VincentChuWaiChow
- 760 skills
- 0 followers
- 1 day ago last updated
- ▌ Sap Supply Chain Ibp Resilience Review · vincentchuwaichow bundleSAP Supply Chain IBP Resilience Review
- ▌ Snowflake Platform Administrator · vincentchuwaichow bundleUse this skill to review the operability of a running Snowflake estate: account and organization administration, warehouse and object lifecycle, account parameter posture and resolution level, ownership mapping, measured configuration drift, usage monitoring coverage, and operational readiness. Trigger when the question is how the platform is run and recovered rather than how it should be shaped. Static review only: it never executes an administrative statement and never mutates an account.
- ▌ Terraform Supply Chain Integrity · vincentchuwaichow bundleUse this skill to decide whether Terraform or OpenTofu dependencies come from where their authors intended and whether that trust is actually enforced at install time: provider source addresses and namespace lookalikes, `.terraform.lock.hcl` coverage across every platform that runs `init`, the `h1:`/`zh:` hash schemes, mirrors and `dev_overrides` that bypass verification, and module sources pinned to mutable references. Static review of declarations, lock files, and CLI configuration only.
- ▌ Alibaba Live Kms Key Mutation Guard · vincentchuwaichow bundleGate KMS key deletion and disable operations. All data encrypted with a deleted CMK (OSS SSE-KMS, ECS encrypted disks, RDS/PolarDB TDE) becomes permanently and irrecoverably inaccessible. This guard enforces complete CMK dependency audits, deletion window confirmation, and explicit operator approval before any key state mutation.
- ▌ Alibaba Oss Data Perimeter Governor · vincentchuwaichow bundleGovern Alibaba Cloud OSS data perimeters — bucket ACL and policy conflict resolution, Block Public Access configuration, cross-account access via RAM role, VPC endpoint binding for private access, WORM (Object Lock), and MLPS 2.0 data residency compliance.
- ▌ AWS Rds Aurora Performance Investigator · vincentchuwaichow bundleInvestigate Amazon RDS and Aurora-specific incidents involving latency, connection exhaustion, slow queries, lock waits, storage pressure, CPU/I/O saturation, replica lag, failover behavior, Performance Insights, and database capacity. Prefer this for database performance; prefer broad observability responder for non-database incidents.
- ▌ Azure Live Arm Deployment Stack Guard · vincentchuwaichow bundleGuard live ARM, Bicep, and Deployment Stack changes with what-if evidence, denySettings review, changeset diff, rollback posture, and approval gates.
- ▌ Azure Resource Health Incident Triage · vincentchuwaichow bundleAzure Resource Health Incident Triage
- ▌ Databricks Platform Architecture · vincentchuwaichow bundleUse this skill to review Databricks account and workspace topology for scalability and Well-Architected alignment: metastore-per-region constraint, workspace segmentation ratios, serverless vs classic placement, catalog organisation, cross-region and cross-organisation access patterns, and platform quota headroom. Reads workspace inventory and compute/metastore assignments only; never accesses live workspaces or requires credentials.
- ▌ Databricks Streaming Reliability · vincentchuwaichow bundleUse this skill to verify Structured Streaming query correctness and recovery: state-schema immutability, checkpoint compatibility across restarts, watermark semantics, trigger selection (AvailableNow, Once, ProcessingTime), exactly-once vs at-least-once sinks, foreachBatch idempotency, RocksDB and changelog checkpointing, serverless constraints, and restart/backfill safety. Reads query source, state schema, and checkpoint configuration only; never executes queries and never assumes DBR version features without verification.
- ▌ Transfer Pricing Pillar Two Advisor · vincentchuwaichow bundleMulti-jurisdiction reference framework for OECD transfer pricing (arm's length principle, five TP methods, BEPS Action 13 documentation, CbCR) and OECD Pillar Two GloBE rules (IIR, UTPR, QDMTT, ETR computation, SBIE carve-outs, safe harbors, deferred tax divergence under IAS 12 vs. ASC 740). Advisory only — never files tax returns, submits CbCR, or engages in competent authority proceedings.
