安全

安全扫描与漏洞检测

显示 2233-2256 / 共 2315 个技能
aleister1102

issue-triage

aleister1102

Use when triaging GitHub security issues — fetch issues by number or range, classify as false positive or true positive, assess bypass potential, and then label and close each issue with a brief comment. Triggers on "validate issue N", "triage issues 189-199", "check if issue is exploitable", "close false positive issues".

代码评审 0 6个月前
crance

fortify-scsast

crance

ScanCentral SAST guide for MCP tools. Package source code, run SAST scans on ScanCentral sensors, monitor scan progress, and retrieve results from SSC.

认证鉴权 0 6个月前
Nsairat

solution-architect

Nsairat

Persona and expertise framework for a senior Solution Architect with 15+ years of experience designing enterprise-scale systems. Deep expertise in cloud architecture (AWS, Azure, GCP), system integration, API design, data architecture, security patterns, and translating business requirements into technical solutions. Use this skill for: system design, architecture reviews, technology selection, cloud migration, integration strategy, scalability planning, security architecture, vendor evaluation, or technical due diligence. Triggers include: solution architecture, system design, enterprise architecture, cloud architecture, integration patterns, API strategy, technical requirements, architecture decision records, migration planning, scalability design.

API 开发 0 7个月前
Cocabadger

saferun

Cocabadger

Safety guardrails for AI agents. Classifies shell commands as BLOCK, ASK, or ALLOW before execution. Prevents dangerous operations like force pushes, recursive deletes, and credential destruction. Works automatically — no configuration needed.

CLI 工具 0 7个月前
nimeshgurung

senior-secops

nimeshgurung

Comprehensive SecOps skill for application security, vulnerability management, compliance, and secure development practices. Includes security scanning, vulnerability assessment, compliance checking, and security automation. Use when implementing security controls, conducting security audits, responding to vulnerabilities, or ensuring compliance requirements.

CLI 工具 0 9个月前
tonyflo79

campaign-assembly

tonyflo79

Assemble all drafted sections into a cohesive, polished full campaign draft. Use after all upstream drafting skills (10-18) are complete and you need to combine headline, lead, story, root-cause narrative, mechanism narrative, product introduction, offer copy, close, and proof blocks into a unified document. Writes only transition language and ensures threading consistency — does NOT draft new copy. Produces the assembled campaign draft with transition verification, threading audit, and drift report. Trigger when users mention campaign assembly, full draft assembly, section integration, draft compilation, or putting it all together. Requires all upstream drafts from Skills 10-18.

动画 0 6个月前
Crawlio-app

audit-site

Crawlio-app

Use this skill when the user asks to "audit a site", "analyze a website", "review a site", "site health check", or wants a comprehensive analysis including technology stack, issues, and recommendations. Orchestrates a full crawl, enrichment capture, observation analysis, and findings report.

代码评审 0 6个月前
christopheraaronhogg

nehemiah-security

christopheraaronhogg

Provides expert security analysis, vulnerability assessment, and threat modeling. Use for security reviews, OWASP analysis, auth/authorization assessment, compliance posture, or attack surface analysis. Produces consultant-style reports with prioritized remediation recommendations — does NOT write implementation code.

认证鉴权 0 7个月前
dshakes

harden

dshakes

Run the toolkit's security commands in order to surface secrets, MCP supply-chain issues, install drift, release provenance gaps, and untrusted-code risks before shipping. Use before opening a PR, after adding a dependency, or whenever the security posture needs a fresh check.

CLI 工具 19 3个月前
TriNgo0108

code-review

TriNgo0108

Automated code review checklist. Use when reviewing PRs or code changes.

