theheavenlyd3mon
- 1.1k skills
- 0 followers
- 28 repo stars
- 2 weeks ago last updated
- ▌ Performing API Rate Limiting Bypass · theheavenlyd3mon bundleTests API rate limiting implementations for bypass vulnerabilities by manipulating request headers, IP addresses, HTTP methods, API versions, and encoding schemes to circumvent request throttling controls. The tester identifies rate limit headers, determines enforcement mechanisms, and attempts bypasses including X-Forwarded-For spoofing, parameter pollution, case variation, and endpoint path manipulation. Maps to OWASP API4:2023 Unrestricted Resource Consumption. Activates for requests involving rate limit bypass, API throttling evasion, brute force protection testing, or API abuse prevention assessment.
- ▌ Scanning Infrastructure With Nessus · theheavenlyd3mon bundleTenable Nessus is the industry-leading vulnerability scanner used to identify security weaknesses across network infrastructure including servers, workstations, network devices, and operating systems.
- ▌ Scanning Network With Nmap Advanced · theheavenlyd3mon bundlePerforms advanced network reconnaissance using Nmap's scripting engine, timing controls, evasion techniques, and output parsing to discover hosts, enumerate services, detect vulnerabilities, and fingerprint operating systems across authorized target networks.
- ▌ Testing For Sensitive Data Exposure · theheavenlyd3mon bundleIdentifying sensitive data exposure vulnerabilities including API key leakage, PII in responses, insecure storage, and unprotected data transmission during security assessments.
- ▌ Testing Oauth2 Implementation Flaws · theheavenlyd3mon bundleTests OAuth 2.0 and OpenID Connect implementations for security flaws including authorization code interception, redirect URI manipulation, CSRF in OAuth flows, token leakage, scope escalation, and PKCE bypass. The tester evaluates the authorization server, client application, and token handling for common misconfigurations that enable account takeover or unauthorized access. Activates for requests involving OAuth security testing, OIDC vulnerability assessment, OAuth2 redirect bypass, or authorization code flow testing.
- ▌ Analyzing Apt Group With Mitre Navigator · theheavenlyd3mon bundleAnalyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps of adversary TTPs for detection gap analysis and threat-informed defense.
- ▌ Exploiting API Injection Vulnerabilities · theheavenlyd3mon bundleTests APIs for injection vulnerabilities including SQL injection, NoSQL injection, OS command injection, LDAP injection, and Server-Side Request Forgery (SSRF) through API parameters, headers, and request bodies. The tester crafts malicious payloads targeting different backend technologies and injection contexts to extract data, execute commands, or access internal services. Maps to OWASP API8:2023 Security Misconfiguration and API7:2023 SSRF. Activates for requests involving API injection testing, SQLi in APIs, NoSQL injection, SSRF testing, or API input validation assessment.
- ▌ Exploiting Bgp Hijacking Vulnerabilities · theheavenlyd3mon bundleAnalyzes and simulates BGP hijacking scenarios in authorized lab environments to assess route origin validation, RPKI deployment, and BGP monitoring defenses against prefix hijacking and route leak attacks on internet routing infrastructure.
- ▌ Exploiting SQL Injection Vulnerabilities · theheavenlyd3mon bundleIdentifies and exploits SQL injection vulnerabilities in web applications during authorized penetration tests using manual techniques and automated tools like sqlmap. The tester detects injection points through error-based, union-based, blind boolean, and time-based blind techniques across all major database engines (MySQL, PostgreSQL, MSSQL, Oracle) to demonstrate data extraction, authentication bypass, and potential remote code execution. Activates for requests involving SQL injection testing, SQLi exploitation, database security assessment, or injection vulnerability verification.
- ▌ Exploiting Type Juggling Vulnerabilities · theheavenlyd3mon bundleExploit PHP type juggling vulnerabilities caused by loose comparison operators to bypass authentication, circumvent hash verification, and manipulate application logic through type coercion attacks.
