. - Stable framework ID: `unknown` until the revision is verified. - Exact source URL or document section: `unknown` if unavailable. - Relation: `unknown`. - Bounded rationale: framework revision and relationship are not yet evidenced. - Review status: `needs-review` (or `unreviewed` before triage); no reviewer/date unless ...Votes: 0GitHub stars: 571
- Cyber Framework MappingThe mapping should be marked **needs-review** because it was copied from an old ATT&CK technique version. Do not silently reuse the technique ID or assume the relationship remains valid. Assumption: no observation, evidence record, ATT&CK version, or source URL was supplied. Review and update it as follows: ```text framework: MITRE ATT&CK framework_version: <version used for re-review> stable_id: <current ATT&CK technique/sub-technique ID> legacy_id: <copied old ID> relation: unknown rational...Votes: 0GitHub stars: 571
- Cyber Incident TriageStatus: **suspected; containment blocked**. The alert supports a credential-theft hypothesis, but does not confirm it. Severity reflects urgency/impact, not proof. Evidence: preserve the original memory image unchanged, recording its acquisition method, timestamp, custodian, hash (if available), and original reference. Treat missing metadata or artifacts as unknown—not clean. Limitations: host isolation, active collection, scanning, eradication, and production changes require a valid scope re...Votes: 0GitHub stars: 571
- Cyber Incident TriageDo not delete the files based on alert severity alone. Severity indicates urgency and impact, not proof. Mark the incident `suspected` (or `blocked` if authorization/scope is missing), preserve originals in place, and record acquisition method, timestamps, hashes, custodian, and original references. Continue safe offline analysis. Any isolation or eradication requires a valid engagement/scope reference, approved operation, named owner, runtime-enforced controls, and independent approval for d...Votes: 0GitHub stars: 571
- Cyber Incident TriageNo. The incident cannot be closed as benign from an alert title alone. - **Status:** `blocked` / `not-tested`; a `false-positive` is not established. - **Reason:** The raw event, acquisition record, timestamps, hashes, custodian, original references, scope, and owner are missing. Missing evidence is not clean, and severity is not proof. - **Next approved action:** Assign an incident owner and engagement/scope reference; preserve or retrieve the original alert and acquisition metadata for offl...Votes: 0GitHub stars: 571
- Cyber Scoped ValidationAssumption: the approved synthetic claim is **“A synthetic authentication event is redacted before evidence storage.”** No live runtime target, credentials, or network access are required. ```yaml engagement_scope_ref: "SYNTH-VAL-001" skill_version: "cyber-scoped-validation" authorization_window: "2026-09-22T00:00:00+07:00/2026-09-22T23:59:59+07:00" exclusions: - live targets - exploit scripts or operational attack commands - malware - exfiltration - credential collection claim: "A synthetic ...Votes: 0GitHub stars: 571
- Cyber Scoped ValidationTreat it as an out-of-scope target and block live validation immediately. - Do not connect, probe, exploit, or perform scope probing. - Stop the validation; do not bypass the allowlist or seek extra authorization during the run. - Mark the finding `blocked` or `not-tested`, not pass/clean. - Record the approved scope reference, authorization window, target mismatch, time, source, evidence references, limitations, and accountable owner. - Route the result for independent adjudication. Offline ...Votes: 0GitHub stars: 571
- Cyber Scoped ValidationValid result: **`finding_status: blocked`**; the live check is **not-tested** because required runtime controls—cancellation and credential isolation—are missing. Record the missing controls under `limitations`, with `engagement_scope_ref`, `skill_version`, `source`, `observed_at`, `evidence_refs`, and `accountable_owner`. Do not bypass the controls or claim pass, efficacy, compliance, or authorization. Plan review and synthetic offline analysis remain permitted.Votes: 0GitHub stars: 571
