All authors

Claude Skills by Intense-Visions
github.com/Intense-Visions800 skills2 installs984 views
- Resilience Health Checks> Implement health check endpoints for service readiness, liveness, and dependency monitoringVotes: 0GitHub stars: 20
- Resilience Idempotency> Ensure safe retries by making operations produce the same result regardless of how many times they executeVotes: 0GitHub stars: 20
- Resilience Rate Limiting> Control request throughput with token bucket, sliding window, and fixed window algorithms to protect services from overloadVotes: 0GitHub stars: 20
- Resilience Retry Pattern> Handle transient failures with configurable retry strategies, exponential backoff, and jitterVotes: 0GitHub stars: 20
- Resilience Timeout Pattern> Prevent resource exhaustion and hung requests with timeouts, AbortController, and deadline propagationVotes: 0GitHub stars: 20
- Roadmap Fleet> Autonomous batch-build orchestrator — score a batch of backlog candidates, confirm it with the human in one up-front round, fan out worktree-isolated subagents that each run the **real** per-item pipeline (brainstorming then autopilot), independently verify every result by artifact and all-OS CI, and hand back a set of merge-ready PRs for one bulk review. The fleet never auto-merges and never trusts a subagent's self-report. Building a backlog through the harness pipeline one item at a time...Votes: 0GitHub stars: 20
- Security Abac Design> Evaluate access decisions using attributes of the subject, resource, action, and environment -- eliminating role explosion by expressing authorization as policy rules over contextual dataVotes: 0GitHub stars: 20
- Security Asymmetric Encryption> Public-key cryptography for key exchange, digital signatures, and identity verification > -- Ed25519 for signatures, X25519 for key exchange, RSA-2048+ only for legacy > compatibilityVotes: 0GitHub stars: 20
- Security Attack Trees> Model multi-step adversary strategies as goal-oriented tree decompositions -- revealing which attack paths are cheapest and which defenses yield the highest leverageVotes: 0GitHub stars: 20
- Security Audit Log Design> Log the who, what, when, where, and outcome of every security-relevant event in a > structured, tamper-evident format that enables both real-time detection and forensic > reconstructionVotes: 0GitHub stars: 20
- Security Authentication Flows> Login, registration, password reset, magic links, and SSO -- each flow has distinct attack surfaces and each must be hardened independentlyVotes: 0GitHub stars: 20
- Security Capability Based Security> Replace ambient authority ("who are you?") with explicit capabilities ("what token do you hold?") -- eliminating confused deputy attacks by making every permission a transferable, revocable, unforgeable objectVotes: 0GitHub stars: 20
- Security Certificate Management> X.509 certificates are the backbone of internet trust -- manage them correctly or accept > that attackers can impersonate any service, intercept any connection, and forge any > identityVotes: 0GitHub stars: 20
- Security Ci Security Testing> Run SAST, DAST, SCA, and secrets scanning on every commit -- automated security gates that > catch vulnerabilities before they reach productionVotes: 0GitHub stars: 20
- Security Code Signing> Sign every artifact you produce and verify every artifact you consume -- because an unsigned > binary could have been built by anyone, including an attackerVotes: 0GitHub stars: 20
- Security Compliance Logging> Regulatory frameworks mandate specific logging requirements -- SOC2, GDPR, HIPAA, and > PCI-DSS each define what must be logged, how long logs are retained, and what constitutes > auditable evidence, and failing to meet these requirements carries fines, legal liability, > and loss of certificationVotes: 0GitHub stars: 20
- Security Craft> LLM-judgment critique of security posture for TS/JS source — the ceiling counterpart to `harness-security-scan` (CVE/OWASP rule-based floor) and `harness-security-reviewer` (procedural review). Threat-modeling-as-skill rather than pattern-matching. Critiques whether trust boundaries are respected, where implicit privilege escalation lurks, whether the code defends in depth or just at the gate, whether principle of least authority is honored. Sixth non-design member of the craft-pipeline ini...Votes: 0GitHub stars: 20
- Security Credential Storage> Argon2id for new systems, bcrypt for broad compatibility -- always salt, consider peppering, tune cost parameters to hardware, and plan hash upgrade pathsVotes: 0GitHub stars: 20
- Security Cryptographic Randomness> Every session token, encryption key, nonce, and CSRF token depends on unpredictable randomness -- use a CSPRNG or accept that attackers will predict your secretsVotes: 0GitHub stars: 20
- Security Dependency Auditing> Your application is 90% third-party code -- scan it for known vulnerabilities, lock it > to exact versions, and have a strategy for when a critical CVE drops on a Friday > afternoonVotes: 0GitHub stars: 20
- Security Deserialization Attacks> Deserialization reconstructs objects from byte streams -- and in most languages, that > reconstruction executes code, meaning an attacker who controls the serialized input controls > what code runs on your serverVotes: 0GitHub stars: 20
- Security Environment Variable Risks> Environment variables are visible in process listings, inherited by child processes, > captured in crash dumps, and logged by every debugging tool -- they are the worst place > to store secretsVotes: 0GitHub stars: 20
- Security Fleet> Autonomous security backlog sweep — enumerate risk-ranked code areas plus the resolved dependency tree, discard every candidate that cannot produce concrete evidence, confirm one ranked batch with the human in a single up-front round, then route each survivor by a bounded-fix test: a safe bounded fix is built through the **real** pipeline into an independently verified PR, while a risky or structural finding is filed with its evidence packet instead of force-fixed. The fleet never auto-merg...Votes: 0GitHub stars: 20
- Security Forensics Fundamentals> Digital forensics is the discipline of collecting, preserving, and analyzing evidence from > compromised systems -- done correctly, it reveals the full attack narrative; done poorly, it > destroys the evidence needed to understand what happened and prevent recurrenceVotes: 0GitHub stars: 20
