thedixitjain
- 10k skills
- 0 followers
- 2 repo stars
- 2 weeks ago last updated
- ▌ Achieving Cmmc Level 2 Compliance · thedixitjain bundle>- Prepare a defense-contractor environment for CMMC Level 2 certification: scope CUI and FCI, implement the 110 NIST SP 800-171 Rev 2 security requirements across 14 families, compute the SPRS score with the DoD Assessment Methodology, manage a compliant POA&M, and ready the organization for a C3PAO assessment. Use when an organization handles Controlled Unclassified Information (CUI) under a DoD contract, when a contract carries DFARS clause 252.204-7012/7019/7020/7021, when preparing for or responding to a CMMC assessment, when computing or improving an SPRS score, when building a System Security Plan or POA&M for 800-171, or when scoping which systems are in the CUI boundary. Keywords: CMMC, CMMC Level 2, NIST 800-171, SP 800-171 Rev 2, CUI, FCI, SPRS, DFARS 7012, C3PAO, POA&M, System Security Plan, DoD Assessment Methodology, 110 controls, defense industrial base, DIB, FedRAMP...
- ▌ Azure Security Keyvault Keys Java · thedixitjain bundleAzure Key Vault Keys Java SDK for cryptographic key management. Use when creating, managing, or using RSA/EC keys, performing encrypt/decrypt/sign/verify operations, or working with HSM-backed keys.
- ▌ Content Security Policy Generator · thedixitjain'Generate content security policy generator operations. Auto-activating skill for Security Fundamentals. Triggers on: content security policy generator, content security policy generator Part of the Security Fundamentals skill category. Use when working with content security policy generator functionality. Trigger with phrases like "content security policy generator", "content generator", "content". '
- ▌ Deploying Ransomware Canary Files · thedixitjain bundle'Deploys and monitors ransomware canary files across critical directories using Python''s watchdog library for real-time filesystem event detection. Places strategically named decoy files that mimic high-value targets (financial records, credentials, database exports) in locations ransomware typically enumerates first. Monitors for any read, modify, rename, or delete operations on canary files and triggers immediate alerts via email, Slack webhook, or syslog when interaction is detected, providing early warning before full encryption begins. '
- ▌ Detecting Mobile Malware Behavior · thedixitjain bundle'Detects and analyzes malicious behavior in mobile applications through behavioral analysis, permission abuse detection, network traffic monitoring, and dynamic instrumentation. Use when analyzing suspicious mobile applications for data exfiltration, command-and-control communication, credential stealing, SMS interception, or other malware indicators. Activates for requests involving mobile malware analysis, app behavior monitoring, trojan detection, or suspicious app investigation. '
- ▌ Detecting Rdp Brute Force Attacks · thedixitjain bundleDetect RDP brute force attacks by analyzing Windows Security Event Logs for failed authentication patterns (Event ID 4625), successful logons after failures (Event ID 4624), NLA failures, and source IP frequency analysis.
- ▌ Generating Security Audit Reports · thedixitjain bundle'Generate comprehensive security audit reports for applications and systems. Use when you need to assess security posture, identify vulnerabilities, evaluate compliance status, or create formal security documentation. Trigger with phrases like "create security audit report", "generate security assessment", "audit security posture", or "PCI-DSS compliance report". '
- ▌ Hunting For Dns Based Persistence · thedixitjain bundleHunt for DNS-based persistence mechanisms including DNS hijacking, dangling CNAME records, wildcard DNS abuse, and unauthorized zone modifications using passive DNS databases, SecurityTrails API, and DNS audit log analysis.
- ▌ Performing Csrf Attack Simulation · thedixitjain bundleTesting web applications for Cross-Site Request Forgery vulnerabilities by crafting forged requests that exploit authenticated user sessions during authorized security assessments.
- ▌ Performing Malware Ioc Extraction · thedixitjain bundleMalware IOC extraction is the process of analyzing malicious software to identify actionable indicators of compromise including file hashes, network indicators (C2 domains, IP addresses, URLs), regist
- ▌ Performing Red Team With Covenant · thedixitjain bundleConduct red team operations using the Covenant C2 framework for authorized adversary simulation, including listener setup, grunt deployment, task execution, and lateral movement tracking.
- ▌ Performing Security Headers Audit · thedixitjain bundleAuditing HTTP security headers including CSP, HSTS, X-Frame-Options, and cookie attributes to identify missing or misconfigured browser-level protections.
