
Claude Skills by andycungkrinx91
github.com/andycungkrinx91'Performs OAuth 2.0 scope minimization review to identify over-permissioned
Monitor paste sites like Pastebin and GitHub Gists for leaked credentials,
GoPhish is an open-source phishing simulation framework used by security
'Executes a structured ransomware incident response from initial detection
'Plans and facilitates tabletop exercises simulating ransomware incidents
Automate GoPhish phishing simulation campaigns using the Python gophish
Automate credential rotation for service accounts across Active Directory,
Perform recon, persistence, privilege escalation, and data search via the Microsoft Graph API using GraphRunner.
'Executes structured recovery from a ransomware incident following NIST
Run ntlmrelayx into ADCS web enrollment to obtain a domain controller certificate via ESC8.
Reverse engineer ransomware encryption routines to identify cryptographic
Scan container images, IaC, and SBOMs for vulnerabilities and misconfigurations in CI/CD with Trivy.
'This skill guides practitioners through hardening AWS Identity and Access
Test and validate ransomware recovery procedures including backup restore
Threat actor infrastructure tracking involves monitoring and mapping
Run targeted forensic artifact collection and module parsing with KAPE.
Validate backup integrity through cryptographic hash verification, automated
Standard Operating Procedures for web research, documentation lookup, evidence synthesis with citations.
Standard Operating Procedures for read-only codebase exploration, symbol search, dependency mapping, code tracing, code review, architecture analysis, technical research, source evaluation, and evidence-based reporting.
Standard Operating Procedures and router for premium UI development, design match comparison, component architecture, and 3D web experiences.
Standard Operating Procedures for architecture decisions, security audits, deep code analysis, risk assessment, and critical problem solving.
Use when the user requests diagrams, flowcharts, architecture diagrams, ER diagrams, UML / sequence / class diagrams, SysML / MBSE diagrams (block definition, internal block, requirement, parametric), BPMN business process diagrams, swimlane / cross-functional flowcharts, network topology, cloud architecture from Terraform or Kubernetes manifests, ML/DL model figures (Transformer/CNN/LSTM), mind maps, or any visualization. Also use proactively when explaining systems with 3+ components, compl...
Guidelines and instructions for maintaining, extending, and debugging the Konoha MCP Tools Orchestrator, MCP middleware, and multi-archetype website builder across 7 coding clients (Antigravity IDE/CLI, Cursor, Claude Code, OpenCode, Command Code, Codex, Pi/pi.dev).
Standard Operating Procedures and router for MCP task triage, subagent selection, and orchestration.
Standard Operating Procedures for technical writing, README creation, API specifications, runbooks, and documentation updates.
Use when creating, editing, or generating draw.io diagram files
Design, organize, and manage Helm charts for templating and
Create optimized multi-stage Dockerfiles for any language or framework
React 18/19 patterns including hooks discipline, server/client component boundaries, Suspense + error boundaries, form actions, data fetching, state management decision trees, and accessibility-first composition. Use when writing or reviewing React components.
React component testing with React Testing Library, Vitest/Jest, MSW for network mocking, accessibility assertions with axe, and the decision boundary between component tests and Playwright/Cypress end-to-end runs. Use when writing or fixing tests for React components, hooks, or pages.
Standard Operating Procedures for backend development, bug fixing, DevOps, infrastructure deployment, and security hardening.
Extract DPAPI-protected secrets such as credentials and browser data offline and online.
Take over Active Directory user and computer accounts by writing alternate certificate keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, and Certipy, then authenticate via PKINIT.
Monitor Certificate Transparency logs using crt.sh and Certstream to
Parse and analyze email headers to trace the origin of phishing emails,
'Analyzes indicators of compromise (IOCs) including IP addresses, domains,
'Analyzes malicious Linux ELF (Executable and Linkable Format) binaries
'Analyzes encryption algorithms, key management, and file encryption
Monitor and analyze ransomware group data leak sites (DLS) to track victim
'Traces ransomware cryptocurrency payment flows using blockchain analysis
'Queries Certificate Transparency logs via crt.sh and pycrtsh to detect
Detect typosquatting, homograph phishing, and brand impersonation domains
Enumerate Entra ID with ROADrecon and acquire and exchange tokens with roadtx.
Run OAuth 2.0 device-code and illicit-consent phishing against Microsoft Entra ID to steal access and refresh tokens, bypass MFA, and pivot across Microsoft 365 services.
Run Microsoft Entra ID tenant reconnaissance, token acquisition and manipulation, and federation backdoor testing with the AADInternals PowerShell toolkit to validate identity-attack resilience.
'Auditing Kubernetes cluster RBAC configurations to identify overly permissive
Find over-permissive RBAC roles and service-account token abuse paths in Kubernetes using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess during authorized cluster security reviews.
Run CIS Kubernetes Benchmark checks and remediate findings with kube-bench.
Architect redirectors with nginx and Apache, malleable profiles, and OPSEC
Establish SAML 2.0 identity federation between on-premises Active Directory