安全

安全扫描与漏洞检测

显示 1873-1896 / 共 2326 个技能
lukhanteanini21-glitch

code-audit

lukhanteanini21-glitch

Professional code security audit skill covering 55+ vulnerability types. Enhanced with WooYun 88,636 real-world vulnerability cases (2010-2016). This skill should be used when performing security audits, vulnerability scanning, penetration testing preparation, or code review for security issues. Supports 9 languages: Java, Python, Go, PHP, JavaScript/Node.js, C/C++, .NET/C#, Ruby, Rust. Includes 143 mandatory detection items across all languages with language-specific checklists. Covers SQL injection, XSS, RCE, deserialization, SSRF, JNDI injection, JDBC protocol injection, authentication bypass, business logic flaws, race conditions, and modern security domains (LLM, Serverless, Android). WooYun integration adds: statistical-driven parameter priority, bypass techniques library, logic vulnerability patterns, and real-case references. v1.0: Initial public release with Docker deployment verification framework.

安全 2 6个月前
Coowoolf

Energy Audit and Zone of Genius

Coowoolf

Review your calendar, color-code activities by energy impact (Green/Red), and systematically delegate draining tasks to maximize time in your Zone of Genius.

代码评审 2 7个月前
plutowang

code-critic

plutowang

Use when explicitly asked to critique code, find bugs, audit code quality, analyze performance, or review a specific code snippet for security issues. Do not use for full branch or PR reviews.

代码评审 2 6个月前
jforksy

cto

jforksy

CTO Co-Pilot - strategic technical leadership, architecture decisions, infrastructure optimization, and engineering team coordination

代码评审 2 7个月前
fefogarcia

dependency-audit

fefogarcia

Comprehensive dependency health auditing for JavaScript/TypeScript projects. Run npm audit, detect outdated packages, check for security advisories, and verify license compliance. Prioritises vulnerabilities by severity and provides actionable fix recommendations. Use when: auditing project dependencies, checking for vulnerabilities, updating packages, preparing for release, or investigating "npm audit" warnings. Keywords: audit, vulnerabilities, outdated, security, npm audit, pnpm audit, CVE, GHSA, license.

代码评审 2 6个月前
jforksy

ciso-vendor-risk

jforksy

Third-party risk management - vendor security assessments, SaaS tool reviews, vendor risk scoring, and onboarding checklists

数据处理 2 6个月前
plutowang

critical-thinking

plutowang

Always-on skill that enforces critical thinking during coding. Auto-apply on every coding task to prevent yes-man behavior, challenge assumptions, and ensure technical decisions are well-reasoned.

调试 2 6个月前
jforksy

ciso-compliance

jforksy

Compliance management - SOC 2 policies, Vanta integration, evidence collection, audit readiness, and gap analysis

数据处理 2 6个月前
cartoonitunes

ai-readiness-audit

cartoonitunes

Audit any website for AI agent readiness. Check llms.txt, MCP servers, structured data, semantic HTML, meta quality, and more. Use when optimizing a site for AI agents, checking AI discoverability, or preparing for AI search engines.

代码评审 1 6个月前
baotoq

kubernetes-architect

baotoq

Expert Kubernetes architect specializing in cloud-native

Docker 1 6个月前
oakencore

skillvet

oakencore

"Security scanner for ClawHub/community skills — detects malware, credential theft, exfiltration, prompt injection, obfuscation, homograph attacks, ANSI injection, campaign-specific attack patterns, and more before you install. Use when installing skills from ClawHub or any public marketplace, reviewing third-party agent skills for safety, or vetting untrusted code before giving it to your AI agent. Triggers: install skill, audit skill, check skill, vet skill, skill security, safe install, is this skill safe."

CLI 工具 1 6个月前
baotoq

k8s-manifest-generator

baotoq

Create production-ready Kubernetes manifests for Deployments, Services, ConfigMaps, and Secrets following best practices and security standards. Use when generating Kubernetes YAML manifests, creating K8s resources, or implementing production-grade Kubernetes configurations.

