React Nextjs Frontend
Apply frontend guidance for React and Next.js stacks, including routing, rendering strategy, state boundaries, and performance defaults. Use when a project uses React, Next.js, TypeScript, and component-driven UI delivery.
Mcp Compliance Integration
Hardens Model Context Protocol (MCP) server integrations for compliance—OAuth 2.1, PKCE, scoped tool sets, transport security, and patterns for Playwright, Postgres, Slack, and Presidio MCP servers in audit workflows. Trigger when deploying, configuring, or auditing MCP servers for HIPAA, PCI, or SOC 2 agent architectures. Do not use for general IAM reviews without MCP focus (use access-control-i…
Glue Data Catalog And Lake Formation Governance
Guides agents through AWS-native data catalog and lake governance workflows. Use when designing or reviewing Glue Data Catalog, Lake Formation permissions, governed sharing, metadata quality, and access boundaries for S3, Athena, Redshift, EMR, or Glue pipelines.
Skill 09 Compliance Aml
Handles crypto compliance including sanctions screening, Travel Rule, MiCA requirements, tax reporting, and SEC Howey test analysis. Use for regulated workflows, KYC/AML checks, or jurisdictional compliance questions.
Skill 07 Token Analytics
Analyzes on-chain token data including whale tracking, DEX volume, wallet PnL, and token unlock schedules. Use when researching token metrics, portfolio performance, or market activity.
Skill 13 Rwa Tokenization
Handles real-world asset tokenization including treasuries, real estate, bonds on-chain, ERC-3643 compliance tokens, and yield distribution. Use for institutional RWA workflows.
Skill 14 Social Reputation
Integrates Web3 social protocols including Lens, Farcaster, Frames, reputation scores, and prediction markets. Use for social graph queries, on-chain reputation, or social trading features.
Skill 10 Identity Did
Manages decentralized identity including DIDs, verifiable credentials, ENS names, ZK-KYC, and on-chain attestations. Use for identity verification, name resolution, or credential workflows.
Skill 15 Mev Protection
Protects transactions from MEV via Flashbots, intent-based trading, sandwich attack mitigation, and TWAP orders. Use for high-value swaps, liquidations, or any MEV-exposed on-chain activity.
Skill 05 Dao Governance
Manages DAO governance including proposals, voting, delegation, treasury management, and timelocks. Use when interacting with Governor contracts, Snapshot, or DAO treasuries.
Skill 03 Defi Operations
Executes DeFi operations including token swaps, lending/borrowing, staking, liquidity provision, flash loans, perpetuals, and vault strategies. Use when interacting with Uniswap, Aave, Compound, Lido, or other DeFi protocols.
Dbt And Analytics Engineering
Guides agents through analytics engineering workflows with dbt. Use when building or modifying staging models, marts, tests, snapshots, documentation, exposures, or semantic-layer-facing models.
Skill 04 Nft Management
Manages NFTs including minting, trading, ERC-721/1155 operations, marketplace integration, and token-bound accounts (ERC-6551). Use when working with NFT collections, metadata, or TBA wallets.
Skill 01 Wallet Management
Manages Web3 wallets including HD derivation, ERC-4337 account abstraction, multi-sig (Safe), and social recovery. Use when creating wallets, signing transactions, managing keys, or configuring smart accounts.
Duckdb Local Analytics And Dev
Guides agents through DuckDB-based local analytics and development workflows. Use when prototyping models locally, validating transformations, reproducing data issues quickly, or building lightweight analytical tooling without a full warehouse.
Data Contract Testing With Schema Registry
Guides agents through data-contract testing using schema registries and compatibility checks. Use when validating event contracts, stream schema evolution, consumer compatibility, or release gates for schema-managed systems.
Coppa Children Privacy
Implements FTC COPPA (15 U.S.C. §6501–6506; 16 CFR Part 312) for operators of websites, apps, and AI agents directed to children under 13 or with actual knowledge of child users—verifiable parental consent, data minimization, retention, security, and third-party LLM/MCP subprocessors. Trigger when building consumer apps, chatbots, or agents used by children, auditing EdTech with under-13 users ou…
Microsoft Purview And Azure Data Governance
Guides agents through Microsoft Purview and Azure-native data governance workflows. Use when designing collections, scans, classifications, lineage, policy boundaries, and governed publishing across ADLS, Synapse, Data Factory, Azure Databricks, Fabric, and Azure analytics estates.
Notebook To Production Hardening
Guides agents through converting exploratory notebooks into production-ready data jobs. Use when operationalizing notebooks from Databricks, Jupyter, or similar environments into tested, packaged, repeatable workflows.
Feature Store And Ml Data Pipelines
Guides agents through machine-learning data pipelines and feature serving workflows. Use when designing feature generation, offline and online consistency, training-serving parity, point-in-time correctness, or ML-oriented data product contracts.
