Engineering
blast-radius
Analyzes code change impact with risk scoring and affected-node mapping. Use before merging to understand what a change touches and what lacks test coverage
Security
risk-classification
Classifies agent tasks into 4 risk tiers (GREEN/YELLOW/RED/CRITICAL)
Security
misteye-security-check
This is the MistEye security gate skill. It is triggered by pre-installation risk checks (including Skill/MCP dependency manifests), pre-access security checks for domains or URLs,…
Security
cyber-risk-modeling
Quantify cyber risk using FAIR methodology with Monte Carlo simulation, assess control effectiveness against NIST CSF/CIS/ISO 27001 frameworks, evaluate risk appetite alignment, an…
Security
auditclaw-grc
GRC automation suite covering 13 frameworks (SOC 2, ISO 27001, HIPAA, GDPR, NIST CSF, PCI DSS, CMMC, FedRAMP, others). Manages controls, evidence, risks, policies, vendors, inciden…
Security
risk-control
Manages hazard and risk records for regulated projects via a single normalized YAML file (docs/.index/risk-file.yaml) with hazard IDs, risk estimates, controls, verification links,…
Business
sap-treasury-cash-risk-review
Reviews SAP Treasury and Risk Management (TRM) and Cash Management setups, covering cash positioning, liquidity forecasting, bank account governance, in-house cash design, hedge co…
Documentation
sd-22-dmsms
Knowledge base from the SD-22 DMSMS Guidebook covering the full five-step obsolescence process—Prepare, Identify, Assess, Analyze, Implement—plus the Strategize overlay, DMT/DMP se…
Security
exceptions-register
Maintains a defensible register of accepted residual risks and control exceptions in a local file, capturing approver, justification, compensating controls, and re-validation dates…
Engineering
tooling-risk-assessment
Evaluates injection-mold and production tooling decisions before steel is cut—soft versus hard tooling tradeoffs, tool life versus forecast, cavitation calculations, T1 sample time…
Security
soup-inventory
Maintains a SOUP register for third-party software dependencies. Scans lockfiles to identify candidates, enriches with risk classification and verification references, validates ag…
Business
think-scenario-planning
Creates 2–4 contrasting, internally consistent future narratives along two critical uncertainty axes, then assesses strategy robustness across those worlds—identifying resilient mo…
Business
risikoampel-aggregation
Consolidates traffic-light ratings across all three cube axes — per cell (atomic), per row (document total), per column (data-point hotspots), per worksheet (perspective total), an…
Business
anschluss
Entry point for corporate law workflows: gathers role, goals, deadlines, documents and risks, then routes to the right module or proposes a clear plan. Handles uploads autonomously…
Business
juriscan
Análise forense de processos judiciais brasileiros. Extrai, classifica e cruza peças processuais, detecta contradições, calcula prazos CPC e gera relatórios de risco com exportação…
Business
insurance-underwriter
Determines insurance underwriting decisions for commercial property & casualty risks—pricing renewals via exposure-based rating, selecting deductible or SIR structures, evaluating …
Security
risk-management
Handles project risk identification, analysis, and response planning for software and systems projects. Covers probability-impact matrices, qualitative/quantitative analysis, Monte…
Business
legal-review-contract
Review contracts against an organization's negotiation playbook — flag deviations, generate redlines, and provide business impact analysis. Use for supplier or customer agreements,…
Engineering
derisk-sequencer
Sequences a validated idea into risk-ordered experiments and build steps, enforcing that no product code is scheduled before its de-risking test; surfaces load-bearing assumptions,…
Business
legal-notque
Supports legal workflows including contract review, compliance checks, NDA triage, risk assessment, and legal briefs. Use for reviewing contracts, checking compliance, triaging NDA…
Security
aws-remediation-leverage
Ranks AWS remediation options by attack-chain impact, surfacing the highest-leverage fixes that sever the most kill chains, techniques, and crown-jewel paths. Produces a marginal-g…
Security
steel-quench
Hardens near-complete artifacts through iterative attack-defense cycles that surface root weaknesses, residual risks, and hidden complexity. Supports standard threat modeling plus …
Business
kontrola-souladu
Assess regulatory compliance for proposed actions, product features, or initiatives by identifying applicable rules, required approvals, and risk areas. Use when handling personal …
Business
strategic-planning-master
Orchestrates complete strategic planning: scans environment, defines assumptions, sets objectives, tracks execution, and adjusts dynamically. Integrates assumption management, obje…
Productivity
abandon-criteria
At each phase start, explicitly declare at least three kill criteria alongside success metrics to prevent sunk-cost extensions; continuously monitor triggers and halt immediately u…
Security
loeschkonzept-und-aufbewahrungsfehler
Structure data deletion concepts and retention violations as fine-risk topics: missing erasure, excessive storage, backups, and statutory duties. Map GDPR Art. 58/77-84, BDSG § 41,…
Research
hormuz-strait
Check current status of the Strait of Hormuz — shipping transit data, oil price impact, stranded vessels, insurance risk levels, diplomatic developments, and global trade impact. U…
AI / ML
voorspellen-classificatie
Build predictive models for categorical outcomes where each individual prediction matters—such as student dropout risk, application approval, or churn detection. Use this skill for…
Security
nist-800-37
NIST SP 800-37 RMF knowledge base covering the seven-step risk management lifecycle, three-tier risk model, authorization boundaries, FIPS 199/200 categorization, SP 800-53 control…
Security
event-safety-plan
Creates complete event safety documentation for venues or licensing: risk assessment, crowd-capacity planning, emergency procedures, medical/welfare arrangements, and defined roles…
Engineering
tk-grill
Grills any plan, design, or architectural decision through relentless, one-branch-at-a-time questioning until shared understanding is reached, then emits a logged DEC-NNN entry. Us…