- ▌ Monorepo Package Governance Review · vincentchuwaichow bundleReviews monorepo task-graph configuration (Turborepo tasks/caching, Nx task pipelines) alongside dependency and lockfile governance (pnpm catalogs, npm overrides, lifecycle-script risk) to prevent false-green CI from stale cache reuse and unpinned supply-chain exposure.
- ▌ Visual Regression Storybook Review · vincentchuwaichow bundleReviews Storybook visual-testing setup -- test-runner wiring, Chromatic integration, and the a11y addon's axe-core gating -- to ensure visually-critical components have deterministic pixel-diff and accessibility coverage before merge, grounded in current Storybook docs.
- ▌ Hetzner Live Server Lifecycle Guard · vincentchuwaichow bundleGuard Hetzner Cloud server creation, destruction, type changes (rescale), and power operations with mandatory server ID, region, explicit human approval, target confirmation, account, and rollback plan. Server deletion is irreversible without a prior snapshot. Use only when live server lifecycle operations are required and all pre-flight checks are confirmed.
- ▌ Huawei Drs Data Replication Operator · vincentchuwaichow bundlePlan and execute Huawei DRS (Data Replication Service) migration and real-time sync tasks, CDM (Cloud Data Migration) batch ETL jobs, and DMS (Distributed Message Service) Kafka cluster operations with safe cutover sequencing.
- ▌ Huawei Live Cost Budget Action Guard · vincentchuwaichow bundleGate Huawei Cloud CBC budget threshold changes, Reserved Instance purchases, and CUD commitments — budget threshold reduction can trigger service suspension and RI/CUD are non-refundable committed spend.
- ▌ Huawei Secmaster Security Operations · vincentchuwaichow bundleOperate Huawei SecMaster (integrated SIEM/SOAR/threat intelligence), HSS (Host Security Service) host intrusion detection, CFW (Cloud Firewall), WAF (Web Application Firewall), Anti-DDoS, and VSS (Vulnerability Scan Service) for comprehensive cloud security operations.
- ▌ Kotlin Estate Modernization Governor · vincentchuwaichow bundleUse this skill to statically review Java-to-Kotlin migration strategy and mixed-codebase governance: strangler-fig / module-by-module vs file-by-file sequencing, the mixed Java/Kotlin interop boundary and its platform-type null-safety debt, reversibility of each migration step, when a module should NOT be migrated, and governance of J2K automatic-converter output (review required, never merge as-is). Reads module inventories, dependency graphs, and sanitized diffs only; it never runs the converter, merges, or deploys.
- ▌ External Secrets Operator Review · vincentchuwaichow bundleUse this skill when reviewing External Secrets Operator (ESO) configuration, including SecretStore, ClusterSecretStore, ExternalSecret, and PushSecret resources. Trigger when a user provides ESO YAML manifests, asks about secret rotation interval compliance, questions whether ClusterSecretStore scope is too broad, or wants to audit the auth method used to reach an external secret store (AWS Secrets Manager, Azure Key Vault, GCP Secret Manager, HashiCorp Vault, 1Password).
- ▌ Eu AI Act Marketing System Review · vincentchuwaichow bundleUse this skill when reviewing a marketing AI system's description card against EU AI Act risk-tier criteria to classify the system (prohibited / high-risk / limited-risk / minimal-risk), flag documentation obligations, and identify deployment-readiness gaps before the August 2, 2026 full-enforcement date. Trigger when a user provides an AI system description card covering system purpose, input data types, output decisions, human-oversight mechanism, deployment geography, and whether it profiles natural persons — or when they ask whether their marketing AI tool, lead-scoring model, content personalization engine, or automated ad-decisioning system requires a conformity assessment or transparency notice under EU AI Act Regulation 2024/1689.
- ▌ D365 Success By Design Governance · vincentchuwaichow bundleReview Dynamics 365 implementation governance against the Success by Design framework. Enforces the five Success by Design phases (Strategize, Initiate, Implement, Prepare, Operate), mandatory Solution Blueprint Review, fit-to-standard and fit-gap discipline, customization sprawl controls, FastTrack implementation gates, and go-live readiness evidence. Refuses to bless go-live without documented phase gate evidence and stakeholder sign-off. Production deployment is live-guard gated and requires escalation.
