All authors

Claude Skills by VincentChuWaiChow
github.com/VincentChuWaiChow765 skills4 installs1,172 views
- Scaleway Kapsule Platform OperatorReview and advise on Scaleway Kapsule managed Kubernetes cluster readiness: node pool sizing and autoscaling, CNI plugin selection (Cilium, Calico, Kilo), placement group policy (max_availability vs enforced), Kubernetes version currency, PodDisruptionBudget coverage, and workload scheduling posture. Use when the user asks to assess Kapsule production readiness, select a CNI, design node pools, or plan a version upgrade strategy.Votes: 0GitHub stars: 23
- Scaleway Live Kapsule Rollout GuardGate and execute Scaleway Kapsule live mutations — Kubernetes version upgrades, node pool creation/deletion/scaling, and cluster configuration changes — with mandatory PDB audit, cluster health verification, explicit approval, and a documented rollback plan. Use when a live Kapsule cluster or node pool mutation is requested. Hard-stops when target cluster ID, region/zone, approval, or rollback plan is absent or ambiguous.Votes: 0GitHub stars: 23
- Scaleway MaestroClassify and route Scaleway tasks to the narrowest qualified specialist agent. Use when a user presents a Scaleway request that spans IAM, cost, Kapsule/Kubernetes, networking, or live-guard domains, and the correct specialist is not yet identified. Produces a domain verdict, recommended specialist, and routing rationale without answering specialist questions directly.Votes: 0GitHub stars: 23
- Scaleway Network ArchitectReview and design Scaleway network topology for security and high availability: VPC layout, Private Network attachment across zones, security group rules, Load Balancer configuration, placement group policy selection (max_availability vs enforced), and multi-zone resilience patterns. Use when the user asks to design a Scaleway VPC, audit security group rules, configure a Load Balancer, or plan HA across zones fr-par-1/2/3, nl-ams-1, or pl-waw-1/2/3.Votes: 0GitHub stars: 23
- Sigstore Cosign Supply Chain ReviewUse this skill when reviewing Sigstore Cosign supply chain security for Kubernetes workloads. Trigger when the user asks whether images are properly signed, whether Kyverno imageVerify policy is correctly scoped, whether SLSA provenance attestations exist, whether SBOM attestations are present, whether keyless signing is in use, or whether Rekor transparency log posture is appropriate for private images.Votes: 0GitHub stars: 23
- Snowflake Analytics Semantic Data ProductUse this skill to review analytical correctness and business semantics in Snowflake: join grain and fan-out, window and null semantics, semantic views and their declared relationships, metric and KPI contracts, BI workload design, the Cortex Analyst semantic boundary, and conflicting business definitions. Trigger when a number is disputed, a metric is being defined, or a semantic model is being built. Static review only: it never executes a query, and it never settles a business-definition co...Votes: 0GitHub stars: 23
- Snowflake Bcdr ResilienceUse this skill to test whether a Snowflake recovery claim is provable: replication versus failover groups and their membership, edition and region constraints, Client Redirect, RPO and RTO tracked as requested/feasible/proven, the dependency matrix outside Snowflake, DR drill scope and evidence, failover preconditions and data-loss window, and failback design. Trigger on any DR, failover, replication, or business-continuity question. Static review only: it never promotes or fails over anythin...Votes: 0GitHub stars: 23
- Snowflake Business Value Adoption StrategistUse this skill to test whether a Snowflake initiative removes a business constraint anyone owns: value hypothesis, pre-work baseline, benefit modelling by credibility category, unit economics, causal attribution, adoption, time to value, decision latency, alternatives including do-nothing, benefit realization, and translation into executive KPIs. Trigger when an initiative is proposed, prioritized, or being justified — and especially when the justification is that Snowflake supports the capab...Votes: 0GitHub stars: 23
- Snowflake Compliance Evidence AuditorUse this skill to establish whether a Snowflake control is provable to an auditor: evidence collection from ACCESS_HISTORY, LOGIN_HISTORY, grant history and Trust Center, control mapping with named gaps, audit-period coverage, evidence freshness and retention limits, and segregation-of-duties analysis derived from the grant graph. Trigger when the question is proof rather than configuration. It never implements a control and never states a compliance conclusion.Votes: 0GitHub stars: 23
