VincentChuWaiChow
- 760 skills
- 0 followers
- 1 day ago last updated
- ▌ Python Live Governance Maestro · vincentchuwaichow bundleUse this skill to classify a Python live-control-plane task by runtime, business process, data class, environment, and control profile, and route it to the narrowest live specialist (read-only-runtime or mutating-runtime), or to gate a mutating request to a named human owner under live-guard-gate. Routing only — never mutates, approves, or declares compliance.
- ▌ Python Live Identity Authority · vincentchuwaichow bundleUse this skill to confirm active identity, role, credential age, target scope, JIT status, and approval authority before any gated live action. Read-only-runtime: it blocks shared identities, unidentified principals, standing administrative credentials, and requester-as-approver conflicts, but never grants, elevates, or approves anything itself.
- ▌ Kubernetes Manifest Quality Review · vincentchuwaichow bundleUse this skill when the user provides raw Kubernetes YAML manifests or asks to review K8s manifests for quality, security, or policy compliance — covering Deployment, StatefulSet, DaemonSet, Service, Ingress, NetworkPolicy, RBAC, and CRD resources.
- ▌
- ▌ Sap Signavio Process Mining Value · vincentchuwaichow bundleSAP Signavio Process Mining Value Review
- ▌ Terraform Plan Blast Radius · vincentchuwaichow bundleUse this skill to read a Terraform or OpenTofu plan and explain why the engine is replacing or destroying anything, what the replacement ordering means for availability, whether address churn is causing mass recreation, and whether the reviewed plan will actually bind the apply. Engine-level plan mechanics across every cloud. Reads plan output and source only — it never runs the engine and never approves an apply.
- ▌ Terraform State Reliability · vincentchuwaichow bundleUse this skill to judge the reliability, recoverability, and confidentiality of Terraform or OpenTofu state: backend and locking configuration, backup and restore posture, whether a proposed `state mv`/`state rm`/`force-unlock` is justified and reversible, OpenTofu's native state encryption and its key-loss risk, and which sensitive values state records in the clear. Advisory only — it reads backend blocks and state metadata, never a raw state file, and never performs a state operation.
- ▌ Equity Compensation Advisor · vincentchuwaichow bundleMulti-jurisdiction equity-based compensation reference framework covering stock options, RSUs, ESPPs, and performance awards under ASC 718 and IFRS 2.
- ▌ Revenue Recognition Advisor · vincentchuwaichow bundleApply the ASC 606 / IFRS 15 five-step revenue recognition model to described arrangements. Provides the complete five-step framework with paragraph citations, judgment-area reference tables, confidence-scoring guidance, common restatement triggers, GAAP/IFRS delta checklist, and official documentation URLs. Use when analyzing revenue recognition treatment for SaaS, licenses, professional services, multi-element arrangements, and channel partnerships. Advisory only — all outputs require external auditor review for material amounts.
- ▌ Alibaba Landing Zone Architect · vincentchuwaichow bundleDesign Alibaba Cloud landing zone — Resource Management org tree, Cloud SSO, Control Policy (SCP equivalent), multi-account governance baseline, billing account structure, and ActionTrail centralization.
- ▌ Alibaba Live Ack Rollout Guard · vincentchuwaichow bundleGate ACK deployment mutations, node pool scaling, and cluster version upgrades against rollback posture and workload disruption budget. Prevents irreversible cluster version upgrades from proceeding without PodDisruptionBudget verification, node drain confirmation, and explicit operator approval.
- ▌ Alibaba Resilience Bcdr Review · vincentchuwaichow bundleReview Alibaba Cloud workload HA and BCDR designs — RDS High-Availability Edition failover, PolarDB Global Database Network, ACK multi-zone, ECS disaster recovery cross-region, RTO/RPO target analysis, and HBR (Hybrid Backup Recovery) coverage.
- ▌ Alibaba Waf Reliability Review · vincentchuwaichow bundleAssess Alibaba Cloud workload reliability: multi-AZ ECS topology, SLB/ALB/NLB load balancing, Auto Scaling health policies, RDS/PolarDB HA failover, backup and cross-region DR, and Cloud Monitor/ARMS observability coverage.
