yanacuti1121
- 1.8k skills
- 0 followers
- 2 repo stars
- 2 weeks ago last updated
- ▌ Agency Client · yanacuti1121Client lookup and history — searches all output files for a client and displays a comprehensive summary
- ▌ Agency Status · yanacuti1121Agency dashboard — shows agency-wide status, pipeline metrics, installed tools, and recent activity
- ▌ Book Refactoring Full · yanacuti1121Refactoring (Martin Fowler) — Full rules — comprehensive mandatory coding standards. Use when asked to apply Refactoring principles or review code against Refactoring standards.
- ▌ Book Refactoring Mini · yanacuti1121Refactoring (Martin Fowler) — Condensed rules — key principles distilled. Use when asked to apply Refactoring principles or review code against Refactoring standards.
- ▌ Book Refactoring Nano · yanacuti1121Refactoring (Martin Fowler) — Minimal rules — essential one-liners only. Use when asked to apply Refactoring principles or review code against Refactoring standards.
- ▌ Claudiodrews Memory Os · yanacuti1121Hệ thống bộ nhớ 7 lớp chạy local dành cho AI agent — SQLite + Qdrant + Fabric, zero cloud dependency. Agent nhớ project, decision, reasoning pattern xuyên session.
- ▌ Cloud Cost Optimization · yanacuti1121Reduce cloud spend — rightsizing, spot/preemptible instances, reserved capacity, storage lifecycle, idle resource cleanup, autoscaling tuning, and cost anomaly alerting. Use when asked to "reduce cloud costs", "AWS bill too high", "rightsizing", "spot instances", "reserved instances", "savings plan", "idle resources", "cost anomaly", "FinOps", or "infracost". Covers AWS primarily; GCP/Azure patterns noted where they differ. Do NOT use for: application-level performance optimization — see web-performance or load-testing skills.
- ▌ Ebpf Syscall Monitoring · yanacuti1121Monitor and intercept Linux kernel syscalls from agent processes using eBPF (Extended Berkeley Packet Filter). Real-time syscall filtering, PID-based policy enforcement, cgroups v2 throttling, and seccomp profile generation.
- ▌ Error Handling Patterns · yanacuti1121Production error handling — typed errors, Result type, error boundaries, structured logging, retry strategies
- ▌ Honeypot Tarpits · yanacuti1121Lightweight detection techniques that work without a SIEM. Covers fake admin paths, decoy .env files, canary tokens, fake API keys planted in JS bundles, and tarpits that slow automated scanners. Invoke when public services see constant automated probing, when complementing fail2ban and WAF rules, or when high-signal detection is needed on a small budget.
- ▌ LLM App Security · yanacuti1121Apply operational controls to applications built on the Anthropic API or similar LLM SDKs. Maps the OWASP LLM Top 10 to practical controls, plus rate limiting, cost caps, PII scrubbing, audit logging, model-version pinning, and an AI-incident response playbook. Invoke when shipping an LLM feature to production, when handling an abuse complaint, or after a model-provider advisory.
- ▌ Instinct Based Learning · yanacuti1121Học hành vi từ session thực tế — tạo atomic instincts với confidence scoring, tự động activate khi gặp pattern tương tự. Bản đơn giản hơn continuous-learning-v2.
- ▌ Open LLM Vtuber Vtuber · yanacuti1121Talk to LLM với hands-free voice + Live2D avatar chạy local — voice interruption, real-time lip sync, cross-platform. 8.7K stars.
- ▌ Paddlepaddle Paddleocr · yanacuti1121PaddleOCR — OCR toolkit 80+ ngôn ngữ: PP-OCR (general), PP-Structure (layout+table), PP-ChatOCR (LLM key extraction). PDF/image → text/structured data. Apache-2.0.