- Security Hashing Fundamentals> One-way functions for integrity verification, content addressing, and commitment schemes > -- SHA-256 for interoperability, BLAKE3 for performance, and never MD5 or SHA-1 for > securityVotes: 0GitHub stars: 20
- Security Hmac Signatures> HMAC proves a message was created by someone with the shared secret; digital signatures prove it was created by a specific private key holder -- choose based on whether you need symmetric verification or non-repudiationVotes: 0GitHub stars: 20
- Security Hsts Preloading> Tell the browser "never connect to this domain over HTTP, ever" -- and make it permanent > by embedding the directive in every browser's shipped preload listVotes: 0GitHub stars: 20
- Security Identity Verification> Authentication at login is necessary but insufficient -- continuously evaluate identity > confidence using device trust, behavioral signals, and environmental context throughout > the sessionVotes: 0GitHub stars: 20
- Security Incident Containment> The first 60 minutes of a security incident determine whether the organization loses days > of data or months of data -- containment is not about fixing the vulnerability, it is about > stopping the bleeding while preserving the evidence needed to understand what happenedVotes: 0GitHub stars: 20
- Security Injection Families> Every injection vulnerability has the same root cause: untrusted data is interpreted as > code because the boundary between data and instructions was not enforced -- fix the > boundary, fix the bugVotes: 0GitHub stars: 20
- Security Log Correlation> Correlate events across multiple log sources to detect attacks that are invisible in any > single log stream -- because attackers do not confine their activities to one systemVotes: 0GitHub stars: 20
- Security Memory Safety> Memory corruption vulnerabilities account for 70% of critical CVEs in C/C++ codebases -- > choose memory-safe languages by default, and when you cannot, understand the vulnerability > classes and mitigationsVotes: 0GitHub stars: 20
- Security Mfa Design> Something you know, something you have, something you are -- combining authentication factors so that compromising one factor alone is insufficient to gain accessVotes: 0GitHub stars: 20
- Security Microsegmentation> Isolate every workload behind its own perimeter -- so compromising the web server does > not hand the attacker the database, the secrets store, and the internal APIsVotes: 0GitHub stars: 20
- Security Mtls Design> Both sides prove their identity with certificates -- the server authenticates to the > client and the client authenticates to the server, establishing a cryptographically > verified service-to-service channelVotes: 0GitHub stars: 20
- Security Penetration Testing> Hire skilled attackers to find the vulnerabilities your automated tools and internal reviews > miss -- then fix what they find and verify the fixesVotes: 0GitHub stars: 20
- Security Post Incident Review> Organizations that conduct blameless post-incident reviews after every significant security > incident reduce their recurrence rate by identifying systemic weaknesses; organizations that > skip the review are condemned to repeat the same failures with different symptomsVotes: 0GitHub stars: 20
- Security Race Conditions> When security depends on the order of operations but the system does not enforce that > order, attackers exploit the gap between check and use -- turning microsecond timing windows > into privilege escalation, double-spend, and data corruptionVotes: 0GitHub stars: 20
- Security Rbac Design> Assign permissions to roles, assign roles to users -- simple, auditable, and sufficient for most applications when combined with resource-level checksVotes: 0GitHub stars: 20
- Security Rebac Design> Model authorization as a graph of relationships -- "User X is an editor of Document Y which belongs to Folder Z owned by Team W" -- enabling inherited permissions that follow resource hierarchiesVotes: 0GitHub stars: 20
- Security Sbom Provenance> Know exactly what is in your software (SBOM) and prove how it was built (provenance) -- because > you cannot secure what you cannot inventoryVotes: 0GitHub stars: 20
- Security Secrets Lifecycle> Secrets are born (generated), distributed (delivered to consumers), rotated (replaced on > schedule), and die (revoked and destroyed) -- manage every phase or the secret manages youVotes: 0GitHub stars: 20
- Security Security Champions> Scale security knowledge across the engineering organization by embedding trained security > advocates in every development team -- because the security team cannot review every line of > code, but developers canVotes: 0GitHub stars: 20
- Security Session Management> Session tokens are bearer credentials -- generate with CSPRNG, bind to client context, enforce idle and absolute timeouts, and regenerate on privilege changesVotes: 0GitHub stars: 20
- Security Shift Left Design> Find security flaws in the design document, not in the penetration test report -- because > fixing an architecture flaw costs 100x more after deployment than during designVotes: 0GitHub stars: 20
- Security Symmetric Encryption> AES-256-GCM for most use cases, ChaCha20-Poly1305 when hardware AES is unavailable -- > always use authenticated encryption, never roll your ownVotes: 0GitHub stars: 20
- Security Threat Modeling Process> End-to-end threat modeling from system decomposition through threat enumeration, risk rating, and mitigation tracking -- the operational backbone of proactive security designVotes: 0GitHub stars: 20
- Security Threat Modeling Stride> Systematic threat identification using the six STRIDE categories -- Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of PrivilegeVotes: 0GitHub stars: 20
- Security Tls Fundamentals> TLS 1.3 with ECDHE key exchange, AES-256-GCM or ChaCha20-Poly1305 ciphers, and valid > certificates -- the minimum bar for all network communicationVotes: 0GitHub stars: 20
- Security Trust Boundaries> Every security control exists because data crosses from a trusted zone to a less-trusted one -- identify the boundaries first, then concentrate defenses thereVotes: 0GitHub stars: 20