安全
安全扫描与漏洞检测
mapbox-token-security
mapbox
Security best practices for Mapbox access tokens, including scope management, URL restrictions, rotation strategies, and protecting sensitive data. Use when creating, managing, or advising on Mapbox token security.
secure-coding
baz-scm
Incorporating security at every step of software development – writing code that defends against vulnerabilities and protects user data.
discover
AsiaOstrich
"[UDS] Assess project health, architecture, and risks before adding features"
changelog
AsiaOstrich
"[UDS] Generate and maintain CHANGELOG.md entries"
team-uidesign
catlog22
Unified team skill for UI design team. All roles invoke this skill with --role arg for role-specific execution. CP-9 Dual-Track design+implementation.
security-flutter
TheBeardedBearSAS
Flutter Security. Use when reviewing security, implementing auth, or hardening code.
security-react
TheBeardedBearSAS
React Security. Use when reviewing security, implementing auth, or hardening code.
spring-boot-security-jwt
giuseppe-trisciuoglio
Provides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based access control using Spring Security 6.x. Use when implementing authentication or authorization in Spring Boot applications.
threat-model-generation
Factory-AI
Generate a STRIDE-based security threat model for a repository. Use when setting up security monitoring, after architecture changes, or for security audits.
vulnerability-validation
Factory-AI
Validate security findings from commit-security-scan by assessing exploitability, filtering false positives, and generating proof-of-concept exploits. Use after running commit-security-scan to confirm vulnerabilities.
security-auditor
zhaono1
Security vulnerability expert covering OWASP Top 10 and common security issues. Use when conducting security audits or reviewing code for vulnerabilities.
code-reviewer
zhaono1
Reviews pull requests and code changes for quality, security, and best practices. Use when user asks for code review, PR review, or mentions reviewing changes.
competitor-scan
WellApp-ai
Research best-in-class products using Browser MCP and WebSearch
tool-ast-grep-rules
Heyvhuang
'Write AST-based code search and rewrite rules using ast-grep YAML. Create linting rules, code modernizations, and API migrations with auto-fix. Use when the user mentions ast-grep, tree-sitter patterns, code search rules, lint rules with YAML, AST matching, or code refactoring patterns.'
mcp-cloudflare
Heyvhuang
"Manage Workers/KV/R2/D1/Hyperdrive via Cloudflare MCP, perform observability/build troubleshooting/audit/container sandbox operations. Triggers: worker/KV/R2/D1/logs/build/deploy/screenshot/audit/sandbox. Three permission tiers: Diagnose (read-only), Change (write requires confirmation), Super Admin (isolated environment). Write operations must follow read-first, user confirmation, post-execution verification."
cloudflare
Heyvhuang
"Infrastructure operations for Cloudflare: Workers, KV, R2, D1, Hyperdrive, observability, builds, audit logs. Triggers: worker/KV/R2/D1/logs/build/deploy/audit. Three permission tiers: Diagnose (read-only), Change (write requires confirmation), Super Admin (isolated environment). Write operations follow read-first, confirm, execute, verify pattern. MCP is optional — works with Wrangler CLI/Dashboard too."
Canon
simota
ä¸çæ¨æºã»æ¥çæ¨æºã§ç©äºã解決ãã調æ»ã»åæã¨ã¼ã¸ã§ã³ããOWASP/WCAG/OpenAPI/ISO 25010çã®æ¨æºã¸ã®æºæ 度è©ä¾¡ãæ¨æºé忤åºãæ¹åææ¡ãæ å½ãæ¨æºæºæ è©ä¾¡ãè¦æ ¼é©ç¨ãå¿ è¦ãªæã«ä½¿ç¨ã
backend-dev-suite
Leavesfly
后端开发综合技能包(Java 编码 + 数据库设计 + 安全加固)
aws-cost-operations
CommandCodeAI
This skill provides AWS cost optimization, monitoring, and operational best practices with integrated MCP servers for billing analysis, cost estimation, observability, and security assessment.
ad-persistence
blacklanternsecurity
Establishes persistent access in Active Directory environments after domain compromise. Covers DCShadow (rogue DC attribute modification), Skeleton Key (LSASS master password), custom SSP injection (credential logging via mimilib/memssp), security descriptor backdoors (WMI/WinRM/ DCOM/registry ACL modification), ADFS Golden SAML (DKM key extraction and forged SAML tokens), SID history persistence (DA SID in regular user), and certificate-based persistence (golden certificate, renewal, enrollment agent).
k8s-security-policies
HermeticOrmus
Implement Kubernetes security policies including NetworkPolicy, PodSecurityPolicy, and RBAC for production-grade security. Use when securing Kubernetes clusters, implementing network isolation, or enforcing pod security standards.
ai-code-review
sundial-org
Top OpenClaw skills, with the most popular and useful ones.
a11y-checker
sundial-org
Scan HTML and JSX for accessibility issues with AI-powered fix suggestions
reconciliation
JoelLewis
"Reconciliation operations: position/cash/transaction matching with tolerance thresholds, three-way reconciliation (PMS/custodian/clearing), break identification (timing, pricing, corporate action, stock split/merger/DRIP), tolerance rules, STP rates (95-99% position, 85-95% transaction), auto-resolution, cost basis and tax lot matching, accrued income reconciliation, multi-custodian data normalization (Schwab, Fidelity, Pershing), ex-date processing, custodian feed formats, reconciliation scheduling, regulatory compliance (SEC Rule 204-2, ERISA, SOC 1/SOC 2, books and records), 1099-B accuracy, reconciliation automation platforms (Arcesium, Duco, Advent Geneva)."