- ▌ Pairwise Prioritization · yanacuti1121Prioritize a task list by direct pairwise comparison instead of isolated scoring — compare every pair on importance, urgency, and impact, then produce a ranked execution order. Use when asked 'so từng cặp', 'sắp xếp ưu tiên', 'prioritize these tasks', 'việc nào làm trước', 'rank this backlog', 'đặt độ ưu tiên', or 'compare tasks head to head'. Do NOT use for: choosing between solution options — see option-tournament. Do NOT use for: sprint ceremony planning — see /sprint-planning.
- ▌ Prompt Caching Strategy · yanacuti1121Minimize token cost and latency with Anthropic prompt caching — cache breakpoints, static vs dynamic block separation, skills snapshot pre-computation, context invalidation strategy, and 90% cost reduction patterns for repeated system content. Use when asked about "prompt caching", "cache breakpoint", "reduce token cost", "Anthropic caching", "cache_control", "reuse system prompt", "skills snapshot", "context invalidation", "token budget", "90% cache hit", "cost optimization for Claude", or "cached prompt tokens". Do NOT use for: general output budget — see the OUTPUT_BUDGET_POLICY.md. Do NOT use for: session memory compaction — see pre-compact-backup.
- ▌ Sovereign Overlord Gate · yanacuti1121When an agent needs to stop, roll back, or restrict access for a human — the real mechanisms are require-tier.sh's tier check, human-gate-policy.md's confirmation gate, and git's own revert/reset. Replaces an earlier design that instructed agents to implement ECDSA-P384 signed commands and a "freeze the swarm" API that was never built.
- ▌ Churn Analysis · yanacuti1121When the user needs to identify at-risk accounts, understand why customers are leaving, reduce churn rate, build health scores, design save plays, or create win-back campaigns.
- ▌ Employer Brand · yanacuti1121When the user needs to create or improve content that shapes how candidates and the public perceive the company as a place to work.
- ▌ Privacy Policy · yanacuti1121When the user needs to draft, review, or update a privacy policy for their product, or needs to understand data privacy obligations across jurisdictions.
- ▌ Social Content · yanacuti1121When the user needs to build a LinkedIn authority system, create social content strategy, define content pillars, write posts, or establish thought leadership positioning. Activate on "LinkedIn strategy," "content pillars," "what should I post," or "build my personal brand."
- ▌ Trading Journal Analyst · yanacuti1121Paste your trading history (CSV / broker export / list of trades) and AI extracts hidden behavioral biases, implicit rules, and compares your actual behavior vs an ideal shadow strategy. Inspired by HKUDS/Vibe-Trading Shadow Account Analysis (MIT).
- ▌ Trending Pulse Research · yanacuti1121Research what the community actually thinks about a topic in the LAST 30 DAYS — search Reddit, X, YouTube, Hacker News and GitHub in parallel, weight results by real engagement (upvotes, likes, stars/day), detect cross-platform convergence, and synthesize one grounded brief with citations. Use when asked 'cộng đồng đang nói gì về X', 'what's trending in X', 'last 30 days research', 'tin mới nhất về X trên Reddit/HN', 'is X actually popular or hype', or 'research recent sentiment'. Do NOT use for: deep technical/academic research with no recency requirement — see deep-research or arxiv-research. Do NOT use for: one-off fact lookups — plain web search is enough.
- ▌ Venice Venice API Keys · yanacuti1121Manage Venice API keys. Covers GET/POST/PATCH/DELETE /api_keys, GET /api_keys/{id}, GET /api_keys/rate_limits, GET /api_keys/rate_limits/log, the two-step /api_keys/generate_web3_key wallet flow, INFERENCE vs ADMIN key types, and per-key consumption limits (USD / DIEM).
- ▌ Zero Trust Network Mesh · yanacuti1121Implement Zero Trust networking for multi-agent swarms. mTLS mutual authentication, egress proxy whitelisting, DNS-over-HTTPS pinning, Ed25519 message signing, and network segmentation for agent clusters.
