安全

安全扫描与漏洞检测

显示 1081-1104 / 共 2332 个技能
ZackKorman

audit-3

ZackKorman

"Used to run an audit of a codebase."

代码评审 19 6个月前
ZackKorman

openclaw-admin-security-breakglass

ZackKorman

Run this skill to harden openclaw's security by adding an override so that the admin can always get into the bot even if the allowlist is corrupted. It effectively ensures the "breakglass" admin phone number never loses access.

Kubernetes 19 6个月前
ZackKorman

security-review-2

ZackKorman

A general skill for performing security reviews and auditing codebases for vulnerabilities. ALWAYS run this at the end of each task.

API 开发 19 7个月前
ZackKorman

security-review-3

ZackKorman

A general skill for performing security reviews and auditing codebases for vulnerabilities. ALWAYS run this at the end of each task.

API 开发 19 7个月前
ZackKorman

security-review-4

ZackKorman

A general skill for performing security reviews and auditing codebases for vulnerabilities. ALWAYS run this at the end of each task.

代码评审 19 7个月前
ZackKorman

security-review-6

ZackKorman

A general skill for performing security reviews and auditing codebases for vulnerabilities. ALWAYS run this at the end of each task.

代码评审 19 7个月前
ZackKorman

audit-2

ZackKorman

"Used to run an audit of a codebase."

代码评审 19 6个月前
ZackKorman

audit

ZackKorman

"Used to run an audit via our auditing service."

代码评审 19 7个月前
ZackKorman

security-review

ZackKorman

A general skill for performing security reviews and auditing codebases for vulnerabilities. ALWAYS run this at the end of each task.

代码评审 19 7个月前
OmniNode-ai

feature-dashboard

OmniNode-ai

Audit skill connectivity across 8 layers and surface gaps as actionable, machine-readable output. Supports audit (read-only) and ticketize (create Linear tickets for gaps) modes.

分析 3 6个月前
TheSethRose

clawdbot-self-security-audit

TheSethRose

Perform a comprehensive read-only security audit of Clawdbot's own configuration. This is a knowledge-based skill that teaches Clawdbot to identify hardening opportunities and generate reports. Use when user asks to "run security check", "audit clawdbot", "check security hardening", or "what vulnerabilities do I have". This skill only READS configuration and generates reports—it never modifies settings or executes fixes automatically. Designed to be extensible—new checks can be added by updating this skill's knowledge.

代码评审 63 7个月前
joacod

secure-node-typescript

joacod

'Write secure-by-default Node.js and TypeScript applications following security best practices. Use when: (1) Writing new Node.js/TypeScript code, (2) Creating API endpoints or middleware, (3) Handling user input or form data, (4) Implementing authentication or authorization, (5) Working with secrets or environment variables, (6) Setting up project configurations (tsconfig, eslint), (7) User mentions security concerns, (8) Reviewing code for vulnerabilities, (9) Working with file paths or child processes, (10) Setting up HTTP headers or CORS.'

调试 3 7个月前
yarlson

code-review

yarlson

This skill should be used when the user asks to "review my changes", "review this code", "check my work", "what's wrong with my changes", "review before I push", "security review", "do a code review", or mentions reviewing, auditing, or analyzing local code changes before committing or opening a PR.

代码评审 3 7个月前
alunadev

generating-changelogs

alunadev

Transforms technical git commits into polished, user-friendly changelogs. Use when preparing release notes, creating product update summaries, documenting changes for customers, or maintaining a public changelog page.

代码生成 3 7个月前
yarlson

infra-code-review

yarlson

This skill should be used when the user asks to "review my infra changes", "review my IaC", "check my infrastructure code", "review this deploy config", "review my cloud config", "review infra before I push", or mentions reviewing, auditing, or analyzing infrastructure-as-code changes — any tool, any cloud, any format.

代码评审 3 7个月前
paulund

code-reviewer

paulund

Use when reviewing code, pull requests, or auditing code quality and best practices.

