All authors

Claude Skills by ModernNomad-98
github.com/ModernNomad-98212 skills1 installs122 views
- Compliance Evidence CollectorDesign the operating-effectiveness evidence program SOC 2 Type 2 demands and ISO surveillance audits reuse — evidence OVER TIME, not point-in-time. Per control (from compliance-control-foundation): evidence type, cadence matched to control operating frequency, population for auditor sampling, named collector, retention, and audit-window coverage with a hole map. Formalizes the Phase 5 evidence pack (screenshot-evidence-planner, manual-test-case-creator), audit-log-architect trails, and agent-...Votes: 0GitHub stars: 4
- Compliance Gap AuditorRun ONE parameterized compliance gap audit — current state vs the chosen framework(s): ISO 27001:2022, ISO 42001:2023, SOC 2 (TSC), optionally a NIST AI RMF profile — never a per-framework fork. Consumes the compliance-control-foundation catalog, multi-framework-crosswalk rows, the SoA, and compliance-evidence-collector coverage; verdicts per requirement: MET / PARTIAL / GAP / UNVERIFIABLE from cited evidence — missing evidence is never MET (agent-governance-audit discipline, org-wide). Outpu...Votes: 0GitHub stars: 4
- Context Co Update Ci GateDesign the CI gate that FAILS any PR touching "important" paths without a matching context-map/notes update, plus the update protocol that keeps the map honest: every update stamps date + commit SHA scanned, status moves only on cited evidence, and an unresolved risk note is never deleted — only replaced by proof. Deliverables: important-paths list, co-update rule with a declared (never silent) no-change-needed escape hatch, check logic + failure message, protocol doc. The WRITE-BACK half of ...Votes: 0GitHub stars: 4
- Contribution Guide AuthorDesign a CONTRIBUTING guide that takes a contributor from zero to a merged change — environment setup, the contribution workflow (fork/branch/PR or the project's flow), coding standards and commit/PR conventions, how to run tests and checks locally, the review and merge process, honest expectation-setting (response times, what gets accepted), code-of-conduct and licensing/DCO-CLA pointers, and lowering the first-contribution barrier (good-first-issues, where to ask). Designs contribution guid...Votes: 0GitHub stars: 4
- Cross Team Dependency NegotiatorIdentify, negotiate, and track the cross-team dependencies an effort needs — map what you need from other teams AND what they need from you, surface each dependency EARLY (before it's a blocker), negotiate a CONCRETE commitment (specific deliverable, interface/contract, date, owner on both sides) rather than a vague "we'll help", de-risk it (fallbacks if it slips, decoupling via a stubbed interface, parallel paths), account for the reality that other teams have their own priorities (align inc...Votes: 0GitHub stars: 4
- Dast Safety Harness DesignerDesign a SAFE dynamic-testing (DAST) harness against a RUNNING application — the safety harness is the deliverable, not an attack method. Mandates EXPLICIT WRITTEN AUTHORIZATION before any run (scope, target, window, blast radius recorded — composes human-approval-boundary); staging/non-production targets only unless prod is explicitly authorized; rate/impact limits so it never DoS-es the target; no destructive probes without separate sign-off; data-handling; and the run/result contract. Fail...Votes: 0GitHub stars: 4
- Data Migration Runbook AuthorAuthor the operator-executable runbook for a DATA move or schema-migration deploy (backfill, re-shard, store cutover, tenant move, CDC initial load, or applying reviewed DDL to a named environment) that a stranger can run under pressure: target confirmed by a read-only fingerprint before any write, preconditions gated on verified backups and dry-run evidence, batching with throttles and pause/resume, per-step verification queries and post-apply smoke checks with expected output, abort criteri...Votes: 0GitHub stars: 4
- Data Partitioning Sharding StrategistDesign OLTP partitioning and sharding for WRITE/size scale in a multi-tenant SaaS — shard-key selection (tenant-as-shard-key and its hot-tenant limit), range/hash/list partitioning of large tables, resharding/rebalancing a hot tenant, and the cross-shard query/transaction costs you inherit — all gated behind the DON''T-SHARD-PREMATURELY rule: a well-indexed primary plus read replicas can serve a large SaaS while measured write, size, and maintenance limits permit, so shard ONLY on evidence of...Votes: 0GitHub stars: 4
