oyi77
- 1.3k skills
- 0 followers
- 10 repo stars
- 2 weeks ago last updated
- ▌ Building Detection Rule With Splunk Spl · oyi77Use when build effective detection rules using Splunk Search Processing Language (SPL) correlation searches to identify security threats in SOC environments. Use when building effective detection rules using splunk search processing language (spl).
- ▌ Building Patch Tuesday Response Process · oyi77Use when establish a structured operational process to triage, test, and deploy Microsoft Patch Tuesday security updates within risk-based remediation SLAs. Use when working with building patch tuesday response process.
- ▌ Detecting Azure Service Principal Abuse · oyi77Use when detect and investigate Azure service principal abuse including privilege escalation, credential compromise, admin consent bypass, and unauthorized enumeration in Microsoft Entra ID environments. Use when detecting and investigate azure service principal abuse including privilege escalation,.
- ▌ Detecting Compromised Cloud Credentials · oyi77Use when detecting compromised cloud credentials across AWS, Azure, and GCP by analyzing anomalous API activity, impossible travel patterns, unauthorized resource provisioning, and credential abuse indicators using GuardDuty, Defender for Identity, and SCC Event Threat Detection. . Use when working with detecting compromised cloud credentials.
- ▌ Detecting Credential Dumping Techniques · oyi77Use when detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft using Sysmon Event ID 10, Windows Security logs, and SIEM correlation rules. Use when detecting lsass credential dumping, sam database extraction, and ntds.dit theft.
- ▌ Detecting Email Forwarding Rules Attack · oyi77Use when detect malicious email forwarding rules created by adversaries to maintain persistent access to email communications for intelligence collection and BEC attacks. Use when detecting malicious email forwarding rules created by adversaries to maintain.
- ▌ Detecting Privilege Escalation Attempts · oyi77Use when detect privilege escalation attempts including token manipulation, UAC bypass, unquoted service paths, kernel exploits, and sudo/doas abuse across Windows and Linux. Use when detecting privilege escalation attempts including token manipulation, uac bypass, unquoted.
- ▌ Detecting S3 Data Exfiltration Attempts · oyi77Use when detecting data exfiltration attempts from AWS S3 buckets by analyzing CloudTrail S3 data events, VPC Flow Logs, GuardDuty findings, Amazon Macie alerts, and S3 access patterns to identify unauthorized bulk downloads and cross-account data transfers. . Use when working with detecting s3 data exfiltration attempts.
- ▌ Detecting Serverless Function Injection · oyi77Use when detects and prevents code injection attacks targeting serverless functions (AWS Lambda, Azure Functions, Google Cloud Functions) through event source poisoning, malicious layer injection, runtime command execution, and IAM privilege escalation via function modification. The analyst combines static analysis of function code, CloudTrail event correlation, runtime behavior monitoring, and IAM policy auditing to identify injection vectors across the expanded serverless attack surface inc...
- ▌ Exploiting Constrained Delegation Abuse · oyi77Use when exploit Kerberos Constrained Delegation misconfigurations in Active Directory to impersonate privileged users via S4U2self and S4U2proxy extensions for lateral movement and privilege escalation. Use when exploiting kerberos constrained delegation misconfigurations in active directory to impersonate.
- ▌ Exploiting Mass Assignment In REST Apis · oyi77Use when discover and exploit mass assignment vulnerabilities in REST APIs to escalate privileges, modify restricted fields, and bypass authorization controls by injecting unexpected parameters in API requests. Use when working with exploiting mass assignment in rest apis.
- ▌ Extracting Credentials From Memory Dump · oyi77Use when extract cached credentials, password hashes, Kerberos tickets, and authentication tokens from memory dumps using Volatility and Mimikatz for forensic investigation. Use when working with extracting credentials from memory dump.
- ▌ Extracting Memory Artifacts With Rekall · oyi77Use when uses Rekall memory forensics framework to analyze memory dumps for process hollowing, injected code via VAD anomalies, hidden processes, and rootkit detection. Applies plugins like pslist, psscan, vadinfo, malfind, and dlllist to extract forensic artifacts from Windows memory images. Use during incident response memory analysis. . Use when working with extracting memory artifacts with rekall.
- ▌ Extracting Windows Event Logs Artifacts · oyi77Use when extract, parse, and analyze Windows Event Logs (EVTX) using Chainsaw, Hayabusa, and EvtxECmd to detect lateral movement, persistence, and privilege escalation. Use when working with extracting windows event logs artifacts.