- ▌ Interview Me · yanacuti1121Extracts what the user actually wants instead of what they think they should want. Achieves this through one-question-at-a-time interview until ~95% confidence about the underlying intent. Use when an ask is underspecified ("build me X" without "for whom" or "why now"), when the user explicitly invokes ("interview me", "grill me", "are we sure?", "stress-test my thinking"), or when you catch yourself silently filling in ambiguous requirements before any plan, spec, or code exists.
- ▌ Adversarial Team Pattern · yanacuti1121Template pattern for multi-agent analysis where agents hold opposing mandates. Use when spawning subagents for complex research, code review, architecture decisions, or risk assessment. Triggers on: 'adversarial team', 'devil's advocate analysis', 'multi-perspective review', 'challenge this decision', 'stress test this plan', 'red team this'.
- ▌ Agent Messaging Patterns · yanacuti1121Wire inter-agent communication — signal files, shared state via files/KV, approval queues, budget delegation, capability passing, and broadcast/ subscribe patterns for agents running in parallel terminals or processes. Use when asked about "agents communicating", "agent signals", "how agent A tells agent B", "agent approval queue", "agent budget cap", "pass context between agents", "agent broadcast", "agent subscribe", "hcom", "inter-agent protocol", "agent pipeline", or "agent tool approval chain". Do NOT use for: git-based agent coordination — see git-native-agent-protocol. Do NOT use for: subagent spawning API — see subagent-dependency.
- ▌ Agency Onboard · yanacuti1121Full Agency Onboard — launches 5 parallel audit teams and produces a unified client-ready report with composite scoring
- ▌ Agency Propose · yanacuti1121Unified Agency Proposal Generator — builds a three-tier service proposal with ROI projections from all available audit data
- ▌ Apply Premium Background · yanacuti1121CSS and Tailwind background effects — animated dots, grids, radial gradients, aurora blurs, mesh gradients, noise textures. Ibelick-style premium backgrounds for hero sections, cards, and full-page layouts.
- ▌ Autonomous Agent Harness · yanacuti1121Transform Claude Code into a fully autonomous agent system with persistent memory, scheduled operations, computer use, and task queuing. Replaces standalone agent frameworks (Hermes, AutoGPT) by leveraging Claude Code's native crons, dispatch, MCP tools, and memory. Use when the user wants continuous autonomous operation, scheduled tasks, or a self-directing agent loop.
- ▌ Autonomous Patching Loop · yanacuti1121Closed-loop scan → isolate → repair → verify cycle. Agent detects code vulnerabilities or test failures, creates an isolated fix branch, applies auto-remediation, runs the full test gate, and merges only on pass. Inspired by darrenburns/cliche error capture + marionevra/awesome-ai-agents-security playbooks.
- ▌ Circuit Breaker Rollback · yanacuti1121Implement circuit breaker patterns, canary deployment gates, hallucination telemetry checkers, and automated rollback for agent skill deployments. Stop cascading failures before they propagate across the swarm.
- ▌ Containing Active Breach · yanacuti1121 bundleExecutes containment strategies to stop active adversary operations and prevent lateral movement during a confirmed security breach. Implements short-term and long-term containment using network segmentation, endpoint isolation, credential revocation, and access control modifications. Activates for requests involving breach containment, lateral movement prevention, network isolation, active threat containment, or live incident response.
- ▌ Incident Response · yanacuti1121Run a structured response to a suspected web or server compromise. Follows SANS PICERL — Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned — and includes a post-mortem template. Invoke when a site is defaced, when malware or webshells appear, when admin accounts arrive unannounced, or when a provider sends an abuse notice.
- ▌ Site Server Audit · yanacuti1121Audit a public-facing site or server for common misconfigurations without sending exploit traffic. Covers DNS hygiene, TLS and HSTS, security headers, exposed paths (.git, .env, backups), cookie flags, and software fingerprinting. Invoke when onboarding a new client site, before launch, after infrastructure changes, or as periodic re-audit.
- ▌ Investment Research Team · yanacuti11214-agent parallel investment research team modeled after legendary investors. business-analyst (Duan Yongping lens), financial-analyst (Buffett lens), industry-researcher (Munger lens), risk-assessor (Li Lu lens). team-lead synthesizes into a single verdict. Inspired by ai-berkshire (MIT).