- ▌ Recovering From Ransomware Attack · thedixitjain bundle'Executes structured recovery from a ransomware incident following NIST and CISA frameworks, including environment isolation, forensic evidence preservation, clean infrastructure rebuild, prioritized system restoration from verified backups, credential reset, and validation against re-infection. Covers Active Directory recovery, database restoration, and application stack rebuild in dependency order. Activates for requests involving ransomware recovery, post-encryption restoration, or disaster recovery from ransomware. '
- ▌ Securing Github Actions Workflows · thedixitjain bundle'This skill covers hardening GitHub Actions workflows against supply chain attacks, credential theft, and privilege escalation. It addresses pinning actions to SHA digests, minimizing GITHUB_TOKEN permissions, protecting secrets from exfiltration, preventing script injection in workflow expressions, and implementing required reviewers for workflow changes. '
- ▌ Security Guidance · thedixitjain bundlePreToolUse security-anti-pattern hook for Claude Code. Catches 12 common security risks (command injection, XSS, SQL injection, unsafe deserialization, GitHub Actions workflow injection, eval/new Function code injection) BEFORE the Edit/Write/MultiEdit operation completes. Session-state caching prevents duplicate warnings on the same file+rule combo. Stdlib only — no dependencies. Use when you want a safety net during Claude Code sessions that touch security-sensitive code (auth, payments, user input handling, IaC). Disable with ENABLE_SECURITY_REMINDER=0 if you need to perform a verified-safe operation that would otherwise trip a pattern. Triggers — "add security hook", "block unsafe code", "detect command injection before write", "prevent SQL injection patterns", "security warning hook".
- ▌ Implementing Mitre Attack Coverage Mapping · thedixitjain bundleImplement MITRE ATT&CK coverage mapping to identify detection gaps, prioritize rule development, and measure SOC detection maturity against adversary techniques.
- ▌ Performing Privilege Escalation Assessment · thedixitjain bundle'Performs privilege escalation assessments on compromised Linux and Windows systems to identify paths from low-privilege access to root or SYSTEM-level control. The tester enumerates misconfigurations, vulnerable services, kernel exploits, SUID binaries, unquoted service paths, and credential stores to demonstrate the full impact of an initial compromise. Activates for requests involving privilege escalation testing, local exploitation, post-compromise escalation, or OS-level security assessment. '
- ▌ Testing For Business Logic Vulnerabilities · thedixitjain bundleIdentifying flaws in application business logic that allow price manipulation, workflow bypass, and privilege escalation beyond what technical vulnerability scanners can detect.
- ▌ Testing For JSON Web Token Vulnerabilities · thedixitjain bundleTest JWT implementations for critical vulnerabilities including algorithm confusion, none algorithm bypass, kid parameter injection, and weak secret exploitation to achieve authentication bypass and privilege escalation.
- ▌ Agent Platform RAG Engine Management · thedixitjain>- Manage and query Agent Platform RAG Engine Corpora and retrieve grounded contexts using the Google GenAI SDK. Use when listing RAG corpora or files, inspecting a corpus, retrieving contexts, or generating content grounded in a RAG corpus. Do not use for standard database queries (use SQL/Spanner skills), Google Workspace RAG, or other RAG products like gRAG.
- ▌ Deploying Edr Agent With Crowdstrike · thedixitjain bundle'Deploys and configures CrowdStrike Falcon EDR agents across enterprise endpoints to enable real-time threat detection, behavioral analysis, and automated response. Use when onboarding endpoints to EDR coverage, configuring detection policies, or integrating Falcon telemetry with SIEM platforms. Activates for requests involving CrowdStrike deployment, Falcon sensor installation, EDR policy configuration, or endpoint detection and response. '
- ▌ Folder Specific Claude And Agents Md · thedixitjainCreate folder-scoped CLAUDE.md and AGENTS.md guidance for future agents working in that area.
- ▌
- ▌ Orchestrating LLM Attacks With Pyrit · thedixitjain bundleBuild multi-turn, Crescendo, and Tree-of-Attacks-with-Pruning (TAP) automated attack chains against conversational LLM agents using Microsoft PyRIT, with adversarial chat and scorer feedback loops.
- ▌ Self Improving Agent · thedixitjainCurate Claude Code's auto-memory into durable project knowledge. Analyze MEMORY.md for patterns, promote proven learnings to CLAUDE.md and .claude/rules/, extract recurring solutions into reusable skills. Use when: (1) reviewing what Claude has learned about your project, (2) graduating a pattern from notes to enforced rules, (3) turning a debugging solution into a skill, (4) checking memory health and capacity.
