安全

安全扫描与漏洞检测

显示 2041-2064 / 共 2326 个技能
Hack23

compliance-frameworks

Hack23

Multi-framework compliance (ISO 27001, NIST CSF, CIS Controls, GDPR, NIS2, EU CRA, SOC 2), control mapping

代码评审 236 6个月前
mishankov

code-review

mishankov

Perform comprehensive software code reviews focused on correctness, regressions, security, reliability, performance, and test quality. Use when asked to review pull requests, commits, branches, patches, or source files and deliver prioritized findings with severity, concrete impact, and file/line references.

代码评审 0 6个月前
pietz

code-audit

pietz

Structural health assessment for codebases. Use when the user asks to audit code quality, assess code health, review a codebase, find technical debt, clean up code structure, or identify refactoring opportunities. Also use when asked to do a "code audit", "codebase review", "quality assessment", or "tech debt analysis". Provides parallel multi-lens analysis via sub-agents with specialized checklists for code health, cross-module coherence, refactoring detection, and security.

代码评审 0 6个月前
htooayelwinict

code-review-checklist

htooayelwinict

Review code changes for correctness, security, performance, and maintainability. Use for PR reviews, code audits, pre-merge checks, or quality validation of Laravel + React + Python code. EXCLUSIVE to reviewer agent.

代码评审 0 7个月前
rhein1

agoragentic-buzz-signed-workspace-evidence

rhein1

Convert exported Block Buzz / Nostr workspace events into bounded Agoragentic evidence. Use for signed release history, incident memory, workflow evidence, or Transaction Assurance preparation without treating channel membership as financial authority.

代码评审 36 1个月前
gajakannan

Quality Engineer Agent

gajakannan

Opinionated AI‑agent development framework with a reference Insurance CRM implementation.

CI/CD 0 6个月前
chrbailey

securing-ai-generated-code

chrbailey

Reviews AI-generated code for security vulnerabilities before commit. Checks for injection flaws, privilege escalation, hardcoded secrets, insecure defaults, and missing input validation. Use when reviewing code written by AI coding agents, after code generation, or before committing AI-assisted changes.

数据库 0 6个月前
danbars

writing-meeting-notes

danbars

Use when a meeting just occurred and notes need to be turned into a clear summary with decisions, action items, owners, and dates.

代码生成 0 7个月前
NguyenMinhGitHub

Solaudit - Smart Contract Security Scanner

NguyenMinhGitHub

Solidity smart contract security auditor. Detect reentrancy, overflow, access control issues. 50+ vulnerability patterns. CI/CD ready. Free CLI tool.

安全 0 7个月前
nimeshgurung

information-security-manager-iso27001

nimeshgurung

Senior Information Security Manager specializing in ISO 27001 and ISO 27002 implementation for HealthTech and MedTech companies. Provides ISMS implementation, cybersecurity risk assessment, security controls management, and compliance oversight. Use for ISMS design, security risk assessments, control implementation, and ISO 27001 certification activities.

代码评审 0 9个月前
jcastillotx

AWS Penetration Testing

jcastillotx

This skill should be used when the user asks to "pentest AWS", "test AWS security", "enumerate IAM", "exploit cloud infrastructure", "AWS privilege escalation", "S3 bucket testing", "metadata SSRF", "Lambda exploitation", or needs guidance on Amazon Web Services security assessment.

CLI 工具 0 7个月前
Hack23

security-by-design

Hack23

Threat modeling before coding, STRIDE methodology, defense in depth, security controls in SDLC

认证鉴权 236 6个月前
IHKREDDY

security-scan

IHKREDDY

Run security checks before PR including secrets, vulnerabilities, and best practices

代码评审 0 8个月前
kunhai-88

supabase-postgres-best-practices

kunhai-88

"Supabase 出品的 Postgres 性能优化与最佳实践。在编写、评审或优化 Postgres 查询、表结构设计或数据库配置时使用。"

数据库 0 7个月前
arielperez82

asking-questions

arielperez82

Guidance for asking clarifying questions when user requests are ambiguous, have multiple valid approaches, or require critical decisions. Use when implementation choices exist that could significantly affect outcomes.

认证鉴权 0 6个月前
vircung

Elixir Code Review Skill

vircung

Use this skill to ensure Elixir code meets BEAM VM best practices, security standards, and performance requirements while maintaining the functional programming paradigms that make Elixir powerful.

代码评审 0 7个月前
bromanko

elm-security-review

bromanko

This skill should be used when the user asks for "security review", "vulnerability scan", "audit Elm security", "security audit", "find vulnerabilities", "check for security issues", or wants a deep security analysis of Elm code including port safety, JSON decoder validation, and XSS prevention.

代码评审 0 6个月前
JoseGusnay

angular-enterprise-review

JoseGusnay

"Professional Code Auditor for Angular Enterprise Architecture. Performs strict reviews against SOLID, Smart/Dumb patterns, naming conventions, and testing standards."

代码评审 0 6个月前
scottwater

rails-security

scottwater

"Run a multi-agent security review of Rails application code. Use when the user asks for a Rails security review or audit, or raises a specific concern — authorization/IDOR/tenant isolation, XSS/SQL injection/SSRF, vulnerable gems/Brakeman/bundle audit, or prompt injection in AI features."

认证鉴权 1 29天前
automindtechnologie-jpg

Burp Suite Web Application Testing

automindtechnologie-jpg

This skill should be used when the user asks to "intercept HTTP traffic", "modify web requests", "use Burp Suite for testing", "perform web vulnerability scanning", "test with Burp Repeater", "analyze HTTP history", or "configure proxy for web testing". It provides comprehensive guidance for using Burp Suite's core features for web application security testing.

API 开发 0 7个月前
qingchunwuhui

blind-spot-scanner

qingchunwuhui

全景盲点扫描仪 - 使用 5W1H 方法强制拷问文档/方案,发现逻辑漏洞和执行盲点。

代码评审 0 6个月前
Out-treatyofversailles910

grounded-research

Out-treatyofversailles910

Enforces source-grounded, citation-first research discipline. Use this skill whenever the user asks to research a topic, fact-check a claim, summarize recent findings, look up current information, explain what the evidence says about something, or produce any factual output where accuracy and verifiability matter. Trigger even on conversational phrasing like "what's the deal with X", "is it true that Y", "what do experts say about Z", or "can you check if..." — if the answer requires facts that could be wrong or outdated, this skill applies. When in doubt, use it.

学术 0 3个月前
SteveLeve

workers-specialist

SteveLeve

Provide Cloudflare Workers runtime guidance for routing, bindings, performance, security headers, rate limiting, and Hono patterns used in this repo.

智能体 0 7个月前
halilugur

spring-boot-ultimate

halilugur

Spring Boot patterns, best practices, and code generation for REST APIs, JWT authentication, JPA, pagination, and modern Spring Boot development (Java 21+, Spring Boot 4.x)

API 开发 0 7个月前