安全

安全扫描与漏洞检测

显示 1969-1992 / 共 2326 个技能
physics91

code-reviewer

physics91

WHEN: Code review, quality check, code smell detection, refactoring suggestions WHAT: Complexity analysis + code smell list + severity-based issues + improvement suggestions WHEN NOT: Next.js specific → nextjs-reviewer, Security → security-scanner, Performance → perf-analyzer

代码评审 1 9个月前
terraphim

quality-gate

terraphim

Right-side-of-V verification/validation orchestration for a change or PR. Produces a single Quality Gate Report with evidence covering: code review, security audit, performance regression risk, requirements traceability, acceptance/UAT scenarios, and (when UI changes) visual regression testing. Use when preparing a PR for merge/release, doing a “ready?” check, or enforcing an engineering quality gate.

代码评审 1 7个月前
ViniciusMarsili

kube-audit-kit

ViniciusMarsili

Performs read-only Kubernetes security audits by exporting resources, sanitizing metadata, grouping applications by topology, and generating PSS/NSA-compliant audit reports. Use when the user requests auditing Kubernetes clusters, Namespaces, security reviews, or configuration analysis.

CLI 工具 1 8个月前
physics91

fastapi-reviewer

physics91

WHEN: FastAPI project review, Pydantic models, async endpoints, dependency injection WHAT: Pydantic validation + Dependency injection + Async patterns + OpenAPI docs + Security WHEN NOT: Django → django-reviewer, Flask → flask-reviewer, General Python → python-reviewer

API 开发 1 9个月前
yariv1025

owasp-cloud-native-top-10

yariv1025

"OWASP Cloud-Native Application Security Top 10 - prevention, detection, and remediation for containers, orchestration, and cloud-native apps. Use when securing insecure config, injection, auth, CI/CD and supply chain, secrets, network policies. Note - official list has 6 risks; project archived."

认证鉴权 1 7个月前
youlianvr

dependency-auditor

youlianvr

"Audit and manage dependencies across multi-language projects. Identifies vulnerabilities, license conflicts, transitive dependency risks, and safe-upgrade paths. Use when auditing third-party packages before release, investigating a CVE, planning a major version bump, or running a license-compliance review. Examples: 'audit our npm dependencies', 'do we have GPL contamination', 'plan the upgrade to React 19'."

法律 1 2天前
anavvanzin

SQLite Database Expert

anavvanzin

Expert in SQLite embedded database development for Tauri/desktop applications with focus on SQL injection prevention, migrations, FTS search, and secure data handling

数据库 1 2个月前
Hack23

input-validation

Hack23

Implement comprehensive input validation to prevent XSS, SQL injection, and command injection attacks with sanitization strategies

注释 236 6个月前
ecelayes

htmx-universal-patterns

ecelayes

The definitive guide for building Hypermedia-Driven Applications (HDA) using HTMX, prioritizing security and UX patterns.

调试 0 7个月前
ameistad

native-app-publish-ready

ameistad

Comprehensive app store submission readiness checker for mobile apps. Audits iOS App Store and Google Play Store requirements including build config, privacy compliance, store assets, metadata, technical requirements, and common rejection causes. Use when the user asks to "check if my app is ready to submit", "review for app store", "app store checklist", "pre-submission check", "ready for Play Store", "ready for App Store", "submission readiness", or wants to audit a mobile app before publishing. Supports native iOS (Swift/ObjC), native Android (Kotlin/Java), Flutter, and React Native (including Expo) projects.

代码评审 0 6个月前
kbrdn1

role-definitions

kbrdn1

Skill migrated from _fragments/base/role-definitions

安全 3 今天
jcastillotx

SSH Penetration Testing

jcastillotx

This skill should be used when the user asks to "pentest SSH services", "enumerate SSH configurations", "brute force SSH credentials", "exploit SSH vulnerabilities", "perform SSH tunneling", or "audit SSH security". It provides comprehensive SSH penetration testing methodologies and techniques.

CLI 工具 0 7个月前
jcastillotx

javascript-best-practices

jcastillotx

JavaScript coding standards and best practices. This skill should be used when writing, reviewing, or refactoring JavaScript code. Triggers on tasks involving vanilla JavaScript, DOM manipulation, async operations, or performance optimization.

调试 0 7个月前
shivamsinghchahar

rails-security-audits

shivamsinghchahar

Audit Rails applications for security vulnerabilities using Brakeman, Bundler Audit, and security best practices. Use when scanning for CVEs, setting up security checks, or implementing security headers.

代码评审 0 6个月前
waseemkhan00777

wcag-audit

waseemkhan00777

Automated WCAG 2.1 AA accessibility audit using Puppeteer and axe-core across all application routes.

无障碍 0 6个月前
nexscope-ai

Domain Monitoring

nexscope-ai

E-commerce skills for AI agents — product research, marketing automation, supply chain optimization, and business analytics for online sellers across Amazon, Shopify, Etsy, TikTok Shop, and all platforms.

数据处理 835 5个月前
kbrdn1

security

kbrdn1

Skill migrated from _fragments/backend/security

认证鉴权 3 今天
jonathanprozzi

pre-pr-scan

jonathanprozzi

Pre-PR compliance and security scan. Checks diff against CLAUDE.md guidelines and security best practices before creating a pull request.

代码评审 0 7个月前
whatyourname12345

poc-validator

whatyourname12345

Automated Vulnerability Verification and Payload Replay Probe. Dynamically executes HTTP requests and analyzes HTTP status codes, error traces, time delays, and response lengths (e.g., Error-based, Time-based, and Boolean Blind SQLi). Use when: Testing specific payloads, verifying vulnerabilities, checking for blind injection conditions, or replaying raw HTTP requests. NOT for: Automated mass scanning, DDoS attacks, or unauthorized exploitation.

数据处理 0 5个月前
dtsvetkov1

security-audit

dtsvetkov1

Scans code for security vulnerabilities, hardcoded secrets, and unsafe patterns in React Native and Expo applications. Use before merging sensitive changes or as part of a regular audit.

代码评审 0 8个月前
Nomik94

python-best-practices

Nomik94

Python 코드 리뷰 및 베스트 프랙티스 검증. Use when: /python-best-practices, 코드 품질 분석, .py 파일 리뷰, 타입 힌트 검증, 린팅, 테스트 커버리지 분석, 의존성 점검. NOT for: 아키텍처 리뷰 (/code-review), 보안 전문 분석 (/security-audit).

代码评审 0 6个月前
bromanko

gleam-review

bromanko

This skill should be used when the user asks to "review Gleam", "full Gleam review", "review all Gleam", "comprehensive Gleam review", or wants a complete review covering code quality, security, performance, and testing for Gleam code.

代码评审 0 6个月前
gajakannan

writing-blogs

gajakannan

"Writes technical blog posts, devlogs, tutorials, and retrospectives based on completed project work. Activates when writing blog posts, creating devlogs, writing about features, summarizing builds, writing retrospectives, or documenting learnings. Does not handle official API or operations documentation (technical-writer), writing production code (backend-developer or frontend-developer), or security reviews (security)."

安全 0 6个月前
open-agreements

iso-27001-evidence-collection

open-agreements

Collect, organize, and validate evidence for ISO 27001 and SOC 2 audits. API-first approach with CLI commands for major cloud platforms. Produces timestamped, auditor-ready evidence packages. Use when user says "collect audit evidence," "prepare evidence package," "evidence for the auditor," "refresh evidence," or "evidence gap analysis."

数据处理 53 2个月前