- Data Quality Monitor DesignerDesign data-quality monitoring for production pipelines and stores — checks across the six dimensions (freshness, completeness/volume, uniqueness, validity, consistency/referential integrity, distribution drift), placed at the right pipeline stage (ingest, transform, serving), each with severity, an owner, and a failure action (block, quarantine to a reviewable location, or alert-and-pass — never silent auto-fix), plus per-dataset quality SLAs and incident routing. Produces the monitor spec a...Votes: 0GitHub stars: 4
- Design Review FacilitatorFacilitate a technical DESIGN REVIEW — prepare it (circulate the design/spec ahead, state the decision the review must reach, invite the right reviewers including the skeptics and cross-cutting owners), structure the discussion (surface assumptions, probe the risky parts and cross-cutting concerns, weigh alternatives, keep it about the design not the person), actively elicit dissent and the strongest objection, drive to an EXPLICIT outcome (approved / approved-with-changes / needs-rework / bl...Votes: 0GitHub stars: 4
- Diataxis Doc OrganizerOrganize a documentation SET using the Diátaxis framework — sort content into the four modes (tutorials for learning, how-to guides for tasks, reference for information, explanation for understanding), diagnose what each existing doc actually IS versus what it claims to be (the common rot: a "tutorial" that is really reference, a how-to bloated with explanation), place each piece in the right quadrant, structure the doc tree accordingly, and set the maintenance discipline that keeps the modes...Votes: 0GitHub stars: 4
- Docs As Code ArchitectDesign the docs-as-code TOOLCHAIN and pipeline — docs living in the repo beside the code, the format and static-site generator, the build/preview/deploy pipeline, versioning docs with the code they describe, review via pull requests, link-checking and prose/style linting in CI, testing that code samples actually run, search, and the docs contribution workflow. This is the ENGINEERING of documentation — the infrastructure that keeps docs building, published, and honest — not their content or o...Votes: 0GitHub stars: 4
- Docs First ImplementerMANUAL-ONLY; never auto-invoke. Implement against frameworks, libraries, or external services by first identifying the EXACT versions installed in this repo and reading the matching documentation — official docs, local node_modules/vendored docs, changelogs — before writing any code. Summarizes only the syntax relevant to the task, implements, then verifies with the project's tests/build/lint. States uncertainty explicitly when docs for the pinned version are unavailable instead of guessing f...Votes: 0GitHub stars: 4
- Docs Retention IndexDesign the numbered retention index governing every workflow/process doc's LIFECYCLE — each doc gets a retention category, a reason-to-keep, a superseded-by pointer, and a cleanup rule, mirrored by per-doc retention frontmatter, so doc retirement becomes an explicit, approvable operation instead of silent rot or hoarding. Runs the reverse-reference sweep before retiring a doc, stages retirement (mark → redirect → remove) with human approval for deletion, and keeps the index the source of trut...Votes: 0GitHub stars: 4
- Domain ModelerModel the business domain before any implementation — extract ubiquitous language, actors, workflows, subdomains, bounded contexts, entities, value objects, aggregates, domain services, domain events, and context relationships from requirements, docs, and existing code. Use when starting a new feature or system from prose requirements, when no domain model exists, when naming or entity confusion keeps causing rework, or when asked to map business concepts. Ends at a hard "do not code yet" gat...Votes: 0GitHub stars: 4
- Edge State Ux DesignerDesign the non-happy-path UI states for a view or flow — the distinct empty states (first-run vs filtered-to-nothing vs error-emptied, each with its own copy and next action), loading states (skeleton vs spinner vs inline, a delay threshold to avoid flash, optimistic updates with rollback), error states (inline vs toast vs full-page, retry affordance, partial failure, stale-on-error), and the permutations teams forget (offline, refetching/stale, slow, partial data, permission-denied, too-much...Votes: 0GitHub stars: 4
- Error Handling Security ReviewerReview error/exception handling through a security lens — fail-closed defaults (a failed check, timeout, or down dependency DENIES, never allows), error-path AUTHORIZATION (authz still enforced on every error/retry/fallback branch), exception-driven logic BYPASS (does an exception skip a check, validation, rollback, or audit write?), and leak-free error responses (no stack traces/secrets/internal detail to callers — generic outside, rich inside). Closes OWASP Top 10:2025 A10 (Mishandling of E...Votes: 0GitHub stars: 4