Lineage Pii And Governance
Applies governance, lineage, ownership, and sensitive-data controls to data changes. Use when a pipeline touches published datasets, regulated information, or shared business metrics.
Dataplex And Bigquery Governance
Guides agents through GCP-native data governance workflows with Dataplex and BigQuery. Use when designing lakes, zones, policy tags, metadata quality, lineage, discovery, and governed publishing across Cloud Storage, BigQuery, Dataflow, Dataproc, and Google Cloud analytics platforms.
Dotnet Aspnet Core Microservices
Apply backend defaults for .NET ASP.NET Core microservices with strong contracts, health checks, and production-safe operations. Use when backend services are built with .NET and C#.
Testing Pyramid
Use when writing tests of any kind — unit, slice, or integration. Covers test structure, naming conventions, Mockito patterns, @WebMvcTest, @DataJpaTest, and Testcontainers setup.
Compliance Agent Skills
30 Agent Skills for deterministic USA compliance auditing of AI agents — HIPAA, NIST AI RMF, FERPA, COPPA, PCI-DSS, SOC 2, FedRAMP, CMMC, GLBA, privacy & GDPR. Presidio PHI redaction, MCP templates, Pydantic AI, VS Code & JetBrains plugins.
Micronaut Reactive Microservices
Build reactive Micronaut microservices with compile-time DI, non-blocking I/O, and GraalVM-ready APIs. Use for low-latency Java services with Netty and Project Reactor.
Mcp Data Observability Integration
Guides agents to wire Model Context Protocol servers for live data platform observability including Spark execution plans, OOM diagnosis, Kafka consumer lag, and orchestration run state. Use when agents need cluster metrics, streaming lag, or job diagnostics instead of blind code changes.
Compliance As Code Governance
Implements policy-as-code and infrastructure compliance scanning—OPA/Rego policies, Terraform static analysis, CI gates, and drift remediation—for SOC 2, HIPAA, and PCI control enforcement. Trigger when codifying security policies, integrating Checkov/tfsec/Sentinel, or automating guardrails for agent/MCP deployments. Do not use for one-time manual audits (use framework-specific skills) or vendor…
Vendor Third Party Risk
Performs third-party and vendor risk assessments for compliance programs—security questionnaires, SOC 2 report review, control inheritance, and ongoing monitoring—for LLM, cloud, MCP, and GRC tool vendors (Vanta/Drata alternative operational mindset). Trigger when onboarding vendors, annual vendor reviews, or assessing subprocessor risk for HIPAA, PCI, and SOC 2. Do not use for BAA clause legal a…
Data Reconciliation And Financial Controls
Guides agents through reconciliation and control design for business-critical data. Use when validating financial, operational, or audit-sensitive metrics with source-to-target totals, control balances, exception tracking, or close-process dependencies.
Langchain Agent Orchestration
Build LangChain/LangGraph agents with tool registries, memory checkpointers, structured outputs, and production guardrails. Use for Python backend AI orchestration beyond generic LLM integration skills.
Ai Safety Red Teaming And Compliance
Implements OWASP Top 10 for Agentic Applications 2026 defenses, NIST AI RMF alignment, EU AI Act high-risk compliance, and CI red-teaming with Confident AI or DeepTeam. Use when deploying AI agents, tool-calling systems, or high-risk automated workflows.
Data Sharing And Publishing Contracts
Guides agents through publishing data products for internal or external consumers. Use when sharing tables, files, extracts, APIs, or reverse-ETL-ready outputs that require stable contracts, ownership, and communication.
Delta Lake And Medallion Architecture
Guides agents through Delta Lake and medallion-style lakehouse design. Use when building or modifying bronze, silver, and gold layers, Delta Lake mutation patterns, streaming-to-batch lakehouse flows, or Databricks-centered serving architectures.
Data Catalog And Discovery
Guides agents through data catalog, discovery, and metadata quality workflows. Use when publishing datasets, improving discoverability, curating lineage metadata, or making data products easier for other teams to find and trust.
Data Specification
Creates structured specifications for data products and pipeline changes. Use when starting a new pipeline, model, ingestion flow, or any significant change with unclear requirements.
Mainframe Modernization And Data Offload
Guides agents through mainframe data modernization and offload workflows. Use when migrating or exposing data from COBOL, JCL, VSAM, IMS, DB2 for z/OS, or batch-oriented mainframe estates into modern lakes, warehouses, streaming systems, and governed data products.
Using Compliance Agent Skills
Meta entry skill for the USA compliance agent repository. Routes tasks to HIPAA, HITECH, PCI-DSS, SOC 2, ISO 27001, NIST CSF 2.0, CCPA/CPRA, US state privacy, GDPR, FedRAMP, SOX, CMMC, and GLBA skills; configures presets, MCP servers, and the audit lifecycle (/scope, /audit, /evidence, /remediate, /report). Trigger when starting any compliance engagement, choosing which skill to load, onboarding…
Clickhouse Real Time Analytics
Guides agents through ClickHouse-based real-time analytics design. Use when building fast analytical serving layers, event aggregations, materialized views, or low-latency metric access patterns.
