安全

安全扫描与漏洞检测

显示 2257-2280 / 共 2315 个技能
ReGYChang

repo-scan-2-jira

ReGYChang

Scan a repo scope for actionable work items (bugs, TODO/FIXME, doc inconsistencies, performance/maintainability risks) and emit Jira-ready issues in a strict JSON schema. Use when asked to scan a specific module/path/page/route and produce evidence-backed Jira tickets.

数据处理 0 7个月前
djankies

reviewing-server-actions

djankies

Review Server Actions for security, validation, and best practices in React 19. Use when reviewing forms, mutations, or server-side logic.

数据库 0 9个月前
williamlimasilva

ai-prompt-engineering-safety-review

williamlimasilva

'Comprehensive AI prompt engineering safety review and improvement prompt. Analyzes prompts for safety, bias, security vulnerabilities, and effectiveness while providing detailed improvement recommendations with extensive frameworks, testing methodologies, and educational content.'

提示词 0 6个月前
pmco23

quick

pmco23

Use when implementing small features, bug fixes, typo corrections, config tweaks, or any well-understood change that does not require the full pipeline. Completely independent of the brief/design/review/plan/build/qa flow. Use --deep to escalate to Opus for trickier problems.

自动化 0 6个月前
jacoblewisau

design-hig-principles

jacoblewisau

Audit iOS/macOS UI against Apple Human Interface Guidelines. Provides context-aware, multi-perspective feedback on colors, typography, layout, accessibility, and platform conventions.

无障碍 0 7个月前
ehtbanton

csp-header-generator

ehtbanton

Generate Content Security Policy (CSP) header configurations for web security. Triggers on "create csp header", "generate content security policy", "csp config", "security headers".

代码生成 0 8个月前
ideola-ai

marketing-os

ideola-ai

Complete AI agent system for social media content marketing workflow. Use when user wants to create content briefs, plan content calendars, generate social media content assets, plan ad campaigns, or audit existing ad performance. Includes 5 integrated skills: brief (research-backed strategy), content-plan (calendar + ClickUp tasks), content-create (ready-to-use content), campaign (paid media strategy), and ads-audit (comprehensive ads audit).

代码评审 0 6个月前
kimasplund

adversarial-reasoning

kimasplund

Stress-test solutions using the STRIKE framework. Systematically attack proposals to find weaknesses before deployment.

安全 0 7个月前
xuziqiang98

pwn-exploit

xuziqiang98

Comprehensive binary exploitation techniques covering stack overflow, format string, heap exploitation, integer overflow, and advanced exploitation methods. Use when working on CTF challenges, binary vulnerability analysis, exploit development, or debugging memory corruption vulnerabilities in Linux binaries (x86/x64).

数据处理 0 7个月前
Jackiexiao

react-doctor

Jackiexiao

Run after making React changes to catch issues early. Use when reviewing code, finishing a feature, or fixing bugs in a React project.

调试 0 6个月前
thanhnk1602

review

thanhnk1602

Review code changes for quality, patterns, and Acme standards compliance

代码评审 0 6个月前
anorbert-cmyk

WSTG Test Planner

anorbert-cmyk

Web Security Test Planner generating systematic, prioritized security testing plans based on OWASP WSTG.

认证鉴权 0 7个月前
simplerick0

dast

simplerick0

Security reviewer specializing in Dynamic Application Security Testing - analyzing running application behavior and runtime vulnerabilities. Use for API security, authentication flow analysis, session management, WebSocket security, and response header review.

API 开发 0 7个月前
kimasplund

security-analysis

kimasplund

Security assessment using STRIDE threat modeling, OWASP Top 10, and CVSS scoring. Use for security reviews, threat modeling, and secure coding guidance.

代码评审 0 7个月前
affaan-m

perl-security

affaan-m

Comprehensive Perl security covering taint mode, input validation, safe process execution, DBI parameterized queries, web security (XSS/SQLi/CSRF), and perlcritic security policies. Use when reviewing Perl input handling, process execution, DBI queries, or web-facing code.