- Error Taxonomy DesignerDesign the error model for an API or product surface — a finite, stable taxonomy of error categories with machine-readable codes, an error envelope (code, human message, field-level details, correlation id, retryable flag), an honest client-fault vs server-fault vs retryable split, actionable messages that say what to DO, ONE mapping boundary where exceptions become taxonomy errors, and a disclosure rule that keeps stack traces, internal identifiers, and PII out of what the caller sees. Owns ...Votes: 0GitHub stars: 4
- Eval Runner DesignerDesign how skill-library eval cases would execute in an isolated live session and be judged, while distinguishing the shipped offline Behavioral Eval Runner from unbuilt live/provider dispatch. Covers fresh-session isolation, trigger verification, deterministic versus semantic judging, refusal cases, honest UNRUN status, cost, flake policy and advisory CI. Design/spec ONLY — it does not execute cases or report passing results without recorded observations; further live/provider implementation...Votes: 0GitHub stars: 4
- Event Schema ArchitectDesign the ANALYTICS event schema and tracking plan for product measurement — the event naming taxonomy (consistent object-action), a typed property schema per event (required/optional, enums), shared global properties (user/session/tenant/timestamp), the identity model (anonymous→identified stitching; user/account/tenant keys), a tracking plan/registry as the source of truth, additive versioning, cross-platform naming consistency, and PII minimization. These are BEHAVIORAL events for MEASURE...Votes: 0GitHub stars: 4
- Feature Flag Rollout StrategistDesign the ROLLOUT STRATEGY for a change behind a flag — classify the flag by purpose (release, ops/kill-switch, experiment, permission — release flags stay separate from permanent entitlements), plan progressive delivery (internal → canary/% → cohorts → GA), define sticky targeting, set guardrail metrics with auto-rollback criteria and a pre-ramp kill-switch test gate, choose the fail-safe default when the flag service is down, and manage the lifecycle so release flags are removed after GA (...Votes: 0GitHub stars: 4
- File Upload Storage ArchitectDesign file/object storage and upload flows for a multi-tenant SaaS — direct-to-storage vs proxied upload, short-lived signed URLs scoped to one object + verb + expiry, tenancy by bucket/path-prefix, size/type/CONTENT validation (magic-byte, not just extension), malware scanning, image/derivative processing off the request path, retention/lifecycle, CDN + cache-control, and storage-cost posture. Produces the upload-flow design, the storage-tenancy + signed-URL contract, the validation/scan pi...Votes: 0GitHub stars: 4
- Flaky Test DetectiveMANUAL-ONLY; never auto-invoke. Drive a flaky (intermittently failing) test to its root cause and bounded stability evidence through the fixed sequence CLASSIFY (ordering, shared state, timing/race, environment, infrastructure, or real intermittent product bug) → REPRODUCE deterministically (repeat runs, order shuffling, parallel stress, seed/timezone control) → FIX ONE CAUSE → MEASURE stability with repeated runs and real counts. Never fixes by adding retries, sleeps, or looser assertions; d...Votes: 0GitHub stars: 4
- Framework Edition TrackerTrack the editions of external standards the library''s framework-mapping skills cite — OWASP Top 10 / LLM / Agentic, ISO 27001/42001, SOC 2, NIST AI RMF and similar — by maintaining an edition register (framework → cited edition → where cited), detecting when a NEW edition ships, and producing a DELTA report of what changed. Pins currency without touching any mapping: it reports drift, it does not update. The delta it produces feeds framework-mapping-refresher, which proposes the specific ed...Votes: 0GitHub stars: 4
- Framework Mapping RefresherGiven an edition delta (from framework-edition-tracker), propose the SPECIFIC updates to every affected skill description, reference file, and coverage map — locate each site that cites or maps the old edition, propose the concrete change per site (renamed category, added/removed control, restructured mapping, updated edition string), surface any new coverage GAP the edition introduces, and flag the whole set for HUMAN REVIEW before anything lands. Proposes; never auto-applies. Downstream of ...Votes: 0GitHub stars: 4
