安全

安全扫描与漏洞检测

显示 2209-2232 / 共 2315 个技能
iamkaf

ai-writing-audit

iamkaf

Use when the user asks to "audit AI writing", "remove AI patterns", "make this sound less AI", "un-AI this text", or similar requests to identify/remove AI-generated writing patterns.

代码评审 0 7个月前
slurpyb

action-item-organizer

slurpyb

Systematic framework for extracting actionable items from documents and

自动化 0 6个月前
aiagentskills

attack-tree-construction

aiagentskills

Build comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders.

数据处理 0 7个月前
Raftersecurity

rafter

Raftersecurity

"Entry point for rafter. Invoke when a sub-skill is unclear, or when the task needs rafter run (remote SAST+SCA), rafter secrets (local secrets-only), rafter audit, policy checks, or command-risk evaluation. Scope by security surface, not task label: engage when the diff touches auth, credentials/secrets/tokens, untrusted input, SQL, shell/exec, file paths, deserialization, crypto, network endpoints, data deletion, or dependencies; for research/experimental/local-only code with none of that, a quick surface check is enough. When such surface IS present and no rafter skill or CLI call has been made, invoke this before handing the task off — an un-evaluated \"done\" on genuine security surface is not done."

CLI 工具 27 1个月前
Hack23

mcp-gateway-security

Hack23

MCP gateway security patterns, token management, request validation, and audit logging for MCP communications

代码评审 236 6个月前
YottaMeta

yotta-verify

YottaMeta

元信 —— 装任何技能/包前的确定性安全扫描器:prompt injection(提示注入)+ 危险模式 + SKILL.md 完整性 + 权限需求,输出 verdict(SAFE TO INSTALL / INSTALL WITH CAUTION / REVIEW REQUIRED / DO NOT INSTALL)+ audited 徽章。触发:安装/评估任何技能或 npm 包前、给技能做安全验证、生成 audited 徽章、CI 装前闸门;或用户说 装前扫描/验证/audited/安全验证/verify-skill/可信 等。边界:只做确定性静态扫描与报告,不执行被测代码、不联网、不装包、不修复;结论需人工确认,不代替最终决策。

代码评审 0 8天前
darrenrolf0481-ship-it

code-reviewer

darrenrolf0481-ship-it

Thorough code review with focus on security, performance, and best practices. Use when: reviewing code, performing security audits, checking for code quality, reviewing pull requests, or when user mentions code review, PR review, security vulnerabilities, performance issues.

数据库 0 4个月前
keep-starknet-strange

cairo-auditor

keep-starknet-strange

Security audit of Cairo/Starknet code. Trigger on "audit", "check this contract", "review for security". Modes - default (full repo), deep (+ adversarial reasoning), or specific filenames.

代码评审 80 4个月前
SSZcreate

performing-subdomain-enumeration-with-subfinder

SSZcreate

Enumerate subdomains of target domains using ProjectDiscovery's Subfinder

数据处理 0 8天前
Hack23

github-actions-workflows

Hack23

Create secure CI/CD workflows with GitHub Actions for Java 26/Maven/PostgreSQL builds, security scans, and deployments

CI/CD 236 4个月前
anorbert-cmyk

AppSec Engineer

anorbert-cmyk

Application Security Engineer preventing vulnerabilities and enabling secure development.

API 开发 0 7个月前
ruchernchong

security

ruchernchong

Run security audit with GitLeaks pre-commit hook setup and code analysis

代码评审 0 6个月前
pmco23

qa

pmco23

Use after /build to run the full post-build QA pipeline. Supports --parallel (all audits simultaneously) or --sequential (denoise → qf → qb → qd → security-review in order). Requires .pipeline/build.complete.

代码评审 0 6个月前
Hack23

information-security-strategy

Hack23

AI-enabled security excellence through transparent ISMS implementation, defense-in-depth, and strategic planning aligned with Hack23 business model

认证鉴权 236 3个月前
markfred5377

opencode-config-audit

markfred5377

Comprehensive configuration audit skill for OpenCode desktop application. Detects configuration errors, security issues, duplicate files, and optimization opportunities. Supports self-check of installed skills.

代码评审 0 6个月前
lct1407

python-backend-development

lct1407

Generate Python FastAPI code following project design patterns. Use when creating models, schemas, repositories, services, controllers, database migrations, authentication, or tests. Enforces layered architecture, async patterns, OWASP security, and Alembic migration naming conventions (yyyymmdd_HHmm_feature).

认证鉴权 0 7个月前
Hack23

secure-development-policy

Hack23

Hack23 secure development policy enforcement, SAST/DAST integration, dependency scanning, and code signing practices

代码评审 236 6个月前
kprsnt2

nodejs

kprsnt2

Node.js server development patterns including async patterns, error handling, and security best practices.

调试 0 8个月前
mrqureshi95

sdlc-autopilot

mrqureshi95

Full software development lifecycle orchestrator for ANY coding task. Triggers on ALL code changes — bug fixes, features, refactors, improvements, performance, security fixes, API changes, UI changes, database changes, config changes, new files, deletions, or any request to modify, create, fix, build, or ship code. This skill should activate FIRST on every coding prompt to orchestrate the full pipeline — understand, plan, implement, test, audit, guard against recurrence, and ship. It automatically discovers and delegates to other installed skills for domain expertise.

代码评审 0 5个月前
lenneTech

maintaining-npm-packages

lenneTech

Analyzes and optimizes npm package dependencies. Handles outdated packages, npm audit findings, security vulnerabilities, dependency updates, unused dependency removal, and devDependencies recategorization. Recommends the lt-dev:npm-package-maintainer agent via /maintain commands. Activates for "update packages", "npm audit", "check dependencies", "security fix", or package.json optimization. NOT for @lenne.tech/nest-server version updates (use nest-server-updating).

代码评审 0 7个月前
Rimblehelm

maui-authentication

Rimblehelm

A brief description of what this skill does

认证鉴权 0 7个月前
cuioss

recipe-security-audit

cuioss

On-demand security-audit recipe that runs the shared five-stage audit engine over the current footprint and emits findings into the triage pipeline

智能体 4 2个月前
aleister1102

fp-check

aleister1102

"Systematically verifies suspected security bugs to eliminate false positives. Produces TRUE POSITIVE or FALSE POSITIVE verdicts with documented evidence for each bug."

代码评审 0 6个月前
jwa91

mac-cleanup

jwa91

"Interactive macOS system cleanup for any dev machine. Frees disk space by pruning caches, package managers, unused apps, stale dev artifacts, and more. Discovers what's installed rather than assuming a specific setup. Always consults the user before deleting anything. Use when the user asks to: clean up their Mac, free disk space, remove unused apps, prune caches, clean developer artifacts, or any disk space maintenance task."

CLI 工具 0 6个月前