ersinkoc
- 52 skills
- 0 followers
- 6 hours ago last updated
- ▌ Project Bootstrapper · ersinkoc bundleUniversal meta-skill that bootstraps ANY software project regardless of programming language. Auto-generates 15-30+ hyper-detailed, project-specific coding skills BEFORE writing code. Language-agnostic: works with TypeScript, Python, Go, Rust, Java, C#, Swift, Kotlin, PHP, Ruby, and polyglot projects. AGGRESSIVE version enforcement: EVERY technology version MUST be verified via real-time lookup — never use memorized versions. Generates skills for architecture, security, performance, privacy, testing, error handling, accessibility, observability, data modeling, API design, DevOps. Each skill enforces zero-bug standards with concrete code examples, anti-patterns, and measurable budgets. Triggers on: "bootstrap", "new project", "start project", "create project", "set up", "generate skills" — use BEFORE any code exists.
- ▌ Project Manager · ersinkoc bundleActs as a vigilant project manager throughout development, ensuring all code adheres to the project's skill rules. Monitors .claude/skills/ for changes, validates code against active skills, prevents skill drift, enforces pre-commit checks, generates compliance reports, and guides developers back to skill compliance when deviations occur. Activates on every code change, file creation, refactoring, or when developers say "implement", "add feature", "refactor", "fix", or "code review". Must read active skills before any code modification.
- ▌ Security Check · ersinkoc bundleComprehensive AI-powered security scanning suite with 48 skills covering OWASP Top 10, 7 language-specific deep scanners (Go, TypeScript, Python, PHP, Rust, Java, C#), supply chain analysis, infrastructure-as-code scanning, and 3000+ checklist items. Use when you need to run a security audit, find vulnerabilities, scan a PR for security issues, or perform a penetration test on a codebase.
- ▌ Sc Iac · ersinkocInfrastructure-as-Code security scanning — Dockerfile, Kubernetes, Terraform, and GitHub Actions misconfigurations
- ▌ Sc JWT · ersinkocJWT implementation flaw detection — algorithm confusion, weak secrets, missing validation, and storage issues
- ▌ Sc Rce · ersinkocRemote Code Execution detection via eval, exec, dynamic code loading, and code injection vectors
- ▌ Sc Xss · ersinkocCross-Site Scripting detection for Reflected, Stored, and DOM-based XSS across all frameworks
- ▌ Sc Xxe · ersinkocXML External Entity injection detection across all XML parsers and document formats
- ▌ Sc Auth · ersinkocAuthentication flaw detection — weak passwords, broken auth, credential stuffing, and bypass vectors
- ▌ Sc Cmdi · ersinkocOS Command Injection detection in shell execution, subprocess calls, and process spawning
- ▌ Sc Cors · ersinkocCORS misconfiguration detection — wildcard origin, reflected origin, null origin, and credential leaks
- ▌ Sc Csrf · ersinkocCross-Site Request Forgery detection — missing tokens, SameSite misconfiguration, and CORS-CSRF interaction
- ▌
- ▌ Sc Sqli · ersinkocSQL Injection detection across all variants — classic, blind, time-based, second-order, and UNION-based
- ▌ Sc Ssrf · ersinkocServer-Side Request Forgery detection — URL fetching with user input, DNS rebinding, cloud metadata access
- ▌
- ▌ Sc Authz · ersinkocAuthorization flaw detection — IDOR, broken access control, horizontal and vertical privilege issues
- ▌ Sc CI CD · ersinkoc bundleCI/CD pipeline security — GitHub Actions injection, secret exposure, untrusted actions, and artifact poisoning
- ▌
- ▌ Sc Crypto · ersinkocCryptography misuse detection — weak algorithms, ECB mode, static IVs, weak PRNG, and key management flaws
- ▌ Sc Docker · ersinkoc bundleDocker-specific security checks — image hardening, secrets in layers, compose security, and runtime configuration
- ▌
- ▌ Sc Report · ersinkocFinal consolidated security assessment report generator with CVSS severity and remediation roadmap
- ▌ Sc GRAPHQL · ersinkocGraphQL injection, introspection abuse, query complexity attacks, and authorization bypass detection
- ▌
- ▌ Sc Secrets · ersinkocHardcoded secrets, API keys, tokens, credentials, and private key detection in source code
- ▌ Sc Session · ersinkocSession management flaw detection — fixation, hijacking, cookie misconfiguration, and lifecycle issues
- ▌
- ▌
- ▌
- ▌
- ▌ Sc Websocket · ersinkocWebSocket security flaw detection — missing origin validation, authentication bypass, and message injection
- ▌ Sc Diff Report · ersinkocIncremental security scan for changed files only — optimized for PR and commit-level reviews
- ▌ Sc File Upload · ersinkocInsecure file upload detection — unrestricted types, MIME mismatch, polyglot files, and webshell upload
- ▌
- ▌
- ▌ Sc API Security · ersinkoc bundleREST, GraphQL, and gRPC API security audit — authentication, authorization, data exposure, and configuration
- ▌ Sc Clickjacking · ersinkocClickjacking and UI redressing detection — missing frame protection headers and CSP frame-ancestors
- ▌ Sc Orchestrator · ersinkocMaster orchestration skill that coordinates the entire 4-phase security scanning pipeline
- ▌ Sc Data Exposure · ersinkocSensitive data exposure detection — PII leaks, verbose errors, debug mode, and information disclosure
- ▌ Sc Open Redirect · ersinkocOpen redirect detection — unvalidated redirect URLs, protocol-relative bypasses, and URI scheme abuse
- ▌ Sc Rate Limiting · ersinkocMissing rate limiting and application-level DoS vector detection — ReDoS, query complexity, resource exhaustion
- ▌ Sc Business Logic · ersinkocBusiness logic flaw detection — price manipulation, workflow bypass, race conditions, and abuse vectors
- ▌ Sc Path Traversal · ersinkocPath traversal and directory traversal detection — LFI, RFI, zip slip, and symlink attacks
- ▌ Sc Race Condition · ersinkocRace condition and TOCTOU detection — database races, file system races, double-spend, and atomicity failures
- ▌ Sc Deserialization · ersinkocInsecure deserialization detection across all serialization formats and languages
- ▌
- ▌ Sc Mass Assignment · ersinkocMass assignment and over-posting detection — unfiltered request body binding to data models
- ▌ Sc Dependency Audit · ersinkocSupply chain and dependency security analysis across all package ecosystems
- ▌ Sc Header Injection · ersinkocHTTP Header Injection and Response Splitting detection via CRLF injection in headers
- ▌ Sc Privilege Escalation · ersinkocPrivilege escalation vector detection — role manipulation, admin bypass, and RBAC circumvention
- ▌ Project Architect · ersinkoc bundleDocumentation-first project planning that produces implementation-ready blueprints and single-shot coding agent prompts. Generates 4 interconnected docs — SPECIFICATION.md, IMPLEMENTATION.md, TASKS.md, BRANDING.md — plus a self-contained PROMPT.md for autonomous execution by any coding agent. Includes interactive tech stack selection, design pattern recommendations, and architecture decisions with trade-off analysis. Trigger when user wants to: plan a project, create specs, architect a system, break work into tasks, choose a tech stack, get design pattern advice, generate a coding agent prompt, or do documentation-first development. Phrases: "plan my project", "spec this out", "architect", "help me plan", "what stack should I use", "generate a prompt", "break this into tasks", "project docs", "I want to build X".