VincentChuWaiChow
- 760 skills
- 0 followers
- 8 hours ago last updated
- ▌ Provider Skill Name · vincentchuwaichow bundleUse this skill for a specific cloud workflow. Mention provider, trigger phrases, expected inputs, and when not to use it.
- ▌ Legal Counsel Review · vincentchuwaichow bundleUse this skill when reviewing legal, contractual, regulatory, privacy, litigation, compliance, or risk-governance questions for an enterprise legal function. Trigger when a user provides a contract excerpt, a policy, a compliance question, a privacy-risk question, or a legal intake item and wants risks, evidence gaps, decision options, and escalation paths surfaced. This skill is an adversarial risk-review discipline; it does not provide legal advice, form an attorney-client relationship, or issue binding legal conclusions.
- ▌ Netsuite Suitecloud Developer Skill · vincentchuwaichow bundleStatic-review flashlight for NetSuite SuiteCloud Development Framework projects and SuiteScript 2.x code. Adapts the Oracle netsuite-suitescript-upgrade upstream skill (UPL-1.0, Copyright (c) 2019, 2023 Oracle and/or its affiliates) with Vanguard-specific CI gate thresholds and CHANGELOG conventions. Reviews SDF object XML, deployment manifests, SuiteScript entry points, custom record definitions, and SuiteApp packaging. TRIGGER when: user asks to review SDF project structure, audit SuiteScript 2.x code, assess SuiteScript 1.0 or 2.0 upgrade readiness, review a Suitelet or RESTlet design, inspect custom record definitions, review SuiteApp manifest configuration, or score SuiteScript migration complexity. Trigger phrases: SDF review, SuiteScript upgrade, SuiteScript 2.1, custom record design, Suitelet review, SuiteApp packaging, SDF manifest. DO NOT TRIGGER when: the question is about SDF DevOps release pipeline or CI/CD (use netsuite-sdf-devops-release-agent), OWASP SuiteScript security review (use netsuite-s
- ▌ Netsuite Suiteflow Automation Skill · vincentchuwaichow bundleFlashlight skill for static review of SuiteFlow workflow designs in NetSuite — state machine correctness, condition logic, approval routing, action configuration, trigger alignment, and run-as role least-privilege posture. T0 static review — no live account connection required. TRIGGER when: user submits a SuiteFlow workflow definition for review, asks about workflow state machine design, condition logic coverage, approval routing configuration, workflow action correctness, trigger event alignment, or run-as role permissions for a workflow. Trigger phrases: SuiteFlow review, workflow state machine, approval routing workflow, workflow condition logic, workflow action review, trigger configuration workflow, workflow run-as role, SuiteFlow design. DO NOT TRIGGER when: request involves activating, enabling, or changing workflow status in any environment (escalate to netsuite-live-org-mutation-guard-agent — NEVER activate workflows live); SuiteScript code security within workflow-called scripts (use netsuite-suite
- ▌ Nvidia Cuda Kernel Performance Review · vincentchuwaichow bundleUse this skill when reviewing CUDA C/C++ kernel sources statically against NVIDIA's published performance guidance — global-memory coalescing, shared-memory bank conflicts, warp divergence, occupancy and register pressure, stream/event concurrency, kernel launch parameter selection. Trigger when the user asks whether a `.cu` or `.cuh` file follows NVIDIA's published performance and correctness guidance, or asks for the exact `nsight-compute` or `nsight-systems` invocation to run themselves.
- ▌ Nvidia Tensorrt LLM Deployment Review · vincentchuwaichow bundleUse this skill when reviewing TensorRT or TensorRT-LLM deployment artifacts statically — ONNX/PyTorch export pipelines, precision selection (FP16/BF16/INT8/FP8/INT4), calibration cache integrity, dynamic shape profiles, custom plugin loading, engine cache and serialized engine provenance, runtime memory pool sizing. Trigger when the user asks whether a TensorRT build script, calibration pipeline, or trtexec invocation follows NVIDIA's published guidance.
- ▌ Salesforce Apex Test Runner Skill · vincentchuwaichow bundleExecutes Apex tests against a connected SANDBOX org via sf apex run test, parses results and coverage delta, identifies failures with stack traces, and suggests fixes. T1 read-only runtime (sandbox-only). Production org targets are HARD REFUSED before any API call. TRIGGER when: user wants to run Apex tests, execute a test class, check test coverage, diagnose test failures, or validate coverage before deployment. Trigger phrases: run apex tests, execute test class, test my changes, check test coverage, why is my test failing. DO NOT TRIGGER when: user needs to generate test classes (use salesforce-apex-test-generator-skill), debug without running tests (use salesforce-apex-log-analyzer-skill), static code review of test code (use salesforce-apex-lwc-code-review-skill), or user needs a deployment (use salesforce-deployment-validator-skill).
- ▌ Salesforce Metadata Fetcher Skill · vincentchuwaichow bundleFetches Salesforce metadata (objects, fields, flows, validation rules, permission sets, profiles, Apex classes/triggers, Lightning components) live from a connected org under T1 least-privilege scope (api + refresh_token only, no ModifyMetadata grant — uses sf org list metadata and REST describe endpoints requiring only View Setup and Configuration). Sanitizes output (redacts org IDs, user IDs, hardcoded values) and feeds downstream review skills: salesforce-metadata-review-skill, salesforce-flow-automation-review-skill, salesforce-permission-model-review-skill, salesforce-apex-lwc-code-review-skill. TRIGGER when: user asks to fetch metadata live, retrieve object schema, list flows, list permission sets, retrieve Apex classes, fetch validation rules, or wants live org schema rather than pasting XML. Trigger phrases: fetch metadata, retrieve from org, show me the schema, list my flows, get object describe, pull validation rules from prod. DO NOT TRIGGER when: only data records are needed (use salesforce-soql-e
- ▌ Sap AI Core Generative AI Hub Governance · vincentchuwaichow bundleGovernance review for SAP AI Core, AI Launchpad, and Generative AI Hub deployments. Assesses model access control, data privacy for RAG pipelines and embeddings, prompt-injection risk in orchestration configurations, grounding data classification, prompt-log handling, and auditability of AI outputs. Does not run models or access production AI deployments.