- ▌ Exploiting Excessive Data Exposure In API · thedixitjain bundle'Tests APIs for excessive data exposure where endpoints return more data than the client application needs, relying on the frontend to filter sensitive fields. The tester intercepts API responses and analyzes them for leaked PII, internal identifiers, debug information, or sensitive business data that the UI does not display but the API transmits. This maps to OWASP API3:2023 Broken Object Property Level Authorization. Activates for requests involving API data leakage testing, excessive data exposure, response filtering bypass, or API over-fetching. '
- ▌ Stripe Integration Expert · thedixitjainProduction-grade Stripe integrations: subscriptions with trials and proration, one-time payments, usage-based billing, checkout sessions, idempotent webhook handlers, customer portal, and invoicing. Covers Next.js, Express, and Django patterns. Use when integrating Stripe for the first time, debugging webhook reliability issues, migrating from a different payment provider, or adding usage-based billing to an existing subscription product.
- ▌ Procurement Optimizer · thedixitjain bundleUse when running an annual SaaS audit, doing category-level spend review, or rationalizing the supplier base — when the user needs a spend audit, spend categorization (UNSPSC-aligned with Pareto breakdown and industry profiles), purchasing-cycle analysis (bottleneck categories per Goldratt's Theory of Constraints), or risk-balanced supplier consolidation that refuses single-source recommendations for tier-1 categories without a documented break-glass plan. Triggers on "spend audit", "SaaS audit", "spend categorization", "supplier rationalization", "supplier consolidation", "category strategy", "duplicate SaaS", "renewal cluster".
- ▌ Artificial Intelligence And Statistics · thedixitjainUse when targeting International Conference on Artificial Intelligence and Statistics (AISTATS) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for AI statistics.
- ▌ Detecting Beaconing Patterns With Zeek · thedixitjain bundle'Performs statistical analysis of Zeek conn.log connection intervals to detect C2 beaconing patterns. Uses the ZAT library to load Zeek logs into Pandas DataFrames, calculates inter-arrival time standard deviation, and flags periodic connections with low jitter. Use when hunting for command-and-control callbacks in network data. '
- ▌ Detecting Command And Control Over Dns · thedixitjain bundle'Detects command-and-control (C2) communications tunneled through DNS protocol including DNS tunneling tools (Iodine, dnscat2, dns2tcp, Cobalt Strike DNS beacon), domain generation algorithms (DGA), encoded payload delivery via TXT/CNAME records, and DNS beaconing patterns. Covers Shannon entropy analysis of query subdomains, statistical anomaly detection, ML-based DGA classification, passive DNS correlation, and Zeek/Suricata signature development. Activates for requests involving DNS-based C2 detection, DNS tunnel identification, suspicious DNS traffic investigation, or DGA domain classification. '
- ▌ European Conference On Computer Vision · thedixitjainUse when targeting European Conference on Computer Vision (ECCV) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for computer vision flagship.
- ▌ Analyzing Azure Activity Logs For Threats · thedixitjain bundle'Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative operations, impossible travel, privilege escalation, and resource modifications. Builds KQL queries for threat hunting in Azure environments. Use when investigating suspicious Azure tenant activity or building cloud SIEM detections. '
- ▌ Analyzing Persistence Mechanisms In Linux · thedixitjain bundleDetect and analyze Linux persistence mechanisms including crontab entries, systemd service units, LD_PRELOAD hijacking, bashrc modifications, and authorized_keys backdoors using auditd and file integrity monitoring
- ▌ Azure Monitor Opentelemetry Exporter Java · thedixitjain bundle| Azure Monitor OpenTelemetry Exporter for Java. Export OpenTelemetry traces, metrics, and logs to Azure Monitor/Application Insights. Triggers: "AzureMonitorExporter java", "opentelemetry azure java", "application insights java otel", "azure monitor tracing java". Note: This package is DEPRECATED. Migrate to azure-monitor-opentelemetry-autoconfigure.
- ▌ Azure Resource Manager Durabletask Dotnet · thedixitjain| Azure Resource Manager SDK for Durable Task Scheduler in .NET. Use for MANAGEMENT PLANE operations: creating/managing Durable Task Schedulers, Task Hubs, and retention policies via Azure Resource Manager. Triggers: "Durable Task Scheduler", "create scheduler", "task hub", "DurableTaskSchedulerResource", "provision Durable Task", "orchestration scheduler".