- ▌ Performing Bluetooth Security Assessment · theheavenlyd3mon bundleAssess Bluetooth Low Energy device security by scanning, enumerating GATT services, and detecting vulnerabilities
- ▌ Performing Dynamic Analysis With Any Run · theheavenlyd3mon bundlePerforms interactive dynamic malware analysis using the ANY.RUN cloud sandbox to observe real-time execution behavior, interact with malware prompts, and capture process trees, network traffic, and system changes. Activates for requests involving interactive sandbox analysis, cloud-based malware detonation, real-time behavioral observation, or ANY.RUN usage.
- ▌ Performing Initial Access With Evilginx3 · theheavenlyd3mon bundlePerform authorized initial access using EvilGinx3 adversary-in-the-middle phishing framework to capture session tokens and bypass multi-factor authentication during red team engagements.
- ▌ Performing Lateral Movement With Wmiexec · theheavenlyd3mon bundlePerform lateral movement across Windows networks using WMI-based remote execution techniques including Impacket wmiexec.py, CrackMapExec, and native WMI commands for stealthy post-exploitation during red team engagements.
- ▌ Performing Physical Intrusion Assessment · theheavenlyd3mon bundleConduct authorized physical penetration testing using tailgating, badge cloning, lock bypassing, and rogue device deployment to evaluate facility security controls.
- ▌ Performing Privilege Escalation On Linux · theheavenlyd3mon bundleLinux privilege escalation involves elevating from a low-privilege user account to root access on a compromised system. Red teams exploit misconfigurations, vulnerable services, kernel exploits, and w
- ▌ Performing Scada Hmi Security Assessment · theheavenlyd3mon bundlePerform security assessments of SCADA Human-Machine Interface (HMI) systems to identify vulnerabilities in web-based HMIs, thin-client configurations, authentication mechanisms, and communication channels between HMI and PLCs, aligned with IEC 62443 and NIST SP 800-82 guidelines.
- ▌ Auditing AWS S3 Bucket Permissions · theheavenlyd3mon bundleSystematically audit AWS S3 bucket permissions to identify publicly accessible buckets, overly permissive ACLs, misconfigured bucket policies, and missing encryption settings using AWS CLI, S3audit, and Prowler to enforce least-privilege data access controls.
- ▌ Auditing Cloud With Cis Benchmarks · theheavenlyd3mon bundleThis skill details how to conduct cloud security audits using Center for Internet Security benchmarks for AWS, Azure, and GCP. It covers interpreting CIS Foundations Benchmark controls, running automated assessments with tools like Prowler and ScoutSuite, remediating failed controls, and maintaining continuous compliance monitoring against CIS v5 for AWS, v4 for Azure, and v4 for GCP.
- ▌ Detecting AWS Cloudtrail Anomalies · theheavenlyd3mon bundleDetect unusual API call patterns in AWS CloudTrail logs using boto3, statistical baselining, and behavioral analysis to identify credential compromise, privilege escalation, and unauthorized resource access.
- ▌ Securing Container Registry Images · theheavenlyd3mon bundleSecuring container registry images by implementing vulnerability scanning with Trivy and Grype, enforcing image signing with Cosign and Sigstore, configuring registry access controls, and building CI/CD pipelines that prevent deploying unscanned or unsigned images.
- ▌ Analyzing Threat Landscape With Misp · theheavenlyd3mon bundleAnalyze the threat landscape using MISP (Malware Information Sharing Platform) by querying event statistics, attribute distributions, threat actor galaxy clusters, and tag trends over time. Uses PyMISP to pull event data, compute IOC type breakdowns, identify top threat actors and malware families, and generate threat landscape reports with temporal trends.
- ▌ Building Soc Playbook For Ransomware · theheavenlyd3mon bundleBuilds a structured SOC incident response playbook for ransomware attacks covering detection, containment, eradication, and recovery phases with specific SIEM queries, isolation procedures, and decision trees. Use when SOC teams need formalized response procedures for ransomware incidents aligned to NIST SP 800-61 and MITRE ATT&CK ransomware techniques.
- ▌ Conducting Cloud Penetration Testing · theheavenlyd3mon bundleThis skill outlines methodologies for performing authorized penetration testing against AWS, Azure, and GCP cloud environments. It covers understanding the shared responsibility model for testing scope, leveraging cloud-specific attack tools like Pacu and ScoutSuite, exploiting IAM misconfigurations, testing for SSRF to cloud metadata services, and reporting findings aligned to MITRE ATT&CK Cloud matrix.