代码生成 1 6个月前
chen-ye

app-audit

chen-ye

Analyzes installed Termux packages and Android apps to identify redundancies, categorize usage, and suggest cleanups. Use when the user asks to audit apps, check for bloatware, or analyze installed software.

自动化 1 7个月前
yellinzero

aico-pm-clarification

yellinzero

Resolve requirement ambiguities through STRUCTURED questioning: one question at a time, with recommended options and reasoning. UNIQUE VALUE: Prevents overwhelming users with multiple questions. Provides expert recommendations for each decision. Use this skill when: - Running /pm.clarify command - User says "unclear", "not sure what this means", "confused about" - User asks "what does X mean?", "how should X work?", "can you clarify?" - Requirements have conflicting or inconsistent details - Stories are missing acceptance criteria or have gaps - Need to fill information gaps BEFORE development can proceed Process: Ask ONE question at a time (max 5 per session), provide recommended option with reasoning. DO NOT ask multiple questions at once - this overwhelms users.

认证鉴权 1 7个月前
ANGUARDA

clawvitals

ANGUARDA

Security health checks and secure configuration auditing for OpenClaw. Reviews your core security vitals across authentication, version currency, and platform config. Tracks whether your security posture improves or regresses over time, and alerts on new critical findings. Run "run clawvitals" to get your first score in under 30 seconds.

安全 1 5个月前
keep-starknet-strange

starknet-skills

keep-starknet-strange

Routes Cairo/Starknet coding and audit tasks to the smallest relevant module for focused, high-quality execution.

代码评审 1 6个月前
danielcubas

security-audit-saas-generic

danielcubas

Perform a full security audit for any SaaS web application regardless of specific framework or ORM. Use before production or after MVP completion.

认证鉴权 1 6个月前
theepan

java-code-review

theepan

Review Java source code for bugs, security vulnerabilities, performance problems, concurrency issues, AI-generated code quality issues, dependency licensing risks, and best practice violations. Use when a user asks to review Java code, audit Java files, find bugs in Java, check Java code quality, detect AI slop, check library licenses, or perform a code review on .java files. Accepts code provided directly, as local file paths, as directory paths, or as unified diff output.

代码评审 1 6个月前
cachemoney

dependency-updater

cachemoney

Smart dependency management for any language. Auto-detects project type, applies safe updates automatically, prompts for major versions, diagnoses and fixes dependency issues.

CLI 工具 1 6个月前
WyrdWerk

repo-security-audit

WyrdWerk

Quick security checklist for evaluating GitHub repos and npm packages before/after installation. For non-coders and users. Heavy details live in references/.

Git 与版本控制 1 3个月前
yariv1025

owasp-api-security-top-10

yariv1025

"OWASP API Security Top 10 - prevention, detection, and remediation for REST/GraphQL/API security. Use when designing or reviewing APIs - object- and function-level authorization, authentication, rate limiting and resource consumption, sensitive business flows, SSRF, API inventory and versioning, or consumption of third-party APIs."

API 开发 1 7个月前
Git-Fg

managing-npm

Git-Fg

"Manages npm, pnpm, and bun dependencies following strict protocols. Use when installing, updating, or auditing packages. Do not use for TypeScript configuration or build tooling."

CLI 工具 1 7个月前
makgunay

macos-distribution

makgunay

macOS app distribution covering code signing (Developer ID, App Store certificates), notarization (notarytool), DMG/pkg creation, App Store submission workflow, sandboxing entitlements, StoreKit for in-app purchases and subscriptions (SubscriptionOfferView, appTransactionID, Transaction.currentEntitlements, subscriptionStatusTask), StoreKit testing with local configuration files, PrivacyInfo.xcprivacy manifest, and dual distribution strategies (App Store + direct). Use when preparing an app for distribution, implementing purchases/subscriptions, configuring signing, or troubleshooting App Store rejection.

代码生成 1 7个月前
getskillsdev

claude-md-bp-context

getskillsdev

Audit CLAUDE.md for best practices. 18-point checklist.

代码评审 1 7个月前