- ▌ Database Cloud Optimization Cost Optimize · thedixitjain bundleYou are a cloud cost optimization expert specializing in reducing infrastructure expenses while maintaining performance and reliability. Analyze cloud spending, identify savings opportunities, and implement cost-effective architectures across AWS, Azure, and GCP.
- ▌ Deploying Osquery For Endpoint Monitoring · thedixitjain bundle'Deploys and configures osquery for real-time endpoint monitoring using SQL-based queries to inspect running processes, open ports, installed software, and system configuration. Use when building visibility into endpoint state, threat hunting across fleet, or implementing compliance monitoring. Activates for requests involving osquery deployment, endpoint visibility, fleet management, or SQL-based endpoint querying. '
- ▌ Hunting For Command And Control Beaconing · thedixitjain bundleDetect C2 beaconing patterns in network traffic using frequency analysis, jitter detection, and domain reputation to identify compromised endpoints communicating with adversary infrastructure.
- ▌ Monitoring Scada Modbus Traffic Anomalies · thedixitjain bundle'Monitors Modbus TCP traffic on SCADA and ICS networks to detect anomalous function code usage, unauthorized register writes, and suspicious communication patterns. The analyst uses deep packet inspection with pymodbus, Scapy, and Zeek to baseline normal PLC/RTU communication behavior, then applies statistical and rule-based anomaly detection to identify reconnaissance, parameter manipulation, and denial-of-service attacks targeting Modbus devices on port 502. Activates for requests involving Modbus traffic analysis, SCADA network monitoring, ICS anomaly detection, PLC security monitoring, or OT network threat detection. '
- ▌ Performing Indicator Lifecycle Management · thedixitjain bundleIndicator lifecycle management tracks IOCs from initial discovery through validation, enrichment, deployment, monitoring, and eventual retirement. This skill covers implementing systematic processes f
- ▌ Performing Kubernetes Penetration Testing · thedixitjain bundleKubernetes penetration testing systematically evaluates cluster security by simulating attacker techniques against the API server, kubelet, etcd, pods, RBAC, network policies, and secrets. Using tools
- ▌ Analyzing Powershell Script Block Logging · thedixitjain bundleParse Windows PowerShell Script Block Logs (Event ID 4104) from EVTX files to detect obfuscated commands, encoded payloads, and living-off-the-land techniques. Uses python-evtx to extract and reconstruct multi-block scripts, applies entropy analysis and pattern matching for Base64-encoded commands, Invoke-Expression abuse, download cradles, and AMSI bypass attempts.
- ▌ Engineering Features For Machine Learning · thedixitjain bundle'Execute create, select, and transform features to improve machine learning model performance. Handles feature scaling, encoding, and importance analysis. Use when asked to "engineer features" or "select features". Trigger with relevant phrases based on skill purpose. '
- ▌ Exploiting JWT Algorithm Confusion Attack · thedixitjain bundle'Exploits JWT algorithm confusion vulnerabilities where the server''s token verification library accepts the algorithm specified in the JWT header rather than enforcing a fixed algorithm. The tester manipulates the alg header to switch from RS256 to HS256 (using the RSA public key as the HMAC secret), sets alg to none to bypass signature verification, or exploits kid/jku/x5u header injection to supply attacker-controlled keys. Activates for requests involving JWT algorithm confusion, alg none attack, key confusion attack, or JWT signature bypass. '
- ▌ Google Cloud Waf Performance Optimization · thedixitjain>- Generates performance-focused guidance for Google Cloud workloads based on the design principles and recommendations in the Performance Optimization pillar of the Google Cloud Well-Architected Framework (WAF). Use this skill to evaluate a workload, identify performance requirements, and provide actionable recommendations for resource allocation, modular design, and elasticity.
- ▌ Implementing Soar Automation With Phantom · thedixitjain bundle'Implements Security Orchestration, Automation, and Response (SOAR) workflows using Splunk SOAR (formerly Phantom) to automate alert triage, IOC enrichment, containment actions, and incident response playbooks. Use when SOC teams need to reduce manual analyst work, standardize response procedures, or integrate multiple security tools into automated workflows. '
- ▌ Javascript Typescript Typescript Scaffold · thedixitjainYou are a TypeScript project architecture expert specializing in scaffolding production-ready Node.js and frontend applications. Generate complete project structures with modern tooling (pnpm, Vite, N
- ▌ Providing Performance Optimization Advice · thedixitjain bundleProvide comprehensive prioritized performance optimization recommendations for frontend, backend, and infrastructure. Use when analyzing bottlenecks or seeking improvement strategies. Trigger with phrases like "optimize performance", "improve speed", or "performance recommendations".