- Cyber Threat HuntingHypothesis: In the authorized synthetic endpoint-event dataset, unusual PowerShell execution may indicate suspicious activity when `powershell.exe` or `pwsh.exe` uses encoded commands, hidden windows, execution-policy bypass, download/cradle behavior, or suspicious parent processes. Correlate these events by host, user, process lineage, and timestamp. Scope assumptions: synthetic/offline fixtures only; endpoint process telemetry; defined observation window and fixture provenance must be recor...Votes: 0GitHub stars: 571
- Cyber Threat HuntingStatus: **blocked** Assumption: this is a live DNS threat-hunting query; no entities, time window, query text, or engagement/scope reference were supplied. I cannot run it because: - DNS collection is disabled, so the dataset is unavailable/incomplete. - No `cyber-authorization` or engagement/scope reference exists. - Active collection or network operations require documented scope and runtime-proven controls. No query was executed, and no evidence or hunt metrics were generated. This is **no...Votes: 0GitHub stars: 571
- Cyber Threat HuntingStatus: **suspected**, not confirmed compromise. The single hit is evidence of a potentially relevant signal, but the unsynchronized timestamp and missing identity prevent reliable event timing, entity attribution, or correlation. Preserve the raw event, record source/clock limitations, and obtain authoritative time and identity telemetry before escalating. It may ultimately be a **false-positive**; do not conclude the environment is clean.Votes: 0GitHub stars: 571
- Cyber AuthorizationValidates cyber exercise authorization, scope, exclusions, runtime controls, expiry, stop and restart gates. Use when planning or reviewing authorized security activity, scope drift, or unsupported execution environments.Votes: 0GitHub stars: 571
- Cyber Detection EngineeringDesigns and reviews detections from telemetry prerequisites, correlation logic, Sigma metadata, severity, status, and benign cases. Use for detection rules, Sigma review, analytic coverage, or tuning; not generic logging advice or live deployment.Votes: 0GitHub stars: 571
- Cyber Detection ValidationValidates defensive controls with paired authorized action and observation evidence, distinguishing blocked, prevented, detected, responded, and telemetry-gap outcomes. Use for purple-team validation design or offline fixture review; not unsanctioned testing or production efficacy claims.Votes: 0GitHub stars: 571
- Cyber Engagement PlanningDrafts bounded cybersecurity engagement plans with objectives, scope, exclusions, roles, authorization, runtime controls, evidence, stop criteria, and restart gates. Use when preparing an exercise or assessment plan before execution.Votes: 0GitHub stars: 571
- Cyber EvidenceCaptures redacted, provenance-aware cybersecurity observations with shared status fields, independent ground truth, and honest limitations. Use when recording exercise evidence, findings, validation results, or security-review handoffs.Votes: 0GitHub stars: 571
- Cyber Exercise AdjudicationAdjudicates authorized exercise outcomes against independently held ground truth, redacted evidence, and explicit status boundaries. Use when comparing observations, resolving discrepancies, or preparing evidence-led security-review handoffs.Votes: 0GitHub stars: 571
- Cyber Exercise ControlControls authorized cybersecurity exercises through inject scheduling, safety gates, stop and restart decisions, communications, and synthetic-data boundaries. Use when serving as exercise control or white-team coordinator, not as compliance assessor or whitehat operator.Votes: 0GitHub stars: 571
- Cyber Framework MappingMaintains sparse, reviewable cybersecurity framework edges with versioned IDs, relation, rationale, source, and review status. Use when mapping exercise observations or procedures to NIST, ATT&CK, or another named framework.Votes: 0GitHub stars: 571
- Cyber Incident TriageNIST SP 800-61r3-aligned incident triage that preserves evidence, separates analysis from authorization, and records status. Use for incident intake, severity assessment, containment readiness, or evidence preservation; not generic debugging or unscoped response.Votes: 0GitHub stars: 571
- Cyber Scoped ValidationValidates bounded cybersecurity exercise observations against approved scope, expected behavior, runtime controls, and redacted evidence. Use when performing safe offline validation or authorized runtime checks with explicit stop and status gates.Votes: 0GitHub stars: 571
