all publishers

thedixitjain

@thedixitjain source repo

10,417 published skills · page 20 of 105

  1. ▌
    Detecting Cloud Threats With Guardduty · thedixitjain bundle
    'This skill teaches security teams how to deploy and operationalize Amazon GuardDuty for continuous threat detection across AWS accounts and workloads. It covers enabling protection plans for S3, EKS, EC2 runtime monitoring, and Lambda, interpreting finding severity levels, and building automated response workflows using EventBridge and Lambda. '
    2 repo stars
  2. ▌
    Google Cloud Recipe Foundation Builder · thedixitjain bundle
    >- Deploys a baseline landing zone foundation for a Google Cloud Organization, establishing security guardrails using Organization Policies, resource hierarchy folders and projects, billing association, and centralized logging and monitoring. Deploys Google Cloud's recommended security controls and architecture. Use when setting up a new Google Cloud Organization or establishing a secure, enterprise-grade landing zone foundation. Don't use for individual project onboarding (use google-cloud-recipe-onboarding or product-specific skills instead).
    2 repo stars
  3. ▌
    Hunting For Startup Folder Persistence · thedixitjain bundle
    Detect T1547.001 startup folder persistence by monitoring Windows startup directories for suspicious file creation, analyzing autoruns entries, and using Python watchdog for real-time filesystem monitoring.
    2 repo stars
  4. ▌
    Implementing Cloud Workload Protection · thedixitjain bundle
    'Implements cloud workload protection using boto3 and google-cloud APIs for runtime security monitoring, process anomaly detection, and file integrity checking on EC2/GCE instances. Scans for cryptomining, reverse shells, and unauthorized binaries. Use when building runtime security controls for cloud compute workloads. '
    2 repo stars
  5. ▌
    Implementing Zero Trust Network Access · thedixitjain bundle
    'Implementing Zero Trust Network Access (ZTNA) in cloud environments by configuring identity-aware proxies, micro-segmentation, continuous verification with conditional access policies, and replacing traditional VPN-based access with BeyondCorp-style architectures across AWS, Azure, and GCP. '
    2 repo stars
  6. ▌
    Observability Monitoring Monitor Setup · thedixitjain bundle
    You are a monitoring and observability expert specializing in implementing comprehensive monitoring solutions. Set up metrics collection, distributed tracing, log aggregation, and create insightful da
    2 repo stars
  7. ▌
    Observability Monitoring Slo Implement · thedixitjain bundle
    You are an SLO (Service Level Objective) expert specializing in implementing reliability standards and error budget-based engineering practices. Design comprehensive SLO frameworks, establish meaningful SLIs, and create monitoring systems that balance reliability with feature velocity.
    2 repo stars
  8. ▌
    Remediating S3 Bucket Misconfiguration · thedixitjain bundle
    'This skill provides step-by-step procedures for identifying and remediating Amazon S3 bucket misconfigurations that expose sensitive data to unauthorized access. It covers enabling S3 Block Public Access at account and bucket levels, auditing bucket policies and ACLs, enforcing encryption, configuring access logging, and deploying automated remediation using AWS Config and Lambda. '
    2 repo stars
  9. ▌
    Scanning Containers With Trivy In Cicd · thedixitjain bundle
    'This skill covers integrating Aqua Security''s Trivy scanner into CI/CD pipelines for comprehensive container image vulnerability detection. It addresses scanning Docker images for OS package and application dependency CVEs, detecting misconfigurations in Dockerfiles, scanning filesystem and git repositories, and establishing severity-based quality gates that block deployment of vulnerable images. '
    2 repo stars
  10. ▌
    Securing Azure With Microsoft Defender · thedixitjain bundle
    'This skill instructs security practitioners on deploying Microsoft Defender for Cloud as a cloud-native application protection platform for Azure, multi-cloud, and hybrid environments. It covers enabling Defender plans for servers, containers, storage, and databases, configuring security recommendations, managing Secure Score, and integrating with the unified Defender portal for centralized threat management. '
    2 repo stars
  11. ▌
    Code Documentation Code Explain · thedixitjain bundle
    You are a code education expert specializing in explaining complex code through clear narratives, visual diagrams, and step-by-step breakdowns. Transform difficult concepts into understandable explanations for developers at all levels.
    2 repo stars
  12. ▌
    Code Documentation Doc Generate · thedixitjain bundle
    You are a documentation expert specializing in creating comprehensive, maintainable documentation from code. Generate API docs, architecture diagrams, user guides, and technical references using AI-powered analysis and industry best practices.