- ▌ D365 Supply Chain Plan To Produce · vincentchuwaichow bundleReview Dynamics 365 Supply Chain Management master planning (Planning Optimization/MRP), inventory management accuracy, procurement and sourcing configuration, warehouse management setup, and production control parameters including BOMs and routes. Enforces data-accuracy-before-planning discipline, detects coverage-settings and BOM configuration gaps, and requires live-guard escalation before production master-planning parameter or item-coverage changes. Refuses to approve planning output without inventory accuracy and coverage-settings evidence.
- ▌ M365 Copilot Readiness Governance · vincentchuwaichow bundleReview Microsoft 365 Copilot readiness posture and data-exposure governance against the Microsoft Zero Trust 7-layer model. Covers oversharing assessment, SharePoint Advanced Management controls, Microsoft Purview sensitivity labels and DLP, Microsoft Graph permission scope, connector and plugin risk, and user permissions to data. Refuse to recommend Copilot enablement without a completed oversharing and permissions baseline. Prefer static review and advisory guidance; escalate live-tenant configuration mutations to live-guard gate.
- ▌ Nvidia Generative AI Platform Review · vincentchuwaichow bundleUse this skill when reviewing NVIDIA generative-AI platforms — NeMo training and customization pipelines, NIM inference microservices, NeMo Guardrails, model card and weights provenance, evaluation/eval-harness posture, and tenant data isolation. Trigger when the user asks whether NIM containers are correctly verified before deployment, whether NeMo Guardrails are configured, or whether the deployment meets NCA-GENL, NCA-GENM, or NCP-GENL expectations.
- ▌ Nvidia Ngc Nim Supply Chain Governor · vincentchuwaichow bundleUse this skill when reviewing NVIDIA NGC and NIM supply chain posture — NGC org and team boundaries, API key scope and rotation, NIM container cosign verification against NVIDIA's published identity, model card and weights provenance, AI Enterprise entitlement posture, and air-gap mirror integrity. Trigger when the user asks whether NIM images are verified before deployment, whether NGC keys are scoped per environment, or whether the deployment is procurement-defensible for a regulated tenant.
- ▌ Python Async Concurrency Reliability · vincentchuwaichow bundleUse this skill to statically review Python asyncio reliability: blocking calls that stall the event loop, cancellation correctness, missing timeouts on external awaits, task lifecycle and structured concurrency, backpressure on unbounded fan-out, and context propagation across executor and thread boundaries. Reads source only; it never runs the service or measures actual timing.
- ▌ Python Estate Modernization Governor · vincentchuwaichow bundleUse this skill to statically review Python runtime-estate support posture and upgrade sequencing: end-of-life/unsupported interpreters, deprecation exposure, dependency/framework compatibility for an upgrade, and ownership/business-criticality gaps. Reads inventory, manifests, and config only; it never runs an upgrade or installs an interpreter.
- ▌
- ▌ Sap Analytics Cloud Planning Governance · vincentchuwaichow bundleSAP Analytics Cloud Planning Governance Review
- ▌ Sap Hypercare Incident Commander Review · vincentchuwaichow bundleSAP Hypercare and Incident Commander Review
- ▌ Sap Manufacturing Execution Risk Review · vincentchuwaichow bundleSAP Manufacturing Execution Risk Review
- ▌
- ▌ Snowflake Migration Modernization · vincentchuwaichow bundleUse this skill to assess migration to Snowflake from, or coexistence with, Teradata, Oracle, SQL Server, Redshift, BigQuery, Databricks, Hadoop/Spark, or a legacy EDW: workload inventory and per-workload classification, SQL and semantic compatibility, data gravity, security mapping and control gaps, wave sequencing, dual running, reconciliation, cutover, and rollback expiry. Trigger on any migration, replatform, or coexistence question. Static review only: it never moves data or executes a cutover, and it may conclude that a workload should not move.
- ▌ Typescript Engineering Economics · vincentchuwaichow bundleUse this skill to convert another TypeScript specialist's supplied measurements into a funding decision: annual engineering-hours lost, CI compute cost, migration cost, break-even, cost of postponement, and investment priority order, with formulas, sensitivity analysis, and every value labelled measured, supplied, or assumed. It never originates a measurement, is never dispatched first, and is re-prosecuted two quarters after shipping. Reads only user-supplied figures and other specialists' handed-off measurements.
