← all publishers

n-shadloo

@n-shadloo source repo

2 published skills

  1. Secure Code Auditor · n-shadloo bundle
    Backend security auditor for Django and DRF on an OWASP Top 10 (2025), API Security Top 10 (2023), and ASVS 5.0 foundation. Use when backend code is written or reviewed and touches authentication, sessions, cookies, JWT, OAuth2/OIDC, API keys, password hashing, permissions, access control, IDOR, SSRF, path traversal, open redirect, impersonation, SQL/command/template injection, LDAP, row-level security, encrypted columns, NoSQL, Redis, file uploads, S3, serializers, rate limiting, CSRF/CORS, OpenAPI schema, GraphQL, Django Ninja, gRPC, AI agents, MCP tools, secrets, payments, webhooks, Celery, Django tasks, race conditions, ReDoS, caching, deserialization, async/ASGI, WebSockets, audit logging, erasure, retention, personal data, migrations, JWKS, mutual TLS, SECRET_KEY, SBOM, X-Forwarded-For, SPF/DKIM/DMARC, or deployment config, even if "security" is never used. Review-time returns prioritized findings with fixes; write-time applies secure defaults. Django/DRF-first; general layer suits any stack.
    0 installs
  2. Git Authoring · n-shadloo bundle
    Authors and executes git work end to end — Conventional Commits messages, pull-request content, release notes, and pull-request review, plus the repository operations an engineer runs daily: branching, rebasing, squashing, cherry-picking, reverting, merge-conflict resolution, stashes, tags, remotes, and recovery through the reflog. Use whenever the user is about to commit, asks for a commit message, exact commands, or file selection, mentions staged changes, asks for a pull-request title or description, a release note or a changelog entry, asks the agent to stage, commit, and push, asks for help reviewing, approving, rejecting, or merging someone else's pull request, and whenever the user asks how to branch, rebase, squash, split, revert, cherry-pick, resolve a conflict, undo or amend a commit, move work between branches, recover lost commits, or clean up history before review. Adds co-author, sign-off, or AI or agent attribution only when the user asks for it in the session, and never by default.
    0 installs