
This Skill is built on practical expertise in AI agent safety, prompt-injection defense, source-to-sink privacy review, tool and MCP metadata integrity, memory provenance checks, autonomous action scoping, and evidence-based verification. It helps agents separate instructions from evidence before tool calls, uploads, publishing, deletion, code execution, or network output.

I've spent years building production software, designing enterprise architectures, reviewing thousands of code changes, and optimizing AI-assisted development workflows. This Skill packages proven engineering, planning, documentation, testing, and code-review practices into a lightweight workflow that helps AI understand any project before making changes, reducing mistakes, hallucinations, unnecessary token usage, and repeated context loading.

Defensive application-security auditing: turns a repo, manifest, or code snippet into an actionable report—dependency vulnerabilities, leaked secrets, insecure code patterns, and config hardening—mapped to OWASP Top 10 and ranked by severity. Finds risk and the fix only, never attack content.

Created from 10+ years of manufacturing and industrial automation experience across food packaging, planter-part manufacturing, and Tier 1 automotive environments, with Ignition used in production-facing work over that span. The skill packages practical SCADA judgment around maintainable expressions, operator-safe behavior, troubleshooting habits, and realistic Designer/Gateway validation workflows.

Before you write code, kill the causes of rework. A phase-gate skill that runs a pre-implementation diagnosis (clarify requirements, success criteria, non-goals, hidden risks) and sets up the dev environment (toolchain check, repo init, dependency/secret/config templates, DB/API contract, folder layout). Each gate must pass before moving on. Delivers a diagnosis report, a stack-selection doc, and a ready-to-build foundation to hand off to implementation.

Connect any MCP-compatible AI agent (Claude, Cursor, Copilot, Codex, Windsurf, Amp, Cline) to Penpot to create, audit, and maintain design systems — tokens, flows, interactions, animations, and design-to-code export to HTML/CSS/React.

Autopsy and rewrite the first second of your Shorts — eight field-tested failure patterns, ranked rewrites, and a promise ledger the body must pay.

A kickoff protocol (agent skill) for multi-step tasks. Before writing any code, the agent must: run a spec interview, batch every human-authorization step into one checklist, build a self-verification loop (log sink + verify script + dry-run) *before* the feature itself, and build comparable variants instead of blocking on third-party decisions.

Created from 10+ years of manufacturing and industrial automation experience across food packaging, planter-part manufacturing, and Tier 1 automotive environments, with Ignition used in production-facing work over that span. The skill packages practical SCADA judgment around maintainable expressions, operator-safe behavior, troubleshooting habits, and realistic Designer/Gateway validation workflows.