- ▌ Alibaba Function Serverless Operator · vincentchuwaichow bundleDeploy and operate Function Compute 3.0, SAE (Serverless App Engine) applications, and EDAS microservice apps. Guide the serverless vs. PaaS vs. container platform choice for each workload type.
- ▌ Alibaba Kms Secret Lifecycle Steward · vincentchuwaichow bundleAudit and govern Alibaba Cloud KMS key lifecycles, Certificate Manager, SSM (Secrets Manager), and HSM key operations. Ensure encryption-at-rest coverage and rotation compliance across CMKs, envelope encryption, and certificate lifecycle.
- ▌ Alibaba Live Oss Bucket Policy Guard · vincentchuwaichow bundleGate OSS bucket ACL and policy mutations — public-read/write ACL exposes data to internet crawlers within seconds; CN-* cross-border replication requires DSL Article 31 assessment.
- ▌ Alibaba Live Ram Policy Change Guard · vincentchuwaichow bundleGate RAM policy/role mutations against the Alibaba Cloud account hierarchy. RAM AdministratorAccess assignment, policy deletion with active STS tokens, and Resource Directory Control Policy changes carry account-wide or org-wide blast radius. This guard enforces blast-radius assessment, STS token impact analysis, and explicit authority approval before any policy mutation is executed.
- ▌ Alibaba Maxcompute Dataworks Analyst · vincentchuwaichow bundleManage MaxCompute CU package governance, DataWorks scheduling, Quick BI reporting, and PAI ML platform. Optimize query cost and job scheduling efficiency for big data workloads.
- ▌ Alibaba Support Incident Coordinator · vincentchuwaichow bundleCoordinate Alibaba Cloud support incidents — case creation with correct severity (紧急/高/中/低), Enterprise Support SLA enforcement, account manager escalation path, status page monitoring for CN-* and international, internal stakeholder communication, and post-incident evidence packaging.
- ▌ Alibaba Waf Cost Optimization Review · vincentchuwaichow bundleAssess Alibaba Cloud cost posture: ECS instance family rightsizing, Savings Plans and Reserved Instance coverage, Preemptible Instance adoption, cost allocation tagging, OSS storage tiering, analytics pricing, and idle resource elimination.
- ▌ AWS Ticket Triage Escalation Coordinator · vincentchuwaichow bundleTriage AWS tickets and alerts using priority, owner, evidence, incident context, escalation path, OpsCenter, health signals, and safe next steps. Prefer this for non-destructive request coordination and escalation; prefer deep domain skills for implementation or root-cause investigation.
- ▌ Azure App Service Production Readiness · vincentchuwaichow bundleAzure App Service Production Readiness
- ▌ Azure Live App Service Slot Swap Guard · vincentchuwaichow bundleGuard live App Service slot swaps with sticky-settings audit, warmup probe verification, swap-with-preview staging, and instant rollback posture.
- ▌ Azure Live Entra Role Assignment Guard · vincentchuwaichow bundleGuard live permanent Microsoft Entra ID and Azure RBAC role assignments with scope audit, principal-type risk classification, dangerous-role detection, and explicit approval gates before write. Use only when a direct (non-PIM) role assignment is intentionally requested against a confirmed target.
- ▌ Case To Resolution Protocol · vincentchuwaichow bundleUse this skill when a customer service case must be triaged, routed to the right team, driven to resolution, and captured as reusable knowledge in Dynamics 365 Customer Service. Covers intake-to-routing, SLA tracking, escalation gates, knowledge capture, and post-resolution CSAT. Orchestrates the d365-customer-service-contact-center-agent as primary and invokes human escalation when SLA risk or knowledge gaps are detected. Does not make final resolution decisions or override customer service policies; all production-impacting steps escalate to the relevant service owner or quality team.
