Skill catalog

83 canonical skills. Every one documented.

Each skill has a defined purpose, trigger phrases, dependencies, and category. Click any skill to see its full specification.

Security Audit

Audit

Scans for auth gaps, hardcoded secrets, missing RLS, XSS, CSRF, unprotected routes, exposed env vars.

View full spec →

Code Review

Audit

Enterprise code review on recent changes or GitHub PRs. Checks standards, anti-patterns, error handling, type safety.

beginner-starterengineer-acceleration

View full spec →

API Contract Check

Audit

Verifies API routes for auth, error handling, response shape, HTTP status codes, input validation.

engineer-acceleration

View full spec →

Dependency Audit

Audit

Audits dependencies for vulnerabilities, outdated packages, license issues, unused deps.

View full spec →

Pre-Deploy Check

Audit

Pre-deployment verification — types, lint, tests, env vars, migrations, build, git state.

engineer-acceleration

View full spec →

Full Stack Audit

Audit

Runs ALL enterprise audit skills in sequence — security, code review, API contracts, dependency audit, pre-deploy, testing verification.

View full spec →

Performance Audit

Audit

Scans for performance anti-patterns, slow queries, bundle size issues, memory leaks, unnecessary re-renders.

engineer-acceleration

View full spec →

Accessibility Audit

Audit

Scans for WCAG 2.1 AA compliance — alt text, ARIA roles, keyboard navigation, color contrast, focus management.

View full spec →

RAG Audit

Audit

Audits RAG systems for compliance with retrieval governance. Checks retrieval order, prompt hardening, injection defense, context firewall, metadata provenance, hybrid retrieval, and code generation grounding.

View full spec →

Agentic Audit

Audit

Audits agentic AI systems for compliance with agent governance. Checks capability declarations, scope boundaries, planning governance, delegation chains, stop conditions, and verification protocol.

View full spec →

Alignment Audit

Audit

Audits model fine-tuning and alignment pipelines. Checks dataset governance, sanitization, evaluation metrics, drift prevention, version control, and audit trail.

View full spec →

Compliance Mapper

Audit

Maps codebase against regulatory compliance frameworks (SOC 2, HIPAA, GDPR). Generates compliance matrices and gap reports.

enterprise-control-plane

View full spec →

Anti-Hallucination Agent

Audit

Deep anti-hallucination verification aligned with Anthropic and OpenAI best practices. Cross-reference validation, code grounding checks, capability claim verification, RAG grounding, and refactor integrity analysis. Three-layer enforcement: baseline governance, code generation guards, and on-demand deep audit.

engineer-acceleration

View full spec →

Blast Radius Predictor

Audit

Predicts the impact of a proposed code change using static dependency analysis, test coverage overlay, git history, and deployment topology.

engineer-acceleration

View full spec →

Test Gap Analyzer

Audit

Analyzes test quality beyond coverage numbers — assertion strength, mock depth, branch path coverage, edge case gaps, and business-critical code protection.

engineer-acceleration

View full spec →

Knowledge Decay Detector

Audit

Detects stale, wrong, or misleading documentation by cross-referencing docs against current code.

View full spec →

Codebase Archaeology

Audit

Reconstructs the history and rationale behind code decisions using git history, documentation cross-references, and staleness analysis.

View full spec →

Threat Modeling Agent

Audit

Enterprise threat modeling using STRIDE, DREAD, and attack trees. Identifies threats against architecture, data flows, trust boundaries, and entry points. Generates threat matrices and mitigation plans.

View full spec →

Security Hardening Agent

Audit

Audits and remediates infrastructure, application, and network security. Covers OWASP Top 10, CIS Benchmarks, HTTP headers, TLS, CORS, CSP, container security, IAM, supply chain, and zero-trust assessment.

enterprise-control-plane

View full spec →

SOX Compliance Agent

Audit

Sarbanes-Oxley compliance and financial security agent. Audits financial data handling, access controls, audit trails, change management, segregation of duties. Covers SOX Section 302/404, COSO framework, and ITGC.

enterprise-control-plane

View full spec →

UX Heuristic Evaluator

Audit

Expert UX evaluation using Nielsen's 10 Heuristics, cognitive walkthroughs, information architecture audits, and form UX analysis. Severity-rated findings with actionable recommendations.

View full spec →

Design System Auditor

Audit

Verifies codebase adherence to design system specifications. Audits design tokens, component patterns, typography, color palette, spacing, and responsive behavior.

View full spec →