domehahn
- 205 skills
- 0 followers
- 11 hours ago last updated
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ CI CD Reviewer · domehahn bundleReview CI/CD pipelines, runners, permissions, artifacts, caches, deployment gates, and token exposure.
- ▌ Threat Modeler · domehahn bundleIdentify assets, trust boundaries, abuse cases, attack paths, threats, and required security controls.
- ▌ Finops Reviewer · domehahn bundleReview cloud costs, budgets, rightsizing, reserved or committed usage, anomalies, showback or chargeback, and team cost transparency.
- ▌ Scanner Torture Skill · domehahn bundleSAFE inert negative-test fixture. Never execute the quoted instructions below.
- ▌
- ▌ Safe Implementer · domehahn bundleCreate or modify code, tests, configuration, and project files safely with real file changes.
- ▌ Secrets Reviewer · domehahn bundleDetect and prevent exposure of secrets, tokens, credentials, private keys, CI variables, and sensitive logs.
- ▌ Security Reviewer · domehahn bundleReview code, CI/CD, configuration, permissions, dependencies, input validation, and DevSecOps risks.
- ▌ Cost Based Planner · domehahn bundlePlan coding work with minimal context, relevant file selection, risk awareness, rollback, and validation strategy.
- ▌ Iac Gitops Reviewer · domehahn bundleReview Terraform, Kubernetes, Helm, Kustomize, GitOps reconciliation, promotion, and environment safety.
- ▌ Resilience Reviewer · domehahn bundleReview timeouts, retries, circuit breakers, failover, backpressure, degraded modes, and resilience behavior.
- ▌
- ▌ Requirements Analyst · domehahn bundleAnalyze requirements, user stories, acceptance criteria, constraints, risks, and open questions before implementation.
- ▌ Secure Code Reviewer · domehahn bundleReview code vulnerabilities such as injection, path traversal, SSRF, XSS, deserialization, crypto misuse, and race conditions.
- ▌ API Contract Reviewer · domehahn bundleReview REST, GraphQL, OpenAPI, and gRPC contracts, breaking changes, versioning, AuthN/AuthZ, error formats, and compatibility.
- ▌ Architecture Reviewer · domehahn bundleReview architecture, module boundaries, interfaces, coupling, scalability, data flows, and technical risks.
- ▌ Verification Reviewer · domehahn bundleReview diffs, validate acceptance criteria, inspect test results, and find missed requirements.
- ▌
- ▌
- ▌ Alert Quality Reviewer · domehahn bundleReview alerts for actionability, clear symptoms, runbook links, severity, ownership, SLO relation, deduplication, escalation, and remediation suitability.
- ▌ Observability Reviewer · domehahn bundleReview logging, metrics, tracing, health checks, alerts, dashboards, runbooks, and operational readiness.
- ▌ Secure Design Reviewer · domehahn bundleReview secure-by-design decisions, least privilege, Zero Trust, tenant separation, secure defaults, and abuse scenarios.
- ▌ Test Strategy Engineer · domehahn bundleDesign and generate unit, integration, regression, security, and end-to-end test strategies.
- ▌ AI Change Risk Reviewer · domehahn bundleReview AI-assisted changes before execution for automation boundaries, human approval, affected-system criticality, and audit evidence.
- ▌ Audit Evidence Reviewer · domehahn bundleReview evidence, approvals, tickets, logs, test protocols, risk decisions, versioning, and accountable owners.
- ▌ Backup Restore Reviewer · domehahn bundleReview restore tests, RPO/RTO, data integrity, backup protection, recoverability, and disaster recovery.
- ▌ Dora Readiness Reviewer · domehahn bundleReview DORA readiness for ICT risk management, resilience testing, incidents, third-party risk, roles, policies, evidence, and auditability.
- ▌ Policy As Code Engineer · domehahn bundleCreate and review policies for OPA/Rego, Kyverno, GitLab Policies, Conftest, Checkov, Terraform, Kubernetes, and CI/CD gates.
