
Claude Skills by domehahn
github.com/domehahnReview ICT incident classification, escalation, documentation, reportability, timelines, responsibilities, templates, and communication chains.
Review ICT risks, protection needs, criticality, controls, residual risks, treatment, and recurring reassessment.
Review cloud, SaaS, outsourcing, subcontractors, contracts, exit strategies, concentration risks, and DORA information-register readiness.
Review IAM, roles, service accounts, groups, tokens, OIDC federation, GitLab or GitHub permissions, cloud rights, and privilege-escalation paths.
Support incident analysis, timeline creation, root cause analysis, impact assessment, corrective actions, and follow-up issues.
Review modern Java code, JVM behavior, concurrency, APIs, testing, performance, and maintainability.
Review modern JavaScript for async behavior, modules, runtime correctness, security, tests, and performance.
Review Kotlin code for null safety, coroutines, sealed models, Java interop, Gradle configuration, and tests.
Review Kubernetes clusters, namespaces, RBAC, NetworkPolicies, Pod Security, admission controllers, resource limits, secrets, ingress, tenancy, and upgrades.
Review GenAI workloads for prompt injection, tool permissions, data exfiltration, RAG sources, sensitive prompt logging, evals, guardrails, and model access.
Review database migrations, schema changes, breaking changes, rollback ability, backward compatibility, and zero-downtime deployments.
Review model versioning, training data, bias, drift, monitoring, approvals, reproducibility, model registry, and deployment gates.
Review Next.js routing, Server and Client Components, caching, data fetching, security, deployment, and performance.
Review Node.js services for event-loop safety, async behavior, modules, streams, HTTP security, dependencies, and operations.
Review logging, metrics, tracing, health checks, alerts, dashboards, runbooks, and operational readiness.
Review OpenTofu modules, providers, plans, state, drift, lifecycle, tests, and safe apply or destroy boundaries.
Review backup and restore, failover, disaster recovery, restart procedures, crisis exercises, scenario tests, and lessons learned.
Review exit plans, data return, provider transitions, emergency operations, suboutsourcing, cloud dependencies, and business impact.
Review payment controls and evidence for PCI DSS, privacy, SCA, retention, access, auditability, outsourcing, and exceptions.
Test authorization, capture, settlement, cancellation, refund, timeout, decline, authentication, webhook delay, and provider outage paths.
Review payment fraud signals, velocity controls, risk rules, step-up actions, manual review, false positives, and feedback loops.
Design and implement provider-neutral payment integrations with explicit state machines, idempotency, failure recovery, and auditable order linkage.
Review payment conversion, authorization, webhook, refund, reconciliation, latency, provider health, alerts, and privacy-safe telemetry.
Support controlled capture, cancellation, refund, resend, and lookup operations with approval, limits, idempotency, and audit records.
Review payment-provider migrations for parity, token portability, dual processing, routing, reconciliation, rollback, and decommissioning.
Reconcile orders, provider transactions, fees, refunds, chargebacks, settlements, payouts, and ledger entries.
Review payment data flows, tokenization, credential boundaries, PCI DSS scope, authorization, sensitive logging, and checkout abuse cases.
Review payment webhooks for signature verification, replay and duplicate handling, ordering, durable processing, retries, and reconciliation.
Design and review PayPal Orders and Captures, PayPal-Request-Id, OAuth boundaries, verified webhooks, refunds, and sandbox tests.
Review load behavior, bottlenecks, caching, database access, queue behavior, scaling, timeouts, and resource limits.
Review modern PHP code for type safety, Composer hygiene, framework boundaries, security, tests, and performance.
Design and review secure CI/CD pipelines with isolated runners, minimal rights, OIDC, signed artifacts, protected environments, and approval gates.
Create and review policies for OPA/Rego, Kyverno, GitLab Policies, Conftest, Checkov, Terraform, Kubernetes, and CI/CD gates.
Review GitLab Security Policies, OPA/Rego, Kyverno, Conftest, Sentinel, admission policies, compliance pipelines, and central guardrails.
Create and update policies, standards, procedures, and control descriptions.
Review privacy, personal data, data classification, deletion concepts, purpose limitation, GDPR risks, and sensitive-data logging.
Review Python code for typing, packaging, async behavior, resource safety, tests, security, and maintainability.
Review Quarkus build-time behavior, CDI, reactive paths, native images, configuration, security, and tests.
Review React components, hooks, state, rendering, accessibility, Server Components, testing, and performance.
Guide controlled refunds, reversals, chargebacks, and disputes with eligibility checks, evidence, deadlines, approval, and audit trails.
Assess release readiness, rollback, migrations, feature flags, monitoring, documentation, and breaking changes.
Analyze requirements, user stories, acceptance criteria, constraints, risks, and open questions before implementation.
Review timeouts, retries, circuit breakers, failover, backpressure, degraded modes, and resilience behavior.
Document and assess conscious risk decisions, impact and likelihood, expiry dates, and compensating measures.
Review Rails models, controllers, jobs, migrations, Active Record behavior, security, tests, and deployment safety.
Review Ruby code for idioms, object design, metaprogramming boundaries, Bundler hygiene, tests, and performance.
Create and review runbooks, operating instructions, incident playbooks, escalation paths, restart procedures, and checklists.
Review Rust ownership, lifetimes, unsafe boundaries, concurrency, error handling, Cargo dependencies, and tests.
Create or modify code, tests, configuration, and project files safely with real file changes.
Review SBOM generation, CVE triage, VEX, exception processes, patch SLAs, and the vulnerability lifecycle.