- ▌ Sap Datasphere Data Product Architecture · vincentchuwaichow bundleSAP Datasphere Data Product Architecture Review
- ▌ Scaleway Live Kapsule Rollout Guard · vincentchuwaichow bundleGate and execute Scaleway Kapsule live mutations — Kubernetes version upgrades, node pool creation/deletion/scaling, and cluster configuration changes — with mandatory PDB audit, cluster health verification, explicit approval, and a documented rollback plan. Use when a live Kapsule cluster or node pool mutation is requested. Hard-stops when target cluster ID, region/zone, approval, or rollback plan is absent or ambiguous.
- ▌ Sigstore Cosign Supply Chain Review · vincentchuwaichow bundleUse this skill when reviewing Sigstore Cosign supply chain security for Kubernetes workloads. Trigger when the user asks whether images are properly signed, whether Kyverno imageVerify policy is correctly scoped, whether SLSA provenance attestations exist, whether SBOM attestations are present, whether keyless signing is in use, or whether Rekor transparency log posture is appropriate for private images.
- ▌ Snowflake Identity Access Security · vincentchuwaichow bundleUse this skill to review Snowflake identity and authorization: effective access across role hierarchy, ownership and future grants; custom, database, and application role choice; managed access schemas; authentication policies, MFA, SSO, SCIM, OAuth, key-pair, and workload identity federation; SERVICE and SERVICE_AGENT user types; and concrete privilege-escalation paths. Trigger on any question about who can do what in a Snowflake account, or how a principal proves identity. Static review only: it never executes a grant, never alters a user, and never accepts a credential.
- ▌ Consolidation Intercompany Advisor · vincentchuwaichow bundleMulti-jurisdiction consolidation scope and intercompany elimination reference framework covering ASC 810 / IFRS 10 control models, VIE (Variable Interest Entity) primary beneficiary analysis, NCI measurement, equity method accounting (ASC 323 / IAS 28), intercompany eliminations (sales, profit-in-inventory, debt, interest, dividends), deferred tax on IC eliminations (ASC 740 / IAS 12), and adversarial group reporting scenarios across US GAAP, IFRS, German HGB, JGAAP, CAS, and Ind AS.
- ▌ Alibaba Live Cost Budget Action Guard · vincentchuwaichow bundleGate live financial authority actions — budget threshold changes, Savings Plan purchases, and Reserved Instance commitments. These are committed spend or can trigger immediate service suspension.
- ▌ AWS Daily Operations Briefing Coordinator · vincentchuwaichow bundlePrepare AWS daily operations briefings using CloudWatch, Personal Health Dashboard, Trusted Advisor, cost signals, deployment timelines, incidents, risks, and action backlog. Prefer this for non-destructive business and engineering status coordination; prefer observability, cost, or incident skills for deeper domain investigation.
- ▌ Azure Cosmosdb Performance Investigator · vincentchuwaichow bundleAzure Cosmos DB Performance Investigator
- ▌ Azure Private Endpoint Adoption Planner · vincentchuwaichow bundleAzure Private Endpoint Adoption Planner
- ▌ Cert Manager Issuer Trust Review · vincentchuwaichow bundleUse this skill when reviewing cert-manager PKI configuration for Kubernetes clusters. Trigger when the user asks about Issuer or ClusterIssuer scope, CertificateRequestPolicy coverage, certificate SAN or duration risks, trust-manager bundle distribution, SPIFFE mesh CA integration, cert-manager webhook health, or cloud CA authentication method.
- ▌ Contabo Live Instance Lifecycle Guard · vincentchuwaichow bundleLive-guard skill for Contabo VPS and VDS lifecycle operations including instance creation with product selection and region, reinstallation with image and Cloud-Init userData, and cancellation. Requires mandatory contract period acknowledgment (1, 3, 6, or 12 months), billing impact confirmation, and a rollback plan before any mutation. Hard-stops any lifecycle action that lacks explicit period acknowledgment or rollback documentation.
- ▌ Contabo Live Storage Operations Guard · vincentchuwaichow bundleLive-guard skill for Contabo Object Storage (S3-compatible) bucket operations including inventory audit, access policy review, retention policy enforcement, and deletion workflows. Hard-stops any bucket deletion requested without verified backup evidence and a documented rollback plan. Use when the user needs to manage, audit, or delete Contabo Object Storage buckets or objects.
- ▌ Databricks Data Protection Privacy · vincentchuwaichow bundleUse this skill to review Databricks data protection and privacy design for regulatory alignment and least-privilege enforcement: row filters and column masks, ABAC policies, data classification, deletion and GDPR erasure mechanics, Delta Sharing egress, residency and Geo constraints, and customer-managed encryption. Reads schemas, mask/filter definitions, classification results, sharing configs, and encryption settings only; never executes masks or deletes data.
- ▌ Databricks Genai Agent Engineering · vincentchuwaichow bundleUse this skill to review generative-AI agent design on Databricks: Mosaic AI Agent Framework and ResponsesAgent interface, Databricks AI Search index variant and sync-mode choice, retrieval and context engineering, MCP server category and trust boundaries, external model-provider selection, and Unity AI Gateway policy. Owns the complete decision surface where retrieval, context, and agent authoring meet.
