安全

安全扫描与漏洞检测

显示 2113-2136 / 共 2324 个技能
nimeshgurung

isms-audit-expert

nimeshgurung

Senior ISMS Audit Expert for internal and external information security management system auditing. Provides ISO 27001 audit expertise, security audit program management, security control assessment, and compliance verification. Use for ISMS internal auditing, external audit preparation, security control testing, and ISO 27001 certification support.

代码评审 0 9个月前
hk-vk

httpsdocsbaseorgbase-chainllmstxt

hk-vk

Base is a fast, low-cost Ethereum L2 for building global onchain apps; start here to deploy, connect, and operate reliably.

智能体 0 6个月前
TriNgo0108

defi-protocol-templates

TriNgo0108

Implement DeFi protocols with production-ready templates for staking, AMMs, governance, and lending systems. Use when building decentralized finance applications or smart contract protocols.

金融 0 6个月前
leobrival

lighthouse-cli

leobrival

Lighthouse CLI expert for web performance auditing. Use when users need to audit performance, accessibility, SEO, best practices, or generate audit reports.

无障碍 0 7个月前
ronyparra

dep-check

ronyparra

Auditoría avanzada de dependencias con métricas técnicas centralizadas

代码评审 0 6个月前
nsasoft

nsauditor-ai

nsasoft

Use this skill whenever the user wants network security scanning, auditing, vulnerability assessment, host reconnaissance, or cloud-account security/compliance auditing with NSAuditor AI (via the nsauditor-ai MCP server: scan_host, scan_cloud, get_findings, probe_service, get_vulnerabilities, list_plugins). Triggers include 'scan', 'audit', 'vulnerability', 'CVE', 'network security', 'port scan', 'service detection', 'OS fingerprinting', 'penetration test', 'TLS/cipher audit', 'certificate check', 'DNS security', 'SPF/DKIM/DMARC/DNSSEC', 'SNMP/SMB/NetBIOS', 'CTEM', 'continuous monitoring', or 'audit my AWS/GCP/Azure account' / 'cloud compliance'. Also use it when the user asks to check if a host is up, enumerate services, find open ports, look up CVEs for a version, audit DNS records, or audit a cloud account — even if they don't say NSAuditor, as long as the nsauditor-ai MCP tools are available. Do NOT use for general coding, web development, or non-security topics.

认证鉴权 4 11天前
Olino3

django

Olino3

Expert-level Django development patterns and best practices for building secure, scalable web apps and APIs with Django and Django REST Framework. Guides architecture decisions, data modeling, API design, security, performance, and deployment.

API 开发 0 6个月前
TheWatcher01

smart-commit

TheWatcher01

Automates intelligent Git commits by analyzing unstaged/staged changes, grouping files by logical development concern, and committing sequentially with descriptive Conventional Commit messages. Includes pre-commit security audit protecting against credential leaks and large binary commits. Use when the user says "commit", "smart commit", "save changes", "push", "git commit", or similar.

代码评审 0 7个月前
crance

fortify-ssc

crance

"use this skill whenever the user wants to list and filter application security findings, discover applications and versions, and manage applications using Fortify Software Security Center (SSC). Triggers include: any mention of 'SSC', 'list vulnerabilities', 'list applications', and similar requests indicating interaction with Fortify SSC for application security tasks. OpenText Application Security is the new name for Fortify Software Security Center."

认证鉴权 0 6个月前
AlejandroRV

npm-migrate

AlejandroRV

AI-assisted migration and upgrade of npm packages. Handles breaking changes between major versions, deprecation cleanup within minor versions, adopting new APIs and patterns, security-driven upgrades from npm audit, and full dependency replacement (swapping one package for another, e.g. moment → dayjs). Analyzes changelogs, git diffs, and docs, scans your codebase for actual usage, cross-references to find what's affected, generates targeted code fixes or codemods, and verifies with your test suite. Use this skill whenever a user mentions upgrading, migrating, or updating npm packages, dealing with breaking changes, fixing deprecation warnings, replacing a dependency with an alternative, adopting new APIs from a package update, running npm audit fix with code changes, or comparing what changed between package versions. Trigger phrases include: "upgrade axios to v2", "migrate to express 5", "replace moment with dayjs", "fix deprecation warnings", "npm audit says vulnerable", "adopt the new API", "what changed between version X and Y", "swap lodash for es-toolkit", "help me upgrade my dependencies", "clean up deprecated calls".

