Automate the setup and optimization of Semgrep, SonarQube, and CodeQL for high-signal security testing.
LocoLoboZ
I design and publish skills built from real professional practice across three areas: cyber security consulting, business operations, and AI workflow engineering. My cyber security skills draw on active advisory work spanning governance, risk, compliance, assurance, and executive reporting. They are built for practitioners who need structured, defensible outputs - not generic templates. My business operations skills cover the day-to-day work of running a consulting practice: bookkeeping, financial tracking, expense reconciliation, and marketing content - designed to reduce repetitive overhead and keep outputs consistent. My AI platform and workflow skills are built for people who want to get more out of Claude and similar platforms - covering prompt engineering, skill architecture, automation pipelines, and agent enhancement. Every skill I publish has been tested in production use before it reaches the marketplace. If it is here, it works.
Skills by LocoLoboZ (48)
Turn business inputs into evidence-based content strategies, SEO topical maps, and buyer journey frameworks.
A structured governance auditor to optimize AI project instructions, clean up context, and manage workspace health.
Rigorous academic and internal research verification to score idea novelty and identify prior work.
Turn daily activity and workspace evidence into structured Markdown summaries and portable HTML reports.
Turn messy inboxes into prioritized action lists, follow-up trackers, and professional draft replies.
Build safety-first, framework-aligned incident response playbooks for ICS, SCADA, and OT environments.
Automate Google NotebookLM research workflows, source ingestion, and study material generation via CLI and Python.
Perform evidence-based security assessments and compliance audits for SCADA/HMI systems in OT environments.
Design and analyze industrial control system anomaly detection logic for safe, protocol-aware OT security monitoring.
Generate structured, scored attack trees with AND/OR logic to visualize threat paths and identify security gaps.
Design and govern authorized spearphishing simulations with professional reporting and stakeholder alignment.
Design, facilitate, and document professional security incident response tabletop exercises and after-action reports.
Build structured, tool-agnostic ransomware incident response playbooks tailored to your SOC and organizational context.
Professional-grade orchestration for ransomware triage, containment, recovery planning, and executive reporting.
End-to-end management of authorized phishing simulations, from safe content design to executive reporting.
Orchestrate independent reviews, adversarial audits, and multimodal analysis via secondary models and external tools.
Architect sophisticated Make (Integromat) scenarios with structured module sequences, routing logic, and error handling.
Expert technical configuration and data mapping for Make.com modules, IML expressions, and automation logic.
A technical reference and troubleshooting expert for connecting Make.com scenarios to MCP-compatible AI agents.
Standardize and validate Make API shell scenarios and connection workflows for reusable SaaS integrations.
Professional academic citation formatting and auditing specializing in APA 7, IEEE, and AGLC styles.
A proactive governance layer that validates MCP tool intent and scope to ensure safe, compliant agent behavior.
Automate information security assessments and drafting for procurement contracts, RFPs, and supplier agreements.
Draft, update, and convert professional Functional Requirements Specifications (FRS) for procurement and GRC.
Expert security assessment for industrial control systems, HMIs, and OT environments based on technical evidence.
Professional-grade security assessment framework for IoT, OT, and connected device ecosystems.
Design and validate IEC 62443-compliant security zones and conduits for industrial (OT) networks.
Professional drafting and review of cyber security risk reports, mapping evidence to compliance frameworks.
Transform complex cyber security risks, audit findings, and meeting notes into executive-grade business communications.
Transform raw incident logs and evidence into professional, tool-agnostic IR dashboards and executive reporting packs.
Professional network forensics and packet analysis for incident response and security investigations.
Plan, collect, and synthesize lawful defensive intelligence into structured exposure reports and investigation briefs.
Transform raw vulnerability data into compliant remediation reports, ageing registers, and executive dashboards.
Transform incident timelines into structured Cyber Kill Chain mappings and high-impact defensive roadmaps.
Convert SOPs and checklists into configuration-ready BMC Remedy Service Request and Work Order design documents.
Professional CTI analysis skill for structured attribution using ACH, Diamond Model, and confidence scoring.
Transform CTI reports into structured attack pattern libraries mapped to MITRE ATT&CK for threat-informed defense.
Transform APT threat intelligence into MITRE ATT&CK Navigator layers and prioritized detection gap analyses.
Design, govern, and report on enterprise-grade anti-phishing training programs and simulation metrics.
Build, review, and automate structured incident response playbooks for enterprise security operations.
Convert cyber incident evidence into blameless post-mortem reports, root cause analyses, and action trackers.
Generate audit-ready privacy impact assessments, risk registers, and data flow maps for regulatory compliance.
Professional security incident triage for SOC teams to classify alerts, assess severity, and draft response plans.
Automate weekly receipt reconciliation, bank matching, and Zoho Books posting with strict safety gates.
Automate the ingestion, indexing, and maintenance of a dual-vault Obsidian knowledge base with strict traceability.
Transform technical cyber intel into executive-ready whitepapers, one-pagers, and advisory briefs.
Transform raw security evidence into professional Cyber Healthcheck reports, RAG scorecards, and remediation roadmaps.















