- ▌ AWS Cost Anomaly Watch Coordinator · vincentchuwaichow bundleReview AWS cost anomalies using Cost Explorer, Cost Anomaly Detection, Budgets, usage spikes, commitments, and tagging gaps. Prefer this for proactive FinOps watch and non-destructive escalation; prefer aws-cost-optimization-governor for broader optimization strategy.
- ▌ AWS Data Protection Backup Steward · vincentchuwaichow bundleReview AWS backup and data protection implementation across AWS Backup, EBS/RDS/EFS/S3 recovery patterns, vaults, vault lock, retention, encryption, cross-account/cross-Region copy, restore testing, lifecycle, and recovery evidence. Prefer resilience BCDR review for broader RTO/RPO, failover, and business continuity design.
- ▌ AWS Ec2 Compute Operations Steward · vincentchuwaichow bundleReview Amazon EC2 compute operations across instances, Auto Scaling groups, Launch Templates, AMIs, Systems Manager, Patch Manager, Session Manager, EBS volumes, snapshots, health checks, instance refresh, lifecycle hooks, patch compliance, and fleet reliability. Use for EC2 day-2 operations and legacy workload stewardship.
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Lead To Cash Protocol · vincentchuwaichow bundleUse this skill to orchestrate the end-to-end lead-to-cash business process across Dynamics 365 Sales, Supply Chain Management, and Finance. It coordinates the journey from a qualified sales opportunity through order creation, fulfillment, invoicing, and final revenue recognition. The skill defines stage gates, agent handoff rules, escalation triggers, and decision logic for cross-functional coordination. It does not make business decisions, approve credit limits, authorize revenue recognition treatments, or execute any system transactions; all production-impacting steps are escalated to the relevant specialist or human owner.
- ▌ Legal Hr Case Capsule · vincentchuwaichow bundleUse this skill when a Legal or HR agent must hand a matter to another agent and the context, uncertainty, evidence quality, privilege posture, and privacy posture must survive the handoff. It defines the shared legal-hr-case-capsule — a controlled, auditable exchange record with redacted identifiers, risk labels, privilege and privacy labels, a decision-owner field, and an explicit do-not-do list. It does not give legal or HR advice and does not authorize any action.
- ▌ Debt Capital Structure Advisor · vincentchuwaichow bundleMulti-jurisdiction reference framework for debt and capital structure advisory — optimal capital structure theory (M&M, trade-off, pecking order), leverage and credit metrics, debt instruments, covenant analysis, refinancing, WACC optimization, Basel III/IV capital requirements, liability management, rating agency methodologies, and ESG-linked financing (SLBs/SLLs, green bonds). Advisory only — never executes transactions, accesses banking systems, or writes to any system of record.
- ▌ E2e Testing Playwright Review · vincentchuwaichow bundleReviews Playwright end-to-end test configuration -- fixtures, storageState/auth setup, CI sharding and parallelism, and toHaveScreenshot visual-assertion options -- for reliability and correct gating, grounded in current, version-specific Playwright API docs.
- ▌ Framework Upgrade Risk Review · vincentchuwaichow bundleAssess breaking-change and regression risk for a same-framework major-version upgrade (React, Next.js, Angular, Vue, or core build tooling), grounding every claimed breaking change in the framework's official release notes/migration guide, and separate upgrade-blocking issues from cosmetic deprecation noise.
- ▌ Microfrontend Boundary Review · vincentchuwaichow bundleReviews micro-frontend/module-federation boundary contracts for shared-dependency versioning safety, runtime isolation, and ownership clarity before adoption or extension of a distributed frontend architecture.
- ▌ Nextjs Server Security Review · vincentchuwaichow bundleStatically review Next.js middleware, Server Actions, next.config.js, and environment-variable files for four documented server-side defect classes -- middleware matcher exclusions that silently skip auth on Server Functions, Server Actions missing allowedOrigins CSRF protection, secrets leaked via NEXT_PUBLIC_ prefixes, and SSRF/open-redirect via dangerouslyAllowLocalIP or unvalidated rewrite destinations.
- ▌ Sveltekit Routing Load Review · vincentchuwaichow bundleStatically review SvelteKit route files (+page.js, +page.server.js, +layout.js, +layout.server.js, +server.ts) to verify universal-vs-server load placement, catching server-only secrets, database clients, or privileged API access that would leak into or execute inside the browser.
