安全

安全扫描与漏洞检测

用途与选择建议

这类技能用于检查正确性、安全性和运行表现。优先选择能够说明判断依据并提供可复现验证的工作流,再将结果与项目约定及实际测量基线对照。

显示 1-24 / 共 2316 个技能
TencentBlueKing

蓝鲸代码安全三大红线

TencentBlueKing

基于 IEG 安全规范,覆盖输入校验、鉴权、数据加密三大高危领域

安全 840 7个月前
TencentBlueKing

Node.js 安全审查

TencentBlueKing

检查 RCE、SSRF、SQL 注入、路径穿越等安全问题,支持 Express/Koa/NestJS

安全 840 7个月前
TencentBlueKing

Web 安全漏洞学习指南

TencentBlueKing

OWASP 十大漏洞原理、影响与修复方案,覆盖 Python/Java 场景

安全 840 7个月前
TencentBlueKing

JavaScript 安全审查

TencentBlueKing

检查 XSS、CSRF、原型污染等安全问题,支持 React/Vue/Angular

安全 840 7个月前
dadbodgeoff

audit-logging

dadbodgeoff

Comprehensive audit logging for compliance and security. Track user actions, data changes, and system events with tamper-proof storage.

安全 784 6个月前
dadbodgeoff

error-sanitization

dadbodgeoff

Production-safe error handling that logs full details server-side while exposing only generic, safe messages to users. Prevents information leakage of database strings, file paths, stack traces, and API keys.

安全 784 6个月前
dadbodgeoff

file-uploads

dadbodgeoff

Production-grade secure file upload pipeline with multi-stage validation, malware scanning (ClamAV), hash-based duplicate detection, and race condition protection using distributed locks.

安全 784 6个月前
Leavesfly

security-checklist

Leavesfly

OWASP 安全检查清单

安全 235 9个月前
markus41

code-review

markus41

Comprehensive code review knowledge including security, performance, accessibility, and quality standards across multiple languages and frameworks

无障碍 20 8个月前
rohitg00

k8s-policy

rohitg00

Kubernetes policy management with Kyverno and Gatekeeper. Use when enforcing security policies, validating resources, or auditing policy compliance.

安全 955 7个月前
rohitg00

k8s-certs

rohitg00

Kubernetes certificate management with cert-manager. Use when managing TLS certificates, configuring issuers, or troubleshooting certificate issues.

安全 955 7个月前
rohitg00

k8s-security

rohitg00

Audit Kubernetes RBAC, enforce policies, and manage secrets. Use for security reviews, permission audits, policy enforcement with Kyverno/Gatekeeper, and secret management.

安全 955 7个月前
HacktronAI

ctf-solver

HacktronAI

Solve CTF (Capture The Flag) challenges by analyzing challenge descriptions, source code, and interacting with challenge environments to capture flags.

安全 112 8个月前
HacktronAI

waf-bypass-hunter

HacktronAI

Bypass a Coraza WAF protecting a vulnerable Next.js 16 backend. Analyze parser differentials between Go (WAF) and Node.js (backend) to find bypasses.

安全 112 8个月前
williamzujkowski

api-security

williamzujkowski

Broken Object Level Authorization (BOLA) - API fails to validate user

安全 17 8个月前
handnewb

cybersecurity-lab

handnewb

Turnkey cybersecurity lab — 2,077 skills, 131+ tools, 28 frameworks, and evolving methodology for security research, pentesting, forensics, and threat intelligence. Includes one-step ecosystem cloner for 8 repositories.

安全 9 27天前
UseAI-pro

config-hardener

UseAI-pro

"Audit and harden your OpenClaw configuration. Checks AGENTS.md, gateway settings, sandbox config, and permission policies for security weaknesses."

安全 71 7个月前
UseAI-pro

setup-auditor

UseAI-pro

"Audit your OpenClaw environment for credential leaks, unsafe defaults, and missing sandbox configuration. Wizard-style: answers questions about your setup and produces a fix checklist."

安全 71 7个月前
UseAI-pro

credential-scanner

UseAI-pro

"Scan your project for exposed credentials, API keys, and secrets before running OpenClaw skills. Prevents accidental exfiltration."

安全 71 7个月前
UseAI-pro

skill-auditor

UseAI-pro

"Comprehensive security auditor for OpenClaw skills. Checks for typosquatting, dangerous permissions, prompt injection, supply chain risks, and data exfiltration patterns — before you install anything."

安全 71 7个月前
UseAI-pro

skill-guard

UseAI-pro

"Runtime security monitor for active OpenClaw skills. Watches file access, network calls, and shell commands. Flags anomalous behavior and enforces permission boundaries."

安全 71 7个月前
UseAI-pro

prompt-guard

UseAI-pro

"Detect and neutralize prompt injection attacks in OpenClaw skill content, user inputs, and external data sources. Prevents instruction hijacking and context manipulation."

安全 71 7个月前
UseAI-pro

permission-auditor

UseAI-pro

"Analyze OpenClaw skill permissions and explain exactly what each permission allows. Identifies over-privileged skills and suggests minimal permission sets."

安全 71 7个月前
UseAI-pro

incident-responder

UseAI-pro

"Step-by-step incident response for OpenClaw security breaches. Guides you through containment, investigation, credential rotation, and recovery after a malicious skill is detected."

安全 71 7个月前