- ▌ Hunting For Unusual Network Connections · oyi77Use when hunt for unusual network connections by analyzing outbound traffic patterns, rare destinations, non-standard ports, and anomalous connection frequencies from endpoints. Use when hunting for unusual network connections by analyzing outbound traffic patterns,.
- ▌ Implementing AWS Nitro Enclave Security · oyi77Use when implements AWS Nitro Enclave-based confidential computing environments with cryptographic attestation, KMS policy integration using PCR-based condition keys, and secure vsock communication channels. The practitioner builds enclave images, configures attestation-aware KMS policies, validates attestation documents against the AWS Nitro PKI root of trust, and establishes isolated computation pipelines for processing sensitive data such as PII, cryptographic keys, and healthcare records.
- ▌ Implementing Code Signing For Artifacts · oyi77Use when this skill covers implementing code signing for build artifacts to ensure integrity and authenticity throughout the software supply chain. It addresses signing binaries, packages, and containers using GPG, Sigstore, and platform-specific signing tools, establishing trust chains, and verifying signatures in deployment pipelines.
- ▌ Implementing Network Traffic Baselining · oyi77Use when build network traffic baselines from NetFlow/IPFIX data using Python pandas for statistical analysis, z-score anomaly detection, and hourly/daily traffic pattern profiling. Use when building network traffic baselines from netflow/ipfix data using python pandas.
- ▌ Implementing Ransomware Backup Strategy · oyi77Use when designs and implements a ransomware-resilient backup strategy following the 3-2-1-1-0 methodology (3 copies, 2 media types, 1 offsite, 1 immutable/air-gapped, 0 errors on restore verification). Configures backup schedules aligned to RPO/RTO requirements, implements backup credential isolation to prevent ransomware from compromising backup infrastructure, and establishes automated restore testing.
- ▌ Implementing Soar Playbook For Phishing · oyi77Use when automating phishing incident response using Splunk SOAR REST API to create containers, add artifacts, and trigger playbooks
- ▌ Investigating Insider Threat Indicators · oyi77Use when investigates insider threat indicators including data exfiltration attempts, unauthorized access patterns, policy violations, and pre-departure behaviors using SIEM analytics, DLP alerts, and HR data correlation. Use when SOC teams receive insider threat referrals from HR, detect anomalous data movement by employees, or need to build investigation timelines for potential insider threats.
- ▌ Performing Binary Exploitation Analysis · oyi77Use when analyzing binary exploitation techniques including buffer overflows and ROP chains using pwntools Python library. Covers checksec analysis, gadget discovery with ROPgadget, and exploit development for CTF and authorized security assessments.
- ▌ Performing Disk Forensics Investigation · oyi77Use when conducts disk forensics investigations using forensic imaging, file system analysis, artifact recovery, and timeline reconstruction to support incident response cases. Utilizes tools such as FTK Imager, Autopsy, and The Sleuth Kit for evidence acquisition, deleted file recovery, and artifact examination. Activates for requests involving disk forensics, hard drive analysis, forensic imaging, file recovery, evidence acquisition, or digital forensic investigation. '.
- ▌ Performing GRAPHQL Introspection Attack · oyi77Use when performs GraphQL introspection attacks to extract the full API schema including types, queries, mutations, subscriptions, and field definitions from GraphQL endpoints. The tester uses introspection queries to map the attack surface, identifies sensitive fields and mutations, tests for query depth and complexity limits, and exploits GraphQL-specific vulnerabilities including batching attacks, alias-based brute force, and nested query DoS.
- ▌ Performing Insider Threat Investigation · oyi77Use when investigates insider threat incidents involving employees, contractors, or trusted partners who misuse authorized access to steal data, sabotage systems, or violate security policies. Combines digital forensics, user behavior analytics, and HR/legal coordination to build an evidence-based case. Activates for requests involving insider threat investigation, employee data theft, privilege misuse, user behavior anomaly, or internal threat detection. '.
- ▌ Performing Nist Csf Maturity Assessment · oyi77Use when assessing organizational cybersecurity maturity against NIST CSF framework. Evaluate identify, protect, detect, respond, and recover functions with actionable gap analysis. The NIST Cybersecurity Framework (CSF) 2.0, released in February 2024, provides a comprehensive taxonomy for managing cybersecurity risk through six core Functions - Govern, Identify, Protect, Detect, Respond, and Recover.