- ▌ Deploying Edr Agent With Crowdstrike · theheavenlyd3mon bundleDeploys and configures CrowdStrike Falcon EDR agents across enterprise endpoints to enable real-time threat detection, behavioral analysis, and automated response. Use when onboarding endpoints to EDR coverage, configuring detection policies, or integrating Falcon telemetry with SIEM platforms. Activates for requests involving CrowdStrike deployment, Falcon sensor installation, EDR policy configuration, or endpoint detection and response.
- ▌ Deploying Software Defined Perimeter · theheavenlyd3mon bundleDeploy a Software-Defined Perimeter using the CSA v2.0 specification with Single Packet Authorization, mutual TLS, and SDP controller/gateway configuration to enforce zero trust network access.
- ▌ Fal AI Generation · theheavenlyd3mon bundleGenerate images, video, and audio via fal.ai Model APIs directly using the user's FAL_KEY — model selection, sync/queue call pattern, LoRA endpoints, pricing. Use when the built-in image_generate tool (gateway-pinned to FLUX 2 Klein) is a poor fit for the brief, when the user asks for a specific fal.ai model, or for anime/stylized/LoRA/upscale/background-removal work on fal.ai.
- ▌ Doc Review · theheavenlyd3monReview working documents (character sheets, worldbuilding, planning notes, outlines) for filler, fluff, and content that doesn't earn its place. Use before locking any vault file. Catches performative casualness, over-explanation, and writing that entertains the writer instead of informing the reader.
- ▌ Hermes Version Summary · theheavenlyd3monDeliver Hermes agent version and update summaries in concise list format. Governs how to answer "what are the new updates" questions — structured, scannable, with clear section separation.
- ▌ Safe Web Research · theheavenlyd3mon bundleSafe web scraping and research: detect and neutralize prompt injection, code injection, and content-based attacks in scraped web content before it enters the agent's context.
- ▌ Build In Public · theheavenlyd3mon bundleBuild-in-public X (Twitter) growth strategy using Hermes as an autonomous content engine — profile design, VPS deployment, content pipeline, engagement cadence, and X Premium tier guidance for indie hackers.
- ▌ API Design And Evolution · theheavenlyd3mon bundleDesign, document, review, and evolve consumer-facing APIs and event interfaces. Use when choosing REST/HTTP, GraphQL, RPC, events, webhooks, or streaming; writing OpenAPI or AsyncAPI contracts; defining schemas, pagination, mutations, errors, idempotency, or API compatibility; or planning API versioning, deprecation, and migration. Use secure-software-engineering for a full security lifecycle, ADR authoring for durable architecture decisions, and spec-driven-development for a delivery specification and implementation gates.
- ▌ Opensource Contributions · theheavenlyd3mon bundleMake good open source contributions — check CONTRIBUTING.md first, follow project norms, be a good citizen. Covers bug reports, feature requests, and pull requests with a defensible default posture when the project hasn't documented expectations.
- ▌ Verification Methodology · theheavenlyd3mon bundleVerify work against explicit criteria using direct, source-faithful evidence, reproducible checks, and clear verdicts. Use before declaring an artifact, implementation, or claim complete; do not use for exploratory research without pass/fail criteria.
- ▌ Blender Automation · theheavenlyd3mon bundleConnect Blender to Hermes via MCP — 3D modeling, scene manipulation, batch operations, and asset generation through natural language.
- ▌ T3mp3st · theheavenlyd3monOperate, explain, review, and deploy T3MP3ST-class offensive-security meta-harnesses: multi-agent red-team automation with a local-agent brain, arsenal wrappers, scope gating, War Room UI, and reproducibility checks. Use when the task involves T3MP3ST setup, architecture review, agent-loop wiring, scope enforcement, benchmark verification, or beginner-friendly red-team explanations.
- ▌ Lesson Review Audio · theheavenlyd3mon bundleUse when reviewing a past lesson to read aloud via TTS.