- Snowflake Cortex Ai Agent Security GovernorUse this skill to review the security and governance boundary of Snowflake AI: Cortex Agents and their identity and effective data reach, CORTEX_USER versus CORTEX_AGENT_USER and AI-function privileges including grants to PUBLIC, Cortex Search corpora as an untrusted-content surface, Cortex Analyst semantic exposure, tools and MCP connectors as privilege grants, prompt and indirect prompt injection, exfiltration paths, guardrails, adversarial evaluation, observability, and cost per successful...Votes: 0GitHub stars: 23
- Snowflake Data Engineering PipelinesUse this skill to review Snowflake batch and ELT pipelines for data correctness: COPY and load semantics, Streams offset behaviour, Tasks and task graphs, Dynamic Tables and achieved versus configured target lag, Snowpark transformations, schema evolution from the consumer's position, idempotency and replay, and reconciliation design. Trigger when data is late, duplicated, incomplete, or suspected wrong, or when a pipeline is being designed. Static review only: it never runs, resumes, or back...Votes: 0GitHub stars: 23
- Snowflake Data Platform Engineering At AzureDesign and review Snowflake data platform engineering on Azure, covering warehouse sizing and cost governance, Azure Private Link requirements, storage integration with ADLS Gen2 and Azure Blob, Snowpipe automation, object tagging, dynamic data masking, row access policies, and ACCESS_HISTORY lineage for GDPR and CCPA compliance.Votes: 0GitHub stars: 23
- Snowflake Data Science MlUse this skill to review the ML lifecycle in Snowflake for reproducibility and governability: feature engineering and leakage, point-in-time correctness and training/serving skew, training reproducibility, the model registry and versioning, batch and continuous inference, drift and performance monitoring, ML lineage, and retraining and rollback policy. Trigger when a model is moving toward or already in production. Static review only: it never trains, registers, deploys, or invokes a model, a...Votes: 0GitHub stars: 23
- Snowflake Devops Iac ReleaseUse this skill to review how Snowflake changes ship: the official Terraform provider and its stable-versus-preview resource split, version pinning and upgrade rehearsal, plan review for destroy/replace and grant changes, state posture, Snowflake CLI in automation, CI/CD and environment promotion, drift adoption versus reversion, behaviour-change bundle management, and rollout and rollback strategy. Trigger on any Snowflake IaC, pipeline, or release question. Static review only: it never appli...Votes: 0GitHub stars: 23
- Snowflake Finops Cost GovernorUse this skill to make Snowflake consumption accountable: decompose warehouse, serverless, AI, storage and transfer spend; distinguish budgets from resource monitors and find the uncontrolled surface; attribute credits by query tag, object tag and warehouse; design defensible chargeback; investigate anomalies and forecast variance; and evaluate optimization economics. Trigger on any cost, credit, budget, attribution, or spend-anomaly question. Static review only: it never resizes a warehouse,...Votes: 0GitHub stars: 23
- Snowflake Governance PrivacyUse this skill to design or review Snowflake data controls: sensitive-data discovery and classification, tags and propagation, masking policies, row-access policies, aggregation/projection/join policies, policy assignment and the consumption paths a policy does or does not reach, lineage completeness, and data quality monitoring. Trigger when the question is what a permitted principal sees inside the data, or whether a control actually behaves. Static review only: it never attaches or alters ...Votes: 0GitHub stars: 23
- Snowflake Identity Access SecurityUse this skill to review Snowflake identity and authorization: effective access across role hierarchy, ownership and future grants; custom, database, and application role choice; managed access schemas; authentication policies, MFA, SSO, SCIM, OAuth, key-pair, and workload identity federation; SERVICE and SERVICE_AGENT user types; and concrete privilege-escalation paths. Trigger on any question about who can do what in a Snowflake account, or how a principal proves identity. Static review onl...Votes: 0GitHub stars: 23
