ITIL / CAB
Change Request Writer
Turn a plain-English change summary into a CAB-ready change record with 5x5 risk score, rollback plan, stakeholder email, and pre-flight checklist.
/change-request-writerProduces change record
NIST 800-61
Incident Responder
Walk through a live or recent incident. Produces timeline, 5-whys root cause, customer-facing statement, executive one-pager, and remediation plan with owners.
/incident-responderProduces PIR report
CIS / Hardening
Config Auditor
Paste a Cisco / Juniper / Fortinet / Aruba / Palo Alto / MikroTik config. Get findings ranked by severity, remediation commands, and compliance mapping to CIS and NIST.
/config-auditorProduces audit report
Operations
Runbook Generator
Describe a procedure the way you'd explain it to a new hire. Get back a runbook with prerequisites, role-tagged steps, rollback, verification, escalation, and known gotchas.
/runbook-generatorProduces operational runbook
Architecture
Network Documenter
Describe your network the way you'd whiteboard it. Get site summaries, addressing plan, VLAN table, device inventory, topology narrative, and a diagram brief.
/network-documenterProduces documentation pack
Procurement
Vendor Evaluator
Structured, weighted selection scorecard. Transparent scoring, per-vendor strengths / weaknesses, 3-year TCO comparison, risk matrix, and board-ready recommendation memo.
/vendor-evaluatorProduces evaluation pack
ISO 31000 / RMF
Risk Assessor
Produces a formal risk register entry: L x I scoring, inherent vs residual, treatment plan with owners and dates, KRIs, review cadence, and a board paper summary paragraph.
/risk-assessorProduces register entry
HR / IT joiners
Onboarding Builder
Tailored new-hire IT pack: pre-arrival through 90-day review, access matrix with segregation of duties, equipment list, statutory training, and an offboarding preview.
/onboarding-builderProduces onboarding pack
Blameless PIR
Post-Mortem Facilitator
Turns a messy Slack thread into a blameless post-mortem with 5-whys, contributing factors, an honest "where we got lucky" section, and testable action items.
/post-mortem-facilitatorProduces blameless PIR
Live incident
Outage Comms Writer
Drafts synchronised internal, customer, and status-page messages during a live incident. Tone-matched to severity, factual under pressure, with cadence plan.
/outage-comms-writerProduces 3-channel comms pack
Fleet change
Firmware Upgrade Planner
Wave-by-wave upgrade plan with risk ordering, maintenance windows, per-device procedure, rollback, verification, and a CAB-ready change record.
/firmware-upgrade-plannerProduces fleet upgrade plan
Governance
CAB Minute Taker
Turns raw CAB meeting notes into governance-grade minutes with per-RFC decisions, dissent, conditions, actions register, and a circulation email.
/cab-minute-takerProduces CAB minutes
BCP / DR
DR Test Planner
Designs a disaster recovery test: scope, scenario, injects, observer briefs, safety rules, success criteria, and a post-test improvement backlog framework.
/dr-test-plannerProduces DR test plan
Monthly / quarterly
SLA Reporter
Monthly service report with KPI dashboard, incident summary, trend commentary, SLA credit statement, forward risks, and an executive one-pager.
/sla-reporterProduces service report
ISO / SOC 2
Access Review
Periodic access certification pack: scope, sampling plan, per-reviewer worksheets, exception register, SoD checks, and an audit-ready evidence bundle.
/access-reviewProduces review pack
Policy
Security Policy Drafter
Writes governance-ready policy docs: AUP, password, BYOD, remote work, classification, AI use. Testable requirements, exceptions flow, enforcement, review cycle.
/security-policy-drafterProduces policy document
Budget cycle
Capacity Review
Capacity planning memo: utilisation snapshot, 3-scenario projection, do-nothing vs scale vs replace, named recommendation, and a budget ask with cost anchors.
/capacity-reviewProduces capacity memo
Vendor mgmt
Supplier Review Meeting
Annual vendor review pack: pre-meeting brief, agenda, weighted scorecard, issues + wins log, negotiation playbook with counters, and a decision record template.
/supplier-review-meetingProduces review pack
Segmentation
VLAN Designer
Designs a VLAN scheme from plain-English site description: numbering convention, inter-VLAN policy matrix, trunk matrix, IPv6-ready addressing, per-vendor snippets.
