Ralph loop yylo
Execute exactly one explicitly assigned YYLO Ledger task through the Ralph loop to a validated queued commit. Use only when the user explicitly requests ralph-loop-yylo.
Skills for your AI
Execute exactly one explicitly assigned YYLO Ledger task through the Ralph loop to a validated queued commit. Use only when the user explicitly requests ralph-loop-yylo.
Triage ASM/recon output for ownership before testing
Configure Redis for caching and data storage. Set up clustering, persistence, and Sentinel. Use when implementing Redis caching or queues.
Red-team operator discipline
Client-facing red-team deliverable format
Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi
Configure nginx and Traefik as reverse proxies. Implement SSL termination and routing. Use when setting up application gateways.
Create operational runbooks and standard operating procedures. Document troubleshooting guides and recovery procedures. Use when documenting operational knowledge.
Audit and harden your SaaS tool stack
Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube.
Generate, sign, and verify SBOMs and provenance attestations to secure the software supply chain. Use when implementing SLSA controls, artifact trust policies, or compliance evidence for releases.
Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table.
Automate security workflows and remediation. Build security pipelines, automate compliance checks, and implement SOAR capabilities. Use when scaling security operations or implementing DevSecOps.
Automate versioning and changelog generation using semantic versioning principles.
Implement Istio and Linkerd service meshes. Configure mTLS, traffic management, and observability. Use when managing microservices communication.
Implement SOC 2 Trust Services Criteria. Configure security, availability, and processing integrity controls. Use when achieving SOC 2 certification.
Encrypt files and configs with Mozilla SOPS.
Design and operationalize SRE dashboards that surface reliability, latency, error, saturation, and capacity signals across services.
Configure SSH servers and clients securely. Manage keys, tunnels, and config files. Use when setting up secure remote access.
Manage SSL/TLS certificates with Let's Encrypt and internal PKI. Configure secure HTTPS, certificate renewal, and cipher suites. Use when implementing secure communications.
Practical IT troubleshooting playbooks for small teams without dedicated IT staff.
External recon for software supply-chain attack surface
Detect, respond to, and prevent software supply chain attacks on package registries, container images, and CI/CD pipelines with lockfile auditing, provenance verification
Create and manage systemd services and timers. Configure service dependencies and resource limits. Use when managing system services.