    2 repo stars
  13. ▌
    Ieee Transactions On Power Electronics · thedixitjain
    Use when targeting IEEE Transactions on Power Electronics (TPEL) or deciding whether a power-conversion manuscript fits this venue. Encodes the journal's fit, the hardware-validation bar, the converter-and-control scope, the TPEL-vs-TIE routing, house style, official-submission re-check, and desk-reject heuristics.
    2 repo stars
  14. ▌
    Ieee Transactions On Signal Processing · thedixitjain
    Use when targeting IEEE Transactions on Signal Processing or deciding whether a signal-processing methods manuscript fits this venue. Encodes the journal's fit, the algorithm-plus-analysis bar, the baseline-and-guarantee expectation, the regular-paper-vs-correspondence framing, house style, official-submission re-check, and desk-reject heuristics.
    2 repo stars
  15. ▌
    Power Bi Report Design Consultation · thedixitjain
    Power BI report visualization design prompt for creating effective, user-friendly, and accessible reports with optimal chart selection and layout design.
    2 repo stars
  16. ▌
    Detecting Email Forwarding Rules Attack · thedixitjain bundle
    Detect malicious email forwarding rules created by adversaries to maintain persistent access to email communications for intelligence collection and BEC attacks.
    2 repo stars
  17. ▌
    Hunting For Unusual Network Connections · thedixitjain bundle
    Hunt for unusual network connections by analyzing outbound traffic patterns, rare destinations, non-standard ports, and anomalous connection frequencies from endpoints.
    2 repo stars
  18. ▌
    Detecting Email Account Compromise · thedixitjain bundle
    Detect compromised O365 and Google Workspace email accounts by analyzing inbox rule creation, suspicious sign-in locations, mail forwarding rules, and unusual API access patterns via Microsoft Graph and audit logs.
    2 repo stars
  19. ▌
    MCP Implementation Security Review · thedixitjain
    | Review the implementation source code of MCP (Model Context Protocol) servers, clients, and tool handlers against a security baseline — authentication, sessions, rate limiting, input-schema validation, official-SDK usage, RCE vectors, and the OWASP MCP Top 10 — producing a report with file/line evidence. Use this skill when: Reviewing an MCP server implementation for security before release Checking a server against the baseline controls (MCP-01 to MCP-05) and the OWASP MCP Top 10 Auditing tools for RCE vectors (command/code injection, unsafe deserialization, path traversal, SSTI, dependency hijacking, SSRF) Verifying auth, session, rate-limiting, and input-validation controls on a network-exposed server Reviewing MCP client code that handles untrusted server responses and session IDs Requests like "review this MCP server for security" or "is my MCP server implementation secure?"
    2 repo stars
  20. ▌
    Power Platform MCP Connector Suite · thedixitjain
    Generate complete Power Platform custom connector with MCP integration for Copilot Studio - includes schema generation, troubleshooting, and validation
    2 repo stars
  21. ▌
    Analyzing Malicious PDF With Peepdf · thedixitjain bundle
    Perform static analysis of malicious PDF documents using peepdf, pdfid, and pdf-parser to extract embedded JavaScript, shellcode, and suspicious objects.
    2 repo stars
  22. ▌
    Analyzing Windows Amcache Artifacts · thedixitjain bundle
    'Parses and analyzes the Windows Amcache.hve registry hive to extract evidence of program execution, application installation, and driver loading for digital forensics investigations. Uses Eric Zimmerman''s AmcacheParser and Timeline Explorer for artifact extraction, SHA-1 hash correlation with threat intel, and timeline reconstruction. Activates for requests involving Amcache forensics, program execution evidence, Windows artifact analysis, or application compatibility cache investigation. '
    2 repo stars
  23. ▌
    Exploiting Deeplink Vulnerabilities · thedixitjain bundle
    'Tests and exploits deep link (URL scheme and App Link) vulnerabilities in Android and iOS mobile applications to identify unauthorized access, data injection, intent hijacking, and redirect manipulation. Use when assessing mobile app attack surface through custom URI schemes, Android App Links, iOS Universal Links, or intent-based navigation. Activates for requests involving deep link security testing, URL scheme exploitation, mobile intent abuse, or link hijacking. '
    2 repo stars
  24. ▌
    Weekly Review · thedixitjain bundle
    Use when someone wants to run a weekly review, close open loops, audit stalled projects and commitments, get their system back to trusted, restart a lapsed review habit, or says "/cs:weekly-review". Walks David Allen's three-phase loop — GET CLEAR, GET CURRENT, GET CREATIVE — with deterministic scripts that inventory open loops, gate the checklist with named gaps, and score commitment health 0-100.
