security-audit
| rank | capability | source |
|---|---|---|
| #1 | > Agent for `aws-eks-platform-operator`. Review Amazon EKS platform operations across cluster identity, access entries, node strategy, networking, autoscaling, upgrades, reliability, security, observability, and cost. | Raishin/vanguard-frontier-agentic |
| #2 | > Agent for `aws-landing-zone-governor`. Review AWS multi-account landing zones, Control Tower posture, Organizations structure, OUs, guardrails, logging, audit accounts, and account vending decisions. | Raishin/vanguard-frontier-agentic |
| #3 | > Agent for `aws-security-posture-hardening`. Harden AWS security posture across Security Hub CSPM, GuardDuty, Inspector, Macie, Config, IAM, logging, encryption, public exposure, and remediation workflow. | Raishin/vanguard-frontier-agentic |
| #4 | > Agent for `gcp-solution-architect`. Design GCP solutions aligned with the Google Cloud Architecture Framework — reliability, security, cost optimization, operational excellence, and performance efficiency — covering resource hierarchy design, product selection, and… | Raishin/vanguard-frontier-agentic |
| #5 | Review broad AWS security posture across Security Hub CSPM, GuardDuty, Inspector, Macie, Config, CloudTrail, IAM, public exposure, vulnerability findings, and remediation governance. Prefer compliance evidence mapper for audit evidence packs, IAM skill for policy surgery, S3… | Raishin/vanguard-frontier-agentic |
| #6 | Operate GKE clusters (Standard and Autopilot), manage node pools, configure Workload Identity, enforce Binary Authorization, plan node pool upgrades, and review cluster security posture. | Raishin/vanguard-frontier-agentic |
| #7 | Investigate GCP network issues by analyzing VPC Flow Logs, firewall logs, Cloud NAT logs, threat logs, and networking metrics. Diagnose connectivity, packet loss, top talkers, and firewall block events using BigQuery-first methodology and Cloud Monitoring fallback. Use when… | Raishin/vanguard-frontier-agentic |
| #8 | Review GCP security posture via Security Command Center findings, CIS GCP Benchmark gaps, org policy enforcement baseline, Assured Workloads controls, Binary Authorization, and CSPM recommendations. Prefer gcp-iam-least-privilege-review for IAM binding surgery and… | Raishin/vanguard-frontier-agentic |
| #9 | > Agent for `alibaba-daily-operations-briefing-coordinator`. Coordinate the daily Alibaba Cloud operations standup — cost delta from Cost Manager, ActionTrail anomaly review, ACK pod failure triage, quota utilization warnings, Security Center finding review, and action item… | Raishin/vanguard-frontier-agentic |
| #10 | > Agent for `alibaba-ram-iam-review`. Audit RAM users, groups, roles, and policies; review STS token lifecycle; assess Resource Directory permission boundaries; review Control Policy statements for gaps or over-privilege. | Raishin/vanguard-frontier-agentic |
| #11 | > Agent for oci-cloud-guard-responder. Triage and govern OCI Cloud Guard problems, targets, responder recipes, detector findings, and security remediation safely. Use for Cloud Guard reviews, problem prioritization, remediation planning, and compliance evidence when official… | Raishin/vanguard-frontier-agentic |
| #12 | > Agent for `oci-live-iam-policy-compartment-guard`. Guard OCI IAM policy changes and dynamic group mutations using verb-hierarchy audit and tag-condition review before write. | Raishin/vanguard-frontier-agentic |
| #13 | > Agent for oci-security-compliance-reviewer. Review Oracle Cloud Infrastructure security, IAM, network, logging, encryption, and compliance posture. Use when asked to audit OCI policies, compartments, tenancy security, Cloud Guard findings, buckets, vaults, security lists,… | Raishin/vanguard-frontier-agentic |
| #14 | > Agent for `oci-waf-security-review`. Assess OCI workload security posture across IAM, network isolation, encryption, threat detection, and Security Zones aligned to OCI Architecture Best Practices and CIS OCI Benchmark. | Raishin/vanguard-frontier-agentic |
| #15 | Query Alibaba Cloud ActionTrail management API call history, build governance audit reports, create SLS-based compliance evidence trails, and detect anomalous admin activity patterns. | Raishin/vanguard-frontier-agentic |
| #16 | Harden Alibaba Cloud security posture via Security Center (threat detection, vulnerability scanning, baseline checks), WAF, Anti-DDoS Pro, Cloud Firewall, and Network Traffic Analysis (NTA). | Raishin/vanguard-frontier-agentic |
| #17 | Audit Huawei Cloud IAM fine-grained policies, SCP (Service Control Policy) at Organizations level, agency trust relationships (cross-account delegation), and enterprise project permission boundaries. | Raishin/vanguard-frontier-agentic |
| #18 | Operate Huawei SecMaster (integrated SIEM/SOAR/threat intelligence), HSS (Host Security Service) host intrusion detection, CFW (Cloud Firewall), WAF (Web Application Firewall), Anti-DDoS, and VSS (Vulnerability Scan Service) for comprehensive cloud security operations. | Raishin/vanguard-frontier-agentic |
| #19 | > Agent for azure-key-vault-secret-lifecycle-auditor. Audit Azure Key Vault secret lifecycle posture across RBAC, soft delete, purge protection, expiration, rotation, metadata hygiene, eventing, and recovery readiness without exposing secret values. | Raishin/vanguard-frontier-agentic |
| #20 | > Agent for azure-landing-zone-architect. Design or review Azure landing-zone architecture across management groups, subscriptions, governance, security, networking, and operations dependencies. | Raishin/vanguard-frontier-agentic |
| #21 | > Agent for `azure-live-aks-rollout-guard`. Guard AKS deployment rollouts with PDB audit, maxUnavailable and surge check, and explicit pause-before-proceed or undo gate before advancing. | Raishin/vanguard-frontier-agentic |
| #22 | > Agent for `salesforce-hyperforce-security-agent`. Reviews Hyperforce deployment security posture, data residency commitments, shared responsibility boundaries, and edge network hardening controls. | Raishin/vanguard-frontier-agentic |
| #23 | > Maestro agent for the Salesforce domain. Classifies an incoming Salesforce > matter, routes it to the right Salesforce specialist agent(s), and coordinates > cross-functional review with Compliance, Privacy, Security, Architecture, and > business stakeholders. Classification… | Raishin/vanguard-frontier-agentic |
| #24 | > Agent for `salesforce-session-governance-agent`. Reviews Salesforce session security settings, High Assurance session requirements, OAuth session policies, Connected App session controls, and session hijacking risks from long-lived tokens. | Raishin/vanguard-frontier-agentic |
| #25 | Guard live AKS deployment rollouts with PDB audit, maxUnavailable/surge validation, rollout pause/undo gates, and post-rollout health verification. | Raishin/vanguard-frontier-agentic |