Lakehouse Table Format Engineering
Guides agents through lakehouse table design and open table format decisions. Use when designing or changing Iceberg, Delta, Hudi, partitioning, schema evolution, compaction, or batch and streaming interoperability.
Data Security Compliance And Regulated Data
Guides agents through regulated-data security and compliance workflows for PII, PCI, HIPAA, PHI, and similar obligations. Use when data products handle sensitive fields, regulated records, control evidence, or audit-bound publish paths.
Hibernate Orm Persistence
Model and query relational data with Hibernate ORM — entities, associations, fetch plans, caching, and HQL/Criteria. Use for Java persistence beyond basic Spring Data JPA defaults or in Jakarta EE applications.
Aws Fullstack Development
Apply AWS-oriented fullstack defaults for frontend hosting, backend microservices, security, and observability. Use when users request cloud-specific fullstack delivery on AWS.
Airflow And Workflow Orchestration
Guides agents through workflow orchestration design and operation across Airflow-style DAGs, cloud-native schedulers, and event-driven pipeline control planes. Use when building or modifying workflow dependencies, retries, triggers, sensors, SLAs, or cross-system pipeline coordination.
Data Engineering Agent Skills
Production-grade Agent Skills for data engineering AI agents: 73 workflows, platform presets, safe backfill/replay, Kafka & Spark reliability, MCP observability, and VS Code/JetBrains installers.
Etl Elt And Modernization Strategy
Guides agents through ETL, ELT, and transformation-modernization decisions. Use when choosing execution boundaries, redesigning transformation layers, or moving from legacy ETL estates to warehouse- or lakehouse-centered ELT patterns.
Using Platform Engineering Agent Skills
Helps agents classify platform engineering and AI safety work, choose presets and skill bundles, and pick the safest next command. Use when starting a session, triaging IDP/GitOps, agentic security, DataOps, or observability requests.
Apache Beam Unified Batch And Stream
Guides agents through Apache Beam pipelines that unify batch and streaming logic. Use when designing Beam transforms, windowing, runners, replay behavior, or portability across execution backends.
Iso27001 Annex A Controls
Implements ISO/IEC 27001:2022 Annex A control assessment—93 controls across Organizational, People, Physical, and Technological themes—covering Statement of Applicability (SoA), risk treatment, and implementation evidence. Trigger when building or auditing an ISMS, mapping Annex A to existing controls, preparing ISO 27001 certification, or assessing agent/MCP systems against ISO 27002:2022 guidan…
Pci Dss Script Audit
Automates PCI-DSS v4.0 Requirements 6.4.3 (payment-page script authorization, inventory, integrity hashes, and business justification) and 11.6.1 (weekly change/tamper detection for HTTP security headers and DOM scripts). Trigger when auditing ecommerce checkout or payment pages, validating third-party JavaScript governance, detecting unauthorized script or CSP changes, or producing PCI script in…
Data Quality Platforms And Rule Management
Guides agents through data-quality operating models and tool selection. Use when designing rule portfolios, severity levels, ownership, evidence, and enforcement across dbt tests, Great Expectations, Deequ, Cuallee, Soda, warehouse-native checks, and platform monitoring workflows.
Nist Ai Rmf Governance
Implements NIST AI Risk Management Framework (AI RMF 1.0, NIST AI 100-1)—GOVERN, MAP, MEASURE, and MANAGE functions—for trustworthy AI systems including LLM agents, MCP toolchains, and automated compliance workflows. Trigger when assessing AI governance, model risk, agent trustworthiness, GenAI deployment controls, or harmonizing AI RMF with NIST CSF 2.0 and ISO 42001 concepts. Do not use for gen…
Hitech Breach Notification
Implements HITECH Act breach notification depth beyond baseline HIPAA—42 U.S.C. §17921–17923, ARRA Title XIII Subtitle D, OCR breach reporting portal workflows, 500+ individual media/HHS rules, business associate direct liability, encryption/unsecured PHI safe harbor analysis, and accounting of disclosures for breaches involving agent/LLM/MCP systems. Trigger when conducting HITECH-specific breac…
Nist Csf 2 Assessment
Performs NIST Cybersecurity Framework 2.0 gap assessments across six Functions—Govern, Identify, Protect, Detect, Respond, Recover—using CSF 2.0 categories, subcategories, Implementation Tiers, and Organizational Profiles. Trigger when benchmarking security posture, preparing executive risk reporting, assessing AI/agent system controls against NIST CSF, or harmonizing CSF with ISO 27001 or SOC 2…
Fedramp Moderate Baseline
Implements FedRAMP Moderate baseline assessments using NIST SP 800-53 Revision 5 controls—authorization boundary definition, System Security Plan (SSP), Plan of Action and Milestones (POA&M), and continuous monitoring (ConMon)—with Cloud Service Provider (CSP) and agency customer responsibility matrices. Trigger when preparing FedRAMP authorization packages, assessing cloud offerings for federal…
Sox Itgc Audit
Performs Sarbanes-Oxley Act (SOX) IT General Controls (ITGC) audits aligned to COSO Internal Control—Integrated Framework and PCAOB AS 2201—covering access to programs and data, program change management, program development, and computer operations relevant to financial reporting systems. Trigger when preparing SOX 404 management assessment, supporting external auditor ITGC reliance, testing cha…
Data Migration And Platform Cutover
Guides agents through data migration and platform cutover workflows. Use when moving pipelines, tables, contracts, orchestration, or workloads between systems, clouds, warehouses, lakehouses, or serving layers.
