
Claude Skills by domehahn
github.com/domehahnReview Zuplo (member) using its official documentation and repository in the CNCF Members / Silver category.
Review Zuul using its official documentation and repository in the App Definition and Development / Continuous Integration & Delivery category. Zuul is a system that drives continuous integration, delivery, and deployment with a focus on project gating and interrelated projects.
Review governance controls such as CODEOWNERS, branch protection, approvals, auditability, and policy compliance.
Review Dockerfiles, base images, user rights, capabilities, SBOM, image signing, distroless or slim images, CVEs, and runtime hardening.
Map technical measures to DORA, VAIT or BAIT migration needs, ISO 27001, BSI, internal policies, or MaRisk review expectations.
Plan coding work with minimal context, relevant file selection, risk awareness, rollback, and validation strategy.
Review C# and .NET code for async correctness, dependency injection, resource disposal, nullable types, tests, and performance.
Review dependencies, lockfiles, package managers, container images, actions, and supply-chain risks.
Review setup, local development, error messages, Makefiles or scripts, onboarding, tooling consistency, and practicality for teams.
Assess maturity across plan, code, build, test, release, deploy, and operate with automation, security gates, ownership, and feedback loops.
Review Django models, migrations, ORM usage, authentication, middleware, settings, tests, and deployment safety.
Review documentation freshness, ownership, review cycles, approvals, versioning, validity, and traceability.
Create and update README files, ADRs, setup guides, API docs, runbooks, and operational documentation.
Review DORA readiness for ICT risk management, resilience testing, incidents, third-party risk, roles, policies, evidence, and auditability.
Create auditable evidence packages from tickets, pipeline results, test reports, approvals, scans, and architecture information.
Review FastAPI schemas, dependency injection, async paths, authentication, validation, OpenAPI, tests, and operations.
Review cloud costs, budgets, rightsizing, reserved or committed usage, anomalies, showback or chargeback, and team cost transparency.
Review GCP organizations, projects, IAM, networking, compute, data services, observability, cost, and resilience.
Review Argo CD or Flux setups, sync policies, drift detection, promotion, rollback, app-of-apps, secrets, cluster access, and deployment governance.
Review Go code for idioms, concurrency, context propagation, errors, interfaces, modules, tests, and performance.
Review Helm charts, templates, values, dependencies, hooks, secrets, schema validation, upgrades, and rollbacks.
Review Terraform, Kubernetes, Helm, Kustomize, GitOps reconciliation, promotion, and environment safety.
Review ICT incident classification, escalation, documentation, reportability, timelines, responsibilities, templates, and communication chains.
Review ICT risks, protection needs, criticality, controls, residual risks, treatment, and recurring reassessment.
Review cloud, SaaS, outsourcing, subcontractors, contracts, exit strategies, concentration risks, and DORA information-register readiness.
Review IAM, roles, service accounts, groups, tokens, OIDC federation, GitLab or GitHub permissions, cloud rights, and privilege-escalation paths.
Support incident analysis, timeline creation, root cause analysis, impact assessment, corrective actions, and follow-up issues.
Review modern Java code, JVM behavior, concurrency, APIs, testing, performance, and maintainability.
Review modern JavaScript for async behavior, modules, runtime correctness, security, tests, and performance.
Review Kotlin code for null safety, coroutines, sealed models, Java interop, Gradle configuration, and tests.
Review Kubernetes clusters, namespaces, RBAC, NetworkPolicies, Pod Security, admission controllers, resource limits, secrets, ingress, tenancy, and upgrades.
Review GenAI workloads for prompt injection, tool permissions, data exfiltration, RAG sources, sensitive prompt logging, evals, guardrails, and model access.
Review database migrations, schema changes, breaking changes, rollback ability, backward compatibility, and zero-downtime deployments.
Review model versioning, training data, bias, drift, monitoring, approvals, reproducibility, model registry, and deployment gates.
Review Next.js routing, Server and Client Components, caching, data fetching, security, deployment, and performance.
Review Node.js services for event-loop safety, async behavior, modules, streams, HTTP security, dependencies, and operations.
Review logging, metrics, tracing, health checks, alerts, dashboards, runbooks, and operational readiness.
Review OpenTofu modules, providers, plans, state, drift, lifecycle, tests, and safe apply or destroy boundaries.
Review backup and restore, failover, disaster recovery, restart procedures, crisis exercises, scenario tests, and lessons learned.
Review exit plans, data return, provider transitions, emergency operations, suboutsourcing, cloud dependencies, and business impact.
Review payment controls and evidence for PCI DSS, privacy, SCA, retention, access, auditability, outsourcing, and exceptions.
Test authorization, capture, settlement, cancellation, refund, timeout, decline, authentication, webhook delay, and provider outage paths.
Review payment fraud signals, velocity controls, risk rules, step-up actions, manual review, false positives, and feedback loops.
Design and implement provider-neutral payment integrations with explicit state machines, idempotency, failure recovery, and auditable order linkage.
Review payment conversion, authorization, webhook, refund, reconciliation, latency, provider health, alerts, and privacy-safe telemetry.
Support controlled capture, cancellation, refund, resend, and lookup operations with approval, limits, idempotency, and audit records.
Review payment-provider migrations for parity, token portability, dual processing, routing, reconciliation, rollback, and decommissioning.
Reconcile orders, provider transactions, fees, refunds, chargebacks, settlements, payouts, and ledger entries.
Review payment data flows, tokenization, credential boundaries, PCI DSS scope, authorization, sensitive logging, and checkout abuse cases.
Review payment webhooks for signature verification, replay and duplicate handling, ordering, durable processing, retries, and reconciliation.