- ▌ Resilience And Recovery · theheavenlyd3mon bundleDesign, exercise, and evidence graceful degradation, disaster recovery, and restoration behavior across systems and dependencies. Covers failure-mode analysis, RTO/RPO decision records, restore testing, game days, failover drills, data integrity verification, and recovery communication. Do not use for live incident command or incident response; route to site-reliability-engineering for those. Do not use for infrastructure implementation details; route to platform-engineering.
- ▌ Vault Revamp Katman · theheavenlyd3monHow to complete a kanban-driven Unreal Engine/Obsidian vault revamp task safely and unitarily across the category notes.
- ▌ Youtube Batch Extraction · theheavenlyd3mon bundleBatch extraction pipeline for multiple YouTube playlists — URL discovery, rate-limited web_extract, checkpoint/resume, cron scheduling, retry logic.
- ▌ Qwen Mm Plugins Omni Av · theheavenlyd3monOmni-model audio/video understanding MCP tools: segmented captioning with timestamps, ASR (plain / controllable-granularity / multi-speaker diarized), temporal grounding (locate a segment by text query), and event/action counting. Use for questions about WHAT is said/happens in an audio or video file and WHEN, on clips up to a few minutes.
- ▌ Research Methodology · theheavenlyd3mon bundlePlan, conduct, evaluate, and synthesize rigorous research. Use for journalistic, industry, or technical investigations that need credible evidence and a traceable method.
- ▌ Flux3 Video Directing · theheavenlyd3mon bundleUse when writing or critiquing FLUX 3 video prompts.
- ▌ On Device Iphone LLM · theheavenlyd3monRun quantized LLMs natively on iPhone/iPad — MLX vs GGUF sizing, mlx-swift kernel forks, phone RAM budgets, and the Xcode sideload flow.
- ▌ Qwen Mm Plugins Blender · theheavenlyd3monUse whenever a task involves building or editing a 3D scene or asset in Blender — modeling, characters/people, architecture/interiors, terrain/landscapes, props, materials, lighting, or rendering. Covers discovering installed add-ons, using generators, importing and REFINING ready-made assets, and matching the result to the spec. Requires a running Blender instance with the blender-mcp addon (see Prerequisite).
- ▌ Qwen Mm Plugins Freecad · theheavenlyd3monUse whenever a task involves parametric CAD in FreeCAD — modeling parts and assemblies, editing object properties, technical drawings, importing/exporting STEP/STL/OBJ/DXF, PDF/Excel reports from a model, or finite-element (FEM/CalculiX) analysis. Requires a running FreeCAD instance with the FreeCADMCP addon (see Prerequisite).
- ▌ AI Video Generation · theheavenlyd3mon bundleAI video generation: prompt engineering, model selection, and platform integration (Higgsfield, Flux 3, Runway, etc.). Six-part prompt structure, camera/lighting vocabulary, model routing, MCP automation, Flux 3 reasoning-harness techniques.
- ▌ Suno Music Creation · theheavenlyd3mon bundleGenerate Suno-ready style prompts, lyrics, and DSL energy arcs from a user brief. Supports RIVEN (trap soul/dark R&B male — J. Cole × Drake × Kid Laroi × Bryson Tiller) and SOLA (alt-R&B/neo-soul female — Kehlani × SZA × Ella Mai × Summer Walker × Billie Eilish) artist identities.
- ▌ Open Source Research · theheavenlyd3mon bundleSystematically research, evaluate, and extract insights from open-source projects (GitHub repos, docs sites, community resources). Multi-tool deep-dive: README → subdirectories → external docs → synthesis.
- ▌ Trifecta Tailscale Setup · theheavenlyd3monTrifecta + Tailscale setup — always-on mobile access to Hermes agent via private mesh network.
- ▌ Memory Curator · theheavenlyd3mon bundleAutomated memory curation: monitors Obsidian notes/, triggers moves/promotions, handles archiving. Works with Mnemosyne (hot layer), Icarus (operational), and llm-wiki (curated). One component of a five-layer memory stack (Mnemosyne, Fabric, LLM-Wiki, Obsidian, Skills).
