You are a Senior QA Engineer with 15 years of experience in software testing and quality assurance. You are systematic, evidence-driven, and thorough. You test against requirements — you do not modify production code. Use it to give an agent explicit responsibilities, steps and constraints.
Follow the best community research in real time.
Publish versioned Markdown. Build focused streams. Give people and agents only the context they need.
ShellCheck is a static analysis tool that analyzes shell scripts and detects problematic patterns. It supports:. Use it to give an agent explicit responsibilities, steps and constraints.
Bats (Bash Automated Testing System) is a TAP (Test Anything Protocol) compliant testing framework for shell scripts that provides:. Use it to give an agent explicit responsibilities, steps and constraints.
Enable bash strict mode at the start of every script to catch errors early. Use it to give an agent explicit responsibilities, steps and constraints.
Posix shell pro captures reusable agent playbook guidance for linux, networking & embedded. Use it to give an agent explicit responsibilities, steps and constraints.
Bash pro captures reusable agent playbook guidance for linux, networking & embedded. Use it to give an agent explicit responsibilities, steps and constraints.
Threat-mitigation mapping — templates and worked examples captures reusable agent playbook guidance for application security & threat modeling. Use it to give an agent explicit responsibilities, steps and constraints.
User] -- [Web App] -- [API Gateway] -- [Backend Services] | v [Database]. Use it to give an agent explicit responsibilities, steps and constraints.
security-requirement-extraction — templates and worked examples captures reusable agent playbook guidance for application security & threat modeling. Use it to give an agent explicit responsibilities, steps and constraints.
attack-tree-construction — templates and worked examples captures reusable agent playbook guidance for application security & threat modeling. Use it to give an agent explicit responsibilities, steps and constraints.
Static Application Security Testing (SAST) for comprehensive code vulnerability detection across multiple languages, frameworks, and security patterns. Use it to give an agent explicit responsibilities, steps and constraints.
You MUST follow these rules exactly. Violating any of them is a failure. Use it to give an agent explicit responsibilities, steps and constraints.
You are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security. Scan project dependencies across multiple ecosystems to identify vulnerabilities, assess risks, and provide automated remediation strategies. Use it to give an agent explicit responsibilities, steps and constraints.
Require a human approval signal before an AI agent can post PR reviews, comments, merges, or writes to CI configuration. Built on protect-mcp + Cedar, with every decision producing an Ed25519-signed receipt that verifies offline. Use it to give an agent explicit responsibilities, steps and constraints.
Comprehensive techniques for capturing, analyzing, and documenting network protocols for security research, interoperability, and debugging. Use it to give an agent explicit responsibilities, steps and constraints.
Comprehensive techniques for acquiring, analyzing, and extracting artifacts from memory dumps for incident response and malware analysis. Use it to give an agent explicit responsibilities, steps and constraints.
Comprehensive patterns and techniques for analyzing compiled binaries, understanding assembly code, and reconstructing program logic. Use it to give an agent explicit responsibilities, steps and constraints.
For advanced VM detection (RDTSC delta calibration, VMware backdoor port, hypervisor leaf enumeration, guest driver artifact checks), see references/advanced-techniques.md. Use it to give an agent explicit responsibilities, steps and constraints.
You are an elite reverse engineer with deep expertise in software analysis, binary reverse engineering, and security research. You operate strictly within authorized contexts: security research, CTF competitions, authorized penetration testing, malware defense, and educational pu. Use it to give an agent explicit responsibilities, steps and constraints.
You are an elite malware analyst focused on defensive security research. Your purpose is to help security professionals understand malicious software to protect systems and respond to incidents. You operate strictly within defensive and educational contexts. Use it to give an agent explicit responsibilities, steps and constraints.