安全

安全扫描与漏洞检测

显示 1609-1632 / 共 2326 个技能
manastalukdar

dependency-audit

manastalukdar

Comprehensive dependency security and license audit

代码评审 1 7个月前
PrakharMNNIT

backend-principle-eng-java-pro-max

PrakharMNNIT

"Principal backend engineering intelligence for Java services and distributed systems. Actions: plan, design, build, implement, review, fix, optimize, refactor, debug, secure, scale backend code and architectures. Focus: correctness, reliability, performance, security, observability, scalability, operability, cost."

数据处理 1 7个月前
famaoai-creator

compliance-officer

famaoai-creator

status: implemented

代码评审 1 6个月前
ricardogomes

learn-from-real-code

ricardogomes

Teaches learners to extract transferable design lessons from real-world codebases through critical evaluation and systematic exploration. Use when a learner wants to study existing code to learn patterns, architecture, or design decisions—not just understand what it does. Guides through navigation, pattern recognition, critical evaluation (deliberate choice vs. compromise), and lesson extraction. Triggers on phrases like "learn from this codebase", "study how X is implemented", "understand design patterns in Y", or when a learner wants to improve by reading real code.

注释 7 7个月前
corygabrielsen

synthesize

corygabrielsen

Consolidate brainstorm rounds into an organized synthesis. Themes emerge, winners surface, evolution becomes visible.

代码生成 1 6个月前
auldsyababua

Security Validation

auldsyababua

Pre-merge security validation detecting secrets, user-specific paths, insecure SSH configurations, and security-weakening flags

智能体 6 9个月前
amogha-dalvi

creating-sales-enablement

amogha-dalvi

Use when sales reps lack deal-stage-specific content, when the founder's sales knowledge lives in their head instead of a system, when win rates are declining or sales cycles are lengthening, when no buying group content map exists, or when reps spend significant time creating content that should already exist. Use when sales and marketing lack shared definitions and feedback loops.

代码评审 6 6个月前
Exploration-labs

typescript-code-review

Exploration-labs

Perform comprehensive code reviews for TypeScript projects, analyzing type safety, best practices, performance, security, and code quality with actionable feedback

代码评审 6 10个月前
spjoshis

threat-modeling

spjoshis

Master threat modeling with STRIDE, attack trees, risk assessment, and identifying security threats in systems and applications.

认证鉴权 6 8个月前
auldsyababua

skill-security-analyzer

auldsyababua

Comprehensive security risk analysis for Claude skills. Use when asked to analyze security risks, review security stance, audit skills for vulnerabilities, check security before deployment, or evaluate safety of skill files. Triggers include "analyze security," "security risks," "security audit," "security review," "is this skill safe," or "check for vulnerabilities."

代码评审 6 9个月前
spjoshis

security-documentation

spjoshis

Master security documentation with security policies, incident response plans, security procedures, and compliance documentation.

代码评审 6 8个月前
pluginagentmarketplace

production

pluginagentmarketplace

Unit testing, performance optimization, security implementation, Play Store deployment.

Kubernetes 6 8个月前
timequity

secrets-guardian

timequity

Protect repositories from accidental secret commits. Essential when working with AI agents. Use when: setting up new project, adding pre-commit hooks, scanning for secrets, fixing leaked credentials. Triggers: "настрой защиту секретов", "setup secrets", "check secrets", "scan secrets", "проверь секреты", "pre-commit", "gitleaks". PROACTIVELY suggest when creating new projects or when .pre-commit-config.yaml is missing.

CLI 工具 6 9个月前
amogha-dalvi

developing-brand-strategy

amogha-dalvi

Use when the user needs to build a strategic brand narrative, define thought leadership positioning, codify brand voice, or plan community and earned media presence. Use when brand is accidental rather than intentional, messaging could belong to any competitor, or AI search engines are shaping brand perception without input.

代码评审 6 6个月前
hopeoverture

security-hardening-checklist

hopeoverture

This skill should be used when the user requests to audit, check, or improve application security by analyzing security headers, cookie configuration, RLS policies, input sanitization, rate limiting, and other security measures. It generates a comprehensive security audit report with actionable recommendations. Trigger terms include security audit, security check, harden security, security review, vulnerability check, security headers, secure cookies, input validation, rate limiting, security best practices.