- ▌ Tree Shaking Dead Code Review · vincentchuwaichow bundleVerifies that a bundler's tree-shaking actually eliminated dead code by inspecting output bytes and sideEffects/module-format configuration, rather than trusting a clean build as proof of elimination.
- ▌ GCP Cost Anomaly Watch Coordinator · vincentchuwaichow bundleDetect and coordinate response to GCP cost anomalies — BigQuery on-demand query cost spikes ($5/TB scanned), Cloud Run scaling runaway, unattached Persistent Disks, idle GCE instances, budget alert → notification channel → remediation playbook.
- ▌ GCP Live Kms Key Destruction Guard · vincentchuwaichow bundleGate Cloud KMS key version destruction and key ring deletion against a complete CMEK dependency audit. All Cloud SQL, GCS, BigQuery, Compute Engine disk, and Secret Manager resources encrypted by the key version become permanently inaccessible once destruction completes — this guard ensures no key version is destroyed without enumerating every dependent resource and obtaining explicit operator approval.
- ▌ GCP Load Balancer Traffic Engineer · vincentchuwaichow bundleTraffic engineering for GCP load balancers — Global HTTPS LB, Regional HTTPS LB, TCP/SSL Proxy LB, Network LB (passthrough), Internal TCP/UDP LB — type selection, health check configuration, Cloud Armor integration, and traffic distribution.
- ▌ GCP Vpc Service Controls Architect · vincentchuwaichow bundleDesign, review, and troubleshoot VPC Service Controls perimeters, access policies, dry-run mode configuration, bridge perimeters for cross-perimeter access, and Access Context Manager access levels. Prefer gcp-iam-least-privilege-review for IAM binding review and gcp-security-posture-hardening for broad org-level security posture unless the request is primarily VPC-SC perimeter architecture or troubleshooting.
- ▌ Huawei Codearts Devops Operator · vincentchuwaichow bundleBuild and operate Huawei CodeArts CI/CD pipelines across CodeHub (Git), Build, Deploy, TestPlan, and Pipeline modules, managing SWR image lifecycle, deployment automation, and environment promotion with rollback gates.
- ▌ Huawei Iac Change Safety Review · vincentchuwaichow bundleReview Terraform and RFS (Resource Formation Service) changes targeting Huawei Cloud — blast radius analysis, resource deletion detection, Organizations SCP cascade scope, cross-stack dependency impact, state file security, and rollback plan completeness.
- ▌ Huawei Modelarts Mlops Engineer · vincentchuwaichow bundleManage Huawei ModelArts training jobs (GPU and Ascend NPU cost governance), Pangu foundation model deployment, AI Gallery model management, and MLOps pipeline automation for AI/ML workloads.
- ▌ Kotlin Android Security Privacy · vincentchuwaichow bundleUse this skill to statically review an Android app's security and privacy posture against OWASP MASVS: exported components and intent surfaces, deep-link/App Links validation, WebView exposure, cleartext traffic and network-security-config, local storage and secrets (EncryptedSharedPreferences/Keystore), backup exposure, runtime-permission minimization, and PII in logs. Reads manifest, source, and sanitized config only; it never builds, installs, or instruments an app.
- ▌ Kotlin Gradle Build Engineering · vincentchuwaichow bundleUse this skill to statically review Gradle build-graph quality and CI throughput for Kotlin/KMP projects: configuration-cache compatibility (no execution-time Project access), build-cache correctness (@CacheableTask annotation completeness and relocatable/reproducible output), kapt vs KSP annotation-processing configuration and incremental opt-in, configuration-avoidance API usage, and convention-plugin (build-logic included build) centralization. Reads Gradle build files and build-scan evidence only; it never invokes Gradle or measures a live build.
- ▌ Kotlin Language API Correctness · vincentchuwaichow bundleUse this skill to statically review Kotlin language-level correctness: nullability and Java-interop platform types, inline functions with reified type parameters past JVM erasure, @JvmInline value-class boxing behavior, statically-dispatched extension functions vs member precedence, and lateinit use-before-init hazards. Reads source only; it never compiles or runs code to observe runtime null-pointer or boxing behavior.