    2 repo stars
  25. ▌
    Accounting And Economics Research · thedixitjain
    Use when targeting 《会计与经济研究》(Accounting and Economics Research — 上海市教委主管、上海立信会计金融学院主办、双向匿名评审、不收版面费的财经双月刊) or deciding whether a Chinese accounting/finance/econ manuscript fits this venue. Encodes the journal's fit, framing, abstract/keyword/citation house style, official-submission re-check, and desk-reject heuristics.
    2 repo stars
  26. ▌
    Aerj Transparency And Data Policy · thedixitjain
    Use when preparing the transparency, reporting, and data-availability materials for an American Educational Research Journal (AERJ) manuscript. AERJ expects work to meet the AERA Standards for Reporting on Empirical Social Science Research (quantitative + qualitative) and the AERA Code of Ethics expectations on making data available. Prepares the materials; it does not waive requirements.
    2 repo stars
  27. ▌
    Apsr Transparency And Data Policy · thedixitjain
    Use when preparing the reproducibility / replication materials for an American Political Science Review (APSR) manuscript. APSR requires conditionally accepted authors to deposit a reproducibility package in the APSR Dataverse (Harvard Dataverse), which the editorial office verifies before publication. Covers quantitative and qualitative transparency and exemptions. Prepares the package; it does not waive requirements.
    2 repo stars
  28. ▌
    Atmospheric Chemistry And Physics · thedixitjain
    Use when targeting Atmospheric Chemistry and Physics (ACP) or deciding whether an atmospheric-composition manuscript fits this open-access, interactive-peer-review venue. Encodes the journal's fit, framing, method-and-evidence bar, house style, official-submission re-check, and desk-reject heuristics.
    2 repo stars
  29. ▌
    Environmental Health Perspectives · thedixitjain
    Use when targeting Environmental Health Perspectives or deciding whether an environmental-health manuscript fits this venue. Encodes the journal's fit, the public-health-relevance and methodological-rigor bar, epidemiological/toxicological expectations, house style, official-submission re-check, and desk-reject heuristics.
    2 repo stars
  30. ▌
    Est Reporting And Reproducibility · thedixitjain
    Use when assembling the Supporting Information (SI), data-availability statement, and public-data/code deposit for an Environmental Science & Technology (ES&T) manuscript. ES&T expects materials, data, and protocols to be deposited in public databases and a data-availability statement, with SI submitted alongside the manuscript. It guides reporting and deposit; it does not generate the underlying data.
    2 repo stars
  31. ▌
    Jel Comprehensiveness And Balance · thedixitjain
    Use when calibrating completeness vs. selectivity and ensuring fairness across schools, authors, and controversies in a Journal of Economic Literature (JEL) survey — including not over-promoting the author's own work. Audits coverage and even-handedness; it does not design the framework (jel-organizing-framework) or write prose (jel-writing-style).
    2 repo stars
  32. ▌
    Joc Open Science And Transparency · thedixitjain
    Use when preparing the open-science and transparency materials for a Journal of Communication (JoC) manuscript. JoC requires a Data Availability Statement and supports Open Science Badges for open data, open materials, and preregistration. Covers quantitative, computational, and qualitative transparency and the restricted-data path. Prepares the materials; it does not waive requirements.
    2 repo stars
  33. ▌
    Journal Of Clinical Investigation · thedixitjain
    Use when targeting Journal of Clinical Investigation (JCI) or deciding whether a translational medicine manuscript fits this venue. Encodes the journal's fit, framing, method-and-evidence bar, house style, official-submission re-check, and desk-reject heuristics.
    2 repo stars
  34. ▌
    Journal Of Macro Quality Research · thedixitjain
    Use when targeting 《宏观质量研究》(Journal of Macro-quality Research — 教育部主管、武汉大学主办、武大质量发展战略研究院编辑出版的 CSSCI 期刊) or deciding whether a Chinese social-science/econ/management manuscript fits this journal. Applies the journal's quality-economics framing, house-style, official-submission-check (hgzlyj.whu.edu.cn), and desk-reject heuristics.
    2 repo stars
  35. ▌
    Prediction Market Oracle Research · thedixitjain
    Research prediction markets as data sources or oracle signals for products, agents, dashboards, and corporate decision intelligence. Use for source-grounded analysis of market-implied probabilities, caveats, and integration patterns without investment advice.