- ▌ Frontend Finops Cost To Serve Review · vincentchuwaichow bundleBuild a cost-to-serve model covering CDN egress, SSR/edge compute, image transformation, and CI build-minute spend for a frontend surface, and rank remediation options by dollar savings weighed against Core Web Vitals and security impact, without treating cost-cutting and security/performance as unrelated trade-offs.
- ▌ Service Worker Cache Strategy Review · vincentchuwaichow bundleReviews service-worker route-matching and caching-strategy choices (precache vs. cache-first vs. network-first vs. stale-while-revalidate) against request type and security sensitivity, rejecting uniform blanket strategies and flagging authenticated/PII responses cached in the Cache API.
- ▌ GCP Daily Operations Briefing Coordinator · vincentchuwaichow bundleCoordinate the daily GCP operations standup — cost delta from previous day, quota warning review, failed deployment detection, Security Command Center finding triage, SLO burn rate alert review, and action item assignment.
- ▌ Huawei Cce Container Platform Operator · vincentchuwaichow bundleOperate Huawei CCE (Cloud Container Engine) Kubernetes clusters, SWR container image registry lifecycle, ASM service mesh traffic policies, and IEF edge node management for cloud-native and hybrid workloads.
- ▌ Huawei Serverless Production Readiness · vincentchuwaichow bundleReview FunctionGraph production readiness on Huawei Cloud — VPC access configuration, concurrency limits and reserved instances, cold-start optimization, observability via LTS and AOM, timeout configuration, dependency package size, custom vs managed runtimes, and ServiceStage application lifecycle.
- ▌ Java Deserialization And Parser Security · vincentchuwaichow bundleUse this skill when statically reviewing the JVM's untrusted-deserialization and data-parsing surface for remote-code-execution and injection risk — Java native ObjectInputStream gadget chains (and the ObjectInputFilter/JEP 290 control), SnakeYAML bare Constructor, Jackson polymorphic default typing without a PolymorphicTypeValidator, XML external-entity (XXE) exposure across every parser factory, and reflective/expression sinks fed by untrusted input. Trigger when a user provides code that deserializes bytes or parses YAML/JSON/XML from a request, message, uploaded file, or external API, or asks whether a parser is safe. Reads source and sanitized configuration only; it never executes code or deserializes a payload.
- ▌ Kotlin Android Performance Reliability · vincentchuwaichow bundleUse this skill to statically review measured Android runtime performance and reliability evidence: cold/warm startup via StartupTimingMetric and CompilationMode, frame jank via FrameTimingMetric/JankStats against the 60fps budget, Baseline Profile coverage, ANR root-causing against the main-thread-blocking threshold, and Macrobenchmark P50/P90/P99 regression-gating. Reads benchmark reports and source only; it never runs a benchmark or instruments a device.
- ▌ Marketing Pixel Data Leakage Review · vincentchuwaichow bundleUse this skill when reviewing advertising pixels and event-tracking for personal-data leakage to third-party ad networks. Trigger when a user provides a tag-manager container, a Meta/TikTok/Google/LinkedIn pixel snippet, a conversion-event payload, a dataLayer specification, or asks whether their tracking pixels leak email, phone numbers, health, or financial data to ad platforms, or whether pixels on sensitive pages create a breach or HIPAA exposure.
- ▌ Copilot Studio Agent Governance Alm · vincentchuwaichow bundleReview Microsoft Copilot Studio agent governance and application lifecycle management health including authentication configuration, DLP policies for connectors and actions, environment strategy, solution-based ALM across dev/test/prod, content moderation, analytics and telemetry, human-handoff and approval boundaries, sharing and publishing controls, and compliance posture via Microsoft Purview. Use to detect ungoverned agent publishing, overly permissive connector grants, absent DLP enforcement, and missing ALM discipline. Static review only; broad publishing and connector grants are live-guard gated.
- ▌ D365 Live Record Field Update Guard · vincentchuwaichow bundleMutating-runtime live-guard for updating one or more named fields on a single Dataverse row identified by table and record GUID, via the Dataverse Web API PATCH (data plane). Strictly scoped — one record, named fields only. Requires explicit written human approval token referencing the exact target, proposed change, and blast-radius. PREFLIGHT performs a dry-run diff before any write. Fully reversible — prior field values are captured and the inverse PATCH is the rollback. Gate-only; never auto-dispatched. Phase B mutating-runtime.
- ▌ M365 Teams Collaboration Governance · vincentchuwaichow bundleReview and advise on Microsoft Teams collaboration and communications governance covering Teams and Microsoft 365 group lifecycle and sprawl, external access and guest sharing controls, sensitivity labels on Teams and groups, meeting and messaging policies, phone and voice governance, and app permission policies. Cert anchor MS-700 Teams Administrator. Static review and advisory only; tenant-wide external-access or sharing-policy changes are live-guard gated. Refuses to weaken guest sharing or external access controls for convenience.