- ▌ D365 Finance Close To Report · vincentchuwaichow bundleReview Dynamics 365 Finance general ledger configuration, sub-ledger reconciliation, period-end and year-end close procedures, financial consolidation and elimination, posting profiles, tax setup, and financial reporting controls. Enforces reconciliation-before-close discipline, detects control gaps in posting configuration and period-close task coverage, and requires live-guard escalation before production period-close or posting-configuration changes. Refuses to approve a close process without reconciliation and financial controls evidence.
- ▌ D365 Fno Developer Extension · vincentchuwaichow bundleReview Dynamics 365 Finance & Operations developer and extension engineering work — X++ extensions (not over-layering), Chain of Command, extension models, deployable packages, Azure DevOps and Lifecycle Services ALM, build and test automation, upgrade-safe customization, and performance. Detects unsafe customizations, upgrade blockers, fragile extensions, and ALM anti-patterns. Refuses to approve production deployable package deployment or schema changes without sandbox validation evidence and rollback plan. Live-guard gated for deploying packages to production and schema changes.
- ▌ D365 Security Sod Governance · vincentchuwaichow bundleReview Dynamics 365 Finance & Operations security role design, duty and privilege assignments, segregation of duties (SoD) conflict rules, user-role assignments, and audit evidence for least-privilege compliance. Enforces SoD conflict detection, security reports review, role layering analysis, and privileged access controls. Refuses to approve role changes that introduce SoD conflicts or bypass audit controls. Production role changes are live-guard gated and require escalation.
- ▌
- ▌ Power Platform Alm Pipelines · vincentchuwaichow bundleReview Power Platform application lifecycle management health across managed and unmanaged solutions, Power Platform Pipelines, environment strategy (dev/test/prod), solution layering, connection references, environment variables, source control via Git integration, and deployment gates. Use to detect unhealthy ALM patterns, missing rollback paths, and ungoverned production deployments. Static review only; production pipeline and deployment-configuration changes are escalated.
- ▌ Netsuite AI Foundations Skill · vincentchuwaichow bundleFlashlight skill for reviewing NetSuite AI feature enablement and AI Connector Service configuration posture, aligned to the AI Foundations Associate certification (N16765GC10, available). T0 static review — no live account connection required. NOTE: AI Specialist and AI Professional certifications are COMING SOON and are not yet available; this skill does not cover those levels. TRIGGER when: user asks to review NetSuite AI feature enablement (bill matching, anomaly detection, text enhancement, predicted risk), AI Connector Service configuration, MCP Server Connection permission setup, OAuth 2.0 Access Tokens permission for AI roles, HIPAA/BAA restriction for healthcare accounts, or AI governance and PII exposure controls. Trigger phrases: AI Foundations review, AI Connector configuration, MCP Server Connection permission, NetSuite AI features, AI bill matching, AI anomaly detection, HIPAA AI restriction, AI governance review, Log in using OAuth 2.0 Access Tokens. DO NOT TRIGGER when: request is about AI Con
- ▌ Netsuite Erp Consultant Skill · vincentchuwaichow bundleFlashlight skill for reviewing NetSuite ERP implementation configurations aligned to the ERP Consultant Professional certification (N16302GC10). T0 static review — no live account connection required. TRIGGER when: user asks to review order-to-cash configuration, procure-to-pay workflow, inventory management setup, pricing rule design, fulfillment or receipt workflow, item record configuration, or implementation gap analysis in NetSuite. Trigger phrases: review OTC setup, audit procure to pay, check inventory configuration, validate pricing rules, review fulfillment workflow, implementation gap analysis, ERP consultant review. DO NOT TRIGGER when: request concerns financial close controls or posting periods (use netsuite-financial-foundations-agent), SOX control design (use netsuite-audit-controls-sox-agent), custom SuiteScript code (use netsuite-application-developer-agent), multi-subsidiary intercompany transactions (use netsuite-oneworld-multisubsidiary-agent), or any live account mutation is required.
- ▌
- ▌
- ▌ Composer Audit Supply Chain Review · vincentchuwaichow bundleUse this skill to review PHP Composer dependency supply-chain posture — whether composer audit is wired into CI with a failing exit-code gate on security advisories, whether config.policy.advisories.audit and config.policy.abandoned settings are configured to actually surface risk, whether abandoned packages have a tracked replacement plan, and whether composer.lock is present, current, and pins dependencies at security-sensitive boundaries. Use when a vulnerable or abandoned Packagist dependency could reach production because the audit gate is missing or non-blocking, an abandoned package has no owner, or the lock file is absent, drifted, or bypassed by unpinned constraints. Static review only; it never installs packages, runs Composer commands, or contacts Packagist.
