安全
安全扫描与漏洞检测
container-scan-dockle
vchirrav
Run Dockle to audit container images against CIS Docker Benchmark and best practices. Checks for running as root, sensitive files, HEALTHCHECK, and more.
sast-spotbugs
vchirrav
Run SpotBugs with Find Security Bugs plugin on Java code. Detects injection flaws, XXE, insecure crypto, SSRF, deserialization, and other JVM security bugs.
sast-gosec
vchirrav
Run gosec SAST scans on Go code. Detects SQL injection, hardcoded credentials, insecure TLS, command injection, and other Go security issues.
firestore-security-rules-generation
Agentient
Firestore Security Rules patterns for user-scoped access, RBAC, and field validation. PROACTIVELY activate for: (1) implementing user-scoped data access rules, (2) setting up role-based access with custom claims, (3) validating fields and enforcing immutability. Triggers: "security rules", "rbac", "firestore rules"
security-intel-brief
pramseier-tenb
Build a leadership-ready security intelligence brief (PDF) for selected vendors and software products, down to specific versions. Collects CVEs, CISA KEV (known exploited vulnerabilities) status, latest/fixed versions, end-of-life dates, vendor advisories, and recent security news, then assigns per-product risk ratings. Use this skill whenever the user wants security research on a vendor or product, asks about CVEs/KEVs/vulnerabilities affecting software they run, wants a patch/version exposure check, or asks for a security report or briefing for leadership — even if they don't say "PDF" or "brief". Trigger on phrases like "what vulnerabilities affect X", "security posture of [vendor/product]", "CVE report", "vulnerability briefing", "is [software version] safe/exposed".
sast-semgrep
vchirrav
Run Semgrep SAST scans on code. Supports 30+ languages with OWASP, security, and custom rulesets. Parses results and provides remediation guidance.
secure-coding-generate
vchirrav
Generate secure code following OWASP Secure Coding rules. Automatically detects the security domain and produces code with inline Rule ID citations (e.g., [INPUT-04], [AUTH-07]) plus a rules-applied summary.
terraform
poindexter12
Terraform infrastructure-as-code reference for HCL syntax, state management, module design, and provider configuration. Use when working with Terraform configurations (.tf files), running terraform commands, troubleshooting state issues, or designing modules. Includes Telmate Proxmox provider patterns. Triggers: terraform, tfstate, .tf files, HCL, modules, providers, proxmox_vm_qemu.
container-optimize
manastalukdar
Docker/container optimization for size, layers, caching, and security
license-auditor
famaoai-creator
Output path for license report
backend-principle-eng-javascript-pro-max
PrakharMNNIT
"Principal backend engineering intelligence for JavaScript services. Actions: plan, design, build, implement, review, fix, optimize, refactor, debug, secure, scale backend code and architectures. Focus: correctness, reliability, performance, security, observability, scalability, operability, cost."
investor-readiness-audit
famaoai-creator
Output file path
code-review
truongnat
Perform deep semantic code reviews that go beyond syntax checking. Evaluates architecture adherence, security vulnerabilities, performance bottlenecks, and maintainability. Use when reviewing PRs, auditing code quality, or when the user asks for a code review of any file or module.
financial-modeling-maestro
famaoai-creator
Output file path
docker-expert
samChang72
Docker containerization expert with deep knowledge of multi-stage builds, image optimization, container security, Docker Compose orchestration, and production deployment patterns. Use PROACTIVELY for Dockerfile optimization, container issues, image size problems, security hardening, networking, and orchestration challenges.
ai-ethics-auditor
famaoai-creator
Audits AI systems for bias, fairness, and privacy. Analyzes prompts and datasets to ensure ethical and safe AI implementation.
red-team-adversary
famaoai-creator
Output path for report
mcp-aws-knowledge-connector
famaoai-creator
status: implemented
skill-shield
gpu-cli
Security audit and active remediation for agent skills. Analyzes SKILL.md instructions and bundled scripts for prompt injection, data exfiltration, excessive permissions, supply chain risks, and other threats. Presents findings inline, optionally generates reports, and can rewrite skills to remove security concerns.
quality-scorer
famaoai-creator
Output JSON path
cloud-waste-hunter
famaoai-creator
Actively identifies and eliminates unused or over-provisioned cloud resources. Goes beyond estimation to hunt for actual cost savings in live environments.
supply-chain-sentinel
famaoai-creator
Output path for report
security-scanner
famaoai-creator
Scans the codebase for security risks.
youtube-transcript
ryanhudson
This skill should be used when the user provides a YouTube URL and wants to "download transcript", "get captions", "get subtitles", "transcribe video", or extract text content from a YouTube video. Handles manual subtitles, auto-generated captions, and Whisper transcription as fallback.