naieum
- 20 skills
- 0 followers
- 9 hours ago last updated
- ▌ Snitch Security · naieum bundleAudit AI-written code for security vulnerabilities, with evidence-based findings (file:line + CWE/OWASP mapping) and false-positive prevention. Use when the user asks for a security audit, code review for vulnerabilities, OWASP scan, SARIF output, pre-deploy security check, post-LLM code review, or compliance evidence (HIPAA, SOC 2, PCI-DSS, GDPR, CCPA, SOX). Do NOT use for general code review unrelated to security, license auditing, dependency-version bumps, a voice agent's call path — telephony webhooks, speech injection, dial and transfer control, recordings and consent (use snitch-voice), or paid-ads / pixel readiness (use snitch-adsready) or SEO (use snitch-marketing).
- ▌ Snitch UX · naieum bundleApply behavioral-design / UX-psychology and usability principles when designing, building, or reviewing any user-facing interface — landing pages, onboarding, sign-up, paywalls & pricing, forms, checkout, dashboards, empty states, navigation, mobile nav — or when asked to improve conversion, retention, engagement, reduce drop-off, 'make this clearer / feel premium / more polished', or write UI copy, CTAs, and microcopy, or judge the on-page hero, one-liner, tagline, and value prop against the visitor's decision path. Encodes two lenses — clarity (self-evident pages, scanning, conventions) and persuasion (defaults, anchoring, social proof, loss aversion, friction reduction, visual hierarchy) — as checkable moves, behind a blocking ethics gate that reports dark patterns instead of optimising them. The split across siblings is what the finding is judged against: ux owns what is evaluated against the user's decision path. Do NOT use for security review (use snitch-security), SEO / marketing audits (use snitch-mar
- ▌ Snitch Ada · naieum bundleAudit a site against WCAG 2.2 Level AA conformance, the legal exposure a failure carries, and whether the product is built to serve people in their own language and script — evidence-based findings with file:line or URL+selector per finding, and a coverage block that lists every A/AA criterion as Finding, Pass or Skip. Use when the user asks for an accessibility audit, a11y review, WCAG 2.2 AA conformance review, ADA compliance check, ADA Title II or Title III exposure, Section 508 review, VPAT / ACR prep, European Accessibility Act (EAA) readiness, AODA or UK PSBAR check, accessibility statement review, accessibility overlay widget review, screen reader / keyboard / focus order / color contrast / alt text / captions / target size checks, or an i18n readiness audit — internationalization and localization readiness, RTL and bidi review, hardcoded user-facing strings, ICU plurals, locale date/number/currency formatting, translation catalog completeness, language switcher and locale routing. Do NOT use for SEO s
- ▌ Snitch AWS · naieum bundleAWS security + readiness skill. Thin tools for the agent to compose. Detects the user's project, audits account/IAM/S3/EC2/VPC/RDS/Lambda/CloudFront/Route53/CloudTrail/GuardDuty/SecurityHub/Config/KMS posture across services, applies idempotent hardening, and produces honest migration / scaling guidance. Triggers on audit my AWS account, harden AWS, AWS security audit, secure my AWS infrastructure, AWS WAF setup, AWS IAM audit, AWS scaling readiness, AWS incident response, AWS best practices, AWS hardening, should I move to AWS, migrate to AWS, AWS DNSSEC, AWS S3 public bucket, AWS CloudTrail audit, AWS GuardDuty.
- ▌ Snitch Cmo · naieum bundleGenerate a checked-in marketing foundation (product information, positioning with a scored audience wedge and a pricing-strategy read, competitor analysis, brand voice, content strategy, channel plan) from a product's actual source or site, then draft channel-ready marketing content and campaign collateral driven by those docs or an approved brief for a bounded draft — blog posts, X/LinkedIn posts, Reddit/Hacker News posts, launch and PR sequences, creator-outreach shortlists, sponsorship plans, UGC video briefs, lead generators, sales emails, pitch decks, the About-page story, and company/product/feature names. Every product claim traces to file:line or a fetched URL; every draft identifies the foundation or approved brief behind its angle, voice, and claims. Triggers on "act as my CMO", "build me a marketing strategy", "write my positioning doc", "who should we target", "which segment should we lead with", "is our pricing strategy right", "brand voice guide", "name this product / feature", "write our About
- ▌ Snitch Azure · naieum bundleAzure security + readiness skill. Thin tools for the agent to compose. Detects the user's project, audits subscription/Entra/RBAC/Defender/Sentinel/storage/keyvault/compute/database/network posture, applies free + plan-tier hardening, and produces honest migration / scaling guidance. Triggers on audit my Azure subscription, harden Azure, Azure security audit, secure my Azure resources, should I move to Azure, Azure RBAC audit, Defender for Cloud setup, Azure scaling readiness, Azure incident response.