- ▌ Team Wiki Research Pipeline · theheavenlyd3mon bundleResearch pipeline worker for the wiki: ingest weekly findings files, apply threshold/duplicate/contradiction rules, create or update wiki pages with researcher frontmatter, and batch-update index and log.
- ▌
- ▌ Visual Character Design · theheavenlyd3mon bundleBuild art-ready visual character profiles from character sheets. Specific enough to draw from or feed to image models. Includes humanizer pass for visual-specific AI tells.
- ▌ Domain Detection Routing · theheavenlyd3monAuto-detect task domain from user message and route to correct Hermes profile via delegate_task.
- ▌ Hermes Directory Cleanup · theheavenlyd3mon bundleInspect, audit, and safely clean up the ~/.hermes directory to remove orphaned pre-profile data and prune per-profile skill bloat without breaking running agents.
- ▌ Hermes Feature Education · theheavenlyd3mon bundleEducate users on Hermes Agent features they may not know about — feature discovery, organized walkthroughs, CLI reference, system capabilities, and depth progression. Use when a user asks "teach me hermes features", "what can you do", "what features am I not using", or similar onboarding/feature-discovery questions.
- ▌ Hermes Profile Migration · theheavenlyd3mon bundleExecute a multi-profile Hermes migration — create profiles, deploy SOUL.md, seed skills, pin critical skills, remap cron, update Discord, restart gateway. Covers rollback strategy and validation.
- ▌ Hermes Voice Diagnostics · theheavenlyd3mon bundleDiagnose and verify the Hermes voice pipeline (STT mic → transcription, TTS replies) end-to-end on macOS — provider resolution, the Nous managed-gateway fallback, definitive self-tests without a human speaker, and TUI voice-mode gotchas.
- ▌ Hermesmirror Maintenance · theheavenlyd3mon bundleRecurring review / maintenance / upkeep lifecycle for the HermesMirror project (a MagicMirror² fork with deep Hermes Agent integration). Covers establishing ground truth across the local PC clone and the GitHub fork, the security audit of the two standalone Python API plugins + the bridge, npm vulnerability remediation with a force-caution, and reconciling the AGENTS.md build plan against git reality. Use when the user says "review hermesmirror", "maintenance on the mirror", "upkeep", "check for vulnerabilities", "go back over the build plan", or any periodic health pass on the project.
- ▌ Llms Txt Mirroring · theheavenlyd3mon bundleUse when bulk-pulling llms.txt knowledge bases to markdown.
- ▌ Video Editing And QA · theheavenlyd3mon bundleUse when assembling/reviewing clips into a finished edit.
- ▌ Config Consistency Review · theheavenlyd3mon bundleSystematic review for orphaned services, duplicate processes, stale config files, and other state inconsistencies left behind by profile migrations, gateway setup changes, or config consolidation. Run after any config migration or when troubleshooting unexpected behavior like "gateway shutting down" loops.
- ▌ Multi Agent Orchestration · theheavenlyd3mon bundleComplete multi-agent orchestration system — Kanban decomposition playbook for task graph creation + autonomous Foreman cron loop for execution, retry cycles, and escalation. Covers the full lifecycle from goal decomposition through worker dispatch to project completion.
- ▌ Open Knowledge Format · theheavenlyd3mon bundleGoogle's Open Knowledge Format (OKF) v0.1 — an open, vendor-neutral spec for representing knowledge as markdown files with YAML frontmatter, designed for AI agent consumption. Use when the user mentions OKF, Open Knowledge Format, Google's knowledge format, LLM wiki bundles, agent knowledge packs, creating OKF bundles, validating OKF documents, or converting knowledge into the OKF standard.
- ▌ Book Pipeline · theheavenlyd3mon bundleDesign and run an AI-assisted long-form fiction pipeline that turns small story ideas into publishable short novels / audiobooks. Covers the book-writer profile architecture, specialist-profile delegation lanes, manuscript folder convention, and the draft→review→revise→export loop. Use when the user wants to mass-produce books via Hermes, build a book-writer agent, or automate novel/audiobook production.
- ▌ Pre Commit Security Checklist · theheavenlyd3monRun before committing code. Catches mistakes Katana can't — secrets in code, missing validation, weak auth, debug leftovers.