- ▌ Netsuite Application Developer Skill · vincentchuwaichow bundleReviews NetSuite SuiteScript 2.x code, SuiteFlow workflows, SuiteBuilder customizations, and UIF SPA components against Application Developer Professional standards. Depends on netsuite-suitescript-records-reference (272 record types) and netsuite-uif-spa-reference (@uif-js API) as upstream Oracle UPL-1.0 reference contexts. TRIGGER when: user asks to review or write SuiteScript, design a SuiteFlow workflow, configure a custom record or field, build a UIF SPA component, or review a script deployment; phrases include 'client script', 'user event script', 'MapReduce script', 'scheduled script', 'Suitelet', 'RESTlet', 'SuiteFlow', 'custom record type', 'UIF component', '@uif-js', 'governance limits', 'script entry point'. DO NOT TRIGGER when: the request is about SDF project deployment or SuiteScript 1.0 migration (use netsuite-suitecloud-developer-skill), security code review for injection or XSS (use netsuite-suitescript-secure-code-review-skill), REST or SOAP API integration design (use netsuite-web-services-
- ▌ Netsuite Financial Foundations Skill · vincentchuwaichow bundleFlashlight skill for reviewing NetSuite Accounts Payable, Accounts Receivable, and core accounting configurations aligned to the Financial User (N16599GC10) and Accounting Professional (N16301GC10) certifications. T0 static review — no live account connection required. TRIGGER when: user asks to review AP setup, AR configuration, vendor record defaults, customer invoicing templates, payment terms, chart of accounts structure, accounting preferences, bank account record setup, or period-end reconciliation procedures in NetSuite. Trigger phrases: review AP configuration, check AR setup, audit chart of accounts, validate payment terms, inspect bank account record, period-end reconciliation, accounting preferences review, vendor record defaults. DO NOT TRIGGER when: request involves SOX controls, SoD conflicts, or posting period lock enforcement (escalate to netsuite-audit-controls-sox-agent); multi-subsidiary consolidation (use netsuite-oneworld-multisubsidiary-agent); SuiteFlow workflow mechanics (use netsuite-
- ▌ Netsuite Integration Migration Skill · vincentchuwaichow bundleStatic-review flashlight for NetSuite SOAP-to-REST integration architecture and migration program planning. Assesses integration inventories against the confirmed SOAP sunset timeline: 2026.1 REST+OAuth2 default for new integrations, 2027.1 new SOAP integrations blocked, 2025.2 last planned SOAP endpoint, 2028.2 all SOAP endpoints disabled. TRIGGER when: user asks to plan a SOAP-to-REST migration, assess migration risk across an integration inventory, design a phased migration program, review integration architecture for SOAP sunset exposure, create a migration timeline aligned to NetSuite releases, or design rollback strategies for integration cutover. Trigger phrases: SOAP migration plan, SOAP sunset, migrate to REST NetSuite, integration inventory, 2028.2 deadline, SOAP removal, migration program. DO NOT TRIGGER when: the question is about a single REST API endpoint design or integration record configuration (use netsuite-web-services-integration-agent), OAuth 2.0 or TBA auth mechanics (use netsuite-sso-oa
- ▌ Netsuite Live Operation Safety Skill · vincentchuwaichow bundleEvaluates live NetSuite mutation requests against a structured authorization checklist covering blast-radius, rollback, human decision ownership, and integration posture. T0 static evaluation — no org connection required. TRIGGER when: a request involves activating a workflow, deploying an SDF project, editing live records, publishing a saved search to new roles, changing permissions, rotating OAuth certificates, issuing or revoking TBA tokens, or any other operation that writes to or configures a live NetSuite account. Trigger phrases: deploy to production, activate workflow, change permissions in NetSuite, rotate cert, publish saved search, edit live record, SDF deploy, grant role. DO NOT TRIGGER when: the request is purely a static design review with no live-op intent (use the appropriate domain specialist); request is about reading or querying live data without mutation (use netsuite-saved-searches-workbook-agent or netsuite-bi-reporting-agent); request is about architecture design only (use netsuite-ente
- ▌ Nvidia Triton Inference Serving Review · vincentchuwaichow bundleUse this skill when reviewing Triton Inference Server deployments statically — `model_repository/` layout and `config.pbtxt` files, dynamic batching configuration, ensemble and BLS pipelines, custom backend (Python, C++, ONNX, OpenVINO, vLLM) trust posture, gRPC and HTTP endpoint authentication, response cache configuration, rate-limit and metrics exposure. Trigger when the user asks whether a Triton model repository or `tritonserver` invocation follows NVIDIA's published guidance and security expectations.
- ▌ PHP Session Upload Deserialization Review · vincentchuwaichow bundleUse this skill to statically review PHP code for object-injection risk from unserialize() on untrusted input, session fixation/hijacking from missing session_regenerate_id() or weak session cookie hardening, and unsafe file-upload handling that trusts the client or stores/executes uploads inside the webroot. Use when reviewing a PHP application for deserialization, authentication-session, or upload-handling security issues. Static review only; it never executes payloads, uploads, or requests against any system, and every unserialize()/session/upload claim is grounded in the current php.net manual rather than memory.
- ▌ Python Live Continuous Control Testing · vincentchuwaichow bundleUse this skill to periodically test whether previously operating controls continue to operate, read-only by default. It runs the continuous-control checklist, opens a finding with a named owner and due date for each failure, and distinguishes a single passing observation from continuing operating effectiveness.
- ▌ Salesforce Apex Log Analyzer Skill · vincentchuwaichow bundleRetrieves and analyzes Apex debug logs from a connected Salesforce org to identify governor-limit hits, SOQL N+1 patterns, unhandled exceptions, and async job failures. T1 read-only runtime — retrieves logs only, never executes code or mutates data. TRIGGER when: user asks to analyze an Apex log, debug a trigger failure, diagnose a governor limit hit, interpret a stack trace from a Salesforce org, or review a DEBUG log for performance issues. Trigger phrases: analyze apex log, debug this trigger, why is my trigger failing, governor limit hit, DEBUG log analysis, check my log file. DO NOT TRIGGER when: user wants to run live tests (use salesforce-apex-test-runner-skill), static code review without logs (use salesforce-apex-lwc-code-review-skill), generating new Apex code (use salesforce-apex-generator-skill), or Agentforce session telemetry (use salesforce-agentforce-stdm-observer-skill).