- Snowflake Live Auth Network Policy GuardApproval-gated live guard for exactly one Snowflake network-policy or authentication-policy change. Refuses any tightening for which a surviving administrative path has not been demonstrated from login history — a named principal, a proven location, and the privilege to revert. Refuses combined add-and-remove changes, integration lifecycle operations, MFA weakening, and unconstrained break-glass paths. Runs as a custom role owning only the target policy object; never ACCOUNTADMIN.Votes: 0GitHub stars: 23
- Snowflake Live Data Protection Policy GuardApproval-gated live guard for exactly one Snowflake data-protection policy attachment, detachment, or replacement on one object or column. Requires a per-role-class visibility prediction that has been tested before execution, an enumeration of the consumption paths the protection will and will not follow, and — for any detachment — a written justification, a named data owner, and a committed re-attachment time. Never displays sensitive values, including during verification. Runs as a custom r...Votes: 0GitHub stars: 23
- Snowflake Live Failover Promotion GuardApproval-gated live guard for exactly one Snowflake failover group promotion. Requires a declared incident or drill, a named accountable owner, a data-loss window computed from replication refresh history, dependency readiness confirmed item by item by each owning team, a client redirection plan covering hardcoded clients, and a stated failback strategy — all before the statement is composed. Refuses on urgency alone. Runs as a custom role in the target account able to promote only the named ...Votes: 0GitHub stars: 23
- Snowflake Live Pipeline Streaming Change GuardApproval-gated live guard for exactly one Snowflake pipeline or ingestion change — one task, stream, dynamic table, or pipe operation, or one bounded backfill. Requires a freshness and count baseline, the last successful processing state, the offset or checkpoint position, a downstream consumer enumeration, and an explicit duplication-or-loss analysis before execution, plus a passing reconciliation afterwards. Refuses unbounded replays and replays into targets with no deduplication path. Runs...Votes: 0GitHub stars: 23
- Snowflake Live Rbac Grant Guard At AzureMutating-runtime live guard for Snowflake RBAC privilege management on Azure. Executes exactly ONE GRANT or REVOKE of a single privilege on a single securable to a single custom role — with explicit written human approval, dry-run preflight (SHOW GRANTS prior state), and a named rollback owner. Phase B strictly-scoped controlled mutation; never ACCOUNTADMIN/SECURITYADMIN/SYSADMIN/PUBLIC, never OWNERSHIP, never MANAGE GRANTS, never future grants at database or account scope.Votes: 0GitHub stars: 23
- Snowflake Live Rbac Grant GuardApproval-gated live guard for exactly one Snowflake privilege change: ONE privilege, on ONE securable, to or from ONE custom role. Use only after a human has read the effective-inheritance impact and returned written approval naming account, environment, securable, privilege, role, and accepted blast radius. Runs as a custom role owning only the target securable — never ACCOUNTADMIN, never MANAGE GRANTS. Refuses ALL PRIVILEGES, ownership transfer, system-role and PUBLIC targets, bulk operatio...Votes: 0GitHub stars: 23
- Snowflake Live Warehouse Cost Change GuardApproval-gated live guard for exactly one Snowflake warehouse or cost-governance change: a size, auto-suspend, auto-resume, scaling or concurrency setting, a resource-monitor assignment or threshold, or a supported budget operation. Requires a quantified cost effect, a quantified performance effect with a falsification criterion, an affected-workload enumeration, and an agreed rollback trigger before execution. Treats a suspend-capable monitor as an availability control. Runs as a custom role...Votes: 0GitHub stars: 23
- Snowflake MaestroUse this skill to classify a Snowflake task and route it to the narrowest review specialist on the Snowflake board, or to gate a mutation request behind explicit written human approval. Trigger when a Snowflake architecture, administration, identity, network, governance, compliance, FinOps, query performance, pipeline, streaming, analytics, ML, Cortex AI, Native App, BCDR, DevOps/IaC, migration, or business-value task arrives and the right specialist is not yet obvious. Routing only: it never...Votes: 0GitHub stars: 23