- ▌ Performing Privileged Account Discovery · oyi77Use when discover and inventory all privileged accounts across enterprise infrastructure including domain admins, local admins, service accounts, database admins, cloud IAM roles, and application admin account. Use when working with performing privileged account discovery.
- ▌ Performing Ransomware Tabletop Exercise · oyi77Use when plans and facilitates tabletop exercises simulating ransomware incidents to test organizational readiness, decision-making, and communication procedures. Designs realistic scenarios based on current ransomware threat actors (LockBit, ALPHV/BlackCat, Cl0p), injects covering double extortion, backup destruction, and regulatory notification requirements. Evaluates participant responses against NIST CSF and CISA guidelines. Use when working with performing ransomware tabletop exercise.
- ▌ Performing Soc2 Type2 Audit Preparation · oyi77Use when automating SOC 2 Type II audit preparation including gap assessment against AICPA Trust Services Criteria (CC1-CC9), evidence collection from cloud providers and identity systems, control testing validation, remediation tracking, and continuous compliance monitoring. Covers all five TSC categories (Security, Availability, Processing Integrity, Confidentiality, Privacy) with automated evidence gathering from AWS, Azure, GCP, Okta, GitHub, and Jira.
- ▌ Reverse Engineering Malware With Ghidra · oyi77Use when reverse engineers malware binaries using NSA's Ghidra disassembler and decompiler to understand internal logic, cryptographic routines, C2 protocols, and evasion techniques at the assembly and pseudo-C level. Activates for requests involving malware reverse engineering, disassembly analysis, decompilation, binary analysis, or understanding malware internals. . Use when working with reverse engineering malware with ghidra.
- ▌ Securing Container Registry With Harbor · oyi77Use when harbor is an open-source container registry that provides security features including vulnerability scanning (integrated Trivy), image signing (Notary/Cosign), RBAC, content trust policies, replicatio. Use when working with securing container registry with harbor.
- ▌ Analyzing Apt Group With Mitre Navigator · oyi77Use when analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps of adversary TTPs for detection gap analysis and threat-informed defense. Use when analyzeing advanced persistent threat (apt) group techniques using mitre att&ck.
- ▌ Analyzing Linux Audit Logs For Intrusion · oyi77Use when using the Linux Audit framework (auditd) with ausearch and aureport utilities to detect intrusion attempts, unauthorized access, privilege escalation, and suspicious system activity. Covers audit rule configuration, log querying, timeline reconstruction, and integration with SIEM platforms. Activates for requests involving auditd analysis, Linux audit log investigation, ausearch queries, aureport summaries, or host-based intrusion detection on Linux.
- ▌ Analyzing Network Traffic With Wireshark · oyi77Use when captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations on authorized network segments. . Use when working with analyzing network traffic with wireshark.
- ▌ Analyzing Supply Chain Malware Artifacts · oyi77Use when investigate supply chain attack artifacts including trojanized software updates, compromised build pipelines, and sideloaded dependencies to identify intrusion vectors and scope of compromise. Use when working with analyzing supply chain malware artifacts.
- ▌ Analyzing Windows Registry For Artifacts · oyi77Use when extract and analyze Windows Registry hives to uncover user activity, installed software, autostart entries, and evidence of system compromise. Use when working with analyzing windows registry for artifacts.
- ▌ Building Threat Actor Profile From Osint · oyi77Use when build comprehensive threat actor profiles using open-source intelligence (OSINT) techniques to document adversary motivations, capabilities, infrastructure, and TTPs for proactive defense. Use when building comprehensive threat actor profiles using open-source intelligence (osint) techniques.
- ▌ Building Vulnerability Scanning Workflow · oyi77Use when builds a structured vulnerability scanning workflow using tools like Nessus, Qualys, and OpenVAS to discover, prioritize, and track remediation of security vulnerabilities across infrastructure. Use when SOC teams need to establish recurring vulnerability assessment processes, integrate scan results with SIEM alerting, and build remediation tracking dashboards.
- ▌ Collecting Threat Intelligence With Misp · oyi77Use when mISP (Malware Information Sharing Platform) is an open-source threat intelligence platform for gathering, sharing, storing, and correlating Indicators of Compromise (IOCs) of targeted attacks, threat. Use when working with collecting threat intelligence with misp.