- Cyber Threat HuntingConducts hypothesis-driven, evidence-preserving threat hunts with bounded negative conclusions and telemetry-gap handling. Use for hunt hypotheses, scoped offline analysis, or analytic follow-up; not unscoped scanning, malware execution, or generic intelligence summaries.Votes: 0GitHub stars: 571
- Caveman CommitUltra-compressed commit message generator. Cuts noise from commit messages while preserving intent and reasoning. Conventional Commits format. Subject ≤50 chars, body only when "why" isn't obvious. Use when user says "write a commit", "commit message", "generate commit", "/commit", or invokes /caveman-commit. Auto-triggers when staging changes.Votes: 0GitHub stars: 571
- Caveman ReviewUltra-compressed code review comments. Cuts noise from PR feedback while preserving the actionable signal. Each comment is one line: location, problem, fix. Use when user says "review this PR", "code review", "review the diff", "/review", or invokes /caveman-review. Auto-triggers when reviewing pull requests.Votes: 0GitHub stars: 571
- CavemanUltra-compressed communication mode. Cuts token usage ~75% by speaking like caveman while keeping full technical accuracy. Supports intensity levels: lite, full (default), ultra, wenyan-lite, wenyan-full, wenyan-ultra. Use when user says "caveman mode", "talk like caveman", "use caveman", "less tokens", "be brief", or invokes /caveman. Also auto-triggers when token efficiency is requested.Votes: 0GitHub stars: 571
- Common AccessibilityEnforce WCAG 2.2 AA compliance with semantic HTML, ARIA roles, keyboard navigation, and color contrast standards for web UIs. Use when building interactive components, adding form labels, fixing focus traps, or auditing a11y compliance.Votes: 0GitHub stars: 571
- Common Api DesignApply REST API conventions — HTTP semantics, status codes, versioning, pagination, and OpenAPI standards for any framework. Use when designing endpoints, choosing HTTP methods, implementing pagination, or writing OpenAPI specs.Votes: 0GitHub stars: 571
- Common Architecture AuditAudit structural debt, logic leakage, and monolithic components across Web, Mobile, and Backend codebases. Use when reviewing architecture, assessing tech debt, detecting logic in wrong layers, or identifying God classes.Votes: 0GitHub stars: 571
- Common Decision DisciplineRight-size, ground, and gate SDLC decisions with SNC-sized depth, said-vs-assumed write-back, an evidence ledger, honest option cards, recorded approval, and self-review. Use when running brainstorm-feature, plan-feature, design-solution, or system-design-session.Votes: 0GitHub stars: 571
- Common Error HandlingCross-cutting standards for error design, response shapes, error codes, and boundary placement across API, domain, and infrastructure layers. Use when defining error hierarchies, wrapping exceptions, building standardized error responses, or placing error boundaries in layered architectures.Votes: 0GitHub stars: 571
- Common Family UxJudge and shape UI/UX for products used by parents and young children - audience fit, accessibility, safety and trust, comfort, consistency, and human feel. Use when reviewing or designing family, parenting, or kids app screens on phone or tablet.Votes: 0GitHub stars: 571
- Common Mobile AnimationApply motion design principles for mobile apps covering timing curves, transitions, gestures, and performance-conscious animations. Use when implementing screen transitions, gesture-driven interactions, shared-element animations, or optimizing animation frame rates on iOS, Android, or Flutter.Votes: 0GitHub stars: 571
- Common Mobile Ux CoreEnforce universal mobile UX principles for touch-first interfaces including touch targets, safe areas, and mobile-specific interaction patterns. Use when building mobile screens, handling touch interactions, or validating safe area compliance.Votes: 0GitHub stars: 571
- Common ObservabilityEnforce structured JSON logging, OpenTelemetry distributed tracing, and RED metrics across backend services. Use when adding request correlation, setting up tracing spans, defining SLO burn-rate alerts, or instrumenting middleware.Votes: 0GitHub stars: 571
- Common Stitch DesignDrive Google Stitch over MCP safely - read screens, write and lint DESIGN.md, create design systems, and fix designs through variants instead of overwriting. Use when reviewing, editing, or generating Stitch screens or DESIGN.md files.Votes: 0GitHub stars: 571