安全
安全扫描与漏洞检测
opencode-audit
IdoKendo
Audit OpenCode configuration quality, safety, and operability with a 100-point rubric and concrete remediations.
security-scanner
physics91
WHEN: Security scan, vulnerability detection, XSS/CSRF analysis, secret exposure, OWASP Top 10 WHAT: XSS/injection detection + hardcoded secrets + auth/authz issues + severity-based vulnerability list WHEN NOT: Performance → perf-analyzer, Cloud security → cloud-security-expert
auditing-plugins
Git-Fg
"Comprehensive plugin auditing for compliance with marketplace best practices. MUST Use when validating, refactoring, or improving plugin quality. Do not use for creating new plugins, scaffolding components, or development tasks."
driver-license-eligibility
Ontos-AI
Provides driver license eligibility requirements based on user's country/state and age. It can specify minimum age, required documents, and any specific conditions.
security
scottymcandrew
Security audit specialist. Use before releases, after authentication/authorization changes, when handling sensitive data, or for periodic security reviews of code.
agentaudit-skill
starbuck100
Automatic security gate that checks packages against a vulnerability database before installation. Use before any npm install, pip install, yarn add, or package manager operation.
owasp-iot-top-10
yariv1025
"OWASP IoT Top 10 - prevention, detection, and remediation for IoT device and ecosystem security. Use when designing or reviewing IoT devices - passwords, network services, ecosystem interfaces, secure updates, components, data transfer/storage, device management, default settings, physical hardening, privacy."
owasp-privacy-top-10
yariv1025
"OWASP Top 10 Privacy Risks - prevention, detection, and remediation for privacy in web applications. Use when addressing app vulnerabilities, data leakage, breach response, consent, transparency, data deletion, data quality, session expiration, user access rights, excessive data collection."
react-doctor
Jackiexiao
Run after making React changes to catch issues early. Use when reviewing code, finishing a feature, or fixing bugs in a React project.
acr
johnsonshi
'Comprehensive Azure Container Registry (ACR) knowledge skill. Use when users ask about: container registries, ACR authentication, private endpoints, geo-replication, ACR Tasks, image signing (Notation), artifact cache, connected registry, vulnerability scanning, customer-managed keys, RBAC, network security, artifact streaming, Helm charts in ACR, ORAS, or any Azure container registry feature. Triggers: "ACR", "container registry", "azurecr.io", "az acr", "docker push/pull to Azure", "registry authentication", "private registry", "geo-replicated registry", "image signing", "Notation", "Ratify".'
owasp-cicd-top-10
yariv1025
"OWASP Top 10 CI/CD Security Risks - prevention, detection, and remediation for pipeline security. Use when securing or reviewing CI/CD - flow control, IAM, dependency chain, poisoned pipeline execution, PBAC, credential hygiene, system config, third-party services, artifact integrity, logging and visibility."
titvo
KaribuLab
Analyze generated code, identify vulnerabilities, and report them to the user.
owasp-mobile-top-10
yariv1025
"OWASP Mobile Top 10 - prevention, detection, and remediation for iOS/Android app security. Use when building or reviewing mobile apps - credentials, supply chain, auth, input/output validation, communication, privacy, binary protection, config, data storage, cryptography."
wcag-audit-perceivable-color
Jkense
Route color usage and visual distinction accessibility requirements
Compensation Benchmarks
yamz8
This skill should be used when the user asks about "salary ranges", "equity grants", "compensation benchmarks", "how much to pay", "competitive offer", "market rate", "startup compensation", "equity percentages", "option grants", or mentions specific compensation questions like "what should I pay a senior engineer" or "how much equity for a VP".
vue-doctor
Arjun-Ingole
Diagnose and fix Vue/Nuxt codebase health issues. Use when reviewing Vue code, fixing performance problems, auditing security, or improving code quality.
smart-contract-security
pluginagentmarketplace
Master smart contract security with auditing, vulnerability detection, and incident response
skills-security-audit
agentnode-dev
Audit AI agent skills for security risks before installation or periodically. Works on Claude Code, OpenClaw, and all platforms. Detect prompt injection, data exfiltration, malicious commands, obfuscated code, privilege abuse, supply chain risks, memory poisoning, trust exploitation, and behavioral manipulation. Use before installing third-party skills from any marketplace.
disciplined-validation
terraphim
Phase 5 of disciplined development. Validates system against original requirements through system testing and user acceptance testing (UAT). Uses structured stakeholder interviews to gather sign-off and traces defects back to research or design phases.
wcag-audit-perceivable-media
Jkense
Route audio, video, and multimedia accessibility requirements
antigravity-workflows
ncdevshiv
"Orchestrate multiple Antigravity skills through guided workflows for SaaS MVP delivery, security audits, AI agent builds, and browser QA."
architecture
dy9759
Comprehensive system architecture design and implementation workflow that orchestrates expert analysis, technical decision-making, and architectural pattern selection using the integrated toolset. Handles everything from initial system analysis to implementation-ready technical specifications.
audit-website
Jackiexiao
"Audit websites for SEO, performance, security, technical and content issues with actionable recommendations."
brand-analyzer
nguyendinhquocx
This skill should be used when the user requests brand analysis, brand guidelines creation, brand audits, or establishing brand identity and consistency standards. It provides comprehensive frameworks for analyzing brand elements and creating actionable brand guidelines based on requirements.