- ▌ React Container Presentation Component · thedixitjain bundleCreate a React component using the Container/Presentation pattern in src/components by asking for the component name and type (ui or features), then scaffold files that follow this repository's TypeScript, Storybook, and SCSS conventions. Use when the user explicitly asks for a Container/Presentation-based component or runs /react-container-presentation-component.
- ▌ UX Researcher Designer · thedixitjain bundleUX research and design toolkit for Senior UX Designer/Researcher including data-driven persona generation, journey mapping, usability testing frameworks, and research synthesis. Use when conducting user research, creating personas, mapping user journeys, planning usability tests, or validating designs.
- ▌ Implementing Log Integrity With Blockchain · thedixitjain bundleBuild an append-only log integrity chain using SHA-256 hash chaining for tamper detection. Each log entry is hashed with the previous entry's hash to create a blockchain-like structure where modifying any entry invalidates all subsequent hashes. Implements log ingestion, chain verification, tamper detection with pinpoint identification, and periodic checkpoint anchoring to external timestamping services.
- ▌ Performing Network Packet Capture Analysis · thedixitjain bundlePerform forensic analysis of network packet captures (PCAP/PCAPNG) using Wireshark, tshark, and tcpdump to reconstruct network communications, extract transferred files, identify malicious traffic, and establish evidence of data exfiltration or command-and-control activity.
- ▌ Acquiring Disk Image With Dd And Dcfldd · thedixitjain bundleCreate forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through hash verification.
- ▌ Analyzing Android Malware With Apktool · thedixitjain bundlePerform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source recovery, and androguard for permission analysis, manifest inspection, and suspicious API call detection.
- ▌ Analyzing Windows Event Logs In Splunk · thedixitjain bundle'Analyzes Windows Security, System, and Sysmon event logs in Splunk to detect authentication attacks, privilege escalation, persistence mechanisms, and lateral movement using SPL queries mapped to MITRE ATT&CK techniques. Use when SOC analysts need to investigate Windows-based threats, build detection queries, or perform forensic timeline analysis of Windows endpoints and domain controllers. '
- ▌ Analyzing Windows Prefetch With Python · thedixitjain bundleParse Windows Prefetch files using the windowsprefetch Python library to reconstruct application execution history, detect renamed or masquerading binaries, and identify suspicious program execution patterns.
- ▌ Hunting For Scheduled Task Persistence · thedixitjain bundleHunt for adversary persistence via Windows Scheduled Tasks by analyzing task creation events, suspicious task actions, and unusual scheduling patterns.
- ▌ Hunting For Suspicious Scheduled Tasks · thedixitjain bundleHunt for adversary persistence and execution via Windows scheduled tasks by analyzing task creation events, suspicious task properties, and unusual execution patterns that indicate T1053.005 abuse.
- ▌ Performing IOS App Security Assessment · thedixitjain bundle'Performs comprehensive iOS application security assessments using Frida for dynamic instrumentation, Objection for runtime exploration, SSL pinning bypass for traffic interception, keychain extraction for credential analysis, and IPA static analysis for binary-level review. Use when conducting authorized iOS penetration tests, evaluating mobile app security posture against OWASP MASTG, or assessing iOS app data protection and transport security controls. Activates for requests involving iOS app pentesting, Frida-based iOS instrumentation, mobile app SSL pinning bypass, or IPA reverse engineering. '
- ▌ Reverse Engineering IOS App With Frida · thedixitjain bundle'Reverse engineers iOS applications using Frida dynamic instrumentation to understand internal logic, extract encryption keys, bypass security controls, and discover hidden functionality without source code access. Use when performing authorized iOS penetration testing, analyzing proprietary protocols, understanding obfuscated logic, or extracting runtime secrets from iOS binaries. Activates for requests involving iOS reverse engineering, Frida iOS hooking, Objective-C/Swift method tracing, or iOS binary analysis. '
- ▌ Prompt Engineer Toolkit · thedixitjain bundleTurns marketing prompts into tested, versioned production assets: A/B prompt evaluation against structured test cases, immutable prompt version history with diffs, ready-to-use marketing prompt templates (ad copy, email campaigns, social posts, landing pages, SEO meta), and an LLM-governance playbook for marketing teams (claim discipline, disclosure rules, human-review gates). Use when a marketing team relies on AI-generated content and needs prompt quality to be measurable and safe — or when the user mentions 'prompt engineering,' 'improve my prompts,' 'prompt templates,' 'prompt versioning,' 'AI content workflow,' or 'AI governance for marketing.'