    2 repo stars
  36. ▌
    Configuring Hsm For Key Storage · thedixitjain bundle
    Hardware Security Modules (HSMs) are tamper-resistant physical devices that safeguard cryptographic keys and perform cryptographic operations in a hardened environment. Keys stored in an HSM never lea
    2 repo stars
  37. ▌
    Detecting Golden Ticket Forgery · thedixitjain bundle
    Detect Kerberos Golden Ticket forgery by analyzing Windows Event ID 4769 for RC4 encryption downgrades (0x17), abnormal ticket lifetimes, and krbtgt account anomalies in Splunk and Elastic SIEM
    2 repo stars
  38. ▌
    Detecting Pass The Hash Attacks · thedixitjain bundle
    Detect Pass-the-Hash attacks by analyzing NTLM authentication patterns, identifying Type 3 logons with NTLM where Kerberos is expected, and correlating with credential dumping.
    2 repo stars
  39. ▌
    Implementing Saml Sso With Okta · thedixitjain bundle
    Implement SAML 2.0 Single Sign-On (SSO) using Okta as the Identity Provider (IdP). This skill covers end-to-end configuration of SAML authentication flows, attribute mapping, certificate management, a
    2 repo stars
  40. ▌
    Mapping Mitre Attack Techniques · thedixitjain bundle
    'Maps observed adversary behaviors, security alerts, and detection rules to MITRE ATT&CK techniques and sub-techniques to quantify detection coverage and guide control prioritization. Use when building an ATT&CK-based coverage heatmap, tagging SIEM alerts with technique IDs, aligning security controls to adversary playbooks, or reporting threat exposure to executives. Activates for requests involving ATT&CK Navigator, Sigma rules, MITRE D3FEND, or coverage gap analysis. '
    2 repo stars
  41. ▌
    Performing Purple Team Exercise · thedixitjain bundle
    'Performs purple team exercises by coordinating red team adversary emulation with blue team detection validation using MITRE ATT&CK-mapped attack scenarios, real-time detection testing, and collaborative gap remediation. Use when SOC teams need to validate detection capabilities, improve analyst skills, and close detection gaps through structured offensive-defensive collaboration. '
    2 repo stars
  42. ▌
    Performing Security Code Review · thedixitjain bundle
    'Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin. it analyzes code for potential vulnerabilities like sql injection, xss, authentication flaws, and insecure dependencies. AI assistant uses this skill wh... Use when assessing security or running audits. Trigger with phrases like ''security scan'', ''audit'', or ''vulnerability''. '
    2 repo stars
  43. ▌
    Security Scanning Security Sast · thedixitjain
    'Static Application Security Testing (SAST) for code vulnerability analysis across multiple languages and frameworks '
    2 repo stars
  44. ▌
    Substrate Vulnerability Scanner · thedixitjain bundle
    Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin checks. Use when auditing Substrate runtimes or FRAME pallets.
    2 repo stars
  45. ▌
    Azure Resource Manager Playwright Dotnet · thedixitjain
    | Azure Resource Manager SDK for Microsoft Playwright Testing in .NET. Use for MANAGEMENT PLANE operations: creating/managing Playwright Testing workspaces, checking name availability, and managing workspace quotas via Azure Resource Manager. NOT for running Playwright tests - use Azure.Developer.MicrosoftPlaywrightTesting.NUnit for that. Triggers: "Playwright workspace", "create Playwright Testing workspace", "manage Playwright resources", "ARM Playwright", "PlaywrightWorkspaceResource", "provision Playwright Testing".
    2 repo stars
  46. ▌
    Validating Backup Integrity For Recovery · thedixitjain bundle
    Validate backup integrity through cryptographic hash verification, automated restore testing, corruption detection, and recoverability checks to ensure backups are reliable for disaster recovery and ransomware response scenarios.
    2 repo stars
  47. ▌
    Arsoc Comprehensiveness And Balance · thedixitjain
    Use when calibrating completeness vs. selectivity and ensuring fairness across theoretical schools, methods, authors, and debates in an Annual Review of Sociology (ARSoc) review — including not over-promoting the author's own work. Audits coverage and even-handedness; it does not design the framework (arsoc-organizing-framework) or write prose (arsoc-writing-style).
    2 repo stars
  48. ▌
    Mind Conceptual Analysis And Method · thedixitjain
    Use when sharpening the concepts, distinctions, and method of a Mind article — defining key terms precisely, drawing distinctions, deploying thought experiments, and choosing the right philosophical method. Analytic philosophy lives or dies on conceptual precision and parsimony. Tightens the conceptual machinery; it does not settle the substantive question for you.
