
I built this Skill to help users protect API keys, OAuth tokens and MCP credentials when working with AI agents in Codex Desktop, Claude Desktop and local automation environments. It combines static leak detection, vault preflight checks, runtime redaction, MCP-safe remediation, credential-store guidance and security reporting. The Skill is designed to reduce accidental secret exposure while preserving legitimate MCP and API workflows.

I build small personal productivity tools and repeatedly needed a quick way to track data (books, inventory, expenses, habits) without a server or database. This skill packages that pattern: a reusable HTML/JS template (table, add/edit form, search/filter, chart, JSON/CSV export-import, localStorage) plus a workflow that adapts the template's fields to whatever the user describes in plain language. Output is a single offline HTML file, no account, API key, or server.

Drafts evidence-backed answers for vendor security questionnaires, customer security reviews, RFP security sections, privacy reviews, and AI trust questions. It preserves portal formats, cites sources, flags missing proof, and creates follow-up checklists without inventing compliance claims.

I specialize in safe Codex skill onboarding. This Agent inspects unclear websites, repositories, archives, file trees, snippets, and marketplace listings before installation. It explains candidate skills, identifies when Codex would use them, flags obvious installation risks, and requires explicit user confirmation before anything is downloaded or added to the skill library.

As a productivity expert managing massive knowledge bases, I've seen countless hours lost to cluttered Obsidian vaults. I built this Skill based on my strict "safety-first" data management framework. Unlike basic sorting scripts, this system acts like a professional archivist: it categorizes clear matches, quarantines uncertain files for your review, and generates a full audit log. It guarantees zero accidental deletions, giving creators and founders total peace of mind.

Connect Cursor, Claude Code, Hermes & Codex with a shared local SQLite brain. Slash token costs by 92.2% with instant, zero-amnesia cross-agent recall. 100% private, BYOK, lifetime buyout.

Built around the part everyone gets wrong: when a key leaks you rotate it first — it's compromised the second it hits a remote, and bots scan public pushes within seconds. Scans staged changes, the working tree, and git history for provider key shapes, private keys, committed .env/credential files, and hardcoded creds — tuned for signal over noise so placeholders and $ENV refs don't cry wolf — then walks rotate → purge-from-history → move-to-env → add-a-pre-commit-hook, in the right order.

Every app’s one-star reviews are a list of things somebody should build. Most of them never get built. Name any iOS app. GapFinder pulls its recent reviews from Apple’s public feed — up to 500 per country storefront — and reads what paying users actually complain about, what they keep asking for, and which competitor they say they left for. You get five build opportunities ranked by how often each comes up and how much it costs the user, each backed by quoted reviews.