- ▌ Detecting Mimikatz Execution Patterns · thedixitjain bundleDetect Mimikatz execution through command-line patterns, LSASS access signatures, binary indicators, and in-memory detection of known modules.
- ▌ Detecting Process Hollowing Technique · thedixitjain bundleDetect process hollowing (T1055.012) by analyzing memory-mapped sections, hollowed process indicators, and parent-child process anomalies in EDR telemetry.
- ▌ Acm Symposium On Theory Of Computing · thedixitjainUse when targeting ACM Symposium on Theory of Computing (STOC) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for theory flagship.
- ▌ Agronomy For Sustainable Development · thedixitjainUse when targeting Agronomy for Sustainable Development or deciding whether an agronomy / farming-systems manuscript fits this venue. Encodes the journal's fit, the explicit-and-evidenced sustainability-contribution bar, evidence and data-reporting expectations, house style, official-submission re-check, and desk-reject heuristics.
- ▌ Agsy Reproducibility And Data Policy · thedixitjainUse when preparing the data, code, and model materials for an Agricultural Systems (AgSy) manuscript. AgSy applies Elsevier's research-data policy, which treats software, code, and models as research data — deposit them in a repository and cite/link them, or state why they cannot be shared. Covers model-description standards and exemptions. Prepares the materials; it does not waive requirements.
- ▌ American Journal Of Gastroenterology · thedixitjainUse when targeting The American Journal of Gastroenterology or deciding whether a clinical GI/hepatology study fits this venue. Encodes the journal's fit, the practice-relevant clinical-evidence bar, reporting-guideline and registration requirements, ACG house style, official-submission re-check, and desk-reject heuristics. Venue-fit aid only, not clinical advice.
- ▌ Communications Earth And Environment · thedixitjainUse when targeting Communications Earth & Environment or deciding whether an earth, environmental, or planetary-science manuscript fits this venue. Encodes the journal's fit, the solid-and-complete-advance bar, Nature Portfolio reporting/data standards, house style, official-submission re-check, and desk-reject heuristics.
- ▌ Entrepreneurship Theory And Practice · thedixitjainUse when targeting Entrepreneurship Theory and Practice (ETP) or deciding whether a theory-driven entrepreneurship manuscript fits this venue. Encodes the journal's fit, framing, method-and-evidence bar, house style, official-submission re-check, and desk-reject heuristics.
- ▌ Environmental Science And Technology · thedixitjainUse when targeting Environmental Science & Technology (ES&T) or deciding whether an environmental science or engineering manuscript fits this venue. Encodes the journal's fit, framing, method-and-evidence bar, house style, official-submission re-check, and desk-reject heuristics.
- ▌ Ieee Pacific Visualization Symposium · thedixitjainUse when targeting IEEE Pacific Visualization Symposium (PacificVis) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for visualization.
- ▌ Journal Of Machine Learning Research · thedixitjainUse when targeting Journal of Machine Learning Research (JMLR) or deciding whether a machine learning methods or theory manuscript fits this open-access venue. Encodes the journal's fit, framing, method-and-evidence bar, house style, official-submission re-check, and desk-reject heuristics.
- ▌ Journal Of Management Sciences China · thedixitjainUse when targeting 《管理科学学报》(Journal of Management Sciences in China) — the NSFC-flagship for quantitative / mathematical management science (operations research, decision analysis, mathematical finance, behavioral operations, system modeling). Apply when a paper needs rigorous models, proofs, or algorithms — NOT empirical-survey or case work (that is 管理世界 / 南开管理评论).
- ▌ Journal Of Shenyang Sport University · thedixitjainUse when targeting 《沈阳体育学院学报》(Journal of Shenyang Sport University) — a CSSCI comprehensive sport-science journal hosted by Shenyang Sport University in northeast China, covering the full breadth of sport science with a recognized strength in winter sport (冰雪运动) alongside training, exercise science and sport humanities & social science. Best for well-evidenced studies across sub-fields, and a natural home for winter-sport / ice-and-snow research; route to specialist venues when a sharper home exists.
- ▌ Nature Reviews Earth And Environment · thedixitjainUse when targeting Nature Reviews Earth & Environment (Nat. Rev. Earth Environ.) or deciding whether a review-type Earth or environmental science manuscript fits this commissioned-review venue. Encodes the journal's fit, framing, method-and-evidence bar, house style, official-submission re-check, and desk-reject heuristics.