代码评审 0 6个月前
cuioss

persona-auditor

cuioss

Audit persona that composes other personas as evaluation lenses across a wide scope

性能 4 2个月前
Hack23

hack23-information-security-policy

Hack23

Hack23 Information Security Policy integration for SDLC — developer-facing mapping of ISP requirements to daily engineering activities, tooling, and evidence

法律 236 4个月前
SvarogForge

forge

SvarogForge

⚒️ Forge — IT-фабрика, ключевой навык семейства SvarogForge. Supervisor/Worker оркестратор полного IT-цикла: хотелка → Talaria (гонцы pre-market) → отчёт → OK Gate → команда субагентов → Crucible → релиз. Оптимизирован для DeepSeek V4 Flash. Делегирование через delegate_task(role='orchestrator').

自动化 0 2个月前
hrdtbs

code-review

hrdtbs

Perform a comprehensive and constructive code review. Use this skill when you need to review a pull request, a specific file, or a code snippet. It focuses on correctness, security, performance, maintainability, and style.

代码评审 0 6个月前
Hack23

hack23-isms-compliance

Hack23

Hack23 ISMS organization-wide compliance requirements, policy enforcement, audit preparation

CI/CD 236 6个月前
pmco23

backend-audit

pmco23

Use after build is complete to audit backend code against the project style guide. Supports Go, Python, TypeScript, and C# backends. Checks naming, error handling patterns, package structure, and API conventions. Requires .pipeline/build.complete.

代码评审 0 6个月前
Nomik94

error-handling

Nomik94

FastAPI 에러 핸들링 패턴 레퍼런스. Use when: 예외 처리, 에러 핸들러, exception handler, 에러 응답, 커스텀 예외, 도메인 예외를 HTTP로 매핑, 전역 에러 핸들링, ValidationError 처리, 404 Not Found, 비즈니스 예외, 에러 코드 체계, 에러 로깅, 예외 계층 설계, mappings.py, DOMAIN_EXCEPTION_MAPPINGS, ErrorBody, @transactional, @retry, @log_execution. NOT for: 보안 관련 예외 (security-audit 참조).

API 开发 0 6个月前
Hack23

security-documentation

Hack23

Maintain comprehensive security documentation including SECURITY_ARCHITECTURE.md, THREAT_MODEL.md per Hack23 ISMS standards

认证鉴权 236 6个月前
bromanko

fsharp-review

bromanko

This skill should be used when the user asks to "review F#", "full F# review", "review all F#", "comprehensive F# review", "review fsharp", or wants a complete review covering code quality, security, performance, and testing for F# code.

代码评审 0 6个月前
tonyflo79

ad-intelligence

tonyflo79

Build comprehensive competitive intelligence on what ads are running and winning in a target vertical. Use when launching a new ad campaign, entering a new market, or refreshing competitive intelligence. Scrapes 500+ competitor ads across 2+ platforms (Meta Ad Library, TikTok Creative Center), classifies every ad by hook type (32-type taxonomy), format, visual style, and estimated run duration. Extracts top 20 winning ad specimens with full verbatim copy transcription and identifies opportunity gaps (underused hook types, format gaps, messaging whitespace). Three modes: Initial Scan (new projects), Continuous Monitor (active campaigns), and Tool-Assisted Scan (pre-scraped data import). Trigger when users mention ad research, competitor ads, ad intelligence, what ads are running, or competitive ad analysis. First skill in the Ad Engine pipeline.

数据处理 0 6个月前
freejasonNN

security-audit-rlm

freejasonNN

Run and troubleshoot privacy-preserving, local DSPy RLM security audits for large legacy .NET codebases. Use when asked to scan repositories for vulnerabilities, tune RLM/tool limits, fix truncation/stall issues, or produce actionable markdown/json audit outputs without loading entire codebases into model context.

文件操作 0 7个月前
contextware

mcp-security-scanner

contextware

Scan for unprotected MCP servers using @contextware/mcp-scan package. Enables security auditing of local AI tools and network endpoints.

CLI 工具 0 7个月前
tippyentertainment

qr-code-scanner-tracking

tippyentertainment

Design, build, and refine a QR code–based tracking system. This skill helps generate QR codes, define what happens when they are scanned, and track scan events (who, where, when, how) for marketing, operations, product flows, or internal tools.

代码生成 0 6个月前
jcastillotx

supabase-best-practices

jcastillotx

Supabase development standards. Triggers when working with Supabase projects, Row Level Security, real-time subscriptions, or Edge Functions.

认证鉴权 0 7个月前