- Frontend Perf EngineerDesign the frontend's share of performance — metrics in the loading/interactivity/visual-stability family (largest-paint, interaction latency, layout shift) pinned to a device/network class, bundle strategy (route code splitting, lazy loading, weight audit BEFORE micro-tuning — deletions first), asset strategy (image priority, fonts without invisible-text or reflow), rendering path (SSR/hydration cost honestly counted, long tasks), runtime fixes (re-render storms, unvirtualized lists, layout ...Votes: 0GitHub stars: 4
- Full Codebase AuditorAudit an ENTIRE repository with inventory-first discipline — enumerate every directory, language, entry point, dependency manifest, CI/CD pipeline, and doc before forming any finding, so nothing is judged by its most interesting-looking files. Covers architecture, security, code quality, tests, dependencies, CI/CD, deployment, documentation, and operational readiness, and separates every result into confirmed findings, likely findings, hypotheses, and missing information. Use for whole-repo h...Votes: 0GitHub stars: 4
- Funnel Definition DesignerDefine product funnels and conversion/retention measurement rigorously — the ordered funnel steps grounded in the analytics event schema, the counting model (unique users vs sessions vs events) with an honest denominator, the conversion window (how long a user has to complete), strict-order vs any-order steps, attribution (first/last touch), drop-off and segmentation analysis, and cohort/retention curves — while keeping one metric to one definition so numbers stop drifting, and separating WHE...Votes: 0GitHub stars: 4
- Gated Deployment Prompt TemplateAuthor the reusable operator prompt template gating a RECURRING class of risky operations (migrations, production grants, backfills): operator-filled placeholders (<owner>/<repo>, <tenant-id> — never live identifiers; credentials as env-var names), hard rules with required inputs, stop conditions with safe halt states, backup-then-verify gating (verified backup BEFORE; expected deltas AFTER), per-phase smoke expectations, a required per-run report path, and ETA ranges calibrated from a deploy...Votes: 0GitHub stars: 4
- Horizontal Scalability ReviewerReview whether a system can scale OUT (add nodes) rather than only up — a can-it-scale-horizontally lens: statelessness / session and in-memory-state externalization, connection pooling and connection-count ceilings, sticky-session and in-process-singleton / local-cache / local-cron / local-filesystem smells, autoscaling + load-balancer + health-check config, and graceful shutdown/draining so scale-in does not drop work. Produces a scale-out readiness verdict with component/file findings rank...Votes: 0GitHub stars: 4
- Human Agent Trust ReviewerAdversarially review the human-approval layer of an agent system for trust exploitation (OWASP Agentic ASI09) — consent fatigue (approval floods that train rubber-stamping; rate/latency as the signals), deceptive, over-polished justifications making a dangerous action look routine, self-reported summaries diverging from the actual action, dangerous steps bundled in innocuous batches, urgency manipulation, and automation bias as trust accumulates. Where human-approval-boundary places the gates...Votes: 0GitHub stars: 4
- Human Approval BoundaryCheck current task instructions, prior conversation grants and the owner approval register before a risky action. Proceed within an active scoped grant; obtain a new explicit human approval only when the action is not covered or its security impact is unclear. Covers schema changes or destructive migrations, RLS or security policy, production data, secrets, deployments or releases, billing, git history rewrites and broad multi-file refactors. Use when a task approaches one of these boundaries...Votes: 0GitHub stars: 4
- Iac ReviewerReview infrastructure-as-code changes (Terraform, Bicep, CloudFormation, CDK, Pulumi) for deploy safety and security — destructive replace/delete of stateful resources hidden in innocent diffs, state/backend safety, public exposure, over-broad IAM/RBAC widening, missing encryption, secrets in code or captured in state, tenant-isolation impact, drift from documented architecture, module pinning, and tagging/cost impact. Review-only: severity-ranked findings with file:line evidence and proposed...Votes: 0GitHub stars: 4
