All authors

Claude Skills by Miosa-osa
github.com/Miosa-osa276 skills9 installs363 views
- VerifyQuality gate for knowledge base content. Validates structural compliance (YAML frontmatter, required fields, link integrity), checks that L0 abstracts accurately represent full content, and runs schema conformance. Non-blocking — reports warnings. Triggers on: "verify", "validate", "check quality", "lint knowledge"Votes: 0GitHub stars: 229
- Pipeline> Define and execute a multi-step pipeline with sequential or parallel stages.Votes: 0GitHub stars: 229
- Code ReviewAnalyze pull requests and diffs for bugs, security vulnerabilities, performance issues, style violations, and test coverage gaps — producing structured, actionable feedbackVotes: 0GitHub stars: 76
- Content WriterDraft blog posts, social media content, email campaigns, and marketing copyVotes: 0GitHub stars: 76
- Customer SupportTriage incoming support tickets, draft responses, detect customer sentiment, suggest knowledge base articles, and track resolution metricsVotes: 0GitHub stars: 76
- Daily BriefingGenerate a morning business briefing with weather, calendar, news, and task prioritiesVotes: 0GitHub stars: 76
- Email AssistantTriage inbox, flag urgent emails, summarize threads, and draft repliesVotes: 0GitHub stars: 76
- Meeting PrepResearch attendees, prepare talking points, and summarize previous interactions before meetingsVotes: 0GitHub stars: 76
- Research AssistantConduct deep, multi-source research on technologies, companies, markets, and topics — synthesizing findings into structured reports with citations and actionable insightsVotes: 0GitHub stars: 76
- Sales PipelineMonitor sales pipeline, track deals, send follow-up reminders, and forecast revenueVotes: 0GitHub stars: 76
- Code ReviewAnalyze pull requests and diffs for bugs, security vulnerabilities, performance issues, style violations, and test coverage gaps — producing structured, actionable feedbackVotes: 0GitHub stars: 76
- Content WriterDraft blog posts, social media content, email campaigns, and marketing copyVotes: 0GitHub stars: 76
- Customer SupportTriage incoming support tickets, draft responses, detect customer sentiment, suggest knowledge base articles, and track resolution metricsVotes: 0GitHub stars: 76
- Daily BriefingGenerate a morning business briefing with weather, calendar, news, and task prioritiesVotes: 0GitHub stars: 76
- Diagnosing BugsDiagnose broken, failing, incorrect, flaky, or unexpectedly slow software. Use whenever a user reports a bug, regression, crash, hang, visual defect, or unexplained behavior, even if they ask directly for a fix.Votes: 0GitHub stars: 76
- Email AssistantTriage inbox, flag urgent emails, summarize threads, and draft repliesVotes: 0GitHub stars: 76
- Fleet OrchestrationDecompose a large task into DISJOINT file-owned workstreams, fan out isolated full-power peers, collect structured reports, run ONE authoritative gate, and commit when green — the collision-free, self-verifying multi-agent flow. Ultra-gated.Votes: 0GitHub stars: 76
- Frontend QualityBuild, debug, review, or polish user interfaces with responsive layout, accessibility, and pixel-level visual verification. Use for frontend components, browser UI, terminal UI, resize defects, visual regressions, and interaction problems.Votes: 0GitHub stars: 76
- ImplementationImplement a requested feature or change completely in an existing codebase. Use for multi-file coding tasks, specifications, acceptance criteria, and requests to build or modify behavior rather than merely explain it.Votes: 0GitHub stars: 76
- Meeting PrepResearch attendees, prepare talking points, and summarize previous interactions before meetingsVotes: 0GitHub stars: 76
- Merge ReconcilerRecover the work a fleet wave dropped when two parallel nodes edited the same file — read each claimant's version out of its worktree, reconcile them into one correct file, and re-run the authoritative gate instead of re-running the wave.Votes: 0GitHub stars: 76
- Penetration TestingFull-scope penetration testing — reconnaissance, vulnerability discovery, exploitation, post-exploitation, and reporting against authorized targets. Covers network, web app, API, and host pentesting.Votes: 0GitHub stars: 76
- Research AssistantConduct deep, multi-source research on technologies, companies, markets, and topics — synthesizing findings into structured reports with citations and actionable insightsVotes: 0GitHub stars: 76
- Sales PipelineMonitor sales pipeline, track deals, send follow-up reminders, and forecast revenueVotes: 0GitHub stars: 76
- Security AuditReview code, configuration, permissions, authentication, data handling, and dependencies for exploitable security weaknesses. Use for security reviews, threat analysis, trust boundaries, secrets, authorization, sandboxing, and dangerous command handling.Votes: 0GitHub stars: 76
- Skill AuthoringCreate or improve reusable OSA skills with progressive disclosure, precise selection descriptions, supporting resources, and realistic evaluations. Use when users ask to create, package, test, optimize, or maintain a skill or skill library.Votes: 0GitHub stars: 76