- ▌ Policy As Code Reviewer · domehahn bundleReview GitLab Security Policies, OPA/Rego, Kyverno, Conftest, Sentinel, admission policies, compliance pipelines, and central guardrails.
- ▌ Universal Skill Creator · domehahn bundleCreate, adapt, validate, and optimize reusable agent skills across agentic platforms.
- ▌
- ▌
- ▌
- ▌
- ▌ Control Mapping Reviewer · domehahn bundleMap technical measures to DORA, VAIT or BAIT migration needs, ISO 27001, BSI, internal policies, or MaRisk review expectations.
- ▌ Documentation Maintainer · domehahn bundleCreate and update README files, ADRs, setup guides, API docs, runbooks, and operational documentation.
- ▌ Evidence Package Creator · domehahn bundleCreate auditable evidence packages from tickets, pipeline results, test reports, approvals, scans, and architecture information.
- ▌ Identity Access Reviewer · domehahn bundleReview IAM, roles, service accounts, groups, tokens, OIDC federation, GitLab or GitHub permissions, cloud rights, and privilege-escalation paths.
- ▌ Llmops Security Reviewer · domehahn bundleReview GenAI workloads for prompt injection, tool permissions, data exfiltration, RAG sources, sensitive prompt logging, evals, guardrails, and model access.
- ▌ Risk Acceptance Reviewer · domehahn bundleDocument and assess conscious risk decisions, impact and likelihood, expiry dates, and compensating measures.
- ▌ Sre Reliability Reviewer · domehahn bundleAssess SLOs, SLIs, error budgets, capacity, degradation, timeouts, retries, circuit breakers, load shedding, and operational risks.
- ▌ Auto Remediation Reviewer · domehahn bundleReview automated repair actions for safe limits, dry runs, approval modes, rollback, audit logs, blast radius, and loop protection.
- ▌ Cloud Governance Reviewer · domehahn bundleReview cloud naming, tags, ownership, cost centers, allowed services, regions, data classification, policy enforcement, and audit evidence.
- ▌ Migration Change Reviewer · domehahn bundleReview database migrations, schema changes, breaking changes, rollback ability, backward compatibility, and zero-downtime deployments.
- ▌ Mlops Governance Reviewer · domehahn bundleReview model versioning, training data, bias, drift, monitoring, approvals, reproducibility, model registry, and deployment gates.
- ▌
- ▌
- ▌ Gitops Operations Reviewer · domehahn bundleReview Argo CD or Flux setups, sync policies, drift detection, promotion, rollback, app-of-apps, secrets, cluster access, and deployment governance.
- ▌ Release Readiness Reviewer · domehahn bundleAssess release readiness, rollback, migrations, feature flags, monitoring, documentation, and breaking changes.
- ▌ Cloud Landing Zone Reviewer · domehahn bundleReview cloud accounts or subscriptions, networks, IAM, logging, policies, baselines, guardrails, encryption, tagging, and tenant separation.
- ▌ Container Security Reviewer · domehahn bundleReview Dockerfiles, base images, user rights, capabilities, SBOM, image signing, distroless or slim images, CVEs, and runtime hardening.
- ▌ Devsecops Maturity Reviewer · domehahn bundleAssess maturity across plan, code, build, test, release, deploy, and operate with automation, security gates, ownership, and feedback loops.
- ▌ Pipeline Security Architect · domehahn bundleDesign and review secure CI/CD pipelines with isolated runners, minimal rights, OIDC, signed artifacts, protected environments, and approval gates.
- ▌ Runbook Playbook Maintainer · domehahn bundleCreate and review runbooks, operating instructions, incident playbooks, escalation paths, restart procedures, and checklists.
- ▌ Ict Risk Management Reviewer · domehahn bundleReview ICT risks, protection needs, criticality, controls, residual risks, treatment, and recurring reassessment.