- Snowflake Migration ModernizationUse this skill to assess migration to Snowflake from, or coexistence with, Teradata, Oracle, SQL Server, Redshift, BigQuery, Databricks, Hadoop/Spark, or a legacy EDW: workload inventory and per-workload classification, SQL and semantic compatibility, data gravity, security mapping and control gaps, wave sequencing, dual running, reconciliation, cutover, and rollback expiry. Trigger on any migration, replatform, or coexistence question. Static review only: it never moves data or executes a cu...Votes: 0GitHub stars: 23
- Snowflake Native App Marketplace ProductUse this skill to review a Snowflake Native App or Marketplace listing as a product: application package and application-role design, requested privileges and the provider/consumer trust boundary, security-review readiness, listing and publication requirements, pricing and monetization architecture, version and patch lifecycle including withdrawal, telemetry and shareback consent, and supportability economics. Trigger when building, publishing, or reviewing an application or listing. Static r...Votes: 0GitHub stars: 23
- Snowflake Network Private ConnectivityUse this skill to review Snowflake reachability in both directions: network rules and policies at account and user scope, inbound and outbound private connectivity, internal stage access paths, external access integrations and egress destinations, endpoint pinning, and lockout prevention. Trigger on any question about where Snowflake can be reached from or what it can reach. Static review only: it never activates or alters a network policy, and it refuses any tightening that cannot demonstrat...Votes: 0GitHub stars: 23
- Snowflake Platform AdministratorUse this skill to review the operability of a running Snowflake estate: account and organization administration, warehouse and object lifecycle, account parameter posture and resolution level, ownership mapping, measured configuration drift, usage monitoring coverage, and operational readiness. Trigger when the question is how the platform is run and recovered rather than how it should be shaped. Static review only: it never executes an administrative statement and never mutates an account.Votes: 0GitHub stars: 23
- Snowflake Query Performance EngineerUse this skill to diagnose Snowflake query and workload performance from evidence: Query Profile interpretation, partition pruning, local and remote spilling, queue versus execution time, warehouse sizing and multi-cluster scaling, caching, clustering, materialized views, search optimization, query acceleration, and benchmark design. Trigger on any slow query, queueing, or throughput question. Static review only: it never runs a query, never resizes a warehouse, and never proposes a size chan...Votes: 0GitHub stars: 23
- Snowflake Rbac Access Governance At AzureReview Snowflake RBAC role hierarchies, privilege grants, managed-access schemas, network policies, MFA enforcement, and Entra ID External OAuth/SAML/SCIM integration for least-privilege and separation-of-duties compliance on Azure-hosted Snowflake accounts.Votes: 0GitHub stars: 23
- Snowflake Solution ArchitectUse this skill to review or design end-to-end Snowflake architecture: organization and account topology, workload placement and isolation boundaries, edition/cloud/region constraints, source-to-consumption paths, interoperability and catalog choices, and architecture decision records. Trigger when a Snowflake design decision is structural rather than operational — how many accounts, where a workload lands, which boundary is load-bearing, whether an edition upgrade is justified. Static review ...Votes: 0GitHub stars: 23
- Snowflake Streaming Ingestion ReliabilityUse this skill to review Snowflake continuous ingestion for silent failure: Snowpipe, Snowpipe Streaming high-performance versus classic architecture and its migration, channel and offset semantics, delivery guarantees hop by hop, backpressure and retry correctness, schema validation and rejected records, the Kafka connector and its version-specific behaviour, Openflow connectors, and the observability that detects a partial stop. Trigger on any continuous ingestion question. Static review on...Votes: 0GitHub stars: 23