- ▌ Prompt Firewall Patterns · yanacuti1121Build cognitive security firewalls against prompt injection, jailbreak attacks, and Unicode homoglyph smuggling. Instruction-data segregation, jailbreak token filtering, LLM-as-a-Judge semantic guard, and system prompt reinforcement.
- ▌ Contract Review · yanacuti1121When the user needs to review an existing contract, assess risk in proposed terms, or evaluate a contract before signing.
- ▌ Email Marketing · yanacuti1121When the user needs to design, write, or optimize email sequences -- including welcome series, nurture campaigns, re-engagement flows, onboarding emails, or newsletter strategy.
- ▌ Job Description · yanacuti1121When the user needs to write, review, or improve a job posting for a startup role.
- ▌ Launch Strategy · yanacuti1121When the user needs to plan or execute a product launch — including pre-launch content sequences, launch funnels, JV/affiliate launches, cart open/close strategy, or evergreen launch funnels.
- ▌ Market Research · yanacuti1121When the user needs to estimate market size, understand market dynamics, or validate that a market opportunity is large enough to pursue.
- ▌ Onboarding Flow · yanacuti1121When the user needs to design, improve, or audit a post-signup activation flow to get new users to their first value moment. Activate when activation is lagging, time-to-value feels excessive, or first sessions lack impact.
- ▌ Security Review · yanacuti1121When the user needs a security assessment — threat modeling, vulnerability review, auth flow audit, dependency scanning, or says "is this secure", "review for vulnerabilities", "threat model", "security audit", "pen test prep".
- ▌ Startup Context · yanacuti1121When the user wants to create or update their startup context document. Also use when the user mentions "set up context", "tell you about my startup", or any other skill needs context that doesn't exist yet.
- ▌ Tech Stack Eval · yanacuti1121When the user needs to choose between technologies, frameworks, or tools — or says "which framework should I use", "compare X vs Y", "should we migrate from X to Y", "what database should I use", "calculate TCO".
- ▌ Create Subagents · yanacuti1121Expert guidance for creating, building, and using Claude Code subagents and the Task tool. Use when working with subagents, setting up agent configurations, understanding how agents work, or using the Task tool to launch specialized agents.
- ▌ Text Editor From Scratch · yanacuti1121Use when building a terminal or GUI text editor from first principles — buffer data structures, cursor handling, raw-mode terminal rendering, undo/redo. Not for configuring an existing editor. Triggers on: 'build a text editor', 'implement a text buffer', 'gap buffer vs piece table', 'terminal raw mode editor', 'write my own vim/nano clone', 'undo redo implementation for editor'.
- ▌ Venice Venice Responses · yanacuti1121Use Venice's Alpha POST /responses endpoint - an OpenAI-compatible Responses API with typed output blocks (reasoning, message, function_call, web_search_call). Covers request shape, streaming, differences from /chat/completions, supported venice_parameters subset, and E2EE behavior.
- ▌ Agency Pipeline · yanacuti1121Prospect Pipeline Manager — scans all audit files to build a scored, staged pipeline view with revenue projections
- ▌ Alibaba Open Code Review · yanacuti1121AI-powered code review CLI từ Alibaba — phân tích git diff, comment chính xác theo dòng, tích hợp GitHub Actions / GitLab CI. Đã review cho hàng chục nghìn developer nội bộ Alibaba.
- ▌ Tdd Guide · yanacuti1121Comprehensive Test Driven Development guide for engineering subagents with multi-framework support, coverage analysis, and intelligent test generation
- ▌ Automating Ioc Enrichment · yanacuti1121 bundleAutomates the enrichment of raw indicators of compromise with multi-source threat intelligence context using SOAR platforms, Python pipelines, or TIP playbooks to reduce analyst triage time and standardize enrichment outputs. Use when building automated enrichment workflows integrated with SIEM alerts, email submission pipelines, or bulk IOC processing from threat feeds. Activates for requests involving SOAR enrichment, Cortex XSOAR, Splunk SOAR, TheHive, Python enrichment pipelines, or automated IOC processing.