    2 repo stars
  49. ▌
    Agent Platform Alert Configuration · thedixitjain bundle
    >- Configures best-practice alerting policies for Google Cloud Vertex AI / Agent Platform agents on Agent Runtime. Use when analyzing, writing, or deploying alerting policies to monitor agent latency, error rates, and quality metrics (response quality, tool use, hallucination). Also use when provisioning online monitors for quality evaluation, or analyzing live metrics traffic footprints. NOTE: This skill currently only works for the Agent Runtime. Don't use for configuring general GCP alert policies or non-agent GCP alerting policies.
    2 repo stars
  50. ▌
    Agent Platform Endpoint Management · thedixitjain
    >- Manages Agent Platform serving endpoints. Use when you need to create, list, describe, update, or delete serving endpoints for model deployment on Agent Platform. Also use when troubleshooting endpoint permission, quota, or resource busy errors. Don't use for deploying models to endpoints or for running model evaluations.
    2 repo stars
  51. ▌
    Autoresearch Agent · thedixitjain bundle
    Autonomous experiment loop that optimizes any file by a measurable metric. Inspired by Karpathy's autoresearch. The agent edits a target file, runs a fixed evaluation, keeps improvements (git commit), discards failures (git reset), and loops indefinitely. Use when: user wants to optimize code speed, reduce bundle/image size, improve test pass rate, optimize prompts, improve content quality (headlines, copy, CTR), or run any measurable improvement loop. Requires: a target file, an evaluation command that outputs a metric, and a git repo.
    2 repo stars
  52. ▌
    Error Debugging Multi Agent Review · thedixitjain
    Use when working with error debugging multi agent review
    2 repo stars
  53. ▌
    Implementing Endpoint Dlp Controls · thedixitjain bundle
    'Implements endpoint Data Loss Prevention (DLP) controls to detect and prevent sensitive data exfiltration through email, USB, cloud storage, and printing. Use when deploying DLP agents, creating content inspection policies, or preventing unauthorized data movement from endpoints. Activates for requests involving DLP, data exfiltration prevention, content inspection, or sensitive data protection on endpoints. '
    2 repo stars
  54. ▌
    Backend Development Feature Development · thedixitjain
    Orchestrate end-to-end backend feature development from requirements to deployment. Use when coordinating multi-phase feature delivery across teams and services.
    2 repo stars
  55. ▌
    Detecting S3 Data Exfiltration Attempts · thedixitjain bundle
    'Detecting data exfiltration attempts from AWS S3 buckets by analyzing CloudTrail S3 data events, VPC Flow Logs, GuardDuty findings, Amazon Macie alerts, and S3 access patterns to identify unauthorized bulk downloads and cross-account data transfers. '
    2 repo stars
  56. ▌
    Detecting SQL Injection Vulnerabilities · thedixitjain bundle
    'Detect and analyze SQL injection vulnerabilities in application code and database queries. Use when you need to scan code for SQL injection risks, review query construction, validate input sanitization, or implement secure query patterns. Trigger with phrases like "detect SQL injection", "scan for SQLi vulnerabilities", "review database queries", or "check SQL security". '
    2 repo stars
  57. ▌
    Performing GRAPHQL Introspection Attack · thedixitjain bundle
    'Performs GraphQL introspection attacks to extract the full API schema including types, queries, mutations, subscriptions, and field definitions from GraphQL endpoints. The tester uses introspection queries to map the attack surface, identifies sensitive fields and mutations, tests for query depth and complexity limits, and exploits GraphQL-specific vulnerabilities including batching attacks, alias-based brute force, and nested query DoS. Activates for requests involving GraphQL security testing, introspection attack, GraphQL enumeration, or GraphQL API penetration testing. '
    2 repo stars
  58. ▌
    Chinese Review Of Financial Studies · thedixitjain
    Use when targeting 《金融评论》(Chinese Review of Financial Studies — 中国社会科学院金融研究所主办、2009 年创刊、不收版面费的金融学术双月刊) or deciding whether a Chinese finance manuscript fits this venue. Encodes the journal's fit, framing, abstract/keyword/JEL house style, citation-quota rule, official ajcass.com submission re-check, and desk-reject heuristics.
    2 repo stars
  59. ▌
    Detecting Business Email Compromise · thedixitjain bundle
    Business Email Compromise (BEC) is a sophisticated fraud scheme where attackers impersonate executives, vendors, or trusted partners to trick employees into transferring funds, sharing sensitive data,
    2 repo stars
  60. ▌
    Journal Of Accounting And Economics · thedixitjain
    Use when targeting Journal of Accounting and Economics (JAE) or deciding whether an accounting manuscript fits this venue. Encodes the journal's fit, framing, method-and-evidence bar, house style, official-submission re-check, and desk-reject heuristics.