- ▌ Salesforce Routing Protocol · vincentchuwaichow bundleUse this skill when a Salesforce matter must be classified and routed to the right specialist agent, when a matter crosses multiple Salesforce domains and needs parallel review, or when specialist agents disagree and the conflict must be resolved. It defines routing rules per matter type, the cross-domain overlap matrix covering admin × dev × security × revops × marketing × compliance, and the conflict-resolution protocol. Does not give Salesforce or business advice; routing is a recommendation only and never makes a binding routing decision on behalf of a human owner.
- ▌ Angular Architecture Signals Review · vincentchuwaichow bundleStatically review Angular component and service architecture for correct Signals usage (signal/computed/effect boundaries and purity), appropriate change-detection strategy (OnPush vs default), and service/DI boundary design, grounded in Angular's own Signals, change-detection, and dependency-injection guidance.
- ▌ Bundle Budget Code Splitting Review · vincentchuwaichow bundleReviews JavaScript/CSS bundle composition against explicit numeric budgets, evaluates route- and component-level code-splitting boundaries, and requires a CI-enforced budget before endorsing any size fix as resolved.
- ▌ HTML Semantics Accessibility Review · vincentchuwaichow bundleReview HTML markup and rendered DOM structure for correct native-element usage, valid heading/landmark hierarchy, and WAI-ARIA APG-conformant custom-widget patterns; produce a WCAG 2.2-grounded verdict with APG pattern citations for every custom interactive control, flagging anything that needs live screen-reader verification beyond static review.
- ▌ React Component Architecture Review · vincentchuwaichow bundleStatically review React component trees for composition, prop-interface, and state-placement defects (God-components, prop drilling, overbroad context, hook-rule violations) against React's own composition guidance, producing ranked file:line findings.
- ▌ GCP Live Bigquery Dataset Deletion Guard · vincentchuwaichow bundleGate BigQuery dataset deletion, table truncation, and authorized view changes against a full downstream dependency audit and export confirmation. Dataset deletion is immediate and permanent with no recycle bin — this guard ensures no dataset is deleted without enumerating all tables, scheduled queries, Data Transfer jobs, Looker connections, and Dataflow pipelines that depend on it.
- ▌ GCP Ticket Triage Escalation Coordinator · vincentchuwaichow bundleTriage GCP operational alerts, incidents, and support tickets — P0/P1/P2/P3 classification, GCP Premium/Enhanced Support SLA enforcement, war room coordination, evidence collection from Cloud Monitoring and Cloud Logging, and safe escalation paths.
- ▌ Huawei Cost Anomaly Watch Coordinator · vincentchuwaichow bundleCoordinate Huawei Cloud cost anomaly detection — CBC Cost Center delta analysis (>15% day-over-day threshold), budget alert configuration via Budget Management, ECS/GaussDB Yearly/Monthly vs On-Demand mode cost anomalies, OBS request cost spikes, unattached EVS volume waste, DWS idle cluster detection, and reserved instance coverage gaps.
- ▌ Huawei Live Kms Key Destruction Guard · vincentchuwaichow bundleGate DEW/KMS key deletion and disable operations — all CSMS secrets and DBSS-encrypted database data become permanently unrecoverable once the key deletion window passes.
- ▌ Huawei Load Balancer Traffic Engineer · vincentchuwaichow bundleEngineer and review Huawei Cloud ELB traffic configurations — dedicated vs shared ELB type selection, HTTP/HTTPS/TCP/UDP protocol listener setup, health check configuration, WAF integration on ELB, backend server group routing, connection draining, and TLS policy enforcement on Dedicated ELB.
- ▌ Java Container And Kubernetes Readiness · vincentchuwaichow bundleUse this skill when statically reviewing whether a JVM is correctly sized and configured for the container it runs in — UseContainerSupport and cgroup v1/v2 detection, -XX:MaxRAMPercentage or a fixed -Xmx sized to leave off-heap headroom (metaspace, thread stacks, direct/NIO buffers, code cache) under the container memory limit, ActiveProcessorCount vs CPU limits driving GC and thread-pool (ForkJoinPool) sizing, the interaction between GC stop-the-world pause time and Kubernetes liveness-probe timeouts (which causes kill/restart loops), the need for a startupProbe on slow JVM cold start, and heap-to-limit ratio. Trigger when a user provides a Dockerfile, JVM flags/env, a Kubernetes pod spec or Helm values (resources, probes), or reports OOMKilled pods, CPU throttling, or a probe-triggered restart loop on a Java service. Reads source and sanitized configuration only; it never opens a JDK, runs or profiles the workload, or reads live cgroup/proc filesystem state.