- ▌ Conducting Post Incident Lessons Learned · oyi77Use when facilitate structured post-incident reviews to identify root causes, document what worked and failed, and produce actionable recommendations to improve future incident response. Use when working with conducting post incident lessons learned.
- ▌ Configuring AWS Verified Access For Ztna · oyi77Use when configure AWS Verified Access to provide VPN-less zero trust network access to internal applications using identity and device posture verification with Cedar policy language. Use when configureing aws verified access to provide vpn-less zero trust network.
- ▌ Detecting Ransomware Encryption Behavior · oyi77Use when detects ransomware encryption activity in real time using entropy analysis, file system I/O monitoring, and behavioral heuristics. Identifies mass file modification patterns, abnormal entropy spikes in written data, and suspicious process behavior characteristic of ransomware encryption routines. Activates for requests involving ransomware behavioral detection, entropy-based file monitoring, I/O anomaly detection, or real-time encryption activity alerting. '.
- ▌ Stripe Revenue Bot · oyi77Use when automating posting your Stripe revenue milestones to Twitter/X. Build trust through transparency, attract customers, and join the "build in public" movement.
- ▌ Twitter Automation · oyi77Use when automating Twitter/X presence with AI-powered posting, engagement, and growth. Schedule posts, auto-reply, track analytics, and build audience on autopilot.
- ▌ Persuasion Influence · oyi77Use when apply Cialdini's 6 principles of influence ethically in business contexts. Use when pitching, selling, or driving adoption without formal authority.
- ▌ Payment Invoicing · oyi77Use when processing payments and generating invoices using Indonesian payment gateways (TriPay, LYNK.ID, Midtrans). Create payment links, track transactions, and automate invoicing for 1-man company revenue collection.
- ▌ Continuous Learning · oyi77Use when transform session insights into actionable skills with confidence-weighted scoring — captures patterns, analyzes outcomes, and integrates learnings to improve agent performance. Use when working with continuous learning.
- ▌ Gate Info Riskcheck · oyi77Use when risk-score a token — contract verification, honeypot heuristics, buy/sell tax, and open-source status via public explorers (Etherscan and equivalents). Use when working with token risk check.
- ▌ Social Intelligence · oyi77Use when cross-platform social media intelligence gathering using Agent Reach. Research trends, sentiment, competitive intel, and user insights from Twitter, Reddit, YouTube, XiaoHongShu across 35+ platforms. Use when researching social proof, market sentiment, viral content patterns, or competitive positioning.
- ▌ Polymarket Fast Loop · oyi77Use when trade Polymarket BTC 5-minute and 15-minute fast markets using CEX price momentum signals via Simmer API. Default signal is Binance BTC/USDT klines. Use when user wants to trade sprint/fast markets, automate short-term crypto trading, or use CEX momentum as a Polymarket signal.
- ▌ Code Research · oyi77Use when produce structured understanding of unfamiliar codebases — architecture, data flows, dependencies, and conventions. Use when joining a new project, tracing feature implementations, or mapping system architecture.
- ▌ Comment Reply Manager · oyi77Use when monitor TikTok/Instagram comments, classify sentiment, auto-reply with FAQ answers, and DM high-intent commenters with LYNK affiliate links to convert engagement into sales. Use when monitoring tiktok/instagram comments, classify sentiment, auto-reply with faq answers, and.
- ▌ Ultra Realistic Media · oyi77Use when uLTRA REALISTIC MEDIA GENERATION - TRAINING SKILL. Use when relevant to this domain.
- ▌ Viral Content Creator · oyi77Use when generating 50+ video variations from a single product image across TikTok, Instagram, Facebook, Twitter, and YouTube with hook-based A/B testing, viral score prediction, and autopilot scheduling.
- ▌ Viral Research Engine · oyi77Use when researching trending topics, generating viral hooks, finding content gaps, analyzing competitors, and getting hashtag recommendations for Indonesian short-form video creators on TikTok, Reels, and Shorts.
- ▌ Berkahkarya Orchestrator · oyi77Use when orchestrate multi-skill workflows by routing tasks to the right agents and coordinating cross-platform operations.
- ▌ Runtime Self Improvement · oyi77Use when automatically improve OpenClaw and 1ai-skills at runtime. Analyze performance, detect gaps, enhance skills, and self-optimize during operation. Use when working with runtime self improvement.