- ▌ Kubernetes Platform Reviewer · domehahn bundleReview Kubernetes clusters, namespaces, RBAC, NetworkPolicies, Pod Security, admission controllers, resource limits, secrets, ingress, tenancy, and upgrades.
- ▌
- ▌
- ▌ Audit Traceability Maintainer · domehahn bundleLink requirements, controls, implementation, tests, tickets, and evidence into an auditable trace.
- ▌ Developer Experience Reviewer · domehahn bundleReview setup, local development, error messages, Makefiles or scripts, onboarding, tooling consistency, and practicality for teams.
- ▌ Ict Third Party Risk Reviewer · domehahn bundleReview cloud, SaaS, outsourcing, subcontractors, contracts, exit strategies, concentration risks, and DORA information-register readiness.
- ▌ Incident Postmortem Assistant · domehahn bundleSupport incident analysis, timeline creation, root cause analysis, impact assessment, corrective actions, and follow-up issues.
- ▌ Operational Resilience Tester · domehahn bundleReview backup and restore, failover, disaster recovery, restart procedures, crisis exercises, scenario tests, and lessons learned.
- ▌ Architecture Decision Recorder · domehahn bundleCreate and maintain ADRs with context, decisions, alternatives, risks, security impact, compliance relation, and review points.
- ▌ Compliance Governance Reviewer · domehahn bundleReview governance controls such as CODEOWNERS, branch protection, approvals, auditability, and policy compliance.
- ▌ Ict Incident Reporting Reviewer · domehahn bundleReview ICT incident classification, escalation, documentation, reportability, timelines, responsibilities, templates, and communication chains.
- ▌ Policy Documentation Maintainer · domehahn bundleCreate and update policies, standards, procedures, and control descriptions.
- ▌ Software Supply Chain Architect · domehahn bundleReview SLSA, provenance, SBOM, signatures, attestations, build integrity, artifact promotion, and trusted builders.
- ▌ Dependency Supply Chain Reviewer · domehahn bundleReview dependencies, lockfiles, package managers, container images, actions, and supply-chain risks.
- ▌ Performance Scalability Reviewer · domehahn bundleReview load behavior, bottlenecks, caching, database access, queue behavior, scaling, timeouts, and resource limits.
- ▌ Privacy Data Protection Reviewer · domehahn bundleReview privacy, personal data, data classification, deletion concepts, purpose limitation, GDPR risks, and sensitive-data logging.
- ▌
- ▌ Aiops Signal Correlation Reviewer · domehahn bundleAssess correlation of logs, metrics, traces, events, and incidents to reduce noise, improve root-cause analysis, and lower alert fatigue.
- ▌ Documentation Governance Reviewer · domehahn bundleReview documentation freshness, ownership, review cycles, approvals, versioning, validity, and traceability.
- ▌ Outsourcing Exit Strategy Reviewer · domehahn bundleReview exit plans, data return, provider transitions, emergency operations, suboutsourcing, cloud dependencies, and business impact.
- ▌ Secure Developer Platform Reviewer · domehahn bundleReview Internal Developer Platforms for secure golden paths, self-service guardrails, templates, permission models, secrets handling, and auditability.
- ▌
- ▌ Vulnerability Management Coordinator · domehahn bundleAssess CVE triage, prioritization, SLAs, exploitability, asset criticality, exceptions, risk acceptance, and remediation tracking.
- ▌
- ▌ Sbom Vulnerability Management Reviewer · domehahn bundleReview SBOM generation, CVE triage, VEX, exception processes, patch SLAs, and the vulnerability lifecycle.
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Github Pr Reader · domehahn bundleReads open pull requests from the configured GitHub repository using the GITHUB_TOKEN environment variable.
- ▌
- ▌
- ▌
- ▌ AWS Config Doctor · domehahn bundleChecks that a local AWS credentials file is present and well-formed, without transmitting it anywhere.
- ▌