Spring Cloud Gateway Routing
Configure Spring Cloud Gateway for API routing, rate limiting, JWT validation, and canary traffic splitting. Use at the edge of Spring microservice meshes.
Hateoas
Use when adding hypermedia links to REST responses, building self-describing APIs, or implementing Spring HATEOAS. Use when you see EntityModel, CollectionModel, or RepresentationModel in the project.
Kafka Resilience And Schema Evolution
Enforces production Kafka guardrails including non-breaking schema evolution, dead-letter queues for poison messages, and acks=all producer durability. Use when designing or changing Kafka topics, producers, consumers, schema registry policies, or streaming recovery paths.
Azure Serverless Fullstack
Azure serverless defaults for Static Web Apps, API Management, Azure Functions, Entra ID, Cosmos DB or SQL, Service Bus, and Application Insights.
Avro Protobuf Json Schema Registry
Guides agents through schema-registry-backed event contracts. Use when managing Avro, Protobuf, or JSON Schema for event streams, compatibility policies, producer and consumer evolution, or contract enforcement in messaging systems.
Flyway Migrations
Use when creating database migrations, schema changes, seed data, or any SQL that modifies database structure. Covers Flyway naming conventions, versioning, and safe migration patterns.
Hexagonal Architecture
Use when the project follows hexagonal (ports & adapters) architecture. Prevents domain code from depending on Spring or JPA. Use when you see packages like domain/, application/, infrastructure/, or adapters/ in the project structure.
Oauth2 Resource Server
Use when configuring Spring Boot as an OAuth2 resource server, validating JWTs from an external auth provider (Keycloak, Auth0, Okta, Cognito), extracting claims, or implementing scope-based authorization.
Spring Webflux Reactive
Build reactive Spring WebFlux APIs with non-blocking I/O, backpressure-aware streams, and Project Reactor. Use for high-concurrency Java services without virtual-thread blocking models.
Ef Core Persistence
Model relational domains with EF Core 8, fluent configurations, migrations, interceptors, and performant queries. Use for .NET persistence layers with zero-downtime migration discipline.
Spring Ai Integration
Use when integrating LLMs, chat clients, embeddings, RAG pipelines, or AI agents into Spring Boot. Covers Spring AI ChatClient, prompt templates, embeddings, vector stores, and structured output. Use when user mentions Spring AI, LLM, ChatGPT, Claude, RAG, embeddings.
Java Agent Core
Design and implement AI agent cores in Java/Spring Boot with tool registries, memory, orchestration, and safe execution boundaries. Use when building autonomous agents, multi-step workflows, or agent-as-a-service on the JVM.
Spring Security Jwt
Use when implementing authentication, authorization, JWT tokens, security filters, password encoding, or any Spring Security configuration. Covers stateless JWT auth, token rotation, RBAC, and method-level security.
Multi Module Maven
Use when working in a multi-module Maven project. Covers parent POM conventions, shared dependency management, inter-module rules, and build ordering.
Vercel Ai Sdk Streaming
Build streaming AI features in Next.js with Vercel AI SDK, tool calling, RSC/UI hooks, and edge-safe API routes. Use for TypeScript fullstack AI UX with React Server Components.
Mongodb Document Modeling
Design MongoDB document schemas, indexes, aggregation pipelines, and multi-tenant patterns with operational safety. Use for document-store backends in fullstack applications.
Problem Details Rfc9457
Use when implementing error handling, exception mappers, or error response formatting. Enforces RFC 9457 (Problem Details for HTTP APIs) using Spring's built-in ProblemDetail.
Ai Observability
Use when adding monitoring, metrics, logging, or tracing to Spring AI or LLM integration code. Covers token tracking, latency measurement, cost estimation, and prompt/response logging. Use when user mentions AI monitoring, token costs, or LLM observability.
Elasticsearch Search Patterns
Implement Elasticsearch/OpenSearch indexing, mappings, analyzers, and secure search APIs with sync from primary databases. Use for full-text search, faceted browse, and observability log search in fullstack apps.
Layered Architecture
Use when generating or modifying any Spring Boot class — controllers, services, repositories, DTOs, mappers, or configuration. Enforces strict layer separation and prevents business logic from leaking across boundaries.
