bruk-io
- 15 skills
- 0 followers
- 7 hours ago last updated
- ▌ Skillsign Security Review · bruk-ioThis skill should be used when the user asks to "run a security review", "review the spec", "check the specification security", "analyze SkillSign", or mentions reviewing the SkillSign specification. Launches 6 specialized agents in parallel (crypto-reviewer, input-surface-reviewer, identity-reviewer, policy-reviewer, attack-researcher, consistency-checker) to perform a comprehensive security review and synthesize findings into tiered recommendations.
- ▌ Skillsign Threat Modeling · bruk-ioThis skill provides threat modeling frameworks for signing specifications using STRIDE and attack trees. Use when analyzing supply chain compromise, substitution attacks, sidecar rollback, verification bypass, policy weakening, downgrade attacks, TOCTOU exploitation, temporal attack vectors, or signer impersonation paths. Do NOT use for general application threat modeling unrelated to signing systems.
- ▌ Skillsign Sigstore Protocol · bruk-ioThis skill provides domain knowledge about Sigstore keyless signing infrastructure including Fulcio certificate authority, Rekor transparency log, and TUF root distribution. Use when reviewing cryptographic protocols, certificate chain validation, SCT vs SET distinctions, verification modes (default, strict, offline), or common Sigstore integration vulnerabilities. Do NOT use for general cryptography unrelated to Sigstore.
- ▌ Skillsign Parser Attack Taxonomy · bruk-ioThis skill provides a taxonomy of input parsing attacks relevant to signing specifications. Use when reviewing YAML parsing security, UTF-8 encoding attacks, path traversal in identifiers, whitespace normalization, size-based DoS, or canonical form manipulation. Covers duplicate keys, anchors/aliases, tag injection, BOM manipulation, null bytes, Unicode homoglyphs, and segment injection. Do NOT use for general web security unrelated to input parsing.
- ▌ Skillsign Policy Engine Patterns · bruk-ioThis skill provides security patterns for policy engine design in signing specifications. Use when reviewing trust policy format, rule evaluation order (first-match-wins), default action handling, max_age_days semantics, signer vs signer_org matching, require_signer_id_match behavior, CLI flag interactions with offline mode, or unsigned policy file risks. Do NOT use for general authorization policy design unrelated to signing verification.
- ▌ Skillsign Spec Quality Checklist · bruk-ioThis skill provides a quality checklist for reviewing signing specification documents. Use when checking cross-reference accuracy, terminology consistency, algorithm consistency between signing and verification, error handling coverage, exit code mappings, format specifications, RFC 2119 compliance, implementability, versioning, or common spec anti-patterns. Do NOT use for general document review unrelated to technical specifications.
- ▌ Skillsign Identity Attack Patterns · bruk-ioThis skill provides attack patterns for identity spoofing, namespace squatting, and trust boundary violations in signing systems. Use when reviewing signer identity claims, skill_id ownership, SAN manipulation, certificate chain attacks, percent-encoding bypass, case sensitivity mismatches, org membership confusion, or policy evaluation attacks. Do NOT use for general identity/auth patterns unrelated to signing specifications.
- ▌
- ▌
- ▌ Sprint Review · bruk-ioUse when reviewing completed work after sprint execution. Dispatches the right reviewer agent based on what changed. Covers the review dispatch table, quality gates, and plan approval process. Loaded by team lead and review agents during the VERIFY phase.
- ▌ Sprint Planning · bruk-ioUse when starting a new development cycle. Selects 3-5 issues from GitHub, decomposes them into micro-batches (one issue = one shippable unit), and prepares the task list. Loaded by team lead or PM agent at the start of each sprint cycle.
- ▌ Sprint Evolution · bruk-ioUse after the RETRO phase to apply retrospective outputs and prepare for the next cycle. Covers applying changes, the human checkpoint, agent roster management, model assignment strategy, and stuck agent detection. Loaded by the team lead during the EVOLVE phase.
- ▌ Sprint Execution · bruk-ioUse when working on tasks during a sprint. Covers the full task lifecycle: claim, understand, plan, implement, self-verify, and report. Includes worktree discipline, self-verification checklist, failure reporting, and model assignment guidance. Loaded by implementation agents and any task-executing agent.
- ▌ Sprint Integration · bruk-ioUse when merging reviewed work after the VERIFY phase. Covers merging passing PRs, flagging failures, updating the architecture model, and running integration verification. Loaded by the team lead during the INTEGRATE phase.
- ▌ Sprint Retrospective · bruk-ioUse after the INTEGRATE phase to reflect on the sprint cycle. Analyzes what worked, what didn't, detects patterns across agent failures, checks previous retro effectiveness, and produces concrete outputs (skill/rule updates, new issues, process changes, memory updates). Loaded by team lead or retro agent (Opus) during the RETRO phase.