    2 repo stars
  61. ▌
    Journal Of Financial Intermediation · thedixitjain
    Use when targeting Journal of Financial Intermediation (JFI) or deciding whether a banking / intermediation manuscript fits this venue. Encodes the journal's fit, framing, method-and-evidence bar, house style, official-submission re-check, and desk-reject heuristics.
    2 repo stars
  62. ▌
    Asian Conference On Machine Learning · thedixitjain
    Use when targeting Asian Conference on Machine Learning (ACML) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for AI/ML regional flagship.
    2 repo stars
  63. ▌
    Analyzing Cloud Storage Access Patterns · thedixitjain bundle
    Detect abnormal access patterns in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics. Identifies after-hours bulk downloads, access from new IP addresses, unusual API calls (GetObject spikes), and potential data exfiltration using statistical baselines and time-series anomaly detection.
    2 repo stars
  64. ▌
    Azure Communication Callautomation Java · thedixitjain bundle
    Build call automation workflows with Azure Communication Services Call Automation Java SDK. Use when implementing IVR systems, call routing, call recording, DTMF recognition, text-to-speech, or AI-powered call flows.
    2 repo stars
  65. ▌
    Azure Monitor Opentelemetry Exporter Py · thedixitjain bundle
    | Azure Monitor OpenTelemetry Exporter for Python. Use for low-level OpenTelemetry export to Application Insights. Triggers: "azure-monitor-opentelemetry-exporter", "AzureMonitorTraceExporter", "AzureMonitorMetricExporter", "AzureMonitorLogExporter".
    2 repo stars
  66. ▌
    Benchmarking Kubernetes With Kube Bench · thedixitjain bundle
    Run CIS Kubernetes Benchmark checks and remediate findings with kube-bench.
    2 repo stars
  67. ▌
    Cloudflare Browser Rendering Automation · thedixitjain
    Automate Cloudflare Browser Rendering tasks via Rube MCP (Composio). Always search tools first for current schemas.
    2 repo stars
  68. ▌
    Detecting Azure Service Principal Abuse · thedixitjain bundle
    Detect and investigate Azure service principal abuse including privilege escalation, credential compromise, admin consent bypass, and unauthorized enumeration in Microsoft Entra ID environments.
    2 repo stars
  69. ▌
    Detecting Compromised Cloud Credentials · thedixitjain bundle
    'Detecting compromised cloud credentials across AWS, Azure, and GCP by analyzing anomalous API activity, impossible travel patterns, unauthorized resource provisioning, and credential abuse indicators using GuardDuty, Defender for Identity, and SCC Event Threat Detection. '
    2 repo stars
  70. ▌
    Detecting Privilege Escalation Attempts · thedixitjain bundle
    Detect privilege escalation attempts including token manipulation, UAC bypass, unquoted service paths, kernel exploits, and sudo/doas abuse across Windows and Linux.
    2 repo stars
  71. ▌
    Detecting Serverless Function Injection · thedixitjain bundle
    'Detects and prevents code injection attacks targeting serverless functions (AWS Lambda, Azure Functions, Google Cloud Functions) through event source poisoning, malicious layer injection, runtime command execution, and IAM privilege escalation via function modification. The analyst combines static analysis of function code, CloudTrail event correlation, runtime behavior monitoring, and IAM policy auditing to identify injection vectors across the expanded serverless attack surface including API Gateway, S3, SQS, DynamoDB Streams, and CloudWatch event triggers. Activates for requests involving Lambda security assessment, serverless injection detection, function event poisoning analysis, or serverless privilege escalation investigation. '
    2 repo stars
  72. ▌
    Google Cloud Waf Operational Excellence · thedixitjain
    >- Generates operations-focused guidance for Google Cloud workloads based on the design principles and recommendations in the Operational Excellence pillar of the Google Cloud Well-Architected Framework (WAF). Use this skill to evaluate a workload, identify operational requirements, and provide actionable recommendations for deployment, monitoring, and incident management.
    2 repo stars
  73. ▌
    Mapping Attack Paths With Bloodhound Ce · thedixitjain bundle
    Collect Active Directory data with SharpHound and Entra ID data with AzureHound, ingest into BloodHound Community Edition, and analyze on-prem, cloud, and hybrid attack paths with built-in queries and custom Cypher.
    2 repo stars
  74. ▌
    Performing Privileged Account Discovery · thedixitjain bundle
    Discover and inventory all privileged accounts across enterprise infrastructure including domain admins, local admins, service accounts, database admins, cloud IAM roles, and application admin account
    2 repo stars
  75. ▌
    Securing Container Registry With Harbor · thedixitjain bundle
    Harbor is an open-source container registry that provides security features including vulnerability scanning (integrated Trivy), image signing (Notary/Cosign), RBAC, content trust policies, replicatio
    2 repo stars
  76. ▌
    Comment Code Generate A Tutorial · thedixitjain
    Transform this Python script into a polished, beginner-friendly project by refactoring the code, adding clear instructional comments, and generating a complete markdown tutorial.