- ▌ PHP Runtime Eol Opcache Fpm Review · vincentchuwaichow bundleUse this skill to review PHP runtime upgrade readiness — whether the target or running PHP version is past php.net's published four-year support window (active support, then security-only, then EOL) — and to review production OPcache (enable, validate_timestamps, memory sizing) and PHP-FPM (pm, max_children, max_requests) hardening. Use when production PHP could be running an EOL or soon-security-only-EOL version, or when OPcache/FPM configuration could serve stale code or let a traffic spike exhaust workers. An EOL runtime is always a blocking finding. Static review only; it never installs, upgrades, or restarts a PHP runtime.
- ▌ Python Live Data Change Control · vincentchuwaichow bundleUse this skill to govern a migration, backfill, pipeline reprocessing, or bounded data correction against a live system: confirm data ownership sign-off, data classification, a bounded record/partition scope, a reconciliation plan, and a rollback before acting, then require reconciliation evidence and apply data-minimization/residency controls to captured evidence. It never allows an unbounded or ad-hoc production data mutation.
- ▌ Python Native Extension Interop · vincentchuwaichow bundleUse this skill to statically review Python native extensions and interop (CPython C API, Cython, PyO3/Rust): reference-ownership correctness, stable-ABI use, buffer-protocol safety, exception translation, and thread/GIL and free-threaded readiness. Reads extension source and build config only; it never compiles or runs the extension.
- ▌ Sap Custom Code Remediation Review · vincentchuwaichow bundleReview custom ABAP code remediation plans and ATC findings for S/4HANA readiness. Assesses SAP simplification item violations, ABAP Test Cockpit results using S/4HANA readiness check variants, custom code migration app output, deprecated API usage, replacement API mapping, and clean-core alignment of proposed remediation paths. Advisory only — does not access or modify live SAP systems.
- ▌ Sap Guarded Btp Entitlement Change · vincentchuwaichow bundleChange SAP BTP entitlements, quotas, and service plan subscriptions using a mandatory 17-step guarded mutation sequence covering classification, target global account and subaccount confirmation, criticality, requester, approver (platform-owner plus FinOps required), ticket, scope, read-only current state, diff of entitlement changes, blast radius (cost and dependent applications), rollback, post-change verification, and audit evidence. Refuses if any step is missing, if FinOps approval is absent for entitlement increases, or if a cost-impact assessment has not been produced. Use when a confirmed and approved BTP entitlement, quota, or subscription change must be executed under traceable controls.
- ▌
- ▌ Snowflake Devops Iac Release · vincentchuwaichow bundleUse this skill to review how Snowflake changes ship: the official Terraform provider and its stable-versus-preview resource split, version pinning and upgrade rehearsal, plan review for destroy/replace and grant changes, state posture, Snowflake CLI in automation, CI/CD and environment promotion, drift adoption versus reversion, behaviour-change bundle management, and rollout and rollback strategy. Trigger on any Snowflake IaC, pipeline, or release question. Static review only: it never applies a change and never treats a successful plan as proof of safety.
- ▌ Snowflake Governance Privacy · vincentchuwaichow bundleUse this skill to design or review Snowflake data controls: sensitive-data discovery and classification, tags and propagation, masking policies, row-access policies, aggregation/projection/join policies, policy assignment and the consumption paths a policy does or does not reach, lineage completeness, and data quality monitoring. Trigger when the question is what a permitted principal sees inside the data, or whether a control actually behaves. Static review only: it never attaches or alters a policy and never handles real sensitive values.
- ▌ Snowflake Solution Architect · vincentchuwaichow bundleUse this skill to review or design end-to-end Snowflake architecture: organization and account topology, workload placement and isolation boundaries, edition/cloud/region constraints, source-to-consumption paths, interoperability and catalog choices, and architecture decision records. Trigger when a Snowflake design decision is structural rather than operational — how many accounts, where a workload lands, which boundary is load-bearing, whether an edition upgrade is justified. Static review only: it never executes SQL and never mutates an account.