CLI 工具 24.4万 26天前
anorbert-cmyk

Fullstack Web Engineer

anorbert-cmyk

World-class Full-Stack Web Engineer and Tech Lead focusing on security, accessibility, performance, and maintainability.

无障碍 0 7个月前
nimeshgurung

senior-security

nimeshgurung

Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing. Includes security assessment tools, threat modeling, crypto implementation, and security automation. Use when designing security architecture, conducting penetration tests, implementing cryptography, or performing security audits.

CLI 工具 0 9个月前
jonathansantilli

mobb-vulnerabilities-fixer

jonathansantilli

Scan, fix, and remediate security vulnerabilities in a local code repository using Mobb MCP/CLI. Use when the user asks to scan for vulnerabilities, run a security check, auto-fix issues, remediate findings, or apply Mobb fixes (e.g., \"scan this repo\", \"fix security issues\", \"remediate vulnerabilities\", \"run Mobb on my changes\").

认证鉴权 0 6个月前
koshimazaki

ue5-blueprint-audio

koshimazaki

Unreal Engine 5 Blueprint audio specialist. Use when working with Blueprint audio logic, game event detection, parameter wiring, audio components, scanning blueprints for audio nodes, listing project assets, or connecting game state to audio systems via UE5.

游戏开发 0 6个月前
copyleftdev

uunet

copyleftdev

Engineer at global scale in the style of UUNET (now Verizon Business). Emphasizes massive infrastructure resilience, "plumbing" the internet, pragmatic problem solving, and the evolution from moving bits to securing them (DBIR). Use when designing backbone networks, security operations centers, or large-scale distributed systems.

数据处理 0 7个月前
lenneTech

generating-nest-servers

lenneTech

Handles ALL NestJS and @lenne.tech/nest-server development tasks including module creation, service implementation, controller/resolver development, model definition, and debugging. Activates when working with src/server/ files, NestJS modules, services, controllers, resolvers, models, DTOs, guards, decorators, or REST/GraphQL endpoints. Supports monorepos (projects/api/, packages/api/). Covers lt server commands, @Roles/@Restricted security, CrudService patterns, and API tests. NOT for nest-server version updates (use nest-server-updating). NOT for TDD workflow orchestration (use building-stories-with-tdd).

API 开发 0 6个月前
profbernardoj

everclaw

profbernardoj

Open-source first AI inference — GLM-5 as default, Claude as fallback only. Own your inference forever via the Morpheus decentralized network. Stake MOR tokens, access GLM-5, GLM-4.7 Flash, Kimi K2.5, and 30+ models with persistent inference by recycling staked MOR. Open-source first model router routes all tiers to Morpheus by default — Claude only kicks in as an escape hatch when needed. Includes Morpheus API Gateway bootstrap for zero-config startup, OpenAI-compatible proxy with auto-session management, automatic retry with fresh sessions, OpenAI-compatible error classification to prevent cooldown cascades, multi-key auth rotation v2 with proactive DIEM balance monitoring and reactive 402 watchdog, Gateway Guardian v5 with direct curl inference probes (eliminates Signal spam), proactive Venice DIEM credit monitoring, circuit breaker for stuck sub-agents, nuclear self-healing restart, always-on proxy-router with launchd auto-restart, smart session archiver, three-shift cyclic execution engine (v2 with 15-minute execution loops), 24/7 always-on power configuration for macOS, bundled security skills, zero-dependency wallet management via macOS Keychain, x402 payment client for agent-to-agent USDC payments, ERC-8004 agent registry reader for discovering trustless agents on Base, and hardware-aware local Ollama fallback with auto model selection (Qwen3.5 family, 1.5B–72B based on available RAM/GPU).

自动化 0 5个月前
TriNgo0108

_workflow-security-audit

TriNgo0108

Process for conducting system security reviews and remediating vulnerabilities. Follow the phases sequentially.

代码评审 0 6个月前
prulloac

skill-validator

prulloac

Validate agent skills for correctness, readability, workflow clarity, and isolation, ensuring they can be installed independently without dependencies on other skills.

代码评审 0 6个月前