Loading...
Loading...
Found 56 Skills
Guides product infrastructure security—securing the runtime, data plane, and control plane that ships with the product: multi-tenant isolation, service-to-service auth, customer data boundaries, secure defaults in APIs and workers, abuse-resistant rate limits, product-scoped secrets and encryption, and security design reviews for product infra changes. Use when threat-modeling product features, designing tenant isolation, hardening service mesh or internal APIs, reviewing product IaC/modules for data leaks, defining secure baselines for microservices the product team owns, or partnering on incidents affecting customer workloads—not for corporate IdP/SIEM (information-security-engineer), CI pipeline gates only (devsecops), SOC operations (defensive-security-analyst), authorized pentest execution (offensive-security-analyst), general IDP golden paths (platform-engineer), company-wide GRC (cybersecurity), or applied AI solution architecture for LLM features (applied-ai-architect-commercial-enterprise).
Complete Operation Guide for Zsxq CLI (zsxq-cli), covering all scenarios of Zsxq (Knowledge Planet) and content management. This Skill must be used when users mention Zsxq, zsxq, Xiaomiquan (former name of Zsxq), login/authentication, posting, commenting, answering, editing, deleting topics, notes, digest, tags/hashtag, members, footprints, question records, share links, NPS feedback, group_id, topic_id; need to login/check authentication status, view/search/publish/edit/manage Zsxq content; perform operation scenarios such as daily patrol, comment section operation, question management, digest and tag organization, operation daily/weekly report & review, generating Zsxq daily poster images, generating vertical animated videos, negative content monitoring, batch tagging, renewal care for expiring members, archiving topics to columns; splice share links, directly call underlying APIs (api call / api raw), check member lists/member expiration dates/column lists; or need to check/migrate/clean up legacy Zsxq Skills (such as upgrading zsxq-shared, zsxq-group to a single zsxq). It should be triggered even if only a single operation is involved (e.g., obtaining group_id, viewing post details, replying to comments).
Gerente do ciclo de vida de stories e orquestrador de handoffs no SynkOS. Use esta skill quando o usuário pedir para decompor um épico em stories, criar stories com critérios de aceite, fazer backlog grooming, planejar sprint, orquestrar handoffs entre roles (architect → dev → qa), ou fazer perguntas como "quebre esse épico em stories", "crie a story para X", "o backlog está priorizado?", "faça o checkpoint da story Y", "orquestre o handoff para QA". Ative também para resolver dependências entre stories, escalar stories bloqueadas, e garantir que cada story tem ownerRole e reviewRole definidos antes de entrar em implementação.
Generates woodworking cut lists from OpenSCAD furniture designs using the woodworkers-lib library. Automates panel dimension extraction from ECHO output for furniture, cabinets, wardrobes, and shelving units. Use when designing furniture with plywood/MDF panels, generating cut lists for CNC routing or manual cutting, or preparing data for sheet optimization tools. Triggers on "generate cut list", "extract panel dimensions", "furniture cut list", "woodworking ECHO output", or when working with planeLeft/planeRight/ planeTop/planeBottom/planeFront/planeBack modules. Works with .scad files using woodworkers-lib library.
Audits, configures, and hardens workload-level security controls for Google Kubernetes Engine (GKE) applications and namespaces. Covers running cluster security audits (`audit_cluster.sh`), configuring Workload Identity Federation (impersonation, KSA/GSA binding, and pod setup), enforcing Network Policies (default-deny and Dataplane V2 logging), isolating high-risk pods inside GKE Sandbox (`gVisor`), enforcing Pod Security Standards (`restricted` labeling), and mounting Secret Manager secrets via CSI (`SecretProviderClass`). Use when auditing cluster security posture, isolating namespaces, applying pod security standards, setting up Workload Identity, or configuring network policies and secret volume mounts. Don't use for cluster-wide control plane security, RBAC hardening, Binary Authorization, Shielded Nodes, or enabling platform-level GKE add-ons (use gke-platform-security instead).
Plans, configures, and hardens platform-level Google Kubernetes Engine (GKE) cluster security. Covers cluster add-ons (Secret Manager enablement), RBAC hardening (disabling insecure bindings, audit tools), Binary Authorization, enabling Shielded Nodes, GKE Sandbox cluster enablement, GKE IAM roles, and cross-service authentication IAM patterns. Use when securing cluster control planes, hardening GKE RBAC, enabling Shielded Nodes, enabling GKE Sandbox runtime, enabling cluster-wide security add-ons, or managing GKE IAM roles. Don't use for workload-level security (Workload Identity, SecretProviderClass, PSS, NetPol, gVisor pod runtimeClassName; use gke-workload-security instead).
Expert in Galaxy workflow development, testing, and IWC best practices. Create, validate, and optimize .ga workflows following Intergalactic Workflow Commission standards.
PostgreSQL best practices, query optimization, connection troubleshooting, and performance improvement. Load when working with Postgres databases.