- Incident Response RunbookAuthor incident response runbooks a responder who didn''t write them can execute at 3am — a SEV1–SEV4 ladder with one-minute criteria (ambiguity classifies up), roles (incident commander, comms, ops — small-org collapse stated), triage from page to decision point, containment invoking the rollback runbook by reference (rollback-runbook-author), tenant-aware comms templates per severity (never leaking other tenants'' data), evidence capture DURING the incident, SLI-verified resolution, and a b...Votes: 0GitHub stars: 4
- Integration Test DesignerDesign integration tests — the layer BETWEEN unit and E2E — that exercise modules through REAL service, command, database, auth, and permission boundaries with no browser. Every suite names exactly which boundaries are real and which seams stay faked (third-party APIs, clocks, email), with rationale per seam; defines the seeded-data and transaction/cleanup strategy, auth-context minting through real code paths, and per-boundary negative cases. Produces implementable specs and hands implementa...Votes: 0GitHub stars: 4
- Inter Agent Comms ReviewerReview the security of agent-to-agent and agent-to-MCP-server communication (OWASP Agentic ASI07) — mutual authentication, message integrity, replay protection, confidentiality, topology allowlists and spoofed tool results. Enforces authenticated ≠ trusted: ordinary peer content is untrusted input and cannot assert approvals or permissions; task mutation requires a separate verified authorized channel. Use when agents exchange messages (A2A, MCP transports, shared queues/buses), when wiring a...Votes: 0GitHub stars: 4
- Intra Tenant Scope ArchitectDesign a second mandatory data-scoping axis BELOW the tenant (location / site / region / org-unit / business-unit) for a multi-tenant SaaS — the per-user scope-grant model, the composite row-filter predicate on every scoped table (tenant_id AND scope), which roles are scope-restricted vs tenant-wide, server-derived propagation through app and edge layers, and the migration to add the axis to a live per-tenant schema. Presupposes the tenant boundary; this is a sub-tenant dimension inside ONE t...Votes: 0GitHub stars: 4
- Iso 27001 Isms ArchitectDesign ISO/IEC 27001:2022 certification readiness — the ISMS under clauses 4–10 and Annex A selection across organizational, people, physical, and technological themes. Include the Amd 1:2024 climate-relevance check, risk treatment and Statement of Applicability, internal audit, management review, and documented information. Verify details against licensed text. Shipped skills provide control design routes via compliance-control-foundation; organizational implementation and evidence require s...Votes: 0GitHub stars: 4
- Iso 42001 Aims ArchitectDesign ISO/IEC 42001:2023 certification readiness — the AI management system (AIMS) under clauses 4–10, AI risk assessment and treatment, AI system impact assessment, and Annex A control-objective selection. Verify details against licensed text; public Annex A counts conflict. Shipped Phase 1.5 guidance and ai-governance-risk-reviewer provide design routes through compliance-control-foundation, while organizational controls and evidence require separate verification. Composes statement-of-app...Votes: 0GitHub stars: 4
- Lane Authoring GuideAuthor the pre-work, evidence-cited guide a parallel agent lane needs BEFORE its first task: the lane''s slice of the request lifecycle, the contracts it may rely on and must honor, a step-by-step recipe for its repeating unit of work, a per-unit checklist, and an explicit "what this lane must NOT do" boundary — every load-bearing claim cited to source files/PRs or labeled unverified, so the implementing agent starts from distilled verified knowledge instead of re-deriving it. One guide per l...Votes: 0GitHub stars: 4
- Latency Budget ArchitectDecompose an end-to-end latency target into per-hop engineering budgets — map the path (edge → gateway → services → stores → third parties), allocate milliseconds per hop including overhead (serialization, queue wait, connection setup, retries), and do tail math with explicit dependence assumptions. Under independent branch tails, fan-out exposure is 1-(0.99)^N; correlated tails require measured or bounded joint behavior. Derive timeouts and retries from budgets, keep explicit headroom, and d...Votes: 0GitHub stars: 4
- Library Diff ReviewerReview a whole skill-library PR end-to-end — skill-adding, skill-modifying, or skill-retiring — as the integration layer above single-skill quality review. Verifies a fresh mechanical-validator run tied to the PR head (stale or merely claimed passes rejected), registration consistency (catalog, README, status tables, decision-log entry, banked-candidate graduation, skill-count arithmetic agreeing everywhere), collision of each added skill against the shipped corpus AND its in-batch siblings, ...Votes: 0GitHub stars: 4
