All authors

Claude Skills by ModernNomad-98
github.com/ModernNomad-98212 skills1 installs122 views
- Aegis SetupMANUAL-ONLY; never auto-invoke. Use when a person explicitly says "Help me set up Aegis" or "Help me change my Aegis setup" to choose Aegis only or explore future local/online helpers. Do not use for a vague product idea, project stage navigation, ordinary skill selection, security review, or an eval run.Votes: 0GitHub stars: 4
- Feature Flag ArchitectDesign the feature-flag SYSTEM a product runs on — flag store build-vs-buy (an owner choice), SDK and config placement, where flags evaluate (server, client, edge, build time), targeting context (tenant, plan, role, cohort, environment) with tenant-safe caching, the fail-safe mechanism for a flag-service outage (code defaults, last-known-good cache, timeouts), kill-switch propagation and who may flip it, flag-change audit trail, and flag-debt hooks (owner/expiry registry, stale-flag report). ...Votes: 0GitHub stars: 4
- Hidden Context Exposure ReviewerReview an LLM feature for hidden context exposure (OWASP LLM08:2026, formerly LLM07 System Prompt Leakage) across every non-user-facing input the model sees: system prompt, developer instructions, retrieved policy text, tool/function schemas, and other assembled rules. Two axes: CONTENTS (no credentials, keys, internal endpoints, or role, refusal, or workflow logic whose disclosure aids an attacker) and DEPENDENCE (no authorization, filtering, limit, or tool permission may rely on hidden cont...Votes: 0GitHub stars: 4
- Acceptance Criteria ReviewerReview acceptance criteria that already exist, in a spec, ticket or user story, for testability, completeness and ambiguity: each criterion must name an observable outcome, a pass or fail threshold and the evidence that will prove it; missing negative, boundary and permission cases are listed; vague words ("fast", "works", "user-friendly") are flagged with a suggested concrete rewrite for the author to accept. Per-criterion verdict TESTABLE, NEEDS-REWRITE or UNTESTABLE, with one question to t...Votes: 0GitHub stars: 4
- Ai Human In The Loop DesignerDesign how an artificial intelligence (AI) feature''s output becomes product state. Sort every AI-originated write or action into AUTONOMOUS, CONFIRM or FORBIDDEN by risk tier, defaulting to advisory-only (AI proposes, a person commits). For CONFIRM, design the review workflow: a pending proposal that is not yet state, a reviewer queue showing the exact change and its sources, approve, edit, reject and expiry, who may review (no self-approval), commit through the normal write path, and an aud...Votes: 0GitHub stars: 4
- Ai Task DecomposerBreak a broad goal, epic or approved spec into small, ordered tasks an AI agent can each finish, validate and get reviewed as ONE pull request (PR): each task has one intent, an observable acceptance criterion with the evidence that will prove it, the likely files or layers touched, a provisional change class, known risks, dependencies and order, and any human-approval boundary it will cross. Oversized or vague tasks are split again; unknowns become spike tasks or owner questions, never guess...Votes: 0GitHub stars: 4
- Ci Failure ClassifierClassify a CI run''s failures and hidden problems from its logs and reports: each failed or suspicious job gets exactly one class (product bug, test bug, missing secret or config, timeout-only, infrastructure, skipped-runtime where a skip hides the real result, or indeterminate), with duration as first-class evidence and timeouts never conflated with regressions; GREEN runs are scanned for hidden runtime markers (console errors, unhandled rejections, unexpected skips, auth failures). Reads lo...Votes: 0GitHub stars: 4
- Cloud Security Baseline ReviewerReview the CONFIGURED security baseline of a cloud account, subscription or managed platform project (AWS, Azure, GCP, or hosts like Vercel and Supabase) against a named baseline, control by control: identity and owner access, network exposure, secrets and keys, encryption and public storage, audit logging, guardrail policies, posture services and incident readiness. Each control gets MET, GAP or UNVERIFIED from cited evidence (exported settings, posture-scanner findings, IaC or screenshots t...Votes: 0GitHub stars: 4
- Database Backup VerifierMANUAL-ONLY; never auto-invoke. Verify database backups would actually save you: per store, a backup exists, is non-empty, is current against the recovery point objective (RPO), is retained and encrypted as required, has an off-account copy, and is RESTORABLE, proven by a restore drill into an isolated scratch target with row-count and checksum parity and a measured restore time against the recovery time objective (RTO). Also flags dump files inside the repository or its history. Evidence mod...Votes: 0GitHub stars: 4
- Environment Parity ReviewerReview how local, CI, preview, staging and production differ, so "works in staging, fails in production" is caught early: a parity matrix across runtime and dependency versions, environment-variable NAMES and non-secret values, feature-flag defaults, database engine, version and extensions, third-party sandbox versus live modes, auth callbacks, build mode, region, time zone and data shape. Each difference is INTENDED (documented), ACCIDENTAL or UNKNOWN, with evidence and a fix owner; it also ...Votes: 0GitHub stars: 4
- Resilience Architecture ReviewerReview how a system survives failure: per dependency, timeouts, retry budgets with backoff, circuit breakers, bulkheads and graceful degradation; single points of failure and zone or region redundancy with a tested failover path; disaster recovery with recovery time and recovery point objectives (RTO, RPO) per service and store and whether the backup strategy can meet them; and a fault-injection or game-day plan to prove it. Severity-ranked findings cite the component, the failure scenario an...Votes: 0GitHub stars: 4
- Test Tenant ProvisionerMANUAL-ONLY; never auto-invoke. Provision and verify repeatable test tenants and users in a named NON-PRODUCTION environment for auth, row-level-security (RLS), integration and end-to-end (E2E) runs. Every created row carries a test marker and unmarked rows are never mutated; validate-only mode (the default) reports drift against the persona catalog, apply mode creates or repairs only marked tenants, users and memberships; credentials are referenced by environment-variable NAME only; capabili...Votes: 0GitHub stars: 4