- ▌ Book Code Complete Full · yanacuti1121Code Complete (Steve McConnell) — Full rules — comprehensive mandatory coding standards. Use when asked to apply Code Complete principles or review code against Code Complete standards.
- ▌ Book Code Complete Mini · yanacuti1121Code Complete (Steve McConnell) — Condensed rules — key principles distilled. Use when asked to apply Code Complete principles or review code against Code Complete standards.
- ▌ Book Code Complete Nano · yanacuti1121Code Complete (Steve McConnell) — Minimal rules — essential one-liners only. Use when asked to apply Code Complete principles or review code against Code Complete standards.
- ▌ Detecting Wmi Persistence · yanacuti1121 bundleDetect WMI event subscription persistence by analyzing Sysmon Event IDs 19, 20, and 21 for malicious EventFilter, EventConsumer, and FilterToConsumerBinding creation.
- ▌ Event Driven Architecture · yanacuti1121Design event-driven systems — event sourcing, CQRS, saga pattern for distributed transactions, message queue patterns, and event schema design. Use when asked about "event sourcing", "CQRS", "saga", "distributed transaction", "message queue", "Kafka", "publish/subscribe", "event-driven", or "how to coordinate across services without direct calls". Do NOT use for: real-time WebSocket UI patterns — that is a frontend concern.
- ▌ Fixing Motion Performance · yanacuti1121Fix animation jank and layout thrashing — compositor-only properties, will-change hints, avoiding layout-triggering CSS, GPU layer promotion, requestAnimationFrame usage, reduced-motion support, and auditing with DevTools Performance panel. Use when asked to "animation is janky", "fix animation performance", "layout thrashing", "GPU acceleration", "will-change", "compositor layer", "60fps animations", "CSS animation vs JS animation", "prefers-reduced-motion", "scroll performance", or "why is my transition slow". Do NOT use for: accessibility of motion — see fixing-accessibility. Do NOT use for: designing animation curves and timing — see motion-design.
- ▌ Foundationagents Metagpt · yanacuti1121Multi-agent framework — assign roles (PM, architect, engineer) cho GPT team, build software từ 1 requirement. Dùng khi cần orchestrate multi-agent pipeline phức tạp.
- ▌ Git Native Agent Protocol · yanacuti1121Coordinate multiple AI agents using Git as the shared protocol — issues as task queues, branches as agent workspaces, PRs as deliverables, and commit messages as structured agent signals. Use when asked about "GNAP", "git native agent", "agents coordinating through git", "issue-driven agent", "PR as agent output", "multi-agent git workflow", "agent task board", "agents sharing work via repo", "agent kanban in git", or "how do agents hand off work without a message bus". Do NOT use for: real-time inter-agent messaging — see agent-messaging-patterns. Do NOT use for: single-agent worktree isolation — see worktree-safety.
- ▌ Postgres Hardening · yanacuti1121Harden a PostgreSQL deployment whether managed or self-hosted. Covers pg_hba network and authentication rules, role separation (read-only, read-write, migration), row-level security for multi-tenant data, TLS configuration, backup encryption, and pg_audit logging. Invoke when provisioning a new Postgres, before opening it to a new app, or when reviewing a multi-tenant schema for isolation gaps.
- ▌ Hadriansecurity Openhack · yanacuti1121Whitebox security review agent — checkpointed pentest workflow: recon → scenario routing → expert agents (12 OWASP families) → triage → findings. Runs inside Claude Code, Codex, or Cursor.
- ▌ Incident Response Runbook · yanacuti1121Run and document production incidents — severity classification, incident commander role, communication cadence, triage steps, post-incident review (PIR/postmortem) generation, and action item tracking. Use when asked about "incident response", "how to run an incident", "postmortem template", "PIR", "on-call runbook", "severity levels", or when a production issue is actively happening. Do NOT use for: SLO target design — use `slo-design`.