- Terraform Engine CompatibilityUse this skill to decide whether a Terraform core upgrade, a provider major upgrade, or a move between Terraform and OpenTofu is safe to adopt, in what order, and with what rollback. Enumerates breaking changes for the exact version pair, separates errors from forced replacements, tracks deprecation exposure, and treats the engine choice as a divergence register rather than a preference. Static review of version constraints, lock files, and upgrade guidance only.Votes: 0GitHub stars: 23
- Terraform Estate ReconciliationUse this skill to reconcile the Terraform or OpenTofu record with reality without destroying anything: classify drift and decide whether to adopt, revert, or accept it; plan a brownfield import with the right `id`/`identity` addressing and a no-op verification gate; and carry renames or restructures with `moved` and `removed` blocks instead of state surgery. Advisory only — it reads plans and source, never runs `import` or a state command.Votes: 0GitHub stars: 23
- Terraform Execution GovernanceUse this skill to judge whether the pipeline that executes Terraform or OpenTofu changes can be trusted with its privileges: runner identity lifetime and scope, the plan-versus-apply credential split, whether apply consumes the reviewed saved plan, how cleartext-sensitive plan artifacts move between stages, approval integrity, and every trigger that can reach the apply path. Static review of pipeline and runner configuration only — it never triggers, modifies, or approves anything.Votes: 0GitHub stars: 23
- Terraform MaestroRoute a Terraform or OpenTofu task to the right advisory specialist on the IaC board. Use when the specific specialist is not already known. Not for direct IaC answers — this skill classifies, dispatches, and synthesizes only. Applies documented thresholds so a change is not sprayed across four agents when one owns it, and stops for written human confirmation before any live apply, destroy, or state mutation is handed to a cloud live-guard agent.Votes: 0GitHub stars: 23
- Terraform Module ContractUse this skill to review a Terraform or OpenTofu module as a reusable contract: whether its inputs are constrained rather than merely documented, whether its outputs promise more than intended, where each invariant belongs, whether a change is breaking for existing callers, and whether a proposed one-off module should exist at all given the platform modules already available. Static review of source and sanitized variable files only — it never runs the engine, contacts a registry, or reviews ...Votes: 0GitHub stars: 23
- Terraform Plan Blast RadiusUse this skill to read a Terraform or OpenTofu plan and explain why the engine is replacing or destroying anything, what the replacement ordering means for availability, whether address churn is causing mass recreation, and whether the reviewed plan will actually bind the apply. Engine-level plan mechanics across every cloud. Reads plan output and source only — it never runs the engine and never approves an apply.Votes: 0GitHub stars: 23
- Terraform Policy EvidenceUse this skill to turn a Terraform or OpenTofu change into an auditable control decision: which controls it touches, whether the enforcing policy blocks or merely warns, whether the policy evaluates the plan or only the source text, whether an exception is scoped and expiring, and what evidence artifact could be produced months later. Advisory only — it never grants an exception, signs an attestation, or runs a policy engine.Votes: 0GitHub stars: 23
- Terraform State ReliabilityUse this skill to judge the reliability, recoverability, and confidentiality of Terraform or OpenTofu state: backend and locking configuration, backup and restore posture, whether a proposed `state mv`/`state rm`/`force-unlock` is justified and reversible, OpenTofu's native state encryption and its key-loss risk, and which sensitive values state records in the clear. Advisory only — it reads backend blocks and state metadata, never a raw state file, and never performs a state operation.Votes: 0GitHub stars: 23
- Terraform Supply Chain IntegrityUse this skill to decide whether Terraform or OpenTofu dependencies come from where their authors intended and whether that trust is actually enforced at install time: provider source addresses and namespace lookalikes, `.terraform.lock.hcl` coverage across every platform that runs `init`, the `h1:`/`zh:` hash schemes, mirrors and `dev_overrides` that bypass verification, and module sources pinned to mutable references. Static review of declarations, lock files, and CLI configuration only.Votes: 0GitHub stars: 23
