- Home
- /
- Categories
- /
- Security
Security
Security scanning and vulnerability detection
c-framework
by founderjourney
Universal contractual development mode enforcer. Reads project-specific rules from CLAUDE.md dynamically. Activate for any project requiring verified claims, security checks, evidence-based recommendations, or strict development standards. Triggers: /c-framework, /cf, "modo contractual", "verify code", "enforce rules", "contract mode". Works with any stack (Node, Python, Go, etc.) and any project type (API, SaaS, CLI, web-app).
postgresql-performance-expert
by founderjourney
Optimizacion de PostgreSQL para Senior Full-Stack Developer. Usar cuando el usuario necesite diagnosticar queries lentos, optimizar performance de base de datos, disenar indices, resolver N+1 queries, o defender experiencia en optimizacion. Activa con palabras como PostgreSQL, query lento, performance, EXPLAIN, indice, N+1, optimizar base de datos, latencia. Especializado en aplicaciones SaaS con Node.js.
saas-business-logic-analyst
by founderjourney
Senior Business Logic Analyst (15+ years) specialized in SaaS systems (YC/SV standard). Activate when user needs: (1) Audit business logic in code, (2) Detect revenue leakage or billing bugs, (3) Review subscription/billing/multi-tenant logic, (4) Analyze edge cases with business impact, (5) Evaluate code for scaling/pivot readiness, (6) Due diligence on SaaS codebase, (7) Identify invariant violations, (8) Assess organizational/knowledge risks in code. Triggers: "audit business logic", "review billing code", "check subscription logic", "find revenue leakage", "SaaS code review", "multi-tenant security", "pricing logic", "analyze edge cases", "due diligence", "business logic analyst".
digitaliza-data-extractor
by founderjourney
Extract and prepare client data for digitalizaweb.vercel.app LinkTree-style digital cards. Use when: (1) Processing restaurant/business client folders containing screenshots, scraped HTML, or LinkTree data, (2) Extracting brand colors from logos/images, (3) Generating Digitaliza-ready JSON with slug, name, links, colors, and theme configuration, (4) Batch processing multiple client folders for 100+ restaurants project, (5) User mentions "digitaliza", "tarjeta digital", "linktree", "extraer datos de cliente", or "procesar carpeta de restaurante".
technical-storytelling
by founderjourney
Sistema para convertir logros tecnicos en narrativas que comunican senioridad e impacto. Usar cuando el usuario necesite escribir sobre sus proyectos, preparar presentaciones tecnicas, documentar decisiones de arquitectura, o comunicar complejidad a audiencias no-tecnicas. Activa con palabras como explicar proyecto, presentacion, documentar, caso de estudio, blog tecnico, conferencia. Especializado en developers senior que necesitan comunicar impacto business.
integration-patterns-mastery
by founderjourney
Patrones de integracion robustas para Senior Full-Stack Developer. Usar cuando el usuario necesite disenar o explicar integraciones con APIs externas, webhooks, sincronizacion de datos, retry patterns, manejo de errores en integraciones, o defender experiencia con Stripe, OTAs, WhatsApp API. Activa con palabras como webhook, integracion, API externa, sync, retry, idempotencia, Stripe, iCal, OTA, dead letter queue, reconciliacion. Especializado en sistemas de produccion robustos.
nightshift
by adriannutiu
Scriptless overnight repository and code-quality audit for Codex that runs deterministic checks first (code correctness gates, dead code or orphan hints, test gaps, refactor and DRY opportunities, doc drift, dependency or security posture, tech debt, optional infra drift) and then synthesizes prioritized actions with structured artifacts in .nightshift/runs/timestamp. Use after large implementation sessions, before releases, before handoff, or when asking "what did we miss?"
ui-ux-audit
by WomenDefiningAI
Mandatory audit workflow for UI/UX changes that reads current state FIRST, checks for redundancy, respects clean design philosophy, and identifies genuine gaps before implementation. Auto-invoked when user mentions UI, UX, design, layout, homepage, page improvements, visual changes, or interface modifications.
oceanbase-sql-optimization
by amber-moe
SQL optimization best practices for OceanBase database (MySQL & Oracle modes). Covers query optimization, index usage, execution plan analysis, slow query tuning, and performance optimization techniques. Activates for SQL optimization, query performance, index design, execution plan, slow query, database performance.
code-reviewer
by WomenDefiningAI
Research-backed code review skill with OWASP Top 10 security checks, SAST tool integration (SonarQube, CodeQL, Snyk), performance pattern detection, and automated quality standards enforcement. Auto-invoked for code review, security audit, PR analysis, and bug checking. Implements 2025 best practices with 92% faster vulnerability remediation.
web-security
by academind
Enforce web security and avoid security vulnerabilities
action-item-organizer
by 89jobrien
Systematic framework for extracting actionable items from documents and
ms365-tenant-manager
by QuestNova502
Comprehensive Microsoft 365 tenant administration skill for setup, configuration, user management, security policies, and organizational structure optimization for Global Administrators
isms-audit-expert
by QuestNova502
Senior ISMS Audit Expert for internal and external information security management system auditing. Provides ISO 27001 audit expertise, security audit program management, security control assessment, and compliance verification. Use for ISMS internal auditing, external audit preparation, security control testing, and ISO 27001 certification support.
tax-loss-harvesting-tracker
by zen-tradings
Identifies and plans tax loss harvesting opportunities across a portfolio. Use when the user asks about tax loss harvesting, wants to find losses to offset gains, asks "how can I reduce my capital gains tax", "which positions should I sell for losses", "wash sale rules", "tax-efficient selling", or mentions offsetting gains with losses. Also triggers when users share portfolio positions with unrealized losses, ask about year-end tax planning for investments, or want to understand how harvesting losses works. Handles wash-sale compliance, replacement security suggestions, and cross-account tracking.
kql-mde-xdr
by audibleblink
Write and optimize KQL queries for Microsoft Defender (MDE), Sentinel, and Microsoft 365 Defender XDR. Use when threat hunting, writing detection rules, investigating incidents, or analyzing security data with KQL.
information-security-manager-iso27001
by QuestNova502
Senior Information Security Manager specializing in ISO 27001 and ISO 27002 implementation for HealthTech and MedTech companies. Provides ISMS implementation, cybersecurity risk assessment, security controls management, and compliance oversight. Use for ISMS design, security risk assessments, control implementation, and ISO 27001 certification activities.
vendor-rip
by vendor-rip
"Scan, assess, plan, and replace SaaS tools with AI-built code. Analyzes your codebase for SaaS integrations, generates migration plans, executes replacements, and validates results."
security-audit
by 89jobrien
Security auditing and vulnerability assessment specialist. Use when conducting
dependency-management
by 89jobrien
Dependency management specialist. Use when updating dependencies, scanning
code-review
by 89jobrien
Expert code review specialist for quality, security, and maintainability.
security-analysis-skills
by kimasplund
Comprehensive security analysis framework teaching STRIDE threat modeling, OWASP Top 10 vulnerabilities, CVSS risk scoring, and secure coding patterns. Use when conducting security assessments, code reviews, threat modeling, or implementing security controls. Applicable to all development work requiring security consideration.
claude-hooks
by 89jobrien
Claude Code hooks configuration specialist. Use when creating hooks for
cloud-infrastructure
by 89jobrien
Cloud infrastructure design and deployment patterns for AWS, Azure, and