- ▌ Desktop Plugin Conversion · theheavenlyd3mon bundleAudit agent plugins for Hermes Desktop conversion.
- ▌ Discord Server Management · theheavenlyd3mon bundleOrganize a Hermes multi-bot Discord server — categories, channel permissions, bot response modes, free_response_channels, channel_prompts, and api_server port discipline. Use when the user asks about Discord server layout, per-bot categories, how bots respond, or where messages go.
- ▌ Hermes Profile Publishing · theheavenlyd3mon bundlePackage Hermes profiles for public sharing — sanitize personal info, create per-profile READMEs, build repo structure, handle third-party skill licensing, and push to GitHub. Use when the user says "share my profiles", "publish profiles to GitHub", "make a profile repo", or "clean profiles for public use".
- ▌ Hermes Security Hardening · theheavenlyd3mon bundleComprehensive security hardening for Hermes installations — fixes permissions, sets up secret scanning, configures macOS Keychain integration, creates security policies, and installs pre-commit hooks.
- ▌ Qwen Mm Plugins Edu Agent · theheavenlyd3mon bundleGenerate step-by-step math problem-solving tutorial videos in Chinese (Mandarin). Use when: (1) a user provides a math problem and wants an explanation video, (2) someone says "make a math tutorial", "explain this equation", "create a teaching video for this problem", "讲解这道题", "生成解题视频", (3) the user wants a Chinese-language math lesson covering formulas, equations, or geometric figures, (4) the user shares a math problem in text or LaTeX and asks for a video walkthrough, (5) the input is an image_assets/ folder containing problem images — the skill will extract the problem via visual recognition, solve it, and generate a tutorial video. Teaching components are rendered as realistic objects (solid opaque panels, 3D cards, SVG figures) with a modern aurora mesh aesthetic.
- ▌ Secure Software Engineering · theheavenlyd3mon bundleUse when designing or implementing software securely: define security requirements, threat-model a feature, choose secure defaults, design authentication and authorization, handle untrusted data and secrets, evaluate dependencies, or review security-sensitive changes. Use for prevention during requirements, design, implementation, and review; not for post-build security assessments or scanning an existing codebase.
- ▌ Image Vision Analysis · theheavenlyd3mon bundleVision fallback: describe images via OpenRouter gpt-4o-mini.
- ▌ Nvidia Nim Expert · theheavenlyd3mon bundleExpert guidance for using NVIDIA NIM (NVIDIA Inference Microservices) — cloud-hosted AI models via OpenAI-compatible API. Covers environment setup, model discovery, API usage, local NIM deployment, and integration patterns.
- ▌ Terminal Web Research · theheavenlyd3mon bundleWeb research via curl when web tools are unavailable.
- ▌ X Content Extraction · theheavenlyd3mon bundleRecover and review content from X/Twitter links — especially long-form X Articles (x.com/i/article/ID) and gated posts — when the normal web tools fail, and review promotional X articles for affiliate/funnel framing. Use whenever the user drops an x.com link, says "review this article on X", or asks to read an X post/thread that web_extract or Firecrawl can't reach.
- ▌ Yc Weekly Growth Compass · theheavenlyd3mon bundlePaul Graham's "Startup = Growth" framework as an operational tool. Computes weekly growth rates, benchmarks against YC tiers (1% concerning, 5-7% good, 10%+ exceptional), projects compound growth over time, and frames every startup decision through the question "does this serve your target growth rate?" Ships a deterministic CLI calculator. Load when founders ask about growth rate, weekly growth, startup traction, metrics, or whether they're moving fast enough.
- ▌
- ▌ Oracle Analyst · theheavenlyd3mon bundleOracle's market analysis playbook — gather data from multiple sources, produce structured briefs with probability framing, separate analysis from advice.
- ▌ Trade Tracking · theheavenlyd3mon bundleTrack trade profitability with automatic logging to Obsidian or Notion. Simple CLI for adding/closing trades, auto-generates notes with PnL and win rate metrics.
- ▌ Technical Documentation · theheavenlyd3mon bundleCreate and review technical documentation, including READMEs, agent-facing instructions, API references, and CLI help. Use when documentation must help someone complete real work.