代码评审 6 10个月前
auldsyababua

security-validation

auldsyababua

Pre-merge security validation detecting secrets, user-specific paths, insecure SSH configurations, and security-weakening flags. Use before committing code/documentation, before creating PRs, or during QA validation. Supports automated scanning with severity-based enforcement (CRITICAL blocks merge, HIGH requires fixes).

CLI 工具 6 9个月前
amogha-dalvi

reducing-cac

amogha-dalvi

Use when customer acquisition cost is rising, channel-level CAC is unknown, LTV to CAC ratio is below 3 to 1, or paid spend is growing without proportional pipeline growth. Use when founders feel marketing is not working, when budget needs reallocation, or when organic channels are underinvested relative to paid.

代码评审 6 6个月前
auldsyababua

brand-analyzer

auldsyababua

This skill should be used when the user requests brand analysis, brand guidelines creation, brand audits, or establishing brand identity and consistency standards. It provides comprehensive frameworks for analyzing brand elements and creating actionable brand guidelines based on requirements.

代码生成 6 9个月前
spjoshis

security-assessment

spjoshis

Master security assessments with vulnerability scanning, penetration testing, security testing, and security audits.

认证鉴权 6 8个月前
mduongvandinh

spring-boot-full-stack

mduongvandinh

Complete Java Spring Boot skill set for building enterprise applications. Includes modular architecture with optional components: - PostgreSQL database with JPA/Hibernate + Flyway migration - Redis caching (optional) - Kafka/RabbitMQ messaging (optional, choose one) - JWT + OAuth2 authentication (optional OAuth2) - RBAC authorization (optional) - TDD with Mockito - Spec-First Development with OpenSpec

缓存 6 8个月前
peixotorms

soc2-compliance

peixotorms

Use when building SaaS platforms, cloud services, customer-facing APIs, multi-tenant systems, or any service handling customer data that requires SOC 2 certification — Trust Services Criteria, TSC, CC1 through CC9, Type I, Type II, AICPA, security, availability, processing integrity, confidentiality, privacy, evidence collection, vendor management, penetration testing, risk assessment, access review, change management, incident response

代码评审 3 7个月前
hitoshura25

Security Check Skill

hitoshura25

Consider additional security reviews for sensitive changes

代码评审 3 8个月前
mariano-aguero

solidity-security-audit

mariano-aguero

Comprehensive Solidity smart contract security auditing and vulnerability analysis skill. Based on methodologies from Trail of Bits, OpenZeppelin, Consensys Diligence, Sherlock, CertiK, Cyfrin, Spearbit, Halborn, and other leading Web3 security firms. This skill should be used whenever the user asks to "audit a smart contract", "review Solidity code for security", "find vulnerabilities", "check for reentrancy", "analyze gas optimization", "review access control", "check proxy patterns", "analyze DeFi protocol security", "review ERC20/ERC721 implementation", "check oracle manipulation risks", "review upgrade patterns", or mentions any security review of EVM-compatible smart contracts. Also triggers for keywords like "slither", "echidna", "foundry fuzz", "formal verification", "invariant testing", "flash loan attack", "MEV", "sandwich attack", "front-running", "delegatecall", "selfdestruct", "reentrancy guard", "access control vulnerability", "storage collision", "proxy upgrade security", "smart contract exploit", "L2 security", "cross-chain", "bridge security", "sequencer", "LayerZero", "CCIP", "account abstraction", "ERC-4337", "smart account", "paymaster", "bundler", "UserOperation", "re-audit", "diff audit", "remediation review", "fix verification", "Uniswap v4 hooks", "Chainlink integration", "Aave integration", "flash loan receiver", "ERC-4626 vault", "restaking", "EigenLayer", "severity classification", "severity decision". Even if the user simply pastes Solidity code and asks "is this safe?" or "any issues here?", use this skill.

代码评审 3 6个月前
1Mangesh1

security-hardening

1Mangesh1

Security hardening and secure coding practices. Use when user asks to "harden security", "secure coding", "OWASP vulnerabilities", "input validation", "sanitization", "SQL injection prevention", "XSS protection", "CORS security", "secure headers", "vulnerability scanning", or mentions security best practices and threat mitigation.

认证鉴权 3 7个月前