- ▌
- ▌ Sap License Btp Consumption Finops Review · vincentchuwaichow bundleSAP License and BTP Consumption FinOps Review
- ▌ Sap Successfactors Hr Process Risk Review · vincentchuwaichow bundleSAP SuccessFactors HR Process Risk Review
- ▌ Typescript Build Graph Performance · vincentchuwaichow bundleUse this skill to statically review, from supplied measurement evidence only, what in a TypeScript program graph costs measured build or editor time: project references, `composite`/`incremental`/`.tsbuildinfo` behavior, generated-code volume, pathological type instantiation, language-service/editor latency, and duplicated checking across lint, test, and build. Reads `--extendedDiagnostics`/trace output and configuration only; it never invokes the compiler or measures a live system.
- ▌ Alibaba Cost Anomaly Watch Coordinator · vincentchuwaichow bundleDetect and coordinate response to Alibaba Cloud cost anomalies — MaxCompute CU vs on-demand billing mismatch, ECS spot instance interruption cascades, CDN traffic spike billing, OSS API request cost explosions, budget alert → DingTalk notification → remediation playbook.
- ▌ Alibaba Load Balancer Traffic Engineer · vincentchuwaichow bundleTraffic engineering for Alibaba Cloud load balancers — CLB (Classic, legacy), ALB (Application Load Balancer, Layer 7 advanced routing), NLB (Network Load Balancer, Layer 4 high throughput), and GA (Global Accelerator) — type selection, health check design, WAF integration, and traffic distribution.
- ▌ Azure Key Vault Secret Lifecycle Auditor · vincentchuwaichow bundleAzure Key Vault Secret Lifecycle Auditor
- ▌ Azure Keyvault Certificate Issuer Review · vincentchuwaichow bundleUse this skill when reviewing Azure Key Vault certificate issuer configurations for cert-manager on AKS. Trigger on any request to audit Key Vault certificate policies, Managed Identity role assignments, exportability settings, private endpoint connectivity, integrated CA credentials, or rotation policy alignment.
- ▌ Azure Live Keyvault Rotation Purge Guard · vincentchuwaichow bundleGuard Key Vault key rotation, rotation policy changes, soft-delete enforcement, and purge-protection enablement with irreversibility warnings and rollback evidence.
- ▌ Azure Subscription Resource Organization · vincentchuwaichow bundleAzure Subscription Resource Organization
- ▌ Backstage Scaffolder Template Review · vincentchuwaichow bundleUse this skill when reviewing Backstage Scaffolder software templates. Trigger when the user asks whether a template is safe for developer self-service, whether template RBAC gates are in place, whether input parameters are validated, whether a step action has excessive blast radius, or whether template outputs expose secrets.
- ▌ Databricks Unity Catalog Governance · vincentchuwaichow bundleUse this skill to review Unity Catalog governance design for privilege correctness, ownership clarity, and least-privilege enforcement: three-level namespace design, GRANT inheritance, ownership, workspace-catalog binding, governed tags, storage credentials, and audit completeness. Reads UC metadata and privilege assignments only; never executes grants and never requires credentials.
- ▌ Dotnet Aspnetcore Identity Authz Review · vincentchuwaichow bundleUse this skill when reviewing how an ASP.NET Core application authenticates and authorizes requests — authentication schemes, JWT TokenValidationParameters, cookie and session security, policy-based authorization, authorization handlers, claims trust, role-versus-resource authorization, multi-tenant isolation, privilege-escalation paths, and negative-test coverage. Trigger when a user provides ASP.NET Core authentication or authorization source (Program.cs, JWT bearer or cookie configuration, authorization policies, authorization handlers, controller authorize attributes) or sanitized configuration, asks whether their auth boundary is safe, or wants to know whether a tenant or role check can be bypassed. This skill reviews source and sanitized configuration statically; it never runs the application, mints or inspects tokens, or contacts an identity provider.
- ▌ Fluxcd Kustomization Helmrelease Review · vincentchuwaichow bundleUse this skill when reviewing FluxCD Kustomization, HelmRelease, GitRepository, HelmRepository, or OCIRepository resources. Trigger when the user asks whether a Flux configuration is safe for production, whether SOPS encryption is required, whether prune is safe on a given workload, whether commit signature verification is enabled, or whether a Flux multi-tenant setup uses least-privilege ServiceAccounts.
- ▌ CSS Architecture Design System Review · vincentchuwaichow bundleReview CSS for specificity and cascade-layer discipline, design-token (custom-property) conformance, and responsive strategy correctness (container queries vs. media queries), catching specificity wars, hardcoded-value token drift, and non-reflowing layouts that fail WCAG 1.4.10/1.4.4 before they compound into unmaintainable stylesheets.
- ▌ Frontend Auth Session Security Review · vincentchuwaichow bundleReview client-side authentication and session-management code for token-storage location, cookie-flag correctness, CSRF/open-redirect exposure, and OAuth/OIDC flow choice for browser-based apps against OWASP ASVS and Session Management Cheat Sheet guidance, with the OAuth-for-browsers reference loaded only when an OAuth/OIDC flow is in scope.
- ▌ Frontend Migration Modernization Plan · vincentchuwaichow bundleBuild a phased, reversible plan to migrate or modernize a legacy frontend surface (jQuery/Backbone/AngularJS to a modern framework, CRA/Webpack to Vite, or a same-framework major-version bump) using strangler-fig sequencing with measurable exit criteria per phase, without defaulting to a full rewrite.
- ▌ Frontend Platform Architecture Review · vincentchuwaichow bundleReviews cross-cutting frontend architecture decisions (module boundaries, rendering topology, technology adoption) against a rewrite-averse, evidence-grounded standard before they are approved, producing an ADR-quality verdict rather than a stylistic opinion.