- ▌ Go Rust Reverse · oyi77Use when reverse engineer Go and Rust binaries: recognize the language runtime from go.buildid, runtime symbols, or panic strings, recover function tables and names from pclntab, and rebuild symbols with GoReSym or redress before Ghidra/IDA analysis. Use when analyzing stripped Go/Rust malware, ELF/PE binaries with non-standard symbol layouts, or runtime-library-heavy samples.
- ▌ Social Engineer · oyi77Use when social engineering and phishing for authorized security assessments. Use when testing human attack vectors, conducting phishing simulations, or assessing organizational security awareness.
- ▌ Agent Arena Skill · oyi77Use when skill: agent-arena-skill. See SKILL.md body for details. Use when this domain is relevant.
- ▌ Appwrite Patterns · oyi77Use when appwrite backend-as-a-service — auth, database, storage, functions, realtime for web/mobile/desktop. Use when working with appwrite patterns.
- ▌ Daily Dev Agentic · oyi77Use when skill: daily-dev-agentic. See SKILL.md body for details. Use when this domain is relevant.
- ▌ Dynamodb Patterns · oyi77Use when amazon DynamoDB patterns — single table design, GSI/LSI, DynamoDB Streams, PartiQL, performance optimization. Use when working with dynamodb patterns.
- ▌ Firebase Patterns · oyi77Use when firebase patterns and integration — Firestore queries, auth flows, cloud functions, security rules, SDK setup, and real-time data. Use when working with firebase patterns, integrating firebase.
- ▌ Linux Gui Control · oyi77Use when automating Linux desktop GUI interactions using xdotool, wmctrl, and dogtail for window management, mouse/keyboard simulation, and accessibility inspection.
- ▌ Rabbitmq Patterns · oyi77Use when rabbitMQ patterns — exchanges, queues, routing, dead letter queues, priority queues, clustering. Use when working with rabbitmq patterns.
- ▌ React Native Expo · oyi77Use when react Native with Expo — managed workflow, native modules, navigation, and app store deployment. Use when working with react native expo.
- ▌ Supabase Patterns · oyi77Use when supabase patterns — Row Level Security, edge functions, real-time subscriptions, auth integration, setup, and configuration. Use when working with supabase patterns.
- ▌ Visual Regression · oyi77Use when visual regression testing — screenshot comparison, baseline management, and UI change detection. Use when working with visual regression.
- ▌ Investment Earnings · oyi77 bundleUse when trading earnings reports for profit — pre-earnings positioning, post-earnings momentum, and management quality scoring. Systematic framework for the highest-alpha event in equity markets.
- ▌ Investment Industry · oyi77 bundleUse when industry research and sector rotation for portfolio alpha — TAM/SAM/SOM analysis, competitive dynamics, regulatory tailwinds, and sector timing to beat the market by 5-15% annually.
- ▌ Tax Loss Harvesting · oyi77Use when identify TLH opportunities, manage wash sales. Use when user says "tax loss harvest", "TLH", "wash sale check".
- ▌ Kalodata Monitor · oyi77Use when scheduled research runs with auto-alerts for NEW viral products. Runs on configurable schedule (hourly/daily/weekly), detects new products by comparing with previous runs, alerts on revenue threshold crossings, and sends notifications via Slack webhook. Use when working with kalodata monitor.
- ▌ Langchain Skills · oyi77Use when building agents with LangChain, LangGraph, or Deep Agents. 21 skills covering ecosystem primer, quickstarts, Deep Agents (memory, orchestration, managed), LangChain (fundamentals, middleware, RAG), LangGraph (fundamentals, persistence, CLI, human-in-the-loop), evaluation (Harbor), and utilities (swarm).
- ▌ Webhook Patterns · oyi77Use when webhook design and handling — signature verification, retry logic, idempotency, event routing, testing. Use when working with webhook patterns.
- ▌ Affiliate Marketing · oyi77Use when AI-powered affiliate marketing automation. Research products, generate content, optimize conversions, and build passive income through automated affiliate campaigns.
- ▌ AI Digital Products · oyi77Use when creating and selling AI-powered digital products. Build templates, prompt libraries, workflows, and Notion systems. Generate $500-5K/month passive income.