Business
insolvenzrisiko-im-dreipersonenverhaeltnis
Assesses insolvency risk transfer when choosing direct claims in three-party setups. References §§ 812, 818 BGB and §§ 129 ff. InsO. Maps coverage, consideration, payment flow, rec…
Business
fixed-income-credit-analysis
Analyzes credit quality for fixed-income decisions, building industry frameworks, evaluating issuers with dual-track methods, and constructing dashboards from public data. Validate…
Business
gwg-risikoanalyse
Builds and maintains institution-specific risk analyses under § 5 GwG, covering customer, product, distribution, and geographic risk categories. Incorporates supranational and nati…
Business
brand-safety-compliance
Reviews marketing copy for six compliance risks—medical claims, exaggeration, permanence promises, income guarantees, fake scarcity, and fabricated rapport—then flags issues and su…
Engineering
deadly-loop
Iterative multi-agent debate protocol that spawns Reviewer, Auditor, and Critic roles to surface and resolve P0 blockers in high-risk changes before merge. Loops fix waves until co…
Research
acting-on-hypotheses
Discipline for uncertain work: explicitly map hypotheses, run the cheapest test that could disprove them, then leap only on asymmetric upside. Use for de-risking bets, prototyping …
Automation
power-automate-automation-risk-review
Audit Power Automate cloud flows for governance gaps: ownership and sharing models, connector and DLP exposure, error handling patterns, monitoring coverage, and credential lifecyc…
Productivity
stakes-assessor
Evaluates problem-statement stakes as low/medium/high, returning a tag, rationale, and irreversibility flags. Guides binding-vow to select quick/standard/deep modes so low-stakes t…
Business
climate-risk-assessment
Evaluates physical and transition climate risks for sites, products, or portfolios using scenario-based analysis. Generates hazard-exposure-vulnerability matrices across 2030–2050 …
Security
cloud-audit-component
Cloud audit component for Wirtschaftsprüfer: initializes with facts matrix, risk indicators, and documentation gaps; performs live standards checks, chamber logic, proportionality …
Security
triage-nda-nmoralescyber
Rapidly screens standalone NDAs (mutual or unilateral) and classifies them GREEN (standard delegation), YELLOW (counsel review), or RED (full legal review). Detects non-solicits, n…
Business
pre-mortem-panel
Pre-mortem analysis that generates five distinct failure narratives across execution, timing, people, external factors, and flawed assumptions, then identifies the most probable an…
Business
udaap-risk-review
Generates a UDAAP risk memo analyzing products, fees, disclosures, or flows under Dodd-Frank §§1031 and 1036 for unfair, deceptive, or abusive acts. Includes consumer-harm assessme…
Security
product-abuse-risk-review
Design and audit product-wide abuse and fraud controls across identities, automation, promotions, referrals, trials, refunds, content, inventory, scraping, collusion, and evasion—p…
Business
pmo-program-manager
Coordinates multiple workstreams into program outcomes by synthesizing cross-project signals, managing risk posture, and guiding release readiness across agile or waterfall governa…
Security
risk-engine
Quantifies total portfolio risk using parametric, historical, and Monte Carlo VaR. Analyzes asset correlations, calculates expected max drawdown, verifies position limits, detects …
Security
source-protection-plan
Assess and reduce the risk of exposing a confidential journalistic source. Delivers a risk assessment covering metadata, communications, patterns, and documents, plus secure handli…
Business
crash-protocol
Activates a structured response for sharp market declines. Triggers on explicit commands like "crash mode" or when Nifty drops exceed 5% intraday or 10% from peak, then triages pos…
Engineering
fare-impact-analysis
Before modifying any symbol, scan blast radius via FARE code intelligence using code_query, code_context, code_impact, and code_route_map. Classify risk levels; HIGH/CRITICAL findi…
Business
defensive-drafting-fallen-erkennen
Review contract drafts to detect twelve common pitfalls including hidden liability waivers, shifted burden of proof, unfair venue clauses, auto-renewal traps, and non-reciprocal au…
Security
id-impact
Provides two pre-merge advisory reads for infra changes: one surfaces policy-risk findings with rule, resource, severity, and gating type (deny vs warn); the other delivers a Karpe…
Data
pos-calculator
Calculates risk-adjusted probability of success for therapeutic programs by applying historical base rates, mechanism adjustments, and program-specific modifiers to generate phase-…
Business
risk-clause-database
Identifies high/medium/low-risk clauses in contracts, maps each to its statutory basis under the Civil Code and Civil Procedure Law, and recommends revisions. Handles queries on br…
Security
ai-product-risk-review
Designs and audits AI product behavior and launch contracts covering user jobs, model roles, autonomy limits, data use, failure modes, UX disclosure, and release boundaries for ass…
Business
hr-risk-triage-review
Reviews enterprise HR actions and complaints for employment-relations risks—terminations, discipline, accommodations, wage issues, discrimination, harassment, and policy exceptions…
Business
lph-05-haftungsfalle
Identifies typical liability risks in HOAI LPH 5 execution planning and outlines evidence safeguards, covering detailed execution-ready plans, coordination of specialist planners, …
Business
renewal-prep
Gathers renewal context—value delivered, risk signals, and stakeholder status—from recent activity and account data. Accepts ZoomInfo ID or company name/domain; surfaces only evide…
Business
labor-contract-audit
Reviews employment or service contracts for compliance and risk. Covers contract type, probation terms, compensation, benefits, location, confidentiality, non-compete, and service …
AI / ML
frontier-conviction-scorer
Scores early discovery targets and modalities by multiplying empirical base rates for biology validity, modality feasibility, arc position, and competitive timing, enabling objecti…
Showing the top 60 of 1,246. See the full list →