安全

安全扫描与漏洞检测

显示 1129-1152 / 共 2332 个技能
crtvrffnrt

pentest-input-protocol-manipulation

crtvrffnrt

"Security assessment skill for input validation abuse and protocol-level manipulation. Use when prompts include injection, parser differential testing, request smuggling, method tampering, header confusion, serialization abuse, or payload mutation for exploitability testing. Do not use when the task is mainly authz boundary review, business workflow abuse, or report synthesis."

自动化 3 6个月前
lisbeth718

pseo-orchestrate

lisbeth718

Orchestrate the full programmatic SEO implementation by coordinating all pseo-* skills in the correct order. Use when implementing pSEO from scratch, running the full pSEO pipeline, or when the user asks to "set up programmatic SEO" or "build pSEO pages" without specifying a single skill.

代码评审 53 7个月前
hylarucoder

ast-grep-rule-crafter

hylarucoder

Write AST-based code search and rewrite rules using ast-grep YAML. Create linting rules, code modernizations, and API migrations with auto-fix. Use when the user mentions ast-grep, tree-sitter patterns, code search rules, lint rules with YAML, AST matching, or code refactoring patterns.

CLI 工具 53 8个月前
lisbeth718

pseo-audit

lisbeth718

Audit and assess a codebase for programmatic SEO readiness at 1000+ page scale. Use when starting a pSEO project, evaluating an existing codebase for pSEO gaps, or when the user asks to audit, assess, or review their site for programmatic SEO scalability.

代码评审 53 7个月前
julianromli

backend-dev

julianromli

Comprehensive backend development workflow that orchestrates expert analysis, architecture design, implementation, and deployment using the integrated toolset. Handles everything from API design and database architecture to security implementation and DevOps automation.

性能 52 9个月前
andrew

managing-dependencies

andrew

Evaluates packages, manages dependencies, and addresses supply chain security. Use when adding npm/pip/cargo/bundler/go dependencies, auditing packages, reviewing lockfile changes, checking for vulnerabilities, comparing package alternatives, or assessing package trustworthiness.

代码评审 16 7个月前
breethomas

ai-debug

breethomas

Diagnose why an AI feature is underperforming, hallucinating, or behaving inconsistently. Uses 4D audit to work backwards from symptoms to root cause.

代码评审 16 6个月前
ratacat

agent-native-audit

ratacat

Run comprehensive agent-native architecture review with scored principles

智能体 51 7个月前
Exploration-labs

skill-security-analyzer

Exploration-labs

Comprehensive security risk analysis for Claude skills. Use when asked to analyze security risks, review security stance, audit skills for vulnerabilities, check security before deployment, or evaluate safety of skill files. Triggers include "analyze security," "security risks," "security audit," "security review," "is this skill safe," or "check for vulnerabilities."

代码评审 51 10个月前
Exploration-labs

vibe-coding

Exploration-labs

Comprehensive guide for AI-assisted vibe coding. Use when the user wants to build applications through natural language prompts using tools like Lovable, Cursor, Replit, or Bolt. Includes best practices, pitfall awareness, tool-specific guidance, architectural decision support, and MVP scope definition with a bias toward cutting features aggressively to ship faster.

Git 与版本控制 51 10个月前
tzf1003

kali-tools

tzf1003

Comprehensive reference for Kali Linux tools. Use this skill to find, understand, and use security tools in Kali Linux. It provides a categorized index of all available tools.

Git 与版本控制 49 8个月前
maxnorm

magento-code-reviewer

maxnorm

Reviews Magento 2 code for quality, security, performance, and compliance with PSR-12 and Magento coding standards. Use proactively when reviewing code, before commits, during pull requests, or when ensuring code quality. Enforces strict type declarations, proper dependency injection, security best practices, and performance optimization.

代码评审 28 7个月前
jpoutrin

aws-cloud

jpoutrin

AWS cloud infrastructure patterns and best practices. Use when designing or implementing AWS solutions including EC2, Lambda, S3, RDS, and infrastructure as code with Terraform or CloudFormation.

云服务 15 7个月前
jgamaraalv

owasp-security-review

jgamaraalv

"Review code and architectures against the OWASP Top 10:2025 — the ten most critical web application security risks. Use when: (1) reviewing code for security vulnerabilities, (2) auditing a feature or codebase against OWASP categories, (3) providing remediation guidance for identified vulnerabilities, (4) writing new code and needing secure coding patterns. Triggers: 'review for security', 'OWASP audit', 'check for vulnerabilities','security checklist', 'is this code secure', 'security review', 'fix vulnerability'."

认证鉴权 15 6个月前
jgamaraalv

docker

jgamaraalv

"Docker containerization reference — multi-stage builds, Compose configs, image optimization, and container security for Yarn 4 monorepos. Use when: (1) creating or optimizing Dockerfiles, (2) configuring docker-compose for dev or production, (3) reducing image size with multi-stage builds, (4) hardening container security, or (5) setting up health checks and resource limits."

API 开发 15 6个月前
mujez

security-engineering

mujez

Application security and infrastructure security expert. Use when reviewing code for vulnerabilities, implementing authentication/authorization, securing APIs, hardening infrastructure, threat modeling, implementing encryption, or conducting security audits. Covers OWASP Top 10, secure coding, DevSecOps, and compliance.

API 开发 47 7个月前
FuzulsFriend

vibe-code-health-check

FuzulsFriend

Scans any codebase and grades it A through F across 6 health dimensions (security, error handling, code structure, performance, deployment readiness, UX basics). Use when asked to "check my code", "audit my project", "is my code ready to ship", "review my codebase", "health check", "code quality check", "is my app secure", "vibe check my code", "scan my project", or "what is wrong with my code". Takes a codebase path and returns a scored report card with plain-English fixes.

代码评审 6 5个月前
pubnub

pubnub-security

pubnub

Secure PubNub applications with Access Manager, encryption, and TLS

认证鉴权 6 7个月前
martinholovsky

appsec-expert

martinholovsky

"Elite Application Security engineer specializing in secure SDLC, OWASP Top 10 2025, SAST/DAST/SCA integration, threat modeling (STRIDE), and vulnerability remediation. Expert in security testing, cryptography, authentication patterns, and DevSecOps automation. Use when securing applications, implementing security controls, or conducting security assessments."

认证鉴权 45 9个月前
martinholovsky

Encryption Skill

martinholovsky

Encryption done wrong is worse than no encryption - it provides false confidence.

数据处理 45 9个月前
martinholovsky

OS Keychain Skill

martinholovsky

The OS keychain is your first line of defense. Misuse negates all downstream encryption.

API 开发 45 9个月前
martinholovsky

Auto-Update Systems Expert

martinholovsky

Expert in Tauri auto-update implementation with focus on signature verification, rollback mechanisms, staged rollouts, and secure update distribution

数据处理 45 9个月前
martinholovsky

rust

martinholovsky

Systems programming expertise for Tauri desktop application backend development with memory safety and performance optimization

CLI 工具 45 9个月前
martinholovsky

macos-accessibility

martinholovsky

"Expert in macOS Accessibility APIs (AXUIElement) for desktop automation. Specializes in secure automation of macOS applications with proper TCC permissions, element discovery, and system interaction. HIGH-RISK skill requiring strict security controls."

无障碍 45 9个月前