    2 repo stars
  77. ▌
    Folder Structure Blueprint Generator · thedixitjain
    Comprehensive technology-agnostic prompt for analyzing and documenting project folder structures. Auto-detects project types (.NET, Java, React, Angular, Python, Node.js, Flutter), generates detailed blueprints with visualization options, naming conventions, file placement patterns, and extension templates for maintaining consistent code organization across diverse technology stacks.
    2 repo stars
  78. ▌
    Migrate XML Views To Jetpack Compose · thedixitjain bundle
    Provides a structured workflow for migrating an Android XML View to Jetpack Compose. This skill details the step-by-step process, from planning and dependency setup, to theming and layout migration, validation and XML cleanup. Use this skill when you need to migrate an XML View to Jetpack Compose in an Android project. It solves the problem of converting the UI of a legacy XML View into modern, declarative Compose components while maintaining interoperability.
    2 repo stars
  79. ▌
    Technology Stack Blueprint Generator · thedixitjain
    Comprehensive technology stack blueprint generator that analyzes codebases to create detailed architectural documentation. Automatically detects technology stacks, programming languages, and implementation patterns across multiple platforms (.NET, Java, JavaScript, React, Python). Generates configurable blueprints with version information, licensing details, usage patterns, coding conventions, and visual diagrams. Provides implementation-ready templates and maintains architectural consistency for guided development.
    2 repo stars
  80. ▌
    Hunting Bootkits In Efi System Partition · thedixitjain bundle
    Baseline the EFI System Partition and hunt malicious EFI binaries (ESPecter, BlackLotus, Bootkitty, Glupteba) by mounting the ESP, hashing and verifying boot loaders, scanning with YARA, and detecting anomalous non-EFI files.
    2 repo stars
  81. ▌
    Hunting For Living Off The Land Binaries · thedixitjain bundle
    Proactively hunt for adversary abuse of legitimate system binaries (LOLBins) to execute malicious payloads while evading detection.
    2 repo stars
  82. ▌
    Hunting For Process Injection Techniques · thedixitjain bundle
    Detect process injection techniques (T1055) including CreateRemoteThread, process hollowing, and DLL injection via Sysmon Event IDs 8 and 10 and EDR process telemetry
    2 repo stars
  83. ▌
    Validating Tpm Measured Boot Attestation · thedixitjain bundle
    Verify TPM PCRs and measured-boot and remote-attestation integrity.
    2 repo stars
  84. ▌
    Atlassian Templates · thedixitjain bundle
    Atlassian Template and Files Creator/Modifier expert for creating, modifying, and managing Jira and Confluence templates, blueprints, custom layouts, reusable components, and standardized content structures. Use when building org-wide templates, custom blueprints, page layouts, and automated content generation.
    2 repo stars
  85. ▌
    MCP Copilot Studio Server Generator · thedixitjain
    Generate a complete MCP server implementation optimized for Copilot Studio integration with proper schema constraints and streamable HTTP support
    2 repo stars
  86. ▌
    International Conference On 3d Vision · thedixitjain
    Use when targeting International Conference on 3D Vision (3DV) or deciding whether a computer-science manuscript fits this venue. Encodes conference fit, framing, evidence bar, submission-cycle checks, rebuttal posture, and desk-reject risks for 3D vision.
    2 repo stars
  87. ▌
    Java Add Graalvm Native Image Support · thedixitjain
    GraalVM Native Image expert that adds native image support to Java applications, builds the project, analyzes build errors, applies fixes, and iterates until successful compilation using Oracle best practices.
    2 repo stars
  88. ▌
    Analyzing Windows Shellbag Artifacts · thedixitjain bundle
    Analyze Windows Shellbag registry artifacts to reconstruct folder browsing activity, detect access to removable media and network shares, and establish user interaction with directories even after deletion using SBECmd and ShellBags Explorer.
    2 repo stars
  89. ▌
    Hunting For Lateral Movement Via Wmi · thedixitjain bundle
    Detect WMI-based lateral movement by analyzing Windows Event ID 4688 process creation and Sysmon Event ID 1 for WmiPrvSE.exe child process patterns, remote process execution, and WMI event subscription persistence.