- Test Driven DevelopmentBuild features and bug fixes test first using a strict red, green, refactor loop. Use for TDD requests, regression tests, behavior changes with clear acceptance criteria, and risky logic that benefits from executable specification.Votes: 0GitHub stars: 76
- Arsenal Tool ValidationTool-arsenal validation and risk gating for offensive engagements: risk-tier classification of tools (safe/active/intrusive/credential/dangerous), approval gates where intrusive tools are inert until approved (approve-once-then-free or pre-authorized allowlists), fail-safe denial for unattended runs, loud audited warnings for the hottest actions, egress scope enforcement, and pre-engagement availability checks. Use when preparing a toolset before an engagement, deciding which tools need opera...Votes: 0GitHub stars: 76
- Attack SimulationRun cyber defense attack simulations against isolated lab targets, compare detection gaps, apply a lab patch and rerun to prove defenses work. Use for purple team exercises, simulate attacks, sandbox targets, or test a fix.Votes: 0GitHub stars: 76
- Cve Hunt Benchmark HarnessGround-truth vulnerability-hunting benchmarks: challenge definitions with known-vulnerable targets, ground-truth vulnerability records with match keywords and point values, precision/recall/F1 scoring of discovered findings against ground truth, time-to-finding metrics, decoy clean samples to measure false-positive rates, and severity breakdown reporting. Use when evaluating how well an agent or tool finds real vulnerabilities, building a vulnerability-hunting eval set, or scoring a security-...Votes: 0GitHub stars: 76
- Detection EngineeringBuild and validate cyber defense detection rules with malicious and benign fixtures, telemetry prerequisites and false positive controls. Use for Sigma rules, detection engineering, missing alerts or measuring detection coverage.Votes: 0GitHub stars: 76
- Dfir Incident ToolkitDigital forensics and incident response workflow: read-only evidence acquisition with SHA-256 integrity records, typed acquisition outcomes (collected/cancelled/permission-denied/failed), containment previews with digests and approval receipts, rollback planning before execution, and artifact redaction at collection time. Use when responding to a suspected compromise, acquiring disk/memory/log evidence, planning containment actions with approval gates, or structuring a case file for an incide...Votes: 0GitHub stars: 76
- Elixir OtpWrite, review, and repair Elixir or Erlang code with verified syntax, exact API arities, OTP lifecycle handling, and executable checks. Use for .ex/.exs, mix.exs, GenServer, supervision, Ecto, Phoenix, and BEAM runtime bugs.Votes: 0GitHub stars: 76
- Email SecurityAnalyze suspicious email headers and attachments without opening active content, distinguish trusted authentication results and plan mail defenses. Use for phishing triage, email security, spoofed sender or SPF DKIM DMARC evidence.Votes: 0GitHub stars: 76
- Endpoint HardeningAssess host service permissions and defensive configuration, prepare reversible hardening and verify normal behavior plus attack resistance. Use for endpoint hardening, Linux service sandboxing, reducing privileges or securing a workstation.Votes: 0GitHub stars: 76
- Evidence Vault Chain Of CustodyEvidence management for security engagements: chain-of-custody records with SHA-256 integrity, the provenance-strict verification gate (a finding is only 'verified' when backed by real tool output, never prose), credential redaction for any outward-facing surface, CVSS-to-severity scoring, and authorized retest workflows with typed probe dispositions. Use when structuring findings/evidence storage for a pentest or bug-bounty engagement, deciding what evidence makes a claim reportable, redacti...Votes: 0GitHub stars: 76
- Honeytokens DeceptionHoneytoken design and deployment for detecting intrusion attempts: token kinds (opaque, API-key-shaped, credential-shaped, beacon), lifecycle management (create, activate, rotate, revoke, cleanup), HMAC-signed trigger verification with nonce and replay protection, environment-scoped authorization, audit trails for every action, and alert-sink integration. Use when planting decoy credentials or artifacts to detect attackers, designing canary tokens for infrastructure or repos, or building dete...Votes: 0GitHub stars: 76
- Incident ResponseInvestigate suspected compromise, preserve incident evidence, build a timeline and plan containment, recovery and verification. Use for incident response, account takeover, suspicious host activity or recovery after an attack.Votes: 0GitHub stars: 76
- Log AnalysisNormalize and correlate security logs into an evidence-backed timeline while preserving timestamps and parse errors. Use for log analysis, auth failures, event timelines, JSONL triage or suspicious application logs.Votes: 0GitHub stars: 76
