Public benchLIVE

What's on the bench.

5,040
Artifacts
26
Industries
82
Reads / week

All artifacts

5040
Industry
SKILL0

Writing Plans

Use when you have a spec or requirements for a multi-step task, before touching code

ai-prompt-engineering+1
0
SKILL0

Verification Before Completion

Use when about to claim work is complete, fixed, or passing, before committing or creating PRs - requires running verification commands and confirming output before making any success claims; evidence before assertions always

software-engineering+1
0
SKILL0

Using Superpowers

Use when starting any conversation - establishes how to find and use skills, requiring Skill tool invocation before ANY response including clarifying questions

software-engineering+1
0
SKILL0

Using Git Worktrees

Use when starting feature work that needs isolation from current workspace or before executing implementation plans - ensures an isolated workspace exists via native tools or git worktree fallback

software-engineering+1
0
SKILL0

Test Driven Development

Use when implementing any feature or bugfix, before writing implementation code

software-engineering+1
0
SKILL0

Systematic Debugging

Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes

software-engineering+1
0
SKILL0

Subagent Driven Development

Use when executing implementation plans with independent tasks in the current session

ai-prompt-engineering+1
0
SKILL0

Requesting Code Review

Use when completing tasks, implementing major features, or before merging to verify work meets requirements

software-engineering+1
0
SKILL0

Receiving Code Review

Use when receiving code review feedback, before implementing suggestions, especially if feedback seems unclear or technically questionable - requires technical rigor and verification, not performative agreement or blind implementation

software-engineering+1
0
SKILL0

Finishing A Development Branch

Use when implementation is complete, all tests pass, and you need to decide how to integrate the work - guides completion of development work by presenting structured options for merge, PR, or cleanup

software-engineering+1
0
SKILL0

Executing Plans

Use when you have a written implementation plan to execute in a separate session with review checkpoints

ai-prompt-engineering+1
0
SKILL0

Dispatching Parallel Agents

Use when facing 2+ independent tasks that can be worked on without shared state or sequential dependencies

software-engineering+1
0
SKILL0

Brainstorming

You MUST use this before any creative work - creating features, building components, adding functionality, or modifying behavior. Explores user intent, requirements and design before implementation.

ai-prompt-engineering+1
0
SKILL0

Validating Backup Integrity For Recovery

Validate backup integrity through cryptographic hash verification, automated restore testing, corruption detection, and recoverability checks to ensure backups are reliable for disaster recovery and ransomware response scenarios.

cybersecurity-soc
0
SKILL0

Triaging Vulnerabilities With Ssvc Framework

Triage and prioritize vulnerabilities using CISA's Stakeholder-Specific Vulnerability Categorization (SSVC) decision tree framework to produce actionable remediation priorities.

cybersecurity-soc
0
SKILL0

Triaging Security Incident With Ir Playbook

Classify and prioritize security incidents using structured IR playbooks to determine severity, assign response teams, and initiate appropriate response procedures.

cybersecurity-soc
0
SKILL0

Triaging Security Alerts In Splunk

Triages security alerts in Splunk Enterprise Security by classifying severity, investigating notable events, correlating related telemetry, and making escalation or closure decisions using SPL queries and the Incident Review dashboard. Use when SOC analysts face queued alerts from correlation searches, need to prioritize investigation order, or must document triage decisions for handoff to Tier 2/3 analysts.

cybersecurity-soc+1
0
SKILL0

Tracking Threat Actor Infrastructure

Threat actor infrastructure tracking involves monitoring and mapping adversary-controlled assets including command-and-control (C2) servers, phishing domains, exploit kit hosts, bulletproof hosting, a

cybersecurity-soc
0
SKILL0

Testing Websocket API Security

Tests WebSocket API implementations for security vulnerabilities including missing authentication on WebSocket upgrade, Cross-Site WebSocket Hijacking (CSWSH), injection attacks through WebSocket messages, insufficient input validation, denial-of-service via message flooding, and information leakage through WebSocket frames. The tester intercepts WebSocket handshakes and messages using Burp Suite, crafts malicious payloads, and tests for authorization bypass on WebSocket channels. Activates for requests involving WebSocket security testing, WS penetration testing, CSWSH attack, or real-time API security assessment.

cybersecurity-soc+1
0
SKILL0

Testing Ransomware Recovery Procedures

Test and validate ransomware recovery procedures including backup restore operations, RTO/RPO target verification, recovery sequencing, and clean restore validation to ensure organizational resilience against destructive ransomware attacks.

cybersecurity-soc
0
SKILL0

Testing Oauth2 Implementation Flaws

Tests OAuth 2.0 and OpenID Connect implementations for security flaws including authorization code interception, redirect URI manipulation, CSRF in OAuth flows, token leakage, scope escalation, and PKCE bypass. The tester evaluates the authorization server, client application, and token handling for common misconfigurations that enable account takeover or unauthorized access. Activates for requests involving OAuth security testing, OIDC vulnerability assessment, OAuth2 redirect bypass, or authorization code flow testing.

cybersecurity-soc
0
SKILL0

Testing Mobile API Authentication

Tests authentication and authorization mechanisms in mobile application APIs to identify broken authentication, insecure token management, session fixation, privilege escalation, and IDOR vulnerabilities. Use when performing API security assessments against mobile app backends, testing JWT implementations, evaluating OAuth flows, or assessing session management. Activates for requests involving mobile API auth testing, token security assessment, OAuth mobile flow testing, or API authorization bypass.

cybersecurity-soc
0
SKILL0

Testing JWT Token Security

Assessing JSON Web Token implementations for cryptographic weaknesses, algorithm confusion attacks, and authorization bypass vulnerabilities during security engagements.

cybersecurity-soc
0
SKILL0

Testing For Xxe Injection Vulnerabilities

Discovering and exploiting XML External Entity injection vulnerabilities to read server files, perform SSRF, and exfiltrate data during authorized penetration tests.

cybersecurity-soc+1
0

Want your own bench?

Free for crews of 5. Connect your team in minutes.

Sign up free