
Claude Skills by Undermybelt
github.com/UndermybeltOBLITERATUS: abliterate LLM refusals (diff-in-means).
SAM: zero-shot image segmentation via points, boxes, masks.
TRL: SFT, DPO, PPO, GRPO, reward modeling for LLM RLHF.
Create professional architecture, workflow, sequence, data-flow, and lifecycle/state diagrams as standalone HTML files with SVG graphics, a built-in dark/light theme toggle, and one-click export to PNG / JPEG / WebP / SVG. Use when the user asks for system architecture diagrams, infrastructure diagrams, cloud architecture visualizations, security diagrams, network topology diagrams, technical workflows, approval flows, runbooks, CI/CD flows, process diagrams, API call sequences, request lifec...
Gmail, Calendar, Drive, Docs, Sheets via gws CLI or Python.
Practical guide for using an external/shared memory system such as MemOS alongside Hermes memory and session search.
Extract text from PDFs/scans (pymupdf, marker-pdf).
Use when operating productivity platforms and document/work-management APIs from Hermes: Airtable, Linear, Notion, PowerPoint, PDF editing, Teams meeting pipelines, maps/location, or email/document workflows.
Use when a task involves continuing a project, restoring project context, maintaining file-based project memory, updating current-state summaries, or recording meaningful progress across sessions. Works best for long-horizon, file-based projects and supports research writing, product document collaboration, software project coordination, and broader cross-functional project continuity.
Configure and execute access recertification campaigns in Saviynt Enterprise Identity Cloud to validate user
Conduct systematic access reviews and certifications to ensure users have appropriate access rights aligned with
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and
'Executes authorized attack simulations against Active Directory environments to identify misconfigurations,
Use BloodHound and SharpHound to enumerate Active Directory relationships and identify attack paths from compromised
BloodHound is a graph-based Active Directory reconnaissance tool that uses graph theory to reveal hidden and
Exploit misconfigured Active Directory Certificate Services (AD CS) ESC1 vulnerability to request certificates
Investigate Active Directory compromise by analyzing authentication logs, replication metadata, Group Policy
Enumerate and audit Active Directory forest trust relationships using impacket for SID filtering analysis, trust
'Deploys deception-based honeytokens in Active Directory including fake privileged accounts with AdminCount=1,
Conduct a focused Active Directory penetration test to enumerate domain objects, discover attack paths with BloodHound,
Implement Microsoft's Enhanced Security Admin Environment (ESAE) tiered administration model for Active Directory.
Assess Active Directory security posture using PingCastle, BloodHound, and Purple Knight to identify misconfigurations,
'Proactively hunts for Advanced Persistent Threat (APT) activity within enterprise environments using hypothesis-driven
Build an automated system to track adversary infrastructure using passive DNS, certificate transparency, WHOIS
Detect and respond to Adversary-in-the-Middle (AiTM) phishing attacks that use reverse proxy kits like EvilProxy,
AES (Advanced Encryption Standard) is a symmetric block cipher standardized by NIST (FIPS 197) used to protect
Configure and execute agentless vulnerability scanning using network protocols, cloud snapshot analysis, and
Use AI and LLM-based reasoning to correlate findings across multiple OSINT sources—username enumeration, email
'Detects prompt injection attacks targeting LLM-based applications using a multi-layered defense combining regex
'Implements strategies to reduce SOC alert fatigue by tuning detection rules, consolidating duplicate alerts,
Perform systematic alert triage in Elastic Security SIEM to rapidly classify, prioritize, and investigate security
'Performs automated static analysis of Android applications using Mobile Security Framework (MobSF) to identify
'Tests Android inter-process communication (IPC) through intents for vulnerabilities including intent injection,
Perform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source
'This skill covers deploying anomaly detection systems for industrial control environments using machine learning
'Detects anomalous authentication patterns using UEBA analytics, statistical baselines, and machine learning
'Hunt for malicious PowerShell activity by analyzing Script Block Logging (Event 4104), Module Logging (Event
Security awareness training is the human layer of phishing defense. An effective anti-phishing training program
'Configures Windows Group Policy Objects (GPO) to prevent ransomware execution and limit its spread. Implements
Implement API abuse detection using token bucket, sliding window, and adaptive rate limiting algorithms to prevent
'Tests API authentication mechanisms for weaknesses including broken token validation, missing authentication
'Tests REST and GraphQL APIs for Broken Object Level Authorization (BOLA/IDOR) vulnerabilities where an authenticated
Detect and prevent API enumeration attacks including BOLA and IDOR exploitation by monitoring sequential identifier
'Uses Microsoft RESTler to perform stateful REST API fuzzing by automatically generating and executing test sequences
'Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass,
'Securing API Gateway endpoints with AWS WAF by configuring managed rule groups for OWASP Top 10 protection,
'Implements security controls at the API gateway layer including authentication enforcement, rate limiting, request
'Tests APIs for injection vulnerabilities including SQL injection, NoSQL injection, OS command injection, LDAP
'Performs API inventory and discovery to identify all API endpoints in an organization''s environment including