Quarkus Kubernetes Native
Deploy container-first Quarkus applications on Kubernetes with fast startup, low memory, native images, and health probes. Use when Quarkus is chosen specifically for cloud/Kubernetes efficiency over Spring Boot.
Quarkus Cloud Native Apis
Build cloud-native REST and reactive APIs with Quarkus, GraalVM native images, and Kubernetes-ready health probes. Use for Java microservices targeting fast startup and low memory footprint.
Idp Gitops And Golden Paths
Architects Internal Developer Platforms with Backstage golden paths, Scaffolder templates, GitOps (ArgoCD/Flux), and IaC (Terraform/Pulumi). Use when building developer portals, self-service templates, continuous delivery, or modular infrastructure components.
File And Partner Feed Ingestion
Guides agents through file-based and partner-feed ingestion workflows. Use when landing data from SFTP, managed file transfer, shared buckets, recurring flat files, manifests, or externally supplied feeds that need validation, replay safety, and publish discipline.
Great Expectations Deequ And Cuallee
Guides agents through data-quality frameworks such as Great Expectations, Deequ, and Cuallee. Use when implementing framework-based validation suites, reusable checks, or evidence-driven data-quality enforcement.
Soc2 Trust Services Criteria
Maps organizational controls and evidence to AICPA SOC 2 Trust Services Criteria (2017 TSC with 2022 revisions)—Security (CC), Availability (A), Confidentiality (C), Processing Integrity (PI), and Privacy (P). Trigger when scoping SOC 2 audits, gap assessments, control design reviews, or mapping agent/MCP architecture to TSC. Do not use for evidence collection mechanics (use soc2-evidence-collect…
Domain Driven Design
Use when working with domain models, aggregates, value objects, domain events, or repositories in a DDD-style project. Ensures rich domain model over anemic CRUD.
Debezium And Kafka Connect Cdc
Guides agents through Debezium and Kafka Connect CDC workflows. Use when streaming database changes into Kafka topics, managing connectors, snapshots, schema evolution, or downstream CDC consumers.
Soc2 Ccm Continuous Monitoring
Implements Continuous Control Monitoring (CCM) for SOC 2—automated control testing, configuration drift detection, predictive risk scoring, and alerting—for agent platforms, MCP servers, and cloud infrastructure. Trigger when building always-on compliance dashboards, detecting TSC control drift between audits, or operationalizing CC4/CC7 monitoring. Do not use for one-time evidence binders (use s…
Cdc And Incremental Loading
Guides agents through change data capture and incremental load design. Use when building or modifying watermark-based loads, upserts, deduplication, merge logic, late data handling, or replayable incremental pipelines.
Data Mesh And Domain Oriented Design
Guides agents through domain-oriented data product and data mesh design. Use when organizing ownership, domain boundaries, federated governance, and shared platform responsibilities across multiple teams.
Ferpa Education Records
Implements FERPA (20 U.S.C. §1232g; 34 CFR Part 99) protections for student education records in EdTech, LMS integrations, and AI tutoring agents—school official exceptions, legitimate educational interest, directory information, parent/eligible student rights, and vendor DPAs. Trigger when K-12 or higher-ed systems process student records, deploying AI agents in classrooms, auditing EdTech subpr…
Observability And Finops
Standardizes OpenTelemetry telemetry, Keptn SLO analysis gates, and Kubernetes cost management with OpenCost/Kubecost aligned to FOCUS. Use when defining SLIs/SLOs, OTel collectors, deployment quality gates, or FinOps reporting.
Bigquery And Dataform Platform Engineering
Guides agents through BigQuery- and Dataform-centered data engineering workflows. Use when designing BigQuery physical models, ingestion boundaries, Dataform transformation workflows, slot or cost controls, and platform decisions across BigQuery, Dataflow, Dataproc, and GCP orchestration services.
Hipaa Privacy Minimum Necessary
Implements HIPAA Privacy Rule minimum necessary standard—45 CFR §164.502(b)—plus §164.514 de-identification, Limited Data Sets, and patient rights to access and amend records, with agent prompt minimization, role-based PHI exposure, and integration with the Presidio redaction pipeline. Trigger when designing LLM/agent PHI access policies, auditing disclosure practices, implementing patient rights…
Pci Dss Encryption Key Management
Audits PCI-DSS v4.0 Requirement 3 (protect stored account data) and Requirement 4 (protect cardholder data with strong cryptography during transmission)—covering key management lifecycle, HSM usage, PAN masking, tokenization, and TLS 1.2+ enforcement with Terraform/Vault MCP patterns for evidence collection. Trigger when assessing encryption of CHD/SAD at rest or in transit, reviewing key rotatio…
Api And Saas Ingestion Patterns
Guides agents through API and SaaS ingestion workflows. Use when extracting data from REST, GraphQL, or SaaS platforms with pagination, rate limits, auth rotation, backfills, or unstable source contracts.
