
Claude Skills by jmagly
github.com/jmaglyConfigure pnpm's minimumReleaseAge gate (7-day default, 10-day high-sensitivity) plus blockExoticSubdeps for workspace-scope dep-source enforcement. Includes Corepack detection and lockfile-caveat warning.
Detect language/toolchain and emit CI job recipes that build with runtime sanitizers (ASan/UBSan/MSan/TSan, race detectors, faulthandler)
Decision aid for runtime secret hygiene — fd passing, scratch surface, error-path safety, identifier hygiene, and avoiding the SECRETS_ENV aggregation anti-pattern.
Track private vulnerability reports from triage through fix, CVE coordination, embargo, publication, and post-disclosure closure
AUTO-INVOKE when user mentions cryptography, AEAD, KDF, chain of trust, signing key, auth factor, MFA, secret hygiene, supply chain trust, physical threat, DFIR readiness, or incident evidence handoff. Security-engineering quick reference — decision domains for crypto primitives, chain-of-trust, auth factors, degraded modes, supply-chain trust, physical-threat modeling, and DFIR readiness routing.
Guide a reporter through filing a private vulnerability report and route it to the project's configured private channel — never to a public issue tracker
Check build and CI configuration for warning-as-error, strict typechecking, and language-specific compiler/linter floors
Orchestrate a pragmatic npm supply-chain hardening pass: dependency-source audit, release-age gate, lifecycle-script review, trusted publishing, signed releases, SBOM, and user verification docs.
Decision aid for supply-chain trust beyond CVE/SBOM — pinning depth, reproducible builds, snapshot pins, firmware locking, and vendor+hash-lock for critical-path deps.
Configure Yarn's npmMinimalAgeGate (7-day default, 10-day high-sensitivity) for JavaScript projects on Yarn 4.x or later. Includes Corepack detection and lockfile-caveat warning.
Address open issues using issue-thread-driven agent loops with 2-way human-AI collaboration
Search AIWG knowledge base for help, documentation, and troubleshooting
Update project CLAUDE.md with AIWG framework context and configuration
Setup Warp Terminal with AIWG framework context (preserves existing content)
Update AGENTS.md with project-specific context for Factory AI based on codebase analysis
Update existing project CLAUDE.md with latest AIWG orchestration guidance
Analyze project state from .aiwg/ artifacts and provide contextual status with recommended next steps
AWS, Azure, and GCP forensic investigation covering audit logs, IAM review, storage access, network flows, and compute instance forensics
Forensic investigation of Docker, containerd/CRI-O, and Kubernetes — inventory, escape detection, eBPF runtime monitoring, RBAC and etcd audit. Use when investigating container compromise.
Chain of custody and evidence preservation procedures covering log collection, hash verification, custody documentation, and evidence packaging per RFC 3227
Evidence acquisition with chain of custody and hash verification
Threat hunt using Sigma rules against log sources
Full multi-agent investigation workflow
Extract and enrich indicators of compromise
Build target system profile via SSH or cloud API enumeration
Forensics framework quick reference — capability domains and curated discovery phrases for incident response, log analysis, evidence preservation, and IOC extraction
Generate forensic investigation report
Show investigation status dashboard
Build correlated event timeline from multiple sources
Quick triage investigation following RFC 3227 volatility order
Extract, classify, deduplicate, and enrich IOCs from investigation artifacts; map to STIX 2.1 observables
Generalized Linux incident response and forensic analysis covering Debian/Ubuntu, RHEL/CentOS/Rocky, and SUSE families
Correlate auth.log, syslog, journald, application, and web logs to detect brute force, privilege escalation, and lateral movement.
Volatility 3 memory forensics workflows covering acquisition with LiME and WinPmem, and structured analysis using Volatility 3 plugin reference
Apply Sigma rules against log sources for threat hunting; convert rules to Elasticsearch, Splunk, and grep queries
SBOM analysis, build pipeline forensics, and dependency verification covering package integrity, build reproducibility, and CI/CD pipeline tampering
Research and build a target system profile via SSH — discovers OS, services, users, network baseline, and security stack
Lint and health-check the knowledge base. Finds orphan pages, missing cross-references, stale claims, broken wiki-links, and regenerates the index.
Ingest a source (URL, file, or freeform note) into the knowledge base. Creates a source summary and updates or creates relevant entity and concept pages.
Knowledge-base framework quick reference — capability domains and curated discovery phrases for KB ingest/health, semantic-memory kernel skills, and llm-wiki profiles
Project directory path (default current directory)
Project directory path (default current directory)
Refine brand identity through metaphor testing, competitive research, and owner-grounded verification tied to repository reality
Project directory path (default current directory)
Project directory path (default current directory)
Project directory path (default current directory)
Project directory path (default current directory)
Project directory path (default current directory)
Project directory path (default current directory)
Project directory path (default current directory)