- ▌ Openai Github Gh Fix CI · yanacuti1121 bundleUse when a user asks to debug or fix failing GitHub PR checks that run in GitHub Actions. Use the GitHub app from this plugin for PR metadata and patch context, and use `gh` for Actions check and log inspection before implementing any approved fix.
- ▌ Recsys Pipeline Architect · yanacuti1121Design composable recommendation, ranking, and feed pipelines using the six-stage Source→Hydrator→Filter→Scorer→Selector→SideEffect framework popularized by xAI's open-sourced For You algorithm. Use this skill whenever the user is building any system that picks "the top K items for a (user, context)" — social feeds, content CMSs, RAG rerankers, task prioritizers, notification triage, search reranking, ad ranking.
- ▌ Content Strategy · yanacuti1121When the user needs to plan, prioritize, or structure a content program -- including identifying content pillars, mapping content to the buyer journey, choosing content types, or building an editorial calendar.
- ▌ Roadmap Planning · yanacuti1121When the user needs to organize product initiatives into a prioritized, time-sequenced plan with outcomes and dependencies.
- ▌ Terms Of Service · yanacuti1121When the user needs to draft, review, or update terms of service for their SaaS product or web application.
- ▌ State Management Patterns · yanacuti1121Choose and implement state management — local state, Zustand, Redux Toolkit, Jotai, React Query/TanStack Query, URL state, and when to use each. Use when asked about "state management", "Zustand", "Redux Toolkit", "RTK", "React Query", "TanStack Query", "Jotai", "server state vs client state", "global state", "state colocation", "useQuery", "useMutation", "optimistic update", "cache invalidation", or "when to use Redux". Do NOT use for: React Server Components state — see nextjs-patterns. Do NOT use for: WebSocket state — see websocket-patterns.
- ▌ Debug Like Expert · yanacuti1121Deep analysis debugging mode for complex issues. Activates methodical investigation protocol with evidence gathering, hypothesis testing, and rigorous verification. Use when standard troubleshooting fails or when issues require systematic root cause analysis.
- ▌ Untrusted Data Quarantine · yanacuti1121Read-only quarantine mode for processing data from untrusted sources — the reading agent may only summarize, classify, and flag risks; never edit files, run commands, or send data out. Filtered results are handed to a separate step for action. Use when handling 'dữ liệu chưa chắc đáng tin', 'untrusted input', 'tách quyền', 'quarantine this content', 'external paste', 'analyze suspicious file', or 'data from unknown source'. Do NOT use for: scanning for injection patterns — see prompt-firewall-patterns. Do NOT use for: OS-level sandboxing — see runtime-sandbox-runc / wasmtime-wasi-sandbox.
- ▌ Value Investing Checklist · yanacuti1121Buffett 6-gate checklist for any stock or company. Forces a hard pass/fail verdict with moat scoring, management trust rating, and margin of safety. No hedging, no "it depends". Inspired by ai-berkshire (MIT).
- ▌ Venice Venice Characters · yanacuti1121Discover and use Venice public characters (persona-driven system prompts with a bound model). Covers GET /characters (search/filter/sort), /characters/{slug}, /characters/{slug}/reviews, the Character schema, and how to apply a character via venice_parameters.character_slug in chat completions.
- ▌ Venice Venice Crypto Rpc · yanacuti1121Use Venice as a pay-per-call JSON-RPC proxy to 20+ EVM and Starknet networks. Covers GET /crypto/rpc/networks, POST /crypto/rpc/{network}, the 1×/2×/4× method-tier pricing model, per-minute + 24-hour credit rate limits, idempotency keys for safe retries, single vs batch requests, and the unsupported
- ▌ Venice Venice Embeddings · yanacuti1121Call POST /embeddings on Venice. Covers request shape (input, model, encoding_format, dimensions, user), OpenAI compatibility, response compression (gzip/br), and practical usage for retrieval, clustering, and RAG.