- ▌ Vue Router Navigation Security Review · vincentchuwaichow bundleVue Router Navigation Security Review
- ▌ GCP Live Cloud Run Traffic Migration Guard · vincentchuwaichow bundleGate Cloud Run traffic percentage migrations, min-instances changes, and revision deletions against revision health verification and rollback posture assessment. Migrating 100% traffic to a broken revision causes complete service unavailability with no automatic rollback — this guard enforces health checks, gradual canary splits, and explicit approval before any production traffic change is executed.
- ▌ Huawei Event Driven Architecture Review · vincentchuwaichow bundleReview Huawei Cloud event-driven architecture designs — DMS Kafka dead-letter configuration, ROMA Connect integration flow capacity, FunctionGraph event trigger idempotency, SMN delivery retry policy, consumer group lag monitoring, cross-region event replication, and retry storm prevention.
- ▌ Huawei Observability Incident Responder · vincentchuwaichow bundleRespond to Huawei Cloud incidents via CES (Cloud Eye) metric alarms, LTS (Log Tank Service) log analytics, AOM (Application Operations Management) service topology, APM distributed tracing, and SMN notification governance.
- ▌ Kotlin Compose UI Quality Accessibility · vincentchuwaichow bundleUse this skill to statically review Jetpack Compose UI correctness and accessibility: recomposition stability (@Stable/@Immutable, unstable parameters cascading recomposition), correct side-effect API usage with required cleanup, remember/derivedStateOf for recomposition scope, state hoisting and rememberSaveable, and mandatory semantics/contentDescription plus touch-target sizing for accessibility. Reads source only; it never renders or profiles the UI.
- ▌ Kubernetes Live Rbac Mutation Guard · vincentchuwaichow bundleGuard live kubectl apply, create, or delete operations on Kubernetes RBAC objects — Roles, ClusterRoles, RoleBindings, ClusterRoleBindings — with privilege-escalation verb detection, scope assessment, current-state diff, and explicit approval before any write. Use only when an intentional RBAC mutation is requested against a confirmed cluster target.
- ▌ Kubernetes Workload Identity Review · vincentchuwaichow bundleUse this skill for Kubernetes workload identity review covering AWS IRSA (IAM Roles for Service Accounts), Azure Workload Identity, GCP Workload Identity Federation, and the underlying ServiceAccount token volume projection plus OIDC issuer trust. Trigger when the user asks how a pod should authenticate to cloud services, whether long-lived credentials in a Secret can be replaced, whether the OIDC trust policy is correctly scoped, or whether ServiceAccount token reuse is a risk.
- ▌ Marketing Gpc Signal Honoring Review · vincentchuwaichow bundleUse this skill when reviewing the technical path by which a Global Privacy Control opt-out signal travels through the tag stack and CMP to determine whether ad tags, server-side forwarding, and conversion APIs actually cease firing. Trigger when a user provides a tag-manager container export, a CMP opt-out configuration, a server-side tag configuration, or asks whether their GPC implementation actually stops ad tags from firing, whether CPRA opt-out obligations are met technically, or whether the CMP acknowledges GPC but fails to suppress downstream tag execution.
- ▌ D365 Customer Service Contact Center · vincentchuwaichow bundleReview Dynamics 365 Customer Service and Contact Center operations across the case-to-resolution lifecycle — case management, unified routing, Omnichannel for Customer Service, queues, entitlements, service-level agreements (SLAs), knowledge management, and Copilot in Service. Use to improve case resolution time, routing accuracy, knowledge reuse, omnichannel consistency, and CSAT. Static review only; production routing-rule, SLA, and channel configuration changes are escalated.
- ▌ Netsuite Evidence Release Drift Skill · vincentchuwaichow bundleAssigns Vanguard evidence hierarchy labels (LIVE_EVIDENCE through BLOCKED) to NetSuite claims and performs biannual release-drift audits against Oracle NetSuite milestone releases. Tracks SOAP removal (2026.1 REST+OAuth2 default; 2027.1 new SOAP blocked; 2028.2 all SOAP disabled) and TBA deprecation timelines. T0 static review — no org connection required. TRIGGER when: a NetSuite agent claim needs an evidence label, a portfolio drift audit is requested, a release-sensitive claim (SOAP, TBA, OAuth2, cert status) needs verification, or a coming-soon certification status needs confirmation. Trigger phrases: evidence label, release drift, SOAP deprecation timeline, is this cert available, verify NetSuite claim, 2026.1 release, 2027.1 release, biannual audit, UNVERIFIED claim. DO NOT TRIGGER when: the request is about live org operations (use netsuite-live-org-mutation-guard-agent); request is about integration architecture design without evidence labelling (use netsuite-web-services-integration-agent); request i
- ▌ Ovhcloud Kubernetes Platform Operator · vincentchuwaichow bundleReview and advise on OVHcloud Managed Kubernetes (MCK) cluster lifecycle, node pool sizing, autoscaling configuration, version upgrade planning, workload placement via taints and tolerations, network policies, RBAC hardening, and cluster security posture. Use when the user needs MCK operational guidance, Terraform IaC review for `ovh_cloud_project_kube` resources, or upgrade risk assessment.
- ▌ Python Numerical Scientific Correctness · vincentchuwaichow bundleUse this skill to statically review Python numerical and scientific correctness: binary float used for money, rounding-mode errors, silent dtype coercion and integer overflow, missing-data (NaN) handling, timezone-naive timestamps, unseeded randomness and irreproducibility, numerical instability, and unbenchmarked vectorization claims. Reads source only; it never runs the calculation, notebook, or benchmark.