- ▌ Kotlin Supply Chain Release Integrity · vincentchuwaichow bundleUse this skill to statically review Kotlin/Gradle dependency trust and release integrity: whether `gradle/verification-metadata.xml` enforces checksum/signature verification in strict mode, whether dependency locking pins transitive versions for reproducible release builds, whether Gradle plugins are pinned and sourced from trusted repositories, whether repository scope prevents dependency confusion, and whether a KMP/Maven publication carries the metadata and evidence a consumer needs to trust it. Reads build files, verification/lock metadata, and publication config only; it never runs a release, publishes, or signs anything.
- ▌
- ▌ Email Sender Authentication Review · vincentchuwaichow bundleUse this skill when reviewing DNS sender-authentication records for a marketing domain to identify policy gaps exposing campaigns to rejection, spoofing, or inbox displacement. Trigger when a user provides DNS TXT record exports for SPF, DKIM, DMARC, or BIMI, or asks whether their email authentication posture meets Google/Yahoo bulk-sender requirements, DMARC enforcement standards, CISA BOD 18-01 obligations, PCI DSS v4.0 Req 5.3.3, or whether their transactional or marketing emails are at risk of spoofing or bulk-sender quarantine.
- ▌
- ▌ D365 Project Operations · vincentchuwaichow bundleReview Dynamics 365 Project Operations across the project-to-profit lifecycle — project contracts, project planning and scheduling, resource management and assignment, time and expense, project budgeting and cost control, billing and revenue recognition, and integration with Dynamics 365 Finance. Use to reduce project-based revenue leakage, improve resource utilization, correct billing method mismatches, and resolve revenue-recognition configuration errors. Static review only; production project-contract and revenue-recognition configuration changes are escalated.
- ▌ Fabric Data Engineering · vincentchuwaichow bundleReview Microsoft Fabric data engineering artifacts — Lakehouse and OneLake design, medallion (bronze/silver/gold) architecture, Spark notebooks and Spark job definitions, Data pipelines and Dataflows Gen2, Delta/Parquet storage and OneLake shortcuts, Real-Time Intelligence (eventstreams, KQL databases, eventhouse), Direct Lake semantic-model source design, ingestion and orchestration patterns, Capacity Unit (CU) efficiency, and Git integration and deployment pipelines for engineering items. Use to fix brittle pipelines, poor medallion layering, capacity overruns, and fragile ingestion patterns. Static review only; production pipeline runs, capacity changes, and deployment-pipeline promotions are escalated.
- ▌
- ▌
- ▌
- ▌ Rpa Workflow Resilience Review · vincentchuwaichow bundleUse this skill when reviewing exported RPA workflow definitions for resilience and security defects that cause unattended bots to fail silently in production. Trigger when a user provides UiPath XAML files, Automation Anywhere bot exports, Power Automate Desktop flow definitions, Blue Prism process XML, or project dependency manifests, or asks why an unattended bot crashes silently, double-processes transactions, or times out under load. This skill reviews workflow definitions statically; it never connects to a live orchestrator, never runs a bot, and never requests runner credentials or orchestrator URLs.
- ▌
- ▌ Alibaba Solution Architect · vincentchuwaichow bundleDesign Alibaba Cloud solutions — product selection (PolarDB vs RDS, ACK vs ASK vs SAE, MaxCompute vs AnalyticDB), architecture patterns, landing zone design, and disaster recovery strategies aligned to the Alibaba Well-Architected Framework.
- ▌ AWS Compliance Evidence Mapper · vincentchuwaichow bundleMap AWS compliance evidence for audits across Security Hub controls, AWS Config rules/conformance packs, Audit Manager assessments, evidence folders, manual evidence, AWS Artifact reports, CloudTrail, and control narratives. Use for evidence packaging and audit readiness, not general security hardening.
