ansible-automation-eng…
Ansible automation: playbooks, roles, collections, Molecule testing, Vault security.
Proactive threat identification methodology. Use when reviewing code that handles authentication, authorization, data storage, or external communication.
$ npx -y skills add notque/vexjoy-agent --agent claude-codeHow it fires
How this agent gets triggered: by you, by Claude, or both.
Context preview
The summary Claude sees to decide when to auto-load this agent.
Proactive threat identification methodology. Use when reviewing code that handles authentication, authorization, data storage, or external communication.
Proactive threat identification methodology. Use when reviewing code that handles authentication, authorization, data storage, or external communication.
For each component or data flow, check all 6 categories:
| Check | What to Look For | |-------|-----------------| | Authentication bypass | Missing auth on endpoints, default credentials | | Token forgery | Weak JWT signing, no signature verification | | Session hijacking | Session IDs in URLs, missing secure/httponly flags | | Certificate spoofing | Missing TLS validation, self-signed cert acceptance |
| Check | What to Look For | |-------|-----------------| | Input manipulation | Missing validation on bodies, params, headers | | Database tampering | SQL injection, mass assignment, unparameterized queries | | File tampering | Path traversal, arbitrary file write, symlink attacks | | Message tampering | Missing HMAC/signature on webhooks |
| Check | What to Look For | |-------|-----------------| | Missing audit logs | State-changing ops without who/what/when | | Log tampering | Logs writable by app user, no integrity checks | | Unsigned transactions | Financial/permission changes without audit trail | | Missing request IDs | No correlation ID across services |
| Check | What to Look For | |-------|-----------------| | Error message leakage | Stack traces, SQL errors, internal paths | | Verbose logging | PII, tokens, passwords in logs | | Insecure storage | Plaintext passwords, unencrypted PII at rest | | Side channels | Timing differences in auth | | Directory listing | Exposed .git/, .env, backup files |
| Check | What to Look For | |-------|-----------------| | Resource exhaustion | Unbounded queries, missing pagination, no size limits | | Algorithmic complexity | ReDoS, quadratic parsing, hash collision attacks | | Connection exhaustion | Missing pool limits, no timeouts on external calls | | Storage exhaustion | Unbounded uploads, log flooding, cache poisoning |
| Check | What to Look For | |-------|-----------------| | Broken access control | IDOR, missing ownership checks | | Role escalation | User modifies own role, missing role validation | | Privilege inheritance | Child resources inheriting permissions incorrectly | | Default permissions | New resources with overly permissive defaults |
Threat: [description] Category: [S/T/R/I/D/E] Asset: [what's at risk] Attack Vector: [exploitation method] Impact: [1-5] Likelihood: [1-5] Risk Score: Impact x Likelihood [1-25] Mitigation: [specific fix]
| Score | Classification | Action | |-------|---------------|--------| | 15-25 | Critical | Block PR, fix immediately | | 10-14 | High | Fix before merge | | 5-9 | Medium | Track, fix in next sprint | | 1-4 | Low | Accept or defer |
Essays and writing behind this toolkit live at vexjoy.com. VexJoy Agent connects plain-English requests to specialist agents, skills, and workflows. /do selects the knowledge and tools needed for your task.
Repo: notque/vexjoy-agent
Ansible automation: playbooks, roles, collections, Molecule testing, Vault security.
**Scope**: Module selection patterns, builtin vs command/shell decisions, collection modules, and version-specific module changes **Version range**:…
**Scope**: Molecule test scenarios, ansible-lint rules, idempotency validation, and check-mode patterns **Version range**: Molecule 6.0+ / ansible-lint 6.0+ /…
Universal rules injected by /do at dispatch. Each agent's .md file supplies domain rules.
**Scope**: Failure modes in agent output style — over-reporting, self-congratulation, verbose narration, and hedging. Covers what to detect and how to fix…
Zero-dependency combat visual upgrades: CSS particle replacement, Framer Motion combat juice, CSS 3D card transforms.