- Network DefenseReview network exposure, firewall policy and IDS evidence, then validate defensive changes with permitted and denied traffic controls. Use for network defense, segmentation, Suricata rules, firewall review or packet capture triage.Votes: 0GitHub stars: 76
- Offensive Active DirectoryActive Directory attack methodology for internal network red team engagements. Covers reconnaissance (BloodHound, PowerView, ADExplorer), credential abuse (Kerberoasting, ASREProasting, NTLM relay, LLMNR/NBT-NS poisoning), privilege escalation (ACL abuse, GPO abuse, unconstrained/constrained delegation), lateral movement (Pass-the-Hash, Pass-the-Ticket, Overpass-the-Hash, WMI/WinRM/PsExec), persistence (Golden/Silver/Diamond Tickets, DCSync, DCShadow, AdminSDHolder, Skeleton Key), forest trus...Votes: 0GitHub stars: 76
- Offensive Advanced RedteamComprehensive red team operations methodology covering full engagement lifecycle from planning through reporting. Addresses engagement scoping and rules of engagement negotiation, multi-tier C2 infrastructure design with redirectors and domain fronting, malleable traffic profiles and beacon tradecraft, OPSEC discipline including attribution avoidance and indicator management, EDR and AMSI evasion techniques using direct syscalls and unhooking, data collection with chain-of-custody controls, a...Votes: 0GitHub stars: 76
- Offensive Ai SecurityAI/LLM security offensive checklist: prompt injection, jailbreaking, model extraction, training data poisoning, adversarial inputs, LLM-assisted attack automation, and AI system reconnaissance. Use when assessing AI/ML systems, red-teaming LLMs, or researching AI attack vectors.Votes: 0GitHub stars: 76
- Offensive Anti ForensicsAnti-forensics and evidence destruction techniques for red team operators conducting authorized engagements. Covers log clearing on Windows (wevtutil, Clear-EventLog, ETW provider patching) and Linux (journal truncation, utmp/wtmp binary editing, syslog manipulation), timestamp manipulation via Timestomp and SetMACE to defeat timeline analysis, filesystem-level anti-forensics including NTFS Alternate Data Streams for payload hiding and secure deletion with sdelete/shred, memory artifact remov...Votes: 0GitHub stars: 76
- Offensive Api AbuseAdvanced API exploitation methodology focused on business logic abuse and sophisticated attack patterns that bypass traditional security controls. Covers business logic bypass through API call chaining and workflow manipulation. Addresses GraphQL-specific attacks including batching for credential brute-force, query depth exploitation, and introspection abuse. Includes pagination exploitation for data exfiltration, webhook hijacking for SSRF and data interception, and resource exhaustion throu...Votes: 0GitHub stars: 76
- Offensive Api SecurityComprehensive API security testing methodology covering REST, gRPC, and WebSocket attack surfaces. Addresses the full OWASP API Security Top 10 2023 including BOLA/IDOR, broken authentication, excessive data exposure, rate limiting bypass, BFLA, mass assignment, SSRF, and security misconfiguration. Includes REST-specific attacks such as HTTP verb tampering, content-type switching, and parameter pollution. Covers gRPC exploitation through protobuf interception, reflection API enumeration, and ...Votes: 0GitHub stars: 76
- Offensive Basic ExploitationWeek 5 exploit development curriculum. Foundational exploitation techniques: controlling EIP/RIP, ROP chain construction, ret2libc, shellcode injection, heap spraying, bypass techniques for ASLR/NX/stack canaries. Use when building initial PoCs or understanding classic exploitation primitives.Votes: 0GitHub stars: 76
- Offensive Bluetooth BleBluetooth Low Energy (BLE) attack methodology — GATT enumeration, characteristic read/write without auth, pairing downgrade (Just Works forced), LE Secure Connections bypass, MITM via active relay, sniffing with Sniffle (TI CC1352) / Ubertooth / Frontline, encryption key extraction (LE Legacy Pairing crackable, LE Secure Connections strong), proximity authentication abuse (cars, locks), and companion-app trust analysis. Use for IoT BLE devices, smart locks, fitness trackers, medical devices, ...Votes: 0GitHub stars: 76
- Offensive Bluetooth ClassicBluetooth Classic (BR/EDR) attack methodology — device discovery, service enumeration via SDP, LMP/L2CAP layer attacks, legacy PIN cracking (BlueBorne / KNOB), Bluetooth file-transfer abuse (BlueSnarfing legacy), unauthenticated profile abuse (HSP, HFP, OPP), and modern relevance against older industrial / automotive / accessory targets. Use when in-scope devices use Bluetooth Classic (Bluetooth ≤ 4.0 BR/EDR) — common in legacy car kits, industrial sensors, older medical devices, and audio ac...Votes: 0GitHub stars: 76
- Offensive Bug IdentificationSystematic bug identification methodology: source code review patterns, black-box testing strategies, taint analysis, dangerous function hunting, data flow tracing, and automated scanning setup. Use for code audits, bug bounty triage, or building vulnerability identification pipelines.Votes: 0GitHub stars: 76