安全

安全扫描与漏洞检测

显示 1057-1080 / 共 2332 个技能
yoanbernabeu

supabase-audit-rpc

yoanbernabeu

List and test exposed PostgreSQL RPC functions for security issues and potential RLS bypass.

代码评审 67 7个月前
yoanbernabeu

supabase-evidence

yoanbernabeu

Initialize and manage the evidence collection directory for professional security audits with documented proof of findings.

代码评审 67 7个月前
nahisaho

code-reviewer

nahisaho

Copilot agent that assists with comprehensive code review focusing on code quality, SOLID principles, security, performance, and best practices Trigger terms: code review, review code, code quality, best practices, SOLID principles, code smells, refactoring suggestions, code analysis, static analysis Use when: User requests involve code reviewer tasks.

认证鉴权 72 9个月前
nahisaho

security-auditor

nahisaho

security-auditor skill Trigger terms: security audit, vulnerability scan, OWASP, security analysis, penetration testing, security review, threat modeling, security best practices, CVE Use when: User requests involve security auditor tasks.

数据库 72 9个月前
nahisaho

design-reviewer

nahisaho

Copilot agent that assists with systematic design review using ATAM (Architecture Tradeoff Analysis Method), SOLID principles, design patterns, coupling/cohesion analysis, error handling, and security requirements Trigger terms: design review, architecture review, ATAM, SOLID principles, design patterns, coupling, cohesion, ADR review, C4 review, architecture analysis, design quality Use when: User requests involve design document review, architecture evaluation, or design quality assessment tasks.

代码评审 72 8个月前
sergiodxa

owasp-security-check

sergiodxa

Security audit guidelines for web applications and REST APIs based on OWASP Top 10 and web security best practices. Use when checking code for vulnerabilities, reviewing auth/authz, auditing APIs, or before production deployment.

认证鉴权 91 7个月前
shaniidev

bug-reaper

shaniidev

"Web2 bug bounty hunting agent — evidence-based vulnerability finder and report writer. Use when: auditing web apps/APIs for HackerOne, Bugcrowd, Intigriti, YesWeHack; hunting XSS, SQLi, NoSQLi, SSRF, IDOR, auth bypass, RCE, SSTI, LFI, XXE, CORS, CSRF, prototype pollution, subdomain takeover, HTTP smuggling, open redirect, API/GraphQL bugs; auditing locally downloaded GitHub repos or source code (white-box/source code review); writing platform-specific reports. Trigger on: 'pentest', 'find bugs', 'security audit', 'bug bounty', 'find vulnerabilities', 'source code review', 'audit this repo', 'review repo', 'white-box', 'local repo', vulnerability class names, or program/target names. Reports only real, confirmed medium+ severity bugs that pass real triage."

API 开发 67 6个月前
LaravelDaily

technical-debt-manager-php-laravel

LaravelDaily

Expert technical debt analyst for PHP/Laravel code health, maintainability, and strategic refactoring planning. Use PROACTIVELY when a Laravel codebase shows complexity growth, when planning sprints, or when prioritizing engineering work.

代码评审 48 6个月前
third774

adversarial-code-review

third774

Review code through hostile perspectives to find bugs, security issues, and unintended consequences the author missed. Use when reviewing PRs, auditing codebases, or before critical deployments.

代码评审 5 7个月前
skyosev

security-hunter-ts

skyosev

Audit TypeScript code for security vulnerabilities — hardcoded secrets, injection risks, missing input validation at trust boundaries, insecure defaults, auth gaps, sensitive data exposure, and unsafe patterns like eval or innerHTML. Use when: reviewing TypeScript code before deployment, auditing trust boundaries, preparing for a security review, onboarding third-party integrations, or hardening an application.

认证鉴权 5 6个月前
skyosev

simplicity-hunter-go

skyosev

Audit Go code for unnecessary structural complexity — duplication, avoidable abstractions, dead logic paths, over-parameterized APIs, deep nesting, interface pollution, channel misuse, and mixed concerns. Recommends the simplest shape that preserves intended behavior. Use when: reviewing Go code for over-engineering, reducing complexity after prototyping, enforcing reuse over addition, or simplifying before a refactor.