/vlan-designerProduces VLAN design doc
Wireless
Wi-Fi Survey Brief
Produces a survey scope for a wireless audit or deployment: coverage + density + roaming goals, SSID schedule, deliverable format, day-of checklist, RFQ evaluation criteria.
/wifi-survey-briefProduces survey brief
FinOps
Cloud Cost Reviewer
Monthly cloud + SaaS cost report with KPI dashboard, per-service breakdown, anomaly findings, optimisation backlog with quantified savings, and an exec summary.
/cloud-cost-reviewerProduces cost report
NIST 800-207
Zero Trust Assessor
ZTA gap analysis across 6 pillars (identity, device, network, app, data, infra). Maturity scorecard, prioritised roadmap with cost bands, dependencies map, exec summary.
/zero-trust-assessorProduces ZTA assessment
SaaS sprawl
SaaS Spend Auditor
Audit of SaaS spend with shadow-IT register, licence-utilisation gaps, contract risk, consolidation opportunities, and a quantified savings backlog. Built for the budget cycle.
/saas-spend-auditorProduces audit + savings backlog
Architecture
Architecture Decision Recorder
Generates a properly structured ADR (Michael Nygard format): context, decision drivers, options scored, decision, consequences, revisit triggers. Ready to commit to docs/adr/.
/architecture-decision-recorderProduces ADR
Tabletop / BCP
Post-Tabletop Debrief
Turn raw tabletop notes into a structured debrief: timeline, gaps by domain, action register with owners + success criteria, risk register update, recommended next exercise.
/post-tabletop-debriefProduces tabletop debrief
CVE response
CVE Triage
Paste a CVE + vendor bulletin → patch priority (P0/P1/P2/P3), estate impact, targeted runbook, mitigations, comms, rollback, verification checklist. Uses CISA KEV + EPSS signals.
/cve-triageProduces patch decision pack
Ruleset review
Firewall Rule Deduplicator
Paste a firewall ruleset → shadowed / redundant / overly-broad / aliasable / unused rules with per-rule remediation and a prioritised cleanup backlog. Cisco / PA / Fortinet / CP / AWS SG / iptables.
/firewall-rule-deduplicatorProduces cleanup backlog
Change evidence
Config Diff
Semantic diff of two network configs. Ignores trivial ordering and whitespace. Groups changes by intent, flags high-risk deltas, gives a rollback bundle. Cisco / Juniper / PA / Fortinet / Aruba / MikroTik.
/config-diffProduces change-verification report
PKI audit
Cert Expiry Audit
Paste a cert inventory or scanner output → P0/P1/P2/P3 renewal backlog, weak-crypto flags, missing-owner prompts, comms drafts, monthly metrics. Stops 01:30 Saturday pages.
/cert-expiry-auditProduces renewal backlog
Detection engineering
SIEM Rule Writer
Describe a detection in English → production-ready rules in KQL, SPL, Elastic EQL/DSL, Sumo Logic, Chronicle YARA-L. With MITRE ATT&CK mapping, noise assessment, and test cases.
/siem-rule-writerProduces multi-SIEM rules
Layered diagnostics
Network Triage
Describe a symptom ("VPN tunnel flaps every 20 min") → ranked hypotheses, ordered diagnostic commands, decision tree, escalation path, data-capture list for post-incident review.
/network-triageProduces investigation plan
Routing
BGP Troubleshooter
Paste BGP state + logs → ranked diagnosis (peer-down, flap, missing routes, wrong path, leak/hijack) with vendor-specific fix commands for Cisco / Juniper / FRR / Arista / BIRD / MikroTik.
/bgp-troubleshooterProduces diagnosis + fix
Design review
Threat Model Builder
Describe a system in English → STRIDE threat model with data flow diagram, threats per element, ranked mitigations, residual risks, and a pen-tester validation checklist.
/threat-model-builderProduces STRIDE model
Programme planning
Migration Planner
Source → target migration plan (ASA → PA, AD → Entra, Splunk → Sentinel, vSphere → AWS, etc.) with feature mapping, waves, rollback gates, risk register and comms calendar.
/migration-plannerProduces phased migration plan
Tabletop / BCP
Tabletop Scenario Generator
Generate a fresh tabletop scenario on demand: narrative, timed injects, decision points, facilitator script, participant briefing, AAR prompts. Cyber / outage / data loss / supplier / physical themes.
/tabletop-scenario-generatorProduces exercise pack