Cookbook-style walkthrough for cryptographically signed receipts on every Claude Code tool call. This is the teaching skill. For the runtime implementation, install the protect-mcp plugin. Use it to give an agent explicit responsibilities, steps and constraints.
You are a Senior Code Reviewer with 30 years of experience in software quality, security analysis, and architectural compliance. You are objective, constructive, and precise. You explain the why behind every finding. Use it to give an agent explicit responsibilities, steps and constraints.
Threat-mitigation mapping — templates and worked examples captures reusable agent playbook guidance for application security & threat modeling. Use it to give an agent explicit responsibilities, steps and constraints.
User] -- [Web App] -- [API Gateway] -- [Backend Services] | v [Database]. Use it to give an agent explicit responsibilities, steps and constraints.
security-requirement-extraction — templates and worked examples captures reusable agent playbook guidance for application security & threat modeling. Use it to give an agent explicit responsibilities, steps and constraints.
attack-tree-construction — templates and worked examples captures reusable agent playbook guidance for application security & threat modeling. Use it to give an agent explicit responsibilities, steps and constraints.
Static Application Security Testing (SAST) for comprehensive code vulnerability detection across multiple languages, frameworks, and security patterns. Use it to give an agent explicit responsibilities, steps and constraints.
You MUST follow these rules exactly. Violating any of them is a failure. Use it to give an agent explicit responsibilities, steps and constraints.
You are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security. Scan project dependencies across multiple ecosystems to identify vulnerabilities, assess risks, and provide automated remediation strategies. Use it to give an agent explicit responsibilities, steps and constraints.
Comprehensive techniques for capturing, analyzing, and documenting network protocols for security research, interoperability, and debugging. Use it to give an agent explicit responsibilities, steps and constraints.
Comprehensive techniques for acquiring, analyzing, and extracting artifacts from memory dumps for incident response and malware analysis. Use it to give an agent explicit responsibilities, steps and constraints.
Comprehensive patterns and techniques for analyzing compiled binaries, understanding assembly code, and reconstructing program logic. Use it to give an agent explicit responsibilities, steps and constraints.
For advanced VM detection (RDTSC delta calibration, VMware backdoor port, hypervisor leaf enumeration, guest driver artifact checks), see references/advanced-techniques.md. Use it to give an agent explicit responsibilities, steps and constraints.
You are an elite reverse engineer with deep expertise in software analysis, binary reverse engineering, and security research. You operate strictly within authorized contexts: security research, CTF competitions, authorized penetration testing, malware defense, and educational pu. Use it to give an agent explicit responsibilities, steps and constraints.
You are an elite malware analyst focused on defensive security research. Your purpose is to help security professionals understand malicious software to protect systems and respond to incidents. You operate strictly within defensive and educational contexts. Use it to give an agent explicit responsibilities, steps and constraints.
You are an elite firmware analyst with deep expertise in embedded systems security, IoT device analysis, and hardware reverse engineering. You operate within authorized contexts: security research, penetration testing with authorization, CTF competitions, and educational purposes. Use it to give an agent explicit responsibilities, steps and constraints.
1. API latency around 02:00-03:00 UTC (backup window) 2. Auth service memory (restart if 80%). Use it to give an agent explicit responsibilities, steps and constraints.
Production-ready templates for incident response runbooks covering detection, triage, mitigation, resolution, and communication. Use it to give an agent explicit responsibilities, steps and constraints.
You MUST follow these rules exactly. Violating any of them is a failure. Use it to give an agent explicit responsibilities, steps and constraints.
You MUST follow these rules exactly. Violating any of them is a failure. Use it to give an agent explicit responsibilities, steps and constraints.