Ciso review
/cs:ciso-review <plan> — Risk-paranoid interrogation of any plan that touches data, compliance, or production access. Use when launching features that handle customer data, before a SOC 2 / ISO audit, or after any incident or near-miss.
Skills for your AI
/cs:ciso-review <plan> — Risk-paranoid interrogation of any plan that touches data, compliance, or production access. Use when launching features that handle customer data, before a SOC 2 / ISO audit, or after any incident or near-miss.
Analyzes insurance claims feedback, complaints, and process data to produce reports, drafts, and improvement recommendations. Use when a claims manager needs feedback analysis, chatbot or virtual assistant optimization, personalized claimant communication, com
Verifies clickjacking vulnerabilities by screening frame-protection headers, proving iframe rendering, and confirming cross-site sensitive actions. Use when testing authorized web targets for clickjacking, checking X-Frame-Options or CSP frame-ancestors, or bu
Gathers client data, analyzes risk, recommends mitigation and coverage, produces reports, questionnaires, benchmarking, and monitoring updates for insurance agency client risk work. Use when assessing a client's risks, preparing coverage or mitigation plans, d
Produces climate impact studies, risk and vulnerability assessments, mitigation and adaptation plans, policy comparisons, and GHG inventories from user-supplied climate data. Use when asked to analyze climate trends, model emission scenarios, assess climate ri
Guides clinical data managers in planning and drafting safeguards for sensitive clinical data, including encryption, access control, masking, audit trails, secure storage and transfer, breach response, audits, training, compliance, backup, vendor assessment, a
Develops and verifies Clojure solutions in the REPL before touching any files, covering root cause fixes, refactoring, architecture review, and failing-test debugging. Use when fixing Clojure bugs, refactoring functions, reviewing code for best practices, or d
Manages cloud databases end-to-end across AWS, Azure, and GCP — provisioning, migration, performance tuning, backup and recovery, security hardening, scalability, cost optimization, and schema design. Use when planning, configuring, reviewing, or troubleshooti
Classifies leaked cloud credentials and maps privilege escalation paths across AWS, Azure, GCP, and Kubernetes. Use when analyzing a leaked AWS key, Azure secret, GCP service account JSON, or K8s token, validating it, enumerating access, or documenting escalat
Guides cloud integration planning from infrastructure assessment through migration, security, backup, testing, training, cost management, documentation, data integration, and cloud-native development. Use when planning a cloud migration, comparing providers, d
Hunts cloud and infrastructure misconfigurations across AWS, GCP, and Azure by enumerating exposed storage, admin panels, credentials, and services, and validating exploitability with exact evidence. Use when auditing authorized cloud targets, checking buckets
Deploys and manages Google Cloud Run services, jobs, worker pools, revisions and traffic splits with the gcloud CLI. Use when deploying a service from an image or source, creating or executing jobs, listing or describing Cloud Run resources, or shifting traffi
Use when assessing cloud infrastructure for security misconfigurations, IAM privilege escalation paths, S3 public exposure, open security group rules, or IaC security gaps. Covers AWS, Azure, and GCP posture assessment with MITRE ATT&CK mapping.
Advises cybersecurity analysts on cloud security audits, configurations, compliance, and incident readiness across AWS, Azure, and GCP. Use when the analyst asks about cloud encryption, access control, monitoring, incident response, compliance, secure configur
Helps systems administrators plan cloud security across risk assessment, authentication, encryption, monitoring, vulnerability management, backup and recovery, patching, user education, network segmentation, and incident response. Use when an administrator ask
Guides developers through integrating cloud platforms, storage, databases, AI services, analytics, CDNs, IAM, monitoring, and deployment automation. Use when choosing a cloud provider or planning, configuring, or troubleshooting a cloud service integration.
Guides cloud service selection, configuration, monitoring, cost optimization, security, compliance, integration, scaling, storage, deployment, ML pipelines, serverless, databases, CDN, IoT, DevOps, VDI, and media/NLP integration across AWS, Azure, and Google C
Creates and manages Cloud SQL instances, databases, and users for MySQL, PostgreSQL, and SQL Server on Google Cloud, including backups, high availability, and secure connectivity. Use when the user asks to create a Cloud SQL instance, set a database user passw
Deploys apps and infrastructure to Cloudflare Workers, Pages, D1, R2, KV, Durable Objects, and Workflows using Wrangler, Pulumi, Terraform, or the Cloudflare API. Use when the user asks to deploy, host, publish, or troubleshoot a Cloudflare project.
Builds and operates CocoIndex Python flows for AI data pipelines, covering requirements gathering, dependency and environment setup, flow code generation, custom functions, running flows, and debugging. Use when a developer wants to index files or data into a
Analyzes an existing codebase's patterns and conventions and produces a complete implementation blueprint for a requested feature. Use when the user asks to design a new feature, plan an implementation, map data flow, or produce an architecture blueprint for a
Reviews code, troubleshoots errors, inspects stack traces, writes test cases, guides environment setup, version control, tooling, performance profiling, and error handling for developers. Use when a developer shares code, an error message, a stack trace, a fai
Traces a codebase feature from entry points through all layers to data storage and produces a structured analysis report. Use when asked to analyze a feature, find entry points, trace a call chain, map architecture, or document implementation details.
Analyzes provided code to propose refactorings for clarity, performance, and maintainability, covering method extraction, duplication, conditionals, error handling, data structures, dead code, design patterns, and parameter objects. Use when a developer shares