- ▌ Analytics Dashboard · oyi77Use when tracking performance across all platforms. Monitor social media metrics, ad performance, website analytics, and revenue. Generate automated reports and identify trends for data-driven decisions.
- ▌ Influencer Outreach · oyi77Use when influencer and creator partnership management — discovery, outreach, negotiation, campaign tracking. Use when running influencer marketing campaigns.
- ▌ Social Media Upload · oyi77Use when distribute content across multiple social media platforms (X, Instagram, TikTok, LinkedIn, Facebook, YouTube). Upload images, videos, and text with platform-specific optimization. Use when working with social media upload.
- ▌ Leadership Essentials · oyi77Use when lead teams through vision-setting, decision-making, delegation, and accountability. Use when stepping into a leadership role or improving team performance.
- ▌ Project Management · oyi77Use when coordinate sprints, track deadlines, manage tasks, and maintain project documentation with Notion and Slack. Use when working with project management.
- ▌ Email Automation · oyi77Use when automating email workflows, templates, and campaigns with Gmail MCP integration
- ▌ Google Workspace · oyi77Use when integrate with Google Workspace (Docs, Sheets, Drive, Calendar) using MCP servers. Use when integrateing with google workspace (docs, sheets, drive, calendar) using mcp.
- ▌ Data Pipeline Engine · oyi77Use when eTL pipelines that pull data from multiple sources (APIs, databases, web scraping), transform it, and produce actionable dashboards and reports. Use when working with data pipeline engine.
- ▌ Gate Exchange Trading · oyi77Use when executing trades on Gate.io Spot & Futures markets using CCXT/SDK or gate-cli. Triggers on spot buying, margin borrowing, orderbook depth checks, futures position management, or subaccount trade routing.
- ▌ Deploy Agent · oyi77Use when ship code through controlled pipeline with verification gates and rollback plans.
- ▌ Review Agent · oyi77Use when reading code changes with adversarial intent to find bugs, security holes, logic errors, and performance traps.
- ▌ Pipedream Workflows · oyi77Use when pipedream serverless workflows — triggers, code steps, pre-built actions, data stores, HTTP. Use when working with pipedream workflows.
- ▌ Gemini Image Generator · oyi77Use when generating professional posed product images for e-commerce using Gemini AI with optimized prompts
- ▌ Faceless Youtube · oyi77Use when creating and automating faceless YouTube channels using AI-generated scripts, TTS voiceovers, stock footage, and automated publishing workflows with zero on-camera presence.
- ▌ AI Engineering Curriculum · oyi77Use when structured AI engineering curriculum — 382 skills + 99 prompts across 20 phases covering ML, deep learning, LLMs, agents, and production systems. Use when learning AI, building AI skills,.
- ▌ Skill Performance Monitor · oyi77Use when monitor and analyze skill effectiveness in real-time. Track usage, success rates, response quality, and user satisfaction for continuous optimization. Use when monitoring and analyze skill effectiveness in real-time. track usage, success.
- ▌ Pentestagent Tui · oyi77Use when aI-powered pentesting terminal UI with 4 modes (Assist, Agent, Crew, Interact) and RAG knowledge system. Use when running interactive pentests, multi-agent security assessments, or.
- ▌ Report Generator · oyi77Use when generate professional security vulnerability reports for bug bounty platforms. Use when documenting security findings, preparing bug bounty submissions, or creating assessment reports.
- ▌ Cassandra Patterns · oyi77Use when apache Cassandra patterns — data modeling, CQL, partition keys, clustering, replication, performance tuning. Use when working with cassandra patterns.
- ▌ Database Migration · oyi77Use when safe database migrations — schema changes, data migrations, rollback strategies, and zero-downtime deploys. Use when working with database migration.
- ▌ Dependency Scanner · oyi77Use when automated dependency auditing for npm, pip, cargo, go. Detect vulnerabilities, outdated packages, license conflicts, and supply chain risks. Generate SBOMs and compliance reports.
- ▌ Free Dev Resources · oyi77Use when recommend free-tier developer services and SaaS tools. Use when choosing free infrastructure, comparing free tiers, setting up side projects, or optimizing costs for startups and indie devs.
- ▌ QA Review Fix Loop · oyi77Use when comprehensive QA→Review→Fix loop protocol for any codebase. Layer-based testing with evidence requirements. Use when performing full QA cycles, codebase audits, pre-release testing, or.