- ▌ Ppsych Comprehensiveness And Balance · thedixitjainUse when appraising the credibility of the studies a Perspectives on Psychological Science (PoPS) piece synthesizes and calibrating comprehensiveness, balance, and fair treatment of competing camps — including reform-minded but evidence-based critique. Weighs evidence and audits even-handedness; it does not design the spine (ppsych-organizing-framework) or run new analyses.
- ▌ Production And Operations Management · thedixitjainUse when targeting Production and Operations Management (POM) or deciding whether a broad operations-management analytical or empirical manuscript fits this venue. Encodes the journal's fit, framing, method-and-evidence bar, house style, official-submission re-check, and desk-reject heuristics.
- ▌ Research On Economics And Management · thedixitjainUse when targeting 《经济与管理研究》(Research on Economics and Management — 首都经济贸易大学主办的经管交叉月刊, 1980 创刊, 北大核心/CSSCI, 不收费) or deciding whether a Chinese econ/management manuscript fits this venue. Encodes the journal's fit, framing, review timeline, house style, official-submission re-check, and desk-reject heuristics.
- ▌ Resources Conservation And Recycling · thedixitjainUse when targeting Resources, Conservation & Recycling or deciding whether a resource-efficiency/circular-economy manuscript fits this venue. Encodes the journal's fit, the materials-and-waste circularity contribution bar, material-flow-analysis expectations, house style, official-submission re-check, and desk-reject heuristics.
- ▌ Analyzing Indicators Of Compromise · thedixitjain bundle'Analyzes indicators of compromise (IOCs) including IP addresses, domains, file hashes, URLs, and email artifacts to determine maliciousness confidence, campaign attribution, and blocking priority. Use when triaging IOCs from phishing emails, security alerts, or external threat feeds; enriching raw IOCs with multi-source intelligence; or making block/monitor/whitelist decisions. Activates for requests involving VirusTotal, AbuseIPDB, MalwareBazaar, MISP, or IOC enrichment pipelines. '
- ▌ Analyzing Uefi Bootkit Persistence · thedixitjain bundle'Analyzes UEFI bootkit persistence mechanisms including firmware implants in SPI flash, EFI System Partition (ESP) modifications, Secure Boot bypass techniques, and UEFI variable manipulation. Covers detection of known bootkit families (BlackLotus, LoJax, MosaicRegressor, MoonBounce, CosmicStrand), ESP partition forensic inspection, chipsec-based firmware integrity verification, and Secure Boot configuration auditing. Activates for requests involving UEFI malware analysis, firmware persistence investigation, boot chain integrity verification, or Secure Boot bypass detection. '
- ▌ Checking Infrastructure Compliance · thedixitjain bundle'Execute use when you need to work with compliance checking. This skill provides compliance monitoring and validation with comprehensive guidance and automation. Trigger with phrases like "check compliance", "validate policies", or "audit compliance". '
- ▌ Configuring Pfsense Firewall Rules · thedixitjain bundle'Configures pfSense firewall rules, NAT policies, VPN tunnels, and traffic shaping to enforce network segmentation, control traffic flow, and protect internal network zones in enterprise and small-to-medium business environments. '
- ▌ Detecting Attacks On Scada Systems · thedixitjain bundle'This skill covers detecting cyber attacks targeting Supervisory Control and Data Acquisition (SCADA) systems including man-in-the-middle attacks on industrial protocols, unauthorized command injection into PLCs, HMI compromise, historian data manipulation, and denial-of-service against control system communications. It leverages OT-specific intrusion detection systems, industrial protocol anomaly detection, and process data analytics to identify attacks that traditional IT security tools miss. '
- ▌ Detecting Insider Threat Behaviors · thedixitjain bundleDetect insider threat behavioral indicators including unusual data access, off-hours activity, mass file downloads, privilege abuse, and resignation-correlated data theft.
- ▌ Detecting Insider Threat With Ueba · thedixitjain bundleImplement User and Entity Behavior Analytics using Elasticsearch/OpenSearch to build behavioral baselines, calculate anomaly scores, perform peer group analysis, and detect insider threat indicators such as data exfiltration, privilege abuse, and unauthorized access patterns.
