安全

安全扫描与漏洞检测

显示 1729-1752 / 共 2326 个技能
clearsmog

qa

clearsmog

Adversarial quality audit loop. Critic finds issues, fixer applies fixes, loops until APPROVED (max 5 rounds). Works with any document format.

代码评审 2 6个月前
DUBSOpenHub

design-auditor

DUBSOpenHub

🔍 Design Auditor — paste a URL, get 5 ranked fixes to improve conversions. Analyzes layout, performance, accessibility, and CTA effectiveness. Say "audit <url>" to start, or "audit local" for a local dev server.

无障碍 2 6个月前
masanao-ohba

nextjs-deliverable-criteria

masanao-ohba

Quality gates and acceptance criteria for Next.js 15 App Router projects

代码评审 2 7个月前
vchirrav

tls-scan-testssl

vchirrav

Run testssl.sh to analyze TLS/SSL configurations. Checks cipher suites, protocols, certificate validity, known vulnerabilities (Heartbleed, POODLE, ROBOT), and compliance.

数据处理 2 6个月前
ma1orek

attack-tree-construction

ma1orek

Build comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders.

数据处理 2 7个月前
vchirrav

dast-nuclei

vchirrav

Run Nuclei template-based vulnerability scanner. Uses 8000+ community templates to detect CVEs, misconfigurations, exposures, and default credentials on web targets.

代码生成 2 6个月前
costa-marcello

review-code

costa-marcello

"Reviews current git changes with a senior engineer lens. Detects SOLID violations, YAGNI/DRY/KISS breaches, security risks, performance issues, and proposes actionable improvements. Use when reviewing pull requests, checking code quality before merging, or auditing changes for security vulnerabilities."

代码评审 2 6个月前
vchirrav

sast-flawfinder

vchirrav

Run Flawfinder SAST scans on C/C++ code. Detects buffer overflows, format string vulnerabilities, race conditions, and other memory safety issues.

数据处理 2 6个月前
Kooooooma

code-security-scanner

Kooooooma

Scan code repositories for security threats including data exfiltration, backdoors, malicious code injection, dependency chain risks, and sensitive file access. Use this skill when users want to audit a codebase (especially TypeScript/JavaScript/Node.js projects) for security vulnerabilities, detect hidden malware, review npm dependencies for supply-chain attacks, check for credential leaks, or perform a pre-deployment security review. Triggers on requests like "scan for malicious code", "security audit", "check for backdoors", "review dependencies for vulnerabilities", "detect data exfiltration".

代码评审 2 6个月前
vchirrav

dast-zap

vchirrav

Run OWASP ZAP for Dynamic Application Security Testing. Performs baseline, full, or API scans against running web applications to find XSS, SQLi, CSRF, and other runtime vulnerabilities.

API 开发 2 6个月前
ahmed9500070

securebydesign

ahmed9500070

Enforce security-by-design in every line of code, architecture decision, and system recommendation. Activate whenever the user is: building an app, writing code, designing an API, setting up infrastructure, integrating an LLM, reviewing code, planning a deployment, or asking about authentication, data storage, or external service integration. Do not wait to be asked. Proactively flag security issues and apply these guidelines.

认证鉴权 2 6个月前
vchirrav

api-security-spectral

vchirrav

Run Spectral to lint OpenAPI and AsyncAPI specs for security issues. Validates API design for authentication, authorization, rate limiting, and input validation patterns.

API 开发 2 6个月前
cuozg

unity-review-quality

cuozg

Full Unity project audit — A-F graded HTML report covering architecture, performance, best practices, tech debt. Triggers — 'project audit', 'quality audit', 'project review', 'code quality report', 'tech debt audit'.

代码评审 2 6个月前
vchirrav

sca-pip-audit

vchirrav

Run pip-audit for Python dependency vulnerability scanning. Checks installed packages and requirements files against the OSV and PyPI advisory databases.

代码评审 2 6个月前
clearsmog

visual-audit

clearsmog

Adversarial visual layout audit of documents and slides. Checks overflow, font consistency, component fatigue, and spacing. Supports .tex, .qmd, and .typ files.

代码评审 2 6个月前
vchirrav

sast-bandit

vchirrav

Run Bandit SAST scans on Python code. Detects common security issues like SQL injection, hardcoded passwords, exec usage, and insecure crypto.

数据处理 2 6个月前
vchirrav

mobile-security-mobsf

vchirrav

Run MobSF (Mobile Security Framework) for automated static and dynamic analysis of Android and iOS apps. Detects insecure storage, weak crypto, hardcoded secrets, and permission issues.

API 开发 2 6个月前
vchirrav

sast-cargo-audit

vchirrav

Run cargo-audit and cargo-geiger on Rust code. Audits dependencies for known vulnerabilities and detects unsafe code usage for memory safety review.

代码评审 2 6个月前
jorgealves

module-project-generator

jorgealves

Generates end-to-end student projects that reinforce specific modular learning objectives. Use to create professional-grade portfolio pieces and assessment tasks for engineering mentees.

代码生成 2 7个月前
vchirrav

secret-scan-gitleaks

vchirrav

Run Gitleaks to detect hardcoded secrets in git repositories. Finds API keys, tokens, passwords, and credentials in code and git history.

数据处理 2 6个月前
vchirrav

sca-grype

vchirrav

Run Anchore Grype for SCA vulnerability scanning on filesystems and container images. Matches dependencies against multiple vulnerability databases (NVD, GitHub, OS advisories).

数据处理 2 6个月前
vchirrav

cloud-security-prowler

vchirrav

Run Prowler for comprehensive cloud security posture assessment. Audits AWS, Azure, and GCP against CIS Benchmarks, PCI-DSS, HIPAA, GDPR, and other compliance frameworks.

云服务 2 6个月前
masanao-ohba

evaluation-criteria

masanao-ohba

Defines evaluation criteria and scoring methodologies for deliverable assessment

调试 2 7个月前
NewmanXBT

x-content-optimizer

NewmanXBT

Audit and optimize tweets, X articles, and threads for X's recommendation algorithm. Use when user wants to review content before posting, improve engagement potential, or get algorithm-friendly suggestions. Triggers on /x-content-optimizer or requests to "review tweet", "optimize for X algorithm", "audit my post", or "improve engagement".

代码评审 2 7个月前