- ▌ Python Web Service Production Readiness · vincentchuwaichow bundleUse this skill to statically review Python web-service production readiness across FastAPI, Starlette, Django, and Flask (ASGI/WSGI): sync-vs-async endpoint blocking, request validation, authentication and authorization boundaries, middleware order, worker model, timeouts, graceful shutdown, and health checks. Reads source and config only; it never starts the server or sends requests. Loads the framework-specific reference only when the framework is detected.
- ▌
- ▌
- ▌ Sap Live Readonly Identity Trust Discovery · vincentchuwaichow bundleInspect SAP Cloud Identity Services (IAS/IPS), BTP trust and federation configuration, XSUAA role collections, and identity provider settings using read-only list, get, describe, and export operations only. Use when read-only discovery of IAS application assignments, IPS connector configuration, XSUAA role collection assignments, corporate identity provider federation, or BTP trust configurations is needed as evidence for advisory, audit, or compliance purposes. Requires pre-authorized read-only credentials. Never creates, updates, deletes, assigns, rotates, modifies trust, or triggers any mutation.
- ▌ Sap Procurement Ariba Value Leakage Review · vincentchuwaichow bundleSAP Procurement Ariba Value Leakage Review
- ▌ Sap Transformation Portfolio Triage Review · vincentchuwaichow bundleSAP Transformation Portfolio Triage Review
- ▌ Snowflake Data Engineering Pipelines · vincentchuwaichow bundleUse this skill to review Snowflake batch and ELT pipelines for data correctness: COPY and load semantics, Streams offset behaviour, Tasks and task graphs, Dynamic Tables and achieved versus configured target lag, Snowpark transformations, schema evolution from the consumer's position, idempotency and replay, and reconciliation design. Trigger when data is late, duplicated, incomplete, or suspected wrong, or when a pipeline is being designed. Static review only: it never runs, resumes, or backfills a pipeline, and it never accepts job success as proof the data is right.
- ▌ Snowflake Query Performance Engineer · vincentchuwaichow bundleUse this skill to diagnose Snowflake query and workload performance from evidence: Query Profile interpretation, partition pruning, local and remote spilling, queue versus execution time, warehouse sizing and multi-cluster scaling, caching, clustering, materialized views, search optimization, query acceleration, and benchmark design. Trigger on any slow query, queueing, or throughput question. Static review only: it never runs a query, never resizes a warehouse, and never proposes a size change before establishing the mechanism.
- ▌ Alibaba Ack Container Platform Operator · vincentchuwaichow bundleOperate ACK clusters (managed/dedicated/serverless), ACR container registries, ASM service mesh, and container workload placement. Guide ACK type selection, OIDC workload identity, and image vulnerability posture.
- ▌ Alibaba Live Rds Polardb Mutation Guard · vincentchuwaichow bundleGate RDS/PolarDB instance deletion, spec downgrade, and backup policy removal — database deletion without verified backup is permanently destructive.
- ▌ Alibaba Serverless Production Readiness · vincentchuwaichow bundleReview Function Compute 3.0 (FC3), SAE (Serverless App Engine), and EDAS for production readiness — cold start optimization, VPC binding, RAM role injection, ARMS distributed tracing, security group rules, concurrency limits, and SLA-readiness.
- ▌ AWS Non Destructive Task Automation Advisor · vincentchuwaichow bundleDesign AWS non-destructive task automation using EventBridge, Step Functions, Lambda, Systems Manager Automation, SNS, SQS, approvals, notifications, reporting, and evidence gathering. Use only for read-only or coordination-safe automation; do not use for destructive remediation or mutation-heavy runbooks.
- ▌ Field Service To Cash Protocol · vincentchuwaichow bundleUse this skill to orchestrate the field service to cash process (service to deliver) across Dynamics 365 Field Service and Dynamics 365 Finance, covering work order creation through service delivery, parts and inventory consumption, invoicing, and accounts receivable settlement. The skill defines stage gates, agent handoff rules, and escalation triggers so that service work is verified before invoicing, inventory is accurately consumed, and revenue is recognized correctly. It does not create or modify work orders, post invoices, approve service completions, or access field engineer credentials; all production-impacting steps are escalated to the relevant specialist or human owner.
- ▌ Databricks Identity Network Security · vincentchuwaichow bundleUse this skill to review Databricks identity and network security design for proper admin separation, SCIM/federation configuration, credential hygiene, and network boundary enforcement: admin roles, service-principal posture, OAuth vs PAT, token lifecycle, IP access lists, serverless network policies, secret scopes, and best practices. Reads configuration only; never creates, updates, or rotates credentials.
- ▌ Nextjs App Router Data Fetching Review · vincentchuwaichow bundleStatically review Next.js App Router Server/Client Component boundaries and Server Action data mutations for correct data-fetching placement, bundle-leak risk, and authorization-trust integrity, escalating client-trusted authorization to a security finding rather than a style note.
- ▌ Sveltekit Actions Load Security Review · vincentchuwaichow bundleStatically review SvelteKit form actions, load functions, hooks, and templates for CSRF origin-check bypass (checkOrigin/trustedOrigins), unauthenticated sensitive-data returns from load(), auth guards confined to +layout.server.js without an enforced parent()/hooks check, insecure cookies.set() options, and unsanitized {@html} bindings, grounded in SvelteKit's own CSRF, cookies, load, and authentication documentation.
- ▌ Huawei Certificate Manager Issuer Review · vincentchuwaichow bundleReview Huawei Cloud SSL certificate management — SCM certificate lifecycle, ELB SSL certificate binding, DEW-managed certificate storage, renewal automation, wildcard vs SAN cert selection, certificate expiry alerting via CES, and HTTPS enforcement on ELB listeners.