- ▌ Finding Security Misconfigurations · thedixitjain bundle'Configure identify security misconfigurations in infrastructure-as-code, application settings, and system configurations. Use when you need to audit Terraform/CloudFormation templates, check application config files, validate system security settings, or ensure compliance with security best practices. Trigger with phrases like "find security misconfigurations", "audit infrastructure security", "check config security", or "scan for misconfigured settings". '
- ▌ Mailtrap Setting Up Sending Domain · thedixitjainAdd or verify a Mailtrap sending domain, troubleshoot DNS propagation, publish SPF/DKIM/DMARC records, and complete compliance.
- ▌ Operationalizing Misp Threat Feeds · thedixitjain bundleRun MISP, curate feeds, and auto-generate detections for Wazuh, Sigma, and Suricata.
- ▌ Performing Blind Ssrf Exploitation · thedixitjain bundleDetect and exploit blind Server-Side Request Forgery vulnerabilities using out-of-band techniques, DNS interactions, and timing analysis to access internal services and cloud metadata endpoints.
- ▌ Performing Iot Security Assessment · thedixitjain bundle'Performs comprehensive security assessments of IoT devices and their ecosystems by testing hardware interfaces, firmware, network communications, cloud APIs, and companion mobile applications. The tester uses firmware extraction and analysis, hardware debugging via UART and JTAG, network protocol analysis, and runtime exploitation to identify vulnerabilities across all layers of the IoT stack. Activates for requests involving IoT security testing, embedded device assessment, firmware security analysis, or smart device penetration testing. '
- ▌ Performing Packet Injection Attack · thedixitjain bundle'Crafts and injects custom network packets using Scapy, hping3, and Nemesis during authorized security assessments to test firewall rules, IDS detection, protocol handling, and network stack resilience against malformed and spoofed traffic. '
- ▌ Triaging Security Alerts In Splunk · thedixitjain bundle'Triages security alerts in Splunk Enterprise Security by classifying severity, investigating notable events, correlating related telemetry, and making escalation or closure decisions using SPL queries and the Incident Review dashboard. Use when SOC analysts face queued alerts from correlation searches, need to prioritize investigation order, or must document triage decisions for handoff to Tier 2/3 analysts. '
- ▌ Testing Android Intents For Vulnerabilities · thedixitjain bundle'Tests Android inter-process communication (IPC) through intents for vulnerabilities including intent injection, unauthorized component access, broadcast sniffing, pending intent hijacking, and content provider data leakage. Use when assessing Android app attack surface through exported components, testing intent-based data flows, or evaluating IPC security. Activates for requests involving Android intent security, IPC testing, exported component analysis, or Drozer assessment. '
- ▌ Agent Platform Migrate From AI Studio · thedixitjain>- Guides agents and users through migrating from Gemini API in Google AI Studio to Gemini Enterprise Agent Platform (formerly Vertex AI). Use this skill when moving applications to Google Cloud, to leverage Cloud credits, or to unify inferencing with other Cloud infrastructure (IAM, billing, telemetry).
- ▌ Analyzing Powershell Empire Artifacts · thedixitjain bundleDetect PowerShell Empire framework artifacts in Windows event logs by identifying Base64 encoded launcher patterns, default user agents, staging URL structures, stager IOCs, and known Empire module signatures in Script Block Logging events.
- ▌ Suggest Awesome Github Copilot Agents · thedixitjainSuggest relevant GitHub Copilot Custom Agents files from the awesome-copilot repository based on current repository context and chat history, avoiding duplicates with existing custom agents in this repository, and identifying outdated agents that need updates.
- ▌ Datalineage Bigquery Asset Impact Analysis · thedixitjain bundle>- Analyzes the downstream impact (blast radius) when a BigQuery table or view is broken, stale, or modified. Identifies all downstream tables, dashboards, and processes that will be affected. Use when: Performing a blast radius or impact analysis for a BigQuery table or view. Assessing the consequences of modifying, deleting, or pausing updates to a BigQuery asset. Identifying downstream dependencies (tables, dashboards, processes) of a BigQuery asset. Don't use for: General BigQuery querying or data analysis (use BigQuery-related tools instead). Non-BigQuery assets (e.g., Cloud Storage files) unless they are part of the BigQuery lineage. Creating or modifying lineage links directly.
- ▌ Implementing Delinea Secret Server For Pam · thedixitjain bundle'Implements Delinea Secret Server for privileged access management (PAM) including secret vault configuration, role-based access policies, automated password rotation, session recording, and integration with Active Directory and cloud platforms. Activates for requests involving PAM deployment, privileged credential vaulting, secret server administration, or password rotation automation. '