- ▌ Snitch Flyio · naieum bundleFly.io security + readiness skill. Thin tools for the agent to compose. Detects the user's project, audits org/apps/machines/volumes/postgres/redis/secrets/services/network/tokens posture, applies idempotent hardening, and produces honest migration / scaling guidance. Triggers on audit my Fly app, harden Fly.io, secure my Fly machines, Fly secrets review, should I move to Fly, Fly Postgres audit, Fly scaling readiness, Fly incident response, Fly best practices, Fly WireGuard audit.
- ▌ Snitch Voice · naieum bundleAudit an AI voice agent — a phone, SIP, or in-app speech agent built on an LLM — for what a caller can make it do, spend, or say, with evidence-based findings (file:line plus a traced call-path hop per finding) and a coverage block that lists every hop of the call path as Finding, Pass or Skip. Use when the user asks for a voice agent security audit, voice bot security review, phone agent audit, call-center AI review, "can a caller prompt-inject my voice agent", "can it be made to transfer money / dial out / send SMS", voice agent toll-fraud or denial-of-wallet check, telephony webhook signature review, media-stream or realtime session auth review, API keys in the voice client, ephemeral token minting review, caller-ID or voice-cloning trust review, call recording and transcript storage review, PCI or card-number redaction on calls, recording-consent or AI-disclosure or robocall-rule readiness, HIPAA or BIPA exposure for a voice bot, or a pre-launch check on a phone line. Works across telephony carriers, host
- ▌ Snitch Router · naieum bundleAsk which Snitch skill or flow fits your situation. A router over the whole family.
- ▌ Snitch Vercel · naieum bundleVercel security + readiness skill. Thin tools for the agent to compose. Detects the user's project, audits account/team/project/env/domains/deployments/protection/functions/middleware/storage/edge-config/log-drains/analytics/cost posture, applies idempotent hardening, and produces honest migration / scaling guidance. Triggers on audit my Vercel deployment, harden Vercel, Vercel security audit, secure Vercel project, Vercel deployment protection, Vercel env audit, should I move to Vercel, Vercel scaling readiness, Vercel incident response, Vercel custom domain TLS.
- ▌ Snitch Railway · naieum bundleRailway security + readiness skill. Thin tools for the agent to compose. Detects the user's project, audits workspace/project/services/env/volumes/databases/tokens/domains/tcp-proxies/logs/cost posture, applies idempotent hardening, and produces honest migration / scaling guidance. Triggers on audit my Railway project, harden Railway, secure Railway services, Railway env audit, should I move to Railway, Railway scaling readiness, Railway incident response.
- ▌ Snitch Adsready · naieum bundleAudit and set up paid-media ad readiness across Google, Meta, Microsoft / Bing, LinkedIn, TikTok, X, Pinterest, Reddit, Snapchat, and Apple Search Ads. Thin tools for the agent to compose. Audits pixel coverage, conversion tracking, Consent Mode v2, ads.txt, ad-crawler access, Core Web Vitals as a Quality Score input, the CSP / security-header changes a pixel needs, and the Product/Offer markup a shopping feed reads; offers idempotent fixes; recommends external tools (CMP, server-side GTM, CAPI helpers, Lighthouse and CWV monitoring). Triggers on audit my ads readiness, is my Meta Pixel installed, set up Google Ads conversion tracking, is my consent mode v2 wired up, should I add LinkedIn tracking, ads.txt audit, Core Web Vitals for ads, audit my Google/Meta/TikTok pixel, verify tag firing, what tools do I need for ads, is my site ready for ChatGPT ads. Do NOT use for security review (use snitch-security), SEO / marketing audits, SEO structured data, llms.txt / AI search, hreflang, local listings (use snitch-
- ▌ Snitch Devready · naieum bundleBootstrap a repository for effective AI-assisted development. Auto-detects whether the repo is greenfield (no code yet), thin-greenfield (scaffold only), or brownfield (real code), then leaves behind the checked-in artifacts that make an AI coding agent smarter for the whole team: a short CLAUDE.md, slash commands, a screenshot/test feedback loop, an .mcp.json, a permissions allowlist — and a two-tier coding standard (enforced vs advisory) wired to the repo's real gates (linters, hooks, CI) so the agent's code is machine-checked, not just advised. Use when asked to make this repo Claude-ready / dev-ready, onboard a codebase for Claude Code, set up Claude Code for a team/project, bootstrap a new project for AI development, set up coding standards for the agent, or wire lint/test enforcement for AI-written code. Do NOT use for product or marketing decisions (use snitch-blueprint) or for writing the app itself.