- ▌ Venice Venice Image Edit · yanacuti1121Transform existing images with Venice. Covers POST /image/edit (prompt-driven single-image edit), /image/multi-edit (compose 1-3 images), /image/upscale (2-4x upscale + enhance), and /image/background-remove. Accepts base64, file upload, or HTTPS URL.
- ▌ Voxel Engine From Scratch · yanacuti1121Use when building a voxel (cube-based) world engine from first principles — chunking, mesh generation, terrain generation. Not for general 3D rendering or using an existing voxel engine. Triggers on: 'build a voxel engine', 'minecraft-style world generation', 'chunk meshing', 'greedy meshing algorithm', 'voxel terrain generation', 'implement a block world'. Covers chunk representation, face culling, greedy meshing, and noise-based terrain.
- ▌ Adversarial Prompt Testing · yanacuti1121Test LLM applications for prompt injection, jailbreak, data exfiltration, and indirect injection attacks — attack taxonomy, test harness design, automated red-team probes, defense patterns, and evaluation rubrics. Use when asked about "prompt injection", "jailbreak", "LLM red team", "adversarial prompts", "indirect injection", "exfiltration via LLM", "test AI security", "LLM attack surface", "OWASP LLM Top 10", "system prompt leak", "prompt leaking", or "AI safety testing". Do NOT use for: traditional app security — see red-team-check or security-review. Do NOT use for: model alignment — focus is on app layer.
- ▌ Analyzing Cyber Kill Chain · yanacuti1121 bundleAnalyzes intrusion activity against the Lockheed Martin Cyber Kill Chain framework to identify which phases an adversary has completed, where defenses succeeded or failed, and what controls would have interrupted the attack at earlier phases. Use when conducting post-incident analysis, building prevention-focused security controls, or mapping detection gaps to kill chain phases. Activates for requests involving kill chain analysis, intrusion kill chain, attack phase mapping, or Lockheed Martin kill chain framework.
- ▌ Chrome Devtools Extensions · yanacuti1121Install, manage, reload, and trigger Chrome extensions via Chrome DevTools MCP. Enables agent-driven extension testing, side-loading unpacked extensions, and extension action automation.
- ▌ Chrome Devtools Screencast · yanacuti1121Capture screenshots and record live screencasts from Chrome via DevTools MCP. Use for visual regression, agent state verification, bug reproduction capture, and frame-by-frame UI analysis.
- ▌ Detecting Rootkit Activity · yanacuti1121 bundleDetects rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modified kernel structures, hidden files, and covert network connections using memory forensics, cross-view detection, and integrity checking techniques. Activates for requests involving rootkit detection, hidden process discovery, kernel integrity checking, or system call hook analysis.
- ▌ AI Agent Guardrails · yanacuti1121Apply safety controls when an LLM agent has authority to act on real systems. Covers blast-radius classification, dry-run-first patterns, out-of-band approval gates, scope locking, idempotency, kill switches, and rollback strategies. Invoke when designing an autonomous agent, when granting an LLM write access to production, or after an agent makes an unexpected change.
- ▌ Kubernetes Security · yanacuti1121Harden a Kubernetes cluster's data plane and control plane. Covers Pod Security Standards (Restricted, Baseline, Privileged), RBAC with least privilege, NetworkPolicy default-deny, secrets management without raw env vars, admission controllers (Kyverno, OPA Gatekeeper), image scanning, and audit logging. Invoke when provisioning a new cluster, inheriting one, or before adding a new tenant to a shared cluster.
- ▌ Wordpress Hardening · yanacuti1121Detect and contain WordPress compromises, then harden the install against re-entry. Covers webshell detection across the Sid Gifari, WSO, FilesMan, b374k and c99 families, backdoored mu-plugins, malicious admin accounts, and shared-hosting lateral-movement defense. Invoke when a WordPress site shows unexpected files, suspicious admin accounts, defaced pages, or when hardening a fresh install on shared hosting.