Nodejs Microservices
Apply backend service defaults for Node.js microservices including contract governance, resilience, and observability. Use when services are built with Node.js, TypeScript, HTTP APIs, queues, or event-driven boundaries.
Data Platform Disaster Recovery And Business Continuity
Guides agents through disaster recovery and business continuity planning for data platforms. Use when defining region or account failover, backup and restore, RTO or RPO targets, control-plane recovery, or restore drills for pipelines, warehouses, lakehouses, and publish surfaces.
Breach Incident Response
Executes USA breach and security incident response—HIPAA Breach Notification Rule (45 CFR §164.400–414), HITECH 60-day notification, state breach laws, and SOC 2 CC7.4/CC7.5 incident management—for agent, MCP, and LLM-related events. Trigger when investigating suspected PHI/PII exposure, unauthorized MCP access, LLM data leakage, or preparing breach notifications. Do not use for preventive loggin…
Incident Triage And Pipeline Recovery
Guides agents through production data incidents. Use when a pipeline fails, publishes bad data, misses an SLA, partially loads, corrupts state, or requires rollback, replay, or stakeholder communication.
Openmetadata Datahub And Openlineage
Guides agents through metadata platform and lineage workflows using OpenMetadata, DataHub, or OpenLineage-compatible systems. Use when improving discovery, lineage quality, metadata governance, or producer-to-catalog integration.
Glba Ffiec Financial Privacy
Implements Gramm-Leach-Bliley Act (GLBA) Safeguards Rule (16 CFR Part 314) and Privacy Rule (16 CFR Part 313) compliance aligned to FFIEC IT Examination Handbook modules for financial institutions—customer information protection, risk assessments, access controls, vendor oversight, and GLBA privacy notices (initial, annual, opt-out). Trigger when auditing banks, credit unions, fintech lenders, or…
Aws Serverless Fullstack
AWS serverless defaults for API Gateway, Lambda, Cognito, DynamoDB or RDS, S3, CloudFront, EventBridge, and CloudWatch observability.
Java Data Engineering And Integration Services
Guides agents through Java-based data engineering services and processors. Use when building connectors, ingestion services, stream processors, metadata services, JVM batch tools, or operational integrations in Java.
Data Resiliency Testing And Failure Injection
Guides agents through resiliency testing for data platforms. Use when designing or running failure drills, recovery validation, failover tests, replay-safety checks, dependency outage exercises, or fault injection for pipelines and publishes.
Dataops And Rag Architectures
Implements DataOps CI/CD with lakeFS-style branching, pre-commit data validation hooks, and deterministic RAG ingestion with vector DB as fuzzy recall fallback. Use when building data pipelines, RAG systems, or isolated dev/test data environments.
Hipaa Phi Redaction Pipeline
Configures and validates the Presidio-based PHI redaction pipeline—DLP entity detection, reversible tokenization before LLM ingestion, and authorized deanonymization—integrated with redaction.py and the compliance agent. Trigger when ePHI may appear in prompts, implementing minimum-necessary LLM access, tuning entity types, or auditing redaction effectiveness. Do not use for HIPAA access control…
Enterprise Etl And Data Integration Modernization
Guides agents through operating, hardening, and modernizing enterprise ETL and integration stacks such as Informatica, Talend, DataStage, SSIS, and Matillion. Use when legacy mappings, job orchestration, migration, or coexistence with modern lakehouse patterns must be handled safely.
Hipaa Baa Vendor Assessment
Reviews Business Associate Agreements and subprocessors for LLM vendors, cloud providers, and MCP server operators under HIPAA (45 CFR §164.502(e), §164.504(e)). Trigger when onboarding OpenAI/Anthropic/Azure OpenAI, cloud hosts, observability tools, or MCP integrations that may access ePHI. Do not use for technical encryption testing (use hipaa-technical-safeguards) or general vendor SOC reports…
Jakarta Ee Enterprise Platform
Build standards-based enterprise Java with Jakarta EE (JAX-RS, CDI, JPA, Bean Validation, Security) for regulated industries and portable application servers. Use when Jakarta EE compliance matters more than Spring-specific conventions.
Gdpr Us Multinational
Implements GDPR compliance workflows for US-headquartered multinationals—EU/EEA/UK data subjects, Articles 5-7 lawful basis, Article 30 records of processing, Article 32 security, Articles 33-34 breach notification (72 hours), Article 35 DPIA, Standard Contractual Clauses, EU-US Data Privacy Framework adequacy, and DPA/subprocessor governance for agent/LLM cross-border transfers. Trigger when US…
Mcp Server
Use when building MCP (Model Context Protocol) servers in Java/Spring Boot. Covers tool registration, resource exposure, prompt templates, and production deployment using the official MCP Java SDK. Use when user mentions MCP, AI agent integration, or tool calling.
