安全

安全扫描与漏洞检测

显示 1897-1920 / 共 2326 个技能
meetdave3

refine

meetdave3

Audit, score, and improve any project's Claude Code configuration. Analyzes CLAUDE.md, skills, agents, hooks, MCP servers, and settings. Trigger: /refine, /refine audit, /refine quick

智能体 1 6个月前
elliottrjacobs

security-audit

elliottrjacobs

Deep security audit of codebase with parallel domain-focused agents. Use when the user says "security audit", "check for vulnerabilities", "security review", or before a launch/deployment. More thorough than the security reviewer in /engineer-review.

代码评审 1 6个月前
Git-Fg

auditing-security

Git-Fg

"Scans for secrets and performs comprehensive security audits. MUST Use when verifying security of code changes or auditing file safety."

代码评审 1 7个月前
yariv1025

owasp-llm-top-10

yariv1025

"OWASP Top 10 for LLM Applications - prevention, detection, and remediation for LLM and GenAI security. Use when building or reviewing LLM apps - prompt injection, information disclosure, training/supply chain, poisoning, output handling, excessive agency, system prompt leakage, vectors/embeddings, misinformation, unbounded consumption."

MLOps 1 7个月前
jovermier

quality-severity

jovermier

This skill should be used when classifying issues, findings, or code review problems with severity levels. Triggers on requests like "classify severity", "what is P1/P2/P3", "determine issue priority".

数据处理 1 7个月前
jainabhishek

reflect

jainabhishek

Self-improving skill that analyzes conversations for corrections and preferences, then persists them to skill files with optional Git versioning. Use when: (1) User runs "/reflect" or "/reflect [skill-name]" to manually extract learnings, (2) User says "reflect on" or "reflect off" to toggle automatic reflection, (3) User says "reflect status" to check mode, (4) User wants Claude to remember corrections for future sessions. Supports manual and automatic (hook-based) modes.

代码评审 1 8个月前
pluginagentmarketplace

security-practices

pluginagentmarketplace

Master secure development, OWASP top 10, testing, and compliance. Use when building secure systems, conducting security reviews, or implementing best practices.

认证鉴权 1 8个月前
pluginagentmarketplace

security-architecture

pluginagentmarketplace

Design security architectures with threat modeling and zero trust

数据处理 1 8个月前
physics91

django-reviewer

physics91

WHEN: Django project review, ORM queries, views/templates, admin customization WHAT: ORM optimization + View patterns + Template security + Admin config + Migration safety WHEN NOT: FastAPI → fastapi-reviewer, Flask → flask-reviewer, DRF API only → consider api-expert

代码评审 1 9个月前
leobrival

audit-methodology

leobrival

Comprehensive audit methodology for web applications covering accessibility (RGAA 4.1), security (OWASP Top 10), performance (Core Web Vitals), and eco-design. Use when users need guidance on audit processes, testing methodologies, compliance standards, or audit best practices. Includes detailed reference documentation for each audit domain.

无障碍 1 7个月前
physics91

ai-code-reviewer

physics91

WHEN: Deep AI-powered code analysis, multi-model code review, security scanning with Codex and Gemini WHAT: Comprehensive code review using external AI models with severity-based findings, deduplication, and secret detection WHEN NOT: Simple lint checks -> code-reviewer, Quick security only -> security-scanner, Style formatting -> code-quality-checker

CLI 工具 1 8个月前
BankkRoll

google-cloud

BankkRoll

"Scraped from https://cloud.google.com/docs/ Source: https://cloud.google.com/docs. Use when questions involve: ai ml, authentication, buildpacks, enterprise, generative ai, security, terraform."

云服务 1 7个月前
pluginagentmarketplace

agent-safety

pluginagentmarketplace

Ensure agent safety - guardrails, content filtering, monitoring, and compliance

智能体 1 8个月前
yariv1025

owasp-kubernetes-top-10

yariv1025

"OWASP Kubernetes Top 10 - prevention, detection, and remediation for Kubernetes security. Use when designing or reviewing K8s workloads and clusters - workload config, supply chain, RBAC, policy enforcement, logging, authentication, network segmentation, secrets, cluster components, vulnerable components."

智能体 1 7个月前
Jackiexiao

supabase-postgres-best-practices

Jackiexiao

"Postgres performance optimization and best practices from Supabase for schema, indexing, query tuning, security, and operations."

数据库 1 6个月前
physics91

sql-optimizer

physics91

WHEN: SQL query review, query optimization, index usage, N+1 detection, performance analysis WHAT: Query plan analysis + Index recommendations + N+1 detection + Join optimization + Performance tuning WHEN NOT: Schema design → schema-reviewer, ORM code → orm-reviewer

代码评审 1 9个月前
terraphim

disciplined-verification

terraphim

Phase 4 of disciplined development. Verifies implementation against design through unit and integration testing. Builds traceability matrices, tracks coverage, and loops defects back to originating left-side phases.

安全 1 7个月前
josavicentevw

devsecops

josavicentevw

DevSecOps skill for security automation, vulnerability management, secure CI/CD pipelines, container security, secrets management, compliance, and security testing. Use when implementing security in development workflows, scanning for vulnerabilities, securing infrastructure, or when user mentions security automation, SAST, DAST, container scanning, or compliance.

CI/CD 1 7个月前
arc-claw-bot

clawdefender

arc-claw-bot

Security scanner and input sanitizer for AI agents. Detects prompt injection, command injection, SSRF, credential exfiltration, and path traversal attacks. Use when (1) installing new skills from ClawHub, (2) processing external input like emails, calendar events, Trello cards, or API responses, (3) validating URLs before fetching, (4) running security audits on your workspace. Protects agents from malicious content in untrusted data sources.

CLI 工具 1 6个月前
SerendipityOneInc

cloud-resources

SerendipityOneInc

Cloud resource management and monitoring for GCP (云资源管理与监控 - GCP)

代码评审 1 7个月前
chrysos

security-audit

chrysos

Run comprehensive security audit on any project. Detects package manager (npm, pnpm, yarn, bun, pip, composer, cargo, go), runs native audit commands, and searches the web for CVEs and security advisories for ALL dependencies — even those that pass the audit. Generates a detailed security report.

代码评审 1 7个月前
KaribuLab

python-fastapi

KaribuLab

FastAPI Secure Engineering

认证鉴权 1 6个月前
Nep-Cheat

clawdbot-self-security-audit

Nep-Cheat

Perform a comprehensive read-only security audit of Clawdbot's own configuration. This is a knowledge-based skill that teaches Clawdbot to identify hardening opportunities and generate reports. Use when user asks to "run security check", "audit clawdbot", "check security hardening", or "what vulnerabilities do I have". This skill only READS configuration and generates reports—it never modifies settings or executes fixes automatically. Designed to be extensible—new checks can be added by updating this skill's knowledge.

认证鉴权 1 7个月前
fethallaheth

audit-reports

fethallaheth

Generate formatted security audit findings for Web3 platforms (Sherlock, Code4rena, Cantina). Use when user needs to report vulnerabilities, format findings, or create audit reports for smart contract security contests.

代码生成 1 7个月前