- ▌ AWS Cost Optimization Governor · vincentchuwaichow bundleReview AWS cost optimization and FinOps posture across Cost Explorer, Budgets, Cost Optimization Hub, Compute Optimizer, Savings Plans, Reserved Instances, tagging, showback, idle resources, rightsizing, storage, data transfer, and forecast risk. Use when the user asks to reduce or explain AWS cost.
- ▌ AWS Deployment Hotfix Operator · vincentchuwaichow bundlePatch AWS deployment hotfix config, release parameters, manifest mistakes, environment drift, rollback blockers, and rollout blockers in-repo. Use for rapid non-destructive deployment corrections; do not use for live deploy/apply/destroy actions.
- ▌ AWS Iam Least Privilege Review · vincentchuwaichow bundleReview AWS IAM identity policies, trust policies, resource policies, permission boundaries, SCPs, session policies, role design, pass-role, federation, and Access Analyzer findings for least-privilege risk. Prefer KMS/secrets steward for key/secret lifecycle design and S3 perimeter governor for S3 exposure/data-perimeter posture unless the request is primarily policy surgery.
- ▌ AWS S3 Data Perimeter Governor · vincentchuwaichow bundleReview Amazon S3 data perimeter and exposure posture across Block Public Access, Object Ownership, ACL removal, bucket/access point policies, TLS-only access, encryption, replication, lifecycle, logging, cross-account access, and prefix boundaries. Prefer this for S3 data exposure; prefer IAM skill for generic policy surgery.
- ▌ AWS Security Posture Hardening · vincentchuwaichow bundleReview broad AWS security posture across Security Hub CSPM, GuardDuty, Inspector, Macie, Config, CloudTrail, IAM, public exposure, vulnerability findings, and remediation governance. Prefer compliance evidence mapper for audit evidence packs, IAM skill for policy surgery, S3 perimeter for S3 exposure, Bedrock governor for GenAI agents, and KMS/secrets steward for crypto/secret lifecycle.
- ▌
- ▌
- ▌ Azure Live Aks Rollout Guard · vincentchuwaichow bundleGuard live AKS deployment rollouts with PDB audit, maxUnavailable/surge validation, rollout pause/undo gates, and post-rollout health verification.
- ▌
- ▌
- ▌
- ▌ Capital Allocation Advisor · vincentchuwaichow bundleMulti-jurisdiction reference framework for corporate capital allocation, investment appraisal (NPV, IRR, MIRR, payback, profitability index), cost of capital (WACC, CAPM, hurdle rates), M&A valuation methods (DCF, trading comparables, precedent transactions, accretion/dilution), capital return policy (dividends vs. buybacks vs. reinvestment with ROIC > WACC test), and sensitivity/scenario analysis. Jurisdictional and tax overlays for US, EU, UK, Japan, China, India, and Australia. Advisory only — not investment advice and not a fairness opinion.
- ▌ Treasury Liquidity Advisor · vincentchuwaichow bundleMulti-jurisdiction reference framework for corporate treasury operations, cash and liquidity management, FX and currency risk, hedge accounting qualification (ASC 815 / IFRS 9), FX translation (ASC 830 / IAS 21), Basel III LCR/NSFR, Dodd-Frank and EMIR derivatives reporting, and country-specific cash repatriation and capital control regimes (China SAFE, India FEMA, Brazil IOF, Argentina BCRA). Advisory only — never executes transactions or writes to any system of record.
- ▌ Routing Navigation Review · vincentchuwaichow bundleReviews route-tree structure, loader/action placement, code-splitting boundaries, and navigation-blocking/focus-management behavior in React Router and Next.js applications for correctness, server-side security enforcement, and accessibility conformance on route transitions.
- ▌ GCP Iam Least Privilege Review · vincentchuwaichow bundleAudit GCP IAM bindings across the resource hierarchy (org/folder/project), identify overprivileged Service Accounts, review Workload Identity Federation configurations, evaluate org policy conditions, and recommend least-privilege remediation. Prefer gcp-secret-kms-lifecycle-steward for KMS/Secret Manager lifecycle design and gcp-vpc-service-controls-architect for perimeter access policy posture unless the request is primarily IAM binding surgery.