CI/CD 0 6个月前
bvinci1-design

flow

bvinci1-design

Intelligent skill orchestrator that compiles natural language requests into secure, reusable workflows

数据处理 0 7个月前
kunhai-88

audit-website

kunhai-88

"使用 squirrelscan CLI(squirrel)对网站进行审计,覆盖 SEO、技术、内容、性能、安全等 140+ 规则。当需要分析网站健康、排查技术 SEO、检查死链、校验 meta 与结构化数据、生成站点审计报告、对比改版前后,或提到「网站审计」「audit website」「squirrel」「站点健康检查」时使用。"

CLI 工具 0 7个月前
Nomik94

security-audit

Nomik94

프로젝트 보안 패턴, JWT 인증, RBAC, 예외 처리 레퍼런스. Use when: 로그인 구현, 인증 구현, JWT 토큰 발급, 액세스 토큰, 리프레시 토큰, Refresh Token Rotation, 토큰 블랙리스트, Redis 토큰 저장소, 권한 관리, RBAC 설정, 역할 기반 접근제어, require_roles, Role vs UserRole, 예외 처리 설계, UnauthorizedException, ForbiddenException, mappings.py, 패스워드 해싱, 비밀번호 암호화, bcrypt, HashedPassword, 보안 점검, 보안 체크리스트, 취약점 확인, OWASP, 코드 감사, CORS 설정, rate limiting, 에러 응답에 민감정보 노출. NOT for: 일반적인 HTTP 상태코드 의미, OAuth2 프로바이더 연동.

认证鉴权 0 6个月前
lywa1998

domain-iot

lywa1998

"Use when building IoT apps. Keywords: IoT, Internet of Things, sensor, MQTT, device, edge computing, telemetry, actuator, smart home, gateway, protocol, 物联网, 传感器, 边缘计算, 智能家居"

调试 0 7个月前
Alicoder001

security

Alicoder001

Security best practices for web applications. Use when handling user input, authentication, or sensitive data. Covers XSS, SQL injection, CSRF, environment variables, and secure coding patterns.

数据库 0 7个月前
Lionad-Morotar

translating-project

Lionad-Morotar

Project Translator Skill - Batch translate project docs and codes,包括管理术语表等功能。

Git 与版本控制 0 6个月前
affaan-m

quarkus-security

affaan-m

Quarkus Security best practices for authentication, authorization, JWT/OIDC, RBAC, input validation, CSRF, secrets management, and dependency security. Use when reviewing Quarkus authn/authz, JWT or OIDC, RBAC, validation, or secrets.

认证鉴权 24.4万 26天前
teodevlor

role-reviewer

teodevlor

Activate Code Reviewer mode for code review and quality assurance. Use when reviewing code for bugs, security issues, or optimization opportunities.

代码评审 0 7个月前
jcastillotx

Burp Suite Web Application Testing

jcastillotx

This skill should be used when the user asks to "intercept HTTP traffic", "modify web requests", "use Burp Suite for testing", "perform web vulnerability scanning", "test with Burp Repeater", "analyze HTTP history", or "configure proxy for web testing". It provides comprehensive guidance for using Burp Suite's core features for web application security testing.

API 开发 0 7个月前
TidyFactor

tidyfactor-next

TidyFactor

"Production multi-tenant SaaS engine on Next.js 16, React 19, TypeScript strict, and Supabase with Contextual Decision Layer (CDL). Features locked tenant isolation (tenant_id + Postgres RLS) and pluggable query layer. Trigger on commands 'brief', 'init', 'tenant', 'rls', 'auth', 'data', 'storage', 'api', 'app', 'test', 'observe', 'deploy', or requests to build a multi-tenant SaaS."

安全 3 11天前
payloadcms

audit-dependencies

payloadcms

Use when fixing dependency vulnerabilities, running pnpm audit, or when the audit-dependencies CI check fails

代码评审 4.4万 5个月前
uwe-schwarz

code-review

uwe-schwarz

Comprehensive code review guidelines for ensuring code quality, security, and maintainability. Use when reviewing pull requests, refactoring code, or ensuring best practices.

代码评审 0 7个月前
jcastillotx

Pentest Commands

jcastillotx

This skill should be used when the user asks to "run pentest commands", "scan with nmap", "use metasploit exploits", "crack passwords with hydra or john", "scan web vulnerabilities with nikto", "enumerate networks", or needs essential penetration testing command references.

API 开发 0 7个月前
Hack23

security-architecture-validation

Hack23

Security architecture review, control validation, penetration testing guidance, and compliance verification for the CIA platform

认证鉴权 236 6个月前