- Llm Output Safety ReviewerReview how an application consumes LLM output for improper output handling (OWASP LLM10) — treat model output as untrusted and trace it to each sink: HTML/markdown rendering (XSS), SQL/shell/eval execution (injection, RCE), file paths and URLs (traversal, SSRF), tool arguments, stored-then-reused output (second-order), and AI-generated code before it is saved, committed or run (no auto-run, sandbox, checks, human review gate, provenance). Verify context-correct encoding, sandboxing incl. auto...Votes: 0GitHub stars: 4
- Load Test PlannerPlan the load that makes performance testing mean something — a workload model from production evidence (endpoint mix, write share, arrival patterns, think times), a tenant mix (many-small plus few-whale tenants; the noisy-neighbor scenario where one tenant''s burst must not degrade the rest, judged per-tenant, not aggregate), data volumes seeded to production shape and skew, test types chosen by the question (load-at-target, stress-to-break, soak, spike), ramp profiles with abort criteria, a...Votes: 0GitHub stars: 4
- Local Ci Mirror PreflightMANUAL-ONLY; never auto-invoke. Explicitly invoke to mirror the repository's CI locally before commit or push. Read PR-triggered workflow checks, derive and run their local equivalents, and verify clean mainline in a separate Git worktree. Classify failures as PR-caused, pre-existing on main, CI infrastructure, or locally indeterminate; report inherited failures without absorbing them. Includes a declared docs-only path and evidence for closeout. Runs only repository-declared checks. Not the ...Votes: 0GitHub stars: 4
- Manual Test Case CreatorWrite full manual test cases executable by ANOTHER tester with zero tribal knowledge — each case has an id, requirement/risk trace, role/persona, environment, preconditions, exact test data, numbered steps with ONE observable expected result per step, screenshot checkpoints referenced to the evidence rules, pass/fail criteria, and cleanup. Cases cover happy, negative, and boundary paths and stay implementation-agnostic (what the user does, not what the code does). Use when asked to write manu...Votes: 0GitHub stars: 4
- Memory Context Poisoning ReviewerReview an agent's persistent memory and stored context for poisoning (OWASP Agentic ASI06) — can untrusted content write into long-term memory (auto-summarized conversations, "remember this" injections, tool outputs persisted as facts), does a poisoned entry survive sessions and get trusted as ground truth later, and can memory bleed across tenants/users/sessions. Verifies validation-before-write, per-entry provenance, tenant/user/session scoping, TTL, purge with rollback, and recalled memory...Votes: 0GitHub stars: 4
- Merge Is Deploy GovernanceWhen the platform auto-deploys every merge to mainline, author standing merge/deploy governance: document what deploys, make PR-time validation the authoritative pre-production gate, treat post-merge checks as verification, record human-owned branch protection, state the exposure window and whether an authorized risk owner accepted it, and define strategy-correct revert-and-redeploy rollback. Publishing a draft does not accept risk. Use when merge deploys mainline, post-merge checks are mista...Votes: 0GitHub stars: 4
- Mobile Viewport CraftDesign the mobile and responsive viewport craft for a web UI — a content-driven breakpoint strategy (mobile-first; breakpoints where the layout breaks), touch-target sizing and spacing, safe-area/notch handling, the dynamic-viewport-unit fix for the URL-bar resize (the 100vh trap → svh/lvh/dvh), input behavior (right types, no focus-zoom, keyboard occlusion), hover-absence (no hover-only affordances) and gestures, and responsive layout patterns (reflow, wide tables, orientation). Produces a p...Votes: 0GitHub stars: 4
- Model Context DesignerDesign what enters and leaves a model context window: assemble vetted inputs server-side under caps and closed schemas, minimize sensitive data, separate controlled-store persistence from transient segments, verify provider retention before claiming end-to-end non-persistence, make reconstruction limits explicit, and document exclusions. Also design the prompt contract for each call: a versioned, owned instruction, its declared inputs, a pointer to the output contract, when the model must dec...Votes: 0GitHub stars: 4