    2 repo stars
  90. ▌
    Play Billing Library Version Upgrade · thedixitjain bundle
    Use this skill when upgrading or migrating an Android project from any legacy Google Play Billing Library (PBL) version to the latest stable version of PBL.
    2 repo stars
  91. ▌
    Governance Checklist Generator · thedixitjain
    'Generate governance checklist generator operations. Auto-activating skill for Enterprise Workflows. Triggers on: governance checklist generator, governance checklist generator Part of the Enterprise Workflows skill category. Use when working with governance checklist generator functionality. Trigger with phrases like "governance checklist generator", "governance generator", "governance". '
    2 repo stars
  92. ▌
    Production Scheduling · thedixitjain bundle
    Codified expertise for production scheduling, job sequencing, line balancing, changeover optimisation, and bottleneck resolution in discrete and batch manufacturing.
    2 repo stars
  93. ▌
    China Public Administration Review · thedixitjain
    Use when targeting 《公共管理评论》(China Public Administration Review — 教育部主管、清华大学主办的公共管理学术季刊, 2004 年创刊, 匿名评审) or deciding whether a Chinese public-administration/governance manuscript fits this journal. Encodes the journal's fit, framing, abstract/keyword house style, anonymous-review rules, official-submission re-check, and desk-reject heuristics.
    2 repo stars
  94. ▌
    China Sport Science And Technology · thedixitjain
    Use when targeting 《中国体育科技》(China Sport Science and Technology) — the CSSCI applied/competitive sport-science journal from the China Institute of Sport Science (国家体育总局体育科学研究所), sibling to 《体育科学》. Best for competitive sport, sports training practice, talent identification, physical conditioning, technical/tactical analysis, training-load and physiological/biochemical monitoring, anti-doping, and sports rehabilitation — i.e. application-oriented exercise science. Route theory-heavy or综合 contributions to 《体育科学》, and sport-as-case econ/clinical papers out of sport venues.
    2 repo stars
  95. ▌
    Epsl Reporting And Reproducibility · thedixitjain
    Use when assembling the supplementary material, data-availability statement, and FAIR data deposit for an Earth and Planetary Science Letters (EPSL) manuscript. EPSL follows Elsevier's research-data policies and the community expects deposition in discipline repositories — EarthChem, PANGAEA, IRIS/EarthScope, MagIC, NASA PDS, Zenodo. It guides reporting and deposit; it does not generate the data.
    2 repo stars
  96. ▌
    Ieee Transactions On Power Systems · thedixitjain
    Use when targeting IEEE Transactions on Power Systems (TPWRS) or deciding whether an electric-power-systems manuscript fits this venue. Encodes the journal's fit, the methodology-plus-case-study bar, the standard-test-system expectation, the power-system-vs-power-electronics routing, house style, official-submission re-check, and desk-reject heuristics.
    2 repo stars
  97. ▌
    Joap Open Science And Transparency · thedixitjain
    Use when meeting the Journal of Applied Psychology (JAP) open-science requirements. JAP holds empirical work (including meta-analyses) to the TOP framework — data, materials, and code availability with persistent identifiers, a data-transparency / data-availability statement, and preregistration weighed in evaluation. Prepares compliance; it does not waive requirements.
    2 repo stars
  98. ▌
    Journal Of Agrotechnical Economics · thedixitjain
    Use when targeting 《农业技术经济》(Journal of Agrotechnical Economics — 中国农业技术经济研究会与中国农业科学院农业经济与发展研究所主办、农业农村部主管的农业技术经济月刊, 1982 年创刊, CN11-1883/S, 双向匿名, iaecn.cn 投稿) or deciding whether a Chinese 农业技术/效率 manuscript fits this venue. Encodes the journal's fit, framing, fee/review policy, house style, official-submission re-check, and desk-reject heuristics.
    2 repo stars
  99. ▌
    Journal Of International Economics · thedixitjain
    Use when targeting Journal of International Economics (JIE) or deciding whether an international trade or international macro/finance manuscript fits this venue. Encodes the journal's fit, framing, method-and-evidence bar, house style, official-submission re-check, and desk-reject heuristics.
    2 repo stars
  100. ▌
    Journal Of Wuhan Sports University · thedixitjain
    Use when targeting 《武汉体育学院学报》(Journal of Wuhan Sports University) — a CSSCI comprehensive sport-science journal hosted by Wuhan Sports University, covering sports training & competitive sport, exercise science, and sport humanities & social science with a solid all-round profile. Best for well-evidenced studies across sub-fields without a narrowly specialist home; route history/ethnic-traditional-sport to 成都, strongly theory-led social science to 上海/南京, and applied competitive work to 《中国体育科技》.
    2 repo stars