文件操作 5 6个月前
aihxp

godpowers

aihxp

AI-powered development system that takes a project from raw idea to hardened production. Fuses artifact discipline, execution engine, quality enforcement, and team intelligence into one unified workflow. Triggers on: "god mode", "god init", "god prd", "god arch", "god roadmap", "god stack", "god repo", "god build", "god deploy", "god observe", "god launch", "god harden", "god status", "god audit", "god debug", "god review", "god smite", "godpowers", "start a project", "build this", "ship this", "take this from idea to production", "one-shot the whole thing", "autonomous build", "full arc", "idea to deploy"

安全 5 3个月前
skyosev

security-hunter-go

skyosev

Audit Go code for security vulnerabilities — hardcoded secrets, injection risks (SQL, command, template, path), missing input validation at trust boundaries, insecure defaults, auth gaps, sensitive data exposure, unsafe package usage, and weak crypto. Use when: reviewing Go code before deployment, auditing trust boundaries, preparing for a security review, onboarding third-party integrations, or hardening an application.

认证鉴权 5 6个月前
skyosev

simplicity-hunter-ts

skyosev

Audit TypeScript code for unnecessary structural complexity — duplication, avoidable abstractions, dead logic paths, flag-heavy APIs, deep nesting, and mixed concerns. Recommends the simplest shape that preserves intended behavior. Use when: reviewing TypeScript code for over-engineering, reducing complexity after prototyping, enforcing reuse over addition, or simplifying before a refactor.

文件操作 5 6个月前
acedergren

best-practices

acedergren

Use when architecting OCI solutions, migrating from AWS/Azure, designing multi-AD deployments, or avoiding common OCI anti-patterns. Covers VCN sizing mistakes, Cloud Guard gotchas, free tier specifics, OCI terminology confusion, and multi-AD patterns.

云服务 19 7个月前
AIDotNet

security-scanner

AIDotNet

全面的安全分析,识别OWASP Top 10漏洞、检测硬编码密钥和审查安全配置。

数据库 83 7个月前
AIDotNet

port-scanner

AIDotNet

扫描网络端口以检查可用性和检测运行的服务。

CLI 工具 83 7个月前
jgtolentino

audit-skill

jgtolentino

Comprehensive audit capabilities for security, code quality, module structure, compliance, and performance analysis. Use this skill when performing security audits, code reviews, vulnerability assessments, module structure validation, or generating audit reports.

代码评审 22 10个月前
Salesably

multithread-outreach

Salesably

Creates role-specific messages for multiple stakeholders in a deal. Use this skill when engaging additional contacts, following up with people who weren't on calls, or executing account-based selling strategies.

邮件 48 8个月前
yoanbernabeu

supabase-extract-anon-key

yoanbernabeu

Extract the Supabase anon/public API key from client-side code. This key is expected in client apps but important for RLS testing.

数据处理 67 7个月前
Flux-Point-Studios

aiken-dex-security-audit

Flux-Point-Studios

Adversarial security audit playbook for Plutus V3 Aiken DEX contracts (threat model, invariants, findings, tests, tx repro shapes).

分析 8 7个月前
Flux-Point-Studios

aiken-dex-security-audit-operator

Flux-Point-Studios

"Operator skill: run local Aiken build/test commands and capture evidence for the audit. Manual invoke only."

代码评审 8 7个月前
maxnorm

magento-security-analyst

maxnorm

Conducts comprehensive Magento 2 security assessments and implements security measures. Use when auditing security, identifying vulnerabilities, implementing security controls, or ensuring compliance. Masters security auditing, vulnerability management, and compliance frameworks.

数据处理 28 7个月前
duongductrong

backend-development

duongductrong

Build robust backend systems with modern technologies (Node.js, Python, Go, Rust), frameworks (NestJS, FastAPI, Django), databases (PostgreSQL, MongoDB, Redis), APIs (REST, GraphQL, gRPC), authentication (OAuth 2.1, JWT), testing strategies, security best practices (OWASP Top 10), performance optimization, scalability patterns (microservices, caching, sharding), DevOps practices (Docker, Kubernetes, CI/CD), and monitoring. Use when designing APIs, implementing authentication, optimizing database queries, setting up CI/CD pipelines, handling security vulnerabilities, building microservices, or developing production-ready backend systems.

API 开发 21 9个月前