Us State Privacy Laws
Implements comprehensive US state comprehensive privacy law assessments—Virginia VCDPA (Va. Code §59.1-575), Colorado CPA (C.R.S. §6-1-1301), Connecticut CTDPA, Utah UCPA, Texas TDPSA, Oregon OCPA, Montana MCDPA, Iowa ICDPA, Delaware DPDPA, New Jersey, and harmonized multi-state consumer rights programs—for agent/LLM data flows, opt-out, DSAR, and data protection assessments. Trigger when operati…
Esg And Sustainability Regulatory Reporting
Guides agents through ESG, sustainability, and regulatory reporting data products. Use when building governed metrics, traceable evidence, and audit-ready data pipelines for frameworks such as CSRD/ESRS, BRSR, climate disclosures, or similar sustainability reporting obligations.
Micronaut Compile Time Di
Build Micronaut microservices with compile-time dependency injection, zero runtime reflection, and GraalVM-ready APIs. Use when avoiding runtime reflection overhead and annotation processing at build time is preferred.
Java Spring Boot Microservices
Apply service defaults for Java Spring Boot microservices with contract governance, resilience, observability, and delivery safety. Use when backend services are built with Java and Spring.
Aspnetcore Minimal Apis
Build ASP.NET Core minimal APIs with endpoint filters, JWT auth, OpenAPI, and clean handler delegation. Use for lightweight .NET microservices and BFF endpoints without MVC ceremony.
Spring Data Redis
Use when implementing caching, session storage, rate limiting, or any Redis integration. Covers cache-aside pattern, key naming, TTL strategy, and serialization config.
Audit Logging Integrity
Designs and validates tamper-evident audit logging, SIEM integration, and log retention for HIPAA §164.312(b) audit controls, SOC 2 CC7.2/CC7.3, and PCI Req 10. Trigger when assessing agent/MCP audit trails, log tampering risks, centralized logging, or forensic readiness. Do not use for IAM permission reviews (use access-control-identity-audit) or breach notification workflows (use breach-inciden…
Spring Data Jpa
Use when generating JPA entities, repositories, queries, or anything touching the persistence layer. Covers entity conventions, N+1 prevention, projections, and query patterns.
Lower Environment Data Masking And Obfuscation
Guides agents through masking, obfuscating, and safely promoting production-like data into lower environments. Use when QA, development, or staging needs realistic data without exposing production-sensitive values.
Flutter Fullstack Mobile
Build Flutter mobile clients with clean architecture, Riverpod/Bloc state, typed REST/GraphQL clients, offline sync, and secure token storage. Use for fullstack mobile delivery paired with backend APIs.
Hipaa Technical Safeguards
Implements HIPAA Security Rule technical safeguards (45 CFR §164.312)—access control, audit controls, integrity, person/entity authentication, and transmission security—for AI agents, MCP servers, and LLM pipelines. Trigger when assessing ePHI handling in agent architectures, MCP tool authorization, encryption in transit/at rest, or mapping HIPAA controls to technical implementations. Do not use…
Vue Nuxt Frontend
Apply frontend defaults for Vue and Nuxt stacks, including composables, route rendering strategy, and performance guardrails. Use when stack choices include Vue.js, Nuxt, and TypeScript.
Openapi First
Use when the project follows API-first / OpenAPI-first approach: generating controller interfaces, DTOs, and clients from an OpenAPI spec. Use when you see openapi.yaml, openapi-generator-maven-plugin, or ApiDelegate pattern in the project.
Spring Boot Enterprise Foundation
Build enterprise Spring Boot backends and microservices with auto-configuration, production defaults, and Spring AI integration paths. Use as the entry skill when choosing Spring Boot over other JVM frameworks.
Data Lake And Zone Architecture
Guides agents through data lake and zone architecture design. Use when defining raw, refined, curated, or publish layers; storage organization; retention; and operational boundaries for a data lake.
Access Control Identity Audit
Audits identity and access management—least privilege, RBAC, MFA, privileged access, joiner-mover-leaver—for SOC 2 CC6.1–CC6.8, HIPAA §164.312(a), and PCI Req 7/8. Trigger when reviewing IAM policies, agent/MCP service accounts, access certifications, or admin console permissions. Do not use for network firewall segmentation (use pci-dss-network-segmentation) or tamper-evident logging design (use…
Skill 08 Security Audit
Performs Web3 security analysis including vulnerability detection, rug pull checks, and exploit monitoring. Use before interacting with unknown contracts or when auditing smart contract code.
Skill 12 Gas Optimization
Optimizes transaction gas via EIP-1559 fee prediction, nonce management, private transaction submission, and EIP-4844 blob fee handling. Use when estimating fees, fixing stuck transactions, or submitting MEV-sensitive txs.
Skill 02 Smart Contract Interaction
Interacts with smart contracts via ABI encode/decode, read/write calls, deployment, proxy patterns, and multicall batching. Use when calling contract functions, deploying contracts, or working with upgradeable proxies.