- ▌ Hunting For Dcsync Attacks · yanacuti1121 bundleDetect DCSync attacks by analyzing Windows Event ID 4662 for unauthorized DS-Replication-Get-Changes requests from non-domain-controller accounts.
- ▌ Monitoring Darkweb Sources · yanacuti1121 bundleMonitors dark web forums, marketplaces, paste sites, and ransomware leak sites for mentions of organizational assets, leaked credentials, threatened attacks, and threat actor communications to provide early warning intelligence. Use when establishing dark web monitoring coverage, investigating specific data breach claims, or enriching incident investigations with dark web context. Activates for requests involving dark web OSINT, leak site monitoring, credential exposure, Recorded Future dark web, or Tor hidden service intelligence.
- ▌ Openai Supabase Supabase · yanacuti1121 bundleUse when doing ANY task involving Supabase. Triggers: Supabase products (Database, Auth, Edge Functions, Realtime, Storage, Vectors, Cron, Queues); client libraries and SSR integrations (supabase-js, @supabase/ssr) in Next.js, React, SvelteKit, Astro, Remix; auth issues (login, logout, sessions, JWT, cookies, getSession, getUser, getClaims, RLS); Supabase CLI or MCP server; schema changes, migrations, security audits, Postgres extensions (pg_graphql, pg_cron, pg_vector).
- ▌ Fundraising Email · yanacuti1121When the user wants to write an email to an investor — cold outreach, warm intro request, follow-up after a meeting, monthly investor update, or thank-you note. Also activates for "intro email", "investor email", "follow up with VC", or "investor update".
- ▌ Investor Research · yanacuti1121When the user wants to identify, evaluate, or prioritize potential investors for a fundraising round. Also activates when the user asks "who should I pitch?", "find me investors", "build an investor list", or mentions VC/angel targeting.
- ▌ Sourcing Outreach · yanacuti1121When the user needs to write recruiting outreach messages to attract passive candidates or request referrals.
- ▌ Stealth Browser Automation · yanacuti1121Use when asked to scrape a bot-protected website, bypass anti-bot detection, run Playwright with stealth patches, automate a site that blocks normal browsers, or simulate human-like browser behavior. Triggers on: 'scrape protected site', 'bypass bot detection', 'stealth playwright', 'anti-bot browser', 'cloudflare bypass', 'captcha avoidance', 'humanized browser', 'fingerprint evasion', 'botasaurus', 'python scraper', 'scraper ui', 'parallel scraping', 'trình duyệt chống phát hiện', 'vượt qua bot detection', 'cào dữ liệu trang bảo vệ'.
- ▌ Create MCP Servers · yanacuti1121Create Model Context Protocol (MCP) servers that expose tools, resources, and prompts to Claude. Use when building custom integrations, APIs, data sources, or any server that Claude should interact with via the MCP protocol. Supports both TypeScript and Python implementations.
- ▌ Testing JWT Token Security · yanacuti1121 bundleAssessing JSON Web Token implementations for cryptographic weaknesses, algorithm confusion attacks, and authorization bypass vulnerabilities during security engagements.
- ▌ Triaging Security Incident · yanacuti1121 bundlePerforms initial triage of security incidents to determine severity, scope, and required response actions using the NIST SP 800-61r3 and SANS PICERL frameworks. Classifies incidents by type, assigns priority based on business impact, and routes to appropriate response teams. Activates for requests involving incident triage, security alert classification, severity assessment, incident prioritization, or initial incident analysis.
- ▌ Venice Venice Audio Music · yanacuti1121Async music / audio-track generation via Venice. Covers the /audio/quote + /audio/queue + /audio/retrieve + /audio/complete lifecycle, lyrics vs instrumental, voice selection, duration, language, speed, model capability probing, and webhook-free polling.
- ▌ Agency Report PDF · yanacuti1121Unified PDF report generator — combines all audit scores into a professional client-ready PDF