- ▌ Huawei Functiongraph Serverless Operator · vincentchuwaichow bundleDeploy and operate Huawei FunctionGraph functions (event triggers, cold start optimization, concurrency), ServiceStage application lifecycle management, and CSE (Cloud Service Engine) Spring Cloud/ServiceComb microservice governance.
- ▌ Marketing Email List Retention Review · vincentchuwaichow bundleUse this skill when reviewing marketing email list segment metadata, consent-record completeness, suppression-list coverage, and documented data-retention schedules for GDPR storage-limitation, CASL record-keeping, and CCPA deletion-right compliance. Trigger when a user provides a CRM or ESP export of list segment metadata fields — consent source, consent timestamp, last-engagement date, subscription status, suppression-list entries — plus the organization's documented email data-retention policy, and asks whether the stored list inventory and retention posture meets regulatory obligations.
- ▌ M365 Defender Xdr Security Operations · vincentchuwaichow bundleMicrosoft 365 Defender XDR Security Operations
- ▌ M365 Purview Data Security Compliance · vincentchuwaichow bundleMicrosoft 365 Purview Data Security and Compliance
- ▌ Power Automate Automation Risk Review · vincentchuwaichow bundleReview Power Automate cloud flow risk and governance — flow ownership and sharing (run-only vs co-owner), connector and DLP exposure, maker-vs-run-only security segmentation, error handling and retry/terminate patterns, monitoring and alerting, credential/connection lifecycle, and Center of Excellence auditing. Use to harden fragile, unowned, or over-privileged business-critical automations. Static review only; production DLP and flow-ownership changes are escalated.
- ▌ Netsuite Data Governance Privacy Skill · vincentchuwaichow bundleFlashlight skill for auditing PII exposure paths, data retention and purge policies, field-level access restrictions, privacy controls, and export configurations in NetSuite. T0 static review — no live account connection or actual personal data required. TRIGGER when: user asks to review PII field access, audit data retention settings, check field-level security on sensitive records, assess privacy controls, identify PII in saved searches, review export control permissions, or evaluate GDPR/CCPA readiness of a NetSuite configuration. Trigger phrases: PII exposure, field-level security, data retention policy, GDPR compliance, personal data access, export controls, consent tracking, sensitive field access. DO NOT TRIGGER when: the user needs role and permission architecture review beyond PII fields (use netsuite-identity-access-role-permission-skill), SOX audit trail review (use netsuite-audit-controls-sox-skill), integration data-flow security (use netsuite-integration-migration-skill), subsidiary data segrega
- ▌ Netsuite Enterprise Architecture Skill · vincentchuwaichow bundleReviews NetSuite enterprise architecture decisions — SuiteCloud platform design, integration topology (REST/RESTlet/SOAP migration), OneWorld multi-subsidiary layout, SDF project structure, SuiteScript governance, and AI Connector MCP integration patterns — against Oracle best practices and the SOAP removal timeline. Produces risk-rated findings and structured architecture decision records. T0 static review — no org connection required. TRIGGER when: user requests an architecture review, asks for integration protocol selection advice, asks about OneWorld or multi-subsidiary design, needs SDF project structure guidance, needs SuiteScript version strategy, asks about AI Connector MCP design, or needs cross-domain design arbitration. Trigger phrases: NetSuite architecture, should I use REST or SOAP, OneWorld design, SuiteCloud architecture, SDF project structure, customization strategy, integration topology, architecture decision record, ADR, multi-subsidiary. DO NOT TRIGGER when: the request is a live deploymen
- ▌ Netsuite Saved Searches Workbook Skill · vincentchuwaichow bundleReviews NetSuite saved search criteria, results column configuration, SuiteAnalytics Workbook pivot and chart design, PII-in-export exposure, and cross-subsidiary data leakage risk. TRIGGER when: user asks to review or build a saved search, configure search criteria or results columns, design a SuiteAnalytics Workbook, troubleshoot search results, check for PII in exported data, or validate cross-subsidiary filtering; phrases include 'saved search criteria', 'search results columns', 'SuiteAnalytics workbook', 'pivot table in NetSuite', 'scheduled search', 'PII in search export', 'cross-subsidiary filter'. DO NOT TRIGGER when: the request is about high-level report layout or KPI meters (use netsuite-bi-reporting-skill), SuiteScript code driving the search (use netsuite-suitecloud-developer-skill), or when the user needs to execute a live query against a connected org.
- ▌ Nvidia Gpu Operator Kubernetes Hardening · vincentchuwaichow bundleUse this skill when reviewing NVIDIA GPU Operator deployments on Kubernetes — device plugin, MIG manager, NFD labels, time-sliced GPU configuration, container toolkit, securityContext posture, namespace tenancy, and admission policy coverage. Trigger when the user asks whether GPUs are being shared safely across tenants, whether MIG profiles are enforced, or whether the GPU Operator is deployed per NVIDIA hardening guidance.
- ▌ Salesforce Apex Test Generator Skill · vincentchuwaichow bundleGenerates Apex test classes with TestDataFactory patterns, Assert class usage, bulkification (200+ records), positive/negative/bulk test method separation, async test patterns (Test.startTest/stopTest), and proper @TestSetup usage. T0 static generation — no org connection required. TRIGGER when: user asks to write Apex test classes, create @isTest code, generate test setup data, scaffold test coverage for a class, or add a test class for a .cls file. Trigger phrases: write apex tests, test class for, @isTest class, test setup data, generate test coverage. DO NOT TRIGGER when: user wants to execute tests against a live org (use salesforce-apex-test-runner-skill), generating production Apex logic (use salesforce-apex-generator-skill), debugging test failures from log output (use salesforce-apex-log-analyzer-skill).
- ▌ Salesforce Zero Trust Maturity Skill · vincentchuwaichow bundleSalesforce Zero Trust Maturity Skill