
Claude Skills by yanacuti1121
github.com/yanacuti1121Scenario-first whitebox security vulnerability research using the OpenHack methodology (Hadrian Security). 12 OWASP 2025-aligned expert families, recon → route → scenario → triage pipeline. Use for deep source-code audit on a target repo — not for quick YAMTAM rule checks (use strix-scan.sh for that).
OpenTelemetry JS SDK for distributed tracing across agent chains. Span creation, context propagation (W3C Trace Context), OTLP export, baggage passing, and auto-instrumentation for Node.js. Sources: open-telemetry/opentelemetry-js (Apache-2.0).
Instrument multi-agent swarms with OpenTelemetry spans, semantic drift monitoring, anomaly detection, distributed trace propagation across 87 agents, and SIEM bridge export for security events.
Desktop app local-first cho AI agent workflows, thay thế mã nguồn mở cho Claude Cowork/Codex desktop. Dùng khi cần chạy OpenCode với GUI, chia sẻ workflow với team, hoặc kết nối remote OpenCode server. Triggers: "openwork", "openwork agent", "opencode desktop", "ai agent desktop app", "local agent ui", "openwork orchestrator", "chia sẻ agent workflow", "opencode gui", "different-ai openwork"
Generate many candidate options across different styles (concise, simple, creative, professional), then run pairwise elimination rounds to select the top 3 with reasons. Use when asked for 'phương án', 'cho mấy phương án', 'generate options and pick best', 'so sánh phương án', 'naming candidates', 'top 3 approaches', 'loại dần phương án yếu', or 'which wording is best'. Do NOT use for: prioritizing a task list — see pairwise-prioritization. Do NOT use for: exploring solution trees in reasonin...
Outlines — structured generation with guaranteed JSON/regex output from local LLMs
Run a final quality gate on UI output before delivering it to the user. Checks code quality, visual correctness, accessibility baseline, and that no placeholder content remains. Use when about to deliver any frontend implementation — before saying "done", "here is the component", or marking a UI task complete. Do NOT use as a standalone task — this is a pre-delivery gate, not a redesign skill.
Isolate agent file-system writes using OverlayFS and bubblewrap (bwrap). Core directories mounted read-only; all agent writes go to RAM-backed tmpfs. Zero persistence on session end. Anti-graffiti immutable surface pattern.
OWASP Top 10 for LLM applications — full checklist for AI agent systems. Prompt injection, insecure output, training data poisoning, DoS, supply chain, sensitive info disclosure, insecure plugins, excessive agency, overreliance, and model theft. Sources: OWASP/www-project-top-10-for-large-language-model-applications, guardrails-ai/guardrails, MITRE ATLAS, NIST AI RMF, leondz/garak.
P2P append-only action log for distributed agent audit trails. Peer-to-peer replication, content-addressed entries, causal ordering, and tamper-evident chain without central coordinator. Sources: mafintosh/chronicle (MIT).
PaddleOCR — OCR toolkit 80+ ngôn ngữ: PP-OCR (general), PP-Structure (layout+table), PP-ChatOCR (LLM key extraction). PDF/image → text/structured data. Apache-2.0.
Prioritize a task list by direct pairwise comparison instead of isolated scoring — compare every pair on importance, urgency, and impact, then produce a ranked execution order. Use when asked 'so từng cặp', 'sắp xếp ưu tiên', 'prioritize these tasks', 'việc nào làm trước', 'rank this backlog', 'đặt độ ưu tiên', or 'compare tasks head to head'. Do NOT use for: choosing between solution options — see option-tournament. Do NOT use for: sprint ceremony planning — see /sprint-planning.
Use when the user wants a task done much faster through parallel work, concurrent agents, batched tool calls, isolated worktrees, or many independent verification lanes without losing correctness.
Profile and optimize Python/Node.js — cProfile, py-spy, clinic.js, memory profiling, async bottlenecks, DB query analysis
Configure and execute access recertification campaigns in Saviynt Enterprise
Conduct systematic access reviews and certifications to ensure users
Use BloodHound and SharpHound to enumerate Active Directory relationships
Investigate Active Directory compromise by analyzing authentication logs,
Enumerate and audit Active Directory forest trust relationships using
Conduct a focused Active Directory penetration test to enumerate domain
Assess Active Directory security posture using PingCastle, BloodHound,
Detect and respond to Adversary-in-the-Middle (AiTM) phishing attacks
Configure and execute agentless vulnerability scanning using network
Use AI and LLM-based reasoning to correlate findings across multiple
Perform systematic alert triage in Elastic Security SIEM to rapidly classify,
'Performs automated static analysis of Android applications using Mobile
'Uses Microsoft RESTler to perform stateful REST API fuzzing by automatically
'Performs API inventory and discovery to identify all API endpoints in
'Tests API rate limiting implementations for bypass vulnerabilities by
'Uses Postman to perform structured API security testing by building
'Simulates ARP spoofing attacks in authorized lab or pentest environments
Develop and apply a multi-factor asset criticality scoring model to weight
Configure and execute authenticated vulnerability scans using OpenVAS/Greenbone
Authenticated (credentialed) vulnerability scanning uses valid system
Deploy and operate CAPEv2 sandbox for automated malware analysis with
Perform comprehensive security posture assessment of AWS accounts using
'Performing authorized privilege escalation assessments in AWS environments
'Simulates bandwidth throttling and network degradation attacks using
'Analyze binary exploitation techniques including buffer overflows and
Detect and exploit blind Server-Side Request Forgery vulnerabilities
Assess Bluetooth Low Energy device security by scanning, enumerating
Monitor for brand impersonation attacks across domains, social media,
Testing web applications for clickjacking vulnerabilities by assessing
Perform comprehensive cloud asset inventory and relationship mapping
Conduct forensic investigations in cloud environments by collecting and
Perform forensic investigation of AWS environments using CloudTrail logs
Execute cloud-native incident containment across AWS, Azure, and GCP
'Uses AWS Athena to query CloudTrail, VPC Flow Logs, S3 access logs,
'Uses Falco YAML rules for runtime threat detection in containers and
Hunt for threats in AWS environments using Detective behavior graphs,