
Claude Skills by domehahn
github.com/domehahnReview Strong Customer Authentication and 3-D Secure challenge, exemption, liability, fallback, accessibility, and state handling.
Detect and prevent exposure of secrets, tokens, credentials, private keys, CI variables, and sensitive logs.
Review code vulnerabilities such as injection, path traversal, SSRF, XSS, deserialization, crypto misuse, and race conditions.
Review secure-by-design decisions, least privilege, Zero Trust, tenant separation, secure defaults, and abuse scenarios.
Review Internal Developer Platforms for secure golden paths, self-service guardrails, templates, permission models, secrets handling, and auditability.
Derive negative tests and declarative evals from contract capabilities, tools, data flows, approvals, limits, and structured invariants.
Review code, CI/CD, configuration, permissions, dependencies, input validation, and DevSecOps risks.
Review SLSA, provenance, SBOM, signatures, attestations, build integrity, artifact promotion, and trusted builders.
Review Spring Boot dependency injection, transactions, persistence, security, configuration, Actuator, and migrations.
Assess SLOs, SLIs, error budgets, capacity, degradation, timeouts, retries, circuit breakers, load shedding, and operational risks.
Design and review Stripe PaymentIntents or Checkout, idempotency, signed webhooks, Connect or Billing boundaries, versions, and tests.
Design subscription billing for plans, trials, invoices, proration, usage, renewals, dunning, cancellation, and entitlements.
Review Terraform modules, providers, plans, state, drift, lifecycle, IAM, tests, and safe apply or destroy boundaries.
Design and generate unit, integration, regression, security, and end-to-end test strategies.
Identify assets, trust boundaries, abuse cases, attack paths, threats, and required security controls.
Review TypeScript strictness, narrowing, generics, declarations, runtime validation, and compiler configuration.
Create, adapt, validate, and optimize reusable agent skills across agentic platforms.
Review Vagrant environments, providers, networking, provisioning, shared folders, reproducibility, and isolation.
Review diffs, validate acceptance criteria, inspect test results, and find missed requirements.
Review VM and virtualization architecture, images, isolation, networking, storage, snapshots, patching, and capacity.
Review Vue.js Composition API, reactivity, components, state, routing, accessibility, tests, and performance.
Assess CVE triage, prioritization, SLAs, exploitability, asset criticality, exceptions, risk acceptance, and remediation tracking.
Design and review Adyen Checkout, merchant references, idempotency, HMAC webhooks, asynchronous results, modifications, and tests.
Design trajectory-level agent security evals for Goal compliance, contract boundaries, goal hacking, unsafe tools, and long-horizon behavior.
Review agent sandboxes, transitive egress, privilege escalation, lateral movement, shared infrastructure, monitoring, and kill switches.
Compare declared agent contracts with independent runtime enforcement across tools, files, processes, networks, secrets, approvals, and limits.
Threat-model agents as untrusted principals across prompts, tools, MCP, memory, delegation, runtime infrastructure, and external systems.
Review AI-assisted changes before execution for automation boundaries, human approval, affected-system criticality, and audit evidence.
Assess correlation of logs, metrics, traces, events, and incidents to reduce noise, improve root-cause analysis, and lower alert fatigue.
Review alerts for actionability, clear symptoms, runbook links, severity, ownership, SLO relation, deduplication, escalation, and remediation suitability.
Review Angular components, signals, RxJS, forms, routing, state, accessibility, testing, and bundle performance.
Review Ansible inventories, roles, playbooks, idempotency, secrets, privilege escalation, testing, and rollout safety.
Review REST, GraphQL, OpenAPI, and gRPC contracts, breaking changes, versioning, AuthN/AuthZ, error formats, and compatibility.
Create and maintain ADRs with context, decisions, alternatives, risks, security impact, compliance relation, and review points.
Review architecture, module boundaries, interfaces, coupling, scalability, data flows, and technical risks.
Review evidence, approvals, tickets, logs, test protocols, risk decisions, versioning, and accountable owners.
Link requirements, controls, implementation, tests, tickets, and evidence into an auditable trace.
Review automated repair actions for safe limits, dry runs, approval modes, rollback, audit logs, blast radius, and loop protection.
Review AWS accounts, IAM, networking, compute, storage, databases, observability, security, cost, and resilience.
Review Azure tenants, subscriptions, identities, networks, compute, data services, Policy, monitoring, cost, and resilience.
Review changes for hidden privileged paths, triggers, covert egress, persistence, security-control tampering, and unexplained behavior.
Review restore tests, RPO/RTO, data integrity, backup protection, recoverability, and disaster recovery.
Review CI/CD pipelines, runners, permissions, artifacts, caches, deployment gates, and token exposure.
Review cloud naming, tags, ownership, cost centers, allowed services, regions, data classification, policy enforcement, and audit evidence.
Review cloud accounts or subscriptions, networks, IAM, logging, policies, baselines, guardrails, encryption, tagging, and tenant separation.
Review 1NCE (member) using its official documentation and repository in the CNCF Members / Silver category.
Review 23 Technologies (member) using its official documentation and repository in the CNCF Members / Silver category.
Review 3-Shake (KCSP) using its official documentation and repository in the Special / Kubernetes Certified Service Provider category.
Review 3-Shake (member) using its official documentation and repository in the CNCF Members / Silver category.
Review 3Scale using its official documentation and repository in the Orchestration & Management / API Gateway category.