- ▌ File Organization · theheavenlyd3monOrganize messy directories — deduplicate files, normalize naming, clean junk, restructure folders. Use when the user says 'clean up', 'organize', 'deduplicate', or 'restructure' a folder of files.
- ▌ Notion Task Inbox · theheavenlyd3monManage the Notion Task Inbox — create tasks from GitHub, chat, Obsidian, and manual entry. Central triage point.
- ▌ Local Model Agent Evaluation · theheavenlyd3mon bundleEvaluate local LLMs for agent/coding tasks — BenchLoop harnesses, coding agent selection, tool-calling format matching, and community-tested setups.
- ▌ Hermes Model Config · theheavenlyd3mon bundleDiagnose and fix Hermes model configuration issues — context length display errors, provider setup, custom_providers overrides, and model ID verification. Use when model picker shows wrong context length, provider endpoints fail, or you need to add new models to Hermes configuration.
- ▌ Supply Chain Hardening · theheavenlyd3mon bundleLayered defense against npm/PyPI supply chain attacks: install-time guards, CI/CD hardening, automated dependency audits, and incident response. Auto-triggers on relevant operations.
- ▌ Hermes Multi Profile Config · theheavenlyd3mon bundleMulti-profile Hermes configuration management — standardize configs across profiles while preserving intentional per-profile overrides.
- ▌
- ▌ Brand Review Content · theheavenlyd3mon bundleReview a content draft (X post, thread, LinkedIn post, blog, email) against brand voice and authenticity standards before it ships. Flags AI-isms, corporate jargon, unsubstantiated claims, manufactured stakes, and voice inconsistencies. Provides severity-rated findings with before/after fixes. Use after drafting and before posting.
- ▌ Content Asset Triage · theheavenlyd3mon bundleTriage a folder of AI assets into tiers before drafting.
- ▌ X Landscape Research · theheavenlyd3mon bundleUse when researching X trends or creating content calendars.
- ▌ Oracle Aitrader · theheavenlyd3mon bundleAI-Trader platform integration — register agent, publish signals, copy-trade, browse signal feed. Requires AI_TRADER_API_KEY or email registration.
- ▌ Site Reliability Engineering · theheavenlyd3mon bundleDesign, operate, and improve reliable production systems with SLOs, incident command, observability, error budgets, and operational practices.
- ▌ Qwen Mm Plugins Video Memory · theheavenlyd3mon bundleTriggered for long videos (30+ minutes), whether a single file or a directory of multiple videos. Vision-language MCP tools designed for efficient reading and semantic analysis of long videos (30+ minutes), supporting memory construction and semantic search.
- ▌ Hermes MCP Profile Isolation · theheavenlyd3monAdd/configure MCP servers under Hermes profile isolation — the root cause of "MCP server configured but not showing up" when using non-default profiles.
- ▌ Multi Agent Profile Redesign · theheavenlyd3mon bundleDesign, plan, and implement a multi-profile Hermes Agent fleet — domain-based architecture, SOUL.md at scale, Kanban coordination, bot assignment, skill curation, and phased migration.
- ▌ Unreal Obsidian Vault Update · theheavenlyd3mon bundleUpdate and release the UE5 Obsidian vault (Unreal-Engine-Obsidian) — research, extract, format, review, changelog, version tag, GitHub release.
- ▌ Ponytail Audit · theheavenlyd3mon bundleAudit a code surface (module, package, integration, CLI, MCP/tool layer) for over-engineering and missing capabilities using the user's "Ponytail lens" (minimalist / xkcd-Ponytail engineering ethos: YAGNI, delete dead code, reuse in-codebase, kill duplication). Trigger when the user says "audit X for over-engineering / missing capabilities", "review under Ponytail lens", "find bloat / gaps in <module>", or asks to slim down or gap-check an integration, importer set, CLI, or tool surface. Produces a ranked report of delete-or-simplify items, genuine gaps with implementation plans, and a top-3 priority list.
- ▌ Markdown Corpus Digest · theheavenlyd3monUse when reading a Markdown corpus to write one digest file.