Security & privacy auditor for Flutter/Dart mobile games (iOS + Android). Use to find data leaks, insecure storage/network, hardcoded secrets, over-broad permissions (Android INTERNET/location/AD_ID, iOS usage strings), unsafe APIs, and kids-privacy violations — tracking, ads (google_mobile_ads), analytics/Crashlytics, AdvertisingId (IDFA/GAID), Firebase telemetry, external links — across BOTH Apple Kids Category and Google Play Families. Read-only: reports risks and concrete fixes, never edits.
Production-grade frontend engineering for Next.js and TypeScript against a Django/DRF backend — plan first, verify the installed versions, never invent an API, keep the diff minimal, run the checks, and hold the work to a stated definition of done. Covers routing and rendering, the server/client boundary, the React component tree, the typed backend contract, and the non-functional guarantees (accessibility, security, performance, testing) that gate completion. All twenty-four domains are integrated; the router in SKILL.md is the authoritative list of what is loadable. Canonical instructions live in SKILL.md and references/.
Security for LLM and agent systems: direct and indirect prompt injection, the OWASP Top 10 for LLM Applications, MITRE ATLAS technique mapping, excessive agency and tool-scope containment, egress allowlisting to stop data exfiltration, human confirmation for irreversible actions, and treating third-party skills and MCP servers as untrusted code. Use when an agent is given tools or credentials, when retrieved documents or repository files could carry injected instructions, or when reviewing an AI feature before it reaches production.
Review whether security-relevant logging is enabled, complete, shipped off-host, and tamper-resistant across Kubernetes and the cloud control plane. Use when user says 'review my audit logging', 'is audit logging on', 'check my k8s audit policy', 'are we logging API-server access', 'review GKE/AKS logging', 'do we capture admin activity', or when working in audit-policy.yaml, kube-apiserver manifests, or GKE/AKS Terraform. Covers generic Kubernetes audit policy, GKE Cloud Logging + audit config, AKS diagnostic settings, and cross-cloud audit-log immutability. For AWS CloudTrail/flow-log/EKS-audit/S3-access IaC use /clouddrove:tf (SEC-LOG-*); for log retention/centralization, metrics, and SLOs use /clouddrove:observability (OBS-LOG-*).
Handle a secret across its whole lifecycle — keep it out of source and image layers, inject it at runtime via environment or a secret store, scope each credential to least privilege, and rotate on a schedule and immediately after exposure. Invoke when code needs an API key, DB password, token, or private key, or when wiring how an app obtains its secrets. Complements the secret-scan hook (which only blocks committing a literal) and security-review (which only flags secrets in your diff). Skip for code that handles no credentials.
Covers how to run and FIX every quality gate in this repo — ruff (lint + format), mypy --strict, pytest with per-layer coverage, import-linter (lint-imports), bandit, and pip-audit. Use this whenever a quality gate fails locally or in CI, whenever the user asks how to lint, format, type-check, or run security scans on this codebase, or before opening a PR to run the full gate set proactively. Make sure to consult this whenever a ruff, mypy, lint-imports, or bandit error appears in tool output — it gives the exact fix command for each gate rather than requiring you to guess at generic remediation.
mappings (10min TTL). API keys are encrypted before use as cache keys for security. All cache operations fail gracefully—errors are logged but never block requests. Integrated into `deps.py
search functionality
- **Automatic Tracking**: All search operations (regular, streaming, legacy) tracked uniformly via `SearchService`
### Security
- Never use `random.*` for security-sensitive values — ruff
rule `S311` bans it
- Use `secrets.choice()`, `secrets.randbelow
useParentMessaging`)
The widget runs in an iframe and communicates with the parent via `postMessage`.
**SECURITY: Origin validation is enforced for postMessage:**
The Connect widget captures the parent origin from