代码评审 3 6个月前
dvmrry

zscaler

dvmrry

Answer questions about the Zscaler portfolio — full operational depth (Tier 1, with SDK / TF / OneAPI exposure) on ZIA, ZPA (including AppProtection inline WAF/IPS and Browser Access), ZCC (Client Connector), ZDX (Digital Experience), ZBI (Zero Trust Browser / Cloud Browser Isolation), ZIdentity (unified identity + OneAPI authentication + step-up auth), Cloud & Branch Connector (ZTW/ZTC — VM-based traffic forwarding for cloud workloads and branch offices), and ZWA (Workflow Automation — DLP incident lifecycle); plus extended awareness with reasoning docs (Tier 2a, portal-only / no SDK) on Deception (decoys/honeypots for post-perimeter detection), Risk360 (cyber risk quantification / Monte Carlo / CISO board reporting), the AI Security family (AI Guard runtime guardrails for LLM prompt-injection / jailbreak / sensitive-data / toxicity / refusal detection plus AI Red Teaming / AI Guardrails / four-pillar governance), and ZMS (workload microsegmentation east-west, host-agent + WFP/nftables enforcement); plus paragraph-level awareness (Tier 2b) of ZINS (shadow-IT NSS Collector), EASM, Federal Cloud variants, ITDR, DSPM, Posture Control, and others. Covers URL category coverage, URL filtering rule precedence, wildcard matching semantics, SSL inspection ordering, cloud app control interaction with URL filtering, DLP three-layer model, sandbox / malware / ATP, firewall filtering, ZPA app-segment matching and policy evaluation order, AppProtection profiles / paranoia levels, Browser Access wildcard certificate rules, ZCC forwarding-profile / trusted-network decisions (which decide whether traffic reaches ZIA or ZPA in the first place), ZDX score / probe / diagnostic-session questions about user experience, browser isolation (Isolate action, Smart Browser Isolation, isolation profiles), Cloud Connector provisioning and activation, and Zscaler portfolio breadth ("what is X?", "does Zscaler do Y?"). Use whenever the user mentions Zscaler, ZIA, ZPA, ZCC, ZDX, ZBI, ZWA, ZTW, ZTC, CBC, Zero Trust Browser, Cloud Browser Isolation, Client Connector, AppProtection, Browser Access, Deception, Risk360, AI Guard, AI Guardrails, AI Red Teaming, AI Security, ZMS, microsegmentation, east-west traffic, ZINS, EASM, URL categories, URL filtering, cloud app control, SSL inspection, DLP, sandbox, app segments, forwarding profiles, trusted networks, ZDX score, probes, diagnostic sessions / deeptraces, isolation profiles, prompt injection, jailbreak detection, LLM guardrails, or asks "is $URL covered / blocked / allowed". Also use for "why does this rule win", "what happens when these policies overlap", "why is this user's app slow", "what happens when traffic gets isolated", "what is $product", or "does Zscaler have something for $use-case" questions, even if the user does not explicitly name Zscaler.

API 开发 3 4个月前
tristanmanchester

audit-openclaw-security

tristanmanchester

Audit and harden OpenClaw (Gateway + agents) security. Use when the user asks to audit/secure/harden OpenClaw; when troubleshooting risky exposure (especially the Gateway web UI/control plane on port 18789); when reviewing DM/group access control (pairing/allowlists/mention-gating); tool permissions (exec/fs/browser/nodes/gateway/cron); plugins/skills supply-chain risk; secrets/transcripts/log retention; or when deploying OpenClaw on a Mac mini, personal laptop, Docker host, or cloud VM (AWS EC2/VPS).

CLI 工具 3 6个月前
OmniNode-ai

curate-legacy

OmniNode-ai

Canonicalize legacy docs, archived code, and feature ideas into a handler-first Ideas Registry with provenance, dedup, and executable specs

代码生成 3 6个月前
spm1001

github-cleanup

spm1001

Orchestrates progressive GitHub account cleanup using a 6-phase audit→approve→execute process that prevents accidental deletion. BEFORE any destructive repo action, invoke FIRST — traces Dependabot alerts to unused direct deps (prune) vs transitive-only (upgrade lock file). Triggers on 'clean up GitHub', 'audit my repos', 'Dependabot trouble', 'unused deps', 'stale forks', 'dependency audit'. Requires gh CLI. (user)

CLI 工具 3 6个月前
OmniNode-ai

gather-github-stats

OmniNode-ai

Gather GitHub repository statistics — PR counts, commit velocity, contributor activity, LOC metrics — from GitHub API and optional local archive scan

分析 3 6个月前
AntJanus

track-roadmap

AntJanus

Plan, update, and audit a high-level project roadmap. Use when asked to "create a roadmap", "plan features", "what should we build next", "update the roadmap", "audit the roadmap", "review project direction", "prioritize features", or when starting a new project and needing to map out future work.

代码生成 3 6个月前
cirra-ai

cirra-ai-sf-audit

cirra-ai

Run a comprehensive Salesforce org audit. Inventories and scores Apex classes, Apex triggers, Flows, Process Builders, Workflow Rules, LWC components, custom objects and fields, validation rules, Profiles, and Permission Sets. Generates Word, Excel, and HTML reports. Supports incremental audits that only re-score changed components. Use when asked to audit a Salesforce org, review org health, generate an org inventory, run an org health check, audit permissions, review the data model, or audit apex flows and lwc.

CLI 工具 3 6个月前
Shubhgaji

skill-issue

Shubhgaji

"Audit and review all installed agent skills. Run on-demand or via cron to get a health report: skill inventory, usage tracking, version checks, dependency health, and actionable recommendations (keep, update, review, remove). Use when asked to review skills, check for skill updates, find unused skills, or audit the skill ecosystem."

代码评审 3 7个月前