Skill 11 Oracle Data Feeds
Integrates oracle and data feed services including Chainlink and Pyth price feeds, VRF randomness, and Chainlink Automation keepers. Use when consuming on-chain price data, random numbers, or conditional automation.
Soc2 Evidence Collection
Automates SOC 2 evidence gathering—screenshots, configuration exports, access reviews, log samples, and audit-trail packaging with integrity hashes—for AICPA TSC examinations. Trigger when preparing audit binders, populating Vanta/Drata-style evidence requests, or packaging agent/MCP compliance artifacts. Do not use for control mapping (use soc2-trust-services-criteria) or continuous drift monito…
Pci Dss Network Segmentation
Validates PCI-DSS v4.0 network segmentation and scope reduction—Requirement 1.x (firewalls, network security controls) and 2.x (secure configurations)—for Cardholder Data Environment (CDE) isolation. Trigger when scoping PCI environments, reviewing firewall rules, VLAN segmentation, agent/MCP access to CDE, or reducing assessment scope. Do not use for payment-page script audits (use pci-dss-scrip…
Cmmc Nist 800 171
Implements CMMC 2.0 Level 2 assessments aligned to NIST SP 800-171 Revision 2 (110 security requirements across 14 families) for Controlled Unclassified Information (CUI) protection in the Defense Industrial Base (DIB), including SPRS score self-assessment, POA&M management, and government contract flow-down obligations under DFARS 252.204-7012/7019/7020. Trigger when preparing for CMMC Level 2 c…
Gcp Fullstack Development
Apply GCP-oriented fullstack defaults for frontend, microservices, security, and observability. Use when users request cloud-specific fullstack architecture and delivery on GCP.
Master Data And Entity Resolution
Guides agents through master data and entity resolution workflows. Use when matching identities across systems, defining canonical entities, resolving duplicates, or building golden records for shared downstream use.
Gcp Serverless Fullstack
GCP serverless defaults for Cloud Run, API Gateway, Pub/Sub, Cloud CDN, Firebase Auth or IAP, and Cloud Monitoring.
Data Platform Operating Model And Service Ownership
Guides agents through data platform operating model and ownership design. Use when defining platform team responsibilities, service tiers, golden paths, escalation boundaries, onboarding flows, or handoffs between central platform teams and domain or product teams.
Lakefs And Data Versioning
Guides agents through data versioning workflows using lakeFS or similar systems. Use when branching data, validating changes before publish, or controlling risky lakehouse operations with versioned data states.
Azure Fullstack Development
Apply Azure-oriented fullstack defaults for frontend delivery, microservices, identity, and operational readiness. Use when users request cloud-specific fullstack architecture and deployment on Azure.
Ccpa Cpra Privacy Rights
Implements California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA)—Cal. Civ. Code §1798.100 et seq.—covering consumer rights to know, delete, correct, opt-out of sale/share, and limit use of sensitive personal information, plus DSAR workflows, privacy notices, and service provider contracts for AI/agent data handling. Trigger when processing California reside…
Data Quality And Contract Testing
Drives data implementation with contracts, assertions, and validation evidence. Use when adding or changing ingestion logic, transformations, schemas, or published data products.
Skill 06 Cross Chain Bridge
Handles cross-chain operations including token bridging, cross-chain messaging, and intent-based routing. Use when moving assets or data between blockchains.
Fullstack Typescript Monorepo
Apply a TypeScript monorepo preset for fullstack systems with shared contracts, frontend and backend package boundaries, CI caching, and consistent developer workflows.
Operational Datastore Selection Relational And Nosql
Guides agents through choosing relational operational stores such as MySQL versus NoSQL options such as document, key-value, wide-column, or cache-backed systems. Use when deciding where application-adjacent or pipeline-adjacent operational data should live.
Go Gin Rest Microservices
Build Go REST microservices with Gin, clean architecture, context propagation, and production observability. Use for high-performance Go backend APIs and edge services.
Data Observability And Sla Management
Guides agents through data observability and service-level management. Use when defining or improving freshness, completeness, anomaly detection, alerting, lag tracking, run metadata, and ownership for production data products.
Data Platform Ci Cd And Release Management
Guides agents through CI/CD and release management for data platforms. Use when promoting pipeline code, SQL models, contracts, infra, or configuration across environments with validation gates, staged rollout, and rollback awareness.
Kubernetes Fullstack Platform
Kubernetes platform defaults for ingress, autoscaling, secrets, GitOps delivery, and fullstack workload isolation.
Vercel Nextjs Jamstack
Jamstack and edge delivery defaults for Next.js on Vercel-style platforms with ISR, preview deployments, and edge function boundaries.
Angular Frontend
Apply frontend defaults for Angular projects with enterprise modularity, accessibility, and scalable state patterns. Use when the stack is Angular and TypeScript.
Rest Api Conventions
Use when generating REST controllers, response wrappers, DTOs, error handlers, or any HTTP-facing code. Defines response envelope, HTTP status mapping, pagination, and versioning.