- ▌ Snitch Blueprint · naieum bundleMake the load-bearing product decisions BEFORE and WHILE building, instead of discovering them in an audit afterward. Detects what the workspace already answers, interviews the user for only the gaps, classifies the project by how it is bought (local service business, SaaS / web app, e-commerce, content site, mobile app, CLI / library / API), then writes a checked-in BLUEPRINT.md — audience, the one conversion action, surface inventory, build order, per-surface specs — that the build follows and that snitch-marketing and snitch-ux later read to report tensions against; snitch-security audits the code directly. Triggers on "help me build this right from the start", "what should I build first", "set up a new site/app for a <business>", "plan this build", "blueprint this project", "I'm building a site for a local business / a store / an app", "greenfield marketing/UX decisions", "which pages do I need", "make the right choices while we code". Do NOT use for grading an existing site (use snitch-marketing / snitch
- ▌ Snitch Docwriter · naieum bundleWrite or rewrite technical prose — docs, READMEs, PR descriptions, commit messages, error messages, release notes, runbooks, API docs, code comments, reports — in a controlled technical style, and score existing prose with a deterministic anti-slop linter (violations per 100 words). Triggers on make this not sound like AI, remove AI slop, plain English, simplify these docs, tighten this README / PR description, controlled language, rewrite this error message, does my writing sound like AI. Do NOT use for marketing copy, brand voice, or off-site channel content (use snitch-cmo), one page's persuasion structure (use snitch-focusedcopy), or UI microcopy, CTAs, and the on-page hero, one-liner or tagline (use snitch-ux). Those systems keep voice under mechanical discipline. This skill strips voice on purpose. Never rewrite code, identifiers, or command syntax.
- ▌ Snitch Marketing · naieum bundleAudit a site's SEO and marketing with evidence-based findings — reads site source or crawls a URL and reports what a top-tier consultancy would catch, with file:line or URL+selector evidence per finding. Use when the user asks for an SEO audit, marketing audit, technical SEO review, on-page audit, AI search optimization / citation audit (GEO), llms.txt review, schema or structured-data audit, Open Graph audit, Core Web Vitals contributors review (render-blocking, image weight, font loading, bundle weight, CLS; true field CWV via optional free CrUX/PSI when configured), brand SERP audit, traffic-drop diagnosis, post-deploy SEO regression check, competitor SEO analysis, conversion audit, or a lighthouse/ahrefs/semrush/screaming-frog alternative. Do NOT use for paid-ads, pixel, or consent-mode readiness (use snitch-adsready), accessibility conformance, ADA / Section 508 / EAA exposure, or i18n readiness (use snitch-ada), security review (use snitch-security), UX / interface critique judged against the user's dec
- ▌ Snitch Cloudflare · naieum bundleCloudflare security + readiness skill. Thin tools for the agent to compose. Detects the user's project, audits zone/account/Workers/Pages/Tunnel/Access posture, applies free + plan-tier hardening, and produces honest migration / scaling guidance. Triggers on harden Cloudflare, secure my Cloudflare site, Cloudflare audit, Cloudflare best practices, Cloudflare WAF / DNSSEC / HSTS / AOP setup, migrate to Cloudflare, Cloudflare scaling readiness, under attack mode, Cloudflare incident response, should I move to Cloudflare.
- ▌ Snitch Storeready · naieum bundleAudit whether a mobile app is ready for Apple App Store and Google Play submission — review-guideline compliance, privacy manifests and Data safety alignment, target SDK / API floors, permissions and store declarations, metadata and asset rules, monetization and billing rules, and release-track requirements — with file:line evidence for everything checkable from code and an interactive checklist for store-console items. Triggers on is my app ready for the App Store, app store readiness audit, why was my app rejected, prepare for Play Store submission, pre-submission checklist, App Review guidelines check, Play policy check, privacy nutrition labels, privacy manifest check, data safety form help, target API level check, will this pass review, App Store rejection, Google Play rejection, can I put my web app in the App Store, turn my website into an app, publish my PWA to the Play Store, Capacitor or React Native for the stores. For a web app with no native target it does not stop — it assesses store feasibility
- ▌ Snitch Focusedcopy · naieum bundleStructure persuasive on-page copy — landing pages, pricing pages, sales/waitlist pages, cold emails, ad or VSL scripts — around the CLOSER framework (Clarify why they're here, Label the right visitor, Overview the pain, Sell the outcome before the mechanism, Explain objections, Reinforce the decision), a widely taught six-stage sales-call structure adapted to written pages. Audits an existing page's section order and stage coverage, then reorders sections and tightens copy to close gaps, verifying every claim against the actual product before it is written. Triggers on "structure this page like a sales call", "apply the CLOSER framework", "this page isn't converting", "reorder these sections for persuasion", "who is this landing page for", "handle objections on this page", "make this pitch land", "sell the outcome not the mechanism". Do NOT use for SEO / technical marketing audits (use snitch-marketing), broader UX / interaction / dark-pattern review (use snitch-ux), plain technical prose (use snitch-docwrite
- ▌ Snitch Digitalocean · naieum bundleDigitalOcean security + readiness skill. Thin tools for the agent to compose. Detects the user's project, audits account/Droplet/Database/Spaces/App-Platform/DOKS/LB/Firewall/Registry/Functions/VPC/DNS/Monitoring posture, applies idempotent hardening, and produces honest migration / scaling guidance. Triggers on audit my DigitalOcean account, harden DigitalOcean, DO security audit, secure my Droplets, secure DigitalOcean Spaces, should I move to DigitalOcean, DOKS audit, DO scaling readiness, DigitalOcean best practices, DigitalOcean firewall, DigitalOcean managed databases hardening, DigitalOcean App Platform audit.