安全

安全扫描与漏洞检测

显示 1273-1296 / 共 2332 个技能
CsHeng

security-logging

CsHeng

Security controls and structured logging implementation. Use when security logging guidance is required.

文件操作 10 8个月前
CuriousLearner

security-headers

CuriousLearner

Validate and implement HTTP security headers to protect web applications.

API 开发 27 10个月前
gked2121

code-review-pro

gked2121

Comprehensive code review covering security vulnerabilities, performance bottlenecks, best practices, and refactoring opportunities. Use when user requests code review, security audit, or performance analysis.

代码评审 27 10个月前
CuriousLearner

dependency-updater

CuriousLearner

Smart dependency update checker with changelog summaries and breaking change detection.

代码生成 27 10个月前
CuriousLearner

code-reviewer

CuriousLearner

Automated code review with best practices, security checks, and quality standards.

数据库 27 10个月前
CuriousLearner

compliance-checker

CuriousLearner

Check code against security compliance standards and best practices.

数据处理 27 10个月前
CuriousLearner

secret-scanner

CuriousLearner

Detect accidentally committed secrets, credentials, and sensitive information in code.

云服务 27 10个月前
gked2121

brand-consistency-checker

gked2121

Scan documents and slides for off-brand colors, fonts, and logos. Validate against brand guidelines and suggest corrections.

代码生成 27 10个月前
CuriousLearner

dependency-auditor

CuriousLearner

Automated security auditing of project dependencies to identify known vulnerabilities.

CLI 工具 27 10个月前
CuriousLearner

meeting-notes

CuriousLearner

Convert meeting discussions into clear, actionable notes with tasks, decisions, and follow-ups fo...

代码评审 27 10个月前
Mikacr1138

bug-bounty

Mikacr1138

Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind maps, threat modeling), vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling, cache poisoning, OAuth, timing side-channels, OIDC, SSTI, subdomain takeover, cloud misconfig, ATO chains, agentic AI), LLM/AI security testing (chatbot IDOR, prompt injection, indirect injection, ASCII smuggling, exfil channels, RCE via code tools, system prompt extraction, ASI01-ASI10), A-to-B bug chaining (IDOR→auth bypass, SSRF→cloud metadata, XSS→ATO, open redirect→OAuth theft, S3→bundle→secret→OAuth), bypass tables (SSRF IP bypass, open redirect bypass, file upload bypass), language-specific grep (JS prototype pollution, Python pickle, PHP type juggling, Go template.HTML, Ruby YAML.load, Rust unwrap), and reporting (7-Question Gate, 4 validation gates, human-tone writing, templates by vuln class, CVSS 3.1, PoC generation, always-rejected list, conditional chain table, submission checklist). Use for ANY bug bounty task — starting a new target, doing recon, hunting specific vulns, auditing source code, testing AI features, validating findings, or writing reports.

认证鉴权 2 5个月前
WhatIfWeDigDeeper

uv-deps

WhatIfWeDigDeeper

Maintain Python packages through security audits or dependency updates on a dedicated branch using uv. Use for: security audits, CVE fixes, vulnerability checks, dependency updates, package upgrades, outdated packages, bump versions, fix Python vulnerabilities, check for Python CVEs, audit Python packages, update pyproject.toml dependencies, modernize Python deps, or when user types "/uv-deps" with or without specific package names or glob patterns. Use "help" or "--help" to show options.

代码评审 2 6个月前
tomwangowa

research-synthesis

tomwangowa

Use after running 2+ research skills (critical-research, tech-feasibility, narrative-auditor, codebase-audit) to synthesize findings into a unified decision document. Resolves conflicts between sources, weighs evidence, and produces an actionable recommendation.

学术 2 6个月前
StealthyLabsHQ

security-hardening

StealthyLabsHQ

Audit/harden app, infra, AI, privacy. Triggers: OWASP, XSS, SQLi, SSRF, auth/JWT, IDOR, secrets, deps, API, CI/CD, supply chain, cloud, K8s, IaC, AI IDE, browser builder, no-code, LLM/MCP, prompt injection, system prompt leakage, RAG poisoning, tool misuse, excessive agency, GDPR.

智能体 2 4个月前
br3eze-code

Available Skills in AgentOS (br3ezeclaw)

br3eze-code

代码生成 2 4个月前
zircote

backend-development

zircote

Build robust backend systems with modern technologies (Node.js, Python, Go, Rust), frameworks (NestJS, FastAPI, Django), databases (PostgreSQL, MongoDB, Redis), APIs (REST, GraphQL, gRPC), authentication (OAuth 2.1, JWT), testing strategies, security best practices (OWASP Top 10), performance optimization, scalability patterns (microservices, caching, sharding), DevOps practices (Docker, Kubernetes, CI/CD), and monitoring. Use when designing APIs, implementing authentication, optimizing database queries, setting up CI/CD pipelines, handling security vulnerabilities, building microservices, or developing production-ready backend systems.

API 开发 26 9个月前
tomwangowa

skill-auditor

tomwangowa

Audit Claude Code skills for quality, security, and best practices. Use when reviewing SKILL.md files, ensuring skill quality standards, or before sharing skills with team.

代码评审 2 6个月前
tomwangowa

codebase-audit

tomwangowa

Claims-first codebase audit that extracts documentation claims and verifies them against code. Use when asked to "audit", "verify docs match code", "check if README claims are true", or "validate documentation accuracy". Falsification-first approach.

代码评审 2 6个月前
br3eze-code

Available Skills in AgentOS (br3ezeclaw)

br3eze-code

代码生成 2 4个月前
zircote

python-deprecation-fixer

zircote

Automatically detect and fix Python deprecation warnings in codebases, including datetime.utcnow(), and other common deprecated patterns. Supports extensible pattern matching for future deprecations.

CLI 工具 26 9个月前
gemstone-source

0-day

gemstone-source

Systematic vulnerability research for CVE discovery, bug bounty methodology, patch-diff auditing, and offensive security work. Combines strategic architecture analysis with tactical exploitation testing. Covers source-to-sink tracing, trust boundary violations, authorization flaws, and variant hunting.

认证鉴权 2 2个月前
display-design-studio

ruby-on-rails

display-design-studio

Comprehensive Ruby on Rails 8.1 best-practices skill covering MVC, Active Record, routing, views, background jobs, storage, security, testing, and performance. Use when the user mentions Rails, Ruby on Rails, ActiveRecord, ActiveJob, ActionMailer, ActionCable, Active Storage, rails generate, rails routes, Hotwire, Turbo, Stimulus, or asks to build, review, debug, or migrate a Rails application or API.

代码生成 2 6个月前
hexbee

saas-agent-toolkit

hexbee

Design agent-usable SaaS tool systems using six reusable tool shapes (Search, Summarize, Draft, Update, Notify, Approve) plus connectors and policy guardrails. Use when turning SaaS features into reliable agent actions with clear contracts, permissions, audit trails, and approval gates.

智能体 2 6个月前
nicholasgriffintn

security-review

nicholasgriffintn

A specialist skill for security reviews, threat modeling, and remediation guidance. Use for auth/permissions changes, secrets or PII handling, public endpoints, or dependency upgrades.

认证鉴权 2 7个月前