Soc2 compliance
Use when the user asks to prepare for SOC 2 audits, map Trust Service Criteria, build control matrices, collect audit evidence, perform gap analysis, or assess SOC 2 Type I vs Type II readiness.
Skills for your AI
Use when the user asks to prepare for SOC 2 audits, map Trust Service Criteria, build control matrices, collect audit evidence, perform gap analysis, or assess SOC 2 Type I vs Type II readiness.
Extracts backend API hosts, routes, and secrets from a SPA's JavaScript bundles and tests discovered endpoints for missing authentication and broken access control. Use when analyzing an authorized SPA target, mapping its API surface from JS bundles, or probin
Finds and validates Spring Boot vulnerabilities during authorized security testing by fingerprinting targets, enumerating actuator endpoints, and testing heap dump secrets, SpEL, H2, Spring4Shell, and Jolokia. Use when testing Spring Boot apps for authorized p
Hunts SQL injection vulnerabilities in web applications and APIs by enumerating input vectors, identifying the tech stack, running error-based, boolean, time-based and NoSQL probes, extracting proof data, and documenting findings. Use when testing an authorize
Defines SLIs/SLOs, manages error budgets, reduces toil, and designs fault-tolerant systems from provided reliability data. Use when assessing reliability posture, setting SLO targets and burn rate policies, automating incident response, planning chaos experime
Hunts and confirms SSRF vulnerabilities on authorized targets through URL-input surface mapping, out-of-band callback validation, and sink attribution. Use when the user asks to test for SSRF, map URL-accepting parameters, validate blind or full-read SSRF, pro
Sets up StackHawk API security testing for a repository by assessing its attack surface, generating stackhawk.yml and a GitHub Actions workflow, and opening a draft pull request. Use when a user asks to add StackHawk security testing, check if a repo is a good
Plans, optimizes, and secures data storage across backup and DR, archiving, deduplication, encryption, virtualization, performance, capacity, vendor selection, migration, and cloud adoption. Use when the user asks for storage plans, comparisons, policies, blue
Hunts and verifies subdomain takeover vulnerabilities on authorized domains using DNS and HTTP checks, provider fingerprints, and impact analysis. Use when the user asks to enumerate subdomains, detect takeover indicators, verify claimability, assess impact, o
Plans system integration projects end-to-end, covering data mapping, interface design, testing, error handling, security, performance, documentation, API strategy, migration, vendors, scalability, change management, data sync, training and continuous improveme
Runs security assessments for systems analysts — vulnerability scanning, penetration testing, policy review, risk, compliance, architecture, training, incident response, audits and tool evaluation. Use when planning, executing or documenting any of these asses
Evaluates and optimizes a company's tech stack across performance, cost, security, and future readiness, producing comparison reports, POC plans, vendor matrices, and optimization guides. Use when comparing stack options or vendors, assessing security, scalabi
Technology stack evaluation and comparison with TCO analysis, security assessment, and ecosystem health scoring. Use when comparing frameworks, evaluating technology stacks, calculating total cost of ownership, assessing migration paths, or analyzing ecosystem
Assesses technology risks across infrastructure, policy, threats, vendors, data, cloud, mobile, emerging tech, and digital transformation for insurance risk analysts. Use when an analyst needs a structured risk assessment, gap analysis, threat model, or mitiga
Generates compliant Terraform configurations, resolves provider and module versions from public or private registries, orchestrates HCP Terraform workspaces and runs, and runs security scans. Use when the user asks for Terraform code, registry version lookups,
Gathers, analyzes, and prioritizes cyber threat intelligence from open sources, dark web mentions, phishing samples, malware reports, and internal logs. Use when monitoring threats, analyzing phishing emails, tracking malware trends, prioritizing vulnerabiliti
Hunts and triages TLS/SSL and DNS misconfigurations for bug bounty reporting, covering TLS audits, HSTS, AXFR, email spoofing, dangling CNAME takeover, and mTLS bypass. Use when assessing a target domain's TLS or DNS security, checking subdomain takeover or em
Scans a website codebase to extract, categorize, and inventory all URLs and links, flagging suspicious patterns. Use when asked to find all links, audit URLs, list API endpoints or asset references, prepare for domain migration, SEO audit, or security review.
Assesses vendor security risks, compliance, and readiness by analyzing vendor documentation, generating questionnaires, and preparing reports and plans. Use when evaluating a vendor's security posture, reviewing policies or contracts, checking compliance again
Designs, configures, troubleshoots, and documents VLANs including tagging, trunking, inter-VLAN routing, ACLs, security, QoS, and migration. Use when the user asks about VLAN creation, port membership, 802.1Q or ISL, SVI or router subinterface routing, VLAN AC
Provides step-by-step guidance to configure, troubleshoot, secure, optimize, and manage VPN connections and infrastructure. Use when setting up VPN clients or tunnels, diagnosing connectivity issues, hardening VPN security, tuning performance, adding load bala
Guides VPN planning, configuration, access control, monitoring, security auditing, and disaster recovery for network administrators. Use when setting up VPN clients or tunnels, managing user access, troubleshooting connections, hardening security, enforcing po
Fingerprints enterprise SSL VPN appliances, detects versions, and checks them against a curated CVE matrix and configuration weaknesses. Use when recon surfaces a VPN login page or subdomain, or when scoping an authorized test of Cisco, Fortinet, Citrix, Palo
Turns raw vulnerability data into prioritized, actionable intelligence—scanning, assessment, patch planning, reporting, remediation tracking, and trend analysis. Use when analyzing scan results, building patch schedules, writing vulnerability reports, tracking