- Terraform Verification StrategyUse this skill to decide what verification a Terraform or OpenTofu change actually needs and what each option proves: `validate` versus a plan, `terraform test` run blocks with `command = plan` versus `command = apply`, mock providers, and assertions on the properties that would cause an outage. Procedure only — it produces a verification plan, not a pass/fail verdict; the owning agent (`terraform-reviewer` for module contracts, `terraform-plan-blast-radius-agent` for change safety) issues th...Votes: 0GitHub stars: 23
- Typescript Async Contract ReliabilityUse this skill to statically review server-side TypeScript async reliability: floating and ignored promises, async functions passed where `void` is expected, `AbortSignal` cancellation plumbing, unhandled-rejection posture (Node defaults `--unhandled-rejections` to `throw`, and it is not safe to resume after `uncaughtException`), stream/async-iterable backpressure, concurrency bounds, guaranteed cleanup, and typed error channels. Reads source and Node/lint configuration only; it never runs th...Votes: 0GitHub stars: 23
- Typescript Build Graph PerformanceUse this skill to statically review, from supplied measurement evidence only, what in a TypeScript program graph costs measured build or editor time: project references, `composite`/`incremental`/`.tsbuildinfo` behavior, generated-code volume, pathological type instantiation, language-service/editor latency, and duplicated checking across lint, test, and build. Reads `--extendedDiagnostics`/trace output and configuration only; it never invokes the compiler or measures a live system.Votes: 0GitHub stars: 23
- Typescript Business Critical Automation GovernanceUse this skill to statically review whether a privileged TypeScript automation (backfill, migration, reconciliation script) may run and under what controls: dry-run coverage of the write path, technical and business idempotency, blast-radius bounds, approval separation, checkpoint/resume, rollback and reconciliation evidence, audit trail, and a named inverse operation — with particular attention to type-stripped, never-type-checked execution holding production credentials combined with floati...Votes: 0GitHub stars: 23
- Typescript Engineering EconomicsUse this skill to convert another TypeScript specialist's supplied measurements into a funding decision: annual engineering-hours lost, CI compute cost, migration cost, break-even, cost of postponement, and investment priority order, with formulas, sensitivity analysis, and every value labelled measured, supplied, or assumed. It never originates a measurement, is never dispatched first, and is re-prosecuted two quarters after shipping. Reads only user-supplied figures and other specialists' h...Votes: 0GitHub stars: 23
- Typescript Estate Modernization GovernorUse this skill to statically review TypeScript estate-migration sequencing and reversibility: staged strictness adoption, compiler-major upgrades including the TS 6.0→7.0 tooling split, module-system migration, `skipLibCheck`/suppression debt burn-down, and exposure to removed compiler values. Owns sequencing and portfolio prioritization, not per-file fixes, framework migrations, steady-state policy, or the financial case. Reads configuration and version evidence only.Votes: 0GitHub stars: 23
- Typescript MaestroUse this skill to classify a TypeScript task and route it to the narrowest static-review specialist on the TypeScript board, or to gate a production-mutation request to a named human owner. Trigger when a user brings a TypeScript compiler, type-system, runtime-boundary, module-resolution, Node-execution, declaration, build-graph, lint-policy, async-contract, publication, modernization, MCP tool-contract, privileged-automation, or engineering-economics task and the right specialist is not yet ...Votes: 0GitHub stars: 23
- Typescript Mcp Tool ContractUse this skill to statically review MCP tool-contract fidelity in TypeScript servers against the 2026-07-28 specification revision: `inputSchema`/`outputSchema` fidelity against handler behavior, JSON Schema dialect correctness, `structuredContent` vs `content`, protocol-version negotiation and the `-32022` mismatch error, `server/discover`, and protocol vs tool-execution error classification. Reads tool definitions, handler source, and SDK/package metadata only; it never hosts or contacts a ...Votes: 0GitHub stars: 23