Runs 3 vulnerability hunters and 2 PoC engineers in parallel so only findings with a proven, reproducible attack path survive.
An AI/ML-specific security skill that scans for prompt injection and jailbreaks, scores model inversion and data poisoning risk, and maps findings to MITRE ATLAS.
A guided, safety-first workflow to scan for and purge secrets, private domains/IPs and PII from Git history, then force-push safely.
A Bugcrowd-specific reporting overlay: VRT selection, manual severity-override requests, and ready-made out-of-scope rebuttals.
An expert skill for DORA (Regulation (EU) 2022/2554): article-level gap analysis, ICT incident classification and reporting, third-party risk, and TLPT scoping.
Runs six Article-cited forcing questions to pressure-test an AI system's readiness for the EU market.
An end-to-end malware workflow for static/dynamic analysis, YARA rule authoring, and safe sandbox setup.
Mint tamper-evident, post-quantum-signed receipts for consequential agent actions and verify them offline from the certificate alone.
Read-only audit of the skills, MCP servers, hooks, plugins, and credentials already installed across Claude Code, Codex, OpenClaw, and Cursor, with a structured risk briefing.
Turns Claude into a CMMC 2.0 / NIST SP 800-171 consultant for gap assessments, SSP drafting, SPRS scoring and POA&M management in the US defense supply chain.
Guides Claude through expert-grade design, configuration, and troubleshooting of Cloudflare One Zero Trust / SASE deployments.
Pressure-tests an ISO/IEC 42001 AI Management System with six forcing questions before certification or internal audit.
Uses the WinDiff CLI to diff two Windows builds and interpret new syscalls, structs, mitigation flags, and ETW/callback surface into a security-research report.
Designs and verifies auditable human approval gates, escalation paths, and safe state transitions for risky AI agent actions.
Plans assessments, policy mappings, and staged rollouts when migrating from Zscaler ZIA/ZPA, Palo Alto, or legacy VPN/SWG stacks to Cloudflare One.
A hands-on guide for hardening ROS2 robots end to end: SROS2/DDS encryption, network segmentation, secrets, container security, and cyber-physical safety.
Takes a proven vulnerability through private vendor reporting, timeline coordination, CVE assignment, and public advisory publication.
A static-analysis skill that applies abstract interpretation to infer variable ranges and flag potential runtime errors — out-of-bounds, null dereference, divide-by-zero, integer overflow — without running the code.
Analyzes German cease-and-desist letters over unfair T&C clauses and drafts a narrowed cease-and-desist undertaking with cost and risk assessment.
Guides Claude in designing end-to-end security architectures using defense-in-depth, zero trust, STRIDE/PASTA threat modeling, and NIST CSF / CIS / ISO 27001 control mapping.