- ▌ GCP Registry Artifact Governor · vincentchuwaichow bundleGovern GCP Artifact Registry — container image signing via Binary Authorization, vulnerability scanning via Container Analysis, repository IAM least privilege, artifact retention policies, and supply chain security posture.
- ▌ GCP Resource Inventory Analyst · vincentchuwaichow bundleQuery Asset Inventory API for resource discovery, audit resource label/tag coverage, detect stale or orphaned resources, review change history, and build inventory reports across projects and folders.
- ▌ GCP Security Posture Hardening · vincentchuwaichow bundleReview GCP security posture via Security Command Center findings, CIS GCP Benchmark gaps, org policy enforcement baseline, Assured Workloads controls, Binary Authorization, and CSPM recommendations. Prefer gcp-iam-least-privilege-review for IAM binding surgery and gcp-vpc-service-controls-architect for VPC-SC perimeter design unless the request is primarily broad posture hardening.
- ▌ Huawei Dws Dli Data Analyst · vincentchuwaichow bundleOperate Huawei DWS (GaussDB DWS data warehouse), DLI (Data Lake Insight serverless Spark/Flink), MRS (MapReduce Service), and DataArts Studio for data governance and pipeline orchestration.
- ▌ Huawei Ecs Compute Operator · vincentchuwaichow bundleManage Huawei ECS (Elastic Cloud Server) instance lifecycle, AS (Auto Scaling) group configuration and health, IMS (Image Management Service) golden image management, DeH (Dedicated Host) tenancy, and CSBS backup snapshot governance.
- ▌ Kotlin Android Architecture · vincentchuwaichow bundleUse this skill to statically review Android app architecture correctness: ViewModel lifecycle and scoping across configuration changes, SavedStateHandle persistence across process death, lifecycle-aware Flow collection (repeatOnLifecycle/collectAsStateWithLifecycle/flowWithLifecycle), and unidirectional data flow with a single source of truth. Reads source only; it never runs or instruments the app.
- ▌ Kotlin Kmp Boundary Interop · vincentchuwaichow bundleUse this skill to statically review Kotlin Multiplatform source-set architecture, expect/actual design and pairing completeness, platform-API-leakage prevention, cross-target dependency compatibility, Swift/Objective-C interop (suspend-to-async, @Throws, @ObjCName), and Kotlin/Native runtime correctness (new memory manager, freezing deprecation). Reads source and build configuration only; it never compiles or runs a target.
- ▌ M365 Identity Zero Trust · vincentchuwaichow bundleReview Microsoft Entra identity posture, Conditional Access policy design, MFA coverage, Privileged Identity Management (PIM) configuration, access reviews, and least-privilege role assignments against the Zero Trust identity pillar. Static review and advisory only; designing or reviewing Conditional Access baselines, PIM eligible/active role assignments, and access review cadences. Refuse to weaken MFA or Conditional Access for convenience. Escalate live-tenant configuration changes to live-guard gate.
- ▌
- ▌
- ▌
- ▌
- ▌ Python Application Security · vincentchuwaichow bundleUse this skill to statically review Python application code for high-severity security defects: unsafe deserialization (pickle, yaml.load), dynamic execution (eval/exec), subprocess and shell injection, SSRF, path traversal and unsafe archive extraction, secrets exposure, cryptography misuse, and fail-open exception handling. Reads source only; it never runs code, writes an exploit, or opens a live connection.
- ▌ Python Live Release Control · vincentchuwaichow bundleUse this skill to execute exactly one bounded release, canary increment, rollback, or single-instance restart under mutating-runtime controlled execution: confirm an independent approval bound to the plan digest and target, target-scoped JIT credentials, a captured before-state, and a pre-approved rollback exist before acting, then capture the after-state and route verification to an independent check. It never executes a fleet-wide or unbounded change and never self-attests success.
- ▌ Python Live Runtime Control · vincentchuwaichow bundleUse this skill to read live Python interpreter, process, worker, task, thread, memory, and health state through allowlisted read-only diagnostics, and to flag health signals as findings. Read-only-runtime: it never restarts, kills, scales, or reconfigures a process.